Saturday, October 3, 2026

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries.

The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations.

"In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university," the Broadcom-owned cybersecurity unit said. "Victims were in Portuguese- and Spanish-speaking countries, spanning Europe, Africa, and Latin America."

Warlock, also tracked as Gold Salem, Longlegs, and Storm-2603, gained prominence in mid-2025 in connection with the zero-day exploitation of the "ToolShell" SharePoint flaws to deploy ransomware on targeted systems.

Earlier this year, the group was linked to the compromise of SmarterTools by exploiting an unpatched SmarterMail instance. It has also relied on legitimate tools like Velociraptor for command-and-control (C2) and the bring your own vulnerable driver (BYOVD) technique to disarm security software running on a compromised host.

According to Symantec, Warlock shares overlaps with older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang.

"In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain's SYSVOL share, where ordinary domain replication delivered it to machines," the researchers said.

Attacks mounted by Warlock have leveraged multiple vulnerabilities in on-premises Microsoft SharePoint Server deployments. Upon successfully finding a way in, the threat actors have been found to drop web shells that can target multiple versions of SharePoint.

The end goal of the web shell is to collect the SharePoint farm's ASP.NET machine keys, which are then abused to forge a validly signed payload and achieve remote code execution inside the SharePoint application pool.

Some of the other observed tactics are listed below -

  • Using DLL sideloading to load malicious code into memory.
  • Downloading follow-on payloads from legitimate cloud file-sharing and storage services such as catbox[.]moe and wasabisys[.]com to fly under the radar.
  • Abusing a legitimate-but-vulnerable driver K7RKScan.sys (CVE-2025-1055) as part of a BYOVD attack to disable security software. The same driver was previously exploited by DragonForce ransomware actors.
  • Using living-off-the-land (LotL) tooling to perform reconnaissance and run commands on the compromised hosts. This includes the abuse of Microsoft Visual Studio Code's built-in tunnel feature to facilitate remote connections to infected systems.
  • Staging payloads inside the compromised domain's SYSVOL share to deploy ransomware at scale.

As recently as July 22, 2026, the threat actors are said to have exploited SharePoint Server flaws to drop a web shell, conduct discovery, obtain arbitrary code execution inside the SharePoint application pool, deploy additional payloads, burrow deeper into the network, establish VS Code tunnels, terminate security software, and ultimately deploy the ransomware binary.

"Longlegs' continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related-SharePoint vulnerabilities remains a viable initial access route for attackers SharePoint deployments that have not been patched or otherwise mitigated," Symantec and Carbon Black said.

"The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking."



from The Hacker News https://ift.tt/JfnSLMd
via IFTTT

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

Featuring:

Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale.

This report examines how core areas of cybersecurity are evolving in response to that shift. Across identity security, telemetry management, human security, endpoint management, human risk intelligence, exposure management, email and domain security, connected device security, AI-native security operations, and cloud security, it explores how organizations are adapting to threats that increasingly move across systems, identities, and infrastructure rather than targeting a single point of failure.

Read the full report here: https://report.papryon.com/thehackernews

Identity Security — Keeper Security

Identity has become one of the most important security boundaries in modern organizations. As cloud infrastructure, remote work, automation, and AI agents expand the number of identities requiring access, organizations are moving toward continuous governance, least privilege, and stronger control over both human and non-human identities.

“Managing multiple disconnected tools is itself a security liability.”

— Darren Guccione, CEO & Co-Founder, Keeper Security

Website: keepersecurity.com

LinkedIn: https://ift.tt/PkXp9tT

Telemetry & Data Management — Cribl

Security teams are generating more telemetry than ever, but simply collecting more data does not necessarily create better visibility. Organizations are increasingly focused on controlling how telemetry is routed, structured, retained, and reused across security tools, while AI is creating new requirements for the quality and monitoring of security data.

“The winning security programs in 2026 and beyond aren't the ones ingesting the most data. They're the ones who can route, reshape, and reuse it on demand.”

— Nicole Beckwith, Senior Director, Security Engineering & Operations, Cribl

Website: cribl.io

LinkedIn: https://ift.tt/sXqAg8N

Endpoint Management — Automox

As organizations manage increasingly distributed endpoint environments, security teams need to reduce the time between identifying a weakness and applying an effective control. Continuous patching, configuration management, automated remediation, and visibility across Windows, macOS, and Linux are becoming central to endpoint security.

“Patch what's patchable, mitigate what isn't, and govern the endpoint continuously.”

— Justin Talerico, CEO, Automox

Website: automox.com

LinkedIn: https://ift.tt/127G4ml

Human Risk Intelligence — Nisos

Security teams are increasingly looking beyond traditional technical controls to understand the people behind emerging threats. Human risk intelligence combines investigative expertise, digital attribution, and external intelligence to identify risks involving employees, executives, candidates, and third parties.

“Identity Integrity is the new firewall.”

— Ryan LaSalle, CEO, Nisos

Website: nisos.com

LinkedIn: https://ift.tt/uMNq8xc

Exposure Management — Surf AI

Exposure management is shifting from discovering vulnerabilities toward continuously reducing the exposures that matter. As environments become more complex, organizations need to understand how individual weaknesses connect, who owns them, and what actions can safely reduce risk.

“Discovery is commoditized. The middle is hard.”

— Yair Grindlinger, Co-Founder & CEO, Surf AI

Website: surf.ai

LinkedIn: https://ift.tt/6AwJzxp

Human Security — Adaptive Security

AI-powered social engineering is making phishing, voice cloning, deepfakes, and impersonation attacks easier to create and scale. Human security is therefore moving beyond annual awareness training toward continuous, personalized simulations and risk-based intervention across email, voice, SMS, and video.

“Traditional awareness programs weren’t built for today’s threats. Human security must be continuous, personalized, and responsive to real-world risk.”

— Andrew Jones, Co-Founder & CPO, Adaptive Security

Website: adaptivesecurity.com

LinkedIn: https://ift.tt/MPBDTVh

Email & Domain Security — Red Sift

Digital impersonation is increasingly an infrastructure problem rather than an email problem alone. Attackers can combine fraudulent domains, DNS abuse, websites, and email campaigns to impersonate organizations, making visibility across the wider internet-facing environment increasingly important.

“Every part of the chain — email, domain, DNS, certificate — is a trust decision made in public infrastructure.”

— Rahul Powar, Co-Founder & CEO, Red Sift

Website: redsift.com

LinkedIn: https://ift.tt/LcKDFlx

Connected Device Security — Asimily

As connected environments expand, organizations are managing an increasingly complex mix of devices across their infrastructure. Security teams need to understand which devices are exposed, how vulnerabilities could be exploited, and which controls can reduce risk without disrupting operations. For connected environments, this makes continuous visibility, remediation, and enforcement essential.

“Knowing a device is at risk has to end in an enforced control, and it has to hold as the fleet doubles.”

— Shankar Somasundaram, CEO, Asimily

Website: asimily.com

LinkedIn: https://ift.tt/g31Nb96

AI-Native Security Operations — SentinelOne

Security operations are facing a growing gap between the speed of modern attacks and the capacity of human teams to investigate them. AI is increasingly being applied within the SOC to automate investigation, connect evidence, and reduce the manual workload required to understand incidents.

