Cybersecurity News and Vulnerability Aggregator

Cybersecurity news aggregator

Top Cybersecurity Stories Today

Synack • 10h ago

Synack was named a Leader in G2's Fall 2026 Grid® and Enterprise Grid® Reports for Penetration Testing. The reviews show what customers value in a pentesting partner: visibility into testing, access to experts, findings they can fix and verify, and a partner that acts on feedback. The post What Customers Value in a Penetration Testing Partner: Insights from G2 Reviews appeared first on Synack .

Cloudflare • 3h ago

Today, we’re launching eight major updates that bring your logs, traces, analytics, alerts, dashboards, and exporting into one observability platform , with simpler and more predictable pricing. Here's what's launching: One place to explore logs from across Cloudflare End-to-end tracing from Cloudflare's edge to your origin One unified SQL API for querying Cloudflare data One pricing model for observability data ingested and stored across Cloudflare Custom alerts on your observability data All analytics for your domain in one place, with 30 days of data retention Custom dashboards built from your observability data Export your data with Logpush -- now available on self-serve plans One observability platform for all of Cloudflare Understanding an issue often requires data from more than one Cloudflare product. A spike in 5xx responses could come from a Worker, from your origin, or from Cloudflare failing to connect to your origin globally or regionally. But investigating it today requires knowing which product owns each signal and how to query it. Observability should be a platform-wide capability: it should reflect how applications a

Cloudflare • 3h ago
APT

Today, we’re introducing Cloudflare Traces in open beta, extending automatic tracing beyond Workers to the rest of the request path. In one trace, you can see supported security rules, transformations, cache decisions, routing, Worker execution, and origin handling, then continue that trace through services running on Cloudflare, at your origin, or elsewhere in your stack. This is a long-term investment in OpenTelemetry and in making Cloudflare the most observable part of your stack. You can now: Automatically trace requests across Cloudflare : Capture supported platform operations in one request-level timeline, no additional set up required. Control which requests are traced : Set a baseline sampling rate, then use Trace Rules to override it for matching traffic. End-to-end trace context propagation: Accept and forward W3C traceparent headers Investigate traces in Cloudflare : View request timelines and span details directly in the Cloudflare dashboard.

The Hacker News • Oct 1
CVE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with

Latest

Friday, October 2
Cloudflare • Just now

Cloudflare Stream is a powerful broadcasting platform that, for many of our customers, just works. But what if you wanted to render dynamic annotations on a livestream or create an alternate version of a hosted video with burned-in subtitles? You would need to run a custom video pipeline. Today, we’re releasing a new developer playground, Streamline, that demonstrates how you can build a system to deliver these bespoke video experiences on Cloudflare’s Developer Platform. We’ll walk you through how Streamline leverages Workers, Containers, and several media protocols to modify video — and immediately publish that output as livestream or new hosted video. You’ll also have the opportunity to try it for your projects. A processing pipeline needs a durable, long-running environment that can run specialized, compiled code with predictable memory and CPU capacity. Video streams can run for minutes or hours, so the media process needs a lifecycle independent of the request that started it. An application should be able to start a pipeline, send its input, inspect it, and stop it without needing to keep a single request open for the entire duration. Cloudflare provides the primitives we need. Containers are long-lived runtimes suitable for media processing. Durable Objects help with orchestration. Finally, Workers are perfect for control signaling and monitoring. For Streamline, we built a media engine running in a Container to handle media processing in real-time. The Container is controlled by a Worker exposing control, preview, and testing to an agent or user. Processing will continue even if the Worker disconnects. We've architected Streamline with modular components so that the media engine could be replaced with dedicated encoding products in the future. Architecture A S

r/netsec • Just now
CVE

**TL;DR.** [SConnect](https://chromewebstore.google.com/detail/sconnect/mjhbkkaddmmnkghdnnmkjcgpphnopnfk) \- 1M+ users, an extension middleware+native host for authentication with eIDs, 3SKeys and other hardware signing tokens had a drive-by RCE which enabled any site or iframe a user saw to silently download and execute a dll due to a poor hand-rolled implementation of RSA-2048 token validation, enabling a use of uninitialized memory validation bypass which enabled "plugins" (DLLs) to be loaded. v2.16.0.0 of the extension and native host is vulnerable. [CVE-2026-18397](https://nvd.nist.gov/vuln/detail/cve-2026-18397). CVSS 9.4.

