Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
Cybersecurity News and Vulnerability Aggregator
Cybersecurity news aggregator
treemd <(curl -sL https://allsec.sh/md) (as Markdown) Top Cybersecurity Stories Today
The City Attorney’s Office has asked Meta to explain how the harmful ads repeatedly ran on Facebook and Instagram. The company claims the ads are not under the city’s jurisdiction.
Before you sign with a penetration testing vendor, ask precise questions that turn marketing claims into measurable commitments. Confirm exact scope, learn which work is automated, AI-led, or human-led, and require that findings get reproduced and validated before they reach a report. Ask who can access your environment, how testers are vetted, and what the rules of engagement and stop conditions look like. Review sample reports, confirm remediation and retesting terms, and normalize every cost. Place every material promise in the contract rather than a slide deck. The post Questions to Ask a Penetration Testing Vendor Before You Sign appeared first on Synack .
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.
Latest
The City Attorney’s Office has asked Meta to explain how the harmful ads repeatedly ran on Facebook and Instagram. The company claims the ads are not under the city’s jurisdiction.
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here. All the reports and research below were published between August 31st - September 6th. You can get the below into your inbox every week if you want: [https://www.cybersecstats.com/cybersecstatsnewsletter/](https://www.cybersecstats.com/cybersecstatsnewsletter/) # Application Security **Mythos Readiness Report (Echo)** As AI is getting better at finding and exploiting vulnerabilities, how do you decide which findings actually matter? **Key stats:** * Exploit success against a known set of Firefox vulnerabilities increased roughly 90-fold between consecutive model generations on Anthropic's benchmark. * Fewer than 10% of the model's 23,019 candidate findings have undergone any external validation. * Of 27 vulnerabilities publicly disclosed by Anthropic, only one of the eight findings Mythos initially rated Critical held up under independent review. *Read the full report* [*here*](https://www.cybersecstats.com/r/b57899a5?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Ransomware **Recovery Without Compromise (Object First)** Ransomware recovery isn't getting better. For many organizations, it’s actually getting worse. **Key stats:** * 83% of organizations were hit by a successful ransomware attack in the past 24 months, up from 66% in 2024. * Only 39% of ransomware victims recover at least 75% of their data, down from 57% in 2024. * 76% say their largest data-loss event exceeded their Recovery Point Objective targets. *Read the full report* [*here*](https://www.cybersecstats.com/r/55302d39?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Enterprise Perspective **Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise (Cequence Security)** Organizations seem remarkably confident about AI agent permissions. Too confident. **Key stats:** * 94% of enterprise IT and security leaders are confident their AI agents don't have more access than they need, but only 33% provision agents with least-privilege access. * 65% of organizations have experienced an AI agent taking an action outside its intended scope. * 36% have caught a near-miss from an AI agent before it caused damage. *Read the full report* [*here*](https://www.cybersecstats.com/r/6c6c183f?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Consumer Scams **Scammers Are Getting Smarter About Where They Target You (Malwarebytes)** Interesting report on how scammers operate, including their preferred channels and brands, plus when they’re most likely to appear in your inbox. **Key stats:** * Google's name appears in scam content at least twice as often as Amazon's name. * Scam text volume peaks at 12 p.m. ET, when it's approximately 874% higher than at 1 a.m. * By Friday, people receive roughly 50% more fraudulent text messages than at the start of the week. *Read the full report* [*here*](https://www.cybersecstats.com/r/ae4bc943?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Regional Spotlight **European Cyber Report 2026 Mid Year (Link11)** Good news for European businesses: DDoS attacks became less frequent in the first half of 2026. Bad news: they’re more powerful. **Key stats:** * DDoS attack numbers fell 42% compared with the first half of 2025. * The highest measured bandwidth reached 2.3 Tbit/s, up 85% from the previous peak of 1.2 Tbit/s. * Despite the decline in attack numbers, cumulative DDoS traffic increased 61%, from 438 TB to 705 TB. *Read the full report* [*here*](https://www.cybersecstats.com/r/80ff62be?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.*
The new Apple Watch includes several “intelligent” listening features that have privacy and security baked in. But the protections can’t change the facts of what the tools do.
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime
Before you sign with a penetration testing vendor, ask precise questions that turn marketing claims into measurable commitments. Confirm exact scope, learn which work is automated, AI-led, or human-led, and require that findings get reproduced and validated before they reach a report. Ask who can access your environment, how testers are vetted, and what the rules of engagement and stop conditions look like. Review sample reports, confirm remediation and retesting terms, and normalize every cost. Place every material promise in the contract rather than a slide deck. The post Questions to Ask a Penetration Testing Vendor Before You Sign appeared first on Synack .
