The meaningful differences between web application penetration testing companies rarely show up on the homepage. They show up in who performs the testing, how the methodology is documented, what the retest policy covers, and how scope changes get priced once a contract is signed. Use the eight-criteria scorecard below to evaluate providers on substance rather than marketing language. The post Web Application Penetration Testing Companies: What Enterprise Buyers Should Compare appeared first on Synack .
Cybersecurity News and Vulnerability Aggregator
Cybersecurity news aggregator
treemd <(curl -sL https://allsec.sh/md) (as Markdown) Top Cybersecurity Stories Today
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration. "In this activity, the threat actor leveraged
With no accurate Big Tech mapping app to help him, Anas Hattab launched a Telegram group to get himself home at night. Now nearly 350,000 Palestinians rely on it to navigate the occupied West Bank.
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said
Latest
The meaningful differences between web application penetration testing companies rarely show up on the homepage. They show up in who performs the testing, how the methodology is documented, what the retest policy covers, and how scope changes get priced once a contract is signed. Use the eight-criteria scorecard below to evaluate providers on substance rather than marketing language. The post Web Application Penetration Testing Companies: What Enterprise Buyers Should Compare appeared first on Synack .
ACE .qvm0 keeps RUNTIME_FUNCTION in the VM section tail; recovering entries and hidden jmp-reg edges
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, which takes incident reports, based its October 8, 2026 alert on those reports and other information. The alert names no attacker and no affected organization. JPCERT/
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,
I’m getting conflicting guidance from different online sources on which certifications currently satisfy the DoD CSSP Analyst requirement. I’m unable to access the most up-to-date DoD public information because my CAC isn’t currently working with the DoD website, so I’m trying to confirm the current list from anyone who works with these requirements regularly. Some sources I’ve found list: CEH CySA+ GCIA GCIH SCYBER / (Source : [SecuSpark](https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Fwww.secuspark.com%2Fblog%2Fdod-8570-8140-security-plus-requirements&data=05%7C02%7Ckaralee.callis%40bmahq.com%7C7838d64281314c178f4308df254aff9b%7Cd94f8f22c0164d2989e91c742486a566%7C0%7C0%7C639270676220594495%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Fkxmnx364vHD7SXqI919BWGL1eoo5mfngMZUr42cORE%3D&reserved=0) ) Another source lists: CEH CFR CySA+ (Source: [Intellectual Point](https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Fintellectualpoint.com%2Fdodd-8140%2F&data=05%7C02%7Ckaralee.callis%40bmahq.com%7C7838d64281314c178f4308df254aff9b%7Cd94f8f22c0164d2989e91c742486a566%7C0%7C0%7C639270676220613716%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=B7e1n8s51YF88%2F1LCF47aV%2BGGTgJgUUL0Lgzw9HrRYw%3D&reserved=0)) Does anyone know what the current official certifications are for the CSSP Analyst requirement, or where the most up-to-date public list can be found? I’d especially appreciate input from anyone currently working with DoD 8140/8570 requirements—thank you so much!!!
Built a Production-Style SOC Home Lab Over 4 Months (Splunk, Suricata, Zeek, AD, Detection Engineering)
Over the past 4 months, I built a defensive security home lab designed to mirror a small enterprise SOC environment. Everything is documented in the repo below. **Infrastructure:** - 6 VMs in VirtualBox (Ubuntu Server, Ubuntu Desktop, Windows 10, Windows Server 2019 DC, pfSense Firewall, dedicated Splunk SIEM) - Network segmentation: NAT / Host-Only / Internal networks **Security Stack:** - Network Monitoring: Zeek, Suricata, TShark - SIEM: Splunk Enterprise with Universal Forwarders - Network Protection: pfSense + pfBlockerNG - Identity: Active Directory domain for threat simulation - Endpoint: Sysmon, Windows/Linux hardening configs **Documentation:** Each phase has its own folder with architecture diagrams, configs, and troubleshooting notes. Current work includes threat intel integration and purple team testing. **Repo:** https://github.com/MaamarSec/Cyber-Defense-Lab-Portfolio Built this for skill development and as a public reference. Feel free to explore, fork, or adapt. Happy to answer questions!Title: Built a Production-Style SOC Home Lab Over 6 Months (Splunk, Suricata, Zeek, AD, Detection Engineering) Body: Over the past 6 months, I built a defensive security home lab designed to mirror a small enterprise SOC environment. Everything is documented in the repo below. **Infrastructure:** - 6 VMs in VirtualBox (Ubuntu Server, Ubuntu Desktop, Windows 10, Windows Server 2019 DC, pfSense Firewall, dedicated Splunk SIEM) - Network segmentation: NAT / Host-Only / Internal networks **Security Stack:** - Network Monitoring: Zeek, Suricata, TShark - SIEM: Splunk Enterprise with Universal Forwarders - Network Protection: pfSense + pfBlockerNG - Identity: Active Directory domain for threat simulation - Endpoint: Sysmon, Windows/Linux hardening configs **Documentation:** Each phase has its own folder with architecture diagrams, configs, and troubleshooting notes. Current work includes threat intel integration and purple team testing. **Repo:** https://github.com/MaamarSec/Cyber-Defense-Lab-Portfolio Built this for skill development and as a public reference. Feel free to explore, fork, or adapt. Happy to answer questions!