Cloudflare • 2h ago

Fun fact: when you use an agent and it needs to fetch a live web page, the agent usually just guesses the URL of the page and then makes a tool call to curl it. This is why you’ll sometimes see web fetches come back with a 404 Not Found, which happens if the agent incorrectly guesses the URL of that information. As you can imagine, it’s not super efficient to randomly guess URLs all the time. There is a better way. What if your agent can actually browse the Internet, just like how humans start with a search engine query when we’re looking for information? This is what web search is designed to do — it enables agents to search for relevant data on the Internet and grounds an agent’s responses based on live information. Today, we’re announcing Cloudflare’s partnership with web search providers to bring you grounded intelligence via AI Gateway. We’re kicking off this launch with our partners from Ceramic.ai, Exa, and Linkup. What can I do with the Web Search API? AI models are only as good as the context you feed them. Models are typically trained and then frozen at a point in time, operating only on information that existed before their knowledge cut off date. This makes it quite hard to engage with models about recent events, changing APIs, or fast-evolving news. Integrating Web Search API directly into your inference pipeline equips your agents with a dynamic context layer. Your applications get fresh, structured snippets from the web injected straight into context, which gives your models access to live information. For example, if your agent was building with Cloudflare developer tools, it might miss all the new products and features we’re releasing during this Birthday Week ! With web search, you’ll be able to retrieve the latest and greatest documentation and releases, so you can build faster and smarter. Elevating

Cloudflare • 3h ago

Tracking how governments target dissidents living in exile. Helping people in crisis find mental health support. Advocating for legislation that protects free expression online. These are a few examples of how some of the world's leading organizations are building the future of non-profit work with Cloudflare. AI is changing how people do their work. The goal of Cloudflare Impact is to help ensure that non-profit organizations are among the first to benefit. Today, we’re sharing what dozens of civil society organizations have built using our developer services with more than $7.5 million of Cloudflare credits. These stories show what is possible when AI applications are accessible, secure, and affordable to build and run. From "keep us secure" to "help us build" We believe a better Internet is one that allows people to express themselves online and access a diverse range of viewpoints. A key part of Cloudflare's mission has been making security services available for everyone and helping ensure that individuals and organizations working for the public interest are not forced offline by those more powerful. Today, Project Galileo , which provides free cybersecurity services to civil society organizations, protects more than 3,400 domains across more than 120 countries. Through these partnerships, organizations have shared with us how their needs have evolved from not only wanting to secure existing applications, but wanting to build new ones. AI has allowed non-technical teams to design, build, and scale tools tailored specifically for their workstreams and to advance their mission. This opportunity is arriving at a challenging moment for the sector. Many organizations repor

Cloudflare • 3h ago

Today, we’re launching eight major updates that bring your logs, traces, analytics, alerts, dashboards, and exporting into one observability platform , with simpler and more predictable pricing. Here's what's launching: One place to explore logs from across Cloudflare End-to-end tracing from Cloudflare's edge to your origin One unified SQL API for querying Cloudflare data One pricing model for observability data ingested and stored across Cloudflare Custom alerts on your observability data All analytics for your domain in one place, with 30 days of data retention Custom dashboards built from your observability data Export your data with Logpush -- now available on self-serve plans One observability platform for all of Cloudflare Understanding an issue often requires data from more than one Cloudflare product. A spike in 5xx responses could come from a Worker, from your origin, or from Cloudflare failing to connect to your origin globally or regionally. But investigating it today requires knowing which product owns each signal and how to query it. Observability should be a platform-wide capability: it should reflect how applications a

Cloudflare • 3h ago
APT

Today, we’re introducing Cloudflare Traces in open beta, extending automatic tracing beyond Workers to the rest of the request path. In one trace, you can see supported security rules, transformations, cache decisions, routing, Worker execution, and origin handling, then continue that trace through services running on Cloudflare, at your origin, or elsewhere in your stack. This is a long-term investment in OpenTelemetry and in making Cloudflare the most observable part of your stack. You can now: Automatically trace requests across Cloudflare : Capture supported platform operations in one request-level timeline, no additional set up required. Control which requests are traced : Set a baseline sampling rate, then use Trace Rules to override it for matching traffic. End-to-end trace context propagation: Accept and forward W3C traceparent headers Investigate traces in Cloudflare : View request timelines and span details directly in the Cloudflare dashboard.

