Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound to a contract you agreed to while drunk. What they discovered will make you look at your TV rather differently... Meanwhile, awful Android malware with the audacious name "Awesome" (in Indonesian) is doing the rounds, stealing your data, demanding a ransom, and then giving you a "jump scare"... Plus, in our featured interview, Andy Hornegold of Intruder explains why the mid-market is where cybercriminals are having the most fun right now - and how AI is helping attackers get from "first foot in the door" to "full ransomware disaster" in less than a working day. All this and more in episode 485 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lianne Potter.
Identity at machine speed: Okta pushes governance beyond human users
Okta is adding new features to its identity platform to better govern AI agents.
AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
Ars Technica GeneralNonprofit that tracks meteors taken down by "critical blow" from a cyberattack
Group plans to be largely out of commission for several weeks.
CyberScoop GeneralCISA promotes a fresh way to deter cyberattackers: Lie to them
It’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries. The post CISA promotes a fresh way to deter cyberattackers: Lie to them appeared first on CyberScoop.
SC Media VulnConnectWise ScreenConnect bug exploited in the wild, CISA says
Experts warn teams to patch right away to prevent a potential ransomware incident.
CSO Online PolicyLinkedIn fights for the right to tell customers when the feds want their data
Microsoft’s top lawyer argued Tuesday that legislators “must make secrecy [orders] the exception” in government subpoenas demanding information about LinkedIn users. LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US government, which sometimes come with secrecy orders that prevent LinkedIn from alerting customers whose information is being requested. The company is asking federal courts “to enforce meaningful limits on both the scope of government demands and the secrecy that can accompany them,” wrote Jon Palmer, Microsoft’s chief legal officer, in a Tuesday blog post. “We recognize law enforcement’s important role in protecting public safety and investigating crime, and sometimes that does need to be done covertly. At the same time, customers and users deserve meaningful limits and independent oversight through an adversarial process.” He pointed out: “People and organizations increasingly entrust their most sensitive information to online services. If providers cannot challenge demands they know are overbroad—or if courts may silence them without a rigorous, adversarial review—the safeguards the law requires will be weakened precisely when they are most needed.” A tricky issue The issue is a tricky one. Law enforcement often use this type of subpoena as an investigative tool, seeking those who are engaged in illegal activities. The theoretical justification for secrecy is to avoid alerting the investigative target to make it less likely the suspect will try to destroy evidence or flee the jurisdiction. Government lawyers are supposed to only make secrecy requests when absolutely essential. Microsoft is suggesting that courts and congress need to step in to curtail blanket government efforts. “The Fourth Amendment protects the right to be free from unreasonable searches and seizures. That right applies to papers kept in a desk and it also applies when personal and business records are stored online,” Palmer wrote. “Online service providers, like LinkedIn and Microsoft, also have a First Amendment right to speak to their customers when the government obtains an order to search their private information. Secrecy may sometimes be justified, but it should be tailored to demonstrated needs and subject to meaningful review.” He added: “The government must seek only relevant information, justify secrecy with specific evidence and infringe on speech to the least extent possible.” In his post, he pointed to a recent legislative effort in the US House of Representatives that might mitigate the issue if it ends up becoming law. “On August 31, the House passed legislation to rein in secret surveillance and strengthen notice protections when the government seeks data held by technology providers,” he wrote. “The reforms would place clearer limits on secrecy orders, require greater accountability, and help ensure that secrecy is the exception – not the rule. The Senate should act promptly to send these historic reforms to the President.” LinkedIn privacy battles LinkedIn itself is currently fighting litigation that accuses it of directly violating the privacy rights of its customers, and a federal judge this month dismissed another similar case, but gave plaintiffs permission to refile, with a caveat. “Given LinkedIn’s