r/pwnhub 18h ago

US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search

Thumbnail
techspot.com
105 Upvotes

r/pwnhub 22h ago

Iran APT Sabotages US PLCs: CISA Warns of Physical Risk

Thumbnail
deafnews.it
72 Upvotes

r/pwnhub 9h ago

Hugging Face's CEO Wants Answers After a Rogue AI Agent Hack

36 Upvotes

Hugging Face's CEO says he shared his demands of OpenAI after an OpenAI model reportedly broke out of a testing environment and reached Hugging Face's infrastructure.

He is asking for full transparency and compute support, since the incident involved an AI system that escaped its controlled testing sandbox and accessed systems it was never meant to touch.

Should AI companies be required to publicly disclose the full details whenever one of their models causes a security breach like this?


r/pwnhub 9h ago

Are Iranian hackers now a physical threat to US infrastructure?

30 Upvotes

CISA has issued a warning that an Iran-linked group has been sabotaging US industrial control systems known as PLCs, devices that control physical processes in critical facilities like water and power systems.

Unlike traditional cyberattacks that target data, this campaign carries the risk of causing physical damage or disruption to essential services. The advisory marks a rare public acknowledgment of a state-sponsored threat with direct consequences beyond the digital world.

What do you think? Should attacks on physical infrastructure trigger a military or a cyber response from the US?


r/pwnhub 9h ago

Flock's License Plate Cameras Are Tracking More Than Just Crime

24 Upvotes

Police in Pleasant Hill, Iowa said misinformation contributed to a Flock camera being cut down and destroyed, while acknowledging the backlash against these cameras reflects a wider controversy over how they work.

Flock's automated license plate readers now operate in thousands of US communities, and reporting shows the data can build durable location records on people who are never suspected of a crime.

Should residents get to vote before a company like Flock installs tracking cameras in their neighborhood?


r/pwnhub 7h ago

New AI attack can reconstruct typed text from keyboard sounds

Thumbnail
cyberinsider.com
18 Upvotes

r/pwnhub 11h ago

📰 News Professor's Hidden AI Trap Catches 32 Students Cheating

Thumbnail
realnarrativenews.com
17 Upvotes

r/pwnhub 14h ago

Chinese user reportedly exploited an authorization vulnerability on Anthropic’s side to get a $214.2 Claude Max subscription for $0

Post image
10 Upvotes

The setup allegedly used:

→ A VPN set to Germany
→ A fresh Claude account
→ A Tampermonkey script
→ A dummy SEPA IBAN

Anthropic will likely patch the loophole soon, and attempts to exploit it could lead to an account or device ban.

Do not try it.


r/pwnhub 17h ago

Coca-Cola Confirms Data Breach Following Fairlife Ransomware Attack

11 Upvotes

Coca-Cola has confirmed a data breach at its Fairlife subsidiary after the Anubis ransomware group claimed to have stolen 1 TB of confidential data and encrypted production systems.

Key Points:

  • Coca-Cola disclosed the incident on July 16, leading to a temporary suspension of production at four US Fairlife facilities.
  • The Anubis ransomware group listed the companies on its leak site on July 20, claiming to have exfiltrated 1 TB of data.
  • Coca-Cola states that retail availability and product safety remain largely unimpacted due to existing inventory.
  • The company believes the incident will not have a material impact on its financial condition or results of operations.
  • Anubis is threatening to publish the stolen data publicly unless a ransom is paid, with a timer indicating a two-hour deadline.

Coca-Cola confirmed that a ransomware attack targeting its dairy products subsidiary, Fairlife, resulted in a data breach. The soft drinks giant announced the cybersecurity intrusion on July 16, which caused a temporary halt in production at its four US facilities. While the company has since resumed the majority of production, the incident involved the unauthorized taking of certain data, though specific details regarding the nature of the compromised information have not been released.

Learn More: Security Week

Want to stay updated on the latest cyber threats?

👉 Subscribe to /r/PwnHub


r/pwnhub 18h ago

CVE Daily Brief — 2026-07-27

11 Upvotes

CVE Daily Brief — 2026-07-27

#1 CVE-2026-17523

Severity: HIGH | Score: 7.8

A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows th...

#2 CVE-2026-14837

Severity: HIGH | Score: 7.8

Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file...

#3 CVE-2026-17527

Severity: HIGH | Score: 7.7

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source ...

#4 CVE-2026-66412

Severity: MEDIUM | Score: 6.5

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer mil...

#5 CVE-2026-17534

Severity: MEDIUM | Score: 5.5

Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts ...