Cloudflare • 3h ago

Today, end users carry too much of the burden of online privacy. To avoid third-party trackers or targeted ads, users are instructed to use a VPN, disable cookies, or install adblockers. Meanwhile, some app developers end up knowing more about their users than they’d care to: a typical client-server exchange creates a trail of user data, like the client’s IP address or TLS fingerprint. This level of visibility can be a burden. That’s why Cloudflare builds infrastructure that helps developers bake privacy into their apps. Oblivious HTTP (OHTTP) is an IETF standard designed to enable app backends to receive HTTP requests without seeing user IP addresses. This fall, we’re launching the Cloudflare OHTTP Gateway. Customers will be able to enable our new OHTTP Gateway as a paid add-on to their zone and start receiving OHTTP traffic with just a few clicks. Register through our form to join our waitlist. Read on to learn more. Expanding our OHTTP product suite With OHTTP, requests travel through two independently-operated hops: a relay and a gateway. An OHTTP relay blindly forwards encrypted requests in order to hide client identifiers from app servers. An OHTTP gateway performs the cryptographic work of decapsulating encrypted requests and encapsulating responses such that app servers can handle OHTTP requests as if they were plain HTTP. The separation of trust between relay and gateway is critical: it ensures that no single party sees both client identifiers and request contents. In 2022, we launched an OHTTP relay product, Privacy Gateway . Privacy Gateway ena

Cloudflare • 3h ago
APT

We launched Quick Tunnels in 2021 to give developers an easy way to share their latest service, application, or project running in their local development environment. A lot has changed since then, but the core use case remains the same. Your coding agent has just finished the feature. The dev server is up on localhost:5173 , and before you ask, the agent offers to let you try it on your phone. It runs one command and hands you a link: That command starts a Quick Tunnel . cloudflared , Cloudflare's lightweight connector, publishes your local service at a random trycloudflare.com URL. No account, no domain, no cost. Agents now use Quick Tunnels for the same reason people do: they are the shortest path from a local port to a URL. The catch has always been the same. Anyone with the link can open it. Starting with cloudflared 2026.9.3, you can add --allowed-mail to the command, and your Quick Tunnel only lets in the email addresses and domains you choose. Visitors prove they own one of those addresses with a one-time PIN from Cloudflare Access . Nobody, on either side, needs a Cloudflare account. Agents made Quick Tunnels more popular than ever Agents that write code need somewhere to show you the result. Agents that live on a Mac mini at home need to be reachable from your phone. Model Context Protocol servers on a laptop need a public endpoint before a hosted assistant can call them. Each of these needs a URL, and a Quick Tunnel produces one

Cloudflare • 3h ago

Cloudflare is now the fastest provider in 74% of the 1,000 largest networks around the world, up from 60% in April 2026. This huge improvement matters because every millisecond affects how quickly users can reach the applications, APIs, and websites they rely on. In this Birthday Week performance update, we’ll review how we get our measurements, introduce a new measurement methodology using Cloudflare Challenge Pages, and discuss where these improvements have had the biggest impact for customers. Cloudflare is fastest in 74% of top networks In August, Cloudflare was the fastest provider in 74% of top networks, up 14 percentage points from our last update during Agents Week in April. The figure below shows the countries where Cloudflare is the fastest provider. We improved from 60% to 74% by becoming the fastest provider in an additional 150 networks out of that top 1,000, and there are 38 additional countries where Cloudflare now ranks as the fastest. We measure this by looking at the fastest provider for users on the networks serving the largest number of users in each country. The graphic below shows countries where Cloudflare has become the fastest provider across those networks since April. Here you see the number of additional networks on which Cloudflare is now the fastest. How do we get these measurements? Our analysis begins with the 1,000 largest networks in the world, ranked by estimated user population using data from APNIC . Because these networks cover users across a wide range of geographies and access environments, they give us a useful view into how people actually experience the

The Hacker News • 3h ago

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these

The Hacker News • 4h ago

The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is

Trail of Bits • 5h ago

Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a common stumbling point when cryptographers try to use hashes. As part of our goal to “fix software, not bugs,” Trail of Bits is introducing SequenceHash and its sister function SequenceMAC , a pair of related hash constructions that bring secure multihashing to developers using hash functions other than Keccak. We hope SequenceHash and SequenceMAC will help cryptographers avoid attacks that take advantage of ambiguous input encodings. The specification is open source, and is now a part of the Community Cryptography Specification Project (C2SP). SequenceHash and SequenceMAC behave similarly to NIST’s TupleHash , but have the advantage of not being tied to a single hash function. They also don’t require developers to implement fiddly computations that aren’t byte-aligned. Instead, SequenceHash and SequenceMAC work out of the box with nearly any secure cryptographic hash function you care to use, including SHA256/384/512, BLAKE, and RIPEMD. SequenceMAC supports keys 32 bytes or longer (up to the ridiculous limit of ${2}^{128}-1$ bytes). (It’s worth noting: SequenceHash and SequenceMAC rely on the security of the underlying hash for their own security. SequenceHash and SequenceMAC can’t magically make MD4 or SHA0 secure again. For the purposes of this document, it’s assumed that you have chosen a reasonable hash function like SHA256, not CRC32.) To make SequenceHash and SequenceMAC easy to use, we’re releasing

