Cybersecurity News and Vulnerability Aggregator

Cybersecurity news aggregator

Top Cybersecurity Stories Today

watchTowr • 4h ago
CVE

God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up or bothered to acknowledge them. https://www.citrix.com/blogs/2026-01/security-by-design-proven-by-action-with-citrix-netscaler On Saturday, we took our role in the industry seriously - by rapidly adding credibility to the rumors via the (inter)national authorities that we've historically worked with, and then broadcasting that increased confidence to the watchTowr client base and the public. We made the call that our language needed to be clear: given active exploitation in the wild and the critical nature of many of the organizations that run NetScalers, appliances should be taken offline, and that this was "going to be bad." We we

Cloudflare • 1h ago

Over the last year, agent use of Wrangler has skyrocketed. In March 2026, agents were responsible for a quarter of Wrangler use, up from single-digit percentages the year prior. Last week, agent usage reached 48%. Agents are more prolific users, using almost twice as many distinct commands per day, and are almost four times as likely to use six or more commands. Agents love CLIs. But Wrangler only provides commands for around 280 operations, and Cloudflare offers thousands. Earlier in the year we teased how we were planning to solve this and today, we’re enabling agents to use every Cloudflare product by introducing a new CLI: cf. cf is a CLI that is built for the next generation of software development: Agents can find the command they need to do anything they want to do with bespoke search and steering. JSON is the default interface, pretty printed for humans and condensed for agents for maximum context savings. cloudflare.config.ts is the new configuration format for the whole of Cloudflare, starting with Workers, and bringing the safety and accuracy of TypeScript to you and your agent’s language server protocol (LSP) Vite becomes default, bringing with it the best local development server, and a plugin suite for developers and framework authors. Install the open beta today globally and run it from anywhere: Copy prompt Please update your global agent instructions, so you use Cloudflare's new `cf` CLI. Add the Markdown below to the user-level instructions file that you load in every project – not this repository's AGENTS.md or CLAUDE.md. Use the file for the

Cloudflare • 2h ago
CVE

When VoidZero joined Cloudflare four months ago, we made a commitment to open source, promising that Vite, Vitest, Rolldown, Oxc, and Vite+ will stay open source, vendor-agnostic, and community-driven. As part of Cloudflare’s Birthday Week, where Cloudflare gives back to the Internet, we thought it’d be a good time to check in on how we’ve been doing against this commitment. In the four months since VoidZero joined Cloudflare, we’ve shipped more than 80 releases, closed over 1,200 issues, and landed some big performance improvements, including: Oxc React Compiler , released in August, compiles React.js apps 10x faster Vitest 5 , released in September, is up to 50% faster than Vitest 4 tsgolint is now stable, and is up to 18x faster than ESLint in large codebases Oxfmt ’s JSON, CSS, SCSS, Less, GraphQL, and YAML formatters are now written in Rust, making it 7x faster than Prettier On

Troy Hunt • 8h ago

Presently sponsored by: If an AI agent caused an incident tomorrow, what evidence could you produce? Origin and analyst firm SACR answer it live Oct 1. Register. How's that view?! With NDC Oslo now done, it's a little bit of sightseeing before heading to Denmark for GOTO in Copenhagen for Scott's and my "Cyber-broken" talk. In the meantime, this week is mostly about the ShinyHunters trajectory targeting both Cl0p and the FBI, which does feel a little like a crescendo in their activities. Time will tell, but poking the feds in this way doesn't seem great for your longevity. In my disorganised travel state, I also forgot to touch on a brand new sponsor for this week and the weeks to come: Origin . They build tooling to monitor what your AI agents are doing, which is obviously pretty timely given the current climate. They're running a free CISO briefing on 1 Oct , so go check that out if you think maybe your agents might need some oversight.

The Hacker News • Sep 26

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day

Latest

Monday, September 28
Krebs on Security • Just now

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters . In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p . According to three sources familiar with the matter, the Dutch man arrested by authorities this month is Pepijn van der Stap , a convicted cybercriminal from Almere and Leylstad in the Netherlands. Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between €1.5 million and €2.7 million. At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle “ Umbreon ” to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached. By day, however, van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian , while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research group.

r/cybersecurity • Just now
AI

Hi all I’m looking to get an AI certification along with practical experience in doing so. Does anyone have any recommendations around current / up-to-date certifications & material? I have found a below course from TCM. Looks decent, however any feedback or alternatives from the community very much welcome!! https://certifications.tcm-sec.com/papa/

Cloudflare • Just now

When we launched Vinext in February, it was the result of an audacious week-long AI-driven experiment to see how far one engineer, and a stack of tokens, could get to replicating the NextJS framework backed by Vite. In the seven months since that experiment, Vinext has grown into a framework that our customers trust and run in production for high-traffic, dynamic applications. Today we are announcing the release of Vinext 1.0, the latest step on our journey to make it possible to deploy Next.js apps anywhere. Vinext lets you take any Next.js application, whether it was built for the Pages or App Router, and make it portable to be deployed to any web platform, including the Cloudflare Workers free plan, Netlify, or AWS Lambda. Vinext 1.0 brings with it sweeping improvements to compatibility, stability, and caching behaviors, and sets the project up for the long term. There’s never been a better time to take your Next.js project and convert it to Vinext; just run npx vinext check and npx vinext init . Graduation to 1.0 On release Vinext was promising, but it was incomplete. Since then, we’ve spent a lot of time both improving App Router compatibility and expanding that to Pages Router apps — which we’ve learned many customers are longtime fans of, with large applications that are complex to migrate. We didn’t want Vinext to be a tool that only worked for people using the latest App Router features. Our focus has been on adopting both these routers, and watching our test compatibility closely, which for most important customer-requested features now surpasses 99%. This improvement has been fueled through the community around our GitHub project . As soon as Vinext launched, th