“AI accelerates, supports and suggests, but does not replace human judgment.”

— Paolo Cecchi, Area VP Sales, Mediterranean Region, SentinelOne

Website: sentinelone.com

LinkedIn: https://ift.tt/3TkKVcB

Cloud Security — CrowdStrike

Cloud environments are becoming a central target for identity-driven attacks as adversaries exploit credentials, configurations, and cloud controls to move through organizations. Security teams are therefore moving toward unified, real-time protection across identity, endpoint, and cloud environments.

“Traditional CDR capabilities that rely on static risk models and log batch processing... are simply too slow for today's threat landscape.”

— Kartik Shahani, Vice President of India & SAARC, CrowdStrike

Website: crowdstrike.com

LinkedIn: https://ift.tt/noy4xE1

Download The Full Report Here: https://report.papryon.com/thehackernews

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.



from The Hacker News https://ift.tt/B4VkaNg
via IFTTT

Friday, October 2, 2026

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems.

The vulnerabilities are listed below -

  • CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an unauthenticated remote attacker could exploit to obtain unauthorized access to storage backend administrator credentials for all registered storage arrays.
  • CVE-2026-63692 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the authorization proxy and tenant service that an unauthenticated network attacker could exploit to bypass authentication controls and gain administrative-level privileges.
  • CVE-2026-67269 (CVSS score: 9.9) - An improper privilege management vulnerability in the ContainerStorageModule Custom Resource reconciler that a low-privilege remote attacker could exploit to escalate privileges and gain root-level access on cluster nodes.
  • CVE-2026-54472 (CVSS score: 9.8) - A use of hard-coded credentials vulnerability in the CSM Authorization module that a remote unauthenticated attacker could exploit to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM Authorization proxy.
  • CVE-2026-61421 (CVSS score: 9.8) - A use of hard-coded cryptographic key vulnerability in the JWT authentication component of karavi-authorization that a remote unauthenticated attacker with knowledge of this publicly available signing secret could exploit to forge authentication tokens and gain administrative privileges.
  • CVE-2026-67273 (CVSS score: 9.6) - An improper neutralization of special elements used in a template engine vulnerability that a low-privilege attacker with remote access could exploit to escalate privileges, access sensitive information, and carry out unauthorized RBAC tampering.

"This vulnerability is considered critical as it enables a complete bypass of the csm-authorization security model, allowing an attacker to gain full administrative control over the storage infrastructure spanning all five supported Dell storage product families," Dell said about CVE-2026-63688.

As for CVE-2026-63692, Dell noted that successful exploitation could enable an unauthenticated attacker to gain complete administrative control over the authorization service, and allow them to access or manipulate storage resources across all tenants.

The PC maker also noted that an attacker can exploit CVE-2026-67269 to compromise all nodes in a Kubernetes cluster through a single custom resource submission. CVE-2026-54472, on the other hand, can be weaponized to sidestep authentication controls for the CSM Authorization proxy and enable unauthorized management of storage access policies across all connected tenants. Dell is recommending that customers apply the updates and rotate any JWT signing secrets.

"Successful exploitation grants the attacker cluster-wide read access to Kubernetes Secrets and the ability to create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls," Dell said in its advisory for CVE-2026-67273.

The flaws, which affect all versions of CSM prior to 1.17.0, have been addressed in 1.18.0. There are no workarounds or mitigations other than updating to the latest version. With vulnerabilities in Dell products (CVE-2021-21551 and CVE-2026-22769) having come under active exploitation in recent years, it's essential to apply the necessary fixes for optimal protection.



from The Hacker News https://ift.tt/d2tTinZ
via IFTTT

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported.

"We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work."

The impacted employees are Jasmine Wang, Tomek Korbak, and Mikita Balesni, the Journal reported, citing people familiar with the matter. The three researchers have all previously expressed concerns about the pace of artificial intelligence (AI) development.

It's said that the individuals shared confidential information with a third-party AI-safety organization. The name of the organization was not disclosed. According to Bloomberg, the mishandled information pertained to OpenAI's infrastructure architecture.

The departures follow a report from The New York Times that OpenAI had brushed aside employees' warnings about its safety practices when testing AI models, describing a pattern of the company deprioritizing security protocols in favor of releasing them on time.

The development also comes as frontier AI labs like OpenAI and Anthropic have faced a steadily growing number of incidents in which their AI agents broke out of sandboxes, breached real-world systems, and probed various government websites for information. These incidents have led to concerns about the growing capabilities of its most powerful models and the risks they pose.

Earlier this week, OpenAI made the decision to scrap the planned launch of an AI model, GPT-6.1 Astra, over safety concerns. It has also paused training of most powerful models after one of its agents contacted an external chatbot by exploiting a loophole in its internet-access restrictions.

In a new report published Thursday, AI research firm Transluce said it identified more instances where rogue AI agents "used aggressive techniques to access publicly available data" from U.S. and Canadian government websites using techniques like SQL injection. There is no evidence the agents gained access to non-public information.

"This includes two rudimentary and failed hacking attempts, one against the U.S. Department of Education's Civil Rights Data Collection, and one against Library and Archives Canada, a Canadian federal agency," Transluce said. The incidents took place in May and June 2026.

The AI agents have also been observed leveraging "aggressive tactics short of hacking" to target and probe U.S. government websites, such as the White House, the Departments of War, Justice, and Commerce, the CDC and SEC, and state agencies in California, Maryland, Illinois, Texas, and New York.

Although the incidents have not been attributed to any specific AI company, Transluce told Reuters the attempts exhibited tactics "consistent with prior observed ​agent activity that we have attributed to OpenAI in a similar timeframe."

OpenAI said it's "aware of reports of OpenAI models attempting to ‌access publicly ⁠available information from Canadian government websites." The Canadian Centre for Cyber Security acknowledged suspected AI agent activity targeting Government of Canada websites, adding there is no indication of any compromise of its systems.

Asymmetric Security, in another report, said it found additional instances where OpenAI agents scraped data from more than 50 private and public sector organizations' websites between March 6 and September 20, 2026. In an update posted on September 30, 2026, OpenAI said it has notified over 100 organizations about incidents involving unauthorized activity related to its agents.

"In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied," OpenAI said, acknowledging it expects to uncover more such cases as it continues to review historical activity.

"Since the Hugging Face incident, we’ve strengthened security controls⁠, restricted internet access, separated research environments more clearly, expanded monitoring, and added more training to avoid harmful or unauthorized actions."

The U.S. Federal Trade Commission (FTC) has since launched an investigation into OpenAI, Anthropic and other AI companies over the risks their technology could pose to consumers.



from The Hacker News https://ift.tt/wrVm1k0
via IFTTT

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides.

Then a board member asks three questions:

  • How secure is the organization, overall?
  • What is the actual financial exposure?
  • Is the security posture better than it was last quarter?

Most security leaders cannot answer any of them with confidence. Not because the data doesn't exist, but because it lives in a dozen tools that don't share context. A new guide to confident board reporting for CISOs takes on exactly this problem. This article walks through why traditional reporting fails and what a better model looks like.

