Cybersecurity News and Vulnerability Aggregator

Cybersecurity news aggregator

Top Cybersecurity Stories Today

The Hacker News • 6h ago

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network

Cloudflare • 5h ago
CVE

Security alerts rarely arrive one at a time. A single alert can cause a spike across the environment, requiring a human analyst to decide which alerts are related and what they mean. When multiple arrive at the same time, it can quickly overwhelm even a seasoned security analyst. Enter the alert paradox. Now, our built-in, multi-AI-agent security operations harness can handle more of this work at Cloudflare scale. Our Cloudflare Managed Defense AI agent harness speeds up the process of gathering data, connecting and aggregating detections, and accounting for missing sources while new alerts continue to arrive. To further analyze context, we make use of the OpenAI Daybreak Defense Network and our partnership with Anthropic. Cloudflare uses approved OpenAI Daybreak and Anthropic models, including GPT-5.6 Cyber and Mythos, for deeper model-backed analysis. Initial analysis and scoring is done with Clef , Cloudflare’s open-source decision model. Collecting evidence to understand what each alert means requires a lot of time. Even in a highly sophisticated Security Information and Event Management (SIEM), too much is still left for a human to review. Human analysts must gather data, connect and aggregate detections, and account for missing sources while new alerts continue to arrive. Think about every time a human analyst reviews an alert: "Which should we silence? Which action should we take? Which alert should we ignore? Which should we resolve as false positives? Which should we resolve as true positives? Which should trigger our incident team?" We address this predicament with our AI agent strategy. Our approach reduces all of th

Synack • 7h ago

AWS penetration testing is scoped by accounts, identities, and exposed workloads, not IP ranges. AWS lets customers test a defined list of services without prior approval, but it prohibits flooding, DNS attacks, and takeovers, and it requires approval for command-and-control and simulated events. Budget follows two drivers: account and IAM complexity for the cloud control plane, and the number of internet-facing applications for workload testing. The post AWS Penetration Testing for Enterprises: What to Scope and How to Budget appeared first on Synack .

Cloudflare • Oct 2

Today, we’re launching eight major updates that bring your logs, traces, analytics, alerts, dashboards, and exporting into one observability platform , with simpler and more predictable pricing. Here's what's launching: One place to explore logs from across Cloudflare End-to-end tracing from Cloudflare's edge to your origin One unified SQL API for querying Cloudflare data One pricing model for observability data ingested and stored across Cloudflare Custom alerts on your observability data All analytics for your domain in one place, with 30 days of data retention Custom dashboards built from your observability data Export your data with Logpush -- now available on self-serve plans One observability platform for all of Cloudflare Understanding an issue often requires data from more than one Cloudflare product. A spike in 5xx responses could come from a Worker, from your origin, or from Cloudflare failing to connect to your origin globally or regionally. But investigating it today requires knowing which product owns each signal and how to query it. Observability should be a platform-wide capability: it should reflect how applications a

Latest

Wednesday, October 7
r/cybersecurity • 1h ago

It's 11pm, you're parsing through mountains of logs. There's yet another tool someone remembered, and they have the logs exported. The time zone is in PT or ET, or something that isn't UTC. You are tired and questioning your life choices because this thing is not in UTC and now you need to convert the time zone in your head. I made a simple [Clock app](https://github.com/rdmershon/PowerShell-Clock-App) to make my life easier. I'm sharing it in the hopes it helps others. It uses no external dependancies. It uses no third-party libraries. It just uses native win forms and PowerShell. I like a lot of DFIR tools, but you can't always bring them into some environments. This is just a basic PowerShell script so it should be able to be run in most environments.