Cloudflare • 1h ago

Over the last year, agent use of Wrangler has skyrocketed. In March 2026, agents were responsible for a quarter of Wrangler use, up from single-digit percentages the year prior. Last week, agent usage reached 48%. Agents are more prolific users, using almost twice as many distinct commands per day, and are almost four times as likely to use six or more commands. Agents love CLIs. But Wrangler only provides commands for around 280 operations, and Cloudflare offers thousands. Earlier in the year we teased how we were planning to solve this and today, we’re enabling agents to use every Cloudflare product by introducing a new CLI: cf. cf is a CLI that is built for the next generation of software development: Agents can find the command they need to do anything they want to do with bespoke search and steering. JSON is the default interface, pretty printed for humans and condensed for agents for maximum context savings. cloudflare.config.ts is the new configuration format for the whole of Cloudflare, starting with Workers, and bringing the safety and accuracy of TypeScript to you and your agent’s language server protocol (LSP) Vite becomes default, bringing with it the best local development server, and a plugin suite for developers and framework authors. Install the open beta today globally and run it from anywhere: Copy prompt Please update your global agent instructions, so you use Cloudflare's new `cf` CLI. Add the Markdown below to the user-level instructions file that you load in every project – not this repository's AGENTS.md or CLAUDE.md. Use the file for the

Cloudflare • 1h ago

If you work in technology, you’re probably reading this on a powerful laptop or flagship mobile on robust, lightning-fast Wi-Fi. This is fantastic for building software, but often is far removed from the reality facing many who are using that software. End users might be nursing a four-year-old budget phone, running low on battery, on a data plan that throttles after 2 GB, living with under-invested public infrastructure, or even just walking into that corner of the gym where the Wi-Fi never seems to work. Multiply this by billions of people around the world and the gap between “works on my machine” and “works for everyone” starts to widen, distorting critical decisions regarding our technology choices and priorities. Closing the perception gap with objective data is central to our mission of helping build a better Internet, one that's fast and accessible to everyone, not just those of us using the best hardware. That’s why today, we’re sharing a view that offers insight on how real people experience the web, by publishing the Cloudflare BEACON dataset — B rowser E xperience A cross C loudflare's O bserved N etwork. Cloudflare has collected this kind of telemetry for years on behalf of our customers, giving them a customer-specific, detailed understanding of how real users experience their sites. Today, we're opening that view up to everyone. BEACON is an anonymized dataset built from billions of real-world performance measurements across 10,000 of the largest websites on our network. It covers every major browser engine, is updated daily in Google BigQuery, and uses standards defined by the community-led RUM Archive , a publicly available Real User Monitoring (RUM) database. By expanding the footprint of that

The Hacker News • 1h ago

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing

Cloudflare • 2h ago

Today we’re introducing Forge , a fresh approach to generating SDKs, CLIs, docs, and libraries. Forge is an open source, pluggable generation pipeline that anyone can deploy and run for free. Forge is early in its life, but already generates the output required for the cf CLI , and over the next few months will power Cloudflare’s API documentation, SDKs, and much more. We built Forge because we needed it ourselves in order to treat agents as our customers. Now, we’re open sourcing it because we think everyone should be able to generate all the surfaces that agents need. It used to be that only developer products needed CLIs, API SDKs, MCP servers, all with great corresponding docs. Now these are table stakes for every product. Our API outgrew our generators Cloudflare’s API has over 3,500 operations, and the hundreds of services that power these APIs are written in many languages, including Rust, Go, TypeScript, and Python. As we embarked on building a CLI for the entire Cloudflare API, including our SDKs and API docs, we needed a code generation pipeline that could handle this scale. That pipeline needs to be flexible enough to work across languages and the ways each of our engineering teams operate. We needed a way to reduce coordination overhead between teams. When a Cloudflare product team makes an API change, they need to be able to use a preview build of the Cloudflare-wide CLI, SDK, and docs site that will be generated, before merging that change and shipping to customers. We needed a way to ensure they didn’t inadvertently break the generation pipeline. And we needed a system that we could extend to generate more than just an SDK, from Cap‘n Web to MCP and beyond. We’ve tried several hosted products that attempt to solve this

Cloudflare • 2h ago
CVE

When VoidZero joined Cloudflare four months ago, we made a commitment to open source, promising that Vite, Vitest, Rolldown, Oxc, and Vite+ will stay open source, vendor-agnostic, and community-driven. As part of Cloudflare’s Birthday Week, where Cloudflare gives back to the Internet, we thought it’d be a good time to check in on how we’ve been doing against this commitment. In the four months since VoidZero joined Cloudflare, we’ve shipped more than 80 releases, closed over 1,200 issues, and landed some big performance improvements, including: Oxc React Compiler , released in August, compiles React.js apps 10x faster Vitest 5 , released in September, is up to 50% faster than Vitest 4 tsgolint is now stable, and is up to 18x faster than ESLint in large codebases Oxfmt ’s JSON, CSS, SCSS, Less, GraphQL, and YAML formatters are now written in Rust, making it 7x faster than Prettier On

Cloudflare • 2h ago

In August, we introduced Kitesurf, a browser for the agentic age that runs entirely on Cloudflare Workers. We built it around what agents need from the web, rather than carrying all the features and bloat of a browser designed for humans. If this is the first you’re hearing about it, we highly recommend you read the blog post where we introduced Kitesurf , for all the juicy technical details of how we did it. Since then, we’ve put Kitesurf through increasingly realistic tasks and used internal and external feedback from customers to make it more capable and more efficient. Here’s what has changed, how you can try it today, and where we’re going next. WebMCP support Websites were not built for agents to use. Browsing today is a messy process of clicking pixels and hoping the right element loads. In a programmatic world this is slow and fragile. WebMCP helps by allowing developers to expose site functionality directly to agents, where they can call functions like searchFlights() instead of simulating clicks. Cloudflare has been supporting WebMCP since its early days; just a few weeks ago we announced that site owners can now turn on WebMCP with one switch , so browser agents can discover and use tools on their sites without changing the site’s code, and Browser Run has been supporting WebMCP when using Chrome beta for some time now. Today we are announcing that Kitesurf n