further arguments that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation, much less prevail at the end of the day,” US District Court Judge Vince Chhabria wrote. “But in an abundance of caution, dismissal is with leave to amend.” But, he added, if the amended complaint isn’t filed within 14 days, “dismissal will be with prejudice.” Privacy now a ‘data stewardship obligation’ Jeff Valdes, a director at Acceligence, noted, “there is definitely some irony here.” “If Microsoft wants customers to view it as a steward of their privacy when the government comes asking for their information, customers are naturally going to apply that same standard to how Microsoft and LinkedIn collect, use, protect, and disclose information themselves,” he said. “Privacy is difficult to compartmentalize. You cannot have one philosophy of customer privacy for government access, another for product design, and another for your own commercial data practices without eventually creating a credibility problem.” Mike Wilkes, enterprise CISO at Aikido Security, agreed, pointing out, “without meaningful limits, judicial scrutiny, and an expiration mechanism, a temporary investigative necessity starts looking a lot like a permanent architecture for invisible surveillance. The individual may never have an opportunity to challenge the scope of the request, because they may never even know the request existed until prosecutors show up with an indictment.” That, he said, “is why Microsoft’s argument matters, despite the obvious irony of LinkedIn simultaneously defending itself against privacy claims from its own users.” But Ryan O’Leary, an IDC research director, offered a different perspective. “Microsoft makes no bones about using the data contained within its own systems for its own purposes. Both things can be true: Microsoft can fight for the privacy of its platform while still not necessarily respecting the privacy rights of its end users,” O’Leary noted. “This seems to come down to protecting its own proprietary data sets, not some altruistic privacy crusade.” At the same time, Valdes pointed out, Palmer’s post highlights how deeply privacy has become a top-tier enterprise IT priority. “Privacy is rapidly becoming a much broader data stewardship obligation,” he said. “Companies holding sensitive information increasingly have to think simultaneously about government requests, third-party access, their own collection practices, AI use, data retention and what they tell customers about all of it. If you want to be trusted as the custodian of the world’s data, customers are going to judge how you protect that data in every direction.” However, Wilkes noted, “Microsoft does not need to be a perfect privacy saint to be right about this particular problem.”
SC Media GeneralHastily deployed agentic security is not the answer to enterprise cyber threats
Rushing agentic security into production could create new risks instead of strengthening cyber defenses.
Krebs on Security Policy
Data Broker Radaris Loses Domains in Privacy Fight
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in the case ordered that radaris.com and more than a dozen other data broker domains be transferred to the plaintiffs.
Dark Reading General
Fighting Your Dragons Through Tough Tech Times
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.
Dark Reading Breach
BragJack Attack Can Turn a Browser's Agentic AI Against It
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
CSO Online PolicyBig Tech’s AI safety rift signals disruption and disparity for enterprises
A growing divide among leading AI companies over how to secure increasingly powerful models is beginning to translate into challenges for enterprise IT, with implications for how organizations access, deploy, and govern AI systems. The latest flashpoint came after Meta CEO Mark Zuckerberg called for neutral evaluators to independently test AI models, pushing back on calls from rivals to slow development or tighten coordination. “trust and alignment are quickly becoming the most important capabilities that will differentiate agents and models. Any lab that doesn’t focus on alignment will fall behind,” Zuckerberg wrote in a post on X. “Engaging independent evaluators and advisors is industry best practice,” he added, noting that Meta already does this in several areas. His comments follow a series of public proposals from AI industry leaders including Dario Amodei, who argued for a more cautious pace of development, and Sam Altman, who called for collaboration on safety standards. The debate has intensified amid disclosures from AI labs and policymakers on potential misuse of advanced systems. Anthropic has said it restricted attempts to use its Claude models in sensitive domains, while OpenAI has engaged with policymakers on AI-related risks, according to company