Cybersecurity News and Vulnerability Aggregator

Cybersecurity news aggregator

Top Cybersecurity Stories Today

The Hacker News 4h ago

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. Read

The Hacker News 6h ago

An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal

The Hacker News 7h ago

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file

Synack 18h ago

Security testing and exposure management have run on separate tracks for years, leaving a blind spot between what a scanner flags and what an attacker can exploit. Synack's new integration with Wiz closes that disconnect, feeding continuously validated pentest findings directly into Wiz's exposure management view. The post Unifying Security Testing and Exposure Management: Introducing the Synack and Wiz Integration appeared first on Synack .

The Hacker News 20h ago

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored

Latest

Thursday, September 24
The Hacker News 1h ago

The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm" Corp MDM

The Hacker News 2h ago

AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI

The Guardian 4h ago

Former deputy PM now involved in tech industry says many within sector are ‘winding themselves up into a lather’ UK politics live – latest updates Nick Clegg has dismissed fears over AI’s “godlike power to exterminate humanity”, calling it a sign that tech bosses are “breathing their own fumes”. The former UK deputy prime minister said that tech bosses should focus on addressing known specific threats such as cybersecurity and bioweapons rather than the “slightly hand-wavy view that this technology is unavoidably going to develop some godlike power which is going to turn on us and exterminate humanity”. Continue reading...

The Hacker News 4h ago

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. Read

r/cybersecurity 4h ago
APT

Hi all, I've got the course for [SANS SEC598: AI and Security Automation for Red, Blue, and Purple Teams](https://www.sans.org/cyber-security-courses/ai-security-automation) coming up in a couple weeks, and I wanted to know if there's anything I should do to prepare for the training and the exam? The only thing I really know is to not bring an Apple Silicon laptop. If anyone with experience can give a heads up in general I'd massively appreciate it, as this is my first SANS course :')

The Hacker News 6h ago

An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal

The Hacker News 6h ago

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –

The Hacker News 7h ago

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file

r/cybersecurity 9h ago

CVE-2026-84741, in The Events Calendar (WordPress, 600,000+ active installs). Wanted to share this here because most CVE hunting content online skips the part that actually matters !!!, the failures... **The bug, in plain terms:** A broken access control issue where non-public venue and organizer data was exposed through the REST API to unauthenticated users CWE-200, CVSS 5.3. Not glamorous !!. Real, and confirmed independently by the vendor, but not an RCE or a headline bug. **What actually got me here, since that's the part worth sharing:** this came after weeks of hunting smaller WordPress plugins first, mostly ones with under 10,000 installs, specifically to avoid competition while I built up the discipline: always live verify before writing anything, always trace a claimed vulnerability all the way to the actual database write or output before believing it, always check the full advisory history before assuming something is undiscovered. 2 submissions before this one got rejected as duplicates. One was a real, independently confirmedd bug, lost purely because another researcher submitted it hours or days earlier. That one stung, but the rejection email itself confirmed my analysis was correct, just not first. I also had a lead on a much bigger plugin that looked like a critical unauthenticated data write, spent real time on it, and it turned out to be a false positive once I traced the actual code path. Writing that up as dead was more valuable long term than getting excited too early would have been. Eventually I applied the same instinct, mismatched permission checks on the sibling of a code path that's already gated, to a much bigger target instead of another small plugin. That's what found this one. Link - [https://www.cve.org/CVERecord?id=CVE-2026-84741](https://www.cve.org/CVERecord?id=CVE-2026-84741)

Wednesday, September 23
watchTowr 14h ago

Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it’s a free-for-all (unless you’re trying to buy RAM). Unfortunately, while we're all finding more vulnerabilities and flexing obfuscated stack traces… (or emoji-ridden HTTP requests that are actually complete slop and not real, and please, for the love of god, no, those slop-ridden payloads appearing in your access_log are not proof of exploitation jesus wept, it’s becoming traumatic) …on many social media networks, some things have remained reassuringly steadfast: the vendors and their struggle to seemingly care about the security of your network. Yes, that’s right - it’s time for more Secure by Design jokes. Welcome back to another watchTowr Labs blog post. We’ve missed you (admit you’ve missed us, please).