Quick context on why I'm posting this here: AI is making it a lot easier for attackers to find and exploit vulnerabilities in open source projects faster than most maintainer teams can keep up with. At the same time, AI can generate candidate fixes at scale. No one had figured out how to get trustworthy human eyes on those fixes before they went upstream. That's what OASIS (Open Automated Security Initiative for Software) is for. It's a community-run project under OWASP: not a product, not owned by any one company. AppSec practitioners volunteer to validate AI-generated fixes for real open-source vulnerabilities, and the good ones get pushed upstream to maintainers. OASIS is rolling out an alpha and looking for actual volunteers across a few roles: validators, regional community leads, open source liaisons, and more. Whatever your background, there's probably a way to plug in. There are already several hundred signed up. There is plenty to do, sign up and help us out at: [owasp-oasis.org](http://owasp-oasis.org) Happy to answer anything in the comments!
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
A new GTA mod lets you smash and shoot Flock’s automatic license plate readers around the fictional Los Santos.
Update: Attack Shark X6 Linux driver — from DPI-only to button remap, lighting, and emergency reset (Go + Wails)
Piracy CDN renamed .ts video segments to .woff2 to abuse extension-based CDN caching, a byte-level analysis
Realistically, what are the risks of your average iphone user being hit with the Dark sword exploit for ios?
I’ve been seeing talk about [this](https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain) exploit that was going around in early this year. Even though it’s patched now, I’m wondering what the chances were of a random user getting hit with this. 99% of the time, attacks like these are saved for high profile targets, but this seems different, considering the code got leaked. Will this mean anything for the security of an iphone in the future? And does this mean the “Only high profile targets get hit by malware on an iphone” myth is false?
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
We’ve rewritten the module registry in workerd , the core open-source component of the Workers runtime, to be faster, more standards-compliant, and more closely aligned with Node.js' module registry. Over the past few years, we’ve been adding support for more and more Node.js runtime APIs. The Workers runtime now supports every stable API from Node.js that you might want to use in a serverless context, and these APIs are now enabled by default , letting you deploy even larger Node.js apps to Cloudflare (now up to 64 MiB on all plans — we’ve removed the limit on compressed bundle size). But API compatibility alone is not enough: Node.js applications also depend on how the runtime resolves, loads, and caches modules . ESM, CommonJS, and WebAssembly are each types of modules that you can import in your Worker’s code. The system within the runtime that handles all of this is called the module registry. You can start using it today by enabling the new_module_registry compatibility flag in your Worker.
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web
Fermat famously claimed to have a “truly marvelous proof” of his Last Theorem , but he never wrote it down, insisting the margin of his page was too narrow to contain it. A few centuries later, Anthropic announced a complete formalization of Fermat’s Last Theorem using 13 million lines of Lean code (clearly not what Fermat intended). Luckily, we found a wonderfully cursed Lean bug , shown below, that suggests the proof may have fit the margin after all. The issue affects all stable versions of Lean up to 4.33.1, and the patch is incorporated in v4.34.0-rc1. A “checked” proof of Fermat’s Last Theorem using Lean 4.33.1 The blue checkmarks in the screenshot above would suggest that Lean considers this proof correct. This seems odd given the amount of work Sir Andrew Wiles put into this problem and the vast size of Claude’s proof. So what is going on? The “proof” clearly doesn’t make any sense and exploits an issue in Lean. We found the issue while using GPT-5.6 to experiment with a new skill for code review. We want to clarify up front that the issue is not a kernel soundness issue , but it happens to nicely fit any discussion of strings, lengths, and substrings. &
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through
I’ve spent enough time around AI adoption now to notice a pattern. Ask a business how AI is going for them and the honest answer is, lately, “we’ve got Copilot, and it’s not great.” That gap between the hype and the reality is exactly where Samantha North operates. Sam runs an AI transformation agency, helping […] The post AI adoption that pays off is built around keeping humans in the driver’s seat appeared first on Heimdal Security Blog .
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a
11 organizations compromised in 26 seconds. GreyNoise breaks down the AI-enabled campaign against PaperCut that hit 440 instances across 48 countries.
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month. Image: Shutterstock.com, Kirill Makarov. This month’s patch bundle obliterates the software giant’s previous record set in July , when it released updates for at least 570 security vulnerabilities. September’s Patch Tuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go. There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and
Designed to compete with OpenClaw and Instinct, the company says Muse can do everything from sell your car to book you a plane ticket.