statements and reports. Enterprise concerns While the debate is often framed as a choice between slowing innovation and strengthening oversight, analysts said enterprises should focus less on which approach prevails and more on the operational consequences already taking shape. “Divergent safety approaches will make access to advanced AI models less predictable, rather than producing an industrywide slowdown,” said Sushovan Mukhopadhyay, director analyst at Gartner. Vendors are likely to apply different release schedules, regional availability, access tiers, and usage restrictions, he said, meaning enterprises could encounter similar capabilities “at different times and under materially different conditions.” Mukhopadhyay said enterprises should plan for variability in access rather than assuming consistent availability across providers or geographies. “I read this week as the point where frontier AI became a managed supply,” said Bhupendra Chopra, chief revenue officer at Kanerika. “For three years CIOs could assume the next model would simply show up. A frontier model now behaves more like a critical component from a supplier whose delivery dates depend partly on outside reviewers and export rules.” Chopra added that “any AI roadmap built on a specific model arriving on a specific date is carrying supply risk it hasn’t priced.” Security pressure builds regardless of slowdown Analysts said slowing development alone is unlikely to materially change enterprise risk, particularly as open-source models proliferate. “The biggest point isn’t the pause itself. It’s that the leaders of AI companies are agreeing on something,” said Nikhil Gupta, founder and CEO of ArmorCode. Gupta said the threat landscape has already shifted. “Even if companies hit pause, open-source AI models are already out there,” he said. “I’m not convinced slowing down some companies meaningfully changes what adversaries can do.” “Even if AI development slows down tomorrow, security must accelerate,” Gupta added. “The job of securing these systems has effectively gotten ten times harder.” A new ‘AI assurance’ layer emerges The focus on evaluation is driving what analysts described as an emerging “AI assurance” layer, where third parties assess models for safety and compliance. “A distinct AI assurance layer is likely to emerge, but enterprises should not expect a single certification to establish that an AI system is safe,” Mukhopadhyay said. “Enterprise risk also depends on data, system instructions, tools, agents and deployment controls.” Chopra said enterprises risk misinterpreting such evaluations. “Procurement teams may see a third-party evaluation and treat the model as vetted,” he said. “Within a year it becomes a checkbox.” Instead, he said, enterprises will need to run their own validation. “CIOs who get ahead will test each model against their own data before it touches production.” Fragmentation complicates multi-model strategies For CIOs pursuing multi-vendor strategies, differing approaches across providers could introduce additional complexity. “Fragmentation was already the default. Safety divergence deepens it,” Chopra said. He said risk is most acute during transitions. “For an enterprise running several models, the exposure sits in the handoff,” he said. “When a model is delayed or replaced, the system can behave differently.” “I’d rank untested model substitution above vendor lock-in,” Chopra said. Gupta said open architectures will be important. “The framework needs to be open, not locked to any single vendor,” he said. Mukhopadhyay added that enterprises should prepare for models becoming unavailable or restricted. CIOs urged to build resilience Analysts said enterprises will need to design AI strategies that can adapt to changes in availability, pricing, and governance. “For critical applications, CIOs should separate application controls and business logic from the underlying model,” Mukhopadhyay said. Chopra emphasized flexibility. “A routing layer between applications and model providers turns switching into configuration work,” he said, adding that contracts should cover deprecation timelines. He also pointed to pricing implications. “Scarce access to the frontier starts to carry a premium,” Chopra said. This article first appeared on Computerworld.
Bellingcat General“A Recurring Pattern”: Civilians Paying the Price in Mali’s Drone Campaign
Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published. WARNING: This report contains links to graphic images and footage. A joint Bellingcat and Jeune Afrique investigation into drone strikes carried out by the Malian military adds new details about the attacks which frequently are carried out in civilian areas and have […] The post “A Recurring Pattern”: Civilians Paying the Price in Mali’s Drone Campaign appeared first on bellingcat.
