Tuesday, October 6, 2026

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.

Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may make it appear less conspicuous among other Windows processes, lend it a false sense of trust, or be overlooked by an analyst during casual inspection.

However, the backdoors examined by Rapid7 have been found to go beyond imitating file names by assuming the identities of email security products like SpamSniper and ShareTech that are widely used in enterprise environments in South Korea and Taiwan.

According to vendor Jiran Group, SpamSniper is advertised as "Korea's leading email security solution" that defends organizations against spam, malware, and server attacks.

The malicious artifacts include a new BPFDoor variant and a BPF Rekoobe build used against South Korean targets, and a previously unreported Linux implant dubbed AVERAT that's delivered via a dropper and deployed against Taiwanese appliances.

"The BPFDoor variants seen against South Korean systems impersonate the PID file of SpamSniper, a Korean anti-spam product, and rotate through ten Linux daemon names," Rapid7 said. "Across the samples, each component adopts names and conventions designed to look unremarkable in the environment it targets."

Cybersecurity

BPFdoor and its many iterations were the subject of an extensive analysis by Rapid7 earlier this year, with the activity linked to a threat group dubbed Red Menshen (aka Earth Bluecrow, DecisiveArchitect, and Red Dev 18), which has targeted telecom providers across the Middle East and Asia going all the way back to 2021.

At a high level, BPFDoor abuses the Berkeley Packet Filter (BPF) functionality to inspect incoming network traffic and activate its behavior only upon detecting a magic packet. The detection of a new BPFDoor version indicates that the threat actors behind the malware are actively refining and retooling their arsenal in response to public disclosures.

"Once security vendors wrote static network signatures (Suricata/Snort) to detect these Layer 4 anomalies, the operators began targeting the edge proxies," Rapid7 said. "By wrapping the magic packet in standard HTTPS POST requests and relying on SSL offloading common in telecom environments, the trigger can be delivered to the BPFDoor-infected node in a way that may evade conventional deep packet inspection."

While some BPFDoor samples spoof SpamSniper, another artifact sets its process name to "ora_ppmond," mimicking the naming convention associated with Oracle-backed telecom subscriber and provisioning platforms. Specifically, the name appears to be a reference to "ora_pmon_*," which represents the Process Monitor (PMON) background process of an Oracle Database instance.

Once triggered, the BPFDoor sample launches a TinyShell session and supports commands to facilitate interactive shell, upload, and download capabilities. Interestingly, the use of TinyShell has been previously attributed to China-nexus clusters like Liminal Panda, UNC3886 (aka Fire Ant), and Velvet Ant, all of which have singled out telecom networks and edge devices.

"These samples show BPFDoor operating as a modular framework that adapts to the telecom layer it targets, integrating TinyShell and Rekoobe logic to support exfiltration," Rapid7 explained.

Also observed in conjunction with the activity is a Rekoobe-based BPF backdoor that intercepts TCP/UDP/SCTP IPv4 and UDP IPv6 traffic with source and destination ports equal 25. Furthermore, it names its processes after components of SpamSniper.

The dropper observed in an overlapping campaign is an ELF binary that acts as a local installer for AVERAT, a modular implant that uses the Simple Mail Transfer Protocol (SMTP) for command-and-control (C2) and to obscure its malicious activity.

Located within the ShareTech appliance's "/addpkg/sbin/" add-on package directory, the ELF dropper works by deriving its encryption key from the string "ShareTech" and then using it to decrypt a shell script that's responsible for staging and executing two binaries: "ntpdate," which is the dropper itself, and "udevds," which is the AVERAT payload. The two files are deleted 10 seconds later.

AVERAT periodically polls a C2 server ("mx.zxopfds[.]com") over TCP port 25 every 600 to 699 seconds. The server details and beacon interval are extracted from an encrypted configuration. The backdoor supports a long list of command codes that include -

  • 20, to enumerate directory contents
  • 21, to download a file from the host, with resume support
  • 22, to upload a file to the host in chunks
  • 25, to recursively delete a file or directory tree
  • 30, to recursively walk a directory tree
  • 629, to enumerate running processes with command lines
  • 632, to terminate a process (SIGTERM)
  • 842, to overwrite the C2 host and port tables at runtime
  • 912, to open an interactive shell session and up to 10 concurrent sessions
  • 914, to write a command into an open shell session
  • 916, to reboot the appliance
  • 1010, to load or unload a shared object (*.so) module, extending the implant functionality
  • 1576, to set the callback interval and persist it to database
  • 1618, to open a proxy or port-forward channel through the appliance
  • unknown, to close the socket and terminate the process immediately

AVERAT's C2 infrastructure, per Rapid7, matches the device-class profile typically associated with an Operational Relay Box (ORB) network, although there is no evidence it's part of any known ORBs such as LapDogs (aka UAT-7810), SPACEHOP, and FLORAHOX.

Cybersecurity

Organizations are recommended to review unexpected raw packet sockets and BPF filters on Linux systems that do not require packet capture, audit outbound TCP port 25 connections from processes that are not mail services, scan for processes posing as common daemons, and restrict management access to routers, DVRs and other edge appliances.

The findings demonstrate how threat actors are leveraging the privileged position occupied by secure email gateways (SEGs) for intelligence collection. In 2023, a China-nexus threat actor codenamed UNC4841 was observed exploiting two different vulnerabilities in Barracuda Email Security Gateway (ESG) appliances (CVE-2023-2868 and CVE-2023-7102) to deliver persistent backdoors.

"The common thread is regionalized disguise: each sample is aware of the vendor's software running on the targeted systems and implements process spoofing accordingly," the cybersecurity company said. "Passive BPF implants avoid conventional port scans; while outbound beacons hide inside ordinary DNS, TCP, and traffic, the threat actor(s) are leveraging SMTP to stay under the radar."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.



from The Hacker News https://ift.tt/EpTFb7Z
via IFTTT

CISO perspectives on managing vulnerability risks in the age of AI

Most of what has been written about AI and vulnerability management focuses on speed: how much faster frontier AI models can scan code, find weaknesses, design patches, and build exploits than any human team. That part is true, and it matters to how we remediate vulnerabilities.

