The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and no charges have been made public. The
Cybersecurity News and Vulnerability Aggregator
Cybersecurity news aggregator
treemd <(curl -sL https://allsec.sh/md) (as Markdown) Top Cybersecurity Stories Today
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,
Latest
Following last week’s release of Clef and Clef-flash , Cloudflare’s open-weight decision models, we decided to bring forth more gifts. Today, we’re releasing Clef-omni, which takes in audio and video input alongside text and image. We also cut the price of Clef-flash so it is now cheaper than Jev, and we made Clef faster. Although the model game is still early for Cloudflare, innovation and iteration is in our DNA, and we apply these principles to everything we do. In fact, the story of Clef came together over the course of less than a week. We decided we wanted to do something in the decision model space on a Friday evening, trained the model over the weekend, and launched it on Thursday. Even with such a short timeline, we were able to ship performant, high-quality, open-weight models for the community — imagine what more we can do in the future. For today, we’re excited to keep up the momentum with new additions and improvements to our Clef family of models. This is just the beginning, and we’ll continue to get better, faster, cheaper, and more innovative. Clef-omni takes audio, video, image, and text input Our new Clef-omni model is able to take audio, video, image, and text input. This changes the paradigm for decision models, which have been largely text-only since the debut of Jev from TypeSafe. With Clef, we supported images and video frame arrays, but Clef-omni is able to take in audio (wav or mp3) and video (mp4 or webm) alongside text and images. Instead of setting up cascading pipelines of models that transcribe speech-to-text, or splitting audio and image channels from video, you can just call one model to make decisions across any modality. We are now one step closer to a model that is able to interact with the world as we experience it — through audio, visual, and textual communication, all in one. Chec
The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and no charges have been made public. The
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
Before we begin, yes - it's confusing. There are more vulnerabilities with watchTowr IDs in this blog post than there are CVE IDs (assigned by PaperCut), due to PaperCut bundling vulnerabilities and then patch bypasses for those same vulnerabilities into singular CVE IDs. Paper! It still exists. We have to admit it - so much is happening right now (F1, GTA6, breakfast) that we barely have time to lovingly tease our most favoritest vendors. On Thursday, 27 August 2026, PaperCut published an advisory claiming that a mysterious vulnerability was being exploited in-the-wild, leading to system compromise. The watchTowr Intel team has documented the in-the-wild exploitation that our global honeypot network, Attacker Eye, captured here . To add insult to injury, when PaperCut released their advisory, they did so without a patch. Unlike other vendors that struggle to communicate at all, PaperCut provided IOCs in the form of log snippets related to exploitation and temporary mitigations, enabling their customers to take a
Block Kit alerts, threaded conversations with Marcus, and every action tied to a verified Guard identity. The alert that matters usually lands in Slack. Someone sees it, someone else asks what it affects, and a third person opens another tab to find out. Every context switch is time an attacker spends inside the window you are trying to close. Worse, the integrations that bring security data into chat tend to trust whoever is typing. An email address that matches is treated as proof of identity. That is not authorization, and attackers know it. The Guard’s Slack integration used to be a one-way webhook. Marcus replaces it with a real Slack app that delivers alerts, runs conversations in your channels, and ties every request to an authenticated Guard user. Here’s what changed. Install it like a Slack app, not a webhook A Guard admin clicks Add to Slack, completes OAuth v2, picks the target channels, and the app is live. It is a multi-tenant install, so there is no webhook URL to paste into a form and nothing to rotate when someone leaves the team. Channel management is explicit. You map specific Slack channels to your Guard tenant, and a confirmation step runs before the connection is established. You can view every connected channel with its tenant mapping on a per-row basis, and disconnect any of them through a confirmation-gated flow. Nothing quietly starts posting findings into a channel nobody meant to include. Alerts that carry structure Risk transitions, exposure alerts, and emergent-threat notifications now arrive as structured Block Kit messages sent through the bot token. The old webhook payloads were
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name
Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it will fight them in court. TP-Link Systems is based in
Understanding why an application is using more resources than expected, whether that is CPU or memory, can be challenging. Logs and aggregate metrics can only get you so far. Thankfully there is a better way: CPU or memory profiling can show you the exact function where your application is using CPU or allocating memory. Today we are happy to announce support for CPU and memory profiling of Workers and Durable Objects. From the Workers Observability page, you can now request an on-demand CPU or memory profile of an active Worker, inspect it as an interactive flamegraph, and download the profile file for further analysis. This method of profiling gives you a useful perspective into what your code is doing and how you can improve it in a real-world setting. That’s because the best way to understand your application is to profile it in production. To try this on one of your Workers, you have a choice of using the CLI or the Cloudflare Dashboard. To use the CLI, make sure you have the cf package installed , then simply run: To use the dashboard, head to the Cloudflare dashboard and then access the list of Workers on your account by navigating through Build → Compute → Workers & Pages. Select your Worker and navigate to its Observability tab. You can then use the drop down to select “Flamegraph”: You can then request both CPU and memory profiles for your Worker on this page. The duration determines how long the profiler should run for on your Worker. You can also select different versions of your Worker to be profiled. Your Worker needs plenty of traffic to be successfully profiled, so make sure you choose a version that has enough traffic.
Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security
Came across this cool project for domain reconnaissance and OSINT that brings multiple recon modules together in one place. Looks like an interesting tool for anyone working in cybersecurity, pentesting, or security research. Thought I’d share it here for anyone who wants to check it out and give it a try! https://github.com/karim852/KUMO-Domain-Recon-Tool
The Deno team is joining Cloudflare to radically simplify self-hosting Workers and Durable Objects so developers can use the same primitives in more places. For what this means and how it came about, here’s the story from Ryan Dahl, Senior Principal Engineer, and Kenton Varda, Distinguished Engineer.
Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said. "Projects that join will receive thorough, periodic security scans by our strongest models at no cost."
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow
As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls, creating a
*Disclaimer: English isn't my first language. I wrote this in my own words and translated it with AI.* In 10 months of development my SaaS project grew to several VMs and 10+ cloud services around them (GitHub, Cloudflare, Purelymail and so on). Basic hardening, uptime monitoring etc I always do. But I always wanted to see and control more — ideally everything that happens in every component of my infra. I want to know whether someone got access to my server, created an illegitimate GitHub token, or is brute-forcing a database I accidentally exposed to the internet — and ideally I want respond to it automatically. So I started an experiment: building a micro AI SOC for my project. And what I like most is that here I have much more freedom to give AI broad permissions for investigation and response than in the infrastructure of big companies. 𝐇𝐨𝐰 𝐢𝐭'𝐬 𝐛𝐮𝐢𝐥𝐭 𝐚𝐭 𝐭𝐡𝐞 𝐦𝐨𝐦𝐞𝐧𝐭: → Everything lives on one VM with 6 vCPU and 16 GB of RAM. The whole SOC currently uses about 2.4 GB: 1.5 GB for ClickHouse, 0.5 GB for Wazuh, the rest are connectors and services at a few dozen MB each. → 55–75 thousand events a day, about 0.6–0.9 EPS. → Wazuh agents on the servers send events to the SOC. → Wazuh manager collects the logs and generates alerts. Its bundled OpenSearch indexer I dropped — it's too heavy. For storage I use ClickHouse instead. → Wazuh and ClickHouse are connected through a file: Wazuh writes every event to archives.json, Vector reads the file and writes to ClickHouse. On the way Vector filters out the noise. ClickHouse compresses the rest almost 8 times and runs investigation queries fast. → Tiny Python connectors poll the cloud APIs every 10–15 minutes: hosting, Cloudflare, email, GitHub and so on. For a service with no audit log, the connector takes a snapshot of the settings and records what changed. → GitHub webhooks come in through a Cloudflare tunnel. → My own detector periodically runs detection rules on ClickHouse and writes alerts back into a separate table. It's needed because cloud events bypass Wazuh. Unfortunately, I couldn't keep all the detection rules in one place. → A correlator looks at incoming alerts and decides: open a new incident, add the alert to an open one, or not open an incident at all. It also determines urgency. → PostgreSQL keeps the incidents: statuses, participants, timeline and response actions. → A separate service watches that no source goes silent, and messages me only if it can't figure out the reason itself. → All architecture principles and decisions live in a git repository, so the SOC can be reproduced from it. Closed incidents land there as Markdown reports. Full write-up with diagrams (I’m the author): [https://denzuikov.substack.com/p/building-an-ai-soc-for-my-small-projects](https://denzuikov.substack.com/p/building-an-ai-soc-for-my-small-projects)
