Daily Drop (1255)
03-03-26
Tuesday, Mar 03, 2025 // (IG): BB // GITHUB // SN R&D
Hacked Prayer App Weaponized in Cyber Operations Amid U.S.–Israel Strikes on Iran
Bottom Line Up Front (BLUF): The BadeSaba Calendar app—an Iranian prayer app with 5+ million downloads—was compromised to deliver coordinated anti-government push notifications during active U.S. and Israeli strikes on Iran. The operation appears pre-staged and timed, leveraging backend access to the app’s push notification infrastructure to conduct psychological operations at scale. No malware deployment was reported; the impact centered on information warfare and disruption.
Analyst Comments: Compromising a push notification backend—rather than distributing a trojanized update—suggests credential theft, API key compromise, or supply chain access weeks before detonation. The payload triggered at 9:52 AM Tehran time, synchronized with kinetic military action. That timing alone signals planning discipline consistent with nation-state tradecraft. The messaging—“Help Has Arrived” and calls for military defection—targets morale, not endpoints. This is psychological operations delivered through trusted digital channels. No ransomware note. No wiper. Just narrative injection at scale.
READ THE STORY: Cyber Press
Hackerbot-Claw Bot Exploits GitHub Actions CI/CD Flaw to Target Microsoft and DataDog
Bottom Line Up Front (BLUF): A threat actor dubbed “Hackerbot-Claw Bot” is exploiting weaknesses in GitHub Actions CI/CD workflows to compromise repositories and target high-profile organizations, including Microsoft and DataDog. The campaign abuses misconfigured or exposed CI pipelines to inject malicious code, harvest secrets, and potentially pivot into downstream environments. The activity underscores persistent supply chain risk within DevOps ecosystems.
Analyst Comments: When attackers compromise a pipeline, they don’t just access source code—they gain execution inside a trusted automation environment. That means access to secrets, signing keys, cloud credentials, deployment tokens, and sometimes production infrastructure. The reported activity suggests exploitation of misconfigured GitHub Actions workflows, potentially involving exposed tokens, unsafe pull request triggers, or insufficient validation of external contributions. If workflows execute untrusted code without proper isolation, an attacker can inject commands that extract repository secrets or modify build artifacts.
READ THE STORY: GBhackers
Android Security Update Fixes 129 Vulnerabilities, Including Actively Exploited Zero-Day
Bottom Line Up Front (BLUF): Google’s March 2026 Android security update patches 129 vulnerabilities, including at least one actively exploited zero-day. The fixes span the Android framework, system components, and multiple third-party chipsets, reinforcing ongoing concerns around mobile exploit chains targeting privilege escalation and remote code execution. Organizations managing Android fleets should prioritize rapid patch deployment, particularly for high-risk users.
Analyst Comments: Triple-digit patch counts are becoming routine for Android, but the presence of an actively exploited zero-day changes the urgency. Historically, Android exploitation chains rely on chaining together multiple bugs—often beginning with a browser or messaging vector, followed by privilege escalation in the kernel or a vendor component. When Google flags “exploited in the wild,” it typically indicates targeted attacks rather than broad commodity exploitation, though that distinction narrows quickly once technical details circulate. The fragmentation problem persists. Pixel devices receive patches immediately, but OEM rollout timelines vary widely. That lag creates a predictable window for threat actors to scale exploitation before patches reach the broader ecosystem.
READ THE STORY: Cyber Press
CVE-2026-2256: MS-Agent Command Injection Flaw Enables Remote Hijacking of AI Agents
Bottom Line Up Front (BLUF): A critical command injection vulnerability (CVE-2026-2256) in the ModelScope MS-Agent framework allows remote attackers to hijack autonomous AI agents and execute arbitrary system commands. The flaw stems from an insufficient denylist-based validation mechanism in the framework’s Shell tool, enabling prompt injection attacks that can lead to full system compromise. No vendor patch has been issued as of publication.
Analyst Comments: This is the AI-agent security problem in a nutshell: giving autonomous systems shell access and protecting it with a denylist. MS-Agent includes a built-in Shell tool that allows agents to execute operating system commands to complete tasks. That’s powerful—and dangerous. The framework attempts to filter unsafe commands using a check_safe() function backed by a denylist. Researchers found that approach trivial to bypass using prompt injection techniques.
READ THE STORY: GBhackers
Malvertising Campaign Spreads AMOS ‘malext’ macOS Infostealer via Fake Text-Sharing Ads
Bottom Line Up Front (BLUF): A large-scale malvertising campaign is targeting macOS users with fake Google Ads that redirect to spoofed Medium, Evernote, and text-sharing sites. Victims are tricked into executing malicious Terminal commands that deploy a variant of the AMOS infostealer known as “malext.” The malware steals browser credentials, crypto wallets, Apple Notes data, and keychain content, establishes persistence via LaunchDaemons, and enables full remote control. The operation is active and rapidly rotating ad accounts to evade takedowns.
Analyst Comments: This operation succeeds not through zero-days, but through user trust and search engine placement. Victims searching for macOS troubleshooting guidance are presented with malicious ads that appear legitimate. Instead of exploiting the browser or the OS directly, attackers persuade users to copy and paste obfuscated shell commands into Terminal. That single step bypasses many traditional security controls because the execution is user-initiated.