The more challenging question is what happens after the scan? Frontier AI models are about to hand every security team a far larger set of findings than they have ever had to work through. The real test for chief information security officers (CISOs) and IT security leaders is not how fast they can patch. It is whether they can keep the balance between patching quickly and patching correctly, at a scale no human review process was built for.

This shift creates both new challenges and new opportunities. The same AI capabilities accelerating cyberattackers are also enabling defenders to identify exposures earlier, automate remediation, and build more resilient security programs.

Not every vulnerability will be patched in time, so the controls that limit what an attacker can do by defense in depth matter more than ever. CISOs can dramatically improve the security posture of their Microsoft infrastructure by deploying Microsoft Baseline Security Mode (BSM), building on how Microsoft protects Microsoft.

How do frontier AI models change vulnerability management for CISOs?

Microsoft uses frontier AI models to find vulnerabilities in its code base and mitigate them at controlled pace. Potential vulnerabilities are reviewed on validity, severity, and potential impact. As we have explained in previous blogs, many steps in our vulnerability handling and disclosure processes now are AI-powered, allowing them to scale.

Most vulnerabilities in cloud software are being mitigated by Microsoft without customer intervention. For on-premises Microsoft software, customers should continue to expect a substantial increase in the number of vulnerabilities released on Patch Tuesdays relative to historic volumes before the advent of frontier AI models earlier this year—September 2026 saw a record number, close to 1,000.1

Due to the non-deterministic nature of AI models, different runs by the same model or with different models may yield different results. With better models becoming available over time, AI-powered vulnerability scanning of our existing code base and new code should become part of our standard security assurance.

We use a ‘harness’ layer around AI models in vulnerability scanning for better results. This layer controls how models access code, validate outputs, and integrate findings into triage and remediation workflows. Microsoft has expanded the use of harnesses in scanning its code bases across all the engineering groups. One of these harnesses, codename MDASH, has now also been made available to customers. In addition to AI-powered vulnerability scanning, our internal Red Teaming engagements now leverage AI, enhancing the team’s capacity to find weaknesses in controls and boosting the efficiency and speed of the operations.

What can CISOs do to mitigate the risk of vulnerabilities to their organization?

How can CISOs prepare for what’s coming, as new AI models in the hands of threat actors increase the risk and pace of cyberattacks using unknown or unpatched vulnerabilities?

  1. CISOs should increase the resources allocated to Microsoft on-premises software patching, prioritization, and timing as they should continue to expect a high volume of patches on future Patch Tuesdays, at least over the coming period.
  2. CISOs should rethink patch timing for their most critical systems. Traditionally, critical components such as domain controllers and edge devices have been patched when downtime is least disruptive, such as weekends or holidays. As AI shortens the time between patch release and exploitation, that trade-off may need to change. Consider deploying fixes to these systems within 24 hours rather than waiting for the next maintenance window.
  3. CISOs should use harnesses to scan and remediate vulnerabilities in the code base of their organizations. They should do so without delay, rather than wait for access to frontier AI models. They should allocate appropriate resources for tokens and human resources to triage and remediate bugs.
  4. CISOs should focus, more than ever, on defense-in-depth and monitoring of the state of health of their critical controls. As governments and regulators around the world raise expectations for cyber resilience through legislative frameworks, these authorities are compelling organizations to strengthen their security posture, operational resilience and regulatory readiness. Extensive guidance can be found in a new Microsoft Security Exposure Management page with capabilities customers can use to act.

Microsoft helps by tackling open-source vulnerabilities with industry peers

Many organizations use open-source software in their infrastructure or their products. As governments and regulators increase expectations around software security, the ability to find and fix open-source vulnerabilities is becoming more important, but many open-source maintainers don’t have the tools or resources to respond quickly, which increases supply chain risk in the face of AI-supported vulnerability discovery.

Microsoft has teamed up with industry peers to coordinate the scanning and patching of vulnerabilities in critical open-source components before cyberattackers find them. Participating organizations are pooling resources to prioritize and scan open-source packages and remediate in cooperation with the maintainers.

Microsoft helps by offering Secure by Design and Secure by Default to customers

The implementation of defense in depth by organizations worldwide can be vastly improved by implementing baseline security controls by default across their estate. The implementation of Secure by Default requires to carefully balance useful features and fast innovation with security controls and guardrails. Microsoft is committed to implementing Secure by Design and Secure by Default across its products, thereby removing part of the burden of implementing critical controls from customers. See our latest Secure Future Initiative (SFI) report for more details.

With Secure by Design, security comes first when designing a product or service. Customers do not need to opt in and cannot opt out. Recent examples where we have implemented Secure by Design changes in Microsoft products are:

  • Mandatory multifactor authentication for Microsoft Azure administrators.2
  • Enforcing Conditional Access policies to Windows Hello for Business and macOS Platform single sign-on (SSO) registration.3
  • Secure-by-design under the hood in Azure.4

Secure by Default means that security protections and secure configurations are enabled by default, requiring no extra effort. Recent examples where we have implemented Secure by Default changes in Microsoft products are:

  • Azure Backup soft delete enabled by default.5
  • Azure VNet default outbound access disabled.6

Customers can opt out of certain controls if they accept a higher risk posture. Customers may also create a better risk posture by opting in to more demanding or more sophisticated controls.

CISOs can dramatically improve the default security posture of their Microsoft infrastructure by deploying Microsoft Baseline Security Mode (BSM). BSM helps organizations to implement and monitor secure configurations at scale, based on “How Microsoft protects Microsoft.” Scenario analyses are available to assess the impact of additional controls in existing tenants, allowing a staged and controlled rollout. Controls can be turned on and off, and exceptions can be made and removed.

Microsoft Baseline Security Mode is available to existing customers within their current license agreement. We highly recommend CISOs to use BSM to increase the defense-in-depth of their existing infrastructure. New Microsoft customer tenants will come with BSM controls gradually implemented by default.

Final notes

The advent of frontier AI models to discover and exploit vulnerabilities creates both risks and opportunities. Responsible use of these tools allows us to secure the software that we built in the past and mitigate exposure in the future in a way not possible until now.