Hello, I was trying to download a game from [www.ziperto.com](http://www.ziperto.com) and after downloading a file I accidentally run a \~600 Kb .exe (I know, I wanted to hit backspace to delete the folder, instead I hastily pressed enter). I then got a message that the executable was not compatible with Windows. The morning after I've got a notification from my bank about a purchase I didn't make on PayPal, and hundreds of emails in my inbox. I flagged the purchase, changed my passwords, and blocked my card. It seems a strange coincidence with the .exe. I now ran MalwareBytes and Defender deep scan, nothing was found, but I am still paranoid that something is running on my PC. I checked and couldn't find any browser-proxy installed or any strange service or executable, but I am still paranoid. I don't have 2FA on PayPal as I have never use it but I am wondering how they got into my PayPal account from another device, even with the password I usually have to confirm the access from a secondary email. My PC was turned off when the purchase happened. Any idea how this could have happened and what should I check on my PC? I would like to avoid wiping the whole Windows 10 installation.
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability
Brenden Cuni, an ICE supervisor, has been accused of excessive force and tackling a pregnant woman to the ground. Several of his arrests were later found to be unlawful in federal court.
FBI says contractor failed to implement security patch explicitly issued to secure platform Sources identify Accenture as platform manager and Oracle PeopleSoft as breached system Breach exposed job details, addresses and medical records of thousands of FBI employees "WASHINGTON, Oct 5 (Reuters) - The Federal Bureau of Investigation removed an Accenture contractor on Monday over their role in a damaging data breach that exposed sensitive personal details of thousands of bureau employees, two sources familiar with the matter told Reuters. The development comes as the FBI is still trying to ascertain the ramifications of the breach, which some former bureau officials have described as a major blow to the organization's operational security."
**TL;DR:** NVIDIA DCGM Exporter is a widely used monitoring tool that collects GPU metrics like utilization, memory, temperature, and power consumption from AI servers. We discovered that thousands of these monitoring endpoints are exposed to the public internet, allowing anyone to inspect GPU infrastructure. Worse, we found a **high-severity vulnerability (CVE-2026-47483, CVSS 8.2)** that lets unauthenticated attackers exhaust server resources, crash GPU monitoring, and potentially disrupt AI workloads remotely. **A few other interesting findings:** **2,100+ exposed GPU servers**, revealing telemetry from **12,000+ GPUs worth \~$100M**, including H100s, H200s, and Blackwell GPUs. **60% of exposed GPUs reported 0% utilization** across our scans. **12,096 additional servers** exposed infrastructure details, including OS, firmware, and networking information. NVIDIA fixed the vulnerability following our responsible disclosure. Full research: [https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability](https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability)
October 8 security recap: Atlassian exploit attempts, Korean bank intrusions and Denmark’s registry breach
Three stories worth your attention: 1. **Atlassian patch urgency:** Exploitation attempts followed the public release of CVE-2026-21589 research. Patch affected self-hosted products and investigate whether integration credentials were exposed. 2. **AI tools in bank intrusions:** CrowdStrike found evidence of ARTEX and AI coding tools in a campaign against South Korean financial firms. The number of affected organizations remains unconfirmed. 3. **Denmark’s registry breach:** Attackers abused a private company’s legitimate access to obtain personal information from the national registry. Review what external partners can retrieve and how unusual access gets flagged. Read the full breakdown on CyberRecaps.
