Cybersecurity News and Vulnerability Aggregator

Cybersecurity news aggregator

Top Cybersecurity Stories Today

Latest

Monday, October 5
r/cybersecurity • 2h ago

A recently discovered Linux backdoor turns infected systems into proxies that use the Session Traversal Utilities for NAT (STUN) protocol and contains exploits for self-propagation, FortiGuard Labs reports. Dubbed ClingSTUN and functioning as a back-connect proxy backdoor, the malware targets two dozen vulnerabilities for initial access and sets up persistence to ensure malware execution during the boot sequence. The malware’s operators were seen indiscriminately exploiting Avtech, EnGenius, D-Link, Hytec, Ivanti, Lantronix, Linear, MeiG, Realtek, Sunhillo, Tenda, and TP-Link flaws, and appear to be expanding their portfolio with other exploits as well. Reported in October 2026. More details: https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure

r/cybersecurity • 2h ago
CVE

Over the last couple of weeks, I challenged myself to build a tool that centralizes everything you need when conducting recon. And that’s how Kumo was born. Give it a domain and it hands you back everything reachable from outside. What it does in one run: * Maps the surface : DNS, ports, certificates, subdomains, tech stack * Finds what shouldn't be public : exposed configs, secrets in JS, open buckets * Checks for known vulnerabilities without touching anything * Digs up leaked credentials and which employee machines got infected * Pulls in archived pages, forgotten endpoints, threat intel * Builds Google dorks and OSINT links for the target All 27 modules run at once and stream back as they land. No API keys required, CLI and web interface. Works on any domain you're allowed to test. 🔗 [https://github.com/karim852/KUMO-Domain-Recon-Tool](https://github.com/karim852/KUMO-Domain-Recon-Tool) 🖥️ live demo: [https://demo-kumo-kage.vercel.app](https://demo-kumo-kage.vercel.app/demo/kumo/index.html) 🎥 2-min walkthrough: [https://www.youtube.com/watch?v=dM-KbBU93ZM](https://www.youtube.com/watch?v=dM-KbBU93ZM) Feedback and contributions welcome 🙏

r/netsec • 2h ago

I was going through the SelectorsHub code, id:**ndgimibanhlabgdgjcpbbndiehljcpfh** the XPath extension with about **400k users**, and noticed it pulls ads from its own server and opens them in a background tab. You don't click anything. Every couple of days the side panel pops up a "**community link**" and says "100% Safe, No Spam, No Malware." Five seconds later the tab opens by itself. The URL isn't in the extension. Their server picks it, and while I was analysing the extension the links changed three times with no extension update. On install and update it skips the popup and just opens whatever the server sends. The store page says they collect no data. The code still pings them daily, and the extension reads all your cookies to find one of its own instead of just fetching its own cookie value. Another weird finding: there's a hidden Fix Selector button that sends the selector to shubads\[.\]testcasehub.net. [VirusTotal - Domain - shubads.testcasehub.net](https://www.virustotal.com/gui/domain/shubads.testcasehub.net) That host now redirects to a gambling site, blomehairdryers\[.\]com. Nothing gets run today because the reply is HTML, but that's the server the eval path trusts. Looks like adware, not password theft. I wouldn't leave it on a work browser, especially since this is a tool used by devs and tech people browsing protected endpoints in a company. Write-up: [https://malext.io/reports/RedirectorsHub/](https://malext.io/reports/RedirectorsHub/)

r/blueteamsec • 2h ago
CVE

Hey, I’ve been working on a project called **DetectTrace** and just made the first public release. It’s an open-source tool for testing security detections end to end and showing where the detection pipeline failed. It checks things like telemetry, normalization, rule matching, rule state/execution, and whether the expected alert was actually generated. It can also correlate Elastic Security alerts back to the exact test run, so an old alert can’t make a new test pass. Right now it supports offline detection tests and live Elastic Security testing, plus JSON/JUnit output for CI. It’s still early, but I’d be interested to hear what people think. If anyone wants to have a look or try it: [https://github.com/g0dse11/detecttrace](https://github.com/g0dse11/detecttrace) Happy to hear any feedback or criticism.