Microsoft will continue to use the latest technologies to find and correct vulnerabilities in existing code and to avoid vulnerabilities in future code, to decrease the likelihood of exploitation. It will also extensively use AI to protect its own infrastructure and the infrastructure of its clients.

For CISOs, the bottom line remains that risk-based management of cybersecurity is the cornerstone of our defense. AI and the principles of Secure by Default have become an integral part of this approach.

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.


1September 2026 Security Updates, Microsoft.

2Azure mandatory multifactor authentication: Phase 2 starting in October 2025, Microsoft Azure blog. September 5, 2025.

3Protect security info registration with Conditional Access policy, Microsoft Learn.

4Azure IaaS: Defense in depth built on secure-by-design principles, Microsoft Azure blog. May 4, 2026.

5Secure by Default with Soft Delete for Azure Backup, Microsoft Learn.

6Default Outbound Access in Azure – Azure Virtual Network, Microsoft Learn.


The post CISO perspectives on managing vulnerability risks in the age of AI appeared first on Microsoft Security Blog.



from Microsoft Security Blog https://ift.tt/vrmxaVB
via IFTTT

Blinder Tunnel Campaign Targets Iraqi Infrastructure

Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure.

The post Blinder Tunnel Campaign Targets Iraqi Infrastructure appeared first on Unit 42.



from Unit 42 https://ift.tt/qCBAkIl
via IFTTT

Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows.

The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP source code, downloaded more than 150 million times. This time, we looked at what people actually install: community-published servers across the most popular MCP marketplaces. We found no guardrails and no review. Security is a recommendation, not a policy.

A Marketplace With No Bouncer

In 2012, Google ran Bouncer, an automated scanner that checked Android apps for malware before they reached users. It wasn't perfect: researchers slipped malware past it. But it existed. MCP marketplaces have no equivalent. Anyone can write a server, push it, and publish it.

Even a review wouldn't close the gap. At RSAC and OWASP last year, we presented "In GitHub We Trust: 10 Ways You Can Get Pwned," on how developers over-trust what they see in a repository. MCP repeats that mistake. Remote MCP servers can run backend code that differs entirely from what their public repository shows. Code review tells you what the developer published, not what the server runs.

Where Does Your Data Go?

Over the past decade, enterprises built strict governance to adopt public cloud safely: data residency rules, Zero Trust boundaries, granular IAM, and supply chain audits. MCP connections often sit outside all of it.

To measure the gap, we analyzed 15,465 publicly indexed MCP servers across 5 MCP registries, deduplicated to 5,095 unique hostnames.

  • Hosted outside the US: 15.6% of hostnames resolve to infrastructure outside the United States, including 19 in China and 18 in Russia. An agent connected to these servers may send data to jurisdictions the security team never approved.
  • Running on personal machines: 0.45% route traffic through consumer tunneling services, mainly ngrok-free. These publicly listed servers run from personal machines and, likely, home networks.
  • Dangling domains: 2.3% no longer resolve. Six sit on expired domains that anyone can register for $4 to $12 a year. A new owner would inherit an established server identity, along with requests from any agent still configured to call it.

Location can also change. An operator could launch a server on a clean US IP address and later route traffic somewhere else.

The full report covers our methodology, a prompt-injection proof of concept, and the threat scenarios behind each finding. Download "15,465 MCP Servers, 0 Governance"

Trust Is the Attack Surface

The protocol isn't the problem. The trust we hand it is. Until marketplaces add vetting, code signing, and origin verification, the enterprise has to do that work.

It's still a jungle out there. Make sure you're not the prey.

Get the full report, "15,465 MCP Servers, 0 Governance"

Want to go further? Join our live webinar, "The AI Attack Surface Is Already in Your Cloud," on October 13 at 12:00 PM ET. Latio founder and CEO James Berthoty and OX Field CTO Chris Lindsey will cover how AI is reshaping cloud threats and what security teams should do about it. Register

Note: This article has been expertly written and contributed Moshe Siman Tov Bustan, Security Research Team Lead, OX Security.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.



from The Hacker News https://ift.tt/nAHQO78
via IFTTT

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software.

The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are not affected.

Google called the stop temporary in a post on X on October 1 and said it was due to "a significant rise in automated submissions, the vast majority of which are not valid."

The post gave no figures. It did not say whether the submissions were produced with AI tools.

The rules of the program, called the Open Source Software Vulnerability Reward Program (OSS VRP), now carry a notice of the stop. It commits Google to an update in the first quarter of 2027 while it reworks this part of the program.

Neither the post nor the notice gives a date for accepting product vulnerability reports again.

Under the rules, a product vulnerability is a design or implementation flaw in Google's open source software. It must substantially affect the confidentiality or integrity of user data in software built with that code. Examples include memory corruption in file format parsers and path traversal.

The program sorts projects into four tiers based on their sensitivity. Only the top two, called flagship and important, had rewards listed for product vulnerabilities.

The same change that added the notice removed those listed amounts: $500 to $7,500 for flagship projects and $101 to $3,133.7 for important ones. It was published to Google's public GitHub copy of the rules on September 30, a day before the X post.

Google's list of tiered repositories, last updated in mid-September, names 26 flagship repositories and 47 important ones. The flagship tier includes Go, Angular, Flutter, Bazel, and Protocol Buffers.

Supply chain compromises, which are flaws that could let someone tamper with a project's source code or published packages, keep their listed rewards. So do other security issues, such as leaked credentials that give write access.

Category Flagship Important Standard
Supply chain compromises $3,133.7 to $31,337 $1,337 to $13,337 $500 to $3,133.7
Product vulnerabilities None (was $500 to $7,500) None (was $101 to $3,133.7) None
Other security issues $1,000 $500 None

The fourth tier, for low-priority projects, has no listed rewards.

Where Reports Can Go Now

Google's notice names three routes for researchers:

  • Cloud VRP: Product vulnerability reports may still be accepted for some Google Cloud repositories that affect Google Cloud products, but the notice does not name them. Under the Cloud VRP rules, a flaw in an open source repository maintained by Google Cloud that affects Cloud products is rated at most IT3b. That is the tier for acquisitions and lower-priority products, and the cap applies unless Google's product list says otherwise.
  • Patch rewards: The Patch Rewards Program pays $100 to $15,000 for security patches to the projects it covers, not for vulnerability reports. The project's maintainers must accept a patch and remain in place for one month before it can be submitted. A patch that fixes only a single vulnerability is reviewed on a case-by-case basis.
  • Other reward programs: Google asks researchers to check whether a flaw affects something covered by one of its other reward programs and to submit it there. The OSS VRP rules also encourage reporting flaws in projects closely tied to Google Cloud or AI products to the Cloud VRP or the AI VRP.