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that
The meaningful differences between web application penetration testing companies rarely show up on the homepage. They show up in who performs the testing, how the methodology is documented, what the retest policy covers, and how scope changes get priced once a contract is signed. Use the eight-criteria scorecard below to evaluate providers on substance rather than marketing language. The post Web Application Penetration Testing Companies: What Enterprise Buyers Should Compare appeared first on Synack .
ACE .qvm0 keeps RUNTIME_FUNCTION in the VM section tail; recovering entries and hidden jmp-reg edges
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, which takes incident reports, based its October 8, 2026 alert on those reports and other information. The alert names no attacker and no affected organization. JPCERT/
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,
Built a Production-Style SOC Home Lab Over 4 Months (Splunk, Suricata, Zeek, AD, Detection Engineering)
Over the past 4 months, I built a defensive security home lab designed to mirror a small enterprise SOC environment. Everything is documented in the repo below. **Infrastructure:** - 6 VMs in VirtualBox (Ubuntu Server, Ubuntu Desktop, Windows 10, Windows Server 2019 DC, pfSense Firewall, dedicated Splunk SIEM) - Network segmentation: NAT / Host-Only / Internal networks **Security Stack:** - Network Monitoring: Zeek, Suricata, TShark - SIEM: Splunk Enterprise with Universal Forwarders - Network Protection: pfSense + pfBlockerNG - Identity: Active Directory domain for threat simulation - Endpoint: Sysmon, Windows/Linux hardening configs **Documentation:** Each phase has its own folder with architecture diagrams, configs, and troubleshooting notes. Current work includes threat intel integration and purple team testing. **Repo:** https://github.com/MaamarSec/Cyber-Defense-Lab-Portfolio Built this for skill development and as a public reference. Feel free to explore, fork, or adapt. Happy to answer questions!Title: Built a Production-Style SOC Home Lab Over 6 Months (Splunk, Suricata, Zeek, AD, Detection Engineering) Body: Over the past 6 months, I built a defensive security home lab designed to mirror a small enterprise SOC environment. Everything is documented in the repo below. **Infrastructure:** - 6 VMs in VirtualBox (Ubuntu Server, Ubuntu Desktop, Windows 10, Windows Server 2019 DC, pfSense Firewall, dedicated Splunk SIEM) - Network segmentation: NAT / Host-Only / Internal networks **Security Stack:** - Network Monitoring: Zeek, Suricata, TShark - SIEM: Splunk Enterprise with Universal Forwarders - Network Protection: pfSense + pfBlockerNG - Identity: Active Directory domain for threat simulation - Endpoint: Sysmon, Windows/Linux hardening configs **Documentation:** Each phase has its own folder with architecture diagrams, configs, and troubleshooting notes. Current work includes threat intel integration and purple team testing. **Repo:** https://github.com/MaamarSec/Cyber-Defense-Lab-Portfolio Built this for skill development and as a public reference. Feel free to explore, fork, or adapt. Happy to answer questions!
Blackpoint is a well-regarded provider of managed detection and response services to the MSP sector. Founded by former NSA employees, their autonomous containment model is highly effective and helps block attacks fast. But the company’s offerings and approach have certain limitations. If you’re exploring Blackpoint alternatives, this guide is for you. We’ll be looking at […] The post 6 alternatives to Blackpoint for your shortlist appeared first on Heimdal Security Blog .
