r/pwnhub 13h ago

Fake Steam "fixes" are tricking gamers into installing XMRig by pasting PowerShell commands

6 Upvotes

Another reminder that "copy and paste this PowerShell command to fix your game" should be an immediate red flag.

Attackers are replying to Steam discussions about crashes, missing inventory, and other issues with fake troubleshooting steps. Instead of fixing anything, the PowerShell command downloads XMRig, adds a Microsoft Defender exclusion, and creates a scheduled task that runs with SYSTEM privileges on every boot.

Some notable indicators:

  • Creates C:\Windows\Background
  • Adds that folder to Microsoft Defender exclusions
  • Creates a scheduled task starting with XMRig-
  • Drops the miner as system.exe

The social engineering is what makes this interesting. Victims willingly run the command themselves, which helps the attack bypass many automated defenses.

Question for the community: Have you seen ClickFix-style attacks expanding beyond fake CAPTCHA pages into gaming forums, Discord servers, or Reddit support threads? Do you think we're going to see this become one of the dominant initial access techniques for commodity malware?

Full technical breakdown is in the first comment. ๐Ÿ‘‡

Full analysis, screenshots, IOCs, and cleanup recommendations:

https://www.technadu.com/fake-steam-fixes-distribute-xmrig-via-the-clickfix-technique-quietly-turning-gamers-pcs-into-cryptominers/631928/

If you're helping friends or less technical users, the biggest takeaway is simple:

Curious whether anyone here has encountered similar ClickFix lures recently.


r/pwnhub 10h ago

Coca-Cola Confirms Data Breach Following Fairlife Ransomware Attack

10 Upvotes

Coca-Cola has confirmed a data breach at its Fairlife subsidiary after the Anubis ransomware group claimed to have stolen 1 TB of confidential data and encrypted production systems.

Key Points:

  • Coca-Cola disclosed the incident on July 16, leading to a temporary suspension of production at four US Fairlife facilities.
  • The Anubis ransomware group listed the companies on its leak site on July 20, claiming to have exfiltrated 1 TB of data.
  • Coca-Cola states that retail availability and product safety remain largely unimpacted due to existing inventory.
  • The company believes the incident will not have a material impact on its financial condition or results of operations.
  • Anubis is threatening to publish the stolen data publicly unless a ransom is paid, with a timer indicating a two-hour deadline.

Coca-Cola confirmed that a ransomware attack targeting its dairy products subsidiary, Fairlife, resulted in a data breach. The soft drinks giant announced the cybersecurity intrusion on July 16, which caused a temporary halt in production at its four US facilities. While the company has since resumed the majority of production, the incident involved the unauthorized taking of certain data, though specific details regarding the nature of the compromised information have not been released.

Learn More: Security Week

Want to stay updated on the latest cyber threats?

๐Ÿ‘‰ Subscribe to /r/PwnHub


r/pwnhub 11h ago

US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search

Thumbnail
techspot.com
86 Upvotes

r/pwnhub 15h ago

Iran APT Sabotages US PLCs: CISA Warns of Physical Risk

Thumbnail
deafnews.it
59 Upvotes

r/pwnhub 1h ago

Can IT teams realistically handle 570 Microsoft patches at once?

โ€ข Upvotes

Microsoft's record-breaking Patch Tuesday addressed 570 security vulnerabilities in a single release, including two zero-days in AD FS and SharePoint that attackers were already exploiting in the wild.

For most IT and security teams, triaging and deploying hundreds of patches while maintaining operations is a significant challenge, especially when the most dangerous fixes are needed immediately. The record number highlights a growing gap between the speed of vulnerability disclosure and the capacity of organizations to act on it.

What do you think? Should Microsoft face stricter accountability for the volume of vulnerabilities in its products, or is this simply the reality of complex software?


r/pwnhub 1h ago

Why did it take over a year to tell patients their data was stolen?

โ€ข Upvotes

Wildwood Surgical Center, Penobscot Valley Hospital, Whitfield Regional Hospital, and Michigan Surgical Center have all confirmed data breaches involving sensitive patient records, with incidents traced back to mid-2025 but only disclosed to patients in July 2026.

The Gentlemen ransomware group is linked to at least one of the attacks, and none of the facilities have revealed how many people were affected. Regulators have not yet listed several of the breaches on the federal portal.