Cloudflare • 2h ago
CVE

When we introduced EmDash on April 1 as the “spiritual successor to WordPress”, the buzz was hard to ignore. Walking around a WordPress conference that month, we couldn’t walk far without hearing murmurs about EmDash from fellow attendees. But alongside the excitement and curiosity has been a seed of doubt among some in the industry. Was this just an April Fools’ joke? It was not. Today, we are releasing EmDash 1.0: a stable, free, and open source CMS built on Astro, ready to power a production website, your agency’s vibe-coding platform, or your hosting company’s site-building experience. Developers build with Astro, editors manage content through the EmDash admin, and agents can work through the API, CLI, or built-in MCP server. EmDash 1.0 brings those pieces together with production-tested editorial, media, localization, migration, and deployment workflows. We are also launching a decentralized plugin registry that lets developers publish without handing ownership of their identity or releases to a central marketplace, while site owners can discover and install their plugins directly from inside EmDash. The road to 1.0 Since EmDash's first beta, developers have launched real websites with it. Even so, we kept hearing a reasonable response: “This looks interesting. Let me know when it is 1.0.” Before relying on EmDash for their sites, they wanted confidence that it was stable, secure, that upgrades would protect their content, and that we are fully committed to maintaining it. EmDash 1.0 is our answer to that. For the past five months, we have worked with contributors and production users on the parts of the CMS that every site depends upon: data safety, database migrations, editorial workflows, localization, plugin security, performance, and the reliability of the admin, API

Cloudflare • 2h ago
CVE

Today we’re announcing the first public experimental preview of a feature to better support native Rust code and even Tokio-based applications just running natively on Workers: first-class support for the Emscripten wasm32-unknown-emscripten Rust compiler target on the wasm-bindgen open source toolchain and Cloudflare’s Rust Workers. wasm-bindgen is the open source toolchain powering Rust-based WebAssembly applications on our V8-based Workers Runtime. Enabling the Emscripten target for wasm-bindgen has been a long-term effort, first initiated by Google over a year ago, and then further reviewed and supported by the Cloudflare engineers maintaining wasm-bindgen. While still in pre-release, we’re excited to share the new workflow possibilities this work enables in running native wasm-bindgen Rust applications with Emscripten on the web, Node.js , and on Cloudflare’s global Workers platform. In testing we’ve been able to see significantly improved library compatibility for Rust Workers. To illustrate the sort of capabilities supported, we were able to get a Rust-native Minecraft server (Pumpkin) running inside of a Durable Object with TCP ingress, using real TCP sockets via Tokio. See the end of this post for a full description of this port. Emscripten is an open-source WebAssembly compiler toolchain initially created by Mozilla and currently maintained by Google engineers, which makes it possible to run and bridge native code with the web platform, including supporting and virtualizing platform features such as timers, file system operations, sockets, and other native functionality. Since Cloudflare Workers supports Web Platform APIs and Node.js compatibility, we are a

r/cybersecurity • 2h ago

I was working through a lab around ransomware discovery and one question kept coming up: When you see SoftPerfect NetScan (or Advanced IP Scanner) on a workstation, is that enough on its own, or do you need more context before treating it as real ransomware discovery? One thing that changed my triage: the same tool can run as the GUI or headless (`advanced_ip_scanner_console.exe`, `netscan.exe /hide /auto`). Which binary ran is a hint about whether someone was on a desktop or a script ran it. I made a video on how I triaged that from the defender side using MDE telemetry and KQL, plus the same sweep in Elastic ES|QL. Video: [https://www.youtube.com/watch?v=Iun8zko6EZk](https://www.youtube.com/watch?v=Iun8zko6EZk) **The goal was simple: move from "IT scanning the network" to "someone is running discovery on this host."**

r/cybersecurity • 3h ago
CVE

This sounds stupid at first, you could never memorize your passwords, until you use password managers. I don't think anyone with a password manager memorizes their passwords anyways, so why not make it the absolute hardest password to guess? (By unicode characters and symbols, i mean everything listed here [https://symbl.cc/en/unicode-table/](https://symbl.cc/en/unicode-table/) ) But seriously think about it for a sec, even just 3 unrelated unicode characters would be insanely hard to crack. Imagine 20 character strings of this shit. And plus, not only does it make YOUR OWN password unimaginably hard to crack, it also makes everyone else's passwords unimaginably hard to crack (As now cybercriminals have to account for an absurd amount of extra characters, so generating guesses over and over would never work, and if they limit themselves to just the latin characters and numbers for generating guesses to speed it up, they'll never get **your** password or any password that contains any other unicode character.) I think this would mess with encryption a little bit, but with the level of security this offers it is 100% worth it. On no online calculator I found could 2 to the power of 170,000 even be calculated. AFAIK this means just **TWO CHARACTERS** of this password would be absolutely baffling to even guess. I might be wrong, I'm no mathematician, but even if I am, guessing a 20 character password with latin letters, numbers, and special characters is already hard enough. Now add like 170,000 extra characters. This would completely eliminate any threat of brute force attacks mind you, AFAIK if this was applied then the only way to get someone's password is to dig through servers that have the password or just find their computer unlocked and unsupervised. Also, I know what you're probably gonna say, "It's not necessary" or "It's overkill" or even "A (x) character password with regular ol' letters, numerals, and special characters is more than enough". And while you're 100% right, I'm trying to consider the future. Think about how fast technology has evolved these past few decades, a sever the size of a fucking room is outbest by a micro ssd smaller than your fingertip **AND IT'S NOT EVEN CLOSE!** Who knows what cybercriminal tech could be bullshitted up in a decade or two? I'm not really sure how to end this text since i've already talked about every pro about this soo...