The Hacker News • 3h ago

Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted

r/cybersecurity • 3h ago

Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here. All the reports and research below were published between September 28th - October 4th. You can get the below into your inbox every week if you want: [https://www.cybersecstats.com/cybersecstatsnewsletter/](https://www.cybersecstats.com/cybersecstatsnewsletter/)  # Big Picture Reports **Relentless Defense (Cisco)** There are “Relentless Defenders,” and then there’s everyone else, which is what this report claims. It also claims to explore what the best-prepared organizations do differently so you can be like them. **Key stats:** * Only 8% of organizations surveyed qualify as “Relentless Defenders”, the report’s top-performing group for coverage, response speed and organizational alignment. * 40% of security teams say they spend more time manually collecting and correlating data than dealing with threats. * 39% say critical insights are missed because the data sits somewhere they cannot reach. *Read the full report* [*here*](https://www.cybersecstats.com/r/06f2b551?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* **2027 Global Digital Trust Insights (PwC)** A useful large-scale report from PWC to compare notes about where cyber budgets are going, which threats others feel least prepared for, and how much they trust AI to act on its own. **Key stats:** * 84% of security and finance leaders expect their cyber budget to increase, up six percentage points from last year. * Half of security leaders identify attacks targeting AI systems as one of their biggest preparedness gaps. * 55% rank the reliability and maturity of AI technology among their top three barriers to increasing agent autonomy. *Read the full report* [*here*](https://www.cybersecstats.com/r/b53e4634?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* **2026 Digital Defense Report (Microsoft)** Another big report. Microsoft’s annual look at the threat landscape, including credential theft, data theft, and how quickly exposed cloud workloads attract attacks. **Key stats:** * Exposed cloud workloads are attacked an average of 5.3 hours after exposure. * 63% of intrusions involve data theft. * Between 89% and 95% of email phishing attachments lead to credential theft efforts. *Read the full report* [*here*](https://www.cybersecstats.com/r/3bf0fa6a?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # AI Security  **2026 Identity Security Report: The AI Enforcement Gap (Delinea)** What’s the gap between organizations’ AI access policies and their ability to enforce them?  **Key stats:** * 99.7% of organizations have a formal policy governing which data AI tools and agents can access. * 87% of IT leaders say an AI tool or agent accessed sensitive data beyond its intended scope in the past year. * 55% of organizations take a full day or longer to detect when an AI agent steps outside its scope. *Read the full report* [*here*](https://www.cybersecstats.com/r/0ef89734?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Inside the SOC **The New SOC Career Ladder: How AI Is Reshaping the SecOps Workforce (Swimlane)** AI seems to be making SOC work more satisfying. Though some worry it’s leaving them with fewer opportunities to build their skills. **Key stats:** * 88% of security operations professionals and leaders say AI makes their work more satisfying. * 24% say AI limits their skill development. * Among those who say AI limits their skill development, 91% still report higher job satisfaction. *Read the full report* [*here*](https://www.cybersecstats.com/r/a161d98b?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Vulnerability Management  **H2 2026 Cyber Hygiene Index (Detectify)** Comparing how long organizations in different regions take to fix critical and high-severity vulnerabilities. **Key stats:** * 90% of open critical and high-severity vulnerabilities have been exposed for more than 90 days across the organizations analyzed. * That figure reaches 97% in the Nordics. * In the UK, it is 92%, compared with 86% in the US. *Read the full report* [*here*](https://www.cybersecstats.com/r/d1b541ef?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* **Vulnerability Discovery and Exploitation Trends in the AI Era (Google Threat Intelligence Group)** AI is busy finding security holes. Meanwhile, researchers are finding holes in AI. **Key stats:** * Monthly vulnerability disclosures more than doubled, from 5,045 in January 2026 to 10,740 in August. * From January to August 2026, 141 distinct vulnerabilities were disclosed and exploited, already exceeding the 127 recorded across all of 2025. * Only 0.23% of vulnerabilities disclosed in 2026 (about one in 431) were observed in active exploitation. *Read the full analysis* [*here*](https://www.cybersecstats.com/r/358ce6c3?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Social Engineering  **The Deepfake Readiness Index 2026 (Pindrop)** US enterprises’ readiness for deepfake attacks, the impact of incidents and the attention these threats get in the boardroom. **Key stats:** * 74% of US enterprise security leaders have encountered or suspect a deepfake attack in the past year. * Only 10% report having purpose-built tools to address deepfake threats. * 75% of security leaders say it will take a company leader being personally fooled or impersonated before deepfakes become a genuine boardroom priority. *Read the full report* [*here*](https://www.cybersecstats.com/r/fa2033e1?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Skills and Training  **2026 SkillBit Micro-Training Survey Report (SkillBit)** Finding the right security people is only the start.  **Key stats:** * 57% of cybersecurity leaders say new hires take six months to reach full productivity. * Nearly 64% of organizations consider three months an acceptable time-to-value for new cybersecurity hires. * 70% report having few or no roles available to candidates with less than two years’ experience. *Read the full report* [*here*](https://www.cybersecstats.com/r/82ef5bf9?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Industry-Specific **2026 Data and Identity Security Report: Healthcare Findings (Netwrix)** Who’s got access to sensitive healthcare data? With AI adding more people and tools to the mix, keeping track is getting harder. **Key stats:** * 79% of healthcare organizations say their non-human identities are not fully governed. * 77% cannot immediately determine who has access to a specific piece of sensitive data. * 31% experienced unauthorized identities accessing sensitive data in the past year, compared with 24% in other industries. *Read the full report* [*here*](https://www.cybersecstats.com/r/300454ea?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.* # Committed to the Mission: The State of the DIB with CMMC in Flux (Redspin) Where defense contractors are investing and what they’re prioritizing to meet cybersecurity requirements. **Key stats:** * 75% of defense contractors say achieving CMMC Level 2 certification provides value beyond contract eligibility. * 78.2% of organizations are continuing towards CMMC certification or are already Level 2 certified by a third party. * 21.9% are delaying certification or significantly slowing their implementation and certification efforts. *Read the full report* [*here*](https://www.cybersecstats.com/r/6dbf0bb8?m=50f43416-1146-4a3d-a1e1-5afc95e09a39)*.*

The Hacker News • 4h ago

Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have

r/cybersecurity • 4h ago

I started a blog series to provide free insights into appsec. It’s mainly to breakdown what application security is all about and it’s mainly targeted towards beginners and startups, so take it as you will. I want to teach every one interested in appsec my perspective on it from my experience in big tech. So far: know your app → lock down who gets in → follow untrusted input → catch broken business logic → build a threat model. Part 7 puts it all to the test. Literally. Prove which problems are real before you spend time fixing them. Please reach out if you have any questions or would like for me to write on a topic that you’d want to learn more about.

r/cybersecurity • 5h ago
APT

Hundreds of new repositories poisoned with malicious, secret extracting workflows. GitHub held most malicious workflows runs for approval, limiting the impact. Some victims found to also be affected by seemingly unrelated cryptominer attacks, hinting toward a pool of compromised credentials being used by multiple threat actor groups.

Cloudflare • 5h ago
CVE

Security alerts rarely arrive one at a time. A single alert can cause a spike across the environment, requiring a human analyst to decide which alerts are related and what they mean. When multiple arrive at the same time, it can quickly overwhelm even a seasoned security analyst. Enter the alert paradox. Now, our built-in, multi-AI-agent security operations harness can handle more of this work at Cloudflare scale. Our Cloudflare Managed Defense AI agent harness speeds up the process of gathering data, connecting and aggregating detections, and accounting for missing sources while new alerts continue to arrive. To further analyze context, we make use of the OpenAI Daybreak Defense Network and our partnership with Anthropic. Cloudflare uses approved OpenAI Daybreak and Anthropic models, including GPT-5.6 Cyber and Mythos, for deeper model-backed analysis. Initial analysis and scoring is done with Clef , Cloudflare’s open-source decision model. Collecting evidence to understand what each alert means requires a lot of time. Even in a highly sophisticated Security Information and Event Management (SIEM), too much is still left for a human to review. Human analysts must gather data, connect and aggregate detections, and account for missing sources while new alerts continue to arrive. Think about every time a human analyst reviews an alert: "Which should we silence? Which action should we take? Which alert should we ignore? Which should we resolve as false positives? Which should we resolve as true positives? Which should trigger our incident team?" We address this predicament with our AI agent strategy. Our approach reduces all of th