r/cybersecurity • 4h ago

It says "... CISA will discontinue the weekly Vulnerability Bulletin at the end of FY26 (September 28, 2026) as part of a broader shift from severity‑based vulnerability management to risk‑based vulnerability prioritization. Newly recorded vulnerabilities remain available on [CVE.org](http://CVE.org), and users should rely on the Known Exploited Vulnerability (KEV) Catalog, CISA Cybersecurity Alerts and Advisories, and vendor security alerts for actionable, risk‑based updates. Visit our Subscribe to Updates page to sign up to receive automatic updates from CISA with the latest news and information..." I was wondering why nothing today! Bah to those frequent updates. I just want weekly ones. :( Does anyone know of a good one like old CISA's weekly bulletins?

r/cybersecurity • 5h ago

Hi Reddit! 👋 I'm [**Jeff Crume**](https://ibm.biz/~VA32MD7RJ), Distinguished Engineer and Master Inventor at IBM Security. For over 44 years, I've worked across cybersecurity, cryptography, software engineering, and emerging technologies. You may also know me from the [**IBM Technology YouTube**](https://ibm.biz/~dhPhWs0LV) **channel**, where I help break down complex security topics for a broad audience. I've spent much of my career helping organizations understand evolving cyber threats and how to better defend against them. In addition to this, I’m currently an adjunct professor at NC State University. And I'm [**Guido Crucq**](https://ibm.biz/~3KLoYDOJm) 👋 a cybersecurity leader at IBM Security focused on helping organizations strengthen their defenses against today's most pressing security challenges. Throughout my career, I've worked with organizations around the world on cybersecurity strategy, risk management, security operation and incident response. I'm passionate about helping businesses make informed security decisions in a rapidly changing threat landscape. **Join us for a live AMA on October 6 at 10:00 a.m. ET.,** where we'll discuss findings from our [**Cost of a Data Breach Report**](https://ibm.biz/~G54tWK9DB). The report examines incidents from organizations around the world to uncover what drives breach costs, how attack trends are evolving and which security investments make the biggest difference. Happy Cybersecurity Awareness Month! Ask us anything.

The Hacker News • 7h ago
CVE

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a

The Hacker News • 9h ago

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others

Cloudflare • 10h ago
CVE

We celebrated our 16th birthday last week by sharing how we’re building a better Internet for today’s world. As Matthew and Michelle reflected in this year’s Founders’ Letter , this year saw some of the most consequential changes in the history of the Internet. For the first time, automated traffic surpassed human activity. AI is empowering people to build like never before, leading the Internet to grow massively in scale and unlocking more ambition and creativity. As we witnessed the influence that agent-driven recommendations have on consumer choices, we identified the need for a new approach that creates space for new businesses to succeed. Each day of Birthday Week explored a different way we are helping to build the future of the Internet. We began on Monday by strengthening our commitment to open source. Tuesday focused on application security and the post-quantum transition. On Wednesday, we explored new economic models for the agentic Internet. Thursday, we expanded the Developer Platform with new tools for data analysis, storage, AI, and agent development. Finally, we closed out the week by launching features that make Cloudflare faster, easier to operate, and more accessible to everyone. As a special Birthday Week follow-up, we shared an update on our intern program, one year after announcing our goal to hire 1,111 interns . Interns directly contributed to many of the projects launched this week, including EmDash, post-quantum visibility, CryptoLabe, and Protected Quick Tunnels. We shipped 46 announcements this week. In case you missed any, here’s the full list of everything we announced during Birthday Week 2026. Monda

Cloudflare • 10h ago

A year ago, many companies were cutting intern and new-graduate hiring . We went the other way. We announced a goal to hire as many as 1,111 interns in 2026, a number that’s a nod to 1.1.1.1, our public DNS resolver. The bet was that AI makes early-career talent more valuable and able to make an impact faster. The best AI tools help people learn a system faster, try more ideas, and take on harder problems. They don’t supply the energy, curiosity and fresh eyes a new person brings to a team. A year in, and our interns are shipping to our internal teams and to millions of customers. If you’re reading this on the Cloudflare Blog, you’re already using some of their work. The blog runs on EmDash , and EmDash’s second maintainer started at Cloudflare as an intern this past summer. A new generation of builders We’re still working toward 1,111. So far, we’ve hosted 750 internships across 48 teams in nine offices: Austin, San Francisco, London, Lisbon, New York, Singapore, Bengaluru, Washington DC, and Sydney. And we’re still hiring. From their first day, interns joined active teams and worked on real problems. Each was expected to leave something behind: a shipped product improvement, a better process, a new piece of infrastructure, or an insight that changes how a team approaches its work. That work reached far beyond engineering. An internal audit intern built an AI-assisted pipeline to automate ISO compliance control testing and documentation. A product manager intern worked on an API, dashboard, and migration tooling to moder