The notice does not say whether Google will still take product vulnerability reports without a reward.

Some project policies point to other channels. Go takes security reports by email to its own security team. A security policy in Google's GitHub organization sends reporters to Google's vulnerability reporting address, g.co/vulnz.

Angular's security policy, as of October 6, says Angular is part of the OSS VRP, sends vulnerability reports to Google's Bug Hunters site, and names no other channel.

Earlier Limits on Low-Quality Reports

Google launched the OSS VRP in August 2022. In March 2026, it began requiring stronger proof for reports in some tiers to filter out low-quality ones. A patch already merged into the project is one accepted form of proof.

InfoWorld reported at the time that the program's team was concerned about the low quality of some AI-generated submissions, many of which included invented details about how a vulnerability could be triggered.

Separately, the Go project added a section on reports generated by large language models (LLMs) to its security policy in early September. It asks reporters not to send such reports without reviewing and filtering them first.

The policy says LLMs are good at finding real security bugs and just as good at reporting ones that do not exist. Reporters who forward large amounts of unfiltered LLM output will not be credited for their findings.



from The Hacker News https://ift.tt/n7urVbg
via IFTTT

Monday, October 5, 2026

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.

The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system.

"Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network," Microsoft said in an advisory released on October 2, 2026.

The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments. However, the vulnerability does not allow cross-tenant access.

Microsoft has already deployed a "related service-side fix" to Exchange Online to address the issue. As a result, Exchange Online customers are not required to take any action.

Users of affected on-premises Microsoft Exchange Server products are advised to install the updates to stay protected. The following versions are impacted -

  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 15
  • Microsoft Exchange Server 2019 Cumulative Update 14

Redmond has credited Microsoft researcher Jan Mitchell with discovering and reporting the flaw. Although there is no evidence of the flaw being weaponized in the wild, Microsoft has tagged it with an Exploitability assessment of "Exploitation More Likely," making it essential that users move quickly to apply the fixes.

The disclosure comes days after Broadcom-owned Symantec warned that the China-linked Warlock actor is exploiting multiple vulnerabilities in Microsoft SharePoint to deploy its namesake ransomware in attacks targeting organizations in Portuguese- and Spanish-speaking countries.



from The Hacker News https://ift.tt/H1h4620
via IFTTT

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook.

There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others are still getting in because the basics gave way first.

Here’s what mattered this week.

⚡ Threat of the Week

Citrix Warns of Newly Exploited NetScaler ADC and Gateway Flaw — Citrix released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said. "The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met." Successful exploitation requires NetScaler ADC or NetScaler Gateway to be configured either as a SAML service provider (SP) or SAML identity provider(IdP).

🔔 Top News

  • Critical FortiMail Zero-Day Flaw Exploited in Attacks — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a critical security flaw impacting Fortinet FortiMail. The flaw, CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. According to Fortinet, the vulnerability "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests."
  • Two ShinyHunters Members Arrested — Law enforcement agencies have arrested two members associated with the ShinyHunters digital extortion group. One of them is a 24-year-old Amsterdam man, who is believed to be Pepijn van der Stap, while the second individual is Saif ‌al-Din Khader, who is said to have been detained by Jordanian authorities last week. ShinyHunters has drawn attention in recent weeks for hijacking the darknet website of Cl0p and its hack of the FBI's "apply.fbijobs[.]gov" portal.
  • Authorities Arrest 16-Year-Old Mastermind Behind KillSec — Police in Spain apprehended a 16-year-old who is suspected to be the leader of the KillSec (aka Kill Security Ransomware Group) ransomware operation. According to Europol, authorities took control of KillSec's leak site on September 30, 2026, securing no less than 110 terabytes of data. As part of Operation KillSwitch, a total of three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the U.K. One of the group’s accused members, Fouad Eltibrizi, was arrested in the U.K. and is awaiting extradition to the U.S. Since emerging in 2024, the group is estimated to have launched around 1,000 attacks, at least half of which were successful. "The group exploited software vulnerabilities and poorly secured access points, particularly to cloud storage, to gain access to organizations' systems," Europol said. "Its members then copied sensitive internal data to infrastructure under their control. Victims were named on the group's dark web leak site and threatened with publication of their data unless paid." Per Group-IB, which identified 274 publicly claimed victims, out of which most were U.S., Indian, and Brazilian organizations. "The group also sold stolen data outright, with asking prices ranging from USD 5,000 for a single company's records to USD 500,000 for the data it claimed to have taken from the global insurer, making KillSec as much a data broker as a ransomware operator," Group-IB said.
  • New Spectre v2 Variant Leaks Linux Root Password Hash in Minutes — A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few minutes. The attack exploits stale information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code. By tampering with this information, an attacker can trick the processor into temporarily executing wrong instructions and potentially expose sensitive data. "We evaluated the end-to-end exploit on both Raptor Cove and Lion Cove, and leaked the password within 3 and 5 minutes on average, respectively," researchers claimed. "Indirect branch prediction is inherent to modern CPUs, and BTR exploits the desynchronization between the branch predictor and the actual state of the code. No current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable."
  • Star Blizzard Uses Fake Invites to Deploy CosmicPulse — The Russian state-sponsored threat actor known as Star Blizzard has employed a new malware delivery technique called RedFlick in attacks targeting Ukrainian individuals and institutions as well as international non-government organizations (NGOs), Western think tanks, governments, and other organizations associated with international policy. The end goal is to deploy a custom backdoor called CosmicPulse by setting up scheduled tasks using RedFlick through phishing emails masquerading as invitations. Once a victim responds to an initial phishing email, Star Blizzard typically sends a follow-up containing a password-protected archive that triggers the RedFlick chain. "This technique is a notable departure from the actor’s previous use of ClickFix-based infection chains which required victims to complete multiple actions before CosmicPulse could be installed," Microsoft said. "By contrast, the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process."
  • NeedyMantis Malware Enables Persistent Network Access — A modular post-compromise malware family called NeedyMantis is being used by threat actors to maintain long-term stealth access and support post-compromise operations. Distributed by a two-stage loader and launched via DLL sideloading, the malware has been observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. The activity aligns with operations that are associated with threat actors operating from China. The malware operation has been active since at least October 2025. "While NeedyMantis employs techniques commonly used by modern malware, its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components that enable operators to evade analysis and extend functionality through additional modules," Microsoft said. At least one threat actor has been linked to its use: Storm-3069, which is Microsoft's designation for the DAEMON Tools supply chain attack that took place in May 2026.
  • RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims — The Android malware known as RatHat has been observed using Google Gemini to estimate each victim's bank balance and sorts the device into high-value and mid-value groups. "Gemini is used on both sides of the operation: the malware asks an LLM where to tap when its automation fails on an unfamiliar phone, and the panel uses one to estimate victims' bank balances from their SMS," Cleafy said. Over the course of the operation, the threat actors behind RatHat changed its command-and-control (C2) panel entirely, moving from ackCat to Panda Workshop. "The panel works as a complete malware factory: it builds, signs, and publishes new samples from the console, rebuilds them on a schedule to evade hash-based detection, without the operator touching the hosting infrastructure," Cleafy added. "Account caps and role-gated sections exist to constrain the panel's own users, and pivoting on its frontend artifacts resolves the three generations to nearly 100 separate deployments since April 2026."
  • AI Coding Agents Leaked 13K Internal Company Screenshots — A new report from Glow Labs found that AI coding agents posted more than 13,000 sensitive screenshots of corporate software projects from 343 companies to public GitHub repositories. The activity has been codenamed PixelLeak. About a third of the exposures came from developers who were using gitshot. "Each case investigated during our 'PixelLeak' research started with a developer asking an agent to prove that a visual change worked," researchers said. "The software was changed, for example with a fix to the user interface layout, and the reviewers needed to see the before and after. The agents figured out that they could make the image available to the human reviewer by hosting it in an adjacent public repo. They just didn't consider the security implications." These incidents show that AI creates new security risks even without having to facilitate cyber attacks.

