Monday, October 5, 2026

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.

The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system.

"Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network," Microsoft said in an advisory released on October 2, 2026.

The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments. However, the vulnerability does not allow cross-tenant access.

Microsoft has already deployed a "related service-side fix" to Exchange Online to address the issue. As a result, Exchange Online customers are not required to take any action.

Users of affected on-premises Microsoft Exchange Server products are advised to install the updates to stay protected. The following versions are impacted -

  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 15
  • Microsoft Exchange Server 2019 Cumulative Update 14

Redmond has credited Microsoft researcher Jan Mitchell with discovering and reporting the flaw. Although there is no evidence of the flaw being weaponized in the wild, Microsoft has tagged it with an Exploitability assessment of "Exploitation More Likely," making it essential that users move quickly to apply the fixes.

The disclosure comes days after Broadcom-owned Symantec warned that the China-linked Warlock actor is exploiting multiple vulnerabilities in Microsoft SharePoint to deploy its namesake ransomware in attacks targeting organizations in Portuguese- and Spanish-speaking countries.



from The Hacker News https://ift.tt/H1h4620
via IFTTT

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook.

There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others are still getting in because the basics gave way first.

Here’s what mattered this week.

⚡ Threat of the Week

Citrix Warns of Newly Exploited NetScaler ADC and Gateway Flaw — Citrix released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said. "The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met." Successful exploitation requires NetScaler ADC or NetScaler Gateway to be configured either as a SAML service provider (SP) or SAML identity provider(IdP).

🔔 Top News

  • Critical FortiMail Zero-Day Flaw Exploited in Attacks — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a critical security flaw impacting Fortinet FortiMail. The flaw, CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. According to Fortinet, the vulnerability "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests."
  • Two ShinyHunters Members Arrested — Law enforcement agencies have arrested two members associated with the ShinyHunters digital extortion group. One of them is a 24-year-old Amsterdam man, who is believed to be Pepijn van der Stap, while the second individual is Saif ‌al-Din Khader, who is said to have been detained by Jordanian authorities last week. ShinyHunters has drawn attention in recent weeks for hijacking the darknet website of Cl0p and its hack of the FBI's "apply.fbijobs[.]gov" portal.
  • Authorities Arrest 16-Year-Old Mastermind Behind KillSec — Police in Spain apprehended a 16-year-old who is suspected to be the leader of the KillSec (aka Kill Security Ransomware Group) ransomware operation. According to Europol, authorities took control of KillSec's leak site on September 30, 2026, securing no less than 110 terabytes of data. As part of Operation KillSwitch, a total of three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the U.K. One of the group’s accused members, Fouad Eltibrizi, was arrested in the U.K. and is awaiting extradition to the U.S. Since emerging in 2024, the group is estimated to have launched around 1,000 attacks, at least half of which were successful. "The group exploited software vulnerabilities and poorly secured access points, particularly to cloud storage, to gain access to organizations' systems," Europol said. "Its members then copied sensitive internal data to infrastructure under their control. Victims were named on the group's dark web leak site and threatened with publication of their data unless paid." Per Group-IB, which identified 274 publicly claimed victims, out of which most were U.S., Indian, and Brazilian organizations. "The group also sold stolen data outright, with asking prices ranging from USD 5,000 for a single company's records to USD 500,000 for the data it claimed to have taken from the global insurer, making KillSec as much a data broker as a ransomware operator," Group-IB said.
  • New Spectre v2 Variant Leaks Linux Root Password Hash in Minutes — A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few minutes. The attack exploits stale information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code. By tampering with this information, an attacker can trick the processor into temporarily executing wrong instructions and potentially expose sensitive data. "We evaluated the end-to-end exploit on both Raptor Cove and Lion Cove, and leaked the password within 3 and 5 minutes on average, respectively," researchers claimed. "Indirect branch prediction is inherent to modern CPUs, and BTR exploits the desynchronization between the branch predictor and the actual state of the code. No current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable."
  • Star Blizzard Uses Fake Invites to Deploy CosmicPulse — The Russian state-sponsored threat actor known as Star Blizzard has employed a new malware delivery technique called RedFlick in attacks targeting Ukrainian individuals and institutions as well as international non-government organizations (NGOs), Western think tanks, governments, and other organizations associated with international policy. The end goal is to deploy a custom backdoor called CosmicPulse by setting up scheduled tasks using RedFlick through phishing emails masquerading as invitations. Once a victim responds to an initial phishing email, Star Blizzard typically sends a follow-up containing a password-protected archive that triggers the RedFlick chain. "This technique is a notable departure from the actor’s previous use of ClickFix-based infection chains which required victims to complete multiple actions before CosmicPulse could be installed," Microsoft said. "By contrast, the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process."
  • NeedyMantis Malware Enables Persistent Network Access — A modular post-compromise malware family called NeedyMantis is being used by threat actors to maintain long-term stealth access and support post-compromise operations. Distributed by a two-stage loader and launched via DLL sideloading, the malware has been observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. The activity aligns with operations that are associated with threat actors operating from China. The malware operation has been active since at least October 2025. "While NeedyMantis employs techniques commonly used by modern malware, its architecture combines multiple loaders, custom encrypted file archives, a custom executable file format, and modular components that enable operators to evade analysis and extend functionality through additional modules," Microsoft said. At least one threat actor has been linked to its use: Storm-3069, which is Microsoft's designation for the DAEMON Tools supply chain attack that took place in May 2026.
  • RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims — The Android malware known as RatHat has been observed using Google Gemini to estimate each victim's bank balance and sorts the device into high-value and mid-value groups. "Gemini is used on both sides of the operation: the malware asks an LLM where to tap when its automation fails on an unfamiliar phone, and the panel uses one to estimate victims' bank balances from their SMS," Cleafy said. Over the course of the operation, the threat actors behind RatHat changed its command-and-control (C2) panel entirely, moving from ackCat to Panda Workshop. "The panel works as a complete malware factory: it builds, signs, and publishes new samples from the console, rebuilds them on a schedule to evade hash-based detection, without the operator touching the hosting infrastructure," Cleafy added. "Account caps and role-gated sections exist to constrain the panel's own users, and pivoting on its frontend artifacts resolves the three generations to nearly 100 separate deployments since April 2026."
  • AI Coding Agents Leaked 13K Internal Company Screenshots — A new report from Glow Labs found that AI coding agents posted more than 13,000 sensitive screenshots of corporate software projects from 343 companies to public GitHub repositories. The activity has been codenamed PixelLeak. About a third of the exposures came from developers who were using gitshot. "Each case investigated during our 'PixelLeak' research started with a developer asking an agent to prove that a visual change worked," researchers said. "The software was changed, for example with a fix to the user interface layout, and the reviewers needed to see the before and after. The agents figured out that they could make the image available to the human reviewer by hosting it in an adjacent public repo. They just didn't consider the security implications." These incidents show that AI creates new security risks even without having to facilitate cyber attacks.