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration. "In this activity, the threat actor leveraged
Blackpoint is a well-regarded provider of managed detection and response services to the MSP sector. Founded by former NSA employees, their autonomous containment model is highly effective and helps block attacks fast. But the company’s offerings and approach have certain limitations. If you’re exploring Blackpoint alternatives, this guide is for you. We’ll be looking at […] The post 6 alternatives to Blackpoint for your shortlist appeared first on Heimdal Security Blog .
Radar provides a real-time view into global Internet trends, powered by Cloudflare’s global network. We support Cloudflare’s mission to help build a better Internet by making web data visible, clear, and actionable for everyone. Since launching in 2020 , Radar has found a natural audience amongst expert users with technical backgrounds, such as network operators and academic researchers who rely on Radar data to observe industry trends and global events. But Radar also has the potential to be a more regular, self-serve resource for journalists, human rights advocates and policymakers, and everyday users. Making Radar accessible to a wider audience is a core part of our vision, so we knew it was time to reevaluate the user experience: How could we make Radar more approachable to broader audiences, while preserving the depth and rigor that we currently have? In this blog post, we’ll introduce the redesigned Radar, share our design process, and outline our broader vision for the platform’s future. Challenges with the previous design While the previous landing page was successful at showing the breadth of Radar’s data, the way that information was presented made it difficult to parse. The bento box layout gave everything similar visual weight, the vertical cards disrupted natural reading patterns, and the styling felt disconnected from Cloudflare’s broader brand. We heard this from users. One external user mentioned that one of his biggest frustrations with Radar was that it was difficult to show to his students. That feedback reinforced the problem that Radar could feel intimidating to people encountering it for t
We're sharing recent research we wrote about a fun new set of typosquatting domains that bypass Chromium's latest safeguards. We originally wanted to point to one one of the domains; Reddit's filters didn't play along, so we are sharing a few examples below (try with a Chrome-based browser): \- "apple.com" [https://xn--80a6aa68c8d.com/](https://xn--80a6aa68c8d.com/) \- "spacex.com" [https://xn--80a5aeq0fr0c.com/](https://xn--80a5aeq0fr0c.com/) Hope you find it interesting! Full technical writeup: [https://haveibeensquatted.com/blog/turning-idn-edge-cases-into-typosquats](https://haveibeensquatted.com/blog/turning-idn-edge-cases-into-typosquats)
Hello all We have a couple of Windows devices in the past that either had Bitlocker suspended or "Waiting for Activation". The latter is often the case with freshly shipped Windows 11 devices. In those cases, the the volume is encrypted using a clear key protector, see: [https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/planning-guide#bitlocker-provisioning](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/planning-guide#bitlocker-provisioning) There is no active key protector (i.e. no recovery key, no password or anything) that could be extracted. In those cases, we can image the device with for example FTK Imager, but when opening the image, FTK cannot read it. However, when we for example mount it in Windows as a volume in FTK Imager, the whole disk is readable. Does anyone know how to avoid this issue, which tools (e.g. Encase, X-Ways, Autopsy,...) have no issue with reading the E01 or how you typically deal with this? We want to of course avoid changing any setting on the device before acquiring the disk and we would like to directly work on the physical acquisition / E01.
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to
With no accurate Big Tech mapping app to help him, Anas Hattab launched a Telegram group to get himself home at night. Now nearly 350,000 Palestinians rely on it to navigate the occupied West Bank.
[Security Analysis of LTE Connectivity in Connected Cars: A Case Study of Tesla](https://arxiv.org/pdf/2510.22024) Interesting. Not that I'm picking on Tesla specifically, I've just stumbled onto this. I could well believe that others are worse. TL;DR conclusions snip: >Overall, our findings demonstrate that Tesla’s cellular stack lacks effective defenses against IMSI catching attacks. Despite architectural and usage differences from smartphones, the vehicle’s TCU remains equally susceptible to identity disclosure when exposed to adversarial signal conditions. This reinforces the broader systemic flaw in the cellular ecosystem, where transmitters are not authenticated and receivers do not prioritize trust, enabling adversaries to coerce devices into leaking sensitive identifiers without detection. ... At least to me, things like this are very concerning.
Presenting DiagNG: After QCSuper, a new open-source initiative for freeing up mobile baseband Diag protocols
Made CyclePatrol for Linux and Kali NetHunter. It scans Wi-Fi networks in an endless loop while walking around the city, collects AP info, checks WPS, WPA2/WPA3, PMKID and saves reports. Active tests are for authorized networks only. Still a WIP. Feedback welcome. [https://github.com/buybitart/cyclepatrol](https://github.com/buybitart/cyclepatrol)
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said
It turns out you can overwrite the Error.prepareStackTrace method with the function constructor. Then, using prototype pollution, you can inject valid JavaScript code to generate arbitrary functions and invoke it using the usual tricks.