r/cybersecurity • 5h ago

My team wrote a technical walkthrough of the distributed alerting workflow we use internally. It uses an agent to investigate GuardDuty findings, identify owners, and handle responses in Slack. Slack helped popularize distributed alerting by sending alerts directly to the people involved and asking whether they recognized the activity. Dropbox and Brex described similar approaches, but most teams we’ve spoken with struggled to scale beyond user-centric alerts where someone’s identity was already in the payload. Our security engineer ran into this at his previous company. A suspicious login was straightforward to route, but an alert about a host or infrastructure change could take hours or days of work with detection engineers before they could reliably identify someone to ask. We walk through a concrete Kubernetes example where the alert only names a service account. Finding a person means following the evidence through workload metadata, code ownership, deployment history, and identity logs. The tutorial shows how we turn that investigation method into reusable skills so an agent can work through those steps for each finding. We cover: * The history of distributed alerting and why deterministic workflows struggle to scale * The estimated effort of building owner lookups across GuardDuty finding types * How the agent uses skills, drilldown queries, and context from inventory, code, tickets, and logs * The full flow from investigation to a Slack conversation and the owner’s confirmation * Permissions, tool restrictions, observability, and keeping context current What interested us most was extending this to host and infrastructure alerts that had been impractical to automate with individual lookup rules. The walkthrough includes the setup and examples so you can see how it works. We know many folks were are divided by the use of agents in security automation. Hopefully this article on distributed alerting presents an example of something that wasn't possible / too time consuming to work before agents + context / skills driven automation vs fully determined paths. [https://www.tracecat.com/blog/agentic-security-alerts](https://www.tracecat.com/blog/agentic-security-alerts)

The Hacker News • 5h ago

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being

The Hacker News • 6h ago

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network

The Hacker News • 6h ago

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including

Synack • 7h ago

AWS penetration testing is scoped by accounts, identities, and exposed workloads, not IP ranges. AWS lets customers test a defined list of services without prior approval, but it prohibits flooding, DNS attacks, and takeovers, and it requires approval for command-and-control and simulated events. Budget follows two drivers: account and IAM complexity for the cloud control plane, and the number of internet-facing applications for workload testing. The post AWS Penetration Testing for Enterprises: What to Scope and How to Budget appeared first on Synack .

r/cybersecurity • 7h ago

Log extractions (such as a compromised `.claude.json` file) show the stealer successfully exfiltrating raw `primaryApiKey` values and detailed OAuth account data tied to Anthropic/Claude accounts. By grabbing these CLI tokens, attackers are bypassing traditional web logins entirely, gaining direct, programmatic access to premium AI models, organizational workspaces, and potentially sensitive source code passing through these tools.

Krebs on Security • 8h ago
CVE

A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle “ Rey ,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing , which manufactures the fleet of planes used by the employer of Rey’s father — Royal Jordanian Airlines . The logo for Jeppesen ForeFlight, a business unit divested last year by the aerospace firm Boeing. On October 3, Reuters cited three unnamed sources saying a suspected ShinyHunters member in Amman named Saif Al-din Khader was detained by Jordanian authorities and was cooperating with the FBI. KrebsOnSecurity identified Rey as Khader in a November 2025 profile , in which the young m

r/cybersecurity • 8h ago

\> ML4 is one of the world's strongest AI models for cybersecurity. On the Artificial Analysis Cyber Index, an independent evaluation of how well AI models find and fix security flaws in real software, it ranks among the top five models globally and leads open-weight models developed outside China by a wide margin. Their blog talks a lot about the cyber capabilities of their new model. Its quite interesting.

r/blueteamsec • 8h ago

According to the new FBI/USSS advisory, FortiBleed actors no longer just add persistence accounts. In some cases they also delete or reset the original admin accounts (T1531), which locks the owner out of their own FortiGate. That changes the usual playbook. If you assume a password reset gets you back to a clean state, it won't help when you can't log in at all. A few things worth checking: → Do you have out-of-band admin recovery for your edge devices? → Have you audited REST API keys? They survive password resets. → Is SSH left open on the firewall? How are others handling recovery for edge devices? Full breakdown: [https://hubs.la/Q04zrkbN0](https://hubs.la/Q04zrkbN0) Free FortiBleed checker: [https://hubs.la/Q04zrk9\_0](https://hubs.la/Q04zrk9_0) Advisory: [https://www.ic3.gov/CSA/2026/261006.pdf](https://www.ic3.gov/CSA/2026/261006.pdf)

The Hacker News • 9h ago

The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens. For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data loss, more pressure, and more urgency. That

The Hacker News • 9h ago

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat

The Hacker News • 10h ago

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software

The Hacker News • 10h ago

If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a real attacker would. That promise is worth taking seriously. It’s also worth pressure testing, and three questions do the heavy lifting. What can the assessment actually

Heimdal Security • 13h ago

COPENHAGEN, Denmark, 7 October 2026 – Heimdal today officially launches the “Cyber in 60” weekly video series in which Adam Pilton, a former cybercrime detective and now Cybersecurity Advisor at Heimdal, breaks down one cybersecurity term or concept in under 60 seconds. This series solves an old tech to human translation problem. The people who […] The post Cybercrime Detective Explains Cybersecurity Jargon in 60-Second Videos for Cybersecurity Awareness Month appeared first on Heimdal Security Blog .