‎️‍🔥 Trending CVEs

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-88779 (Citrix NetScaler ADC and NetScaler Gateway), CVE-2026-96419, CVE-2026-96421, CVE-2026-95391, CVE-2026-95389 (Wireshark), CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, CVE-2026-86860 (ServiceNow), CVE-2026-93485 aka Comment2Shell (WordPress), CVE-2026-76708, CVE-2026-76709, CVE-2026-76710 (HPE Networking Analytics and Location Engine), CVE-2026-89078, CVE-2026-93577 (GitLab), CVE-2026-96512 (Sudo), CVE-2026-87022, CVE-2026-86350, CVE-2026-78437, CVE-2026-78383, CVE-2026-77791, CVE-2026-79677, CVE-2026-76183, CVE-2026-75973, CVE-2026-86248, CVE-2026-73581 (Apache Tomcat), CVE-2026-18163, CVE-2026-18162, CVE-2026-18169 CVE-2026-18177, CVE-2026-18132, CVE-2026-18872, CVE-2026-17635, CVE-2026-17645, CVE-2026-18137 (IBM Financial Transaction Manager), CVE-2026-94384 (AWS Connect Salesforce Lambda), CVE-2026-65127, CVE-2026-65113, CVE-2026-65128, CVE-2026-65114, CVE-2026-65121, CVE-2026-65130 (NVIDIA), CVE-2026-74849 (ManageEngine ADSelfService Plus), CVE-2026-75939 (Red Hat OpenShift), GHSA-632h-h47v-g4x4 (OpenCode), CVE-2026-91765 (PHP), CVE-2026-96760 (Authlib), CVE-2026-42542, CVE-2026-44639 (TDengine), CVE-2026-86553, CVE-2026-86555, CVE-2026-86552, CVE-2026-86554 (ZTE SmartLife), CVE-2026-101891, CVE-2026-87969, CVE-2026-86102, CVE-2026-86131 (WatchGuard), GHSA-cpc9-c4h3-2jwx (geoserver/geoserver-cloud), CVE-2026-93302, CVE-2026-89102 (WolfSSL), CVE-2026-84782 (OpenSSL), CVE-2026-12530, CVE-2026-16796 (Amazon Bedrock AgentCore Python SDK), CVE-2026-76504 (Cisco Catalyst SD-WAN Manager), CVE-2026-84411 (MikroTik RouterOS), CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, CVE-2026-92371, CVE-2026-19042, CVE-2026-16444, CVE-2026-12703 (TeamViewer), CVE-2026-102331 (Google Chrome), from CVE-2026-100756 through CVE-2026-100793 (Mozilla Firefox), CVE-2026-54154, CVE-2026-102147, CVE-2026-102149, CVE-2026-102102, CVE-2026-102103, CVE-2026-102104, CVE-2026-102105, CVE-2026-102106, CVE-2026-102115, CVE-2026-102095, CVE-2026-85066, CVE-2026-85065 (Kiteworks), CVE-2026-102489, CVE-2026-102490 (Zammad), CVE-2026-63292, CVE-2026-42356, CVE-2026-42528 (Apache HTTP Server), CVE-2026-101898, CVE-2026-101901, CVE-2026-101909, CVE-2026-101906, CVE-2026-101903, CVE-2026-101907, CVE-2026-101905, (Axios), CVE-2026-72018 (Linux kernel), CVE-2026-101169 (Octopus Server), CVE-2026-94545 (Next.js), CVE-2026-73857, CVE-2026-73856 (ModSecurity), CVE-2026-12855 (InsydeH2O IHISI SMM), MTLVULN-1694 (Mitel MiCollab), CVE-2026-81963 (Microsoft Windows), CVE-2026-90970, CVE-2026-1868 (GitLab AI Gateway), CVE-2026-79898, CVE-2026-12627, CVE-2026-79901 (Fortra BoKS), CVE-2026-93698, CVE-2026-93029, CVE-2026-93697 (cPanel and WHM), CVE-2026-103922 (Capacitor), CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184 (Telerik UI for ASP.NET AJAX), CVE-2026-84732, CVE-2026-84256, CVE-2026-84226, CVE-2026-82312, CVE-2026-78043, CVE-2026-81738 (OpenVPN), CVE-2026-75754 (ASUS Control Center Enterprise), CVE-2026-96659 (Foreman), CVE-2026-61500 (Rejetto HFS), CVE-2026-18167, CVE-2026-18330 (TP-Link Archer AX55 v4), CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, and CVE-2026-67273 (Dell Container Storage Modules).

🎥 Cybersecurity Webinars

  • How to Control AI Agents Before Access Sprawl Takes Over → AI agents are rapidly gaining access to sensitive systems, data, and workflows—but most security programs were never designed to govern non-human identities at this scale. This webinar breaks down how to discover AI agents, control their permissions, prevent excessive access, and build a governance model that keeps agent adoption from turning into the next major identity security problem.
  • AI Attacks Move at Machine Speed. Can Your Identity Security Keep Up? → AI-powered attacks can now move from reconnaissance to privilege escalation faster than traditional security teams can investigate and respond. This webinar explains why identity is becoming the critical real-time control layer—and how runtime identity security can help organizations detect risky access, enforce decisions across cloud, SaaS, on-prem, and AI environments, and stop machine-speed attacks before they turn into breaches.