‎️‍🔥 Trending CVEs

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-88779 (Citrix NetScaler ADC and NetScaler Gateway), CVE-2026-96419, CVE-2026-96421, CVE-2026-95391, CVE-2026-95389 (Wireshark), CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, CVE-2026-86860 (ServiceNow), CVE-2026-93485 aka Comment2Shell (WordPress), CVE-2026-76708, CVE-2026-76709, CVE-2026-76710 (HPE Networking Analytics and Location Engine), CVE-2026-89078, CVE-2026-93577 (GitLab), CVE-2026-96512 (Sudo), CVE-2026-87022, CVE-2026-86350, CVE-2026-78437, CVE-2026-78383, CVE-2026-77791, CVE-2026-79677, CVE-2026-76183, CVE-2026-75973, CVE-2026-86248, CVE-2026-73581 (Apache Tomcat), CVE-2026-18163, CVE-2026-18162, CVE-2026-18169 CVE-2026-18177, CVE-2026-18132, CVE-2026-18872, CVE-2026-17635, CVE-2026-17645, CVE-2026-18137 (IBM Financial Transaction Manager), CVE-2026-94384 (AWS Connect Salesforce Lambda), CVE-2026-65127, CVE-2026-65113, CVE-2026-65128, CVE-2026-65114, CVE-2026-65121, CVE-2026-65130 (NVIDIA), CVE-2026-74849 (ManageEngine ADSelfService Plus), CVE-2026-75939 (Red Hat OpenShift), GHSA-632h-h47v-g4x4 (OpenCode), CVE-2026-91765 (PHP), CVE-2026-96760 (Authlib), CVE-2026-42542, CVE-2026-44639 (TDengine), CVE-2026-86553, CVE-2026-86555, CVE-2026-86552, CVE-2026-86554 (ZTE SmartLife), CVE-2026-101891, CVE-2026-87969, CVE-2026-86102, CVE-2026-86131 (WatchGuard), GHSA-cpc9-c4h3-2jwx (geoserver/geoserver-cloud), CVE-2026-93302, CVE-2026-89102 (WolfSSL), CVE-2026-84782 (OpenSSL), CVE-2026-12530, CVE-2026-16796 (Amazon Bedrock AgentCore Python SDK), CVE-2026-76504 (Cisco Catalyst SD-WAN Manager), CVE-2026-84411 (MikroTik RouterOS), CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, CVE-2026-92371, CVE-2026-19042, CVE-2026-16444, CVE-2026-12703 (TeamViewer), CVE-2026-102331 (Google Chrome), from CVE-2026-100756 through CVE-2026-100793 (Mozilla Firefox), CVE-2026-54154, CVE-2026-102147, CVE-2026-102149, CVE-2026-102102, CVE-2026-102103, CVE-2026-102104, CVE-2026-102105, CVE-2026-102106, CVE-2026-102115, CVE-2026-102095, CVE-2026-85066, CVE-2026-85065 (Kiteworks), CVE-2026-102489, CVE-2026-102490 (Zammad), CVE-2026-63292, CVE-2026-42356, CVE-2026-42528 (Apache HTTP Server), CVE-2026-101898, CVE-2026-101901, CVE-2026-101909, CVE-2026-101906, CVE-2026-101903, CVE-2026-101907, CVE-2026-101905, (Axios), CVE-2026-72018 (Linux kernel), CVE-2026-101169 (Octopus Server), CVE-2026-94545 (Next.js), CVE-2026-73857, CVE-2026-73856 (ModSecurity), CVE-2026-12855 (InsydeH2O IHISI SMM), MTLVULN-1694 (Mitel MiCollab), CVE-2026-81963 (Microsoft Windows), CVE-2026-90970, CVE-2026-1868 (GitLab AI Gateway), CVE-2026-79898, CVE-2026-12627, CVE-2026-79901 (Fortra BoKS), CVE-2026-93698, CVE-2026-93029, CVE-2026-93697 (cPanel and WHM), CVE-2026-103922 (Capacitor), CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184 (Telerik UI for ASP.NET AJAX), CVE-2026-84732, CVE-2026-84256, CVE-2026-84226, CVE-2026-82312, CVE-2026-78043, CVE-2026-81738 (OpenVPN), CVE-2026-75754 (ASUS Control Center Enterprise), CVE-2026-96659 (Foreman), CVE-2026-61500 (Rejetto HFS), CVE-2026-18167, CVE-2026-18330 (TP-Link Archer AX55 v4), CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, and CVE-2026-67273 (Dell Container Storage Modules).