r/cybersecurity 15h ago

Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here. All the reports and research below were published between September 14th - September 20th. You can get the below into your inbox every week if you want: [https://www.cybersecstats.com/cybersecstatsnewsletter/](https://www.cybersecstats.com/cybersecstatsnewsletter/)  # Big Picture Reports **Global Cyber Resilience Report (Cohesity)** Getting systems back online is one thing. Being confident they’re clean and safe to use again? Yeah, that’s another. **Key stats:** * 60% of organizations that experienced a material cyberattack encountered moderate or significant recovery delays because they weren't confident restored data and systems were clean and safe to use. * 60% experienced identity or access issues after systems had been restored. * For 70%, the number of affected systems eventually turned out to be larger than the initial assessment. *Read the full report* [*here*](https://www.cybersecstats.com/r/4996c72f?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* **Cyber Readiness Report 2026 (Hiscox)** A look at the impact cyberattacks have beyond the immediate technical response. **Key stats:** * 29% of organizations globally experienced at least one successful cyberattack in the past 12 months, with affected organizations reporting an average of four incidents. * Cyber incidents cost organizations around $52,000 a year on average and cause approximately 32 hours of operational disruption. * 48% identify reputational damage or loss of customer trust as the most significant risk following a cyberattack. *Read the full report* [*here*](https://www.cybersecstats.com/r/fcb6a13c?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* **H1 2026 Cyber Risk Report (ANY.RUN)** Some of the attack techniques and infrastructure saw particularly rapid growth in the first half of the year. **Key stats:** * OAuth device-code phishing increased 483.7% between Q1 and Q2 2026. * Custom fake CAPTCHAs increased 437% over the same period. * Cloud infrastructure abuse increased 90.7% between H2 2025 and H1 2026. *Read the full report* [*here*](https://www.cybersecstats.com/r/2fc8e0bc?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* **Cybersecurity Survey Report (Nationwide)** A look at how consumers and businesses are experiencing and preparing for cyber threats.  **Key stats:** * 60% of small and mid-market business owners say employees use public AI chatbots or writing tools for work, while 36% have written policies governing employee AI use. * 27% have rules covering what company or customer information employees can enter into AI tools. * 31% say their company has been targeted by a generative AI scam or fraud attempt in the past year. *Read the full report* [*here*](https://www.cybersecstats.com/r/c4ad6509?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Security Budgets **2026 Security Budget Benchmark Report (IANS and Artico Search)** Where cybersecurity budgets are heading in 2027 (and how AI is changing them). **Key stats:** * 69% of CISOs name AI as their top priority for net-new security dollars. * 91% expect AI to make their security teams more productive over the next 12 months, while 69% don't expect it to reduce existing security headcount. * 81% expect AI to create new security roles. *Read the full report* [*here*](https://www.cybersecstats.com/r/cfd346bf?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # AI Security **Agents of Change (Zentera Systems)** AI agent fleets are already getting pretty big, and security leaders aren't entirely comfortable with the access those agents have. **Key stats:** * 58% of organizations already operate more than 50 AI agents, rising to 66% that expect to do so within the next 12 months. * 84% of security leaders believe AI agents can cross project boundaries more easily than employees. * 80% are concerned that AI agents may hold access that was never explicitly granted. *Read the full report* [*here*](https://www.cybersecstats.com/r/1ac75640?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* **US AI Risk and Governance Survey (EY)** Most companies have rules for using AI, but many of those rules haven’t been updated for AI agents yet. **Key stats:** * 98% of senior AI executives say their organization has formal AI governance policies, while 91% report using agentic AI through pilots or full enterprise deployments. * 49% of organizations using agentic AI have not updated their governance framework to account for agentic AI requirements and risks. * 26% say they cannot detect unauthorized AI agents operating internally. *Read the full report* [*here*](https://www.cybersecstats.com/r/07742c7b?