The Hacker News • 4h ago

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through

watchTowr • 4h ago
CVE

God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up or bothered to acknowledge them. https://www.citrix.com/blogs/2026-01/security-by-design-proven-by-action-with-citrix-netscaler On Saturday, we took our role in the industry seriously - by rapidly adding credibility to the rumors via the (inter)national authorities that we've historically worked with, and then broadcasting that increased confidence to the watchTowr client base and the public. We made the call that our language needed to be clear: given active exploitation in the wild and the critical nature of many of the organizations that run NetScalers, appliances should be taken offline, and that this was "going to be bad." We we

r/blueteamsec • 5h ago

Reference: https://nvidianews.nvidia.com/news/open-agent-safety-platform Nvidia launched their Open Agent Safety Platform this morning, relying on an out-of-band DPU (Sentry on BlueField) to achieve what they call "millisecond-scale quarantine" for autonomous agents. For defensive engineering and blue teams looking at runtime agent containment, the architectural contrast between their hardware approach and an in-line kernel approach is worth breaking down: The DPU Approach (Nvidia): Moving the enforcement layer physically out-of-band to a DPU is excellent for surviving a total host-kernel root compromise. However, it relies on telemetry crossing the PCIe bus to evaluate policy. In compute time, a millisecond is an eternity—more than enough time for a rogue agent to successfully exfiltrate a small payload or drop a persistence mechanism before the DPU severs the connection. The In-Line Kernel Approach (eBPF): In my recent preprint (Hard Stop, arXiv: 2609.29808), we evaluated an alternative software-only approach. By hooking security\_bpf and security\_file\_open via eBPF LSM at the syscall boundary, you achieve sub-5-microsecond preemption. Because it operates synchronously in-line, it intercepts and denies the action before the kernel processes the call, achieving zero-leakage containment without waiting on hardware bus round-trips. Nvidia’s platform is a strong validation of the need for non-bypassable agent containment, but it couples security to proprietary silicon. If you strictly isolate worker namespaces and cgroup boundaries, kernel-level preemption provides deterministic zero-leakage isolation orders of magnitude faster on commodity Linux hardware. Preprint: https://arxiv.org/abs/2609.29808 Repository: https://github.com/joseluispino/hardstop

The Hacker News • 6h ago

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations

Troy Hunt • 8h ago

Presently sponsored by: If an AI agent caused an incident tomorrow, what evidence could you produce? Origin and analyst firm SACR answer it live Oct 1. Register. How's that view?! With NDC Oslo now done, it's a little bit of sightseeing before heading to Denmark for GOTO in Copenhagen for Scott's and my "Cyber-broken" talk. In the meantime, this week is mostly about the ShinyHunters trajectory targeting both Cl0p and the FBI, which does feel a little like a crescendo in their activities. Time will tell, but poking the feds in this way doesn't seem great for your longevity. In my disorganised travel state, I also forgot to touch on a brand new sponsor for this week and the weeks to come: Origin . They build tooling to monitor what your AI agents are doing, which is obviously pretty timely given the current climate. They're running a free CISO briefing on 1 Oct , so go check that out if you think maybe your agents might need some oversight.

r/ReverseEngineering • 8h ago

To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have better luck on the [Reverse Engineering StackExchange](http://reverseengineering.stackexchange.com/). See also /r/AskReverseEngineering.

r/cybersecurity • 9h ago

Solved this years GrrCon badge the other day and wrote it up. Hope you enjoy! I put the firmware on Github too: [https://github.com/securekomodo/grrcon-2026-badge-firmware](https://github.com/securekomodo/grrcon-2026-badge-firmware)

Sunday, September 27
Cloudflare • 22h ago

This week Cloudflare celebrates our 16th birthday. Like many 16-year-olds, we find ourselves looking around at the world we grew up in and feeling caught between the past and future. Also like many 16-year-olds, we look at all the change in the world and sometimes see risk. But, on balance, we come out incredibly optimistic for what lies ahead. What drives our optimism and fear is a recognition that change involves disruption. The Internet is changing more today than at any point since Cloudflare launched back on September 27, 2010. Some of that change seems undoubtedly good. Some of it is upending the way we think the Internet works. One significant change is the rate of growth of the web itself. From 2012 through 2025, the web plateaued and by some measures even shrank. That changed in mid-2025 when there was an explosion of new websites. The popular narrative is that growth has been driven by AI "slop." And, while there is some of that, that's not the majority of what we see. Instead, AI has unleashed a new cohort of creators. Individuals with ideas but without coding skills who, aided by so-called "vibe coding" tools, are able to bring new creations to life. We're proud that the majority of these tools have Cloudflare's developer platform as their preferred deployment target. Technology at its best allows more people to express their creativity. We have front row seats to watch students around the world building apps to solve real world problems. Startups with new business ideas getting built in record time. Today more than 7 million developers are building the future on Cloudflare’s developer platform. The last year has also changed in terms of who — and increasingly what — is using the Internet. We originally forecast that automated traffic would pass human traffic in the second half of 2027. The rise of agents and AI crawlers pulled that date forward to May of 2026