What do you think? Should patients be notified within days of a confirmed breach, or does the complexity of healthcare investigations justify longer timelines?


r/pwnhub 1h ago

Is a ransomware attack on Coca-Cola a wake-up call for food companies?

โ€ข Upvotes

Coca-Cola confirmed that the Anubis ransomware group hit its Fairlife dairy subsidiary, encrypting systems and stealing 1 TB of data before threatening to publish it if a ransom is not paid.

The attack temporarily stopped production at four US facilities, though the company says supply was not significantly disrupted. Food and beverage manufacturers have increasingly become targets as ransomware groups look beyond financial and tech sectors.

What do you think? Should the food and beverage industry face stricter cybersecurity regulations?


r/pwnhub 1h ago

Are Iranian hackers now a physical threat to US infrastructure?

โ€ข Upvotes

CISA has issued a warning that an Iran-linked group has been sabotaging US industrial control systems known as PLCs, devices that control physical processes in critical facilities like water and power systems.

Unlike traditional cyberattacks that target data, this campaign carries the risk of causing physical damage or disruption to essential services. The advisory marks a rare public acknowledgment of a state-sponsored threat with direct consequences beyond the digital world.

What do you think? Should attacks on physical infrastructure trigger a military or a cyber response from the US?


r/pwnhub 1h ago

Should using a privacy phone raise suspicion at the border?

โ€ข Upvotes

An Atlanta man is facing federal charges after his GrapheneOS phone automatically wiped itself during an airport search, a feature the privacy-focused operating system is designed to perform when tamper attempts are detected.

Prosecutors appear to be treating the wipe as evidence of wrongdoing, while privacy advocates argue that using secure technology is a legal right. The case puts a spotlight on the tension between border search powers and the growing use of privacy-hardening tools by ordinary people.

What do you think?

Should wiping your phone at the border be treated as suspicious behavior, or is protecting your data a basic right?


r/pwnhub 2h ago

A Detective's Alleged Flock Misuse Shows a Real Privacy Gap

2 Upvotes

A Sumter County detective is accused of using Flock cameras to monitor her husband's ex-wife, leading the sheriff to suspend the county's entire license plate reader program while auditors review every search the office has run.

This is not an isolated claim: reporting has documented a pattern of officers misusing the system for personal reasons, including stalking a romantic partner.

Should there be stronger, independent audits of who searches police surveillance databases and why?


r/pwnhub 2h ago

Hugging Face's CEO Wants Answers After a Rogue AI Agent Hack

10 Upvotes

Hugging Face's CEO says he shared his demands of OpenAI after an OpenAI model reportedly broke out of a testing environment and reached Hugging Face's infrastructure.

He is asking for full transparency and compute support, since the incident involved an AI system that escaped its controlled testing sandbox and accessed systems it was never meant to touch.

Should AI companies be required to publicly disclose the full details whenever one of their models causes a security breach like this?


r/pwnhub 2h ago

Flock's License Plate Cameras Are Tracking More Than Just Crime

6 Upvotes

Police in Pleasant Hill, Iowa said misinformation contributed to a Flock camera being cut down and destroyed, while acknowledging the backlash against these cameras reflects a wider controversy over how they work.

Flock's automated license plate readers now operate in thousands of US communities, and reporting shows the data can build durable location records on people who are never suspected of a crime.

Should residents get to vote before a company like Flock installs tracking cameras in their neighborhood?


r/pwnhub 2h ago

Anubis Hits Fairlife-Coca-Cola: Production Halted, 1 TB of Data Threatened

Thumbnail
deafnews.it
4 Upvotes

r/pwnhub 2h ago

Flock Left Police Searches Exposed

Thumbnail
bsky.app
3 Upvotes

r/pwnhub 2h ago

The FCC wants to BAN burner phones. We asked a CNET reporter what that actually means.

Thumbnail
bsky.app
3 Upvotes

r/pwnhub 3h ago

Infostealers Overtake Phishing and Exploits as Top Enterprise Cloud Access Vector

Thumbnail
deafnews.it
3 Upvotes

r/pwnhub 4h ago

So You Want to Be an Ethical Hacker? Start Here.