🎥 Cybersecurity Webinars

  • How to Control AI Agents Before Access Sprawl Takes Over → AI agents are rapidly gaining access to sensitive systems, data, and workflows—but most security programs were never designed to govern non-human identities at this scale. This webinar breaks down how to discover AI agents, control their permissions, prevent excessive access, and build a governance model that keeps agent adoption from turning into the next major identity security problem.
  • AI Attacks Move at Machine Speed. Can Your Identity Security Keep Up? → AI-powered attacks can now move from reconnaissance to privilege escalation faster than traditional security teams can investigate and respond. This webinar explains why identity is becoming the critical real-time control layer—and how runtime identity security can help organizations detect risky access, enforce decisions across cloud, SaaS, on-prem, and AI environments, and stop machine-speed attacks before they turn into breaches.

📰 Around the Cyber World

  • Google Halts OSS VRP Submissions — As of October 1, 2026, Google is no longer accepting OSS VRP product vulnerability submissions due to a "significant rise in automated submissions, the vast majority of which are not valid." The tech giant added: "For some Google Cloud repos impacting Google Cloud products, we may still accept reports covering product vulnerabilities through the Cloud VRP. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027."
  • Microsoft's X Account Briefly Hijacked — Unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. "We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft," a Microsoft spokesperson told The Verge. "The account has been secured, and the unauthorized posts have been removed, and we are continuing to investigate the circumstances."
  • TIKTOUK, a WordPress Credential Collection Toolkit — A new toolkit called TIKTOUK "brings together WordPress probing, collection of exposed configuration data, recovery of encrypted email credentials, and JavaScript secret scanning," LevelBlue said. TIKTOUK features Python components and a Go-based Linux crawler that probes WordPress pages and REST batch routes, collects configuration and option values, and retrieves referenced JavaScript files, scans their contents, and reports matching secret patterns.
  • Google Details PageBreak — Google has detailed an internal AI agent called PageBreak that aims to autonomously scale vulnerability discovery while minimizing manual work arising from hallucinated bug reports. "Rather than simply hypothesizing bugs based on code patterns, the system closes the loop by verifying potential flaws against running environments," Google said. "This approach results in a near-zero false positive rate, ensuring that we avoid overloading product teams with unverified vulnerability reports." Page has uncovered over 500 Cross-Site Scripting (XSS) vulnerabilities across Google first-party web applications.
  • Milk Dragon Phishing Kit Detailed — Group-IB has shed light on an adversary-in-the-middle (AiTM) phishing kit called Milk Dragon (aka NaiLong) that has been active since October 2025. "Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures victims with big discounts on consumer goods distributed via Facebook and TikTok marketplace advertisements," Group-IB said. "Phishing pages impersonate brands across multiple industries, including Retail & Supermarket chains. Well-known brand names such as LEGO, Calvin Klein, Aeon Malaysia, and many others are exploited and used as lures." The attack is designed to steal financial information from victims. Actively sold on Telegram, Milk Dragon has claimed victims spanning 66 countries, with 258 phishing pages identified to date.
  • Iranian Hacker Extradited to the U.S. — An Iranian hacker accused of being behind a cyber espionage campaign targeting hundreds of universities, federal and state government agencies, private sector companies, and non-governmental organizations has been extradited to the U.S. Amir Barati, 40, is expected to face wire and computer fraud charges in the US Southern District of New York. The High Court in Podgorica approved his extradition last month.
  • New Variant of NodeStealer Emerges — Netskope Threat Labs said it detected a new variant of NodeStealer packing major updates that turn it into a full-blown spyware. The new features were likely written with AI assistance. "The latest Python NodeStealer variant incorporates new spyware features, including keylogging, clipboard monitoring, and screenshot capture," Netskope said. "In addition, it expands its theft targets to include Wi-Fi passwords, the victim’s Pictures folder, and two additional web browsers. Earlier NodeStealer variants queried only two Facebook Graph API endpoints. The latest variant queries more than 20 endpoints to construct a comprehensive dossier on the individual managing the account."
  • Bypassing Microsoft's RejectDirectSend — ReliaQuest said an empty Simple Mail Transfer Protocol (SMTP) envelope sender can bypass RejectDirectSend, which is designed to block unauthenticated Direct Send mail. "An external sender can omit the envelope domain while retaining an internal-looking address, making phishing messages more likely to be trusted. The message still carries an internal-looking address, increasing the likelihood that spearphishing reaches the recipient," ReliaQuest said. "The technique requires only one empty field – no credentials, no registered lookalike domain, and no dedicated sending infrastructure – so organizations should expect continued use." The cybersecurity company said it observed attackers repeatedly using self-addressed messages and familiar business lures to target leadership and business-facing users.
  • Attackers Exploit PaperCut Flaws to Deliver AdaptixC2 — In late August 2026, threat actors exploited CVE-2026-82078 and CVE-2026-81578, two PaperCut MF vulnerabilities, as zero-days to load an in-memory Java loader, which in turn deployed a web shell. The web shell was then used to deploy a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant. "AdaptixC2 is an open-source and highly modular post-compromise framework that provides a broad set of capabilities, including remote shell access, file management, reverse proxying, and modules for Active Directory attacks, credential harvesting, lateral movement, and more," eSentire said. "In this intrusion, threat actors used the lateral movement module to steal a token from a process running under a domain-privileged service account and move laterally to a domain controller." Upon gaining access to the domain controller, the threat actors dumped credentials to obtain the service account's NTLM hash and enabled Windows Restricted Admin mode. Ultimately, the attackers dumped the domain's Active Directory NTDS.dit database in an attempt to collect password hashes for all domain accounts.
  • Anthropic Says GLM-5.3 Can Build Cyber Exploits — Anthropic revealed that Zhipu AI's (aka Z.ai) GLM-5.3 model can autonomously build end-to-end cyber exploits, like Claude Mythos Preview, and that it has been released without "meaningful safeguards to limit misuse." The AI company said attackers can bypass the open-weight model's safeguards between 64% and 100% of the time with simple techniques, adding that these lax safeguards significantly increase the cyber capabilities available to malicious actors. "At the same time, these capabilities can also benefit defenders working to secure their systems," it added. "The funniest part is how Anthropic admitted self-reflectively that the lack of guardrails may actually be benefiting the defenders working to secure their systems," Evilginx creator Kuba Gretzky said in an X post. "Something they never wanted to allow, because of possible misuse."