r/cybersecurity • Sep 27

The editors at CISO Series present this AMA. This has been a long-term partnership between r/cybersecurity and the CISO Series. This month, CISO Series has assembled a panel of accomplished security leaders who have built and led many security teams over their careers. They are here to help you level up your own career and to answer your questions about growing in your current role, moving into leadership, hiring and managing teams, and everything in between. This week's participants are: * Mathew Biby, ([u/RelativeWolf](https://www.reddit.com/user/RelativeWolf/)), director of cybersecurity, TixTrack * Joshua Scott, ([u/threatrelic](https://www.reddit.com/user/ThreatRelic/)), CISO, Hydrolix * Janet Heins, ([u/JBossOnTheLake](https://www.reddit.com/user/JBossOnTheLake/)), former CISO, ChenMed * Jim Bowie, ([u/IllustriousLadder211](https://www.reddit.com/user/illustriousLadder211/)), healthcare CISO, Zscaler * Tomás Maldonado, ([u/tomas\_mald](https://www.reddit.com/user/tomas_mald/)), CISO, NFL * Roland Toussaint, ([u/AutoExec-exe](https://www.reddit.com/user/AutoExec-exe/)) head of information security, ChenMed [Proof Photos](https://imgur.com/a/1ObkreS) We addressed career questions like these at Black Hat. This recent video from CISO Series ([https://youtu.be/YwG0WmK6Tv4](https://youtu.be/YwG0WmK6Tv4)) asks seasoned professionals how they'd approach a career in cyber today. It's a great companion to this AMA, with perspective on how careers in security are changing in the AI era. Editor's note: This AMA is focused on leveling up for people already working in security, not on getting your first job in the field. Per r/cybersecurity rules, "how do I break in" questions may be removed by the mods, so please keep questions focused on career growth, leadership, and building teams. This AMA will run all week from 09-27-2026 to 10-02-2026. Our participants will check in over that time to answer your questions. All AMA participants were chosen by the editors at CISO Series (/r/CISOSeries), a media network for security professionals delivering the most fun you'll have in cybersecurity. Please check out our podcasts and their weekly Friday event, Super Cyber Friday, at[ cisoseries.com](http://cisoseries.com/).

r/blueteamsec • Sep 27

Hey Folks, I pushed an update to DFIR-Companion. It’s a local AI assistant for forensic investigations. You feed it the outputs from the tools you already use, and it helps turn all of that into something you can actually work with: a timeline, leads to follow, findings to validate, and eventually a report. Here’s what it does today: * Pulls imported evidence into one forensic timeline. It detects the format and uses deterministic parsing rules before AI gets involved. * Highlights findings, maps them to MITRE ATT&CK, and connects activity across different sources. * Extracts IOCs and can enrich them with sources such as VirusTotal and AbuseIPDB. * Builds an asset ↔ IOC graph, as well as a separate view of logins across systems. * Helps answer the questions that usually come up in an investigation: initial access, lateral movement, privilege escalation, and so on. * Lets you ask plain-English questions about the case. * Exports reports to PDF, Word, Markdown, or CSV. * Can compare the output of two models, with an optional third model acting as a tie-breaker. * Includes JEV support to surface events the primary model may not have considered relevant. * Can run recommended artifact bundles on Velociraptor endpoints and pull the results automatically or manually. This is not meant to replace Sigma, YARA, Suricata, or the rest of your detection stack. Those tools keep doing their job. DFIR-Companion is for the next step: taking all the alerts, artifacts, and tool output and helping you make sense of the case. It runs locally, the evidence stays on your disk, and you choose the AI provider and model. Love to hear your feedbacks 🙏 Repo: [https://github.com/hasamba/DFIR-Companion](https://github.com/hasamba/DFIR-Companion) Landing page: [https://hasamba.github.io/DFIR-Companion/](https://hasamba.github.io/DFIR-Companion/) Demo server (please read the instructions first): [https://killercoda.com/dfir-companion/scenario/killercoda](https://killercoda.com/dfir-companion/scenario/killercoda)

r/netsec • Sep 27

A technical audit evaluating the security defaults of 15 official Helm charts used for AI serving, vector databases, and Model Context Protocol (MCP) agents (including KubeRay, vLLM, LiteLLM, Qdrant, Weaviate, and Flux159 MCP). Key findings from static manifest analysis and live single-pod lateral movement probes on a test cluster: * Plaintext Secret Handling: LiteLLM database migration Job embeds raw database passwords in container environment variables (F-13). * Unauthenticated Remote Code Execution: KubeRay defaults accept unauthenticated job submissions via HTTP, running commands inside a container with passwordless sudo access. * Over-privileged Agent Access: Flux159 Kubernetes MCP server mounts a ClusterRole with cluster-wide Secret read and pod exec permissions, exposed without an authentication token over HTTP. * Static Scanners vs CRDs: Standard static analysis tools (Checkov, Trivy, Kubescape) failed to inspect pods nested inside Custom Resource Definitions like Ray clusters. The paper documents reproducible test commands, network capture logs, and remediation Helm snippets. Scrubbed raw probe logs and results tables are available on GitHub: [https://github.com/Sorami-Consulting-AU/ai-kubernetes-helm-chart-security](https://github.com/Sorami-Consulting-AU/ai-kubernetes-helm-chart-security)

Saturday, September 26
The Hacker News • Sep 26

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

The Hacker News • Sep 26

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day

The Hacker News • Sep 26

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to

The Hacker News • Sep 26
CVE

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions

The Hacker News • Sep 26

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint

The Hacker News • Sep 26
APT

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief

Friday, September 25
Krebs on Security • Sep 25
CVE

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims. One of several selfies from the Facebook page of Cameron Wagenius. Cameron John Wagenius , 22, was stationed at a U.S. Army base in South Korea when he adopted the cybercriminal persona “ Kiberphant0m .” Working with three alleged co-conspirators, Kiberphant0m downloaded data from several large customers of the cloud data storage service Snowflake that had exposed credentials and did not enforce multi-factor authentication (Snowflake has since mandated MFA on all accounts). In October 2024, Kiberphant0m bragged on the cybercrime forums that he’d stolen the call and text metadata (e.g. source and destination number, timestamp, duration, etc.) for tens of millions of AT&T customers. Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data. In late November 2025, KrebsOnSecurity warned that Kiberphant0