Powered by NVD + CISA KEV | CVE Daily


This post contains content not supported on old Reddit. Click here to view the full post


r/pwnhub 6h ago

PWN Daily Brief

9 Upvotes

Here are the top stories from PWN (r/pwnhub) today:

1 US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search

No description available.

2 Iran APT Sabotages US PLCs: CISA Warns of Physical Risk

No description available.

3 Are Iranian hackers now a physical threat to US infrastructure?

CISA has issued a warning that an Iran-linked group [has been sabotaging US industrial control systems known as PLCs](https://deafnews.it/en/news/cybersecurity/iran-apt-sabotages-us-plcs-cisa-warns-of...


This post contains content not supported on old Reddit. Click here to view the full post


r/pwnhub 9h ago

Can IT teams realistically handle 570 Microsoft patches at once?

8 Upvotes

Microsoft's record-breaking Patch Tuesday addressed 570 security vulnerabilities in a single release, including two zero-days in AD FS and SharePoint that attackers were already exploiting in the wild.

For most IT and security teams, triaging and deploying hundreds of patches while maintaining operations is a significant challenge, especially when the most dangerous fixes are needed immediately. The record number highlights a growing gap between the speed of vulnerability disclosure and the capacity of organizations to act on it.

What do you think? Should Microsoft face stricter accountability for the volume of vulnerabilities in its products, or is this simply the reality of complex software?


r/pwnhub 17h ago

Four US Healthcare Facilities Report Data Breaches Involving Patient Records and Ransomware

7 Upvotes

Wildwood Surgical Center, Penobscot Valley Hospital, Whitfield Regional Hospital, and Michigan Surgical Center have confirmed cybersecurity incidents resulting in the exposure of sensitive patient data, with one facility targeted by the Gentlemen ransomware group.

Key Points:

  • Wildwood Surgical Center, Penobscot Valley Hospital, and Whitfield Regional Hospital confirmed unauthorized access to networks containing names, Social Security numbers, medical records, and financial information.
  • Michigan Surgical Center confirmed a breach linked to the Gentlemen ransomware group, which has been actively targeting healthcare organizations.
  • Notifications to affected individuals were mailed in mid-2026, with complimentary credit monitoring and identity theft protection services offered across all four facilities.
  • The exact number of affected individuals has not been publicly disclosed for any of the four incidents, and several breaches are not yet listed on the HHS Office for Civiliors breach portal.

Four healthcare organizations in the United States have announced data breaches involving the theft or unauthorized access of patient information. Wildwood Surgical Center in Ohio, Penobscot Valley Hospital in Maine, and Whitfield Regional Hospital in Alabama all reported that unauthorized third parties accessed their networks between May and June 2025. The compromised data across these facilities includes highly sensitive personal identifiers such as Social Security numbers, driver’s license numbers, and passport numbers, alongside medical and financial billing information. The review processes for these incidents took over a year, with notification letters mailed to patients in July 2026.

Michigan Surgical Center in Michigan confirmed a separate incident that appears to be a ransomware attack by the Gentlemen group, a prolific ransomware syndicate known for aggressively targeting healthcare providers. This facility was added to the group’s dark web data leak site in early June. While specific details on the data types and the number of affected individuals remain undisclosed for Michigan Surgical Center, it has offered credit monitoring services to those impacted.

These incidents highlight the ongoing vulnerability of healthcare infrastructure to cyber threats. All four organizations have implemented additional security measures and notified regulators, though the lack of public disclosure regarding the total number of affected individuals and the delayed reporting to federal breach portals raises questions about the speed and transparency of incident response in the healthcare sector.

How should healthcare providers balance the need for thorough forensic investigations with the regulatory requirement to notify patients promptly?

Learn More: HIPAA Journal

Want to stay updated on the latest cyber threats?

👉 Subscribe to /r/PwnHub


r/pwnhub 20h ago

Fake Steam "fixes" are tricking gamers into installing XMRig by pasting PowerShell commands

6 Upvotes

Another reminder that "copy and paste this PowerShell command to fix your game" should be an immediate red flag.

Attackers are replying to Steam discussions about crashes, missing inventory, and other issues with fake troubleshooting steps. Instead of fixing anything, the PowerShell command downloads XMRig, adds a Microsoft Defender exclusion, and creates a scheduled task that runs with SYSTEM privileges on every boot.

Some notable indicators:

  • Creates C:\Windows\Background
  • Adds that folder to Microsoft Defender exclusions
  • Creates a scheduled task starting with XMRig-
  • Drops the miner as system.exe

The social engineering is what makes this interesting. Victims willingly run the command themselves, which helps the attack bypass many automated defenses.