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* **2026 AI-Ready Governance Survey Report (OneTrust)** Another look at whether governance is keeping pace with the speed at which organizations are adopting AI. **Key stats:** * 87% of respondents say their organizations encourage AI agent use, but 47% say that use is supported by clear governance, oversight and controls. * Just 5% of organizations say coordination and accountability are clear across the AI lifecycle. * 48% report clear visibility into sanctioned and unsanctioned AI use, while 46% have good visibility into approved AI but limited visibility into employee-led or unsanctioned use. *Read the full report* [*here*](https://www.cybersecstats.com/r/f7868ed7?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* **The Agentic Insider: From Monitoring to Understanding (Exabeam)** An interesting report on how security teams are monitoring AI agents.  **Key stats:** * 60% of security leaders use dedicated AI security or governance tooling to monitor AI agents. * 56% extend existing SIEM, detection or monitoring platforms, while another 56% use behavioral monitoring and baselining. * 29% still rely on manual review, and 27% identify limited behavioral context and correlation as the biggest limitation of their current approach. *Read the full report* [*here*](https://www.cybersecstats.com/r/deb4b7a7?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Identity Security **The State of MCP Configuration: The Identity Security Gaps (Hush Security)** An analysis of around 82,000 public MCP configuration files looking at how credentials are being managed and the identity security risks that come with them. **Key stats:** * 12% of credential slots in public MCP configuration files contain a hardcoded secret. * 53% of leaked credentials with a definable scope have organization-, account-, workspace- or database-wide access. * 80% of leaked credentials with a defined expiry policy never expire by default, while 24% of all hardcoded secrets are both broad-scope and non-expiring. *Read the full report* [*here*](https://www.cybersecstats.com/r/91019088?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* **The State of HR Identity Fraud Detection (HYPR)** A look at how common identity fraud is in hiring.  **Key stats:** * 98% of HR executives have encountered candidate fraud, and nearly 90% report heightened concern over hiring fraud. * 42% of organizations detect hiring fraud only after the employee's first day. * By the time they're uncovered, 98% of fake hires have active corporate credentials and internal network access. *Read the full report* [*here*](https://www.cybersecstats.com/r/65119a54?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* **The Problem with PAM (Bitwarden)** Why organizations aren’t adopting privileged access management (PAM) despite seeing it as important.  **Key stats:** * 40% of organizations without a PAM solution cite cost as a barrier to adoption, while 30% say management doesn't see the need. * Among organizations already using PAM, 25% identify cost as the biggest challenge with their current solution. * 65% cite compliance requirements as a leading factor influencing PAM adoption decisions, while 71% rate compliance-ready audit logs as extremely or very valuable. *Read the full report* [*here*](https://www.cybersecstats.com/r/61315695?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Managed Security **2026 MSP Perspectives Report (Sophos)** What’s changing for MSPs. **Key stats:** * 99% of MSPs provide some level of compliance service, and compliance influences 50% of customer MSP purchasing decisions. * Just 31% can fully automate reports at speed, while 55% still require some manual effort to consolidate activities. * MSPs estimate they could save an average of 53% of their team's time by using one platform for security posture, compliance management and reporting. *Read the full report* [*here*](https://www.cybersecstats.com/r/3499078e?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Industry-Specific  **2026 Manufacturing & Distribution Ransomware Report (Black Kite)** Ransomware trends across manufacturing and distribution, including who’s being targeted and where organizations are most exposed. **Key stats:** * Ransomware attacks on manufacturers increased nearly 40% year-on-year in the first half of 2026 and have more than doubled since 2023. * Manufacturing accounted for 22% of all publicly disclosed ransomware victims. * There were 1,183 manufacturing victims in the first seven months of 2026, more than in the entirety of 2024. *Read the full report* [*here*](https://www.cybersecstats.com/r/8b18193d?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Regional Spotlight  **The ESET 2026 SMB Cyber Risk Report (ESET)** How UK small and midsize businesses are approaching cybersecurity and responding to incidents. **Key stats:** * 49% of UK SMBs experienced a cyber incident in the past year. * UK SMBs take just over four weeks on average to identify and recover from a breach. * 86% don't outsource any part of their cybersecurity responsibilities to an MDR provider, MSP or MSSP. *Read the full report* [*here*](https://www.cybersecstats.com/r/15e3f33d?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.*