Compass Security • 6h ago
CVE

Introduction Pwn2Own is a renowned hacking competition organized by the Zero Day Initiative (ZDI), where security researchers demonstrate previously unknown vulnerabilities in popular software, operating systems, browsers, IoT devices, and other technologies. Having participated in both the 2023 and 2024 editions of Pwn2Own, we decided to take another shot in 2025. This time, our goal was to avoid collisions, where multiple teams discover the same vulnerability during the same event, leading to reduced prize money and fewer Master of Pwn points. This blog post walks through our journey from discovery to full exploitation. We start by exploring the Home Assistant device architecture, then detail how we found a remote code execution vulnerability in an add-on. From there, we show how we leveraged it to pivot to the underlying operating system and achieve root-level access. We conclude with our experience at the Pwn2Own 2025 Cork edition. Target Selection We started by looking at several different targets. Our initial list included the Wyze Cam Pan v3 and the Synology CC400W from the surveillance system category, the Brother MFC-J1010DW from the printer category, the Philips Hue Bridge and the Home Assistant Green from the smart home category. After assessing the various targets, we shifted our focus to the Home Assistant Green due to the progress we had made on that platform. This led us to the discovery of an exploit chain that resulted in an unauthenticated remote code execution vulnerability. Device Overview

The Hacker News • 8h ago

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a

Synack • 10h ago

Synack was named a Leader in G2's Fall 2026 Grid® and Enterprise Grid® Reports for Penetration Testing. The reviews show what customers value in a pentesting partner: visibility into testing, access to experts, findings they can fix and verify, and a partner that acts on feedback. The post What Customers Value in a Penetration Testing Partner: Insights from G2 Reviews appeared first on Synack .

The Hacker News • 10h ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper

Thursday, October 1
r/computerforensics • 18h ago
APT

I've been picking through a SCADA-style telemetry capture and I can't explain what I'm seeing. The file has 14 authorisation records, each with its own CRC. All 14 validate. The file header carries a CRC-32 over the whole block, and that one fails. Two of the operator-name fields are zeroed. My reading is that someone blanked those fields, recomputed the per-record CRCs so they'd pass, and never touched the block CRC. But I'd like a sanity check — is there a corruption mode that breaks a block checksum while leaving every record checksum intact? File (8.8MB): www.[st88openocean.github.io/slip-three/MCA-CTL-0314-RAW.slice](https://st88openocean.github.io/slip-three/MCA-CTL-0314-RAW.slice) Published digests for it are here: www.[st88openocean.github.io/slip-three/archive](https://st88openocean.github.io/slip-three/archive)

r/cybersecurity • 18h ago

I started a blog series to provide free insights into appsec. It’s mainly to breakdown what application security is all about and it’s mainly targeted towards beginners and startups, so take it as you will. I want to teach every one interested in appsec my perspective on it from my experience in big tech. In this blog post we talk about how to do “proper” threat modeling and it isn’t through a framework! Please reach out if you have any questions or would like for me to write on a topic that you’d want to learn more about.