The Hacker News • 13h ago

Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional

The Hacker News • 14h ago

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the

r/blueteamsec • 16h ago

Sharing a few recent dark web listings that came up in monitoring. None of these are confirmed yet, so take them as claims for now, not confirmed breaches. → France: a seller claims 10M+ residential records → IUT Paris Seine: 6.8GB of data plus about 30M log entries → U.S. manufacturer: VPN and RDP access up for auction → SMTP dump: about 19M credentials → Apache Struts: an exploit tool sold together with access to servers already compromised The Struts listing stands out to me. Selling the tool together with working access points more to an access broker than to someone trying to sell a PoC. The 19M SMTP creds are the likeliest to show up again soon in phishing and credential stuffing. Has anyone seen overlap with the SMTP dump in their own environment, or seen recent Struts exploitation in the wild? Full breakdown:https://hubs.la/Q04z7HkK0

The Guardian • 20h ago

We don’t accept drugs killing a few people because they cure most patients. Or a few planes crashing because most land safely. AI should be no different OpenAI’s CEO Sam Altman was asked to appear before the Joint Select Committee on Artificial Intelligence in Australia and explain how and why their agents have been hacking into multiple government websites . Altman didn’t turn up but sent Jason Kwon, his chief strategy officer, instead to answer the committee’s many tricky questions on its first day of public hearings on Tuesday. The committee is conducting a comprehensive inquiry into the economic, societal, regulatory, and national security implications of AI for Australia. It will report back to parliament at the end of November. This is an unusually fast pace, but then it’s an unusually fast paced technology. Continue reading...

Tuesday, October 6
The Hacker News • Oct 6

Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in

The Hacker News • Oct 6

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may

Cloudflare • Oct 6

On October 11, 2026, the DNS root is scheduled to change its key-signing key (KSK) for only the second time ever. This key anchors DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures. The change is called a KSK rollover. Validating resolvers need to trust the new key before the switch, as otherwise healthy websites could become unreachable. When we wrote about the first root KSK rollover in 2018 , we had seen resolvers lose their learned trust in the new key during software upgrades or moves between machines. Publishing the key well in advance was only part of the job. We also needed to know whether resolvers had retained it, and we couldn’t give users a practical way to check. Most website operators do not need to make any changes for this rollover. If you run a DNSSEC-validating resolver, check that it trusts the new root key, KSK-2024, and follow your software vendor’s instructions to update its trust anchors if the key is missing. If you use Cloudflare for your domain's DNS or rely on 1.1.1.1 and Gateway DNS, you do not need to take any action — our systems already trust KSK-2024. To check ahead of time, visit our rollover readiness test . It asks the resolver your browser uses whether it trusts the new key. The test uses RFC 8509: A Root Key Trust Anchor Sentinel for DNSSEC , which we’ve implemented in 1.1.1.1 ahead of the rollover. Where DNSSEC trust begins A DNS resolver looks up the addresses of websites and other services for your device. DNSSEC lets it check digital signatures on DNS records to verify that they ar

The Guardian • Oct 6

Shares in fashion company fall nearly 10% after its app systems are accessed by ‘unidentified third party’ Asos is investigating unauthorised access to its app system after shoppers received a notification claiming hackers had “fully compromised” its data. The online fashion retailer said basic personal information including name and contact details might have been accessed by an unidentified third party but it did not believe payment card records or passwords had been compromised. Continue reading...

watchTowr • Oct 6

Welcome back to yet another episode of "security was taken seriously". Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure by design” public statements. And in the times we live in, where anyone with a prompt window in front of them can say "reproduce the vulnerability, make no mistakes", so are you. In Greek mythology, Atlas was punished by the gods for misbehaving. Reality is unfair, and all we get is Atlassian punishing the rest of us for running their systems on-prem. And so they did, on October 5th, in a security advisory . Sometimes we regret that CVSS scores go as high as 10, because when a vu

r/netsec • Oct 6
APT

I wanted to share a project I’ve been working on that I’m super excited about: Project RedTeam: Contract Offensive There’s a free Demo that provides a tutorial and lets you play a few contracts (no time limit, play as much as you want). Some players are already pulling some serious hours in the demo! At its core, this is a game about using MITRE ATT&CK adversarial techniques against procedurally generated networks. It's delivered in a gameplay loop that plays a lot like Balatro and other card based Roguelike games. In Project RedTeam, you need to earn money to pay off debts after every contract within a run. Earn money by completing objectives, side bounties, or executing exfiltration/ransom against targets- the choice on how to be profitable is always yours. It's a challenging but fun and fast paced take on network-intrusion cybersecurity concepts. It's entertaining in a deliberately gamified way. A goal of this project was to create a hacking game that is realistic enough to keep it meaningful as a tool to teach intrusion concepts and stages to anyone- but not be overcomplicated and slow-paced like most hacking games. I've put a lot of thought into the design and dynamics of how to capture the core-loop of network intrusion and turn it into a game that's approachable. The design direction of this project is an outcome of having over a decade of training and experience in cybersecurity. Feel free to AMA! I'm happy to answer any questions about the game and/or development process :) Give the game a Wishlist on Steam or share this post if it's something you support and want to see further development on. Project background: This was implemented over the past 3 months using a modern development workflow (yes, modern AI tools make this possible- I'm not hiding that fact!). That being said, this is by far the most complex software project I've built as a solo developer and it was not an easy or simple development task. There's a Steam Community with a Dev Blog for this game that provides more history/progress updates on the project. Mods: This will be my only and last post here, since it is promotional. I just wanted to share this since there’s been very positive interest from similar subreddits.

The Hacker News • Oct 6

The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,

The Hacker News • Oct 6

In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP

The Hacker News • Oct 6

Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are

Project Zero • Oct 6

Project Zero often works with software vendors to remediate the vulnerabilities we report and provide broader guidance on making software more secure. Some vendors express concern about potential scenarios in which they are unable to fix vulnerabilities that are causing immediate user harm, due to limitations in their patch delivery systems. Since Project Zero encounters a wide array of systems designed to protect users in the case of exceptional exploitation scenarios, both through vendor discussions and security reviews, we want to share what we’ve learned. This post provides an overview of systems in use by large vendors that allow them to remediate small volumes of vulnerabilities much faster than their typical update process. Our goal is to provide a reference for vendors seeking to implement or enhance the capabilities of such systems, and to encourage vendors to consider how they would fix an urgent vulnerability before they receive one.