The Hacker News • 11h ago

Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and what they

The Hacker News • 11h ago

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report

The Hacker News • 12h ago

Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge

Synack • 13h ago

A year since launching Synack’s integration with Qualys, the partnership now includes broader platform support, more AI-led testing, and a shared presence at Qualys ROCon Americas 2026. The post Turn Scanner Findings into Validated Risk with Synack and Qualys appeared first on Synack .

r/ReverseEngineering • 16h ago

To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have better luck on the [Reverse Engineering StackExchange](http://reverseengineering.stackexchange.com/). See also /r/AskReverseEngineering.

The Hacker News • 16h ago

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to

r/Malware • 17h ago

I wrote up my investigation into @goodjavascript/dotenv@1.0.0, including how to recover its entry-point file after the npm tarball and jsDelivr file URLs returned 404. The useful detail: Software Heritage’s latest snapshot contained only the security placeholder. An older snapshot retained the original release and its 840-byte index.js. Its SHA-256 matched the digest still available in jsDelivr’s file manifest. Static inspection showed a timer scheduled at module load that collects host information and can execute JavaScript supplied in a server response. The package had no installation scripts, and its exported config() function was empty. The article includes the package-to-archive discovery steps, dated evidence, an annotated code excerpt and a Python verifier that retrieves and hashes the file without executing it. It also links my analysis contribution to the existing OSV advisory. [https://cgsec.dev/research/dotenv-recovery/](https://cgsec.dev/research/dotenv-recovery/) This concerns the scoped @goodjavascript/dotenv package, not the unscoped dotenv package. Have you used other archives or retained metadata sources to recover removed package evidence?

r/blueteamsec • 17h ago

Hey everyone, I wanted to share a self-hosted, open-source project I’m currently developing called OpenDRP. You can find the repository at https://github.com/OpenDRP/opendrp and the main site at opendrp.dev. We have great open-source tools for Threat Intelligence, like OpenCTI, and various EASM solutions, but the Digital Risk Protection space is still heavily dominated by expensive enterprise SaaS products. I wanted a modular, self-hosted alternative to monitor external brand threats, so I started building one. The project is in its early stages as an MVP. Instead of trying to parse every obscure darkweb forum from day one, I focused on building a solid, scalable backend architecture and integrated three core data sources to prove the concept. For phishing intelligence, it uses dnstwist to automate monitoring for domain mutations and active lookalike domains. For shadow IT and brand hunting, it leverages Shodan to discover rogue assets and exposed infrastructure. Additionally, it tracks compromised corporate accounts via Have I Been Pwned for breach monitoring. Whenever a new threat is detected, the system generates PDF reports and sends alerts via Telegram or Email. Under the hood, the goal was to make the platform extremely easy to scale and extend. The backend is built with FastAPI and Python, using PostgreSQL for the database. Asynchronous scans and integrations are handled by Celery and Redis workers, and the entire project is distributed under the AGPL-3.0 license. Since the core engine, including the database schema, UI, and async queues, is up and running, I am currently working on expanding the integrations to include Certificate Transparency logs and GitHub secret scanning. I would love to get your feedback on the architecture and hear what external data sources or modules you would consider absolute must-haves for a DRP platform. If anyone is interested in writing simple Celery connectors for new APIs, pull requests and code reviews are more than welcome. Cheers!

Sunday, October 4
Troy Hunt • Oct 4

Presently sponsored by: Where are your AI agents? Origin's sensor finds every install on your fleet, grouped by owner, including the ones your MDM never sees. I'm in Denmark! Well, just, I'm now at Copenhagen airport ready to begin the long trek home, with the final event at GOTO now done and going just perfectly. This week, there are two ShinyHunters arrests in the news: Pepijn in the Netherlands and then Saif in Jordon . It's an inevitable outcome, of course, and as I say this week, it was also the most likely one. Time will tell how many more join their ranks, but the seriousness of the crimes, the length of time they were perpetrated over, and the motivations behind them will certainly see substantial custodial sentences. In other news, this week I'm properly introducing a new sponsor for the blog: Origin . One of our next AI frontiers is understanding what agents have actually done (and we've all seen news of where they're been a bit too, well, "creative" in executing their tasks), and Origin's solution gives you visiblity into just that. Check them out, and a big thanks to them for their ongoing support.