r/cybersecurity • 21h ago

FELG Software sp. z o.o., the Polish maker of the FELG Dent application for dental practices, told customers on October 1, 2026, that it had been attacked. In a statement on the company's status page, CEO Grzegorz Stawarz said an attacker claiming to belong to the "Fingerprint" group may have accessed patient data that dental practices had entrusted to FELG for processing. The attacker says he holds about 10% of the database and wants a ransom to keep it unpublished. FELG has notified the prosecutor's office and contacted UODO, Poland's data protection authority. The company's preliminary estimate is around 2 million affected patient records. That figure is based partly on the attacker's own claims. The records include: * names, addresses and PESEL numbers (Poland's national identification number) * medical data * information related to e-prescriptions * e-ZLA records (electronic sick-leave certificates) * eWUŚ checks (the system practices use to verify a patient's public health insurance) FELG notes that the number of records doesn't necessarily match the number of people. It expects results from its log analysis within a few days. The company says it knows how the breach happened but won't disclose technical details. # What the attacker claims The attacker, who calls himself Horus, contacted two Polish IT security news sites, Sekurak and Zaufana Trzecia Strona (Z3S). He told Sekurak he had data on 2.4 million [felgdent.com](http://felgdent.com) patients. He said this included PESEL numbers, names, addresses, phone numbers, NIP tax identification numbers and each patient's dental practice. He also claimed 1.2 million prescriptions, visit records, e-ZLA records, eWUŚ tables, files and photographs. He also claimed 712,000 staff records. FELG denied that figure immediately, and he lowered it to 28,000, blaming duplicate records. Sekurak received a sample of data on several well-known people but could not confirm it was genuine, since it might have come from earlier breaches. Z3S gave the attacker the PESEL numbers of eight people who had agreed to the test. None of them were in his database. According to Z3S, Fingerprint had nothing to do with the attack, and the group itself confirmed this. The attacker admitted to Z3S that he had brought up the attacks on MyDr and Medyc when talking to FELG to make his ransom demand more intimidating. His account of the method is a textbook IDOR (insecure direct object reference) flaw. He says he created a demo account and found API endpoints that didn't check authorization. By incrementing a query parameter, he could pull successive patients, prescriptions and doctors. He says he started downloading data on September 6. FELG told Z3S it learned of the incident on September 28 at around 6 p.m. The attacker also says the attack was spotted after several days and the faulty endpoint was fixed. He claims he then found other endpoints with the same flaw and kept using them for a while. None of this is verified, and FELG isn't commenting on technical details. Because FELG broke off negotiations and went public, he says he will sell the database on Cebulka, a Polish-language dark web forum. # How big is FELG? Sources disagree. Sekurak cited 16,000 dental practices. FELG's website claims more than 4,000 practices, more than 16,000 doctors and hygienists, and more than 12 million patient records. Z3S, also going by the website, reads the 16,000 figure as dentists using FELG's tools. Z3S says the leak may involve more than 2 million people. In its statement to Sekurak, FELG spoke of about 2 million records. # What affected practices should know Under GDPR, a practice using FELG Dent is the data controller for its patients' data, and FELG is its processor. FELG has asked customers not to report the breach to the President of UODO (the head of the authority) until it formally confirms whether a given practice is affected. After the weekend, affected practices are due to receive a ready-made UODO notification and a free tool for notifying patients. The other practices will get confirmation that their data was not affected. Article in Polish here: [https://pelnomocnikcyber.pl/aktualnosci/felg-dent-incydent-dane-pacjentow/](https://pelnomocnikcyber.pl/aktualnosci/felg-dent-incydent-dane-pacjentow/)

Synack • 22h ago

Before you build an AI pentesting agent, run it through 5 tests for production readiness. Mark Kuhr breaks down what separates a prototype from a system. The post Build or Buy AI Pentesting? 5 Tests to Judge Production Readiness appeared first on Synack .

The Hacker News • 23h ago

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected

The Hacker News • 23h ago

This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can

r/netsec • Oct 1

A blue-team writeup on detecting a compromised MikroTik from its own config. Seven techniques, each with the collection command, the artifact it leaves behind, and a triage step. Feedback welcome.

The Hacker News • Oct 1

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

CERT/CC • Oct 1

Overview An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code executes in System Management Mode (SMM), successful exploitation can allow an attacker to modify SMM-protected memory and potentially achieve arbitrary code execution in SMM. Depending on the platform's memory and firmware configuration, the arbitrary physical memory write primitive may also have implications for UEFI firmware update or flash-related operations. Description HP PC BIOS is firmware that initializes and manages hardware components during the boot process and provides runtime services to the operating system and provide the ability to update firmware. The affected system uses InsydeH2O Kernel version 5.5 or earlier. The BIOS includes custom HP SMM handlers that execute in System Management Mode (SMM), a highly privileged CPU execution mode that is isolated from the operating system. CVE-2026-12855 : An Out-of-bounds Write vulnerability in the H19WMIHandlerSmm module (GUID f1946499-571b-44c3-9b9c-cc55210b0c02) allows a local attacker with OS kernel privileges to read or write arbitrary physical memory, including SMRAM, through a Software SMI handler. An attacker with kernel-level privileges can trigger the vulnerable SMM handler by issuing a Software System Management Interrupt (SMI) through I/O port 0xB2 and supplying specially crafted CPU register values. The vulnerable handler does not adequately validate the supplied parameters before performing memory operations, allowing the attacker to influence the physical address and data involved in the operation. Because the affe