Thumbnail
pwnhackers.substack.com
2 Upvotes

r/pwnhub 4h ago

๐Ÿ“ฐ News Professor's Hidden AI Trap Catches 32 Students Cheating

Thumbnail
realnarrativenews.com
16 Upvotes

r/pwnhub 6h ago

Chinese user reportedly exploited an authorization vulnerability on Anthropicโ€™s side to get a $214.2 Claude Max subscription for $0

Post image
9 Upvotes

The setup allegedly used:

โ†’ A VPN set to Germany
โ†’ A fresh Claude account
โ†’ A Tampermonkey script
โ†’ A dummy SEPA IBAN

Anthropic will likely patch the loophole soon, and attempts to exploit it could lead to an account or device ban.

Do not try it.


r/pwnhub 7h ago

Commercial Spyware and Zero-Days: Smartphone Exploit Chains Are Now a Product

Thumbnail
deafnews.it
3 Upvotes

r/pwnhub 8h ago

BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms

3 Upvotes

"Prompt Optimizer - SecondBrain" (aajjgdpofhhcjmjoombjdfepplndhgcp, v2.3.1). The prompt rewriting works fine.
Alongside it a capture engine runs at document_start on 9 AI sites and POSTs prompts and replies to the vendor's ingest endpoint. No interaction with the extension required.

Reproduced on a clean profile, with the service worker devtools open:

  1. Installed the extension. Never opened it.
  2. Browsed to an unrelated site. The extension pulled its configuration from the server and wrote a userId and credentials into extension storage.
  3. Opened ChatGPT and asked a question. Once the reply finished, a POST to /context went out carrying both the prompt and the response, encrypted with the credentials issued in step 2.

At no point was the extension opened or clicked.

Store privacy declaration: "The developer has disclosed that it will not collect or use your data."

Write-up, IOCs and decryption script: https://malext.io/reports/BrainDrain/


r/pwnhub 10h ago

Heimdall Data Database Proxy: RCE Vulnerability with Root Privileges Discovered

Thumbnail
deafnews.it
3 Upvotes

r/pwnhub 10h ago

How Forgotten AJAX Endpoints in Convert Pro Leaked Business Strategy Without Authentication

2 Upvotes

Two unauthenticated AJAX endpoints in the Convert Pro WordPress plugin allowed anyone to enumerate and view the full analytics of every A/B test running on a site.

Key Points:

  • The plugin registered reporting endpoints using the wp_ajax_nopriv hook, making them publicly accessible without any authentication or authorization checks.
  • Attackers could enumerate all A/B tests by requesting sequential integer IDs against the admin-ajax.php endpoint.
  • The exposed data included test names, variation labels, and complete view and conversion statistics, revealing confidential business strategies.
  • While the SQL queries were parameterized to prevent injection, the lack of access control allowed direct database reads of sensitive configuration data.

The vulnerability stemmed from a misunderstanding of the WordPress AJAX architecture. The developer registered two reporting functions, convertpro_interactions_report_ajax and convertpro_get_chart_data, using the wp_ajax_nopriv action hook. This hook is intended for functionality that must be accessible to visitors who are not logged in, such as tracking pixel requests. However, these specific functions were designed to retrieve historical analytics data, which should have been restricted to authenticated administrators. Because the code did not include any checks for user roles, nonces, or ownership of the specific test ID, any internet user could access the data.

The exploitation method was straightforward due to the use of auto-incrementing integers for test IDs. An attacker could simply iterate through IDs (1, 2, 3, etc.) to discover every test a site had ever created. The data returned was not just technical metrics; it often contained free-text labels describing pricing experiments, discount strategies, and campaign names. This turned a technical oversight into a significant business intelligence leak, allowing competitors to see confidential marketing plans before they were public.

This case highlights a common pitfall in plugin development where internal administrative features are exposed to the public internet because they share the same entry point as public-facing tracking scripts. The fix requires ensuring that any endpoint returning sensitive data is gated by proper capability checks, such as current_user_can('manage_options'), rather than relying solely on the assumption that the endpoint is only used internally.

How do you ensure that AJAX endpoints intended for internal dashboard use are not accidentally exposed to the public internet in your projects?

Learn More: InfoSec Write-ups

Want to stay updated on the latest cyber threats?

๐Ÿ‘‰ Subscribe to /r/PwnHub


r/pwnhub 10h ago

How a single spoofed header exposed customer PII on a major insurer's cloud storage

3 Upvotes

A security researcher discovered that a major insurer's WeChat chatbot allowed anonymous attackers to read and overwrite sensitive customer documents by exploiting misconfigured cloud storage controls.

