Archive of

third-party.com placeholder domain now serves ClickFix

The domain third-party.com, a common stand-in for external websites in developer documentation and code samples, is now hosting a fake Cloudflare verification page. The page tries to trick Windows users into running malicious PowerShell commands.

Manifold Security spotted the page while reviewing public AI skills and MCP (Model Context Protocol) server documentation that referenced the domain. BleepingComputer later confirmed the findings.

Developers have long used third-party.com the way they use example.com, to represent some arbitrary outside site, API or service. There is one important difference. IANA, the body that manages key internet naming resources, reserves example.com, example.net and example.org for documentation, and they cannot be registered or transferred. third-party.com has no such protection. It is an ordinary registered domain, and whoever owns it decides what it serves.

Read More


MacSync malware hides payloads in public iCloud calendars

A newly spotted variant of the MacSync infostealer is using public iCloud calendar events to deliver its next-stage payloads to macOS systems, according to Kaspersky researchers.

MacSync is written in Swift and first appeared in April 2025. It has recently been pushed through ClickFix campaigns, in which victims are tricked into running commands themselves. Those lures posed as Homebrew and as macOS tools for analysing disk space. Kaspersky says earlier versions of MacSync were derived from the AMOS stealer family. Since then, the malware has grown through additional modules.

A fake crypto wallet as bait

The operators rely on social engineering. Besides ClickFix-style attacks, they offer MacSync disguised as free or cracked software, or as brand-new applications.

Read More


SalesBleed flaws let attackers hijack Salesforce Agentforce

Researchers at Zenity Labs have disclosed three vulnerabilities in Salesforce Agentforce, the company's platform for AI agents. Attackers could have abused the flaws to turn trusted agents against their own organizations. The agents could be made to leak sensitive customer relationship management (CRM) data or to send phishing messages to employees.

The researchers call the set of bugs SalesBleed. According to Zenity Labs, two of the flaws allowed zero-click data exfiltration. The third let an attacker weaponize an Agentforce agent to spread phishing inside a company.

Zenity Labs reported the issues to Salesforce on June 1. Salesforce confirmed that all three had been fixed by August 19.

Read More


Kyiv internet outages follow Russian strikes on data centers

Russian drone attacks on Kyiv this week hit data centers and telecom facilities, cutting or degrading internet access for thousands of people in the Ukrainian capital and the surrounding region.

Internet monitoring group NetBlocks reported partial connectivity losses at no fewer than four providers after Wednesday's strike. The affected networks were Kyiv Link, Pautina, Utels and Crazy Network, which serve Kyiv as well as other parts of Ukraine.

According to Ukraine's Ministry of Digital Transformation, roughly 100,000 households in Kyiv and the wider region had internet problems after the attack. Repair crews were sent out to assess the damage and bring stable connections back online.

Read More


Oxygen Forensics execs charged over hidden Russian ties

The US Department of Justice (DOJ) has arrested two senior figures at Oxygen Forensics, a digital forensics and data extraction company whose software was bought by several federal agencies. Prosecutors allege the firm hid that Russian nationals controlled it and that its technology was developed in Russia.

Oxygen sells tools that investigators use to extract and analyze data from mobile devices, cloud services and drones. It competes directly with Cellebrite. Police and intelligence agencies commonly use this kind of software to break into phones. The company reportedly holds close to 10,000 contracts across more than 150 countries.

Its customers included the Department of Defense (DOD) and the Department of Homeland Security (DHS). Within DHS, several branches used Oxygen products:

Read More