Cloudflare • Oct 1

It's Birthday Week, when we traditionally ship presents to the Internet. This year, two of them come from Europe: EuroLLM, which covers all 24 official EU languages, and Apertus, Switzerland's fully open model, trained on more than 1,500 languages. Both were built by public universities and research institutions. Both are coming to Workers AI, and you can request access today. We're also launching hands-on workshops that help government cyber agencies and critical infrastructure operators build AI defenses that work with any model. The first runs in Singapore in October. Today's announcements follow from an argument we made a year ago , when questions about AI access and sovereignty were swirling in national capitals. Our answer was choice: the freedom to pick the right tools for the job, and to switch when you need to. Since then, those conversations have hardened. Attackers have used frontier models to run cyber attacks. Access to some frontier models now depends on where you are. Calls to restrict open models are getting louder. Put it all together and it's easy to conclude that AI sovereignty is zero-sum: every model another country controls is one you can't count on, so the safe move is to build walls. We think the past year can point the other way. India, Japan and Singapore focused on open-sourced models, and people across Asia-Pacific built tools on them for rural citizens, elderly patients and the nurses who care for them. Our own security team built AI defenses that work with any model, so losing access to one doesn't mean losing your defenses. Helping build a better Internet has always meant more options, not fewer. That's why we work on open standards that prevent vendor lock-in , why so much o

Cloudflare • Oct 1

Today, we’re introducing Workers KV Instant, a new mode for Workers KV that pushes your changes globally for instant availability without cold read penalties. Workers KV has been one of our most popular services on the Developer Platform since launching during Birthday Week in 2018 . It’s great for quickly accessing data like static assets and user configuration that is written occasionally but read frequently. We use it ourselves across many Cloudflare products. We also have another key-value store, Quicksilver, which we’ve blogged about many times since introducing it in 2020 . We designed Quicksilver for incredibly fast global replication and low-latency access, and nearly every request to Cloudflare looks up at least one key in Quicksilver. People have asked us for years, but we’ve never made Quicksilver available to our customers. We’re changing that today with Workers KV Instant. KV Instant mode provides the same API as Workers KV, but powers it using Quicksilver. KV Instant offers 100 times faster p99 reads and immediate updates, with no need to wait for a TTL to expire. It’s not for every type of data, but, for infrequently updated application configuration data — the same thing we use Quicksilver for ourselves — KV Instant shines. 100x faster reads than Workers KV KV Instant offers read latency that is over 100 times faster than classic mode, with reads resolving in under two milliseconds even at th

Cloudflare • Oct 1
CVE

Cloudflare OS gives everyone in your organization an agent workspace that knows how your company works and connects to its data and systems. Today, we're opening the waitlist for fully managed Cloudflare OS deployments. If I asked you to prepare for an important customer meeting later today, what would you do? You might learn how your company typically runs customer meetings, review the account in your CRM, check recent support tickets and product usage, then turn it into a short presentation to review with the group. Now imagine doing that another 100 times this month. Every team has work like this. With Cloudflare OS, you can ask your agent to handle the work for you, build a tool for your team, or move between the two as the work evolves. Last month, we announced Cloudflare OS and shared the open source repository . Since then, thousands of organizations have started using it to work with company data, produce docs and slides, build tools for their teams, and automate work with agents. With a few clicks in the Cloudflare dashboard, you’ll be able to launch your organization’s own agent workspace. Just tell us what custom domain you want to use, what Cloudflare Access policies apply, and which AI Gateway to connect. We’ll handle the rest. Cloudflare OS, managed for you Every

Heimdal Security • Oct 1

Benedict Jones spent years working for McAfee and Sophos. While doing threat research at Sophos, he spotted a problem in mobile threat defence that nobody had actually fixed. He’s now CEO and founder of Trustd Mobile, and the story of how he got there says more about MSP buying decisions than most vendor pitches ever […] The post Innovation wins. Why smaller beats bigger appeared first on Heimdal Security Blog .

The Hacker News • Oct 1

Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date

The Hacker News • Oct 1

OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any

The Hacker News • Oct 1
CVE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with

WIRED • Oct 1

In an exclusive interview with WIRED, Paragon Solutions CEO Andrew Boyd reveals the limits of the company’s promise to keep bad actors from abusing its powerful espionage tool.