The Guardian • Oct 4

David Robinson joins other insiders in urging industry to take more care over rapidly developing technology A safety leader at OpenAI has quit the company, warning that its culture was broken and that AI firms were not “being nearly careful enough” about developing the technology. David Robinson, who led the writing of safety reports that accompanied the ChatGPT developer’s product releases, explained his resignation in an essay headlined: “I quit OpenAI because its culture is broken.” Continue reading...

The Hacker News • Oct 4

A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, and cooperating with the U.S. Federal Bureau of Investigation (FBI)

The Hacker News • Oct 4

A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a

Saturday, October 3
r/Malware • Oct 3

Confirmed security research — newly reported October 1–2. Researchers at Island documented a large malvertising operation involving roughly 850 paid-ad landings, 26 lookalike destinations and 71 Google Ads campaign IDs. People searching for ChatGPT could encounter sponsored results that initially led to attacker-created content on the genuine ChatGPT domain before directing them to a supposed “backup” site. The final trap was a fake Cloudflare verification screen using the increasingly common ClickFix technique: victims were instructed to press Win+R and paste a command. Doing so downloaded malware, with researchers observing NetSupport RAT activity capable of remote computer control. Google told Tom's Guide it suspended advertiser accounts associated with the campaign and updated its defenses. This is extremely beginner-relevant because simply checking the initial domain wasn't enough, the attackers abused legitimate hosted content and advertising to establish trust.

The Hacker News • Oct 3

The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that

The Hacker News • Oct 3

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the

The Hacker News • Oct 3

Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of

r/netsec • Oct 3
CVE

Internxt is a post-quantum secure encrypted cloud storage provider which is open-source and has passed multiple independent audits. I reviewed their code and found that post-quantum security should have been the least of their problems. Clicking a link in your browser could trigger remote code execution on the desktop app or leak your long-term encryption keys to an attacker-chosen URL. Their cryptographic architecture stands on shaky grounds with public keys never being verified, in some cases man-in-the-middled by design, a flat key hierarchy and a KDF with just 3 iterations of MD5. We need PQC and we need it now, but adding a (self-rolled) PQC hybrid on top of a weak protocol does not make it more secure.

Friday, October 2
Cloudflare • Oct 2

Today, we’re launching eight major updates that bring your logs, traces, analytics, alerts, dashboards, and exporting into one observability platform , with simpler and more predictable pricing. Here's what's launching: One place to explore logs from across Cloudflare End-to-end tracing from Cloudflare's edge to your origin One unified SQL API for querying Cloudflare data One pricing model for observability data ingested and stored across Cloudflare Custom alerts on your observability data All analytics for your domain in one place, with 30 days of data retention Custom dashboards built from your observability data Export your data with Logpush -- now available on self-serve plans One observability platform for all of Cloudflare Understanding an issue often requires data from more than one Cloudflare product. A spike in 5xx responses could come from a Worker, from your origin, or from Cloudflare failing to connect to your origin globally or regionally. But investigating it today requires knowing which product owns each signal and how to query it. Observability should be a platform-wide capability: it should reflect how applications a

The Hacker News • Oct 2

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw

The Hacker News • Oct 2

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

The Hacker News • Oct 2

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an

r/netsec • Oct 2
CVE

When analysing firmware attack surfaces, image decoders built into bootloaders get less scrutiny than cryptographically verified OS kernels. If image parsing happens before signature verification, any memory corruption in the parser breaks the secure boot trust model. researchers analysed U-Boot's video subsystem (drivers/video/video\_bmp.c) and identified an unbounded write in the RLE8 bitmap decoder (video\_display\_rle8\_bitmap()) that leads to a **pre-authentication Secure Boot bypass**. **Root Cause and Vulnerability Mechanics** When **U-Boot** displays a boot logo or splash screen, it parses a BMP image loaded from local storage (SPI flash, MMC/eMMC, USB, or SD card). **Unbounded framebuffer write:** During RLE8 decompression, `video_display_rle8_bitmap()` decodes run-length encoded streams directly into the active framebuffer without validating stream bounds against the frame boundary or allocated buffer size. **Pre-authentication execution window:** In many embedded target configurations, the boot splash screen is rendered immediately on startup, before U-Boot calls Android Verified Boot (AVB) or FIT image signature verification routines. **Storage disparity:** The kernel image and rootfs are signed, but **splash images are frequently stored in unsigned, user-writable partitions or external media**. An attacker who writes a crafted RLE8 BMP to the boot storage can trigger an out-of-bounds write past the framebuffer during early boot, corrupting adjacent bootloader data structures, function pointers, or verification flags in memory. This hijacks the execution flow before signature checking completes.

