?A security incident involving Coder resulted in attackers compromising the infrastructure supporting its module registry and distributing malicious Terraform modules to a subset of users. The attackers reportedly gained access to Coder's Cloudflare infrastructure and added unauthorized servers to the registry pool, causing some requests to be redirected to attacker-controlled systems. The malicious artifacts were distributed between 07:35 UTC and 21:45 UTC on August 31, 2026. The modified Terraform modules contained information-stealing functionality designed to collect sensitive data from affected systems. Targeted information included cloud and AI API keys, CI/CD credentials, environment variables, SSH keys, OIDC tokens, configuration secrets, terminal history, database passwords, and other authentication tokens. The stolen information was exfiltrated to the attacker-controlled domain coder-infra[.]com. Although Coder stated that it found no evidence of an impact on customer data maintained by the company, it cannot conclusively identify every potentially affected deployment because the malicious infrastructure was outside its control. Organizations using Coder should review firewall, proxy, DNS, and VPC flow logs for connections to the identified malicious domain and investigate provisioner logs for suspicious activity. Potentially affected Terraform modules and cached packages should be identified and removed. Users should upgrade to the patched Coder releases and immediately rotate any potentially exposed credentials, API keys, SSH keys, tokens, and other secrets. Security teams should also conduct a thorough investigation of affected systems to identify unauthorized access or potential follow-on activity.
A recently released proof-of-concept called FalconFlank claims to expose a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor for Windows. Published on GitHu...
TP-Link has released security updates for two vulnerabilities affecting the Archer AX55 V4 wireless router: CVE-2026-18167 and CVE-2026-18330. Published on September 3, 2026, the a...
A malicious campaign is abusing rogue ConnectWise ScreenConnect clients to spread malware across Windows systems connected to compromised remote-access environments. According to H...