📰 Around the Cyber World

  • Google Halts OSS VRP Submissions — As of October 1, 2026, Google is no longer accepting OSS VRP product vulnerability submissions due to a "significant rise in automated submissions, the vast majority of which are not valid." The tech giant added: "For some Google Cloud repos impacting Google Cloud products, we may still accept reports covering product vulnerabilities through the Cloud VRP. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027."
  • Microsoft's X Account Briefly Hijacked — Unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. "We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft," a Microsoft spokesperson told The Verge. "The account has been secured, and the unauthorized posts have been removed, and we are continuing to investigate the circumstances."
  • TIKTOUK, a WordPress Credential Collection Toolkit — A new toolkit called TIKTOUK "brings together WordPress probing, collection of exposed configuration data, recovery of encrypted email credentials, and JavaScript secret scanning," LevelBlue said. TIKTOUK features Python components and a Go-based Linux crawler that probes WordPress pages and REST batch routes, collects configuration and option values, and retrieves referenced JavaScript files, scans their contents, and reports matching secret patterns.
  • Google Details PageBreak — Google has detailed an internal AI agent called PageBreak that aims to autonomously scale vulnerability discovery while minimizing manual work arising from hallucinated bug reports. "Rather than simply hypothesizing bugs based on code patterns, the system closes the loop by verifying potential flaws against running environments," Google said. "This approach results in a near-zero false positive rate, ensuring that we avoid overloading product teams with unverified vulnerability reports." Page has uncovered over 500 Cross-Site Scripting (XSS) vulnerabilities across Google first-party web applications.
  • Milk Dragon Phishing Kit Detailed — Group-IB has shed light on an adversary-in-the-middle (AiTM) phishing kit called Milk Dragon (aka NaiLong) that has been active since October 2025. "Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures victims with big discounts on consumer goods distributed via Facebook and TikTok marketplace advertisements," Group-IB said. "Phishing pages impersonate brands across multiple industries, including Retail & Supermarket chains. Well-known brand names such as LEGO, Calvin Klein, Aeon Malaysia, and many others are exploited and used as lures." The attack is designed to steal financial information from victims. Actively sold on Telegram, Milk Dragon has claimed victims spanning 66 countries, with 258 phishing pages identified to date.
  • Iranian Hacker Extradited to the U.S. — An Iranian hacker accused of being behind a cyber espionage campaign targeting hundreds of universities, federal and state government agencies, private sector companies, and non-governmental organizations has been extradited to the U.S. Amir Barati, 40, is expected to face wire and computer fraud charges in the US Southern District of New York. The High Court in Podgorica approved his extradition last month.
  • New Variant of NodeStealer Emerges — Netskope Threat Labs said it detected a new variant of NodeStealer packing major updates that turn it into a full-blown spyware. The new features were likely written with AI assistance. "The latest Python NodeStealer variant incorporates new spyware features, including keylogging, clipboard monitoring, and screenshot capture," Netskope said. "In addition, it expands its theft targets to include Wi-Fi passwords, the victim’s Pictures folder, and two additional web browsers. Earlier NodeStealer variants queried only two Facebook Graph API endpoints. The latest variant queries more than 20 endpoints to construct a comprehensive dossier on the individual managing the account."
  • Bypassing Microsoft's RejectDirectSend — ReliaQuest said an empty Simple Mail Transfer Protocol (SMTP) envelope sender can bypass RejectDirectSend, which is designed to block unauthenticated Direct Send mail. "An external sender can omit the envelope domain while retaining an internal-looking address, making phishing messages more likely to be trusted. The message still carries an internal-looking address, increasing the likelihood that spearphishing reaches the recipient," ReliaQuest said. "The technique requires only one empty field – no credentials, no registered lookalike domain, and no dedicated sending infrastructure – so organizations should expect continued use." The cybersecurity company said it observed attackers repeatedly using self-addressed messages and familiar business lures to target leadership and business-facing users.
  • Attackers Exploit PaperCut Flaws to Deliver AdaptixC2 — In late August 2026, threat actors exploited CVE-2026-82078 and CVE-2026-81578, two PaperCut MF vulnerabilities, as zero-days to load an in-memory Java loader, which in turn deployed a web shell. The web shell was then used to deploy a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant. "AdaptixC2 is an open-source and highly modular post-compromise framework that provides a broad set of capabilities, including remote shell access, file management, reverse proxying, and modules for Active Directory attacks, credential harvesting, lateral movement, and more," eSentire said. "In this intrusion, threat actors used the lateral movement module to steal a token from a process running under a domain-privileged service account and move laterally to a domain controller." Upon gaining access to the domain controller, the threat actors dumped credentials to obtain the service account's NTLM hash and enabled Windows Restricted Admin mode. Ultimately, the attackers dumped the domain's Active Directory NTDS.dit database in an attempt to collect password hashes for all domain accounts.
  • Anthropic Says GLM-5.3 Can Build Cyber Exploits — Anthropic revealed that Zhipu AI's (aka Z.ai) GLM-5.3 model can autonomously build end-to-end cyber exploits, like Claude Mythos Preview, and that it has been released without "meaningful safeguards to limit misuse." The AI company said attackers can bypass the open-weight model's safeguards between 64% and 100% of the time with simple techniques, adding that these lax safeguards significantly increase the cyber capabilities available to malicious actors. "At the same time, these capabilities can also benefit defenders working to secure their systems," it added. "The funniest part is how Anthropic admitted self-reflectively that the lack of guardrails may actually be benefiting the defenders working to secure their systems," Evilginx creator Kuba Gretzky said in an X post. "Something they never wanted to allow, because of possible misuse."

Conclusion

This week was a useful reminder that attackers do not need one perfect path. A fresh exploit, an exposed secret, a weak mail control, or one careless workflow can all get them moving.

Patch what is exposed, review what is trusted by default, and keep an eye on the simple paths. The clever stuff matters, but plenty of trouble still starts with something ordinary being left open.



from The Hacker News https://ift.tt/9V35amn
via IFTTT

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling.

"Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report published last week. "The result is a botnet whose traffic can resemble legitimate NAT-traversal activity while still supporting propagation, proxying, tunneling and denial-of-service commands."

The operational technology (OT) security company said it observed a spike in attempts to exploit CVE-2021-35394 (CVSS score: 9.8), a critical remote code execution (RCE) flaw in Realtek Jungle SDK starting around September 5, 2026, with a subset of the activity delivering Cling.

An analysis of the malware sample has found it to embed exploit logic for various command injection and RCE vulnerabilities impacting routers and DVRs from multiple vendors -

"The single-instance check to only run one copy involves binding a socket with SO_REUSEADDR to port 33957 and exiting cleanly if it fails," Nozomi Networks said. "The sample copies itself to /root/.cling and /usr/local/bin/.cling. Both executables are appended to /etc/inittab, /etc/init.d/rcS, /etc/rc.d/rc.boot, thus achieving persistence on SysV and BusyBox init systems."

An alternative persistence mechanism involves identifying the wget binary on the infected system and then replacing it with the malware, but not before moving the original to another location. This, in turn, causes the malware to be executed when a legitimate process invokes the "wget" command.

A notable aspect of Cling is its abuse of harmless-looking STUN traffic and public STUN infrastructure to register infected hosts, receive operator commands, and make malicious activity less obvious from a network monitoring perspective.

STUN, short for Session Traversal Utilities for Network Address Translation (NAT), is a standardized network protocol that's designed to assist devices behind a NAT or firewall in establishing peer-to-peer real-time communications.