Boards Have Stopped Trusting Activity Metrics

For years, security reporting has run on counts. Vulnerabilities found. Patches applied. Alerts closed. Phishing simulations passed. These numbers measure effort. They don't measure risk.

A board member hearing that the team closed thousands of findings last quarter has no way to judge whether the company is safer. The obvious follow-up, "safer from what, and by how much?", rarely has an answer. [STAT NEEDED: share of board members who report low confidence in the security metrics they receive]

Boards want three things:

  • Exposure, not activity. Which business-critical assets could an attacker actually reach today?
  • Trend, not snapshot. Is that exposure shrinking quarter over quarter?
  • Money, not CVEs. What is the financial impact if those paths are used?

The typical mid-size or growth enterprise runs an identity provider, a CSPM or CNAPP, endpoint detection, a SIEM, a vulnerability scanner and a long tail of SaaS applications. Each tool is accurate about its own slice. None of them sees how the slices connect. Attackers don't care about those boundaries.

Consider a realistic path:

  • A contractor account in the identity provider still holds a group membership from a finished project. The identity tool rates it low risk.
  • That group grants access to a SaaS app with an OAuth integration into the cloud environment. The SaaS security tool sees a normal integration.
  • The integration runs under a service account with broad storage permissions. The cloud posture tool flags it as medium.
  • That storage holds customer records. The data classification tool knows it's sensitive, but not who can reach it.

Four findings. Four tools. Four moderate scores. Together they form a critical path from a phishable account to the company's most sensitive data. No single dashboard shows it, so it doesn't make the board report. It gets found during an incident instead.

AI adoption widens this gap. AI agents, non-human identities, service accounts and MCP-connected tools are being added faster than anyone inventories them. Each one is a new identity with its own access, and most stacks were never designed to map where that access leads. Shadow AI becomes another set of unseen paths.

The reflex is to buy something that covers the gap. That usually produces one more console, one more export and one more column in the reconciliation spreadsheet.

The common pushback is fair: "We already have CSPM. We already have a Zero Trust architecture." Those investments matter. But they are controls, each scoped to a domain. The question the board is asking crosses domains. What's missing isn't another control. It's shared context between the controls already deployed.

This is the idea behind Cybersecurity Mesh Architecture (CSMA), a model Gartner describes for connecting distributed security tools through a common intelligence layer. Instead of replacing tools, CSMA correlates their data so identities, access, assets and exposures can be read as one graph. The CISO board reporting guide breaks down how this approach maps directly to the questions boards ask.

A Practical Framework for Board-Ready Reporting

Security leaders rebuilding their board report around exposure can follow a sequence like this:

1. Define the crown jewels with the business

Start with the assets whose compromise would hurt the business most: customer data stores, payment systems, PHI, source code, production infrastructure. Agree on them with business owners, not just the security team. This list anchors everything that follows.

2. Connect what is already deployed

Pull identity, cloud, endpoint, SaaS and vulnerability data into one correlated view. The goal is deduplication and enrichment, not new sensors. Agentless, API-based integration keeps deployment fast and avoids disrupting production.

3. Map real attack paths to those assets

Replace finding lists with paths. For each crown jewel, show which identities, human and non-human, can reach it, and through what chain of access and misconfiguration.

4. Prioritize by blast radius

A medium-severity misconfiguration on a path to customer data outranks a critical CVE on an isolated test server. Rank remediation by what it cuts off, not by its standalone score.

5. Translate exposure into financial terms

Tie each reachable crown jewel to a business impact estimate built with finance and risk teams. The report moves from "number of vulnerabilities" to "dollars at risk," which is the language boards already use for every other risk category.

6. Report the trend

Show how many attack paths to critical assets existed last quarter, how many exist now, and which remediation work closed them. This also answers the ROI question directly: it shows what the existing security stack is actually protecting.

What Changes in the Boardroom

When the report is built on attack paths instead of activity counts, the three hard questions get concrete answers:

  • How secure are we? Here are the remaining paths to our most critical assets.
  • What is our financial exposure? Here is the estimated impact if those paths are used.
  • Are we improving? Here is how many paths were eliminated since last quarter, and what closed them.

That shifts the CISO's role in the meeting from defending spend to reporting measurable risk reduction. It also gives the security team a prioritized work queue that matches what leadership cares about.

Getting Started

Mesh is the unified intelligence layer for enterprise security teams operating across fragmented security stacks with no shared context. Connecting agentlessly to your existing tools, Mesh correlates signals across identity, cloud, SaaS, endpoint, and AI environments to reveal viable attack paths to your most critical assets. By providing enterprise-wide context that no individual tool can deliver alone, Mesh helps security teams prioritize what matters most and eliminate risk faster through guided workflows. Security leaders preparing for their next board cycle can download the CISO's Guide to Confident Board Reporting.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.



from The Hacker News https://ift.tt/kbYl2Lo
via IFTTT

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled.

With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a security setting that turns on all Android's security features to secure the device against potential threats.

"In Android 17, enabling Advanced Protection automatically restricts AccessibilityService access exclusively to verified applications categorized as Accessibility Tools, closing off a major avenue of attack while preserving vital assistive technology," Google said Thursday.

The Android AccessibilityService API is a powerful framework that allows an application to run in the background, intercept user interface events, and interact with other applications on the user's behalf.

Although its primary purpose is to assist users with disabilities, such as through screen readers or voice control systems, its privileged access has been abused by banking trojans and spyware to extract sensitive data and perform malicious actions without needing root access.

Put differently, once a user is tricked into enabling the service under a social engineering pretext, the malware can turn genuine assistive features into potent cyber weapons to programmatically initiate fraudulent fund transfers from installed financial apps, log keystrokes, draw fake login screens over legitimate apps, and grant itself additional sensitive permissions.

"Because accessibility services are designed to interact directly with the screen, malicious actors can exploit them to read sensitive data, install malware, or block uninstallation," Google said.

In recent years, Google has taken a number of steps to counter this abuse -

Alongside Accessibility protection, Android 17 also brings a number of other security improvements -

  • Intrusion Logging, which enables persistent, privacy-preserving forensics logging to investigate sophisticated spyware attacks
  • USB Protection, which prevents attackers from gaining unauthorized access to your device through a physical USB connection
  • Disable WebGPU, which reduces exposure to sophisticated browser-based exploits
  • Failed Authentication Lock, which protects against physical tampering and brute-force attempts by completely locking down the device to prevent further probing
  • View Supporting Apps, which allows users to view which installed apps have checked the Advanced Protection status

"Developers can be notified when Advanced Protection is enabled so that they can auto-enable any features they have for this user population," Google said. "If you already use Advanced Protection, you will see a notification once these new capabilities arrive on your device. To take advantage of the new forensic capabilities, navigate to your Advanced Protection settings page and manually enable Intrusion Logging."



from The Hacker News https://ift.tt/dV4aRrI
via IFTTT

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.

The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system.

"An improper limitation of a pathname to a restricted directory ('path traversal') [CWE-22] and improper neutralization of NULL byte or NULL character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory.

