<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Cloudflare Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Cloudflare.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel</title><link>https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel</link><guid isPermaLink="false">cst-3081</guid><description>Cisco Talos discovered msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that establishes command-and-control communications exclusively through Chrome DevTools Protocol rather than direct network connections. The malware is delivered via a malicious MSI installer disguised as a Windows update and leverages the browser, Cloudflare Workers, and Twilio TURN relays to create a covert WebRTC DataChannel for C2 communications. Chaos is a ransomware-as-a-service group active since February 2025 that uses phishing, vishing, and legitimate tools for post-compromise activities before deploying encryption.</description><pubDate>Thu, 23 Jul 2026 10:00:38 GMT</pubDate></item><item><title>wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core</title><link>https://tenable.com/blog/wp2shell-cve-2026-63030-cve-2026-60137-frequently-asked-questions-about-remote-code-execution</link><guid isPermaLink="false">cst-2848</guid><description>Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve unauthenticated remote code execution on WordPress 6.9.x and 7.0.x installations. Active exploitation began within days of the July 17, 2026 disclosure, with public proof-of-concept code circulating and multiple security firms confirming attacks in the wild. Patches are available in WordPress 7.0.2 and 6.9.5, with WordPress.org enabling forced automatic updates for affected installations.</description><pubDate>Mon, 20 Jul 2026 13:36:32 GMT</pubDate></item><item><title>New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code</title><link>https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html</link><guid isPermaLink="false">cst-2783</guid><description>A critical vulnerability in WordPress core versions 6.9 and 7.0 allowed unauthenticated attackers to execute arbitrary code on unpatched installations. WordPress released patches (6.9.5 and 7.0.2) on Friday and deployed forced updates through its auto-update mechanism. Adam Kues at Assetnote discovered the flaw and coordinated its disclosure.</description><pubDate>Fri, 17 Jul 2026 21:20:10 GMT</pubDate></item><item><title>New infosec products of the week: July 17, 2026</title><link>https://helpnetsecurity.com/2026/07/17/new-infosec-products-of-the-week-july-17-2026</link><guid isPermaLink="false">cst-2734</guid><description>A weekly roundup highlighting new security product releases from vendors including Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI. Polygraf AI's Meeting Guard is featured as a real-time deepfake detection solution for enterprise meetings that joins sessions as a participant to provide security analysis to attendees.</description><pubDate>Fri, 17 Jul 2026 04:00:15 GMT</pubDate></item><item><title>Cloudflare Precursor uses continuous behavioral analysis to stop advanced bots</title><link>https://helpnetsecurity.com/2026/07/13/cloudflare-precursor</link><guid isPermaLink="false">cst-2422</guid><description>Cloudflare announced general availability of Precursor, a bot management tool that uses continuous behavioral analysis running in web browsers to detect sophisticated bot automation in real time. The system monitors entire user sessions rather than relying on static CAPTCHAs, aiming to catch advanced bots while minimizing disruption to legitimate users.</description><pubDate>Mon, 13 Jul 2026 13:28:04 GMT</pubDate></item><item><title>ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit</title><link>https://bleepingcomputer.com/news/security/artoken-phaas-exposes-eviltokens-microsoft-365-phishing-toolkit</link><guid isPermaLink="false">cst-6</guid><description>Researchers discovered ARToken, a phishing-as-a-service (PhaaS) platform operating as an affiliate of the EvilTokens phishing platform, which provides an extensive toolkit for targeting Microsoft 365 accounts. The discovery reveals the organized infrastructure and business model behind credential theft attacks against enterprise email systems.