Conclusion

This week was a useful reminder that attackers do not need one perfect path. A fresh exploit, an exposed secret, a weak mail control, or one careless workflow can all get them moving.

Patch what is exposed, review what is trusted by default, and keep an eye on the simple paths. The clever stuff matters, but plenty of trouble still starts with something ordinary being left open.



from The Hacker News https://ift.tt/9V35amn
via IFTTT

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling.

"Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report published last week. "The result is a botnet whose traffic can resemble legitimate NAT-traversal activity while still supporting propagation, proxying, tunneling and denial-of-service commands."

The operational technology (OT) security company said it observed a spike in attempts to exploit CVE-2021-35394 (CVSS score: 9.8), a critical remote code execution (RCE) flaw in Realtek Jungle SDK starting around September 5, 2026, with a subset of the activity delivering Cling.

An analysis of the malware sample has found it to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors -

"The single-instance check to only run one copy involves binding a socket with SO_REUSEADDR to port 33957 and exiting cleanly if it fails," Nozomi Networks said. "The sample copies itself to /root/.cling and /usr/local/bin/.cling. Both executables are appended to /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot, thus achieving persistence on SysV and BusyBox init systems."

An alternative persistence mechanism involves identifying the wget binary on the infected system and then replacing it with the malware, but not before moving the original to another location. This, in turn, causes the malware to be executed when a legitimate process invokes the "wget" command.

A notable aspect of Cling is its abuse of harmless-looking STUN traffic and public STUN infrastructure to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective.

STUN, short for Session Traversal Utilities for Network Address Translation (NAT), is a standardized network protocol that's designed to assist devices behind a NAT or firewall in establishing peer-to-peer real-time communications.

Specifically, the malware follows a four-step process for command-and-control (C2) communications -

  • Send a STUN Binding Request to a hard-coded list of 13 STUN servers roughly every 5 seconds. The transaction ID is set to all zeros instead of a random value, as per the specification.
  • Record the externally observed ports returned by those servers upon receiving a Binding Success Response message containing the public IP address of the endpoint and the associated port numbers.
  • Sends a custom registration message (i.e., a UDP datagram) to each server that includes the mapped ports and a tag denoting how the device was infected (e.g., realtek.selfrep, selfrep.router).
  • Poll for UDP packets that encode operator commands in the STUN transaction ID field.

"From a network monitoring perspective, the activity appears as innocuous interaction with STUN servers," Nozomi Networks said. "Given that the custom registration message is sent to every STUN server in the list, it is apparent that the operator requires visibility into at least one of the servers, in order to track new bots joining the swarm to know where to send commands to."

It's worth noting these registration messages do not conform to the STUN protocol definition, causing legitimate STUN servers to drop the packet. However, one of the 13 servers ("145.249.115[.]184") is said to have returned an all-zero transaction ID instead of echoing the transaction ID of the original Binding Request in the Binding Success Response.

This unusual behavior, per Nozomi, suggests the STUN server is tailored to the bot's own STUN traffic and that it's used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field.

The commands allow the threat actor to recursively scan and spread the scale of the botnet in a worm-like fashion, spawn/stop a TCP tunnel, launch/stop a proxy, and perform a denial-of-service (DoS) attack against a specified target for a given time duration. Some of the targets of the flooding attacks are below -

  • 112.151.157[.]222:8080 (South Korean ISP)
  • 192.170.240[.]137:53 (University of Chicago cluster)
  • 23.81.40[.]193:25565 (Minecraft)
  • 147.185.221[.]129:25565 (Minecraft)

"The most interesting part of the C2 traffic is where the commands appeared to come from," Nozomi Networks explained. "The packets carrying operator commands originate from 74.125.250[.]129, an IP address that stun.l.google.com resolves to."

"In other words, the operator is not merely hiding commands inside a STUN-looking packet, but they are making those commands appear as if they are legitimate replies from one of the most recognizable STUN services on the internet."



from The Hacker News https://ift.tt/HbxVqf7
via IFTTT

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.

"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge and understanding," Apple said in a post. "For communication apps, this can also compromise the privacy of the people users are communicating with."

Full Disk Access, accessed via Privacy & Security in the Settings app, was introduced by Apple in macOS Mojave (version 10.14), offers users greater control over which applications can access their entire system and data from apps like Mail, Messages, Safari, and Time Machine backups.

Once the setting is enabled for an application, it allows that program to bypass certain security restrictions and read and write to system files that apps are typically restricted from accessing or modifying. This option is essential for apps, such as security tools and backup software, that require deep system access to function properly.

Stating that Full Disk Access largely bypasses controls designed to safeguard users' private data, Apple said it plans to introduce updates to the setting to ensure that this sort of access is granted only with an explicit user action. It's currently not known when the new controls will be rolled out.

"As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," Apple added. "We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy."

Although Apple did not take any specific name, the development appears to be a response to a recent report about how Meta's Muse agentic tool accessed a journalist's private iMessages after they granted it Full Disk Access. Muse is advertised as a "personal AI agent" built along the lines of OpenClaw that runs on a dedicated Linux virtual machine on Meta's cloud.

Meta has since clarified that, for Muse to be able to access a user's private messages, it must have two permissions: have Full Disk Access and have a Messages connector setting in Muse enabled.

"The Messages integration in the Muse Mac app is opt in," Meta CTO David Singleton said. "Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled."