Specifically, the malware follows a four-step process for command-and-control (C2) communications -

  • Send a STUN Binding Request to a hard-coded list of 13 STUN servers roughly every 5 seconds. The transaction ID is set to all zeros instead of a random value, as per the specification.
  • Record the externally observed ports returned by those servers upon receiving a Binding Success Response message containing the public IP address of the endpoint and the associated port numbers.
  • Sends a custom registration message (i.e., a UDP datagram) to each server that includes the mapped ports and a tag denoting how the device was infected (e.g., realtek.selfrep, selfrep.router).
  • Poll for UDP packets that encode operator commands in the STUN transaction ID field.

"From a network monitoring perspective, the activity appears as innocuous interaction with STUN servers," Nozomi Networks said. "Given that the custom registration message is sent to every STUN server in the list, it is apparent that the operator requires visibility into at least one of the servers, in order to track new bots joining the swarm to know where to send commands to."

It's worth noting these registration messages do not conform to the STUN protocol definition, causing legitimate STUN servers to drop the packet. However, one of the 13 servers ("145.249.115[.]184") is said to have returned an all-zero transaction ID instead of echoing the transaction ID of the original Binding Request in the Binding Success Response.

This unusual behavior, per Nozomi, suggests the STUN server is tailored to the bot's own STUN traffic and that it's used to send operator-issued commands to the infected device by embedding them within the STUN transaction ID field.

The commands allow the threat actor to recursively scan and spread the scale of the botnet in a worm-like fashion, spawn/stop a TCP tunnel, launch/stop a proxy, and perform a denial-of-service (DoS) attack against a specified target for a given time duration. Some of the targets of the flooding attacks are below -

  • 112.151.157[.]222:8080 (South Korean ISP)
  • 192.170.240[.]137:53 (University of Chicago cluster)
  • 23.81.40[.]193:25565 (Minecraft)
  • 147.185.221[.]129:25565 (Minecraft)

"The most interesting part of the C2 traffic is where the commands appeared to come from," Nozomi Networks explained. "The packets carrying operator commands originate from 74.125.250[.]129, an IP address that stun.l.google.com resolves to."

"In other words, the operator is not merely hiding commands inside a STUN-looking packet, but they are making those commands appear as if they are legitimate replies from one of the most recognizable STUN services on the internet."



from The Hacker News https://ift.tt/HbxVqf7
via IFTTT

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.

"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge and understanding," Apple said in a post. "For communication apps, this can also compromise the privacy of the people users are communicating with."

Full Disk Access, accessed via Privacy & Security in the Settings app, was introduced by Apple in macOS Mojave (version 10.14), offers users greater control over which applications can access their entire system and data from apps like Mail, Messages, Safari, and Time Machine backups.

Once the setting is enabled for an application, it allows that program to bypass certain security restrictions and read and write to system files that apps are typically restricted from accessing or modifying. This option is essential for apps, such as security tools and backup software, that require deep system access to function properly.

Stating that Full Disk Access largely bypasses controls designed to safeguard users' private data, Apple said it plans to introduce updates to the setting to ensure that this sort of access is granted only with an explicit user action. It's currently not known when the new controls will be rolled out.

"As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," Apple added. "We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy."

Although Apple did not take any specific name, the development appears to be a response to a recent report about how Meta's Muse agentic tool accessed a journalist's private iMessages after they granted it Full Disk Access. Muse is advertised as a "personal AI agent" built along the lines of OpenClaw that runs on a dedicated Linux virtual machine on Meta's cloud.

Meta has since clarified that, for Muse to be able to access a user's private messages, it must have two permissions: have Full Disk Access and have a Messages connector setting in Muse enabled.

"The Messages integration in the Muse Mac app is opt in," Meta CTO David Singleton said. "Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled."

Apple's announcement also comes weeks after security researcher Patrick Wardle demonstrated a proof-of-concept (PoC) exploit for a zero-day in Muse's Mac app called not-a-mused that allows any app or terminal command to obtain access to the token that authenticates users to their Muse account.

The now-patched vulnerability "can let an unprivileged local process redirect Muse's dictation traffic and abuse the trust/access granted to the app," Wardle said. "The concern is that Muse may have significantly broader access than ordinary local malware, making it a particularly useful target for privilege/access amplification."

Specifically, a local attacker can exploit an undocumented setting named "endo_voyager_dictation_endpoint" without requiring any special privileges, allowing them to capture dictated audio and prompts, inject malicious prompts, and abuse the access Muse has been granted for other malicious actions.

Wardle has also been acknowledged for reporting another vulnerability, tracked as CVE-2026-100754, impacting OpenAI's ChatGPT app for Mac that could have been abused to take over the AI assistant and grant an attacker unauthorized access to chat logs and other data stored by the app.

These findings demonstrate how the privileged position enjoyed by agentic tools, the extensive data they collect, and their ability to interact with various parts of the operating system, like writing files to disk, accessing the mic and camera, creating calendar events, sending emails, and monitoring location, can expand the attack surface and open the door for an adversary to abuse this access and steal sensitive data.



from The Hacker News https://ift.tt/CajPkvB
via IFTTT

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.

The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and seize control of affected systems.

"Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login," according to an advisory for the flaw.

"A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature."

Horizon3.ai researcher Zach Hanley, in a post published on September 30, 2026, said Anthropic's Mythos model was used to discover the vulnerability, describing it as an authentication bypass that facilitates arbitrary remote code execution on Rejetto HFS.

"Rejetto HFS's administrative API allows for custom endpoints that can execute arbitrary JavaScript," Hanley said. "Combined, this presented a clear path from unauthenticated access to administrative control, and ultimately, remote code execution."

A patch for the vulnerability was released in July 2026 in version 3.2.1. However, it was not until late September that a Python-based proof-of-concept (PoC) exploit was publicly released by a security researcher named Alejandro Ramos (aka aramosf).

"HFS generated its Koa session-cookie signing key with JavaScript Math.random() and exposed outputs from the same V8 PRNG in the unauthenticated SRP login handshake," Ramos noted. "An attacker can reconstruct the PRNG state, recover the signing key, forge an administrator session, and use the documented server_code configuration feature to execute server-side JavaScript."

According to VulnCheck's Patrick Garrity, exploitation attempts were detected on October 1, 2026, a day after Horizon3.ai published additional details of the flaw. The cybersecurity company said it identified an unnamed threat actor in China targeting real vulnerable hosts in the U.S.

CVE-2026-61500 is the second vulnerability in Rejetto HTTP File Server after CVE-2024-23692 (CVSS score: 9.8) to come under active exploitation in the wild. In July 2024, multiple threat actors were observed weaponizing the flaw to deliver cryptocurrency miners, trojans, and a malware named HATVIBE.



from The Hacker News https://ift.tt/eAGjPzs
via IFTTT

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks.