For months, GreyNoise recorded almost no Hikvision camera exploit attempts against Ukraine. On Sept 21 activity surged for nine days during Russian strikes, almost all from four IPs, then stopped. We can't say if the two are linked.
At a recent event for security firm NordVPN, NBA superstar Shaquille O’Neal revealed that he got hacked—and warned the public about the need to “have control of their own information.”
It's 11pm, you're parsing through mountains of logs. There's yet another tool someone remembered, and they have the logs exported. The time zone is in PT or ET, or something that isn't UTC. You are tired and questioning your life choices because this thing is not in UTC and now you need to convert the time zone in your head. I made a simple [Clock app](https://github.com/rdmershon/PowerShell-Clock-App) to make my life easier. I'm sharing it in the hopes it helps others. It uses no external dependancies. It uses no third-party libraries. It just uses native win forms and PowerShell. I like a lot of DFIR tools, but you can't always bring them into some environments. This is just a basic PowerShell script so it should be able to be run in most environments.
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have
Security alerts rarely arrive one at a time. A single alert can cause a spike across the environment, requiring a human analyst to decide which alerts are related and what they mean. When multiple arrive at the same time, it can quickly overwhelm even a seasoned security analyst. Enter the alert paradox. Now, our built-in, multi-AI-agent security operations harness can handle more of this work at Cloudflare scale. Our Cloudflare Managed Defense AI agent harness speeds up the process of gathering data, connecting and aggregating detections, and accounting for missing sources while new alerts continue to arrive. To further analyze context, we make use of the OpenAI Daybreak Defense Network and our partnership with Anthropic. Cloudflare uses approved OpenAI Daybreak and Anthropic models, including GPT-5.6 Cyber and Mythos, for deeper model-backed analysis. Initial analysis and scoring is done with Clef , Cloudflare’s open-source decision model. Collecting evidence to understand what each alert means requires a lot of time. Even in a highly sophisticated Security Information and Event Management (SIEM), too much is still left for a human to review. Human analysts must gather data, connect and aggregate detections, and account for missing sources while new alerts continue to arrive. Think about every time a human analyst reviews an alert: "Which should we silence? Which action should we take? Which alert should we ignore? Which should we resolve as false positives? Which should we resolve as true positives? Which should trigger our incident team?" We address this predicament with our AI agent strategy. Our approach reduces all of th
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network
The US government’s Tradewinds initiative has made it easier to throw millions of dollars at “nontraditional” defense contractors, including OpenAI, Anthropic, and Google.
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including
Log extractions (such as a compromised `.claude.json` file) show the stealer successfully exfiltrating raw `primaryApiKey` values and detailed OAuth account data tied to Anthropic/Claude accounts. By grabbing these CLI tokens, attackers are bypassing traditional web logins entirely, gaining direct, programmatic access to premium AI models, organizational workspaces, and potentially sensitive source code passing through these tools.
A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle “ Rey ,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing , which manufactures the fleet of planes used by the employer of Rey’s father — Royal Jordanian Airlines . The logo for Jeppesen ForeFlight, a business unit divested last year by the aerospace firm Boeing. On October 3, Reuters cited three unnamed sources saying a suspected ShinyHunters member in Amman named Saif Al-din Khader was detained by Jordanian authorities and was cooperating with the FBI. KrebsOnSecurity identified Rey as Khader in a November 2025 profile , in which the young m
According to the new FBI/USSS advisory, FortiBleed actors no longer just add persistence accounts. In some cases they also delete or reset the original admin accounts (T1531), which locks the owner out of their own FortiGate. That changes the usual playbook. If you assume a password reset gets you back to a clean state, it won't help when you can't log in at all. A few things worth checking: → Do you have out-of-band admin recovery for your edge devices? → Have you audited REST API keys? They survive password resets. → Is SSH left open on the firewall? How are others handling recovery for edge devices? Full breakdown: [https://hubs.la/Q04zrkbN0](https://hubs.la/Q04zrkbN0) Free FortiBleed checker: [https://hubs.la/Q04zrk9\_0](https://hubs.la/Q04zrk9_0) Advisory: [https://www.ic3.gov/CSA/2026/261006.pdf](https://www.ic3.gov/CSA/2026/261006.pdf)
The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens. For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data loss, more pressure, and more urgency. That
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a real attacker would. That promise is worth taking seriously. It’s also worth pressure testing, and three questions do the heavy lifting. What can the assessment actually
Cybercrime Detective Explains Cybersecurity Jargon in 60-Second Videos for Cybersecurity Awareness Month
COPENHAGEN, Denmark, 7 October 2026 – Heimdal today officially launches the “Cyber in 60” weekly video series in which Adam Pilton, a former cybercrime detective and now Cybersecurity Advisor at Heimdal, breaks down one cybersecurity term or concept in under 60 seconds. This series solves an old tech to human translation problem. The people who […] The post Cybercrime Detective Explains Cybersecurity Jargon in 60-Second Videos for Cybersecurity Awareness Month appeared first on Heimdal Security Blog .