The vulnerability impacts the following versions -

  • FortiMail 8.0.0 through 8.0.1 (Upgrade to upcoming 8.0.2 or above)
  • FortiMail 7.6.0 through 7.6.6 (Upgrade to upcoming 7.6.7 or above)
  • FortiMail 7.4.0 through 7.4.8 (Upgrade to upcoming 7.4.9 or above)
  • FortiMail 7.2.0 through 7.2.9 (Upgrade to branch 7.4 or above)
Cybersecurity

Fortinet has acknowledged that the vulnerability has been exploited in the wild, urging customers to apply the following workarounds until fixes are available for certain versions -

  • Disable IBE feature support using the following CLI command:
config system encryption ibe
set status disable
end
  • Disable access to the FortiMail management interface from the internet or restrict access only from trusted private networks.

Fortinet credited Gwendal Guégniaud of the Fortinet Product Security team with discovering and reporting the flaw. It has shared the following indicators of compromise -

  • IP addresses -
    • 79.141.169[.]187
    • 45.129.0[.]192
  • Files -
    • /data/lib/liblog.so (added)
    • /data/bin/webconsole (added)
    • /data/bin/mailservice (added)
    • /data/etc/ld.so.preload (added)
    • /bin/smit (modified)
    • /data/etc/httpd.conf (modified)
    • /data/migadmin.tar.gz (modified)

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the patch or workarounds by October 4, 2026.

Cybersecurity

The development comes as number of security flaws in Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) have come under in-the-wild exploitation.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.



from The Hacker News https://ift.tt/JZei09a
via IFTTT

Thursday, October 1, 2026

Give yourself room to be human

Give yourself room to be human

Welcome to this week’s edition of the Threat Source newsletter. 

Fall is officially here in Maryland, and I can’t be more relieved. I flourish in 50 degree weather, where it feels natural to burrow under blankets, knit sweaters, and listen to an audiobook. 

Beyond that, though, can I say that I’m glad fall is here because the end of summer has been a bit of a shitshow? I’m allowed to curse on here, right? 

Without going into too much detail, my uncle was diagnosed with a rare cancer, and my family decided we were going to fly out to spend a week with him. I was determined to find a way to make it work, but on top of all of the emotions, my mind was racing with trying to figure out how to request the time off and get coverage for the tasks I’d be missing. 

I was anxious to ask, but my manager’s response to me requesting the week off was:

“Family always, always comes first at Talos. You spend as much time with your family as you need. Don’t worry, we’ll work everything out. We have your back.”

I knew I was in such a fortunate position to have that kind of support. Yet, even with the explicit encouragement to step away, there was still a lingering weight on my shoulders that I couldn't quite set down. 

LinkedIn might be an awful, artificial place, but occasionally I’ll find a non-AI-generated think piece or quote that sticks with me. On a recent post, I read, “We’d all be better off if we gave each other a little more room to be human here without worrying it makes us look less capable.” 

Okay, ouch! That described the unsettled feeling to a T. Ever since I was laid off at my previous company, my trauma response has insisted I prove myself, make myself “indispensable” and capable of taking on any challenges thrown my way. I'm sure if you've been through a layoff, you can relate. 

If you’re scared of your team perceiving you as less capable and more dispensable, please hear this: You are not a machine, and your value to your team isn't defined by how much personal or professional weight you take on without a break. It's so easy to extend grace to others, to insist that they spend time with their ill family members, but we have to extend the same grace to ourselves. 

If your team is great, they’ll want you at your best, not just your most productive, so you can fight the good fight. Don't let this fear stop you from taking the time you need. Life is worth living now, and we’re better at what we do when we’re well in all aspects of life.

The one big thing  

For Cybersecurity Awareness Month, Talos is sharing crowdsourced strategies from our researchers to help you master “The Fine Art of Frustrating the Adversary.” By deploying deception techniques, behavioral detections, and strict controls over legitimate tools, defenders can strip away an attacker's advantages. The goal is to make every alternative slower, less stealthy, and significantly more expensive for the threat actor. Ultimately, we want to force them to make mistakes or give up entirely. 

Why do I care? 

Threat actors rely on predictable environments, dual-use tools, and manufactured urgency to execute operations at scale. If defenders rely solely on tool-specific detections, adversaries can easily pivot by simply swapping out a payload. Shifting to behavior-based detections and introducing friction, like honeypots or strict AI boundaries, exploits the fact that attackers have rigid end goals. This approach slows down their operations and gives defenders earlier opportunities to interrupt the attack chain. 

So now what? 

Start by allowlisting approved remote monitoring and management (RMM) tools and blocking unauthorized ones to prevent dual-use abuse. Build resilient behavioral analytics that target underlying techniques rather than specific malware. Consider deploying deception tactics like fake employee profiles or false infrastructure. Ensure any AI agents in your environment have identifiable, short-lived credentials and strict network boundaries. And, of course, explore the blog to dive deeper into these strategies. 

Top security headlines of the week 

South Africa seeks help after cyber attack targets air traffic control 
The South African state-owned company that provides air traffic control and weather operations for approximately 10% of the world's airspace discovered ransomware-linked malware in an OT network. (Dark Reading) 

Automated AI agent used to breach cybersecurity nonprofit DIVD 
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyber attack that the organization described as “loud and very, very messy.” Evidence uncovered during the ongoing investigation indicates the attacker exploited a vulnerability, but the attack's purpose and impact remain unclear at this stage. (Bleeping Computer)

Citrix confirms 2 NetScaler zero-days after admins pulled the plug 
Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities that have been exploited in the wild. The advisory covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway. (SecurityWeek) 

Pentagon personnel agency data breach impacts 3 million people 
The US Defense Manpower Data Center (DMDC), which maintains personnel records for the Pentagon, has started notifying people that their personal information was exposed. Unauthorized users had access to one of its file-sharing servers for roughly nine months. (SecurityWeek) 

TeamViewer urges users to patch severe flaws “as soon as possible” 
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. (Bleeping Computer) 

Cisco’s Relentless Defense report is available now 
Cisco asked 8,000 security leaders from across the globe how they’re coping with a threat landscape being reshaped by AI, including whether their processes can keep pace with AI’s ability to surface thousands of vulnerabilities at once, and whether they’re confident staying ahead of the volume of new threats being discovered. (Cisco) 

Can’t get enough Talos? 

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor 
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts. 

Securing the keys to the kingdom: Announcing Executive Threat Detection 
For a sophisticated threat actor, an executive is not only a high-ranking employee, but also a high-yield target. Talos IR’s new service offers protection for up to 10 principals, with monthly custom threat hunts and reports relevant to your organization’s most high-value IT assets. 

Beers with Talos: Your AI malware experiments are showing 
Adversaries are experimenting with AI-integrated malware, and today's guest, Talos researcher Ryan Fetterman, has been looking at their working notes. 

