CISA Advisories

7.5M Utility Customers Exposed 🔍 & One Click That Owns Your PC 🖱️

Two stories from today's security headlines land squarely on regular people: a Texas utility leaked millions of customer records through a door it left wide open, and a keyboard app used by hundreds of millions could be hijacked with a single click. Here's what happened and why it matters.

A Texas Utility Left the Back Door Unlocked — 7.49 Million Records Walked Out

CenterPoint Energy has confirmed that an attacker siphoned customer data out of one of its public-facing APIs — essentially a web address that other software talks to — on September 12. The hacker claims to have taken 7.49 million records containing names, phone numbers, billing addresses, account numbers, payment status, and partial Social Security numbers.

The uncomfortable part isn't the sophistication; it's the absence of basics. According to the attacker, that API had no rate limiting, no authentication tokens, and no web application firewall in front of it. They say they only stopped because someone finally added a CAPTCHA. If you're a CenterPoint customer, assume your details are in circulation and watch for targeted phishing calls and texts that reference your real account information — that's what makes this kind of leak dangerous long after the news cycle ends. If you run a business, the lesson is blunt: the API you forgot to inventory is the one that will be counted in millions of records.

Read more

One Click, Total Control: A Keyboard App Becomes a Nation-State Backdoor

A China-linked group tracked as UNC3569 found they could take full control of a Windows machine using nothing but a crafted link. The weak spot was Sogou Input Method, Tencent's Chinese-language keyboard app installed on hundreds of millions of Windows PCs. Clicking the link was enough to run code at the system level and quietly install a backdoor researchers named GrayRabbit.

How? The app shipped with its own bundled web browser engine that was roughly six years out of date, ran with no sandbox, and had its cross-site protections switched off. Chain that with a flaw in how the app handled links, and one click becomes total ownership. Tencent has patched the link-handling bug, but as of September 10 the ancient browser engine underneath it was still there.

The bigger takeaway applies to every organization: the risk isn't only in your operating system or your browser. It hides inside everyday helper apps — keyboards, printer utilities, mouse configurators — that quietly bundle their own outdated components and run with high privileges. You can't patch what you don't know is installed.

Read more

Stay ahead of threats with GOCO Security at gocosecurity.com.

Comments

Popular Posts