The Hacker News • Oct 6
CVE

The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​

The Hacker News • Oct 6

Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to

Monday, October 5
Cloudflare • Oct 5
CVE

We celebrated our 16th birthday last week by sharing how we’re building a better Internet for today’s world. As Matthew and Michelle reflected in this year’s Founders’ Letter , this year saw some of the most consequential changes in the history of the Internet. For the first time, automated traffic surpassed human activity. AI is empowering people to build like never before, leading the Internet to grow massively in scale and unlocking more ambition and creativity. As we witnessed the influence that agent-driven recommendations have on consumer choices, we identified the need for a new approach that creates space for new businesses to succeed. Each day of Birthday Week explored a different way we are helping to build the future of the Internet. We began on Monday by strengthening our commitment to open source. Tuesday focused on application security and the post-quantum transition. On Wednesday, we explored new economic models for the agentic Internet. Thursday, we expanded the Developer Platform with new tools for data analysis, storage, AI, and agent development. Finally, we closed out the week by launching features that make Cloudflare faster, easier to operate, and more accessible to everyone. As a special Birthday Week follow-up, we shared an update on our intern program, one year after announcing our goal to hire 1,111 interns . Interns directly contributed to many of the projects launched this week, including EmDash, post-quantum visibility, CryptoLabe, and Protected Quick Tunnels. We shipped 46 announcements this week. In case you missed any, here’s the full list of everything we announced during Birthday Week 2026. Monda

Cloudflare • Oct 5

A year ago, many companies were cutting intern and new-graduate hiring . We went the other way. We announced a goal to hire as many as 1,111 interns in 2026, a number that’s a nod to 1.1.1.1, our public DNS resolver. The bet was that AI makes early-career talent more valuable and able to make an impact faster. The best AI tools help people learn a system faster, try more ideas, and take on harder problems. They don’t supply the energy, curiosity and fresh eyes a new person brings to a team. A year in, and our interns are shipping to our internal teams and to millions of customers. If you’re reading this on the Cloudflare Blog, you’re already using some of their work. The blog runs on EmDash , and EmDash’s second maintainer started at Cloudflare as an intern this past summer. A new generation of builders We’re still working toward 1,111. So far, we’ve hosted 750 internships across 48 teams in nine offices: Austin, San Francisco, London, Lisbon, New York, Singapore, Bengaluru, Washington DC, and Sydney. And we’re still hiring. From their first day, interns joined active teams and worked on real problems. Each was expected to leave something behind: a shipped product improvement, a better process, a new piece of infrastructure, or an insight that changes how a team approaches its work. That work reached far beyond engineering. An internal audit intern built an AI-assisted pipeline to automate ISO compliance control testing and documentation. A product manager intern worked on an API, dashboard, and migration tooling to moder

Synack • Oct 5

A year since launching Synack’s integration with Qualys, the partnership now includes broader platform support, more AI-led testing, and a shared presence at Qualys ROCon Americas 2026. The post Turn Scanner Findings into Validated Risk with Synack and Qualys appeared first on Synack .

r/ReverseEngineering • Oct 5

To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have better luck on the [Reverse Engineering StackExchange](http://reverseengineering.stackexchange.com/). See also /r/AskReverseEngineering.

r/Malware • Oct 5

I wrote up my investigation into @goodjavascript/dotenv@1.0.0, including how to recover its entry-point file after the npm tarball and jsDelivr file URLs returned 404. The useful detail: Software Heritage’s latest snapshot contained only the security placeholder. An older snapshot retained the original release and its 840-byte index.js. Its SHA-256 matched the digest still available in jsDelivr’s file manifest. Static inspection showed a timer scheduled at module load that collects host information and can execute JavaScript supplied in a server response. The package had no installation scripts, and its exported config() function was empty. The article includes the package-to-archive discovery steps, dated evidence, an annotated code excerpt and a Python verifier that retrieves and hashes the file without executing it. It also links my analysis contribution to the existing OSV advisory. [https://cgsec.dev/research/dotenv-recovery/](https://cgsec.dev/research/dotenv-recovery/) This concerns the scoped @goodjavascript/dotenv package, not the unscoped dotenv package. Have you used other archives or retained metadata sources to recover removed package evidence?

Sunday, October 4
Troy Hunt • Oct 4

Presently sponsored by: Where are your AI agents? Origin's sensor finds every install on your fleet, grouped by owner, including the ones your MDM never sees. I'm in Denmark! Well, just, I'm now at Copenhagen airport ready to begin the long trek home, with the final event at GOTO now done and going just perfectly. This week, there are two ShinyHunters arrests in the news: Pepijn in the Netherlands and then Saif in Jordon . It's an inevitable outcome, of course, and as I say this week, it was also the most likely one. Time will tell how many more join their ranks, but the seriousness of the crimes, the length of time they were perpetrated over, and the motivations behind them will certainly see substantial custodial sentences. In other news, this week I'm properly introducing a new sponsor for the blog: Origin . One of our next AI frontiers is understanding what agents have actually done (and we've all seen news of where they're been a bit too, well, "creative" in executing their tasks), and Origin's solution gives you visiblity into just that. Check them out, and a big thanks to them for their ongoing support.

The Guardian • Oct 4

David Robinson joins other insiders in urging industry to take more care over rapidly developing technology A safety leader at OpenAI has quit the company, warning that its culture was broken and that AI firms were not “being nearly careful enough” about developing the technology. David Robinson, who led the writing of safety reports that accompanied the ChatGPT developer’s product releases, explained his resignation in an essay headlined: “I quit OpenAI because its culture is broken.” Continue reading...