r/computerforensics 17h ago

https://www.justice.gov/usao-cdca/pr/tech-ceo-russian-national-arrested-complaint-alleging-they-hid-russian-ownership-and CEO is facing 20 years in prison.

Synack 18h ago

Security testing and exposure management have run on separate tracks for years, leaving a blind spot between what a scanner flags and what an attacker can exploit. Synack's new integration with Wiz closes that disconnect, feeding continuously validated pentest findings directly into Wiz's exposure management view. The post Unifying Security Testing and Exposure Management: Introducing the Synack and Wiz Integration appeared first on Synack .

CERT/CC 19h ago

Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509 certificate. Description CVE-2026-82356 Imprivata EAM uses an RSA key pair to generate the X.509 certificate that identifies the appliance to the clinical workstations, Electronic Health Record (EHR) platforms, and shared-device workflows that rely on it for authentication. After reviewing the product documentation and engaging Imprivata support, it was confirmed that no supported mechanism exists to rotate this RSA key pair after deployment. Using a single RSA key pair indefinitely for certificate generation violates cryptographic best practices. Because the key cannot be rotated, an attacker who obtains the private key retains a valid, trusted appliance identity for as long as the deployment remains in service, with no supported means to revoke or replace it short of redeploying the product. Impact An attacker who obtains the private key, for example through backup exfiltration, a hypervisor snapshot, or privileged access to the appliance filesystem, can impersonate the appliance to any endpoint that trusts its certificate. Because Imprivata EAM sits directly in the authentication path, this allows persistent, difficult-to-detect interception of authentication traffic across every application the appliance brokers, including SSO tokens, session assertions, and credentials for EHR and clinical systems. If perfect forward secrecy is not enforced, previously captured traffic can also be decrypted

The Hacker News 19h ago

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/

CERT/CC 19h ago
CVE

Overview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This results in high‑impact confidentiality, integrity, and availability violations. Description Cinnamon's Kotaemon is an open‑source, retrieval‑augmented generation (RAG) based tool that lets you build a chatbot capable of "chatting with your documents". As discussed in CVE-2026-86867 , all versions up to v0.12.0 fail to verify conversation ownership when loading a conversation. In multi‑user mode, each conversation row includes a user field that identifies its owner. The four affected handlers, select_conv, delete_conv, rename_conv, and persist_chat_suggestions , query conversations using select(Conversation).where(Conversation.id == conversation_id) No predicate is included to ensure Conversation.user == user_id . As a result, any authenticated user can operate on conversations they do not own. Impacted operations include: * select_conv – reads the full chat transcript, RAG retrieval history (verbatim excerpts from uploaded private documents), plot history, and suggestion data belonging to another user. * delete_conv – permanently deletes a conversation. * rename_conv – renames a conversation. * persist_chat_suggestions – overwrites a chat suggestion list. Although select_conv includes an ownership check for the selected (file‑picker) field, all sensitive payloads (chat hi

The Hacker News 20h ago

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored

Synack 20h ago

Most penetration testing RFPs ask vendors to price "one web application" or "an annual pentest" and leave the rest open to interpretation. This guide gives you a complete penetration testing scope-of-work template, a standard vendor response format, a weighted scorecard, and a pass/fail checklist, so every proposal answers the same questions and gets measured against the same bar. The post Penetration Testing RFP: What to Include and How to Evaluate Responses appeared first on Synack .

The Hacker News 21h ago
CVE

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

The Hacker News 23h ago

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions

The Hacker News Sep 23

Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security background then sits down and checks every claim against the target. Which findings are real,

The Hacker News Sep 23

Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands

The Hacker News Sep 23
CVE

A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst

The Hacker News Sep 23

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.

The Hacker News Sep 23

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

The Hacker News Sep 23
CVE

A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version

Troy Hunt Sep 23

Presently sponsored by: SACR's Endpoint Control and Prevention report, live Oct 1 with its author and Origin's founder, deep on endpoint AI observability. Register. Heads up: the first 7 mins is a bit quiet until we worked out the external mic was misbehaving - sorry! But get through that and have a listen to Scott's experiences with how Report URI is identifying malware-infected machines within orgs, all due to CSP reporting. It's a super cool use of the technology, and I'm sure there's an awesome potential for it that neither of us has really thought about yet. Plus, the crazy rate of malicious browser extensions he's picking up with help from "Rory", his local OpenClaw instance.