Radar provides a real-time view into global Internet trends, powered by Cloudflare’s global network. We support Cloudflare’s mission to help build a better Internet by making web data visible, clear, and actionable for everyone. Since launching in 2020 , Radar has found a natural audience amongst expert users with technical backgrounds, such as network operators and academic researchers who rely on Radar data to observe industry trends and global events. But Radar also has the potential to be a more regular, self-serve resource for journalists, human rights advocates and policymakers, and everyday users. Making Radar accessible to a wider audience is a core part of our vision, so we knew it was time to reevaluate the user experience: How could we make Radar more approachable to broader audiences, while preserving the depth and rigor that we currently have? In this blog post, we’ll introduce the redesigned Radar, share our design process, and outline our broader vision for the platform’s future. Challenges with the previous design While the previous landing page was successful at showing the breadth of Radar’s data, the way that information was presented made it difficult to parse. The bento box layout gave everything similar visual weight, the vertical cards disrupted natural reading patterns, and the styling felt disconnected from Cloudflare’s broader brand. We heard this from users. One external user mentioned that one of his biggest frustrations with Radar was that it was difficult to show to his students. That feedback reinforced the problem that Radar could feel intimidating to people encountering it for t
Hello all We have a couple of Windows devices in the past that either had Bitlocker suspended or "Waiting for Activation". The latter is often the case with freshly shipped Windows 11 devices. In those cases, the the volume is encrypted using a clear key protector, see: [https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/planning-guide#bitlocker-provisioning](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/planning-guide#bitlocker-provisioning) There is no active key protector (i.e. no recovery key, no password or anything) that could be extracted. In those cases, we can image the device with for example FTK Imager, but when opening the image, FTK cannot read it. However, when we for example mount it in Windows as a volume in FTK Imager, the whole disk is readable. Does anyone know how to avoid this issue, which tools (e.g. Encase, X-Ways, Autopsy,...) have no issue with reading the E01 or how you typically deal with this? We want to of course avoid changing any setting on the device before acquiring the disk and we would like to directly work on the physical acquisition / E01.
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to
With no accurate Big Tech mapping app to help him, Anas Hattab launched a Telegram group to get himself home at night. Now nearly 350,000 Palestinians rely on it to navigate the occupied West Bank.
Presenting DiagNG: After QCSuper, a new open-source initiative for freeing up mobile baseband Diag protocols
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice
It turns out you can overwrite the Error.prepareStackTrace method with the function constructor. Then, using prototype pollution, you can inject valid JavaScript code to generate arbitrary functions and invoke it using the usual tricks.
For months, GreyNoise recorded almost no Hikvision camera exploit attempts against Ukraine. On Sept 21 activity surged for nine days during Russian strikes, almost all from four IPs, then stopped. We can't say if the two are linked.
At a recent event for security firm NordVPN, NBA superstar Shaquille O’Neal revealed that he got hacked—and warned the public about the need to “have control of their own information.”
Security alerts rarely arrive one at a time. A single alert can cause a spike across the environment, requiring a human analyst to decide which alerts are related and what they mean. When multiple arrive at the same time, it can quickly overwhelm even a seasoned security analyst. Enter the alert paradox. Now, our built-in, multi-AI-agent security operations harness can handle more of this work at Cloudflare scale. Our Cloudflare Managed Defense AI agent harness speeds up the process of gathering data, connecting and aggregating detections, and accounting for missing sources while new alerts continue to arrive. To further analyze context, we make use of the OpenAI Daybreak Defense Network and our partnership with Anthropic. Cloudflare uses approved OpenAI Daybreak and Anthropic models, including GPT-5.6 Cyber and Mythos, for deeper model-backed analysis. Initial analysis and scoring is done with Clef , Cloudflare’s open-source decision model. Collecting evidence to understand what each alert means requires a lot of time. Even in a highly sophisticated Security Information and Event Management (SIEM), too much is still left for a human to review. Human analysts must gather data, connect and aggregate detections, and account for missing sources while new alerts continue to arrive. Think about every time a human analyst reviews an alert: "Which should we silence? Which action should we take? Which alert should we ignore? Which should we resolve as false positives? Which should we resolve as true positives? Which should trigger our incident team?" We address this predicament with our AI agent strategy. Our approach reduces all of th
The US government’s Tradewinds initiative has made it easier to throw millions of dollars at “nontraditional” defense contractors, including OpenAI, Anthropic, and Google.
AWS penetration testing is scoped by accounts, identities, and exposed workloads, not IP ranges. AWS lets customers test a defined list of services without prior approval, but it prohibits flooding, DNS attacks, and takeovers, and it requires approval for command-and-control and simulated events. Budget follows two drivers: account and IAM complexity for the cloud control plane, and the number of internet-facing applications for workload testing. The post AWS Penetration Testing for Enterprises: What to Scope and How to Budget appeared first on Synack .