Apple's announcement also comes weeks after security researcher Patrick Wardle demonstrated a proof-of-concept (PoC) exploit for a zero-day in Muse's Mac app called not-a-mused that allows any app or terminal command to obtain access to the token that authenticates users to their Muse account.

The now-patched vulnerability "can let an unprivileged local process redirect Muse's dictation traffic and abuse the trust/access granted to the app," Wardle said. "The concern is that Muse may have significantly broader access than ordinary local malware, making it a particularly useful target for privilege/access amplification."

Specifically, a local attacker can exploit an undocumented setting named "endo_voyager_dictation_endpoint" without requiring any special privileges, allowing them to capture dictated audio and prompts, inject malicious prompts, and abuse the access Muse has been granted for other malicious actions.

Wardle has also been acknowledged for reporting another vulnerability, tracked as CVE-2026-100754, impacting OpenAI's ChatGPT app for Mac that could have been abused to take over the AI assistant and grant an attacker unauthorized access to chat logs and other data stored by the app.

These findings demonstrate how the privileged position enjoyed by agentic tools, the extensive data they collect, and their ability to interact with various parts of the operating system, like writing files to disk, accessing the mic and camera, creating calendar events, sending emails, and monitoring location, can expand the attack surface and open the door for an adversary to abuse this access and steal sensitive data.



from The Hacker News https://ift.tt/CajPkvB
via IFTTT

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.

The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and seize control of affected systems.

"Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login," according to an advisory for the flaw.

"A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature."

Horizon3.ai researcher Zach Hanley, in a post published on September 30, 2026, said Anthropic's Mythos model was used to discover the vulnerability, describing it as an authentication bypass that facilitates arbitrary remote code execution on Rejetto HFS.

"Rejetto HFS's administrative API allows for custom endpoints that can execute arbitrary JavaScript," Hanley said. "Combined, this presented a clear path from unauthenticated access to administrative control, and ultimately, remote code execution."

A patch for the vulnerability was released in July 2026 in version 3.2.1. However, it was not until late September that a Python-based proof-of-concept (PoC) exploit was publicly released by a security researcher named Alejandro Ramos (aka aramosf).

"HFS generated its Koa session-cookie signing key with JavaScript Math.random() and exposed outputs from the same V8 PRNG in the unauthenticated SRP login handshake," Ramos noted. "An attacker can reconstruct the PRNG state, recover the signing key, forge an administrator session, and use the documented server_code configuration feature to execute server-side JavaScript."

According to VulnCheck's Patrick Garrity, exploitation attempts were detected on October 1, 2026, a day after Horizon3.ai published additional details of the flaw. The cybersecurity company said it identified an unnamed threat actor in China targeting real vulnerable hosts in the U.S.

CVE-2026-61500 is the second vulnerability in Rejetto HTTP File Server after CVE-2024-23692 (CVSS score: 9.8) to come under active exploitation in the wild. In July 2024, multiple threat actors were observed weaponizing the flaw to deliver cryptocurrency miners, trojans, and a malware named HATVIBE.



from The Hacker News https://ift.tt/eAGjPzs
via IFTTT

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks.

The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0.

"CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said. "The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met."

For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP). Customers can check if their NetScaler deployment meets the precondition by reviewing their configuration for entries matching the following -

  • SAML SP - add authentication samlAction
  • SAML IdP - add authentication samlIdPProfile

The issue has been addressed in the following versions -

  • NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP

Citrix's Cloud Software Group credited Bishop Fox and watchTowr for reporting the vulnerability.

"Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to denial-of-service," the company acknowledged. "If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data."

The patches come after Citrix said it's tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments and that it's related to deployments that use SAML authentication in conjunction with Gateway or AAA functionality.

The development also follows reports of active exploitation of CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunneling tools on compromised systems.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the patches by October 7, 2026.



from The Hacker News https://ift.tt/7Lzb4QC
via IFTTT

Sunday, October 4, 2026

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations.

The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a U.S. think tank in February 2026. The phishing email carried the subject line "Request for Feedback on Military Integration of Claude."

"This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the U.S. AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the U.S. and China," Proofpoint said in an analysis published this week.

The enterprise security company has described TA419 as a China-aligned and espionage-motivated threat actor that has a track record of orchestrating credential phishing campaigns against individuals working for U.S.- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025.

Around July 2026, the threat actor is said to have impersonated several individuals, including a former member of the White House Office of Science and Technology Policy leadership team, as part of credential phishing campaigns targeting AI policy experts in the U.S.

The attack begins with harmless invitations that aim to establish trust with the target. It's only when the recipient responds to the outreach that the next stage kicks in, with the adversary following it up with a shortened URL that triggers a multi-stage redirection chain, which leads to an OneDrive adversary-in-the-middle (AitM) credential phishing page after completing a Cloudflare Turnstile check.

The page employs a technique called Frameless BitB, a version of the browser-in-the-browser (BitB) attack that spoofs a trusted website or login page by crafting a fake browser window within a legitimate browser session using HTML, CSS, and JavaScript.

While BitB works by serving the sign-in page inside an iframe, Frameless BitB, as the name implies, achieves the same goal without using the HTML element. "This can be achieved by injecting scripts and HTML besides the original content using search and replace (aka substitutions), then relying completely on HTML/CSS/JS tricks to make the visual effect," security researcher Wael Masri noted back in January 2024.

According to Proofpoint, TA419 has extended the open-source tool with a bespoke telemetry and automation module that tracks the target's Microsoft sign-in flow and captures the credential information using the AitM proxy, while relaying the details to the real Microsoft infrastructure in the background.

The main advantage this method offers is that the victim doesn't notice anything is amiss, as the sign-in event is successful and there are no indications that the resulting session cookies have been stealthily captured by the attacker.

To safeguard against this threat, organizations are recommended to enable phishing-resistant authentication methods like passkeys, and individual targets who are the focus of TA419 activity should treat unsolicited subject-matter outreach with caution, and verify their authenticity before proceeding further.

"TA419 has consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the U.S. and Japan," Proofpoint said. "The targeting of AI policy experts represents an extension of that remit rather than a departure from it."



from The Hacker News https://ift.tt/nPNUyZ5
via IFTTT