Cloudflare • Oct 2

Cloudflare Stream is a powerful broadcasting platform that, for many of our customers, just works. But what if you wanted to render dynamic annotations on a livestream or create an alternate version of a hosted video with burned-in subtitles? You would need to run a custom video pipeline. Today, we’re releasing a new developer playground, Streamline, that demonstrates how you can build a system to deliver these bespoke video experiences on Cloudflare’s Developer Platform. We’ll walk you through how Streamline leverages Workers, Containers, and several media protocols to modify video — and immediately publish that output as livestream or new hosted video. You’ll also have the opportunity to try it for your projects. A processing pipeline needs a durable, long-running environment that can run specialized, compiled code with predictable memory and CPU capacity. Video streams can run for minutes or hours, so the media process needs a lifecycle independent of the request that started it. An application should be able to start a pipeline, send its input, inspect it, and stop it without needing to keep a single request open for the entire duration. Cloudflare provides the primitives we need. Containers are long-lived runtimes suitable for media processing. Durable Objects help with orchestration. Finally, Workers are perfect for control signaling and monitoring. For Streamline, we built a media engine running in a Container to handle media processing in real-time. The Container is controlled by a Worker exposing control, preview, and testing to an agent or user. Processing will continue even if the Worker disconnects. We've architected Streamline with modular components so that the media engine could be replaced with dedicated encoding products in the future. Architecture A S

r/netsec • Oct 2
CVE

**TL;DR.** [SConnect](https://chromewebstore.google.com/detail/sconnect/mjhbkkaddmmnkghdnnmkjcgpphnopnfk) \- 1M+ users, an extension middleware+native host for authentication with eIDs, 3SKeys and other hardware signing tokens had a drive-by RCE which enabled any site or iframe a user saw to silently download and execute a dll due to a poor hand-rolled implementation of RSA-2048 token validation, enabling a use of uninitialized memory validation bypass which enabled "plugins" (DLLs) to be loaded. v2.16.0.0 of the extension and native host is vulnerable. [CVE-2026-18397](https://nvd.nist.gov/vuln/detail/cve-2026-18397). CVSS 9.4.

Cloudflare • Oct 2

Fun fact: when you use an agent and it needs to fetch a live web page, the agent usually just guesses the URL of the page and then makes a tool call to curl it. This is why you’ll sometimes see web fetches come back with a 404 Not Found, which happens if the agent incorrectly guesses the URL of that information. As you can imagine, it’s not super efficient to randomly guess URLs all the time. There is a better way. What if your agent can actually browse the Internet, just like how humans start with a search engine query when we’re looking for information? This is what web search is designed to do — it enables agents to search for relevant data on the Internet and grounds an agent’s responses based on live information. Today, we’re announcing Cloudflare’s partnership with web search providers to bring you grounded intelligence via AI Gateway. We’re kicking off this launch with our partners from Ceramic.ai, Exa, and Linkup. What can I do with the Web Search API? AI models are only as good as the context you feed them. Models are typically trained and then frozen at a point in time, operating only on information that existed before their knowledge cut off date. This makes it quite hard to engage with models about recent events, changing APIs, or fast-evolving news. Integrating Web Search API directly into your inference pipeline equips your agents with a dynamic context layer. Your applications get fresh, structured snippets from the web injected straight into context, which gives your models access to live information. For example, if your agent was building with Cloudflare developer tools, it might miss all the new products and features we’re releasing during this Birthday Week ! With web search, you’ll be able to retrieve the latest and greatest documentation and releases, so you can build faster and smarter. Elevating

Cloudflare • Oct 2
APT

Today, we’re introducing Cloudflare Traces in open beta, extending automatic tracing beyond Workers to the rest of the request path. In one trace, you can see supported security rules, transformations, cache decisions, routing, Worker execution, and origin handling, then continue that trace through services running on Cloudflare, at your origin, or elsewhere in your stack. This is a long-term investment in OpenTelemetry and in making Cloudflare the most observable part of your stack. You can now: Automatically trace requests across Cloudflare : Capture supported platform operations in one request-level timeline, no additional set up required. Control which requests are traced : Set a baseline sampling rate, then use Trace Rules to override it for matching traffic. End-to-end trace context propagation: Accept and forward W3C traceparent headers Investigate traces in Cloudflare : View request timelines and span details directly in the Cloudflare dashboard.