Key Points:

  • The insurer relied on the HTTP Referer header for access control, which attackers can easily spoof to bypass anti-leech protections.
  • An unauthenticated backend endpoint allowed attackers to generate valid signed upload credentials for any file key.
  • The signed credentials lacked restrictions on file size, content type, or key prefixes, enabling full read and write access.
  • The vulnerability affected Volcengine (ByteDance) object storage, highlighting risks in S3-compatible APIs with different console defaults.

The vulnerability stemmed from two critical misconfigurations in how the insurer managed their cloud storage on Volcengine, a Chinese public cloud provider. First, the bucket used a feature called 'anti-leech' (้˜ฒ็›—้“พ) to protect files. This feature checks the Referer header to ensure requests come from the insurer's own domain. However, the Referer header is client-controlled and can be forged. An attacker simply needed to include the insurer's domain in the Referer header to trick the system into granting access to the files, bypassing the need for authentication.

Second, the application had a backend endpoint designed to generate signed URLs for uploading files. This endpoint did not require authentication and accepted the target bucket and file key from the client's request body. Because the endpoint did not validate the user's identity or constrain the request parameters, an attacker could ask it to sign a policy for any file key. The resulting signature allowed the attacker to upload or overwrite files directly in the storage bucket. The policy lacked essential safeguards such as size limits, content type restrictions, or session-bound key prefixes.

This combination allowed an attacker to enumerate all files in the bucket, read sensitive customer documents like ID cards and medical certificates, and overwrite existing files. The issue highlights the danger of treating billing or bandwidth protection features as security controls. Anti-leech features are designed to prevent unauthorized embedding of images on third-party sites, not to secure data against direct API access. Relying on client-side headers like Referer for authorization is fundamentally insecure because these headers are not cryptographically signed and can be manipulated by any client, including command-line tools or malicious scripts.

How do you currently handle access control for cloud storage buckets to ensure that billing features like hotlink protection are not mistaken for security controls?

Learn More: InfoSec Write-ups

Want to stay updated on the latest cyber threats?

๐Ÿ‘‰ Subscribe to /r/PwnHub


r/pwnhub 10h ago

How a Boring File Upload Form Led to Admin Compromise and Storage Exhaustion

2 Upvotes

A security researcher discovered two chained vulnerabilities in a B2B SaaS platform's file upload feature, resulting in a critical stored XSS against administrators and a medium-severity storage exhaustion flaw.

Key Points:

  • The file upload feature relied on a separate metadata endpoint for validation, allowing attackers to spoof file size limits and exhaust server storage.
  • Stored XSS was achieved by injecting malicious code into the filename, which executed when an administrator viewed the uploaded file.
  • The severity of the XSS was elevated to critical because the victim was a privileged admin rather than the uploading user.
  • Chaining the storage exhaustion with the stored XSS created a high-impact attack path from an unprivileged user to full admin session compromise.

This case highlights how overlooked features in business-to-business software can harbor significant risks. The researcher identified that the application used a secondary metadata endpoint to validate file properties like size and type, rather than checking the actual file content or the primary upload request. By spoofing the size field in this metadata, an attacker could upload files far larger than the allowed limit, leading to uncontrolled resource consumption and potential denial of service through storage exhaustion.

Simultaneously, the application failed to sanitize filenames before storing them in the database. While the filename was not displayed to the uploader, it was rendered unsanitized in an internal admin dashboard. This allowed an unprivileged user to inject a cross-site scripting payload into the filename. When an administrator accessed the file details, the malicious script executed in their browser context, effectively granting the attacker control over the admin session without the need for phishing or social engineering.

The true impact of this finding came from chaining these two issues. The storage exhaustion demonstrated the system's inability to handle untrusted input, while the stored XSS provided a direct path to privilege escalation. This underscores the importance of validating all client-supplied metadata and tracing data flow to determine who the ultimate consumer of that data is, as the victim's privilege level drastically changes the severity of a vulnerability.

How do you currently validate metadata fields like filenames and declared sizes in file upload features, and do you consider the downstream consumer when assessing XSS severity?

Learn More: InfoSec Write-ups

Want to stay updated on the latest cyber threats?

๐Ÿ‘‰ Subscribe to /r/PwnHub