The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0.

"CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said. "The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met."

For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP). Customers can check if their NetScaler deployment meets the precondition by reviewing their configuration for entries matching the following -

  • SAML SP - add authentication samlAction
  • SAML IdP - add authentication samlIdPProfile

The issue has been addressed in the following versions -

  • NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP

Citrix's Cloud Software Group credited Bishop Fox and watchTowr for reporting the vulnerability.

"Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to denial-of-service," the company acknowledged. "If the condition is triggered repeatedly, the service may remain unavailable. Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data."

The patches come after Citrix said it's tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments and that it's related to deployments that use SAML authentication in conjunction with Gateway or AAA functionality.

The development also follows reports of active exploitation of CVE-2026-88771 and CVE-2026-88772 to plant web shells and tunneling tools on compromised systems.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the patches by October 7, 2026.



from The Hacker News https://ift.tt/7Lzb4QC
via IFTTT

Sunday, October 4, 2026

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations.

The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a U.S. think tank in February 2026. The phishing email carried the subject line "Request for Feedback on Military Integration of Claude."

"This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the U.S. AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the U.S. and China," Proofpoint said in an analysis published this week.

The enterprise security company has described TA419 as a China-aligned and espionage-motivated threat actor that has a track record of orchestrating credential phishing campaigns against individuals working for U.S.- and Japan-based think tanks, defense contractors, universities, and law firms since at least April 2025.

Around July 2026, the threat actor is said to have impersonated several individuals, including a former member of the White House Office of Science and Technology Policy leadership team, as part of credential phishing campaigns targeting AI policy experts in the U.S.

The attack begins with harmless invitations that aim to establish trust with the target. It's only when the recipient responds to the outreach that the next stage kicks in, with the adversary following it up with a shortened URL that triggers a multi-stage redirection chain, which leads to an OneDrive adversary-in-the-middle (AitM) credential phishing page after completing a Cloudflare Turnstile check.

The page employs a technique called Frameless BitB, a version of the browser-in-the-browser (BitB) attack that spoofs a trusted website or login page by crafting a fake browser window within a legitimate browser session using HTML, CSS, and JavaScript.

While BitB works by serving the sign-in page inside an iframe, Frameless BitB, as the name implies, achieves the same goal without using the HTML element. "This can be achieved by injecting scripts and HTML besides the original content using search and replace (aka substitutions), then relying completely on HTML/CSS/JS tricks to make the visual effect," security researcher Wael Masri noted back in January 2024.

According to Proofpoint, TA419 has extended the open-source tool with a bespoke telemetry and automation module that tracks the target's Microsoft sign-in flow and captures the credential information using the AitM proxy, while relaying the details to the real Microsoft infrastructure in the background.

The main advantage this method offers is that the victim doesn't notice anything is amiss, as the sign-in event is successful and there are no indications that the resulting session cookies have been stealthily captured by the attacker.

To safeguard against this threat, organizations are recommended to enable phishing-resistant authentication methods like passkeys, and individual targets who are the focus of TA419 activity should treat unsolicited subject-matter outreach with caution, and verify their authenticity before proceeding further.

"TA419 has consistently shown an interest in defense, national security, energy, international relations, and foreign policy targets, predominantly with a nexus to the U.S. and Japan," Proofpoint said. "The targeting of AI policy experts represents an extension of that remit rather than a departure from it."



from The Hacker News https://ift.tt/nPNUyZ5
via IFTTT

AI News for End of September 2026

Brian(@bgracely) and Brandon(@bwhicard) discuss the biggest AI news stories from the second half of September 2026.

Oracle sent a force majeure notice on a major data center build, which Brandon reads as an early signal worth tracking. If other companies follow, it would point to stress in AI infrastructure commitments, and if not, it is a one-off. Brian suggests the industry needs a "Jenga chart" of whose money is propping up whose, with the contractors who actually pour concrete at the base. On the wave of agent launches (Meta's Muse, OpenAI's dots, and OpenClaw Enterprise), they agree that giving everyone a cloud-hosted computer for their agent is a real step toward mainstream adoption. Brian says the unanswered questions are accountability when an agent errs, security controls that don't require dozens of settings, and how people decide what is important enough to keep for themselves. Brandon argues agents should step in at the moment of a task, like filling out a form, rather than needing constant delegation. They also note the move toward soft, cuddly agent branding and the lack of easy ways to share skills across people and teams. The show closes with Meta's hiring of MongoDB's CEO to lead its enterprise push, which Brandon expects to fail because consumer companies start at a deficit in enterprise.



SHOW SPONSORS:



SHOW: 1068

SHOW TRANSCRIPT: The Enterprise AI Show #1068 Transcript

SHOW VIDEO: https://youtu.be/kaNik7LxV3s

SHOW LINKS:




FEEDBACK?



from The Cloudcast (.NET) https://ift.tt/qkEDuUj
via IFTTT

Saturday, October 3, 2026

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries.

The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations.

"In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university," the Broadcom-owned cybersecurity unit said. "Victims were in Portuguese- and Spanish-speaking countries, spanning Europe, Africa, and Latin America."

Warlock, also tracked as Gold Salem, Longlegs, and Storm-2603, gained prominence in mid-2025 in connection with the zero-day exploitation of the "ToolShell" SharePoint flaws to deploy ransomware on targeted systems.

Earlier this year, the group was linked to the compromise of SmarterTools by exploiting an unpatched SmarterMail instance. It has also relied on legitimate tools like Velociraptor for command-and-control (C2) and the bring your own vulnerable driver (BYOVD) technique to disarm security software running on a compromised host.

According to Symantec, Warlock shares overlaps with older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang.

"In one intrusion against a critical infrastructure operator, the attackers pushed a tool designed to disable security software to at least 40 hosts within about two hours, then deployed Warlock on at least 33 hosts by staging it in the domain's SYSVOL share, where ordinary domain replication delivered it to machines," the researchers said.

Attacks mounted by Warlock have leveraged multiple vulnerabilities in on-premises Microsoft SharePoint Server deployments. Upon successfully finding a way in, the threat actors have been found to drop web shells that can target multiple versions of SharePoint.

The end goal of the web shell is to collect the SharePoint farm's ASP.NET machine keys, which are then abused to forge a validly signed payload and achieve remote code execution inside the SharePoint application pool.