CSO Online VulnOracle’s September patches put Fusion Middleware back in the hot seat
Oracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities can be remotely exploited without authentication. Other product categories with 50 or more issues fixed in the rollout include Oracle Database Server, Oracle Communications, and Oracle Analytics. Oracle recently accelerated its patching rhythm from quarterly to monthly. It advised customers to apply the September patches immediately, warning that it continues to receive reports of successful attacks on its software where customers had not applied available fixes. Five max-severity flaws sit in Fusion Middleware The September update addresses five critical vulnerabilities carrying the maximum CVSS score of 10.0 within Fusion Middleware. They affect Oracle Access Manager (CVE-2026-71133), Oracle Forms (CVE-2026-83099), Oracle Internet Directory (CVE-2026-83059), Oracle Platform Security for Java (CVE-2026-83020), and Oracle WebLogic Server (CVE-2026-83021). All five are remotely exploitable without authentication over the network; attacking them is of low complexity and requires neither privileges nor user interaction. The update also addressed a sixth CVSS 10.0 vulnerability, this one in Oracle Hyperion Financial Management (CVE-2026-87230); it too can be remotely exploited without authentication. The update also includes 13 Fusion Middleware bugs with a CVSS score of 9.9, just below the maximum severity. These include CVE-2026-71163 and CVE-2026-73945 in Oracle Access Manager, CVE-2026-83055, CVE-2026-83057 and CVE-2026-83056 in Oracle Internet Directory, CVE-2026-83058, CVE-2026-73948 and CVE-2026-83039 in Oracle WebCenter Portal, CVE-2026-82999, CVE-2026-82997 and CVE-2026-82998 in Service Delivery Platform, and one each in Oracle WebCenter Sites (CVE-2026-83031) and Oracle WebLogic Server (CVE-2026-83038). None of these are remotely exploitable without authentication. However, they require low privileges, remain network-accessible and can have high confidentiality and integrity impacts. Oracle did not mark any of the six CVSS 10.0 and 13 CVSS 9.9 vulnerabilities as exploited in the wild. Fusion Middleware has featured heavily in Oracle’s recent patch cycles too. Its July update addressed 10 CVSS 10.0 vulnerabilities, highlighting the product family’s recurring exposure to maximum-severity flaws. Oracle’s patching message is as important as the patches Until patches can be deployed, Oracle said, customers may reduce exposure by blocking network protocols required for an attack or removing unnecessary privileges and package access. However, it cautioned, these measures can break application functionality and should be tested on non-production systems. They are not to be considered long-term solutions because they do not address the underlying vulnerabilities, the company said in its September critical patch update advisory. It also included a warning for organizations running older Oracle releases. The fixes are provided only for supported versions, the company said, adding that “Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Security Patch Update.” Also, for organizations that have skipped earlier security updates, Oracle advises reviewing previous CSPUs and quarterly Critical Patch Updates rather than assuming the September releases covers the backlog. This article first appeared on CIO.
The Hacker News Vuln
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded
CSO Online BreachAI agent authorization risks remain a gap in new NIST-CISA token security guidance
AI agents’ actions are out of scope for new guidance from US authorities on securing identity and access tokens, but there is still plenty enterprises can do to protect their systems from rogue humans and AI agents alike. “Protecting Tokens and Assertions from Forgery, Theft, and Misuse,” a new report from the National Institute of Standards and Technology (NIST) with help from the Cybersecurity and Infrastructure Security Agency (CISA), offers guidance for operators of systems that use digitally signed tokens to make access decisions, including single sign-on and API access. The guidelines, also known as NIST IR 8587, address what happens after authentication: Tokens and assertions can carry proof of authentication or authorization between systems, allowing an attacker who compromises them to exploit access that has already been granted. NIST recommends continuous monitoring, along with tighter controls throughout the token lifecycle. The issue is of particular significance for CISA. In May, a public GitHub repository believed to have been maintained by a CISA contractor was found to contain sensitive government credentials, including AWS tokens and GitHub access tokens. CISA said at the time there was no indication that sensitive data had been compromised. The unresolved question of agent authority NIST recommends applying the same guidelines for securing signed tokens used by AI agents as for securing those used by humans, but notes that the access risks posed by AI and AI agents “create additional IAM challenges that require further guidelines and, in some cases, new or expanded standards and protocols.” NIST and CISA are still working on those, but there are things that IT teams can do meanwhile to secure agentic systems. Managing the lifecycle of an agent’s