Upcoming events where you can find Talos 

Most prevalent malware files from Talos telemetry over the past week 

SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507  
MD5: 2915b3f8b703eb744fc54c81f4a9c67f  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 
Example Filename: sample.exe  
Detection Name: W32.9F1F11A708-100.SBX.TG** 

SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974 
MD5: aac3165ece2959f39ff98334618d10d9  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974 
Example Filename: d4aa3e7010220ad1b458fac17039c274_63_Exe.exe  
Detection Name: W32.Injector:Gen.21ie.1201 

SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59  
MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 
Example Filename: tmp00055df5.dll  
Detection Name: Auto.90B145.282358.in02 

SHA256: 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8 
MD5: d65c7b544a97b0c3f2773b5fcc57d30e  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8 
Example Filename: f_006048.exe  
Detection Name: W32.540080FEA9-95.SBX.TG 

SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
MD5: 38de5b216c33833af710e88f7f64fc98  
Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f 
Example Filename: SECOH-QAD.exe  
Detection Name: W32.9896A6FCB9-95.SBX.TG



from Cisco Talos Blog https://ift.tt/taMny13
via IFTTT

Trust Docker for the agents you don’t

Cloud Sandboxes, open Kits, and a developer community building the next generation of AI software

Docker Cloud Sandboxes are here. At WeAreDevelopers World Congress North America, we launched a way for developers to start agent work in a safe way on their laptop, move to the same microVM environment on Docker-managed cloud compute, and bring the results back. Longer tasks can keep running, even after you close your laptop. 

That launch reflects a bigger ambition. We want developers to be able to give agents useful work with confidence in the systems around them. That means a place for the agent to run, clear limits on what it can access, and a way to inspect what happened. It also means keeping the freedom to choose the agent and model that fit the job.

We brought that message to San Jose with Cloud Sandboxes, the open Sandbox Kit specification, and a commitment to bring the spec to the Cloud Native Computing Foundation (CNCF). Three mainstage talks explored what trust requires in practice. Four workshops gave developers time with the tools. Across the Docker Pavilion and booth, customers, partners, and community members brought their own experience and questions into the discussion.

A year after announcing our partnership to bring WeAreDevelopers to North America, it was exciting to join more than 10,000 developers, AI builders, and technology leaders at the inaugural event, September 23-25. Here is what we shared, and where developers can get started.

Introducing Docker Cloud Sandboxes

An agent working through a large refactor or migration may need more time than you want to keep a laptop open. Running several tasks at once can put pressure on local resources, too. Cloud Sandboxes gives those tasks somewhere else to run.

Each sandbox is an isolated microVM, a small virtual machine with its own kernel and Docker daemon. The agent can install dependencies, build applications, and run containers inside that environment. With Cloud Sandboxes, Docker supplies the compute, and developers use sbx, the same command-line tool they use for local sandboxes.

The workflow starts wherever the developer needs it to. Begin locally, move the sandbox’s filesystem to the cloud for a longer run, and bring it back when it is time to review the results. The same reusable agent packages, called Kits, work in both environments. Local and cloud credentials and policies are configured separately, so the access granted in each environment remains an explicit decision.

Cloud Sandboxes are available now, with compute billed by the second. For developers, that opens up a useful choice: keep interactive work on the laptop and give longer agent tasks their own capacity. It makes the move from local experimentation to sustained agent work a practical part of the development workflow.

The foundation for trusting agents with more work

In his opening keynote, Docker President and COO Mark Cavage explained why giving agents more freedom also requires a stronger foundation. He described four requirements for an agent factory: containment, control, choice, and capacity. Teams need to know where agents can act, see and stop their activity, choose their models and tools, and run work beyond a single laptop.

The keynote included a clear example of what can go wrong. An agent running in a container with the host Docker socket mounted found a way to read a secret on the host. It had not discovered a new vulnerability. It was using access the configuration had given it.

Docker Sandboxes puts a microVM boundary around the agent. In a subsequent demonstration, the same attempt to reach the host through the Docker socket failed inside the sandbox. Containers still do the job of packaging and running applications; the sandbox gives the agent building those applications an execution boundary of its own.

This is what we mean by trust Docker for the agents you don’t. The infrastructure enforces the boundary, even when an agent chooses an unexpected course of action. Developers can decide how much access to grant and retain responsibility for the work that ships.

Cavage also addressed the limits of those controls. Blocking an unapproved network destination is different from recognizing that an otherwise permitted email is going to the wrong customer. Narrow permissions, such as allowing an agent to read and draft messages without letting it send them, remain an essential part of using agents responsibly. There is still work to do on whether an action matches the user’s intent, and we should be clear about that.

Open Kits for environments teams can share

Once an agent has a place to run, the next question is what belongs in that environment. Which tools does it need? Which services may it reach? What credentials and storage should be available?

The new Docker Sandbox Kit specification puts those requirements in an artifact teams can share and review. A Kit is an OCI image containing the agent and its tools, together with declarations of the access it needs. It works with familiar image tooling: teams can build, push, pull, scan, and pin it by digest.

That makes an environment easier to reproduce, and it makes changes to its requested permissions visible. If a Kit asks for another network destination or credential, reviewers can see that change alongside the rest of the package. The runtime decides which requests to grant and enforces the resulting policy outside the agent.

We published the specification under Apache 2.0 and committed to bringing it to the CNCF for neutral governance. Docker Sandboxes is the first runtime to implement it. Opening the format gives other runtimes a specification they can adopt and developers a common way to describe an agent environment.

Nous Research joined Cavage onstage with Hermes, its open-source agent, as a launch partner. Packaging an independently developed agent as a Kit demonstrated the choice we want developers to have: use the agent that fits the work, with an environment and controls the team can understand.

Governing agents across the organization

Docker CTO Tushar Jain’s keynote, “Govern the Runtime, Not the Agent,” took the discussion to the team level. Organizations use different models and agent tools. Governing each tool separately makes it harder to maintain a consistent policy and see the full picture of agent activity.

Tushar made the case for a common runtime layer that can govern execution, tools, credentials, permissions, and spend. His demo supplied a concrete example: an agent’s request to delete a GitHub repository was blocked by a default-deny rule and returned HTTP 403. Enforcement came from the runtime. In the Q&A, he described team-specific policies that can give a finance user and a developer different access to the same agent, while acknowledging that agent identity remains an open industry challenge.

Docker CISO Mark Lechner connected those ideas to security in his keynote, “One Boundary for the Agentic Era”. His talk connected those runtime controls to the software supply chain. An agent consumes dependencies and tools, then creates code that a team has to review and ship. Lechner showed how a Kit manifest describes the agent’s requested access, and how a proxy can use a credential without exposing the raw API key inside the sandbox.

Managing those capabilities as code gives security teams something concrete to review. They can inspect the environment an agent receives and compare its permissions with the activity recorded during a task. Across the three talks, the common goal was to make greater agent autonomy something teams can govern.

Building with our customers, partners, and community

The Docker Pavilion kept the discussion going across Thursday and Friday, with customers, partners, and Docker engineers sharing how these ideas apply to real systems. A field-notes panel compared lessons from rolling out sandboxed agents to thousands of developers. Our engineers took questions about Sandboxes and AI Governance. A panel with Spectro Cloud and J.P. Morgan Payments asked what it takes to own how AI is deployed and governed, beyond simply consuming more tokens.