Saturday, October 3
r/Malware • Oct 3

Hi everyone, I recently bought one of those cheap Android projectors (Nonete HY260Pro, Allwinner H713) and noticed some suspicious network activity. Being curious, I decided to set up a lab, intercept the traffic, and dig into the firmware. I ended up uncovering a factory-installed malware ecosystem: a disguised dropper (StoreOS), a hidden second stage (SilentSDK) and a plugin loader that talks to a C2 server in China (api.pixelpioneerss.com) and deploys up to 5 botnet/fraud plugins. Key findings of my analysis: * Four-stage infection chain: StoreOS → SilentSDK → PluginManager → final plugins. Payloads are hidden with a "Byte-Reversal" trick, XOR encryption and build-fingerprint spoofing. * The plugins currently enroll the device in residential proxy networks (XFJ/net2fast, a UDP proxy node, indicators consistent with the Vo1d botnet) and run ad/click fraud, partly geo-fenced server-side. * The loader executes downloaded code with system privileges, so the operators can push any payload at any time. I only observed proxy and ad-fraud plugins, but the capability for remote code execution is there by design. * The device also ships with open root backdoors and sends device identifiers (MAC, serial, Android ID) to servers in China. * An independent researcher found identical infrastructure on a Magcubic HY300 Pro+, which suggests the problem is the H713 firmware base and not one brand. I could only verify my own device. This is my first independent technical report and deep dive into malware research. I've documented the full kill chain, decrypted the obfuscated strings, listed IOCs and mitigations (DNS blocklist, ADB disable commands), and written scripts to repair the malformed payloads for analysis. Full Report: [https://github.com/Kavan00/Android-Projector-C2-Malware](https://github.com/Kavan00/Android-Projector-C2-Malware) I'd love to get your opinion on the report, especially from owners of other H713 devices who can compare. Looking forward to your feedback!

r/netsec • Oct 3
CVE

Internxt is a post-quantum secure encrypted cloud storage provider which is open-source and has passed multiple independent audits. I reviewed their code and found that post-quantum security should have been the least of their problems. Clicking a link in your browser could trigger remote code execution on the desktop app or leak your long-term encryption keys to an attacker-chosen URL. Their cryptographic architecture stands on shaky grounds with public keys never being verified, in some cases man-in-the-middled by design, a flat key hierarchy and a KDF with just 3 iterations of MD5. We need PQC and we need it now, but adding a (self-rolled) PQC hybrid on top of a weak protocol does not make it more secure.

Friday, October 2
Cloudflare • Oct 2

Today, we’re launching eight major updates that bring your logs, traces, analytics, alerts, dashboards, and exporting into one observability platform , with simpler and more predictable pricing. Here's what's launching: One place to explore logs from across Cloudflare End-to-end tracing from Cloudflare's edge to your origin One unified SQL API for querying Cloudflare data One pricing model for observability data ingested and stored across Cloudflare Custom alerts on your observability data All analytics for your domain in one place, with 30 days of data retention Custom dashboards built from your observability data Export your data with Logpush -- now available on self-serve plans One observability platform for all of Cloudflare Understanding an issue often requires data from more than one Cloudflare product. A spike in 5xx responses could come from a Worker, from your origin, or from Cloudflare failing to connect to your origin globally or regionally. But investigating it today requires knowing which product owns each signal and how to query it. Observability should be a platform-wide capability: it should reflect how applications a

r/netsec • Oct 2
CVE

When analysing firmware attack surfaces, image decoders built into bootloaders get less scrutiny than cryptographically verified OS kernels. If image parsing happens before signature verification, any memory corruption in the parser breaks the secure boot trust model. researchers analysed U-Boot's video subsystem (drivers/video/video\_bmp.c) and identified an unbounded write in the RLE8 bitmap decoder (video\_display\_rle8\_bitmap()) that leads to a **pre-authentication Secure Boot bypass**. **Root Cause and Vulnerability Mechanics** When **U-Boot** displays a boot logo or splash screen, it parses a BMP image loaded from local storage (SPI flash, MMC/eMMC, USB, or SD card). **Unbounded framebuffer write:** During RLE8 decompression, `video_display_rle8_bitmap()` decodes run-length encoded streams directly into the active framebuffer without validating stream bounds against the frame boundary or allocated buffer size. **Pre-authentication execution window:** In many embedded target configurations, the boot splash screen is rendered immediately on startup, before U-Boot calls Android Verified Boot (AVB) or FIT image signature verification routines. **Storage disparity:** The kernel image and rootfs are signed, but **splash images are frequently stored in unsigned, user-writable partitions or external media**. An attacker who writes a crafted RLE8 BMP to the boot storage can trigger an out-of-bounds write past the framebuffer during early boot, corrupting adjacent bootloader data structures, function pointers, or verification flags in memory. This hijacks the execution flow before signature checking completes.

Cloudflare • Oct 2

Cloudflare Stream is a powerful broadcasting platform that, for many of our customers, just works. But what if you wanted to render dynamic annotations on a livestream or create an alternate version of a hosted video with burned-in subtitles? You would need to run a custom video pipeline. Today, we’re releasing a new developer playground, Streamline, that demonstrates how you can build a system to deliver these bespoke video experiences on Cloudflare’s Developer Platform. We’ll walk you through how Streamline leverages Workers, Containers, and several media protocols to modify video — and immediately publish that output as livestream or new hosted video. You’ll also have the opportunity to try it for your projects. A processing pipeline needs a durable, long-running environment that can run specialized, compiled code with predictable memory and CPU capacity. Video streams can run for minutes or hours, so the media process needs a lifecycle independent of the request that started it. An application should be able to start a pipeline, send its input, inspect it, and stop it without needing to keep a single request open for the entire duration. Cloudflare provides the primitives we need. Containers are long-lived runtimes suitable for media processing. Durable Objects help with orchestration. Finally, Workers are perfect for control signaling and monitoring. For Streamline, we built a media engine running in a Container to handle media processing in real-time. The Container is controlled by a Worker exposing control, preview, and testing to an agent or user. Processing will continue even if the Worker disconnects. We've architected Streamline with modular components so that the media engine could be replaced with dedicated encoding products in the future. Architecture A S

r/netsec • Oct 2
CVE

**TL;DR.** [SConnect](https://chromewebstore.google.com/detail/sconnect/mjhbkkaddmmnkghdnnmkjcgpphnopnfk) \- 1M+ users, an extension middleware+native host for authentication with eIDs, 3SKeys and other hardware signing tokens had a drive-by RCE which enabled any site or iframe a user saw to silently download and execute a dll due to a poor hand-rolled implementation of RSA-2048 token validation, enabling a use of uninitialized memory validation bypass which enabled "plugins" (DLLs) to be loaded. v2.16.0.0 of the extension and native host is vulnerable. [CVE-2026-18397](https://nvd.nist.gov/vuln/detail/cve-2026-18397). CVSS 9.4.

