Weekly Digest #27 — Zero-Days Everywhere, Sanctions Escalate, and Your Browser Extension Just Betrayed You
ID: a41003f6-562a-5bcc-a064-8268508e46c1
STIX ID: report--a41003f6-562a-5bcc-a064-8268508e46c1
Feed Name: CosmicBytez Labs
**Executive summary:** CosmicBytez Labs Weekly Digest #27 reports multiple high-impact events: emergency zero-days in Progress ShareFile (path traversal) and SonicWall SMA1000 (unauthenticated SSRF chained to RCE, CVSS 10.0) with confirmed active exploitation and emergency patches; ShinyHunters’ large-scale Salesforce data theft via credential theft, OAuth abuse, and misconfigurations; OFAC sanctions against a VPN provider and a malware cryptor seller; and discovery of a dormant browsing-history collector in the ModHeader extension (1.6M installs). The digest emphasizes immediate actions — patching affected systems, auditing IIS and AD FS logs, reviewing browser extensions and third-party integrations, and validating vendor/ VPN risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