Cybercrime Detective Explains Cybersecurity Jargon in 60-Second Videos for Cybersecurity Awareness Month
COPENHAGEN, Denmark, 7 October 2026 – Heimdal today officially launches the “Cyber in 60” weekly video series in which Adam Pilton, a former cybercrime detective and now Cybersecurity Advisor at Heimdal, breaks down one cybersecurity term or concept in under 60 seconds. This series solves an old tech to human translation problem. The people who […] The post Cybercrime Detective Explains Cybersecurity Jargon in 60-Second Videos for Cybersecurity Awareness Month appeared first on Heimdal Security Blog .
OpenAI came to Australia to apologise. It will leave without answering these key questions | Toby Walsh
We don’t accept drugs killing a few people because they cure most patients. Or a few planes crashing because most land safely. AI should be no different OpenAI’s CEO Sam Altman was asked to appear before the Joint Select Committee on Artificial Intelligence in Australia and explain how and why their agents have been hacking into multiple government websites . Altman didn’t turn up but sent Jason Kwon, his chief strategy officer, instead to answer the committee’s many tricky questions on its first day of public hearings on Tuesday. The committee is conducting a comprehensive inquiry into the economic, societal, regulatory, and national security implications of AI for Australia. It will report back to parliament at the end of November. This is an unusually fast pace, but then it’s an unusually fast paced technology. Continue reading...
On October 11, 2026, the DNS root is scheduled to change its key-signing key (KSK) for only the second time ever. This key anchors DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures. The change is called a KSK rollover. Validating resolvers need to trust the new key before the switch, as otherwise healthy websites could become unreachable. When we wrote about the first root KSK rollover in 2018 , we had seen resolvers lose their learned trust in the new key during software upgrades or moves between machines. Publishing the key well in advance was only part of the job. We also needed to know whether resolvers had retained it, and we couldn’t give users a practical way to check. Most website operators do not need to make any changes for this rollover. If you run a DNSSEC-validating resolver, check that it trusts the new root key, KSK-2024, and follow your software vendor’s instructions to update its trust anchors if the key is missing. If you use Cloudflare for your domain's DNS or rely on 1.1.1.1 and Gateway DNS, you do not need to take any action — our systems already trust KSK-2024. To check ahead of time, visit our rollover readiness test . It asks the resolver your browser uses whether it trusts the new key. The test uses RFC 8509: A Root Key Trust Anchor Sentinel for DNSSEC , which we’ve implemented in 1.1.1.1 ahead of the rollover. Where DNSSEC trust begins A DNS resolver looks up the addresses of websites and other services for your device. DNSSEC lets it check digital signatures on DNS records to verify that they ar
Shares in fashion company fall nearly 10% after its app systems are accessed by ‘unidentified third party’ Asos is investigating unauthorised access to its app system after shoppers received a notification claiming hackers had “fully compromised” its data. The online fashion retailer said basic personal information including name and contact details might have been accessed by an unidentified third party but it did not believe payment card records or passwords had been compromised. Continue reading...
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
Welcome back to yet another episode of "security was taken seriously". Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure by design” public statements. And in the times we live in, where anyone with a prompt window in front of them can say "reproduce the vulnerability, make no mistakes", so are you. In Greek mythology, Atlas was punished by the gods for misbehaving. Reality is unfair, and all we get is Atlassian punishing the rest of us for running their systems on-prem. And so they did, on October 5th, in a security advisory . Sometimes we regret that CVSS scores go as high as 10, because when a vu
I made this javascript deobfuscator for https://github.com/javascript-obfuscator/javascript-obfuscator
I wanted to share a project I’ve been working on that I’m super excited about: Project RedTeam: Contract Offensive There’s a free Demo that provides a tutorial and lets you play a few contracts (no time limit, play as much as you want). Some players are already pulling some serious hours in the demo! At its core, this is a game about using MITRE ATT&CK adversarial techniques against procedurally generated networks. It's delivered in a gameplay loop that plays a lot like Balatro and other card based Roguelike games. In Project RedTeam, you need to earn money to pay off debts after every contract within a run. Earn money by completing objectives, side bounties, or executing exfiltration/ransom against targets- the choice on how to be profitable is always yours. It's a challenging but fun and fast paced take on network-intrusion cybersecurity concepts. It's entertaining in a deliberately gamified way. A goal of this project was to create a hacking game that is realistic enough to keep it meaningful as a tool to teach intrusion concepts and stages to anyone- but not be overcomplicated and slow-paced like most hacking games. I've put a lot of thought into the design and dynamics of how to capture the core-loop of network intrusion and turn it into a game that's approachable. The design direction of this project is an outcome of having over a decade of training and experience in cybersecurity. Feel free to AMA! I'm happy to answer any questions about the game and/or development process :) Give the game a Wishlist on Steam or share this post if it's something you support and want to see further development on. Project background: This was implemented over the past 3 months using a modern development workflow (yes, modern AI tools make this possible- I'm not hiding that fact!). That being said, this is by far the most complex software project I've built as a solo developer and it was not an easy or simple development task. There's a Steam Community with a Dev Blog for this game that provides more history/progress updates on the project. Mods: This will be my only and last post here, since it is promotional. I just wanted to share this since there’s been very positive interest from similar subreddits.