The Hacker News • Oct 1

Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu,

Heimdal Security • Oct 1

London, UK, 1 October 2026 – Heimdal, a global cybersecurity provider, today announced a partnership with Elovade, a European IT security distributor with 250 experts across five countries, to bring its unified security platform to managed service providers (MSPs) across the DACH region: Germany, Austria, and Switzerland. The move extends a relationship that began a […] The post Heimdal partners with Elovade to bring unified cybersecurity platform to the DACH region appeared first on Heimdal Security Blog .

The Hacker News • Oct 1
CVE

Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working

The Hacker News • Oct 1

Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker

The Hacker News • Oct 1

MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet maker said. "At this time, we have identified no immediate threat to MetaMask wallets." MetaMask

The Hacker News • Oct 1
APT

Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler

Wednesday, September 30
The Hacker News • Sep 30

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol

The Hacker News • Sep 30

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared

The Hacker News • Sep 30

Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1.

Tuesday, September 29
r/netsec • Sep 29
CVE

OpenBao engineers at [ControlPlane](https://control-plane.io/) have chained 4 vulnerabilities to show how under certain conditions, an OpenBao or Vault server can be completely compromised from an unauthenticated position. This is only the second RCE ever found in the Vault codebase. The exploit is highly plausible in real-world environments, requiring only an unauthenticated entry path and a defined Raft snapshot policy to trigger a complete server compromise. If you are impacted, upgrade as soon as possible to OpenBao 2.6.3 or 2.7.0 While OpenBao is fully patched, HashiCorp Vault remains exposed as of writing. Unfortunately, IBM's unwillingness to coordinate a mutual disclosure policy means Vault users currently lack an official mitigation

r/netsec • Sep 29

This is an article about the internals of Win32k (Windows's GUI subsystem) and their callouts, with the purpose of shedding light on a very undocumented and crucial subsystem in Windows :)

The Guardian • Sep 29

The need for independent regulation grows more obvious by the day. We must keep this tech in check before it’s too late OpenAI scraps release of new model over safety concerns in internal testing Fool me once, shame on you. Fool me twice, shame on me. Fool me more than 16,000 times – as OpenAI agents did to a UN public data hub while repeatedly trying to find its way around the UN’s cyber-blocks – and perhaps it’s time to admit the system we have for keeping AI agents under control isn’t working particularly well. The news about AI systems cropping up in places they shouldn’t sounds alarming. Though the description of these as “hacks” is perhaps overstating things, AI has exploited issues in IT systems that humans simply haven’t got around to finding. It’s also important to note that we shouldn’t be worried that the machines have suddenly become sentient and decided to rebel against humanity . There is not enough evidence to suggest that’s what is happening. The systems are simply following instructions and trying to complete the tasks they have been given, even if they’re sometimes finding unintended ways around obstacles to do so. Chris Stokel-Walker is the author of TikTok Boom: The Inside Story of the World’s Favourite App Continue reading...

Monday, September 28
CERT/CC • Sep 28

Overview Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() function accepts a JWS object with an empty "signatures" array and treats the payload as successfully verified, allowing attackers to supply arbitrary forged content without possessing any key material. Description Authlib is a Python library that provides tools for implementing OAuth, OpenID Connect, JWT/JWS/JWE (JSON Web Token / JSON Web Signature / JSON Web Encryption), and other modern authentication and authorization standards. It’s widely used in web applications and microservices to handle token creation, cryptographic validation, and secure communication. As discussed in CVE-2026-96760 , a security flaw in Authlib’s handling of JSON Web Signatures (JWS) makes it possible for an attacker to skip signature verification completely. Normally, a JWS should include at least one valid signature to prove the data hasn’t been tampered with. However, Authlib’s deserialize_json() function mistakenly accepts JWS objects even when the "signatures" section is an empty list. Because the function starts by assuming the signatures are valid and never performs any checks when the list is empty, it ends up treating unsigned data as if it were properly signed. This means an attacker could provide a JWS with no signatures, and Authlib would still treat it as trusted. Both ways of loading a JWS in Authlib are affected: jws.deserialize_json({"payload":"...", "signatures":[]}, key=None) jws.deserialize('{"payload":"...","signatures":[]}', key=None) Impact A

r/Malware • Sep 28
CVE

It's called Click Scout - you hover over the link or email sender, and it tells you if it's safe or not. Were gonna push it out to a couple of our repeat offenders at my company. 100% free, just built it to help fewer people get suckered into clicking on stupid stuff. [https://chromewebstore.google.com/detail/clickscout/ekmbgkphebegmfflhfceppmpcheldfak?hl=en-US&utm\_source=ext\_sidebar](https://chromewebstore.google.com/detail/clickscout/ekmbgkphebegmfflhfceppmpcheldfak?hl=en-US&utm_source=ext_sidebar)