Cloudflare • Oct 2

Today, end users carry too much of the burden of online privacy. To avoid third-party trackers or targeted ads, users are instructed to use a VPN, disable cookies, or install adblockers. Meanwhile, some app developers end up knowing more about their users than they’d care to: a typical client-server exchange creates a trail of user data, like the client’s IP address or TLS fingerprint. This level of visibility can be a burden. That’s why Cloudflare builds infrastructure that helps developers bake privacy into their apps. Oblivious HTTP (OHTTP) is an IETF standard designed to enable app backends to receive HTTP requests without seeing user IP addresses. This fall, we’re launching the Cloudflare OHTTP Gateway. Customers will be able to enable our new OHTTP Gateway as a paid add-on to their zone and start receiving OHTTP traffic with just a few clicks. Register through our form to join our waitlist. Read on to learn more. Expanding our OHTTP product suite With OHTTP, requests travel through two independently-operated hops: a relay and a gateway. An OHTTP relay blindly forwards encrypted requests in order to hide client identifiers from app servers. An OHTTP gateway performs the cryptographic work of decapsulating encrypted requests and encapsulating responses such that app servers can handle OHTTP requests as if they were plain HTTP. The separation of trust between relay and gateway is critical: it ensures that no single party sees both client identifiers and request contents. In 2022, we launched an OHTTP relay product, Privacy Gateway . Privacy Gateway ena

Cloudflare • Oct 2
APT

We launched Quick Tunnels in 2021 to give developers an easy way to share their latest service, application, or project running in their local development environment. A lot has changed since then, but the core use case remains the same. Your coding agent has just finished the feature. The dev server is up on localhost:5173 , and before you ask, the agent offers to let you try it on your phone. It runs one command and hands you a link: That command starts a Quick Tunnel . cloudflared , Cloudflare's lightweight connector, publishes your local service at a random trycloudflare.com URL. No account, no domain, no cost. Agents now use Quick Tunnels for the same reason people do: they are the shortest path from a local port to a URL. The catch has always been the same. Anyone with the link can open it. Starting with cloudflared 2026.9.3, you can add --allowed-mail to the command, and your Quick Tunnel only lets in the email addresses and domains you choose. Visitors prove they own one of those addresses with a one-time PIN from Cloudflare Access . Nobody, on either side, needs a Cloudflare account. Agents made Quick Tunnels more popular than ever Agents that write code need somewhere to show you the result. Agents that live on a Mac mini at home need to be reachable from your phone. Model Context Protocol servers on a laptop need a public endpoint before a hosted assistant can call them. Each of these needs a URL, and a Quick Tunnel produces one

Cloudflare • Oct 2

Tracking how governments target dissidents living in exile. Helping people in crisis find mental health support. Advocating for legislation that protects free expression online. These are a few examples of how some of the world's leading organizations are building the future of non-profit work with Cloudflare. AI is changing how people do their work. The goal of Cloudflare Impact is to help ensure that non-profit organizations are among the first to benefit. Today, we’re sharing what dozens of civil society organizations have built using our developer services with more than $7.5 million of Cloudflare credits. These stories show what is possible when AI applications are accessible, secure, and affordable to build and run. From "keep us secure" to "help us build" We believe a better Internet is one that allows people to express themselves online and access a diverse range of viewpoints. A key part of Cloudflare's mission has been making security services available for everyone and helping ensure that individuals and organizations working for the public interest are not forced offline by those more powerful. Today, Project Galileo , which provides free cybersecurity services to civil society organizations, protects more than 3,400 domains across more than 120 countries. Through these partnerships, organizations have shared with us how their needs have evolved from not only wanting to secure existing applications, but wanting to build new ones. AI has allowed non-technical teams to design, build, and scale tools tailored specifically for their workstreams and to advance their mission. This opportunity is arriving at a challenging moment for the sector. Many organizations repor