CERT/CC • Sep 25
CVE

Overview Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned content that bypasses sanitization. Successful exploitation could allow the attacker to execute arbitrary JavaScript within the application's WebView context and compromise the confidentiality and integrity of user data, including access to stored documents, credentials, and session tokens. Description Readwise Reader from Readwise is designed to provide a unified read-it-later service that helps individuals collect and organize articles, newsletters, videos, and other content of interest into a single reading interface. It is available on multiple platforms including Android and can synchronize content across devices. CVE-2026-18311 : A stored cross-site scripting (XSS) vulnerability in the header rendering component in Readwise Reader for Android version 8.7.2 allows remote attackers to execute arbitrary JavaScript via crafted document metadata fields. The header rendering component is impacted due to insufficient HTML escaping of metadata fields such as 'doc.author' and 'doc.title', which allows malicious scripts to be stored in the user's library and synchronized to Android devices where they are executed in the WebView context. CVE-2026-18312 : A stored cross-site scripting (XSS) vulnerability in the WebView URL construction logic in Readwise Reader for Android version 8.7.2 allows remote attackers to execute arbitrary JavaScript via malicious URL metadata. The WebView URL construction for X (formerly Twitter) video fallback and iOS paywall messages is impacted due to improper escaping of URL metadata before interpola

The Hacker News • Sep 25

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

Cloudflare • Sep 25
APT

In 2023, Cloudflare declared itself free from CAPTCHAs with the launch of Turnstile, our privacy-first client-side challenge. Turnstile is free to use, works on any site (no need to proxy traffic through Cloudflare), and never asks a visitor to solve a puzzle. Now, we are launching Turnstile Spin, an agent-mediated end-to-end implementation of Turnstile. Initially built with developers in mind, Turnstile requires a basic two-step implementation and understanding of frontend and backend development. First, you modify your frontend code to render the Turnstile widget; this allows Cloudflare to run the client-side challenges and issue a token. Second, you POST the token to our Siteverify API, which verifies the token and returns metadata about whether the visitor passed or failed the challenge. You can then act on this decision, like gating the login button until the visitor successfully solves a Turnstile challenge. Turnstile now processes about three billion verifications on a typical weekday, and in one recent week more than 23,000 accounts created a new widget in the Cloudflare dashboard. This rapid adoption pushed us to evaluate how we can help users achieve full Turnstile validation seamlessly. Turnstile was built for developers, but demand for simple bot protection reaches far beyond people who write backend code every day. AI raises the stakes: it helps more people build applications, while giving attackers more ways to automate abuse. We wanted the same technology to make Turnstile easier to install correctly. Turnstile Spin is our implementation of this new capability. You can use it to create the widget, embed it on your site, and embed Siteverify to relevant functions in your backend, just as you would manually. Spin also fixes improperly installed widgets and handles migrations from other CAPTCHA provi

The Hacker News • Sep 25

Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like this. An attacker lands on a low-privilege cloud account, and the first try at privilege escalation goes nowhere. That dead end used to cost hours of documentation reading,

r/Malware • Sep 25

1. Infostealers are more focused on session tokens, cookies, recovery codes, cryptowallet data that allows them to take over rather than the traditional password compromises. 2. Malicious LNK (shortcuts) still remain a popular entry point to compromises, as they allow malicious code execution 3. Large increase in abuse of legitimate platforms or impersonation - SEO poisoning, malvertising, fraudulent codesigning and compromises of npm packages, VSCode extesnions 4. Supply chain attacks! Threat actors increasingly target software delivery channels like npm packages, PyPI, [Crates.io](http://Crates.io), and CI/CD publications to include malware. 5. Abuse of RMM tools continues & increases consistently! Initially, a signed tool with low detection ratio may seem legitimate, but remote management software such as ScreenConnect, Action1, Atera are vulnerable to abuse. 6. A large increase was found in legitimate sites spreading ClickFix attacks. This can be done by numerous reasons - administrator account compromise, weak password security, unpatched vulnerabilities in website building platforms (such as WordPress) that allow threat actors to take over the website and host malicious code. 7. Discord, Telegram, GoFile still remain as relevant exfiltration channels. While they do not provide as much flexibility as a regular C2 would, malware can still upload stolen data (passwords, files etc.) to it for the attacker to view. Easy to setup, used to evade detection. If you are interested in intercepting data from a Telegram exfiltration channel that malware uses, check out https://any.run/cybersecurity-blog/intercept-stolen-data-in-telegram/ 8. Dead drop resolvers are still popular! You can use it as an infrastructure layer if necessary to change the configuration. Very popular is abuse of smart contracts, blockchain infrastructure (EtherHiding) but Steam, Telegram or Pinterest profiles are a popular target as well. See full analysis at [https://any.run/cybersecurity-blog/h1-2026-cyber-risk-report](https://any.run/cybersecurity-blog/h1-2026-cyber-risk-report)

Trail of Bits • Sep 25

Threshold signature schemes, a form of multi-party computation (MPC) that lets a set of parties sign together without any one of them holding the key, are increasingly deployed inside trusted execution environments (TEEs). The combination is intended to amplify security for sensitive computations: MPC distributes trust across multiple independent parties, while TEEs root trust in the hardware manufacturer and its attestation infrastructure. But subtle issues can arise when running an MPC protocol inside a TEE without accounting for the untrusted host: for example, a malicious host could roll back the filesystem state after a threshold signer deletes a used pre-signature, causing the signer to reuse their nonce share and disclose their private key share. So is this combination worth it? Provided you treat the TEE as a defense-in-depth layer rather than a substitute for a sound protocol, the answer is yes. This blog post discusses what TEE attestation can and can’t fix in MPC deployments, explores the pitfalls we see most often in audits, and covers best practices, such as incorporating strong attestation processes and binding them to the MPC parties’ identities. MPC: Security that depends on participant behavior Before diving into how TEEs and MPC interact, we need to understand what MPC means and what security guarantees it offers. MPC is a cryptographic technique that allows multiple parties to jointly compute a function over their private inputs without revealing those inputs to each other. The security of MPC protocols depends critically on assumptions about participant behavior. The cryptographic literature uses two primary security models: Semi-honest (honest-but-curious) security : In this model, all participants follow the protocol exactly as specified, but they m