Some of the other observed tactics are listed below -

  • Using DLL sideloading to load malicious code into memory.
  • Downloading follow-on payloads from legitimate cloud file-sharing and storage services such as catbox[.]moe and wasabisys[.]com to fly under the radar.
  • Abusing a legitimate-but-vulnerable driver K7RKScan.sys (CVE-2025-1055) as part of a BYOVD attack to disable security software. The same driver was previously exploited by DragonForce ransomware actors.
  • Using living-off-the-land (LotL) tooling to perform reconnaissance and run commands on the compromised hosts. This includes the abuse of Microsoft Visual Studio Code's built-in tunnel feature to facilitate remote connections to infected systems.
  • Staging payloads inside the compromised domain's SYSVOL share to deploy ransomware at scale.

As recently as July 22, 2026, the threat actors are said to have exploited SharePoint Server flaws to drop a web shell, conduct discovery, obtain arbitrary code execution inside the SharePoint application pool, deploy additional payloads, burrow deeper into the network, establish VS Code tunnels, terminate security software, and ultimately deploy the ransomware binary.

"Longlegs' continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related-SharePoint vulnerabilities remains a viable initial access route for attackers SharePoint deployments that have not been patched or otherwise mitigated," Symantec and Carbon Black said.

"The apparent recent focus on Portuguese- and Spanish-speaking countries suggests either an opportunistic targeting pattern driven by exposed, vulnerable SharePoint servers, or a more deliberate tasking."



from The Hacker News https://ift.tt/JfnSLMd
via IFTTT

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

Featuring:

Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale.

This report examines how core areas of cybersecurity are evolving in response to that shift. Across identity security, telemetry management, human security, endpoint management, human risk intelligence, exposure management, email and domain security, connected device security, AI-native security operations, and cloud security, it explores how organizations are adapting to threats that increasingly move across systems, identities, and infrastructure rather than targeting a single point of failure.

Read the full report here: https://report.papryon.com/thehackernews

Identity Security — Keeper Security

Identity has become one of the most important security boundaries in modern organizations. As cloud infrastructure, remote work, automation, and AI agents expand the number of identities requiring access, organizations are moving toward continuous governance, least privilege, and stronger control over both human and non-human identities.

“Managing multiple disconnected tools is itself a security liability.”

— Darren Guccione, CEO & Co-Founder, Keeper Security

Website: keepersecurity.com

LinkedIn: https://ift.tt/PkXp9tT

Telemetry & Data Management — Cribl

Security teams are generating more telemetry than ever, but simply collecting more data does not necessarily create better visibility. Organizations are increasingly focused on controlling how telemetry is routed, structured, retained, and reused across security tools, while AI is creating new requirements for the quality and monitoring of security data.

“The winning security programs in 2026 and beyond aren't the ones ingesting the most data. They're the ones who can route, reshape, and reuse it on demand.”

— Nicole Beckwith, Senior Director, Security Engineering & Operations, Cribl

Website: cribl.io

LinkedIn: https://ift.tt/sXqAg8N

Endpoint Management — Automox

As organizations manage increasingly distributed endpoint environments, security teams need to reduce the time between identifying a weakness and applying an effective control. Continuous patching, configuration management, automated remediation, and visibility across Windows, macOS, and Linux are becoming central to endpoint security.

“Patch what's patchable, mitigate what isn't, and govern the endpoint continuously.”

— Justin Talerico, CEO, Automox

Website: automox.com

LinkedIn: https://ift.tt/127G4ml

Human Risk Intelligence — Nisos

Security teams are increasingly looking beyond traditional technical controls to understand the people behind emerging threats. Human risk intelligence combines investigative expertise, digital attribution, and external intelligence to identify risks involving employees, executives, candidates, and third parties.

“Identity Integrity is the new firewall.”

— Ryan LaSalle, CEO, Nisos

Website: nisos.com

LinkedIn: https://ift.tt/uMNq8xc

Exposure Management — Surf AI

Exposure management is shifting from discovering vulnerabilities toward continuously reducing the exposures that matter. As environments become more complex, organizations need to understand how individual weaknesses connect, who owns them, and what actions can safely reduce risk.

“Discovery is commoditized. The middle is hard.”

— Yair Grindlinger, Co-Founder & CEO, Surf AI

Website: surf.ai

LinkedIn: https://ift.tt/6AwJzxp

Human Security — Adaptive Security

AI-powered social engineering is making phishing, voice cloning, deepfakes, and impersonation attacks easier to create and scale. Human security is therefore moving beyond annual awareness training toward continuous, personalized simulations and risk-based intervention across email, voice, SMS, and video.

“Traditional awareness programs weren’t built for today’s threats. Human security must be continuous, personalized, and responsive to real-world risk.”

— Andrew Jones, Co-Founder & CPO, Adaptive Security

Website: adaptivesecurity.com

LinkedIn: https://ift.tt/MPBDTVh

Email & Domain Security — Red Sift

Digital impersonation is increasingly an infrastructure problem rather than an email problem alone. Attackers can combine fraudulent domains, DNS abuse, websites, and email campaigns to impersonate organizations, making visibility across the wider internet-facing environment increasingly important.

“Every part of the chain — email, domain, DNS, certificate — is a trust decision made in public infrastructure.”

— Rahul Powar, Co-Founder & CEO, Red Sift

Website: redsift.com

LinkedIn: https://ift.tt/LcKDFlx

Connected Device Security — Asimily

As connected environments expand, organizations are managing an increasingly complex mix of devices across their infrastructure. Security teams need to understand which devices are exposed, how vulnerabilities could be exploited, and which controls can reduce risk without disrupting operations. For connected environments, this makes continuous visibility, remediation, and enforcement essential.

“Knowing a device is at risk has to end in an enforced control, and it has to hold as the fleet doubles.”

— Shankar Somasundaram, CEO, Asimily

Website: asimily.com

LinkedIn: https://ift.tt/g31Nb96

AI-Native Security Operations — SentinelOne

Security operations are facing a growing gap between the speed of modern attacks and the capacity of human teams to investigate them. AI is increasingly being applied within the SOC to automate investigation, connect evidence, and reduce the manual workload required to understand incidents.

“AI accelerates, supports and suggests, but does not replace human judgment.”

— Paolo Cecchi, Area VP Sales, Mediterranean Region, SentinelOne

Website: sentinelone.com

LinkedIn: https://ift.tt/3TkKVcB

Cloud Security — CrowdStrike

Cloud environments are becoming a central target for identity-driven attacks as adversaries exploit credentials, configurations, and cloud controls to move through organizations. Security teams are therefore moving toward unified, real-time protection across identity, endpoint, and cloud environments.

“Traditional CDR capabilities that rely on static risk models and log batch processing... are simply too slow for today's threat landscape.”