Krebs on Security • Sep 28

Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters . In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p . According to three sources familiar with the matter, the Dutch man arrested by authorities this month is Pepijn van der Stap , a convicted cybercriminal from Almere and Lelystad in the Netherlands. Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between €1.5 million and €2.7 million. At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle “ Umbreon ” to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached. By day, however, van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian , while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research group.

watchTowr • Sep 28
CVE

God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up or bothered to acknowledge them. https://www.citrix.com/blogs/2026-01/security-by-design-proven-by-action-with-citrix-netscaler On Saturday, we took our role in the industry seriously - by rapidly adding credibility to the rumors via the (inter)national authorities that we've historically worked with, and then broadcasting that increased confidence to the watchTowr client base and the public. We made the call that our language needed to be clear: given active exploitation in the wild and the critical nature of many of the organizations that run NetScalers, appliances should be taken offline, and that this was "going to be bad." We we

Troy Hunt • Sep 28

Presently sponsored by: If an AI agent caused an incident tomorrow, what evidence could you produce? Origin and analyst firm SACR answer it live Oct 1. Register. How's that view?! With NDC Oslo now done, it's a little bit of sightseeing before heading to Denmark for GOTO in Copenhagen for Scott's and my "Cyber-broken" talk. In the meantime, this week is mostly about the ShinyHunters trajectory targeting both Cl0p and the FBI, which does feel a little like a crescendo in their activities. Time will tell, but poking the feds in this way doesn't seem great for your longevity. In my disorganised travel state, I also forgot to touch on a brand new sponsor for this week and the weeks to come: Origin . They build tooling to monitor what your AI agents are doing, which is obviously pretty timely given the current climate. They're running a free CISO briefing on 1 Oct , so go check that out if you think maybe your agents might need some oversight.

GreyNoise • Sep 28

On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the attack due to it occurring pre-disclosure. However, GreyNoise still detected and labeled the activity as fundamentally malicious within seconds due to behavioral detections.

Saturday, September 26
Friday, September 25
Krebs on Security • Sep 25
CVE

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims. One of several selfies from the Facebook page of Cameron Wagenius. Cameron John Wagenius , 22, was stationed at a U.S. Army base in South Korea when he adopted the cybercriminal persona “ Kiberphant0m .” Working with three alleged co-conspirators, Kiberphant0m downloaded data from several large customers of the cloud data storage service Snowflake that had exposed credentials and did not enforce multi-factor authentication (Snowflake has since mandated MFA on all accounts). In October 2024, Kiberphant0m bragged on the cybercrime forums that he’d stolen the call and text metadata (e.g. source and destination number, timestamp, duration, etc.) for tens of millions of AT&T customers. Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data. In late November 2025, KrebsOnSecurity warned that Kiberphant0

CERT/CC • Sep 25
CVE

Overview Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned content that bypasses sanitization. Successful exploitation could allow the attacker to execute arbitrary JavaScript within the application's WebView context and compromise the confidentiality and integrity of user data, including access to stored documents, credentials, and session tokens. Description Readwise Reader from Readwise is designed to provide a unified read-it-later service that helps individuals collect and organize articles, newsletters, videos, and other content of interest into a single reading interface. It is available on multiple platforms including Android and can synchronize content across devices. CVE-2026-18311 : A stored cross-site scripting (XSS) vulnerability in the header rendering component in Readwise Reader for Android version 8.7.2 allows remote attackers to execute arbitrary JavaScript via crafted document metadata fields. The header rendering component is impacted due to insufficient HTML escaping of metadata fields such as 'doc.author' and 'doc.title', which allows malicious scripts to be stored in the user's library and synchronized to Android devices where they are executed in the WebView context. CVE-2026-18312 : A stored cross-site scripting (XSS) vulnerability in the WebView URL construction logic in Readwise Reader for Android version 8.7.2 allows remote attackers to execute arbitrary JavaScript via malicious URL metadata. The WebView URL construction for X (formerly Twitter) video fallback and iOS paywall messages is impacted due to improper escaping of URL metadata before interpola

Story Overview