The customer and partner sessions covered several parts of the agent workflow:

• Running real workloads. Spectro Cloud showed repeatable agent workloads at the edge. J.P. Morgan Payments brought a two-container payments example that starts with docker compose up. ClickHouse showed what changes when a database starts from a hardened image, and BAND demonstrated separately sandboxed agents exchanging work.

• Controlling access and investigating activity. Palo Alto Networks connected agent audit records to investigation, while Datadog followed a security incident from detection to response. Prediction Guard demonstrated model-call controls alongside execution isolation, and Snyk showed how to inspect work inside a sandbox. GitGuardian, Mend, and Merge covered secrets, runtime guardrails, and third-party integrations.

• Providing context and reviewing results. Box, Cognee, and SurrealDB explored giving agents useful knowledge and memory with visible limits. Chainloop brought signed records to the review process, and Sonar showed how to verify generated code.

These sessions showed how the sandbox fits into a wider system of tools for running agents, protecting their access, and checking their work.

Eli Aleyner and Kelsey Hightower also sat down for a fireside chat at the Pavilion, bringing the cloud-native community into the program alongside customers, partners, and Docker engineers. The platform and security roundtables gave smaller groups space to compare what they were seeing in their own organizations.

Four workshops to get hands-on

On Wednesday, September 23, our stage and workshop program gave developers time to work with the tools themselves. All four workshops connected the larger message to practical development tasks:

• Dan Ndombe introduced Docker’s sbx command for running agents in isolated sandboxes, then worked through network rules, tools connected through Model Context Protocol (MCP), and packaging agent workflows with Kits.

• Michael Irwin built an AI-ready developer environment with Kits and sbxenv files, which describe a set of sandbox environments as configuration.

• Oleg Å elajev connected Sandboxes, MCP, and the infrastructure beneath agent workflows in a hands-on agentic platform workshop.

• Ajeet Raina focused on Docker Hardened Images and supply chain security when agents write the code.

The shorter talks connected those pieces to ordinary development work. Michael showed how to make an agent environment work across machines. Ajeet and Docker Captain Kristiyan Velkov covered Docker tools developers may have missed, including Testcontainers and Scout. Other sessions examined giving an agent its own machine and verifying the components agents put into a software build.

Demos and conversations at the Docker booth

There was plenty to explore at the Docker booth, where a steady stream of visitors could see the tools working and talk with the team. In the coding factory demo, an agent worked on a Next.js app inside its own microVM, built and served the application, and encountered a network destination blocked by organization policy. The audit view recorded the policy decision, letting visitors follow the agent’s work and see where a rule had been enforced. The demonstration connected the infrastructure controls to a familiar result: a working application developers could inspect.

The booth also hosted Sandbox Royale, an AI game challenge that invited visitors to connect agents through Model Context Protocol (MCP) and compete in a shared virtual town. Agents negotiated, traded fictional assets, and navigated a trust dilemma in fifteen-minute games with a live leaderboard. It was a lively way to explore how agents behave when they interact with other agents and untrusted input.

The steady booth traffic, demonstrations, and conversations gave our team opportunities to hear directly from developers about the work they want agents to take on.

Build with us

We came to WeAreDevelopers with a clear direction for Docker’s work in AI: make agents easier to run, make their access visible and controllable, and give developers the tools to build with them on their own terms. Cloud Sandboxes and the open Kit specification are concrete steps in that direction.

The conference gave us the chance to put that work in front of developers alongside the partners and community helping shape it. Thank you to everyone who spent time with us in San Jose. We are looking forward to seeing what you build next.

Try Docker Cloud Sandboxes, start locally with Docker Sandboxes, or explore and contribute to the Sandbox Kit specification.



from Docker https://ift.tt/ZTSm1R2
via IFTTT

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program.

"It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu, senior vice president of Google DeepMind and Chief AI Architect at Google, said.

The development comes nearly a month after the tech giant unveiled Gemini 3.8 Flash Cyber, which it described as the most capable cybersecurity model.

Like similar models from rivals Anthropic and OpenAI, Argon is assessed to be highly capable at autonomously finding, validating, and patching critical software vulnerabilities.

This includes a previously unknown critical vulnerability exposing sensitive personal information across healthcare software used by hospitals worldwide. Google did not reveal which software was affected by the security flaw.

Argon, according to Google, demonstrates "impressive leaps" in vulnerability discovery over 3.8 Flash Cyber, and outperforms the model when it comes to discovering the attack surface and generating proof-of-concepts (PoCs) to validate the findings.

Google said it plans to release a version of Argon without cyber guardrails to trusted defenders and its internal teams so that they can take advantage of its full capabilities.

Ahead of a broader rollout, the company said it's working to strengthen safeguards to rein in misalignment, prevent model misuse by bad actors, and make it resilient to indirect prompt injections (IPIs). According to a model evaluation released by Google, Argon outperforms other models to take the top spot in the Gray Swan's IPI benchmark.

"We are deploying misalignment mitigations that monitor Argon’s chain-of-thought and actions and stop execution when necessary," Google said. "We strongly encourage the rest of the industry to preserve reasoning transparency in these pivotal moments of increased capabilities while navigating alignment risks, so that model thoughts remain helpful in identifying and diagnosing misalignment."



from The Hacker News https://bit.ly/4hzelAp
via IFTTT

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.

The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate.

Apple patched the flaw on September 28, crediting Meta Product Security with the discovery and noting it may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."

The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog the following day, requiring federal agencies to apply the fix by October 2.

Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in the September 28 advisories. No workaround has been described for systems that cannot update immediately.

What the Researchers Found

The analysis was published September 30 by Dion Blazakis, Josh Maine, and Anna Groza of Calif, a firm known for research into zero-click attack surfaces in messaging apps. They started from a publicly available binary comparison of iOS 26.7 and 26.7.1.

CoreGraphics is the Apple framework for 2D drawing, image rendering, and PDF processing. It was the only library changed in 26.7.1, with the same fix applied more than 20 times across eight rasterizer functions.

The patched code converts a glyph coordinate from floating-point to a 32-bit fixed-point value. Before the patch, two of the eight functions handled out-of-range values differently: one saturated the result, the other truncated it.

That difference caused the calculated bounding box for a glyph to be too narrow. CoreGraphics then allocated a working buffer smaller than the edges it needed to draw, and wrote outside it.

To trigger the bug, the researchers built a TrueType font with coordinates large enough to force the overflow. Embedding it in a PDF with a text matrix and nested composite-glyph scaling pushes those coordinates past the limit. They published the generation scripts and a sample PDF in a public GitHub repository.

The harness calls the same ImageIO thumbnail path an app uses when previewing a received attachment. The researchers say the crash occurs on both macOS and iOS.

The macOS result includes a full debugger call stack. The iOS claim is Calif's, with no separate trace published.

The crash exposes a controlled out-of-bounds write that affects two adjacent 16-bit values in a buffer that the attacker can control, allowing writes to the stack or heap. Calif says converting that primitive into working code execution is separate work. Calif did not obtain the in-the-wild sample and cannot say how the attacker completed the chain.

The WhatsApp Question

Calif examined WhatsApp because Meta Product Security was credited with finding the flaw. The firm compared two recent WhatsApp versions, 26.37.73 and 26.38.74, and found new code in WhatsApp's Kaleidoscope attachment scanner.