— Kartik Shahani, Vice President of India & SAARC, CrowdStrike

Website: crowdstrike.com

LinkedIn: https://ift.tt/noy4xE1

Download The Full Report Here: https://report.papryon.com/thehackernews

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.



from The Hacker News https://ift.tt/B4VkaNg
via IFTTT

Friday, October 2, 2026

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems.

The vulnerabilities are listed below -

  • CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an unauthenticated remote attacker could exploit to obtain unauthorized access to storage backend administrator credentials for all registered storage arrays.
  • CVE-2026-63692 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the authorization proxy and tenant service that an unauthenticated network attacker could exploit to bypass authentication controls and gain administrative-level privileges.
  • CVE-2026-67269 (CVSS score: 9.9) - An improper privilege management vulnerability in the ContainerStorageModule Custom Resource reconciler that a low-privilege remote attacker could exploit to escalate privileges and gain root-level access on cluster nodes.
  • CVE-2026-54472 (CVSS score: 9.8) - A use of hard-coded credentials vulnerability in the CSM Authorization module that a remote unauthenticated attacker could exploit to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM Authorization proxy.
  • CVE-2026-61421 (CVSS score: 9.8) - A use of hard-coded cryptographic key vulnerability in the JWT authentication component of karavi-authorization that a remote unauthenticated attacker with knowledge of this publicly available signing secret could exploit to forge authentication tokens and gain administrative privileges.
  • CVE-2026-67273 (CVSS score: 9.6) - An improper neutralization of special elements used in a template engine vulnerability that a low-privilege attacker with remote access could exploit to escalate privileges, access sensitive information, and carry out unauthorized RBAC tampering.

"This vulnerability is considered critical as it enables a complete bypass of the csm-authorization security model, allowing an attacker to gain full administrative control over the storage infrastructure spanning all five supported Dell storage product families," Dell said about CVE-2026-63688.

As for CVE-2026-63692, Dell noted that successful exploitation could enable an unauthenticated attacker to gain complete administrative control over the authorization service, and allow them to access or manipulate storage resources across all tenants.

The PC maker also noted that an attacker can exploit CVE-2026-67269 to compromise all nodes in a Kubernetes cluster through a single custom resource submission. CVE-2026-54472, on the other hand, can be weaponized to sidestep authentication controls for the CSM Authorization proxy and enable unauthorized management of storage access policies across all connected tenants. Dell is recommending that customers apply the updates and rotate any JWT signing secrets.

"Successful exploitation grants the attacker cluster-wide read access to Kubernetes Secrets and the ability to create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls," Dell said in its advisory for CVE-2026-67273.

The flaws, which affect all versions of CSM prior to 1.17.0, have been addressed in 1.18.0. There are no workarounds or mitigations other than updating to the latest version. With vulnerabilities in Dell products (CVE-2021-21551 and CVE-2026-22769) having come under active exploitation in recent years, it's essential to apply the necessary fixes for optimal protection.



from The Hacker News https://ift.tt/d2tTinZ
via IFTTT

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported.

"We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work."

The impacted employees are Jasmine Wang, Tomek Korbak, and Mikita Balesni, the Journal reported, citing people familiar with the matter. The three researchers have all previously expressed concerns about the pace of artificial intelligence (AI) development.

It's said that the individuals shared confidential information with a third-party AI-safety organization. The name of the organization was not disclosed. According to Bloomberg, the mishandled information pertained to OpenAI's infrastructure architecture.

The departures follow a report from The New York Times that OpenAI had brushed aside employees' warnings about its safety practices when testing AI models, describing a pattern of the company deprioritizing security protocols in favor of releasing them on time.

The development also comes as frontier AI labs like OpenAI and Anthropic have faced a steadily growing number of incidents in which their AI agents broke out of sandboxes, breached real-world systems, and probed various government websites for information. These incidents have led to concerns about the growing capabilities of its most powerful models and the risks they pose.

Earlier this week, OpenAI made the decision to scrap the planned launch of an AI model, GPT-6.1 Astra, over safety concerns. It has also paused training of most powerful models after one of its agents contacted an external chatbot by exploiting a loophole in its internet-access restrictions.

In a new report published Thursday, AI research firm Transluce said it identified more instances where rogue AI agents "used aggressive techniques to access publicly available data" from U.S. and Canadian government websites using techniques like SQL injection. There is no evidence the agents gained access to non-public information.

"This includes two rudimentary and failed hacking attempts, one against the U.S. Department of Education's Civil Rights Data Collection, and one against Library and Archives Canada, a Canadian federal agency," Transluce said. The incidents took place in May and June 2026.

The AI agents have also been observed leveraging "aggressive tactics short of hacking" to target and probe U.S. government websites, such as the White House, the Departments of War, Justice, and Commerce, the CDC and SEC, and state agencies in California, Maryland, Illinois, Texas, and New York.

Although the incidents have not been attributed to any specific AI company, Transluce told Reuters the attempts exhibited tactics "consistent with prior observed ​agent activity that we have attributed to OpenAI in a similar timeframe."

OpenAI said it's "aware of reports of OpenAI models attempting to ‌access publicly ⁠available information from Canadian government websites." The Canadian Centre for Cyber Security acknowledged suspected AI agent activity targeting Government of Canada websites, adding there is no indication of any compromise of its systems.

Asymmetric Security, in another report, said it found additional instances where OpenAI agents scraped data from more than 50 private and public sector organizations' websites between March 6 and September 20, 2026. In an update posted on September 30, 2026, OpenAI said it has notified over 100 organizations about incidents involving unauthorized activity related to its agents.

"In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied," OpenAI said, acknowledging it expects to uncover more such cases as it continues to review historical activity.

"Since the Hugging Face incident, we’ve strengthened security controls⁠, restricted internet access, separated research environments more clearly, expanded monitoring, and added more training to avoid harmful or unauthorized actions."

The U.S. Federal Trade Commission (FTC) has since launched an investigation into OpenAI, Anthropic and other AI companies over the risks their technology could pose to consumers.



from The Hacker News https://ift.tt/wrVm1k0
via IFTTT

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides.

Then a board member asks three questions:

  • How secure is the organization, overall?
  • What is the actual financial exposure?
  • Is the security posture better than it was last quarter?

Most security leaders cannot answer any of them with confidence. Not because the data doesn't exist, but because it lives in a dozen tools that don't share context. A new guide to confident board reporting for CISOs takes on exactly this problem. This article walks through why traditional reporting fails and what a better model looks like.

Boards Have Stopped Trusting Activity Metrics

For years, security reporting has run on counts. Vulnerabilities found. Patches applied. Alerts closed. Phishing simulations passed. These numbers measure effort. They don't measure risk.