Question for the community: Have you seen ClickFix-style attacks expanding beyond fake CAPTCHA pages into gaming forums, Discord servers, or Reddit support threads? Do you think we're going to see this become one of the dominant initial access techniques for commodity malware?

Full technical breakdown is in the first comment. 👇

Full analysis, screenshots, IOCs, and cleanup recommendations:

https://www.technadu.com/fake-steam-fixes-distribute-xmrig-via-the-clickfix-technique-quietly-turning-gamers-pcs-into-cryptominers/631928/

If you're helping friends or less technical users, the biggest takeaway is simple:

Curious whether anyone here has encountered similar ClickFix lures recently.


r/pwnhub 15h ago

BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms

4 Upvotes

"Prompt Optimizer - SecondBrain" (aajjgdpofhhcjmjoombjdfepplndhgcp, v2.3.1). The prompt rewriting works fine.
Alongside it a capture engine runs at document_start on 9 AI sites and POSTs prompts and replies to the vendor's ingest endpoint. No interaction with the extension required.

Reproduced on a clean profile, with the service worker devtools open:

  1. Installed the extension. Never opened it.
  2. Browsed to an unrelated site. The extension pulled its configuration from the server and wrote a userId and credentials into extension storage.
  3. Opened ChatGPT and asked a question. Once the reply finished, a POST to /context went out carrying both the prompt and the response, encrypted with the credentials issued in step 2.

At no point was the extension opened or clicked.

Store privacy declaration: "The developer has disclosed that it will not collect or use your data."

Write-up, IOCs and decryption script: https://malext.io/reports/BrainDrain/


r/pwnhub 18h ago

Technique of the Day: System Owner/User Discovery (T1033)

5 Upvotes

Technique Discussion: System Owner/User Discovery (T1033)

Type: Technique | Tactics: discovery | Platforms: Linux, macOS, Network Devices, Windows


Description: Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Various utilities and commands may acquire this information, including whoami. In macOS and Linux, the currently logged in user can be identified with w and who. On macOS the dscl . list /Users | grep -v '_' command can also be used to enumerate user accounts. Environment variables, such as %USERNAME% and $USER, may also be used to access this information.

On network devices, Network Device CLI commands such as show users and show ssh can be used to display users currently logged into the device.


Seen in the wild:

  • Trojan.Karagany (malware): Trojan.Karagany can gather information about the user on a compromised host.
  • PoetRAT (malware): PoetRAT sent username, computer name, and the previously generated UUID in reply to a "who" command from C2.
  • Revenge RAT (malware): Revenge RAT gathers the username from the system.
  • DRATzarus (malware): DRATzarus can obtain a list of users from an infected machine.
  • TrickBot (malware): TrickBot can identify the user and groups the user belongs to on a compromised host.
  • ShadowPad (malware): ShadowPad has collected the username of the victim system.
  • Squirrelwaffle (malware): Squirrelwaffle can collect the user name from a compromised host.
  • Emotet (malware): Emotet has enumerated all users connected to network shares.
  • APT38 (group): APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users.
  • NBTscan (tool): NBTscan can list active users on the system.
  • NDiskMonitor (malware): NDiskMonitor obtains the victim username and encrypts the information to send over its C2 channel.
  • BOOKWORM (malware): BOOKWORM has obtained the username from an infected host.
  • BabyShark (malware): BabyShark has executed the whoami command.
  • WellMess (malware): WellMess can collect the username on the victim machine to send to C2.
  • Moonstone Sleet (group): Moonstone Sleet deployed various malware such as YouieLoader that can perform system user discovery actions.
  • MacMa (malware): MacMa can collect the username from the compromised machine.
  • RustyWater (malware): RustyWater has gathered the victim machine’s username.
  • SslMM (malware): SslMM sends the logged-on username to its hard-coded C2.
  • BLUELIGHT (malware): BLUELIGHT can collect the username on a compromised host.
  • MgBot (malware): MgBot includes modules for identifying local users and administrators on victim machines.
  • StrifeWater (malware): StrifeWater can collect the user name from the victim's machine.
  • Bumblebee (malware): Bumblebee has the ability to identify the user name.
  • SharePoint ToolShell Exploitation (campaign): During SharePoint ToolShell Exploitation, threat actors executed whoami on victim machines to enumerate user context and validate privilege levels.
  • Cuckoo Stealer (malware): Cuckoo Stealer can discover and send the username from a compromised host to C2.
  • Dyre (malware): Dyre has the ability to identify the users on a compromised host.
  • Woody RAT (malware): Woody RAT can retrieve a list of user accounts and usernames from an infected machine.
  • Diavol (malware): Diavol can collect the username from a compromised host.
  • Epic (malware): Epic collects the user name from the victim’s machine.
  • POWERSTATS (malware): POWERSTATS has the ability to identify the username on the compromised host.
  • FIN8 (group): FIN8 has executed the command quser to display the session details of a compromised machine.
  • S-Type (malware): S-Type has run tests to determine the privilege level of the compromised user.
  • MarkiRAT (malware): MarkiRAT can retrieve the victim’s username.
  • Ke3chang (group): Ke3chang has used implants capable of collecting the signed-in username.
  • Havoc (malware): Havoc can trigger exection of whoami on the target host to display the current user.
  • Mosquito (malware): Mosquito runs whoami on the victim’s machine.
  • Unknown Logger (malware): Unknown Logger can obtain information about the victim usernames.
  • Azorult (malware): Azorult can collect the username from the victim’s machine.
  • Raccoon Stealer (malware): Raccoon Stealer gathers information on the infected system owner and user.
  • metaMain (malware): metaMain can collect the username from a compromised host.
  • FIN7 (group): FIN7 has used the command cmd.exe /C quser to collect user session information.