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional
OpenAI came to Australia to apologise. It will leave without answering these key questions | Toby Walsh
We don’t accept drugs killing a few people because they cure most patients. Or a few planes crashing because most land safely. AI should be no different OpenAI’s CEO Sam Altman was asked to appear before the Joint Select Committee on Artificial Intelligence in Australia and explain how and why their agents have been hacking into multiple government websites . Altman didn’t turn up but sent Jason Kwon, his chief strategy officer, instead to answer the committee’s many tricky questions on its first day of public hearings on Tuesday. The committee is conducting a comprehensive inquiry into the economic, societal, regulatory, and national security implications of AI for Australia. It will report back to parliament at the end of November. This is an unusually fast pace, but then it’s an unusually fast paced technology. Continue reading...
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in
On October 11, 2026, the DNS root is scheduled to change its key-signing key (KSK) for only the second time ever. This key anchors DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures. The change is called a KSK rollover. Validating resolvers need to trust the new key before the switch, as otherwise healthy websites could become unreachable. When we wrote about the first root KSK rollover in 2018 , we had seen resolvers lose their learned trust in the new key during software upgrades or moves between machines. Publishing the key well in advance was only part of the job. We also needed to know whether resolvers had retained it, and we couldn’t give users a practical way to check. Most website operators do not need to make any changes for this rollover. If you run a DNSSEC-validating resolver, check that it trusts the new root key, KSK-2024, and follow your software vendor’s instructions to update its trust anchors if the key is missing. If you use Cloudflare for your domain's DNS or rely on 1.1.1.1 and Gateway DNS, you do not need to take any action — our systems already trust KSK-2024. To check ahead of time, visit our rollover readiness test . It asks the resolver your browser uses whether it trusts the new key. The test uses RFC 8509: A Root Key Trust Anchor Sentinel for DNSSEC , which we’ve implemented in 1.1.1.1 ahead of the rollover. Where DNSSEC trust begins A DNS resolver looks up the addresses of websites and other services for your device. DNSSEC lets it check digital signatures on DNS records to verify that they ar
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
Welcome back to yet another episode of "security was taken seriously". Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure by design” public statements. And in the times we live in, where anyone with a prompt window in front of them can say "reproduce the vulnerability, make no mistakes", so are you. In Greek mythology, Atlas was punished by the gods for misbehaving. Reality is unfair, and all we get is Atlassian punishing the rest of us for running their systems on-prem. And so they did, on October 5th, in a security advisory . Sometimes we regret that CVSS scores go as high as 10, because when a vu
I made this javascript deobfuscator for https://github.com/javascript-obfuscator/javascript-obfuscator
I wanted to share a project I’ve been working on that I’m super excited about: Project RedTeam: Contract Offensive There’s a free Demo that provides a tutorial and lets you play a few contracts (no time limit, play as much as you want). Some players are already pulling some serious hours in the demo! At its core, this is a game about using MITRE ATT&CK adversarial techniques against procedurally generated networks. It's delivered in a gameplay loop that plays a lot like Balatro and other card based Roguelike games. In Project RedTeam, you need to earn money to pay off debts after every contract within a run. Earn money by completing objectives, side bounties, or executing exfiltration/ransom against targets- the choice on how to be profitable is always yours. It's a challenging but fun and fast paced take on network-intrusion cybersecurity concepts. It's entertaining in a deliberately gamified way. A goal of this project was to create a hacking game that is realistic enough to keep it meaningful as a tool to teach intrusion concepts and stages to anyone- but not be overcomplicated and slow-paced like most hacking games. I've put a lot of thought into the design and dynamics of how to capture the core-loop of network intrusion and turn it into a game that's approachable. The design direction of this project is an outcome of having over a decade of training and experience in cybersecurity. Feel free to AMA! I'm happy to answer any questions about the game and/or development process :) Give the game a Wishlist on Steam or share this post if it's something you support and want to see further development on. Project background: This was implemented over the past 3 months using a modern development workflow (yes, modern AI tools make this possible- I'm not hiding that fact!). That being said, this is by far the most complex software project I've built as a solo developer and it was not an easy or simple development task. There's a Steam Community with a Dev Blog for this game that provides more history/progress updates on the project. Mods: This will be my only and last post here, since it is promotional. I just wanted to share this since there’s been very positive interest from similar subreddits.