A board member hearing that the team closed thousands of findings last quarter has no way to judge whether the company is safer. The obvious follow-up, "safer from what, and by how much?", rarely has an answer. [STAT NEEDED: share of board members who report low confidence in the security metrics they receive]

Boards want three things:

  • Exposure, not activity. Which business-critical assets could an attacker actually reach today?
  • Trend, not snapshot. Is that exposure shrinking quarter over quarter?
  • Money, not CVEs. What is the financial impact if those paths are used?

The typical mid-size or growth enterprise runs an identity provider, a CSPM or CNAPP, endpoint detection, a SIEM, a vulnerability scanner and a long tail of SaaS applications. Each tool is accurate about its own slice. None of them sees how the slices connect. Attackers don't care about those boundaries.

Consider a realistic path:

  • A contractor account in the identity provider still holds a group membership from a finished project. The identity tool rates it low risk.
  • That group grants access to a SaaS app with an OAuth integration into the cloud environment. The SaaS security tool sees a normal integration.
  • The integration runs under a service account with broad storage permissions. The cloud posture tool flags it as medium.
  • That storage holds customer records. The data classification tool knows it's sensitive, but not who can reach it.

Four findings. Four tools. Four moderate scores. Together they form a critical path from a phishable account to the company's most sensitive data. No single dashboard shows it, so it doesn't make the board report. It gets found during an incident instead.

AI adoption widens this gap. AI agents, non-human identities, service accounts and MCP-connected tools are being added faster than anyone inventories them. Each one is a new identity with its own access, and most stacks were never designed to map where that access leads. Shadow AI becomes another set of unseen paths.

The reflex is to buy something that covers the gap. That usually produces one more console, one more export and one more column in the reconciliation spreadsheet.

The common pushback is fair: "We already have CSPM. We already have a Zero Trust architecture." Those investments matter. But they are controls, each scoped to a domain. The question the board is asking crosses domains. What's missing isn't another control. It's shared context between the controls already deployed.

This is the idea behind Cybersecurity Mesh Architecture (CSMA), a model Gartner describes for connecting distributed security tools through a common intelligence layer. Instead of replacing tools, CSMA correlates their data so identities, access, assets and exposures can be read as one graph. The CISO board reporting guide breaks down how this approach maps directly to the questions boards ask.

A Practical Framework for Board-Ready Reporting

Security leaders rebuilding their board report around exposure can follow a sequence like this:

1. Define the crown jewels with the business

Start with the assets whose compromise would hurt the business most: customer data stores, payment systems, PHI, source code, production infrastructure. Agree on them with business owners, not just the security team. This list anchors everything that follows.

2. Connect what is already deployed

Pull identity, cloud, endpoint, SaaS and vulnerability data into one correlated view. The goal is deduplication and enrichment, not new sensors. Agentless, API-based integration keeps deployment fast and avoids disrupting production.

3. Map real attack paths to those assets

Replace finding lists with paths. For each crown jewel, show which identities, human and non-human, can reach it, and through what chain of access and misconfiguration.

4. Prioritize by blast radius

A medium-severity misconfiguration on a path to customer data outranks a critical CVE on an isolated test server. Rank remediation by what it cuts off, not by its standalone score.

5. Translate exposure into financial terms

Tie each reachable crown jewel to a business impact estimate built with finance and risk teams. The report moves from "number of vulnerabilities" to "dollars at risk," which is the language boards already use for every other risk category.

6. Report the trend

Show how many attack paths to critical assets existed last quarter, how many exist now, and which remediation work closed them. This also answers the ROI question directly: it shows what the existing security stack is actually protecting.

What Changes in the Boardroom

When the report is built on attack paths instead of activity counts, the three hard questions get concrete answers:

  • How secure are we? Here are the remaining paths to our most critical assets.
  • What is our financial exposure? Here is the estimated impact if those paths are used.
  • Are we improving? Here is how many paths were eliminated since last quarter, and what closed them.

That shifts the CISO's role in the meeting from defending spend to reporting measurable risk reduction. It also gives the security team a prioritized work queue that matches what leadership cares about.

Getting Started

Mesh is the unified intelligence layer for enterprise security teams operating across fragmented security stacks with no shared context. Connecting agentlessly to your existing tools, Mesh correlates signals across identity, cloud, SaaS, endpoint, and AI environments to reveal viable attack paths to your most critical assets. By providing enterprise-wide context that no individual tool can deliver alone, Mesh helps security teams prioritize what matters most and eliminate risk faster through guided workflows. Security leaders preparing for their next board cycle can download the CISO's Guide to Confident Board Reporting.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.



from The Hacker News https://ift.tt/kbYl2Lo
via IFTTT

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled.

With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a security setting that turns on all Android's security features to secure the device against potential threats.

"In Android 17, enabling Advanced Protection automatically restricts AccessibilityService access exclusively to verified applications categorized as Accessibility Tools, closing off a major avenue of attack while preserving vital assistive technology," Google said Thursday.

The Android AccessibilityService API is a powerful framework that allows an application to run in the background, intercept user interface events, and interact with other applications on the user's behalf.

Although its primary purpose is to assist users with disabilities, such as through screen readers or voice control systems, its privileged access has been abused by banking trojans and spyware to extract sensitive data and perform malicious actions without needing root access.

Put differently, once a user is tricked into enabling the service under a social engineering pretext, the malware can turn genuine assistive features into potent cyber weapons to programmatically initiate fraudulent fund transfers from installed financial apps, log keystrokes, draw fake login screens over legitimate apps, and grant itself additional sensitive permissions.

"Because accessibility services are designed to interact directly with the screen, malicious actors can exploit them to read sensitive data, install malware, or block uninstallation," Google said.

In recent years, Google has taken a number of steps to counter this abuse -

Alongside Accessibility protection, Android 17 also brings a number of other security improvements -

  • Intrusion Logging, which enables persistent, privacy-preserving forensics logging to investigate sophisticated spyware attacks
  • USB Protection, which prevents attackers from gaining unauthorized access to your device through a physical USB connection
  • Disable WebGPU, which reduces exposure to sophisticated browser-based exploits
  • Failed Authentication Lock, which protects against physical tampering and brute-force attempts by completely locking down the device to prevent further probing
  • View Supporting Apps, which allows users to view which installed apps have checked the Advanced Protection status

"Developers can be notified when Advanced Protection is enabled so that they can auto-enable any features they have for this user population," Google said. "If you already use Advanced Protection, you will see a notification once these new capabilities arrive on your device. To take advantage of the new forensic capabilities, navigate to your Advanced Protection settings page and manually enable Intrusion Logging."



from The Hacker News https://ift.tt/dV4aRrI
via IFTTT