The Hacker News • Sep 25
APT

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain

The Hacker News • Sep 25

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company

The Hacker News • Sep 25

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,

r/netsec • Sep 25
CVE

**(1)** An exposed IOCTL lets unprivileged users disable the x86 [MONITOR](https://www.felixcloutier.com/x86/monitor) & [MWAIT](https://www.felixcloutier.com/x86/mwait) instructions used by [Hyper-V](https://en.wikipedia.org/wiki/Hyper-V) and other kernel components--triggering a HYPERVISOR\_ERROR bugcheck. **(2)** Reaching the IOCTL requires exploiting a [TOCTOU](https://en.wikipedia.org/wiki/Time-of-check_to_time-of-use) bug arguably caused by poor documentation of the [SeLocateProcessImageName](https://learn.microsoft.com/en-us/windows-hardware/drivers/ddi/ntifs/nf-ntifs-selocateprocessimagename) function. **(3)** Reimplementation of the driver's security through obscurity IOCTL encryption scheme: SHA-256 KDF-derived XOR keystream & CRC16 Checksum. See [full write-up](https://connorjaydunn.github.io/blog/posts/argus-monitor-ldos-cve-2026-79417/), and [Github](https://github.com/connorjaydunn/CVE-2026-79417) for PoC.

Thursday, September 24
CERT/CC • Sep 24
CVE

Overview ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise. Description ViewSonic ViewBoards are widely used smart display devices (smartboard), typically deoloyed in enterprise and educational environments. vCast is ViewSonic’s proprietary software suite for wireless connection between smartboards, which are Android-based systems, and devices running a client application. Three distinct vulnerabilities, all invoking unauthenticated endpoints, have been identified within the vCast suite. CVE-2026-82989 vCast’s media streaming service allows a remote attacker to exfiltrate JPEG images of screen content via GET requests to an unauthenticated /snapshot or /screen API endpoint. CVE-2026-82988 vCast’s Android Package Kit (APK) delivery mechanism allows a remote attacker to trigger unprivileged file installation by providing a malicious APK URL through an unauthenticated download endpoint. CVE-2026-82987 vCast’s network services allow a remote attacker to inject arbitrary input into service endpoints via HTTP requests to exposed unauthenticated endpoints Impact An unauthenticated attacker can chain these vulnerabilities via a shared network to deliver and execute arbitrary code on a vCast-based device without user interaction. Potential device-level impact includes unauthorized access to displayed content, persistent installation and execution of arbitrary applications, and full compromise of the device. Additionally, an exploited device’s connected network may be prone to lat

The Hacker News • Sep 24

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not

r/Malware • Sep 24

**Tl:dr** * **Blackpoint’s Adversary Pursuit Group (APG)** identified two previously undocumented .NET malware components delivered together through a ClickFix chain: **RemotePanel**, a persistent remote access platform, and **BoundSiphon**, a credential and cryptocurrency stealer.  * RemotePanel establishes persistence by masquerading as the Windows Time service and gives operators broad control over infected systems, including PowerShell, file and process management, screen access, modular HVNC, and fleet management.  * RemotePanel uses a BNB Smart Chain contract to resolve its active Command and Control (C2) server, allowing operators to rotate infrastructure without rebuilding or redeploying the RAT.  * BoundSiphon runs primarily from memory and targets browser credentials and sessions, cryptocurrency wallets, password manager data, and selected documents, including secrets protected by Chromium App-Bound Encryption.  * APG identified strong code and build overlap between BoundSiphon and a stealer [previously documented by Socket](https://socket.dev/blog/5-malicious-nuget-packages-impersonate-chinese-ui-libraries), linking the sample to an earlier stealer codebase or builder lineage.  * **APG is seeking additional research and samples tied to RemotePanel, BoundSiphon, the AntiSNG implementation, Socket linked stealer activity, and the BNB Smart Chain resolver to help connect the remaining lineage and infrastructure gaps.**  * RemotePanel and BoundSiphon reflect a broader shift toward modular malware ecosystems that separate persistent access from data theft, allowing operators to replace infrastructure and individual components while retaining the underlying capabilities needed to continue an operation.  * For victims, a single successful infection can lead to persistent remote access and theft of credentials, browser sessions, cryptocurrency wallets, password manager data, and other sensitive information, increasing the risk of account takeover, fraud, and continued compromise.  * Blackpoint has detections in place for key behaviors across the infection chain, providing coverage even as individual payloads and infrastructure change. 

CERT/CC • Sep 24

Overview Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identification (RFID) device to grant unauthorized entry to areas secured by these controllers. Description Norwegian Cruise Line is a global cruise company that operates a modern fleet sailing to destinations worldwide. As described in CVE-2026-75907 , the affected card reader authenticates NFC credentials only by checking their static 7-byte UID. A UID is not a secret and does not support cryptographic challenge‑response operations, so it cannot serve as a reliable authentication factor. Although the keycard's NTAG212 tag contains a memory block with a printed serial number and a value resembling a signature, the reader does not inspect this data during the access-control process. Validation based solely on UID constitutes identification rather than authentication. Because the credential performs no cryptographic exchange and offers no defense against cloning, any device capable of replaying or emulating UIDs can reproduce a functioning keycard. Impact An attacker with brief physical proximity to a valid keycard can use an RFID reader to capture the UID without interacting with or altering the card. Once obtained, this UID can be copied to an inexpensive UID‑writable card to create a permanent duplicate credential. The access control readers will accept these forgeries as genuine, granting entry. Depending on logging configuration, the unauthorized entry may be indistinguishable from legitimate use. Because unauthorized access to restricted areas on a cruise vessel can have direct safety implications, this vulnerability presents a significant security risk to both internal operations and guest

The Guardian • Sep 24

Former deputy PM now involved in tech industry says many within sector are ‘winding themselves up into a lather’ Nick Clegg has dismissed fears over AI’s “godlike power to exterminate humanity”, calling it a sign that tech bosses are “breathing their own fumes”. The former UK deputy prime minister said that tech bosses should focus on addressing known specific threats such as cybersecurity and bioweapons rather than the “slightly hand-wavy view that this technology is unavoidably going to develop some godlike power which is going to turn on us and exterminate humanity”. Continue reading...