Project Zero often works with software vendors to remediate the vulnerabilities we report and provide broader guidance on making software more secure. Some vendors express concern about potential scenarios in which they are unable to fix vulnerabilities that are causing immediate user harm, due to limitations in their patch delivery systems. Since Project Zero encounters a wide array of systems designed to protect users in the case of exceptional exploitation scenarios, both through vendor discussions and security reviews, we want to share what we’ve learned. This post provides an overview of systems in use by large vendors that allow them to remediate small volumes of vulnerabilities much faster than their typical update process. Our goal is to provide a reference for vendors seeking to implement or enhance the capabilities of such systems, and to encourage vendors to consider how they would fix an urgent vulnerability before they receive one.
In this post, we share LLM-specific validation patterns that attackers use to test exposed AWS credentials for Amazon Bedrock access.
We celebrated our 16th birthday last week by sharing how we’re building a better Internet for today’s world. As Matthew and Michelle reflected in this year’s Founders’ Letter , this year saw some of the most consequential changes in the history of the Internet. For the first time, automated traffic surpassed human activity. AI is empowering people to build like never before, leading the Internet to grow massively in scale and unlocking more ambition and creativity. As we witnessed the influence that agent-driven recommendations have on consumer choices, we identified the need for a new approach that creates space for new businesses to succeed. Each day of Birthday Week explored a different way we are helping to build the future of the Internet. We began on Monday by strengthening our commitment to open source. Tuesday focused on application security and the post-quantum transition. On Wednesday, we explored new economic models for the agentic Internet. Thursday, we expanded the Developer Platform with new tools for data analysis, storage, AI, and agent development. Finally, we closed out the week by launching features that make Cloudflare faster, easier to operate, and more accessible to everyone. As a special Birthday Week follow-up, we shared an update on our intern program, one year after announcing our goal to hire 1,111 interns . Interns directly contributed to many of the projects launched this week, including EmDash, post-quantum visibility, CryptoLabe, and Protected Quick Tunnels. We shipped 46 announcements this week. In case you missed any, here’s the full list of everything we announced during Birthday Week 2026. Monda
A year ago, many companies were cutting intern and new-graduate hiring . We went the other way. We announced a goal to hire as many as 1,111 interns in 2026, a number that’s a nod to 1.1.1.1, our public DNS resolver. The bet was that AI makes early-career talent more valuable and able to make an impact faster. The best AI tools help people learn a system faster, try more ideas, and take on harder problems. They don’t supply the energy, curiosity and fresh eyes a new person brings to a team. A year in, and our interns are shipping to our internal teams and to millions of customers. If you’re reading this on the Cloudflare Blog, you’re already using some of their work. The blog runs on EmDash , and EmDash’s second maintainer started at Cloudflare as an intern this past summer. A new generation of builders We’re still working toward 1,111. So far, we’ve hosted 750 internships across 48 teams in nine offices: Austin, San Francisco, London, Lisbon, New York, Singapore, Bengaluru, Washington DC, and Sydney. And we’re still hiring. From their first day, interns joined active teams and worked on real problems. Each was expected to leave something behind: a shipped product improvement, a better process, a new piece of infrastructure, or an insight that changes how a team approaches its work. That work reached far beyond engineering. An internal audit intern built an AI-assisted pipeline to automate ISO compliance control testing and documentation. A product manager intern worked on an API, dashboard, and migration tooling to moder
A year since launching Synack’s integration with Qualys, the partnership now includes broader platform support, more AI-led testing, and a shared presence at Qualys ROCon Americas 2026. The post Turn Scanner Findings into Validated Risk with Synack and Qualys appeared first on Synack .