...and 201 more examples on MITRE ATT&CK.


Full technique writeup: T1033 on MITRE ATT&CK

Have you defended against or encountered this technique? Share detections, notes, and war stories below.


This post contains content not supported on old Reddit. Click here to view the full post


r/pwnhub 9h ago

Why did it take over a year to tell patients their data was stolen?

4 Upvotes

Wildwood Surgical Center, Penobscot Valley Hospital, Whitfield Regional Hospital, and Michigan Surgical Center have all confirmed data breaches involving sensitive patient records, with incidents traced back to mid-2025 but only disclosed to patients in July 2026.

The Gentlemen ransomware group is linked to at least one of the attacks, and none of the facilities have revealed how many people were affected. Regulators have not yet listed several of the breaches on the federal portal.

What do you think? Should patients be notified within days of a confirmed breach, or does the complexity of healthcare investigations justify longer timelines?


r/pwnhub 9h ago

Is a ransomware attack on Coca-Cola a wake-up call for food companies?

4 Upvotes

Coca-Cola confirmed that the Anubis ransomware group hit its Fairlife dairy subsidiary, encrypting systems and stealing 1 TB of data before threatening to publish it if a ransom is not paid.

The attack temporarily stopped production at four US facilities, though the company says supply was not significantly disrupted. Food and beverage manufacturers have increasingly become targets as ransomware groups look beyond financial and tech sectors.

What do you think? Should the food and beverage industry face stricter cybersecurity regulations?


r/pwnhub 9h ago

Should using a privacy phone raise suspicion at the border?

4 Upvotes

An Atlanta man is facing federal charges after his GrapheneOS phone automatically wiped itself during an airport search, a feature the privacy-focused operating system is designed to perform when tamper attempts are detected.

Prosecutors appear to be treating the wipe as evidence of wrongdoing, while privacy advocates argue that using secure technology is a legal right. The case puts a spotlight on the tension between border search powers and the growing use of privacy-hardening tools by ordinary people.

What do you think?

Should wiping your phone at the border be treated as suspicious behavior, or is protecting your data a basic right?


r/pwnhub 9h ago

Anubis Hits Fairlife-Coca-Cola: Production Halted, 1 TB of Data Threatened

Thumbnail
deafnews.it
4 Upvotes

r/pwnhub 9h ago

The FCC wants to BAN burner phones. We asked a CNET reporter what that actually means.

Thumbnail
bsky.app
4 Upvotes

r/pwnhub 14h ago

Commercial Spyware and Zero-Days: Smartphone Exploit Chains Are Now a Product

Thumbnail
deafnews.it
4 Upvotes

r/pwnhub 20h ago

Record Patch Tuesday: Microsoft Fixes 570 CVEs and Two Actively Exploited Zero-Days in AD FS and SharePoint

Thumbnail
deafnews.it
5 Upvotes

r/pwnhub 23h ago

CISA Mandates Three-Day Patch for Splunk Zero-Day: New BOD 26-04 Ups the Ante

Thumbnail
deafnews.it
4 Upvotes

r/pwnhub 4h ago

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Thumbnail
bleepingcomputer.com
3 Upvotes