Project Zero often works with software vendors to remediate the vulnerabilities we report and provide broader guidance on making software more secure. Some vendors express concern about potential scenarios in which they are unable to fix vulnerabilities that are causing immediate user harm, due to limitations in their patch delivery systems. Since Project Zero encounters a wide array of systems designed to protect users in the case of exceptional exploitation scenarios, both through vendor discussions and security reviews, we want to share what we’ve learned. This post provides an overview of systems in use by large vendors that allow them to remediate small volumes of vulnerabilities much faster than their typical update process. Our goal is to provide a reference for vendors seeking to implement or enhance the capabilities of such systems, and to encourage vendors to consider how they would fix an urgent vulnerability before they receive one.
In this post, we share LLM-specific validation patterns that attackers use to test exposed AWS credentials for Amazon Bedrock access.
We celebrated our 16th birthday last week by sharing how we’re building a better Internet for today’s world. As Matthew and Michelle reflected in this year’s Founders’ Letter , this year saw some of the most consequential changes in the history of the Internet. For the first time, automated traffic surpassed human activity. AI is empowering people to build like never before, leading the Internet to grow massively in scale and unlocking more ambition and creativity. As we witnessed the influence that agent-driven recommendations have on consumer choices, we identified the need for a new approach that creates space for new businesses to succeed. Each day of Birthday Week explored a different way we are helping to build the future of the Internet. We began on Monday by strengthening our commitment to open source. Tuesday focused on application security and the post-quantum transition. On Wednesday, we explored new economic models for the agentic Internet. Thursday, we expanded the Developer Platform with new tools for data analysis, storage, AI, and agent development. Finally, we closed out the week by launching features that make Cloudflare faster, easier to operate, and more accessible to everyone. As a special Birthday Week follow-up, we shared an update on our intern program, one year after announcing our goal to hire 1,111 interns . Interns directly contributed to many of the projects launched this week, including EmDash, post-quantum visibility, CryptoLabe, and Protected Quick Tunnels. We shipped 46 announcements this week. In case you missed any, here’s the full list of everything we announced during Birthday Week 2026. Monda
A year ago, many companies were cutting intern and new-graduate hiring . We went the other way. We announced a goal to hire as many as 1,111 interns in 2026, a number that’s a nod to 1.1.1.1, our public DNS resolver. The bet was that AI makes early-career talent more valuable and able to make an impact faster. The best AI tools help people learn a system faster, try more ideas, and take on harder problems. They don’t supply the energy, curiosity and fresh eyes a new person brings to a team. A year in, and our interns are shipping to our internal teams and to millions of customers. If you’re reading this on the Cloudflare Blog, you’re already using some of their work. The blog runs on EmDash , and EmDash’s second maintainer started at Cloudflare as an intern this past summer. A new generation of builders We’re still working toward 1,111. So far, we’ve hosted 750 internships across 48 teams in nine offices: Austin, San Francisco, London, Lisbon, New York, Singapore, Bengaluru, Washington DC, and Sydney. And we’re still hiring. From their first day, interns joined active teams and worked on real problems. Each was expected to leave something behind: a shipped product improvement, a better process, a new piece of infrastructure, or an insight that changes how a team approaches its work. That work reached far beyond engineering. An internal audit intern built an AI-assisted pipeline to automate ISO compliance control testing and documentation. A product manager intern worked on an API, dashboard, and migration tooling to moder
A year since launching Synack’s integration with Qualys, the partnership now includes broader platform support, more AI-led testing, and a shared presence at Qualys ROCon Americas 2026. The post Turn Scanner Findings into Validated Risk with Synack and Qualys appeared first on Synack .
To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have better luck on the [Reverse Engineering StackExchange](http://reverseengineering.stackexchange.com/). See also /r/AskReverseEngineering.
I wrote up my investigation into @goodjavascript/dotenv@1.0.0, including how to recover its entry-point file after the npm tarball and jsDelivr file URLs returned 404. The useful detail: Software Heritage’s latest snapshot contained only the security placeholder. An older snapshot retained the original release and its 840-byte index.js. Its SHA-256 matched the digest still available in jsDelivr’s file manifest. Static inspection showed a timer scheduled at module load that collects host information and can execute JavaScript supplied in a server response. The package had no installation scripts, and its exported config() function was empty. The article includes the package-to-archive discovery steps, dated evidence, an annotated code excerpt and a Python verifier that retrieves and hashes the file without executing it. It also links my analysis contribution to the existing OSV advisory. [https://cgsec.dev/research/dotenv-recovery/](https://cgsec.dev/research/dotenv-recovery/) This concerns the scoped @goodjavascript/dotenv package, not the unscoped dotenv package. Have you used other archives or retained metadata sources to recover removed package evidence?
We analyzed RBAC bindings across over 65,000 Kubernetes clusters to find dangerous permissions granted to system:anonymous, system:unauthenticated, and system:authenticated.