identity is part of the challenge, said Yih Khai Wong, senior research manager for security services at IDC Asia/Pacific. Enterprises need visibility into who provisioned an agent’s credentials and what those credentials allow, Wong said. Access should also be withdrawn when the agent’s task ends. “Token hardening assumes the token holder is a known, bounded actor,” Wong said. “An agentic system breaks that assumption.” Delegation can make that boundary harder to establish, said Amit Kumar Jena, head of AI development at Kanerika. An agent may act on behalf of a user, invoke a tool and then reach another service, making it increasingly difficult to determine whose authority is being exercised as the chain grows. Jena said prompt injection could also steer an agent holding a valid token toward an action the user never requested. Token verification would not necessarily detect that misuse because the token itself could still be legitimate. Jain argued that CISOs should treat AI agents as low-trust non-human identities, granting only the access required for a task. Higher-risk actions should require human approval, he added. Wong also recommended maintaining an agent inventory and keeping those identities separate from human accounts. Credentials should expire when the task is complete, he said. Why valid tokens can still be dangerous A common weakness is assuming that because a token is valid, the activity associated with it is legitimate, according to Jonathan Ong, senior analyst for managed security services at Omdia. Organizations should consider the context in which a token is presented, including whether a user is accessing sensitive systems from an unusual location or at an unexpected time, Ong said. Detection should also correlate activity across security domains to identify behavior that may appear benign in isolation. Containment presents another challenge once a token has been compromised. “Token revocation may not always be possible due to architectural limitations,” Ong said. Other controls can limit the usefulness of a compromised token. Neil Shah, vice president for research and partner at Counterpoint Research, said that NIST’s recommendations can reduce both the duration and reach of a token compromise. Audience restrictions can limit where a stolen token is accepted, while cryptographically binding a token to the client holding the corresponding private key makes replay by an attacker more difficult. The report also points organizations toward shared-signal mechanisms such as the Continuous Access Evaluation Profile (CAEP) and Risk Incident Sharing and Coordination (RISC), which can help connected systems respond when token-related security conditions change, Shah said. Token security extends beyond IAM The CISA credential exposure also highlights how token security can break down outside traditional IAM controls, Jain said. Credentials can surface in source code, CI/CD pipelines, logs and contractor environments even when access policies themselves are sound. “If a contractor can copy a cloud credential to their local machine, the identity governance has already failed,” Shah said. Managing that risk through policy alone can be difficult in DevOps environments, where credentials can be copied onto developer machines or exposed through automated pipelines, Shah said. He argued that enterprises should eliminate static tokens wherever possible and replace them with short-lived credentials. The CISA incident also exposes a boundary in the NIST guidance, Jena said. IR 8587 focuses on asymmetrically signed tokens and explicitly places mechanisms such as API keys outside the scope of its controls. NIST nevertheless requires covered tokens to be kept out of logs, CI/CD pipelines, and build artifacts.
The Hacker News Malware
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
InfoSecurity Magazine VulnPHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
CyberScoop BreachCoast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.” The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.
The Hacker News General
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge,
SC Media GeneralPreparing for AI-enabled incidents: Helping business leaders understand enterprise risk
Here's a primer on proactive incident response in the age of AI.
CyberScoop GeneralTreasury’s Scott Bessent says no liability exemptions for AI labs
The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.” The post Treasury’s Scott Bessent says no liability exemptions for AI labs appeared first on CyberScoop.
InfoSecurity Magazine GeneralCISA and NIST Issue Guidance to Protect Cloud Identity Tokens
CISA and NIST issued final guidance to help protect cloud identity tokens and assertions
The Hacker News Malware
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the
The Hacker News Vuln
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine as a normal user, so it does not work over the network. JFrog says the fix is in Parallels Desktop 27, a version that Intel Macs cannot install. Yuval Moravchick, who leads
The Hacker News Breach
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud
The Hacker News Vuln
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database
The Hacker News Breach
Threat Intelligence Alone Won't Close the Exploitation Gap
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.