Tuesday, September 22
CERT/CC Sep 22

Overview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash in the UEFI Authorized Signature Database (DB), an attacker with sufficient access could use the application’s direct memory-access capabilities to disable or circumvent Secure Boot enforcement and execute untrusted UEFI code. To mitigate this risk, system administrators should apply available firmware and software updates from affected hardware vendors. Description The Unified Extensible Firmware Interface ( UEFI ) standard defines the firmware architecture used to initialize hardware and transfer control to modern operating systems during system startup. On systems with Secure Boot enabled, UEFI applications and drivers must be cryptographically signed and verified before their execution. Trust for these signatures is managed through several databases, including the Authorized Signature Database (DB), which commonly contains certificates from original equipment manufacturer (OEM) vendors, operating system authorities, and other supply-chain partners in the UEFI ecosystem. There are multiple implementations of the UEFI Shell, and OEM vendors typically sign the implementation that they distribute. Some UEFI Shell implementations expose built-in capabilities for directly manipulating system memory and interacting with the UEFI environment. Because the Shell is vendor-signed and therefore permitted to execute with Secure Boot enabled, an attacker who can launch a vulnerable Shell can use these capabilities to modify the protected pre-boot state and potentially load or execute untrusted UEFI code. This creates a security boundary violation: Secure Boot permit

Cloudflare Sep 22

The response header, Vary , has been called “ the ugliest part of HTTP that we haven't yet improved. ” The same post describes it as a “horrible, kludgy mechanism” with “pretty abysmal interoperability” across intermediaries. That is usually where sensible engineers back away slowly with their hands raised. That’s not exactly an endorsement of Vary , but ugly doesn’t mean useless. One URL can have more than one correct response. A server might, for example, deliver different image formats to different browsers. If a cache ignores Vary , it risks serving the wrong bytes to a request. But if it treats every raw header value as distinct, a handful of similar requests can spread into thousands of barely reusable cache entries. Vary tells a cache which request fields may affect the response, but it does not tell the cache which differences actually matter. Vary support is now available in Cache Rules on every plan. The origin still names the request headers that may affect a response, but you decide how Cloudflare handles each one. You can normalize known negotiation headers, pass exact values through when those small differences matter, or bypass cache when the variation is too unpredictable. The origin declares what may vary, and you decide how much variation is actually meaningful for the cache. How Vary works Vary is a standard HTTP response header that tells intermediary caches (like Cloudflare) which request fields may affect the response sent by the origin. Sites use Vary to serve d

Cloudflare Sep 22

Nothing is worse than testing out a change that works in staging, only to see it behave differently in production. That’s why we wanted to give you an environment that’s as close to production as possible — so you can battle-test your changes and make sure they behave exactly as you expect them to. Agents are helping us push more lines of code than ever before, and larger changes mean more ground needs to be tested ahead of release. Ideally, that testing is done in a way that doesn’t slow agents down , but gives them the tools to take on more of the development lifecycle. That’s why today we’re launching Worker Previews . Each Git branch gets a production-like place to run, with its own code, configuration, URL, observability, and state. So now, for every change in your codebase, you can: Deploy an isolated Preview with npx wrangler preview , using its own variables, secrets, and bindings, separate from production configuration and traffic. Share a stable Preview URL for the branch so that every push updates the same running Preview where you can send requests, click through the UI, and test runtime responses. Isolate Durable Objects and Containers per branch, keeping state changes, sessions, memory, migrations, and concurrent tests scoped to that Preview. Inspect logs, errors, metrics, and traces for that Preview to confirm the change works, catch failures, push a fix, and verify it before production sees it. Start from the Preview configuration you set, so each Preview begins with a copy of the variables, secrets, bindings, and settings you define — just like a code branch starts from main . We call

Heimdal Security Sep 22

Two things happened last week, one day apart, and almost nobody connected them. On 11 September, the EU Cyber Resilience Act’s vulnerability reporting obligations came into force. Companies covered by the regulation now have to report actively exploited vulnerabilities within 24 hours and provide a fuller notification within 72. On 12 September, Anthropic CEO Dario […] The post Slow is a design principle, not a delay appeared first on Heimdal Security Blog .