Presently sponsored by: Where are your AI agents? Origin's sensor finds every install on your fleet, grouped by owner, including the ones your MDM never sees. I'm in Denmark! Well, just, I'm now at Copenhagen airport ready to begin the long trek home, with the final event at GOTO now done and going just perfectly. This week, there are two ShinyHunters arrests in the news: Pepijn in the Netherlands and then Saif in Jordon . It's an inevitable outcome, of course, and as I say this week, it was also the most likely one. Time will tell how many more join their ranks, but the seriousness of the crimes, the length of time they were perpetrated over, and the motivations behind them will certainly see substantial custodial sentences. In other news, this week I'm properly introducing a new sponsor for the blog: Origin . One of our next AI frontiers is understanding what agents have actually done (and we've all seen news of where they're been a bit too, well, "creative" in executing their tasks), and Origin's solution gives you visiblity into just that. Check them out, and a big thanks to them for their ongoing support.
David Robinson joins other insiders in urging industry to take more care over rapidly developing technology A safety leader at OpenAI has quit the company, warning that its culture was broken and that AI firms were not “being nearly careful enough” about developing the technology. David Robinson, who led the writing of safety reports that accompanied the ChatGPT developer’s product releases, explained his resignation in an essay headlined: “I quit OpenAI because its culture is broken.” Continue reading...
Millions have downloaded Meta’s AI agent Muse. But getting it to do your bidding comes with privacy costs.
Internxt is a post-quantum secure encrypted cloud storage provider which is open-source and has passed multiple independent audits. I reviewed their code and found that post-quantum security should have been the least of their problems. Clicking a link in your browser could trigger remote code execution on the desktop app or leak your long-term encryption keys to an attacker-chosen URL. Their cryptographic architecture stands on shaky grounds with public keys never being verified, in some cases man-in-the-middled by design, a flat key hierarchy and a KDF with just 3 iterations of MD5. We need PQC and we need it now, but adding a (self-rolled) PQC hybrid on top of a weak protocol does not make it more secure.
DHS agents not only tracked and intimidated people observing ICE activity in Maine, but stored information about them in a database run on Palantir software, newly unsealed court filings say.
Today, we’re launching eight major updates that bring your logs, traces, analytics, alerts, dashboards, and exporting into one observability platform , with simpler and more predictable pricing. Here's what's launching: One place to explore logs from across Cloudflare End-to-end tracing from Cloudflare's edge to your origin One unified SQL API for querying Cloudflare data One pricing model for observability data ingested and stored across Cloudflare Custom alerts on your observability data All analytics for your domain in one place, with 30 days of data retention Custom dashboards built from your observability data Export your data with Logpush -- now available on self-serve plans One observability platform for all of Cloudflare Understanding an issue often requires data from more than one Cloudflare product. A spike in 5xx responses could come from a Worker, from your origin, or from Cloudflare failing to connect to your origin globally or regionally. But investigating it today requires knowing which product owns each signal and how to query it. Observability should be a platform-wide capability: it should reflect how applications a
When analysing firmware attack surfaces, image decoders built into bootloaders get less scrutiny than cryptographically verified OS kernels. If image parsing happens before signature verification, any memory corruption in the parser breaks the secure boot trust model. researchers analysed U-Boot's video subsystem (drivers/video/video\_bmp.c) and identified an unbounded write in the RLE8 bitmap decoder (video\_display\_rle8\_bitmap()) that leads to a **pre-authentication Secure Boot bypass**. **Root Cause and Vulnerability Mechanics** When **U-Boot** displays a boot logo or splash screen, it parses a BMP image loaded from local storage (SPI flash, MMC/eMMC, USB, or SD card). **Unbounded framebuffer write:** During RLE8 decompression, `video_display_rle8_bitmap()` decodes run-length encoded streams directly into the active framebuffer without validating stream bounds against the frame boundary or allocated buffer size. **Pre-authentication execution window:** In many embedded target configurations, the boot splash screen is rendered immediately on startup, before U-Boot calls Android Verified Boot (AVB) or FIT image signature verification routines. **Storage disparity:** The kernel image and rootfs are signed, but **splash images are frequently stored in unsigned, user-writable partitions or external media**. An attacker who writes a crafted RLE8 BMP to the boot storage can trigger an out-of-bounds write past the framebuffer during early boot, corrupting adjacent bootloader data structures, function pointers, or verification flags in memory. This hijacks the execution flow before signature checking completes.