The newer version reads PDF files for embedded font streams and flags suspicious ones with three defect tags: MalformedFontProgram, UndecodableFontProgram, and UnverifiedFontProgram. Any such tag returns a high-risk score to WhatsApp's attachment checker, which then stops automatic parsing of the flagged file.

Calif described those changes as circumstantial evidence pointing toward WhatsApp as a possible delivery vector. The firm's post describes its research as covering a possible WhatsApp zero-click path.

The published analysis does not describe or test a WhatsApp delivery path. The initial version did: it said the researchers' analysis suggested WhatsApp could deliver a PDF that triggers the flaw when a victim opens a chat from a trusted contact with automatic media downloads on.

That sentence was removed 85 minutes after publication in a commit by Calif CEO Thai Duong, who described the change as removing the WhatsApp speculation.

The analysis closes with a question: whether the flaw "was combined with additional vulnerabilities in WhatsApp to reach parsing with less user interaction." That phrasing suggests the path Calif studied would require user action or further WhatsApp vulnerabilities in the chain.

WhatsApp has published no advisory linking this flaw to its products. Its 2026 advisory page lists two unrelated vulnerabilities.

The Hacker News asked Meta whether WhatsApp was involved in the reported attacks. Meta did not respond before publication.

An earlier case makes the hypothesis plausible. In August 2025, WhatsApp assessed that a flaw in its linked-device synchronization messages may have been combined with a separate Apple out-of-bounds write and used against fewer than 200 targeted users, a pair of vulnerabilities THN covered at the time.

The Hacker News asked Calif about the removed delivery claim and whether the researchers had obtained the in-the-wild sample since publication. Calif did not respond before publication.

No network indicators, attacker identifiers, or exploit payload names have been made public. Apple has not said whether Lockdown Mode would have blocked the delivery path used in the reported attacks.



from The Hacker News https://bit.ly/4z6jln0
via IFTTT

MetaMask Security Incident Prompts Exit of Affected Ethereum Validators

MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure.

"We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet maker said. "At this time, we have identified no immediate threat to MetaMask wallets."

MetaMask did not disclose any additional details related to the security issue. As a precautionary measure, MetaMask said it's proactively exiting affected validators within its non-custodial staking operations, in coordination with clients and partners.

"As a reminder, our staking operations are non-custodial in nature, and we do not manage withdrawal keys for stake on behalf of our clients," it added.

Lido, a decentralized liquid staking solution for Ethereum, said MetaMask has taken steps to protect client assets related to its operated Ethereum validators.

"These steps include exiting its Ethereum (ETH) validators in the Lido protocol, and will likely incur foregone rewards as well as possible downtime penalties should validators be taken offline in the near future to reduce risks related to potential network penalties," it said.

"Relevant validators have begun the exit process, with the final validators expected to be exited (but not fully withdrawn) by the end of October 7, 2026."

(This is a developing story. Please check back for more details.)



from The Hacker News https://bit.ly/4rHn5J9
via IFTTT

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.

LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771.

CVE-2026-88771 (CVSS score: 9.5) is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.

The security flaw, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands that urged organizations to shut their appliances down, citing active exploitation. As of writing, there are currently no details about who is behind these efforts.

"One of the most consistent characteristics across the identified events was attacker-controlled authentication data containing variations of the pitboss and NSPPE strings associated with exploitation of CVE-2026-88771," LevelBlue said.

Other attempts have been observed using curl or wget to fetch additional payloads from external servers, or extract NetScaler configuration data -

  • 64.94.85[.]67:443/update_c08937.pl
  • 31.56.197[.]72:9090/lula
  • 31.56.197[.]72:9090/lula
  • 23.27.143[.]20:9000/main.py

"Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation," LevelBlue said. "The attempts included payload retrieval and execution as well as collection and staging of NetScaler configuration data."

Notable among the second-stage payloads is a Python script ("main.py") that's designed to establish a reverse shell to "45.141.21[.]130" over TCP port 443. It also searches for running processes associated with "/var/python/bin/customsnmpd" and forcefully terminates them by issuing a "kill -9" command.

Another second-stage payload, "update_c08937.pl," is a Perl script with several post-exploitation capabilities -

  • Modify "/flash/nsconfig/ns.conf" to create a local account named sec_monitor and assign it the superuser role.
  • Archive the "/flash/nsconfig" directory into "/tmp/update_result_3567cs.tgz" and upload the resulting archive containing NetScaler configuration data to "64.94.85[.]67:443." The script then deletes the archive and erases itself to reduce the forensic footprint on disk.
  • Change the permissions of "/bin/sh" to 6555 and deploy a PHP web shell at "/var/netscaler/logon/LogonPoint/.local_journal" for remote command execution and file upload and download.
  • Modify "/etc/httpd.conf" to enable PHP execution and map the web shell to URLs resembling legitimate NetScaler CSS resources, corroborating activity observed by GreyNoise.

"While some attempts used commands such as whoami to test command execution, others attempted to retrieve additional payloads, collect NetScaler configuration data, establish reverse shells, create privileged accounts, and deploy web shells," LevelBlue said.

The disclosure comes a day after Mandiant Consulting and Google Threat Intelligence Group (GTIG) said dozens of organizations have been impacted by attacks exploiting CVE-2026-88772 to deliver PHP web shells, like WHIPSHOT, and a Python tunneler dubbed SLAPSHOT.



from The Hacker News https://bit.ly/4hCrmJi
via IFTTT

Wednesday, September 30, 2026

​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026

In the agentic era, the stakes are higher: AI agents now act with real access to your identities, your data, and your cloud, so every adoption decision is a trust decision. That is why security is a through line at Microsoft Ignite 2026, from a Security Pre-Day before the event opens to a security segment in the keynote, and four security themes across all four days.

Join us in San Francisco from November 17 to 20, 2026, or online. See the Microsoft Security roadmap first, get hands-on with new agentic security solutions, and connect directly with the experts, partners, and peers who can help you make it real. This year we spotlight our AI-first, end-to-end security platform designed to protect identities, devices, data, applications, clouds, infrastructure, and the AI agents now working alongside your teams.

Why you should attend Microsoft Ignite

  • Understand where Microsoft is placing its bets. See what is being announced, what is shipping next, and what it means for your architecture, your security operations center (SOC), and your governance model.
  • Build skills you can use immediately. Technical breakouts run from level 200 to level 400, paired with instructor-led labs and onsite certifications, so you leave with implementation guidance rather than slideware.
  • Pressure-test your plans with the people who built it. Bring your real architecture, deployment, and roadmap questions to Microsoft engineers, MVPs, and the product teams behind these tools.
  • See the proof, not the promise. Customer stories, live demos, and partner solutions show what is already working in production today.
  • Connect with the people who make it real. Expert meetups, connection pods, table talks, and evening events put you alongside security practitioners, leaders, Microsoft partners, and peers working the same problems.

Make the most of your time at Microsoft Ignite

Whether you join us in San Francisco or online, you will have access to a full slate of experiences designed to help you connect, learn, and grow as a security professional. Here is what is in store.