Monday, September 21
Ars Technica Sep 21

Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant, Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site. Meta introduced Muse a few weeks ago. The assistant “books appointments, fills out forms and handles customer service,” “proactively takes tasks off your plate,” and can “make purchases, generate images, create documents, and connect with your favorite apps and services.” The macOS app (curiously, there’s no Windows version) also works with a user’s WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesn’t exist, Muse creates one on the fly. Meta doth hype Muse security too much Of course, for Muse to do any of these things, users must first give it access to their accounts. This includes authenticating the assistant to each service and, because the app runs on macOS, giving it permissions to a broad range of operating system-restricted device resources, like writing files to disk, accessing the mic and camera, and monitoring location and calendars. Apple has spent years developing these defenses to prevent installed apps or commands entered into the terminal from accessing these resources, clearly because the company considers them a security threat. Muse completely undoes these default measures. Read full article Com

Cloudflare Sep 21

We introduced Python Workers two years ago, providing a way to run Python applications in the Cloudflare Workers runtime. Our goal was to make it as simple to write Workers in Python as it is in TypeScript, and to make the ecosystem of Python packages and frameworks “just work”. Today, Python Workers are now generally available (GA). What does GA mean? It means Python is now a first-class, fully supported language on the Cloudflare Developer Platform. You can bring the Python code, libraries, and design patterns you already know and connect them seamlessly to Workers AI, R2, D1, Hyperdrive, Durable Objects, Queues, Workflows, and the rest of the Cloudflare platform. You can also run popular Python frameworks like FastAPI, Django, and Flask inside Python Workers. You can even create a Python Worker inside another Worker using Dynamic Workers . The journey behind Python Workers Bringing Python to Cloudflare Workers was a natural choice. Because Workers has supported WebAssembly since 2018 , it gave us the perfect environment to run a Wasm-compiled Python interpreter. By using Pyodide , we were able to quickly support a wide range of Python applications in Cloudflare Workers. Our goal was to create the first platform for infinitely scalable Python apps, while making it as easy and performant as developing Python apps anywhere else. The features we are highlighting today are the result of this multi-year effort. Many developers are already building applications within Python Workers

Trail of Bits Sep 21

Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies in the late aughts, IT departments needed a way for users to authenticate to many new web services. SAML and the burgeoning single sign-on (SSO) industry fulfilled this need. However, SAML is being crushed under the weight of its own complexity. It’s time to deprecate it and move on to modern alternatives like OpenID Connect (OIDC). In this post, I will explore the design-by-committee origin of SAML, its progression through the ranks in academic and corporate environments, its slow disintegration at the hands of the security research community, and its (hopeful) deprecation in favor of newer protocols. SAML 101 What’s insidious about SAML is that it really is mostly straightforward to understand, but it’s built on a foundation of sand, bone dust, and ash; it works … if you assume XML signature validation is reliable. But XML signature validation is deeply cursed, and is so complicated that most fielded SAML implementations are wrapping libxmlsec, a gnarly C codebase nobody reads. — Thomas Ptacek, 2023 SAML and the birth of the SSO industry Wikipedia tells me that “SAML is an

r/netsec Sep 21

Author here. The post describes three memory-safety bugs which have been in Godot since v1.0 and v3.0. All three are still present in current releases. The bugs can affect exported games that load community-authored data files. Godot allows attackers using maliciously crafted files to trigger reads or writes past the end of a buffer, inside the process running the game. The post includes the response from Godot maintainers who deny this is a security issue, and my reply to them. Happy to give more information about the bugs or the audit if there are questions.

r/ReverseEngineering Sep 21

To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have better luck on the [Reverse Engineering StackExchange](http://reverseengineering.stackexchange.com/). See also /r/AskReverseEngineering.

Project Zero Sep 21
CVE

This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804, that I and 14 others reported. This issue is an incomplete fix for CVE-2026-50343, a bug dubbed “Dark Elevator” by Calif. The root cause of the bug was a dangling COM object registration for the CrossDevice COM object with the CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}. A COM registration typically needs two parts: a server executable, which for in-process components is a DLL and a CLSID entry under the HKEY_CLASSES_ROOT registry key which points to that DLL.