The Hacker News • Oct 2

The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is

Trail of Bits • Oct 2

Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a common stumbling point when cryptographers try to use hashes. As part of our goal to “fix software, not bugs,” Trail of Bits is introducing SequenceHash and its sister function SequenceMAC , a pair of related hash constructions that bring secure multihashing to developers using hash functions other than Keccak. We hope SequenceHash and SequenceMAC will help cryptographers avoid attacks that take advantage of ambiguous input encodings. The specification is open source, and is now a part of the Community Cryptography Specification Project (C2SP). SequenceHash and SequenceMAC behave similarly to NIST’s TupleHash , but have the advantage of not being tied to a single hash function. They also don’t require developers to implement fiddly computations that aren’t byte-aligned. Instead, SequenceHash and SequenceMAC work out of the box with nearly any secure cryptographic hash function you care to use, including SHA256/384/512, BLAKE, and RIPEMD. SequenceMAC supports keys 32 bytes or longer (up to the ridiculous limit of ${2}^{128}-1$ bytes). (It’s worth noting: SequenceHash and SequenceMAC rely on the security of the underlying hash for their own security. SequenceHash and SequenceMAC can’t magically make MD4 or SHA0 secure again. For the purposes of this document, it’s assumed that you have chosen a reasonable hash function like SHA256, not CRC32.) To make SequenceHash and SequenceMAC easy to use, we’re releasing

Compass Security • Oct 2
CVE

Introduction Pwn2Own is a renowned hacking competition organized by the Zero Day Initiative (ZDI), where security researchers demonstrate previously unknown vulnerabilities in popular software, operating systems, browsers, IoT devices, and other technologies. Having participated in both the 2023 and 2024 editions of Pwn2Own, we decided to take another shot in 2025. This time, our goal was to avoid collisions, where multiple teams discover the same vulnerability during the same event, leading to reduced prize money and fewer Master of Pwn points. This blog post walks through our journey from discovery to full exploitation. We start by exploring the Home Assistant device architecture, then detail how we found a remote code execution vulnerability in an add-on. From there, we show how we leveraged it to pivot to the underlying operating system and achieve root-level access. We conclude with our experience at the Pwn2Own 2025 Cork edition. Target Selection We started by looking at several different targets. Our initial list included the Wyze Cam Pan v3 and the Synology CC400W from the surveillance system category, the Brother MFC-J1010DW from the printer category, the Philips Hue Bridge and the Home Assistant Green from the smart home category. After assessing the various targets, we shifted our focus to the Home Assistant Green due to the progress we had made on that platform. This led us to the discovery of an exploit chain that resulted in an unauthenticated remote code execution vulnerability. Device Overview

The Hacker News • Oct 2

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a

Synack • Oct 2

Synack was named a Leader in G2's Fall 2026 Grid® and Enterprise Grid® Reports for Penetration Testing. The reviews show what customers value in a pentesting partner: visibility into testing, access to experts, findings they can fix and verify, and a partner that acts on feedback. The post What Customers Value in a Penetration Testing Partner: Insights from G2 Reviews appeared first on Synack .

Thursday, October 1
r/computerforensics • Oct 1
APT

I've been picking through a SCADA-style telemetry capture and I can't explain what I'm seeing. The file has 14 authorisation records, each with its own CRC. All 14 validate. The file header carries a CRC-32 over the whole block, and that one fails. Two of the operator-name fields are zeroed. My reading is that someone blanked those fields, recomputed the per-record CRCs so they'd pass, and never touched the block CRC. But I'd like a sanity check — is there a corruption mode that breaks a block checksum while leaving every record checksum intact? File (8.8MB): www.[st88openocean.github.io/slip-three/MCA-CTL-0314-RAW.slice](https://st88openocean.github.io/slip-three/MCA-CTL-0314-RAW.slice) Published digests for it are here: www.[st88openocean.github.io/slip-three/archive](https://st88openocean.github.io/slip-three/archive)

Synack • Oct 1

Before you build an AI pentesting agent, run it through 5 tests for production readiness. Mark Kuhr breaks down what separates a prototype from a system. The post Build or Buy AI Pentesting? 5 Tests to Judge Production Readiness appeared first on Synack .

r/netsec • Oct 1

A blue-team writeup on detecting a compromised MikroTik from its own config. Seven techniques, each with the collection command, the artifact it leaves behind, and a triage step. Feedback welcome.