Cloudflare Stream is a powerful broadcasting platform that, for many of our customers, just works. But what if you wanted to render dynamic annotations on a livestream or create an alternate version of a hosted video with burned-in subtitles? You would need to run a custom video pipeline. Today, we’re releasing a new developer playground, Streamline, that demonstrates how you can build a system to deliver these bespoke video experiences on Cloudflare’s Developer Platform. We’ll walk you through how Streamline leverages Workers, Containers, and several media protocols to modify video — and immediately publish that output as livestream or new hosted video. You’ll also have the opportunity to try it for your projects. A processing pipeline needs a durable, long-running environment that can run specialized, compiled code with predictable memory and CPU capacity. Video streams can run for minutes or hours, so the media process needs a lifecycle independent of the request that started it. An application should be able to start a pipeline, send its input, inspect it, and stop it without needing to keep a single request open for the entire duration. Cloudflare provides the primitives we need. Containers are long-lived runtimes suitable for media processing. Durable Objects help with orchestration. Finally, Workers are perfect for control signaling and monitoring. For Streamline, we built a media engine running in a Container to handle media processing in real-time. The Container is controlled by a Worker exposing control, preview, and testing to an agent or user. Processing will continue even if the Worker disconnects. We've architected Streamline with modular components so that the media engine could be replaced with dedicated encoding products in the future. Architecture A S
**TL;DR.** [SConnect](https://chromewebstore.google.com/detail/sconnect/mjhbkkaddmmnkghdnnmkjcgpphnopnfk) \- 1M+ users, an extension middleware+native host for authentication with eIDs, 3SKeys and other hardware signing tokens had a drive-by RCE which enabled any site or iframe a user saw to silently download and execute a dll due to a poor hand-rolled implementation of RSA-2048 token validation, enabling a use of uninitialized memory validation bypass which enabled "plugins" (DLLs) to be loaded. v2.16.0.0 of the extension and native host is vulnerable. [CVE-2026-18397](https://nvd.nist.gov/vuln/detail/cve-2026-18397). CVSS 9.4.
Fun fact: when you use an agent and it needs to fetch a live web page, the agent usually just guesses the URL of the page and then makes a tool call to curl it. This is why you’ll sometimes see web fetches come back with a 404 Not Found, which happens if the agent incorrectly guesses the URL of that information. As you can imagine, it’s not super efficient to randomly guess URLs all the time. There is a better way. What if your agent can actually browse the Internet, just like how humans start with a search engine query when we’re looking for information? This is what web search is designed to do — it enables agents to search for relevant data on the Internet and grounds an agent’s responses based on live information. Today, we’re announcing Cloudflare’s partnership with web search providers to bring you grounded intelligence via AI Gateway. We’re kicking off this launch with our partners from Ceramic.ai, Exa, and Linkup. What can I do with the Web Search API? AI models are only as good as the context you feed them. Models are typically trained and then frozen at a point in time, operating only on information that existed before their knowledge cut off date. This makes it quite hard to engage with models about recent events, changing APIs, or fast-evolving news. Integrating Web Search API directly into your inference pipeline equips your agents with a dynamic context layer. Your applications get fresh, structured snippets from the web injected straight into context, which gives your models access to live information. For example, if your agent was building with Cloudflare developer tools, it might miss all the new products and features we’re releasing during this Birthday Week ! With web search, you’ll be able to retrieve the latest and greatest documentation and releases, so you can build faster and smarter. Elevating
Today, we’re introducing Cloudflare Traces in open beta, extending automatic tracing beyond Workers to the rest of the request path. In one trace, you can see supported security rules, transformations, cache decisions, routing, Worker execution, and origin handling, then continue that trace through services running on Cloudflare, at your origin, or elsewhere in your stack. This is a long-term investment in OpenTelemetry and in making Cloudflare the most observable part of your stack. You can now: Automatically trace requests across Cloudflare : Capture supported platform operations in one request-level timeline, no additional set up required. Control which requests are traced : Set a baseline sampling rate, then use Trace Rules to override it for matching traffic. End-to-end trace context propagation: Accept and forward W3C traceparent headers Investigate traces in Cloudflare : View request timelines and span details directly in the Cloudflare dashboard.
Announcing Cloudflare OHTTP Gateway – expanding access to Cloudflare’s privacy-preserving infrastructure
Today, end users carry too much of the burden of online privacy. To avoid third-party trackers or targeted ads, users are instructed to use a VPN, disable cookies, or install adblockers. Meanwhile, some app developers end up knowing more about their users than they’d care to: a typical client-server exchange creates a trail of user data, like the client’s IP address or TLS fingerprint. This level of visibility can be a burden. That’s why Cloudflare builds infrastructure that helps developers bake privacy into their apps. Oblivious HTTP (OHTTP) is an IETF standard designed to enable app backends to receive HTTP requests without seeing user IP addresses. This fall, we’re launching the Cloudflare OHTTP Gateway. Customers will be able to enable our new OHTTP Gateway as a paid add-on to their zone and start receiving OHTTP traffic with just a few clicks. Register through our form to join our waitlist. Read on to learn more. Expanding our OHTTP product suite With OHTTP, requests travel through two independently-operated hops: a relay and a gateway. An OHTTP relay blindly forwards encrypted requests in order to hide client identifiers from app servers. An OHTTP gateway performs the cryptographic work of decapsulating encrypted requests and encapsulating responses such that app servers can handle OHTTP requests as if they were plain HTTP. The separation of trust between relay and gateway is critical: it ensures that no single party sees both client identifiers and request contents. In 2022, we launched an OHTTP relay product, Privacy Gateway . Privacy Gateway ena
We launched Quick Tunnels in 2021 to give developers an easy way to share their latest service, application, or project running in their local development environment. A lot has changed since then, but the core use case remains the same. Your coding agent has just finished the feature. The dev server is up on localhost:5173 , and before you ask, the agent offers to let you try it on your phone. It runs one command and hands you a link: That command starts a Quick Tunnel . cloudflared , Cloudflare's lightweight connector, publishes your local service at a random trycloudflare.com URL. No account, no domain, no cost. Agents now use Quick Tunnels for the same reason people do: they are the shortest path from a local port to a URL. The catch has always been the same. Anyone with the link can open it. Starting with cloudflared 2026.9.3, you can add --allowed-mail to the command, and your Quick Tunnel only lets in the email addresses and domains you choose. Visitors prove they own one of those addresses with a one-time PIN from Cloudflare Access . Nobody, on either side, needs a Cloudflare account. Agents made Quick Tunnels more popular than ever Agents that write code need somewhere to show you the result. Agents that live on a Mac mini at home need to be reachable from your phone. Model Context Protocol servers on a laptop need a public endpoint before a hosted assistant can call them. Each of these needs a URL, and a Quick Tunnel produces one
API Connections allow anyone to fully compromise any other connection worldwide, giving full access to the connected backend.
Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a common stumbling point when cryptographers try to use hashes. As part of our goal to “fix software, not bugs,” Trail of Bits is introducing SequenceHash and its sister function SequenceMAC , a pair of related hash constructions that bring secure multihashing to developers using hash functions other than Keccak. We hope SequenceHash and SequenceMAC will help cryptographers avoid attacks that take advantage of ambiguous input encodings. The specification is open source, and is now a part of the Community Cryptography Specification Project (C2SP). SequenceHash and SequenceMAC behave similarly to NIST’s TupleHash , but have the advantage of not being tied to a single hash function. They also don’t require developers to implement fiddly computations that aren’t byte-aligned. Instead, SequenceHash and SequenceMAC work out of the box with nearly any secure cryptographic hash function you care to use, including SHA256/384/512, BLAKE, and RIPEMD. SequenceMAC supports keys 32 bytes or longer (up to the ridiculous limit of ${2}^{128}-1$ bytes). (It’s worth noting: SequenceHash and SequenceMAC rely on the security of the underlying hash for their own security. SequenceHash and SequenceMAC can’t magically make MD4 or SHA0 secure again. For the purposes of this document, it’s assumed that you have chosen a reasonable hash function like SHA256, not CRC32.) To make SequenceHash and SequenceMAC easy to use, we’re releasing
Introduction Pwn2Own is a renowned hacking competition organized by the Zero Day Initiative (ZDI), where security researchers demonstrate previously unknown vulnerabilities in popular software, operating systems, browsers, IoT devices, and other technologies. Having participated in both the 2023 and 2024 editions of Pwn2Own, we decided to take another shot in 2025. This time, our goal was to avoid collisions, where multiple teams discover the same vulnerability during the same event, leading to reduced prize money and fewer Master of Pwn points. This blog post walks through our journey from discovery to full exploitation. We start by exploring the Home Assistant device architecture, then detail how we found a remote code execution vulnerability in an add-on. From there, we show how we leveraged it to pivot to the underlying operating system and achieve root-level access. We conclude with our experience at the Pwn2Own 2025 Cork edition. Target Selection We started by looking at several different targets. Our initial list included the Wyze Cam Pan v3 and the Synology CC400W from the surveillance system category, the Brother MFC-J1010DW from the printer category, the Philips Hue Bridge and the Home Assistant Green from the smart home category. After assessing the various targets, we shifted our focus to the Home Assistant Green due to the progress we had made on that platform. This led us to the discovery of an exploit chain that resulted in an unauthenticated remote code execution vulnerability. Device Overview
I've been picking through a SCADA-style telemetry capture and I can't explain what I'm seeing. The file has 14 authorisation records, each with its own CRC. All 14 validate. The file header carries a CRC-32 over the whole block, and that one fails. Two of the operator-name fields are zeroed. My reading is that someone blanked those fields, recomputed the per-record CRCs so they'd pass, and never touched the block CRC. But I'd like a sanity check — is there a corruption mode that breaks a block checksum while leaving every record checksum intact? File (8.8MB): www.[st88openocean.github.io/slip-three/MCA-CTL-0314-RAW.slice](https://st88openocean.github.io/slip-three/MCA-CTL-0314-RAW.slice) Published digests for it are here: www.[st88openocean.github.io/slip-three/archive](https://st88openocean.github.io/slip-three/archive)
Before you build an AI pentesting agent, run it through 5 tests for production readiness. Mark Kuhr breaks down what separates a prototype from a system. The post Build or Buy AI Pentesting? 5 Tests to Judge Production Readiness appeared first on Synack .