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
Overview The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot protections. When the UEFI Shell is included in SPI flash, an attacker with the ability to modify UEFI boot configuration may be able to create multiple boot option entries and bypass controls intended to prevent the UEFI Shell from launching while Secure Boot is enabled. This could allow an attacker to modify the pre-boot environment and execute unauthorized software during system startup. Description The Unified Extensible Firmware Interface (UEFI) is a firmware specification that defines the interface between a computing platform's hardware and operating system (OS) during the early boot process before the operating system is loaded. UEFI Secure Boot helps ensure that only trusted and digitally signed software is executed during these early stages of platform initialization. The TianoCore EDK II project provides an open-source reference implementation of the UEFI and Platform Initialization (PI) specifications. The project includes the UEFI Shell , which provides command-line utilities for debugging, diagnostics, and advanced platform management. Many OEM and Independent BIOS Vendor (IBV) firmware implementations include the UEFI Shell in SPI flash for service and support purposes. Because the shell executes in the pre-boot environment, it provides powerful commands such as dmem (display memory) and mm (memory modify) that can access physical memory. Many implementations include a boot entry for the
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&
VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability
Overview Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairing mode or requiring any physical confirmation or interaction from the owner. Description The Skullcandy Dime 3 (Model S2DCW) wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from a previously unpaired device without the device being placed into pairing mode by the owner and without physical confirmation on the earbuds. The device's Bluetooth PnP modalias identifies the chipset vendor as Airoha Technology Corp. (Bluetooth SIG company ID 0x0094). This vulnerability was previously disclosed in CVE-2025-20701 and is described as: In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. An attacker is required to be within Bluetooth radio range to the target earbuds, but no prior pairing, physical access, or interaction with the earbuds' buttons or case is required to exploit the vulnerability. A direct pairing request to the earbuds' known or discovered Bluetooth Classic address can be sent without a PIN, passkey, or physical confirmation. The pairing/bonding completes without owner action due to the device's NoInputNoOutput I/O capability. The firmware version displayed on the affected Skullcandy Dime 3 wireless earbuds is 1.0.0.28. Impact Once bonded, the attacker's device is added as a trusted device and can reconnect automatically whenever in range. This allows an attacker to est
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI
Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)
Every time Cloudflare opens a new TLS 1.3 connection to an origin server, we have to make a guess: the protocol requires us to commit to a key agreement algorithm in the very first packet we send, before the origin has told us anything about itself or what it can support. If we guess right, the handshake completes in one round trip. Guess wrong, and the origin replies with a HelloRetryRequest , we start over, and the connection costs two round trips. For years, our guess was the same for every origin on the Internet: X25519 . Widely supported, but as it turns out, suboptimal for roughly 30% of the origin connections we've since measured. Today we're announcing Automatic Key Exchange , an extension of Automatic SSL/TLS that replaces the guess with a measurement. We probe each origin to learn which key agreement algorithms it supports and prefers, then lead with that algorithm on the first try, preferring the post-quantum hybrid X25519MLKEM768 wherever the origin can speak it. With the ongoing rollout of Automatic Key Exchange across origin connections, HelloRetryRequests fell from roughly 52% to 3.7%, cutting more than 150 ms off connection handshake latency at p90. In addition, as part of our ongoing rollout, hundreds of thousands of domains now
“You’ve been gifted a voucher!”. “Your account will be closed unless you act now”. “Late payment demand. Invoice # 207”. Phishing scams come in many shapes and sizes. And, in 2026, they remain, by far, the most common attack vector targeting both individuals and organizations. To help you understand the scale of the threat, I’ve […] The post Phishing in 2026. Latest statistics and analysis appeared first on Heimdal Security Blog .
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally
Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: Confirming bug candidates that have been discovered manually or through static analysis. Regression tests: After fixing a race condition bug, there is often no good way to write a regression test that reliably triggers the bug as part of a test suite. Automatic bug discovery, such as fuzzing: It is hard for a fuzzer to exercise all interesting interleavings of concurrent operations, or reach code paths that are only exercised when operations are racing.
Bose Sleepbuds II: Reverse-engineered the full BLE file-transfer protocol (TUMBLE) — audio codec still unidentified
The core components required to move from automated discovery to proven risk now exist: capable models, controlled execution, scalable orchestration, evidence capture and human judgement. The opportunity is to engineer them as one dependable system rather than treat each as a standalone feature. The post AI Can Find Vulnerabilities. Building a System That Proves Risk Is the Hard Part. appeared first on Synack .
To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have better luck on the [Reverse Engineering StackExchange](http://reverseengineering.stackexchange.com/). See also /r/AskReverseEngineering.
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I've started playing around with YouTube's "create video thumbnail", which hopefully will give me back a bit of time in my day (it used to be a manual job in Photoshop) and be a bit more interesting. And on that note, the imagery it's chosen this week is spot on: that Lockwood ES2100 electric strike looks like the perfect solution for my first fully installed Ubiquiti Access door lock. Having the door position sensor built in really simplifies things, and hopefully Ubiquiti will later add support to their hubs for the latch position and strike lock status. Once I'm back from this next round of travel, I should be able to do a full review of what it's like to actually live with.
FF-16-Web is a browser-based, interactive static pattern discovery tool that finds frequently occurring local 16-bit patterns across the entire file. It can run offline in a web browser. FF-16-Web is hosted on GitHub and it works in the same way like as the CLI and TUI versions.
Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.
Homeland Security Investigations agents hit the outdoor retailer with a controversial subpoena as part of a dragnet search for the identities of protesters who entered a Minnesota church in March.
ChatGPT, Claude, and Grok all suffered outages at nearly the exact same time for reasons that remain murky.
This week on Uncanny Valley, we dig into the latest prediction market buzz, Flock’s AI-powered police search tool, and how tech bros don’t know how to talk about “rouge” AI agents
Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models
Your scanner just flagged 4,000 new vulnerabilities, 78 of them critical. Which one do you fix first? To answer that question, Cloudflare is announcing early access to Vulnerability Discovery and Remediation, now part of Cloudflare Managed Defense . Vulnerability Discovery and Remediation is a new, invitation-only Cloudflare service that helps customers detect and mitigate vulnerabilities in their codebases. Through the OpenAI Daybreak Defense Network , we use OpenAI Daybreak models, including GPT-5.6 Cyber, for reconnaissance, hunting, and validation against codebases that you authorize us to access. If we detect a vulnerability, we will then propose solutions to you, automatically checking each proposed patch and any accompanying proposed mitigation before presenting them for review. Importantly, you are in the driver’s seat: while we may propose code patches and other mitigations, you decide whether they are implemented. Choosing what to fix first has always been hard. It's getting harder. Large language models can now surface weaknesses across a codebase in minutes , which means the number of findings keeps climbing. But the real problem is speed. Attackers can use AI to accelerate parts of vulnerability discovery and exploitation, giving security teams and developers less time to decide what matters and act on it. Imagine that your scanner tells you there's a vulnerability in a handler. It doesn't tell you whether that code is deployed. It doesn't tell you whether anyone is actually hitting that route, what security activity surrounds it, or what controls you already have
Overview Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions 3.115.0 and earlier. The vulnerability allows a non-global organization administrator to perform unauthorized administrative actions against arbitrary organizations by exploiting inconsistent object resolution between the authorization layer and downstream controllers. In multi-tenant deployments, an attacker with administrative privileges within a single organization can bypass tenant isolation and perform administrative operations against other organizations. Description CVE-2026-15630. The vulnerability stems from a desynchronization between authorization and action in multiple POST /api/{add,delete}- endpoints (e.g., /api/add-user, /api/delete-user, /api/add-permission) . While the global authorization filter ( routers/authzfilter.go ) correctly uses the ?id= URL query parameter as the authoritative target for authorization decisions, the affected controllers ( controllers/user.go , controllers/permission.go , etc.) ignore ?id= and operate solely on the owner and name fields in the JSON request body. As a result, authorization is evaluated against one object while the requested operation is executed against another, allowing an authenticated organization administrator ( IsAdmin=true ) to perform unauthorized administrative actions across tenant boundaries. Impact An attacker with administrative privileges in a single organization can compromise the isolation guarantees of a multi-tenant Casdoor deployment. Depending on the exposed endpoints and de
You know what you spent on penetration testing last year. But can you explain what that investment covered between engagements? For many organizations the honest answer is that it covered the weeks the testers were working against a scope agreed before they started. That was a reasonable arrangement when systems changed a few times a year. It is worth revisiting, now that many of them change weekly. The post Offensive Security Is Becoming a Program, Not a Purchase appeared first on Synack .
Heimdal’s MXDR team flagged a surge in detections tied to a program called Shift Browser on 2 September 2026. Our team confirmed activity on more than 50 client environments in a single day. The installers we captured trace to a malvertising lure. Shift Browser also runs a documented paid creator and affiliate marketing operation, though […] The post Shift Browser is signed adware that fingerprints your endpoint before it drops payload appeared first on Heimdal Security Blog .
WIRED rebuilt Flock’s latest search tool from code the company sends to a police officer’s browser. Its AI can keep watch across multiple cameras for anyone fitting a written description.
While the full implementation of the Cyber Resilience Act (CRA) won’t take effect until December 2027, another critical milestone is already approaching much sooner. Starting from 11 September 2026 , all manufacturers selling products with digital elements in countries of the European Union will be required to report actively exploited vulnerabilities in their digital products, as well as related security incidents, as well as security incidents that affect or compromise products already placed on the market. Incidents or vulnerabilities limited to development or internal environments are therefore only relevant if they result in (or could result in) a compromise of production devices. Although the platform itself is not yet available, the landmark legislation has already established a detailed framework and set of requirements. This article aims to summarize the most important aspects of the reporting process in order to help you prepare for these upcoming changes. Additionally, it provides clear guidelines for determining when a vulnerability or incident becomes mandatory to report. Overview In Chapter I, Article 14, §1, the Cyber Resilience Act states the following: A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. In the context of the CRA, an “ actively exploited vulnerability ” is defined as a “vulnerability for whic