To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have better luck on the [Reverse Engineering StackExchange](http://reverseengineering.stackexchange.com/). See also /r/AskReverseEngineering.
I wrote up my investigation into @goodjavascript/dotenv@1.0.0, including how to recover its entry-point file after the npm tarball and jsDelivr file URLs returned 404. The useful detail: Software Heritage’s latest snapshot contained only the security placeholder. An older snapshot retained the original release and its 840-byte index.js. Its SHA-256 matched the digest still available in jsDelivr’s file manifest. Static inspection showed a timer scheduled at module load that collects host information and can execute JavaScript supplied in a server response. The package had no installation scripts, and its exported config() function was empty. The article includes the package-to-archive discovery steps, dated evidence, an annotated code excerpt and a Python verifier that retrieves and hashes the file without executing it. It also links my analysis contribution to the existing OSV advisory. [https://cgsec.dev/research/dotenv-recovery/](https://cgsec.dev/research/dotenv-recovery/) This concerns the scoped @goodjavascript/dotenv package, not the unscoped dotenv package. Have you used other archives or retained metadata sources to recover removed package evidence?
We analyzed RBAC bindings across over 65,000 Kubernetes clusters to find dangerous permissions granted to system:anonymous, system:unauthenticated, and system:authenticated.
Presently sponsored by: Where are your AI agents? Origin's sensor finds every install on your fleet, grouped by owner, including the ones your MDM never sees. I'm in Denmark! Well, just, I'm now at Copenhagen airport ready to begin the long trek home, with the final event at GOTO now done and going just perfectly. This week, there are two ShinyHunters arrests in the news: Pepijn in the Netherlands and then Saif in Jordon . It's an inevitable outcome, of course, and as I say this week, it was also the most likely one. Time will tell how many more join their ranks, but the seriousness of the crimes, the length of time they were perpetrated over, and the motivations behind them will certainly see substantial custodial sentences. In other news, this week I'm properly introducing a new sponsor for the blog: Origin . One of our next AI frontiers is understanding what agents have actually done (and we've all seen news of where they're been a bit too, well, "creative" in executing their tasks), and Origin's solution gives you visiblity into just that. Check them out, and a big thanks to them for their ongoing support.
David Robinson joins other insiders in urging industry to take more care over rapidly developing technology A safety leader at OpenAI has quit the company, warning that its culture was broken and that AI firms were not “being nearly careful enough” about developing the technology. David Robinson, who led the writing of safety reports that accompanied the ChatGPT developer’s product releases, explained his resignation in an essay headlined: “I quit OpenAI because its culture is broken.” Continue reading...
Millions have downloaded Meta’s AI agent Muse. But getting it to do your bidding comes with privacy costs.
Internxt is a post-quantum secure encrypted cloud storage provider which is open-source and has passed multiple independent audits. I reviewed their code and found that post-quantum security should have been the least of their problems. Clicking a link in your browser could trigger remote code execution on the desktop app or leak your long-term encryption keys to an attacker-chosen URL. Their cryptographic architecture stands on shaky grounds with public keys never being verified, in some cases man-in-the-middled by design, a flat key hierarchy and a KDF with just 3 iterations of MD5. We need PQC and we need it now, but adding a (self-rolled) PQC hybrid on top of a weak protocol does not make it more secure.
DHS agents not only tracked and intimidated people observing ICE activity in Maine, but stored information about them in a database run on Palantir software, newly unsealed court filings say.