</description><pubDate>Fri, 03 Jul 2026 14:12:22 GMT</pubDate></item><item><title>Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access</title><link>https://microsoft.com/en-us/security/blog/2026/06/25/photo-zip-campaign-targeting-hospitality-industry-delivers-node-js-implant-persistent-access</link><guid isPermaLink="false">cst-329</guid><description>Microsoft Threat Intelligence has identified an active campaign targeting hospitality industry organizations in Europe and Asia since April 2026, delivering a Node.js-based implant through photo-themed ZIP archives containing fake image shortcuts. The attack chain uses obfuscated PowerShell, dual registry persistence, and command-and-control communications over non-standard ports, with phishing emails leveraging legitimate services like Calendly and Google to bypass email authentication. The campaign has evolved through two waves with increasing sophistication, including new obfuscation techniques and expanded infrastructure, though the ultimate objective remains unclear.</description><pubDate>Thu, 25 Jun 2026 22:30:29 GMT</pubDate></item><item><title>White House drastically shortens deadline for dropping quantum-vulnerable crypto</title><link>https://arstechnica.com/information-technology/2026/06/executive-order-bumps-up-deadline-to-move-off-quantum-vulnerable-crypto</link><guid isPermaLink="false">cst-427</guid><description>The White House has shortened the deadline for government agencies and critical infrastructure operators to migrate from quantum-vulnerable encryption to post-quantum cryptographic systems, requiring key establishment schemes by the end of 2030 and digital signature schemes by the end of 2031. This accelerated timeline, roughly five years earlier than previous expectations, follows research indicating that building a cryptographically relevant quantum computer requires fewer resources and lower costs than previously estimated. Major technology companies including Google and Cloudflare have similarly advanced their own migration deadlines to 2029.</description><pubDate>Tue, 23 Jun 2026 22:30:57 GMT</pubDate></item><item><title>'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows</title><link>https://darkreading.com/application-security/cordyceps-malicious-pull-requests-developer-workflows</link><guid isPermaLink="false">cst-117</guid><description>A campaign dubbed 'Cordyceps' exploits CI/CD pipeline weaknesses to inject malicious pull requests into high-profile open source projects including Azure Sentinel, Google's AI Agent Development Kit, Apache Doris, Cloudflare Workers SDK, and Python's Black formatter. The attacks leverage automated workflows to introduce compromised code into widely-used developer tools and libraries. This represents a supply chain threat targeting projects with significant downstream dependents.</description><pubDate>Tue, 23 Jun 2026 19:16:42 GMT</pubDate></item><item><title>VerdantBamboo: Just Another BRICKSTORM in the Firewall</title><link>https://volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall</link><guid isPermaLink="false">cst-2103</guid><description>Volexity discovered that a Chinese threat actor tracked as VerdantBamboo had compromised an Egnyte Storage Sync appliance using the BRICKSTORM malware, with the initial compromise dating back at least 18 months. The actor used the compromised appliance to access the victim's Microsoft 365 environment while evading security controls, and later regained access via stolen firewall credentials to deploy additional malware. Investigation revealed the victim organization had been compromised through a breach of their managed services provider, whose pfSense firewall had also been infected with BRICKSTORM for at least 18 months.</description><pubDate>Thu, 04 Jun 2026 20:23:55 GMT</pubDate></item><item><title>Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace</title><link>https://elastic.co/security-labs/tycoon-2fa-aitm-detection-engineering</link><guid isPermaLink="false">cst-616</guid><description>Tycoon 2FA is a prolific phishing-as-a-service platform that performs adversary-in-the-middle attacks to bypass multi-factor authentication and steal authenticated session tokens from Microsoft 365 and Google Workspace. The kit operates as a reverse proxy that captures real-time authentication flows, including MFA challenges, and intercepts post-MFA session tokens before they reach the victim's browser. Despite a March 2026 takedown that seized over 300 domains, operators have adapted and continue deploying variants that use WebSocket-based proxying and OAuth device code abuse, employing sophisticated evasion techniques to avoid researcher detection.