Cloudflare • Oct 2

Fun fact: when you use an agent and it needs to fetch a live web page, the agent usually just guesses the URL of the page and then makes a tool call to curl it. This is why you’ll sometimes see web fetches come back with a 404 Not Found, which happens if the agent incorrectly guesses the URL of that information. As you can imagine, it’s not super efficient to randomly guess URLs all the time. There is a better way. What if your agent can actually browse the Internet, just like how humans start with a search engine query when we’re looking for information? This is what web search is designed to do — it enables agents to search for relevant data on the Internet and grounds an agent’s responses based on live information. Today, we’re announcing Cloudflare’s partnership with web search providers to bring you grounded intelligence via AI Gateway. We’re kicking off this launch with our partners from Ceramic.ai, Exa, and Linkup. What can I do with the Web Search API? AI models are only as good as the context you feed them. Models are typically trained and then frozen at a point in time, operating only on information that existed before their knowledge cut off date. This makes it quite hard to engage with models about recent events, changing APIs, or fast-evolving news. Integrating Web Search API directly into your inference pipeline equips your agents with a dynamic context layer. Your applications get fresh, structured snippets from the web injected straight into context, which gives your models access to live information. For example, if your agent was building with Cloudflare developer tools, it might miss all the new products and features we’re releasing during this Birthday Week ! With web search, you’ll be able to retrieve the latest and greatest documentation and releases, so you can build faster and smarter. Elevating

Cloudflare • Oct 2

Today, end users carry too much of the burden of online privacy. To avoid third-party trackers or targeted ads, users are instructed to use a VPN, disable cookies, or install adblockers. Meanwhile, some app developers end up knowing more about their users than they’d care to: a typical client-server exchange creates a trail of user data, like the client’s IP address or TLS fingerprint. This level of visibility can be a burden. That’s why Cloudflare builds infrastructure that helps developers bake privacy into their apps. Oblivious HTTP (OHTTP) is an IETF standard designed to enable app backends to receive HTTP requests without seeing user IP addresses. This fall, we’re launching the Cloudflare OHTTP Gateway. Customers will be able to enable our new OHTTP Gateway as a paid add-on to their zone and start receiving OHTTP traffic with just a few clicks. Register through our form to join our waitlist. Read on to learn more. Expanding our OHTTP product suite With OHTTP, requests travel through two independently-operated hops: a relay and a gateway. An OHTTP relay blindly forwards encrypted requests in order to hide client identifiers from app servers. An OHTTP gateway performs the cryptographic work of decapsulating encrypted requests and encapsulating responses such that app servers can handle OHTTP requests as if they were plain HTTP. The separation of trust between relay and gateway is critical: it ensures that no single party sees both client identifiers and request contents. In 2022, we launched an OHTTP relay product, Privacy Gateway . Privacy Gateway ena

Cloudflare • Oct 2
APT

Today, we’re introducing Cloudflare Traces in open beta, extending automatic tracing beyond Workers to the rest of the request path. In one trace, you can see supported security rules, transformations, cache decisions, routing, Worker execution, and origin handling, then continue that trace through services running on Cloudflare, at your origin, or elsewhere in your stack. This is a long-term investment in OpenTelemetry and in making Cloudflare the most observable part of your stack. You can now: Automatically trace requests across Cloudflare : Capture supported platform operations in one request-level timeline, no additional set up required. Control which requests are traced : Set a baseline sampling rate, then use Trace Rules to override it for matching traffic. End-to-end trace context propagation: Accept and forward W3C traceparent headers Investigate traces in Cloudflare : View request timelines and span details directly in the Cloudflare dashboard.

Cloudflare • Oct 2
APT

We launched Quick Tunnels in 2021 to give developers an easy way to share their latest service, application, or project running in their local development environment. A lot has changed since then, but the core use case remains the same. Your coding agent has just finished the feature. The dev server is up on localhost:5173 , and before you ask, the agent offers to let you try it on your phone. It runs one command and hands you a link: That command starts a Quick Tunnel . cloudflared , Cloudflare's lightweight connector, publishes your local service at a random trycloudflare.com URL. No account, no domain, no cost. Agents now use Quick Tunnels for the same reason people do: they are the shortest path from a local port to a URL. The catch has always been the same. Anyone with the link can open it. Starting with cloudflared 2026.9.3, you can add --allowed-mail to the command, and your Quick Tunnel only lets in the email addresses and domains you choose. Visitors prove they own one of those addresses with a one-time PIN from Cloudflare Access . Nobody, on either side, needs a Cloudflare account. Agents made Quick Tunnels more popular than ever Agents that write code need somewhere to show you the result. Agents that live on a Mac mini at home need to be reachable from your phone. Model Context Protocol servers on a laptop need a public endpoint before a hosted assistant can call them. Each of these needs a URL, and a Quick Tunnel produces one