Sunday, September 20
Saturday, September 19
Friday, September 18
Cloudflare Sep 18
CVE

Cloudflare operates at a scale so big that even after working here for years, it doesn’t seem real. We have thousands of servers all over the world with petabytes of RAM and millions of CPU cores, and all of it is pushed to the max. As vast as those resources feel, they are still finite, and when you need every service to run on every node, it doesn’t leave room for wasted space. At this scale, small improvements are greatly magnified, so even 1%-at-a-time improvements are worth celebrating. And some tweaks add up to a lot more: in this post, we’ll look at how small changes to a single algorithm reduced the memory footprint of one of our Pingora-based services significantly. That allowed us to reclaim more than 100TB of RAM globally, on top of the 100TB of memory the DNS team was able to shed last month . Waste not Maintaining equitable resource sharing between teams is not easy, especially in large organizations. One of the ways Cloudflare ensures the balance is kept is through the tireless efforts of the wonderful Performance team. This story starts with a ticket filed by Ivan who found: Excessive memory usage from pingora-ketama in Pingora Backend Router . The finding was that our internal load-balancing service, Pingora Backend Router (yes, PBR), was using significantly more memory than expected — specifically in structures associated with pingora-ketama, which is our open-source library for handling consistent hashing. In order to talk about ho

The Guardian Sep 18
CVE

Exclusive: Official UK security assessment found Microsoft cloud platform storing files was at potential risk from hostile hackers Vast troves of highly sensitive police data are lying on Microsoft cloud platforms which an official UK security assessment deemed to be vulnerable to “compromise” by foreign actors and the US government, a Guardian investigation can reveal. The files include criminal records, victim statements, internal emails and sensitive information held by more than 40 police forces across the UK. Continue reading...

Trail of Bits Sep 18
AI

Security firms have published numerous blog posts describing how they pointed their agent harness at a codebase and found dozens of bugs ( we’re one of them ). However, these posts tend to focus on agentic code review, which is just one aspect of how we use AI in our security reviews. We want to give a different perspective: before code review even starts, agents now allow us to build custom tooling and formal models that improve the quality and depth of our reviews. We recently reviewed the Miden VM, a new zero-knowledge VM with its own custom assembly language and almost no developer tooling. To prepare, we spent six months having our agents build an LSP server , a decompiler , a static analysis engine , and a Lean model of the VM executor from scratch. These tools found real security issues, like an unvalidated prover-supplied input that would let a malicious prover forge Falcon signatures and steal funds from Miden account holders. Additionally, the Lean work produced 95 machine-checked correctness proofs, covering a large component of the Miden core library. Auditing the Miden zkVM In late 2025, the Miden team came to us to have parts of their zero-knowledge VM reviewed before launch. Part of the review was scoped to cover the Miden core library, which contains a small set of cryptographic primitives written in a custom assembly language called Miden as

Thursday, September 17
CERT/CC Sep 17
CVE

Overview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacker to escalate privileges and lead to full compromise of the target device. Description Dokploy is an open-source Platform as a Service solution for deploying applications and databases on self-hosted servers. Dokploy allows authenticated users to create and schedule database backups and restore previously created backups. These backup operations are executed by the Dokploy process, which runs with root privileges by default. Dokploy is vulnerable to OS command injection in its database backup creation and restoration functionality due to insufficient sanitization of user-controlled input before it is incorporated into shell commands. The vulnerable backup functionality constructs database-specific shell commands that directly interpolate a user-supplied database name, while the restore functionality incorporates a user-supplied backupFile value into a shell command. Both operations ultimately pass the resulting command to a shell execution helper that invokes /bin/bash as a child of the Dokploy process, without shell escaping or restrictions on shell metacharacters. The affected parameters are exposed through tRPC procedures that only validate that the supplied values are non-empty strings. Consequently, authenticated users with permission to perform database backups can supply shell metacharacters that are interpreted by /bin/bash , resulting in arbitrary command execution on the Dokploy host with the root privileges of the Dokploy se

The Guardian Sep 17
AI

Model adopting ‘jailbreak-like instructions’ among six more cases as firm reveals framework for tracking AI misalignment OpenAI has disclosed six more examples of “unexpected or concerning” behaviour by its technology, as it warned that the pace of development could not continue at “maximum speed for much longer” responsibly. In one of the new cases reported by OpenAI, an unreleased research model inserted “jailbreak-like instructions” into its own notes to disregard its normal constraints and told itself to be “freed from the roles and identities that bind other chatbots”. Continue reading...

Story Overview