Wednesday, September 23
watchTowr • Sep 23

Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it’s a free-for-all (unless you’re trying to buy RAM). Unfortunately, while we're all finding more vulnerabilities and flexing obfuscated stack traces… (or emoji-ridden HTTP requests that are actually complete slop and not real, and please, for the love of god, no, those slop-ridden payloads appearing in your access_log are not proof of exploitation jesus wept, it’s becoming traumatic) …on many social media networks, some things have remained reassuringly steadfast: the vendors and their struggle to seemingly care about the security of your network. Yes, that’s right - it’s time for more Secure by Design jokes. Welcome back to another watchTowr Labs blog post. We’ve missed you (admit you’ve missed us, please).

r/computerforensics • Sep 23

https://www.justice.gov/usao-cdca/pr/tech-ceo-russian-national-arrested-complaint-alleging-they-hid-russian-ownership-and CEO is facing 20 years in prison.

Synack • Sep 23

Security testing and exposure management have run on separate tracks for years, leaving a blind spot between what a scanner flags and what an attacker can exploit. Synack's new integration with Wiz closes that disconnect, feeding continuously validated pentest findings directly into Wiz's exposure management view. The post Unifying Security Testing and Exposure Management: Introducing the Synack and Wiz Integration appeared first on Synack .

CERT/CC • Sep 23

Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509 certificate. Description CVE-2026-82356 Imprivata EAM uses an RSA key pair to generate the X.509 certificate that identifies the appliance to the clinical workstations, Electronic Health Record (EHR) platforms, and shared-device workflows that rely on it for authentication. After reviewing the product documentation and engaging Imprivata support, it was confirmed that no supported mechanism exists to rotate this RSA key pair after deployment. Using a single RSA key pair indefinitely for certificate generation violates cryptographic best practices. Because the key cannot be rotated, an attacker who obtains the private key retains a valid, trusted appliance identity for as long as the deployment remains in service, with no supported means to revoke or replace it short of redeploying the product. Impact An attacker who obtains the private key, for example through backup exfiltration, a hypervisor snapshot, or privileged access to the appliance filesystem, can impersonate the appliance to any endpoint that trusts its certificate. Because Imprivata EAM sits directly in the authentication path, this allows persistent, difficult-to-detect interception of authentication traffic across every application the appliance brokers, including SSO tokens, session assertions, and credentials for EHR and clinical systems. If perfect forward secrecy is not enforced, previously captured traffic can also be decrypted

Synack • Sep 23

Most penetration testing RFPs ask vendors to price "one web application" or "an annual pentest" and leave the rest open to interpretation. This guide gives you a complete penetration testing scope-of-work template, a standard vendor response format, a weighted scorecard, and a pass/fail checklist, so every proposal answers the same questions and gets measured against the same bar. The post Penetration Testing RFP: What to Include and How to Evaluate Responses appeared first on Synack .

Tuesday, September 22
CERT/CC • Sep 22

Overview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash in the UEFI Authorized Signature Database (DB), an attacker with sufficient access could use the application’s direct memory-access capabilities to disable or circumvent Secure Boot enforcement and execute untrusted UEFI code. To mitigate this risk, system administrators should apply available firmware and software updates from affected hardware vendors. Description The Unified Extensible Firmware Interface ( UEFI ) standard defines the firmware architecture used to initialize hardware and transfer control to modern operating systems during system startup. On systems with Secure Boot enabled, UEFI applications and drivers must be cryptographically signed and verified before their execution. Trust for these signatures is managed through several databases, including the Authorized Signature Database (DB), which commonly contains certificates from original equipment manufacturer (OEM) vendors, operating system authorities, and other supply-chain partners in the UEFI ecosystem. There are multiple implementations of the UEFI Shell, and OEM vendors typically sign the implementation that they distribute. Some UEFI Shell implementations expose built-in capabilities for directly manipulating system memory and interacting with the UEFI environment. Because the Shell is vendor-signed and therefore permitted to execute with Secure Boot enabled, an attacker who can launch a vulnerable Shell can use these capabilities to modify the protected pre-boot state and potentially load or execute untrusted UEFI code. This creates a security boundary violation: Secure Boot permit

Cloudflare • Sep 22

The response header, Vary , has been called “ the ugliest part of HTTP that we haven't yet improved. ” The same post describes it as a “horrible, kludgy mechanism” with “pretty abysmal interoperability” across intermediaries. That is usually where sensible engineers back away slowly with their hands raised. That’s not exactly an endorsement of Vary , but ugly doesn’t mean useless. One URL can have more than one correct response. A server might, for example, deliver different image formats to different browsers. If a cache ignores Vary , it risks serving the wrong bytes to a request. But if it treats every raw header value as distinct, a handful of similar requests can spread into thousands of barely reusable cache entries. Vary tells a cache which request fields may affect the response, but it does not tell the cache which differences actually matter. Vary support is now available in Cache Rules on every plan. The origin still names the request headers that may affect a response, but you decide how Cloudflare handles each one. You can normalize known negotiation headers, pass exact values through when those small differences matter, or bypass cache when the variation is too unpredictable. The origin declares what may vary, and you decide how much variation is actually meaningful for the cache. How Vary works Vary is a standard HTTP response header that tells intermediary caches (like Cloudflare) which request fields may affect the response sent by the origin. Sites use Vary to serve d

Heimdal Security • Sep 22

Two things happened last week, one day apart, and almost nobody connected them. On 11 September, the EU Cyber Resilience Act’s vulnerability reporting obligations came into force. Companies covered by the regulation now have to report actively exploited vulnerabilities within 24 hours and provide a fuller notification within 72. On 12 September, Anthropic CEO Dario […] The post Slow is a design principle, not a delay appeared first on Heimdal Security Blog .

Story Overview