Trail of Bits • Oct 2

Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a common stumbling point when cryptographers try to use hashes. As part of our goal to “fix software, not bugs,” Trail of Bits is introducing SequenceHash and its sister function SequenceMAC , a pair of related hash constructions that bring secure multihashing to developers using hash functions other than Keccak. We hope SequenceHash and SequenceMAC will help cryptographers avoid attacks that take advantage of ambiguous input encodings. The specification is open source, and is now a part of the Community Cryptography Specification Project (C2SP). SequenceHash and SequenceMAC behave similarly to NIST’s TupleHash , but have the advantage of not being tied to a single hash function. They also don’t require developers to implement fiddly computations that aren’t byte-aligned. Instead, SequenceHash and SequenceMAC work out of the box with nearly any secure cryptographic hash function you care to use, including SHA256/384/512, BLAKE, and RIPEMD. SequenceMAC supports keys 32 bytes or longer (up to the ridiculous limit of ${2}^{128}-1$ bytes). (It’s worth noting: SequenceHash and SequenceMAC rely on the security of the underlying hash for their own security. SequenceHash and SequenceMAC can’t magically make MD4 or SHA0 secure again. For the purposes of this document, it’s assumed that you have chosen a reasonable hash function like SHA256, not CRC32.) To make SequenceHash and SequenceMAC easy to use, we’re releasing

Compass Security • Oct 2
CVE

Introduction Pwn2Own is a renowned hacking competition organized by the Zero Day Initiative (ZDI), where security researchers demonstrate previously unknown vulnerabilities in popular software, operating systems, browsers, IoT devices, and other technologies. Having participated in both the 2023 and 2024 editions of Pwn2Own, we decided to take another shot in 2025. This time, our goal was to avoid collisions, where multiple teams discover the same vulnerability during the same event, leading to reduced prize money and fewer Master of Pwn points. This blog post walks through our journey from discovery to full exploitation. We start by exploring the Home Assistant device architecture, then detail how we found a remote code execution vulnerability in an add-on. From there, we show how we leveraged it to pivot to the underlying operating system and achieve root-level access. We conclude with our experience at the Pwn2Own 2025 Cork edition. Target Selection We started by looking at several different targets. Our initial list included the Wyze Cam Pan v3 and the Synology CC400W from the surveillance system category, the Brother MFC-J1010DW from the printer category, the Philips Hue Bridge and the Home Assistant Green from the smart home category. After assessing the various targets, we shifted our focus to the Home Assistant Green due to the progress we had made on that platform. This led us to the discovery of an exploit chain that resulted in an unauthenticated remote code execution vulnerability. Device Overview

Thursday, October 1
r/computerforensics • Oct 1
APT

I've been picking through a SCADA-style telemetry capture and I can't explain what I'm seeing. The file has 14 authorisation records, each with its own CRC. All 14 validate. The file header carries a CRC-32 over the whole block, and that one fails. Two of the operator-name fields are zeroed. My reading is that someone blanked those fields, recomputed the per-record CRCs so they'd pass, and never touched the block CRC. But I'd like a sanity check — is there a corruption mode that breaks a block checksum while leaving every record checksum intact? File (8.8MB): www.[st88openocean.github.io/slip-three/MCA-CTL-0314-RAW.slice](https://st88openocean.github.io/slip-three/MCA-CTL-0314-RAW.slice) Published digests for it are here: www.[st88openocean.github.io/slip-three/archive](https://st88openocean.github.io/slip-three/archive)

Synack • Oct 1

Before you build an AI pentesting agent, run it through 5 tests for production readiness. Mark Kuhr breaks down what separates a prototype from a system. The post Build or Buy AI Pentesting? 5 Tests to Judge Production Readiness appeared first on Synack .

r/netsec • Oct 1

A blue-team writeup on detecting a compromised MikroTik from its own config. Seven techniques, each with the collection command, the artifact it leaves behind, and a triage step. Feedback welcome.

CERT/CC • Oct 1

Overview An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code executes in System Management Mode (SMM), successful exploitation can allow an attacker to modify SMM-protected memory and potentially achieve arbitrary code execution in SMM. Depending on the platform's memory and firmware configuration, the arbitrary physical memory write primitive may also have implications for UEFI firmware update or flash-related operations. Description HP PC BIOS is firmware that initializes and manages hardware components during the boot process and provides runtime services to the operating system and provide the ability to update firmware. The affected system uses InsydeH2O Kernel version 5.5 or earlier. The BIOS includes custom HP SMM handlers that execute in System Management Mode (SMM), a highly privileged CPU execution mode that is isolated from the operating system. CVE-2026-12855 : An Out-of-bounds Write vulnerability in the H19WMIHandlerSmm module (GUID f1946499-571b-44c3-9b9c-cc55210b0c02) allows a local attacker with OS kernel privileges to read or write arbitrary physical memory, including SMRAM, through a Software SMI handler. An attacker with kernel-level privileges can trigger the vulnerable SMM handler by issuing a Software System Management Interrupt (SMI) through I/O port 0xB2 and supplying specially crafted CPU register values. The vulnerable handler does not adequately validate the supplied parameters before performing memory operations, allowing the attacker to influence the physical address and data involved in the operation. Because the affe

Heimdal Security • Oct 1

Benedict Jones spent years working for McAfee and Sophos. While doing threat research at Sophos, he spotted a problem in mobile threat defence that nobody had actually fixed. He’s now CEO and founder of Trustd Mobile, and the story of how he got there says more about MSP buying decisions than most vendor pitches ever […] The post Innovation wins. Why smaller beats bigger appeared first on Heimdal Security Blog .

WIRED • Oct 1

In an exclusive interview with WIRED, Paragon Solutions CEO Andrew Boyd reveals the limits of the company’s promise to keep bad actors from abusing its powerful espionage tool.

Heimdal Security • Oct 1

London, UK, 1 October 2026 – Heimdal, a global cybersecurity provider, today announced a partnership with Elovade, a European IT security distributor with 250 experts across five countries, to bring its unified security platform to managed service providers (MSPs) across the DACH region: Germany, Austria, and Switzerland. The move extends a relationship that began a […] The post Heimdal partners with Elovade to bring unified cybersecurity platform to the DACH region appeared first on Heimdal Security Blog .

Story Overview