READ THE STORY: GBhackers
Microsoft Warns OAuth Redirect Abuse Delivers Malware to Government Targets
Bottom Line Up Front (BLUF): Microsoft is tracking phishing campaigns targeting government and public-sector entities that abuse legitimate OAuth redirect functionality to deliver malware and, in some cases, adversary-in-the-middle (AitM) credential harvesting. Rather than exploiting software flaws or stealing tokens directly, attackers weaponize by-design OAuth behavior—crafting malicious apps and manipulated redirect parameters to bounce victims from trusted identity providers (e.g., Entra ID, Google Workspace) to attacker-controlled infrastructure.
Analyst Comments: The attackers aren’t breaking OAuth—they’re using it exactly as designed. By registering malicious applications in their own tenant and configuring rogue redirect URIs, they generate authentication URLs that look legitimate. Victims see a trusted identity provider domain, which is enough to bypass a lot of email and browser skepticism. The key pivot: intentionally invalid scopes. That forces a redirect flow which lands users on attacker infrastructure. From there, payload delivery begins—often as ZIP archives containing LNK files that kick off PowerShell, sideload malicious DLLs, and stage follow-on activity. In other cases, the redirect leads to EvilProxy-style AitM frameworks to intercept credentials and session cookies.
READ THE STORY: THN
RESURGE Malware Targets Ivanti Connect Secure Vulnerabilities
Bottom Line Up Front (BLUF): Threat actors are exploiting vulnerabilities in Ivanti Connect Secure appliances to deploy a malware strain dubbed RESURGE, enabling persistent access, credential theft, and potential lateral movement inside enterprise networks. The activity follows a familiar pattern: edge appliance exploitation, web shell or implant deployment, then hands-on-keyboard post-exploitation. Organizations running unpatched Ivanti instances should assume active scanning and possible compromise.
Analyst Comments: RESURGE appears to function as a post-exploitation implant rather than an initial access vector. That distinction matters. The vulnerability gets them in; RESURGE keeps them there. Edge appliance malware is especially dangerous because defenders often lack deep telemetry at that layer. Traditional EDR doesn’t cover hardened network devices. Logging is limited. And once attackers land, they’re already inside your trusted boundary. If Ivanti has issued patches and you haven’t applied them, you’re effectively betting no one has scanned you yet. That’s not a winning strategy.
READ THE STORY: Cyber Press
Phishing Campaign Abuses .arpa TLD and IPv6 Tunnels to Evade Detection
Bottom Line Up Front (BLUF): Researchers at Infoblox have identified a sophisticated phishing campaign that weaponizes the reserved .arpa top-level domain and free IPv6 tunnel services to bypass domain reputation controls. By creating rogue DNS records inside infrastructure-reserved namespaces and combining them with dangling CNAME hijacking, attackers are evading traditional URL filtering and blacklisting mechanisms while distributing phishing payloads through a traffic distribution system (TDS).
Analyst Comments: According to Infoblox Threat Intelligence, attackers leveraged free IPv6 tunnel services to gain control over IPv6 address ranges. Rather than configuring legitimate reverse DNS (PTR) entries within the .arpa namespace, they created standard A records under .arpa subdomains—effectively turning infrastructure-designated space into phishing infrastructure. The phishing chain begins with brand-impersonation spam emails containing a hyperlinked image, often themed around free gifts or subscription issues. When clicked, victims are routed through a traffic distribution system (TDS) that fingerprints the user and selectively delivers malicious content.
READ THE STORY: Anquanke
Items of interest
Thousands of Public Google Cloud API Keys Gained Unintended Gemini Access
Bottom Line Up Front (BLUF): Researchers identified nearly 3,000 publicly exposed Google Cloud API keys that gained unintended access to Gemini (Generative Language API) endpoints once the API was enabled in their respective projects. Because API keys defaulted to “unrestricted,” keys originally embedded in client-side code for benign services could be abused to access AI endpoints, retrieve stored data, and generate significant billing charges.
Analyst Comments: The keys themselves weren’t new. The exposure wasn’t new. What changed was the permission model after Gemini was enabled. Suddenly, what developers believed were low-risk billing identifiers became live AI credentials. That shift matters. AI APIs introduce higher cost ceilings, new data access paths (/files, /cachedContents), and potential integration with broader cloud resources. An exposed key is no longer just a quota theft risk—it’s a potential data exposure vector. The most concerning detail: keys created in Google Cloud defaulted to “Unrestricted,” meaning they inherit access to every enabled API in the project. When Gemini was turned on, previously deployed keys—some embedded in public JavaScript—quietly gained expanded capability without explicit warning.
READ THE STORY: THN
Thousands of Google API keys exposed (Video)
FROM THE MEDIA: 3,000 publicly exposed Google Cloud API keys that gained unintended access to Gemini (Generative Language API) endpoints once the API was enabled in their respective projects.
Accidentally Leaked My Google/Stripe API Keys Online! Exposed on GitHub .env/secrets (Video)
FROM THE MEDIA: This is the security tutorial every developer needs. Have you ever accidentally committed your sensitive API keys, database passwords, or a critical .env file to a public GitHub repository? The moment that happens, bad people can take your secrets, leading to potential account compromises and huge cloud bills. Google publicy accesible API Key.
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don't hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


