HeadFlash

Security

Active Exploits, Fentanyl Hacks, and a FIFA Data Leak

CISA warns of SharePoint attacks; Canada strikes fentanyl brokers; FIFA platform exposed; NetNut botnet disrupted; Opera blocks clipboard hijacking.

Listen

CISA Adds Actively Exploited SharePoint RCE Flaw to KEV Catalog

CISA has warned that attackers are actively exploiting CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint. The flaw, a deserialization of untrusted data weakness, allows low-privilege authenticated attackers with at least Site Member permissions to execute arbitrary code on unpatched servers with no user interaction required. Microsoft released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition on May 21 to address the issue, noting the vulnerability was accidentally omitted from the May 2026 Security Updates. The Shadowserver Foundation tracks over 10,000 SharePoint servers exposed online, though it is unclear how many are patched. CISA added the flaw to its Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to secure their servers by Saturday under Binding Operational Directive 26-04, which prioritizes patching based on KEV status, automation potential, public exposure, and control risk.

CISA: Microsoft SharePoint RCE flaw now actively exploited →

Canada’s CSE Conducts Cyberattack to Disrupt Fentanyl Precursor Brokers

The Communications Security Establishment (CSE), Canada’s electronic spy agency, carried out a cyberoperation to disrupt online foreign criminals brokering precursor chemicals for fentanyl, according to its latest annual report released Monday. The CSE collected foreign intelligence and executed an active cyberoperation that, as the agency states, ‘disrupted and diminished their ability to operate,’ also supporting law enforcement efforts. Active cyberoperations require authorization from the Minister of National Defence and the consent of the Minister of Foreign Affairs; the report notes three such authorizations in 2025–26, the same as the prior year. The report does not identify the brokers, their country, or specific techniques used. Stephanie Carvin, a national-security expert at Carleton University, suggested the attack could have targeted digital assets like cryptocurrency wallets or communications. This is the first time the CSE has publicly described a completed offensive cyberoperation against the fentanyl supply chain, amid pressure from the Trump administration to crack down on fentanyl production.

Canada’s electronic spy agency conducted cyberattacks on criminals brokering fentanyl ingredients, report says - The Globe and Mail →

FIFA’s Agent Platform Exposed Full World Cup 2026 Streaming and Data to Any Registered User

A security researcher discovered that registering on FIFA’s Agent Platform (agents.fifa.org) with only an ID photo and email verification automatically added accounts to FIFA’s Microsoft Entra tenant, which also powers all internal FIFA platforms. Although the Angular frontend for the Football Data Platform displayed an ‘access denied’ page for accounts with a NO_ROLES role, the backend APIs served all data without server-side role enforcement. This gave full access to the Streaming Management panel for every FIFA World Cup 2026 match, including RTMP ingest URLs, preview manifest URLs serving live video, and output HLS manifest URLs for five camera angles per match. An attacker could push video to an RTMP ingest endpoint, replacing the camera feed and potentially displaying their own video on every TV network receiving the FIFA feed. The NO_ROLES account also accessed the entire fdp.fifa.org platform, including live match dashboards, competition data, the Commentator Information System, and an Azure Function App exposing 23 internal FIFA files with no role checks. The vulnerability was discovered while the World Cup was underway. FIFA had no bug bounty program or published security contact; the researcher attempted multiple email addresses, phone calls, and WhatsApp messages, eventually reaching CISA and FBI contacts who helped. The vulnerability was patched overnight, with the NO_ROLES account returning 403 errors, but FIFA never acknowledged the report. The root cause was client-side authorization with no server-side enforcement across at least three FIFA applications.

I Could’ve Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. | bobdahacker →

Google Disrupts Botnet ‘Popa’ Used by Israeli Proxy Provider NetNut on Millions of TV Streaming Devices

Google has taken action against Israeli residential proxy provider NetNut, alleging it used Android-based TV streaming devices to host internet traffic for hackers. In collaboration with the FBI and Lumen Technologies, Google disrupted a botnet dubbed ‘Popa’ spanning millions of consumer devices. Google’s investigation confirmed NetNut’s network appears to include at least 2 million devices worldwide, with evidence that 316 distinct threat clusters used suspected NetNut proxy exit nodes for activities including account hijacking, password spray attacks, and ad fraud. NetNut allegedly grew the botnet by distributing SDKs preinstalled on smart TVs and streaming boxes, secretly relaying traffic without owner knowledge. Google shut down the accounts and services NetNut relied on to control the botnet, and Android’s Google Play Protect has been disabling apps incorporating NetNut SDKs. Google warns that NetNut may try to rebuild its network, and urges consumers to buy devices from reputable manufacturers and avoid applications offering payment for unused bandwidth. NetNut and parent Alarum Technologies did not respond to requests for comment.

Google: This Proxy Service Is Using TV Streaming Devices to Host Cybercrime →

Opera Browser Launches Paste Protect to Block Clipboard Hijacking Attacks

Opera has introduced Paste Protect, a new security feature designed to block clipboard hijacking attacks, specifically targeting the ‘ClickFix’ technique that uses fake error messages or CAPTCHA tests to trick users into pasting malicious commands. Paste Protect monitors clipboard content in real time and automatically blocks the pasting of malicious code, displaying a red icon and warning in the address bar when triggered. Opera is the first major web browser to implement native clipboard hijacking protection. The feature is currently available only in desktop versions of Opera and is enabled by default. It remains to be seen whether other browsers will follow suit.

Opera now blocks one of the sneakiest malware tricks around →