CERT/CC • Oct 1

Overview An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code executes in System Management Mode (SMM), successful exploitation can allow an attacker to modify SMM-protected memory and potentially achieve arbitrary code execution in SMM. Depending on the platform's memory and firmware configuration, the arbitrary physical memory write primitive may also have implications for UEFI firmware update or flash-related operations. Description HP PC BIOS is firmware that initializes and manages hardware components during the boot process and provides runtime services to the operating system and provide the ability to update firmware. The affected system uses InsydeH2O Kernel version 5.5 or earlier. The BIOS includes custom HP SMM handlers that execute in System Management Mode (SMM), a highly privileged CPU execution mode that is isolated from the operating system. CVE-2026-12855 : An Out-of-bounds Write vulnerability in the H19WMIHandlerSmm module (GUID f1946499-571b-44c3-9b9c-cc55210b0c02) allows a local attacker with OS kernel privileges to read or write arbitrary physical memory, including SMRAM, through a Software SMI handler. An attacker with kernel-level privileges can trigger the vulnerable SMM handler by issuing a Software System Management Interrupt (SMI) through I/O port 0xB2 and supplying specially crafted CPU register values. The vulnerable handler does not adequately validate the supplied parameters before performing memory operations, allowing the attacker to influence the physical address and data involved in the operation. Because the affe

Heimdal Security • Oct 1

Benedict Jones spent years working for McAfee and Sophos. While doing threat research at Sophos, he spotted a problem in mobile threat defence that nobody had actually fixed. He’s now CEO and founder of Trustd Mobile, and the story of how he got there says more about MSP buying decisions than most vendor pitches ever […] The post Innovation wins. Why smaller beats bigger appeared first on Heimdal Security Blog .

WIRED • Oct 1

In an exclusive interview with WIRED, Paragon Solutions CEO Andrew Boyd reveals the limits of the company’s promise to keep bad actors from abusing its powerful espionage tool.

Heimdal Security • Oct 1

London, UK, 1 October 2026 – Heimdal, a global cybersecurity provider, today announced a partnership with Elovade, a European IT security distributor with 250 experts across five countries, to bring its unified security platform to managed service providers (MSPs) across the DACH region: Germany, Austria, and Switzerland. The move extends a relationship that began a […] The post Heimdal partners with Elovade to bring unified cybersecurity platform to the DACH region appeared first on Heimdal Security Blog .

Wednesday, September 30
Tuesday, September 29
watchTowr • Sep 29
CVE

Part 1 of this week's saga can be found here. This research is a glimpse into the capabilities that power our Preemptive Exposure Management solution, enabling organizations to rapidly react to emerging threats: the watchTowr Platform. What Is A Citrix NetScaler? NetScaler, from Citrix (now under Cloud Software Group), is an application delivery controller - some believe it qualifies to be described as a security appliance. It sits in front of an organization's applications and handles load balancing, traffic management, and SSL/TLS termination. NetScaler Gateway adds VPN and secure remote access. What Is the Purpose of a Security Appliance? A security appliance exists to keep an organization secure by standing between its systems and threats that attempt to reach them. It concentrates a defensive function, controlling remote access, filtering hostile traffic, or enforcing who is allowed in, at a single chokepoint that every connection has to pass through. What Does "Hardened" Mean In "Hardened Security Appliance"? "Hardened" mea

The Guardian • Sep 29

The need for independent regulation grows more obvious by the day. We must keep this tech in check before it’s too late OpenAI scraps release of new model over safety concerns in internal testing Fool me once, shame on you. Fool me twice, shame on me. Fool me more than 16,000 times – as OpenAI agents did to a UN public data hub while repeatedly trying to find its way around the UN’s cyber-blocks – and perhaps it’s time to admit the system we have for keeping AI agents under control isn’t working particularly well. The news about AI systems cropping up in places they shouldn’t sounds alarming. Though the description of these as “hacks” is perhaps overstating things, AI has exploited issues in IT systems that humans simply haven’t got around to finding. It’s also important to note that we shouldn’t be worried that the machines have suddenly become sentient and decided to rebel against humanity . There is not enough evidence to suggest that’s what is happening. The systems are simply following instructions and trying to complete the tasks they have been given, even if they’re sometimes finding unintended ways around obstacles to do so. Chris Stokel-Walker is the author of TikTok Boom: The Inside Story of the World’s Favourite App Continue reading...

Story Overview