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>Detecting Web Server Probing &amp; Fuzzing in Traefik with Automated Cloudflare Response</title><link>https://elastic.co/security-labs/detecting-web-server-probing-and-fuzzing</link><guid isPermaLink="false">cst-620</guid><description>A security practitioner describes using Traefik reverse proxy logs ingested into Elastic Security to detect web server probing and fuzzing activity through statistical analysis of HTTP 404 response codes. When suspicious patterns are identified, an automated workflow blocks the offending source IP addresses at the Cloudflare edge using the Cloudflare API, providing perimeter defense without requiring local tools like Fail2Ban.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate></item><item><title>TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook</title><link>https://elastic.co/security-labs/tclbanker-brazilian-banking-trojan</link><guid isPermaLink="false">cst-621</guid><description>Elastic Security Labs identified TCLBANKER, a Brazilian banking trojan that represents a significant evolution of the MAVERICK/SORVEPOTEL malware family. The malware uses a loader with extensive anti-analysis capabilities to deploy a banking trojan targeting 59 Brazilian financial institutions and a worm module that spreads via compromised WhatsApp and Outlook accounts. The infrastructure is hosted on Cloudflare Workers and shows signs of early-stage operations with debug artifacts and incomplete phishing pages.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>LABScon25 Replay | Are Your Chinese Cameras Spying For You Or On You?</title><link>https://sentinelone.com/labs/labscon25-replay-are-your-chinese-cameras-spying-for-you-or-on-you</link><guid isPermaLink="false">cst-609</guid><description>Researchers Marc Rogers and Silas Cutler analyzed ultra-cheap Chinese smart home cameras and video doorbells sold globally under rotating brand names, revealing they share identical hardware platforms, contain hardcoded root passwords, and route user data through servers in China and Hong Kong despite claims of local processing. The devices are distributed through shell companies designed to evade regulatory oversight, with minimal security updates and rapid hardware iterations resembling malware distribution patterns. The investigation demonstrates a widespread, vulnerable Internet of Things (IoT) surface accessible to remote configuration from overseas actors.</description><pubDate>Wed, 22 Apr 2026 22:00:15 GMT</pubDate></item><item><title>Securing the AI Edge: Wiz and Cloudflare Integrate for End-to-End AI Protection</title><link>https://wiz.io/blog/wiz-cloudflare-ai-security-integration</link><guid isPermaLink="false">cst-1313</guid><description>Wiz and Cloudflare have integrated their security platforms to provide unified visibility and protection for AI application endpoints and DNS exposure. The integration allows organizations to see which endpoints are protected by Cloudflare and identify gaps that require additional security measures.</description><pubDate>Tue, 14 Apr 2026 13:00:02 GMT</pubDate></item><item><title>Cybersecurity industry overreacts to React vulnerability, starts panic, burns own house down again</title><link>https://doublepulsar.com/cybersecurity-industry-overreacts-to-react-vulnerability-starts-panic-burns-own-house-down-again-e85c10ad1607?source=rss----8343faddf0ec---4</link><guid isPermaLink="false">cst-588</guid><description>CVE-2025-55182 affects React v19 with React Server Components enabled, a relatively new and niche configuration used by a minority of organizations. The security industry has generated widespread panic and false proofs of concept, with some vendors like Cloudflare implementing hasty patches that caused significant outages, despite the vulnerability having a narrow attack surface and straightforward mitigation path.</description><pubDate>Fri, 05 Dec 2025 11:21:36 GMT</pubDate></item><item><title>Akira Ransomware Indicators | Huntress</title><link>https://huntress.com/blog/akira-ransomware-indicators</link><guid isPermaLink="false">cst-940</guid><description>Huntress analysts have identified multiple indicators associated with Akira ransomware attacks, including threat actor workstation names, passwords used during account creation or modification, and CloudFlare tunnel tokens. Early detection of these artifacts in the attack chain enables organizations to prevent or block file encryption deployment.</description><pubDate>Fri, 20 Sep 2024 00:00:00 GMT</pubDate></item></channel></rss>