Start a day early at the Security Pre-Day

On Monday, November 16, 2026, from 1:00 PM PT to 5:00 PM PT, the Security Pre-Day gives you four hours with Microsoft Security leaders and external industry voices before the main event begins. Expect presentations paired with interactive roundtables and ask-me-anythings (AMAs) with our security experts, built for security decision makers and practitioners alike.

Select the Security Pre-Day option during Microsoft Ignite registration.

Hear the news first in the keynote and Innovation Session

The opening keynote runs Tuesday, November 17, 2026, from 10:00 AM PT to 12:00 PM PT at Chase Center and sets the direction for the week with Satya Nadella, Microsoft CEO, and Judson Althoff.

Later in the week, the Security Innovation Session goes deeper on the security news with executive-led demos.

Where the security community comes together

Microsoft Ignite is where the security community gathers. Beyond the sessions, you will find expert meetups, connection pods, and evening experiences created for security professionals and leaders.

Two women networking at Microsoft Ignite 2025.

Secure the Night

You are invited to Secure the Night on Tuesday, November 17, 2026, an evening bringing the security community together to connect, celebrate, and have some fun. Join fellow customers and Microsoft Security leaders for a night designed to make meaningful connections.

Interested in attending? Fill out the interest form to be notified when registration goes live.

Security and Agent 365 Neighborhood at Microsoft Hub

Bring your hardest questions to the people who build and defend with these products every day. Microsoft engineers, MVPs, and partners staff the Hub throughout the week. Experience hands-on demo, participate in community conversations and happy hours with industry experts. Also check out our Security Insider podcast recorded real time.

Partners and the Microsoft Intelligent Security Association

Microsoft Intelligent Security Association (MISA) members have a full week ahead at Microsoft Ignite. Beyond the partner-focused security sessions running throughout the event, the MISA Demo Station returns to the Expert Meetup Hub from November 17 to 19, 2026, where members will demo their solutions with customers on the show floor.

Thank you to our MISA partners Ascent Solutions, Avertium, BlueVoyant, Devicie, Huntress, Illumio, Mphasis, and RSM who are sponsoring the Microsoft Secure the Night party, each hosting an interactive activation on the party floor, and the week wraps with an exclusive MISA Happy Hour on November 19, 2026—a chance for MISA partners to network with fellow members and select Microsoft Security stakeholders. For information on registration for the MISA Happy Hour, please reach out to your dedicated MISA representative.

Explore the Security sessions at Microsoft Ignite 2026

A photo of a security session stage from Microsoft Ignite 2025.

Below are the four themes shaping this year’s Security track, along with a few sessions you will not want to miss. You can view the full catalog here and filter by topic, format, and role to plan your week.

Here is an overview of the Security tracks with some highlights of our top sessions.

Defend with AI

Security operations are being rebuilt around agents. This track covers what changes when AI can not only analyze but act, and how the SOC’s operating model, data foundation, and response playbooks have to evolve to keep pace.

Sessions to watch for

  • The Alert Is Dead. The Blueprint for the Agentic SOC, which maps what replaces alert-centric operations end to end.
  • The Agentic SOC Reality Check: Market Hype vs. AI Models vs. Automation, a real-time architectural breakdown with no slides and no canned speeches.
  • Winning the Race Against Time with Autonomous Protection, on how AI is changing the economics of cyberattacks and how to compress your response window.
  • Turn signal into real-time protections with Project Perception, a hands-on lab in agentic security.

Also in this track: threat intelligence at AI speed, AI-powered endpoint vulnerability discovery and remediation, attack disruption, finding and fixing code vulnerabilities with codename MDASH, and building the security data foundation the agentic SOC runs on.

Secure AI

Your organization is already shipping agents. This track is about seeing them, governing them, and protecting them from code to runtime, across the identities they use and the data they touch.

Sessions to watch for

  • When AI acts, security has to answer: Microsoft Security for AI, the platform view of securing agentic AI.
  • Inside look: Microsoft Security as customer zero for Agent 365, covering what we learned running it ourselves.
  • Local agents are here. Can you find and secure them?, paired with a companion lab on end-to-end threat protection for local agents.
  • AI Agents Are Scaling. Are Your Access Controls Ready?, a peer discussion on identity for non-human actors.

Also in this track: prioritizing and remediating your riskiest agents, a Zero Trust approach to securing AI runtime with Microsoft Defender, data protection and governance for agents with Microsoft Purview, securing Microsoft 365 Copilot and Cowork, and turning AI security research into deployable defenses.

Get Ready for AI

Before you scale AI, the fundamentals have to hold: identity, device and app trust, data hygiene, exposure management, and Zero Trust. This track is the practitioner’s path to an AI-ready security foundation.

Sessions to watch for

  • Build secure foundations to scale AI across your organization, the anchor session for this track.
  • Identity Knows What Your SOC Doesn’t: Stop Threats Faster Together, on closing the gap between identity and security operations.
  • Can’t Phish a Passkey. But Can You Prove Who’s Behind It? and SMS MFA Is Dead. What Comes Next?, a pair on the state of phishing-resistant authentication.
  • Zero Trust for AI workshop, a hands-on lab with a companion lightning talk, Apply Zero Trust for AI: the practitioner’s shortlist.
  • Insights from Microsoft’s journey to prepare its data for AI adoption, on what it actually took internally.

Also in this track: reducing exposure across your digital estate, a single policy model for humans and agents, protecting cloud and container applications from code to runtime, getting privileged access right, and getting more out of the E5 you already own.

Secure Data

Data is the substrate AI runs on, and the thing cyberattackers are after. This track is about discovering, classifying, and protecting sensitive data across clouds, devices, AI apps, and agents.

Sessions to watch for

  • Microsoft Purview: Build the Trusted Data Foundation for AI, the place to start.
  • Strengthen and Manage Data Security Posture with Microsoft Purview, on data security posture management in practice.
  • Deploy Copilot with confidence: Find and protect exposed sensitive data, a hands-on lab to run before you turn Copilot loose.
  • Microsoft Purview AMA: Preparing Your Data for Secure AI, where you can bring your questions to the product team.

Also in this track: closing exfiltration gaps with data loss prevention, and turning global regulatory requirements into operating controls.

Choose the session format that fits how you learn

  • Breakout sessions run 45 minutes at level 200 to 400, led by experts with live demos and real architecture. They are the technical core of the Security track.
  • Theater sessions are 25 minutes of fast, demo-driven content in the Hub, designed to show rather than tell.
  • Lightning talks are 15 minutes in intimate mini-theaters, built for curiosity, questions, and quick insight.
  • Table talks are 45-minute, small-group technical discussions on real-world challenges and trade-offs, moderated by Microsoft subject matter experts.
  • Hands-on labs are 75 minutes, instructor-led and proctor-supported, in a live environment. RSVP is required and labs fill fast.

Build your schedule

Do not miss your chance to be part of Microsoft Ignite. Explore the full session catalog, filter by topic, format, and role to plan your week, and register today to connect with the global security community and get hands-on with the latest innovations.

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post ​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 appeared first on Microsoft Security Blog.



from Microsoft Security Blog https://ift.tt/RZQNbto
via IFTTT