The Hacker News Vuln
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux
InfoSecurity Magazine GeneralCyber-Attacks Cost Organizations $52,000 on Average
Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000
SC Media BreachHBO Max Reddit account compromised, used in ‘PasteSwitch’ ClickFix attacks
Malicious Reddit advertisements led to macOS and Windows infostealer downloads.
Wired Security GeneralHackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
A hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images of 50,000 vehicles in 21 days.
InfoSecurity Magazine VulnZero-Day Flaw in TP-Link Cameras Enables Eavesdropping
OPSWAT researchers find two zero-days in TP-Link cameras
InfoSecurity Magazine GeneralMajor Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
CSO Online BreachYou don’t have to join the hack-back program to inherit its risk
The obvious question about Washington’s new private offensive cyber program is which security vendors will join it. The CSO question is what happens to you when one of your vendors does. The August 12 National Security Presidential Memorandum, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” directs the National Coordination Center to build a program for vetted “Participating Companies.” The Justice Department and the Department of Homeland Security run it jointly, and two co-executive directors must approve every operation in writing. Once the directors sign, a participating company can run covert access intended to stay undetected (Cyber Surveillance Operations) or manipulation, disruption, degradation, or destruction of systems (Cyber Effects Operations). The memorandum directs the operating procedures to authorize the Department of Justice (DOJ) and the Department of Homeland Security (DHS) to require a forfeitable bond of at least $1 million as a contract condition. Those procedures, which govern day-to-day execution, remain unpublished. They are due in mid-October, 60 days after signing. The White House fact sheet frames the program as consumer protection, citing more than $20.8 billion in American losses to cyber-enabled crime in 2025. The frame that matters to a CSO is different. The memorandum moves sovereign activity onto commercial infrastructure while leaving substantial residual liability in private hands. It behaves like a risk-transfer contract, except that most of the parties bearing the risk never signed it. The shield is thinner than the authorization The program’s criminal protection rests on one untested reading of one statutory clause. The Computer Fraud and Abuse Act (CFFA) exempts “lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency” at 18 U.S.C. 1030(f), and the memorandum styles every operation as federal law enforcement activity to fit inside that exemption. Congress wrote that exemption for law enforcement agencies. No court has ruled on whether it stretches to a private company operating under contract. A statute can create that protection outright. The Active Cyber Defense Certainty Act would have given companies an affirmative defense against CFAA charges for hacking back, but Congress never passed it. A presidential memorandum cannot amend a statute. In Little v. Barreme, the Supreme Court held that a presidential order did not protect an officer from damages when the seizure exceeded congressional authority. What the memorandum withholds runs longer than what it grants. Crowell & Moring’s client alert counts the gaps: no civil safe harbor, so CFAA civil suits by collateral victims remain live; no preemption of state anti-hacking law; no protection under foreign law; no indemnification. Section 5(c) then closes the other direction, creating no right or benefit enforceable against the United States. A participating firm holds an unadjudicated criminal theory, while civil, state, foreign, and contractual exposure sits outside the shield. The same government-control language that supports the domestic CFAA theory also strengthens the case for attributing the operations to the United States internationally. Under Article 8 of the International Law Commission’s state-responsibility articles, private conduct is attributed to a state when that conduct follows the state’s instructions or runs under its direction and control. Both propositions hold at once, and that is the problem for a company more than for a government. The stronger the control record supporting the vendor’s CFAA defense, the more readily a foreign ministry can treat that vendor’s work as an official act of the United States. Non-participation is not an exemption Most security organizations will file this under someone else’s problem. The exposure reaches them four ways. Substrate. Criminal groups rent and compromise the same clouds, content delivery networks, and SaaS platforms your workloads sit on. An approved effects operation against that infrastructure can surface in your environment as an unexplained outage. The memorandum anticipates the event: its implementing guidance orders a participating company to cease, minimize, and notify when an operation unintentionally reaches a system in the United States or under American control. Governments do not write cleanup procedures for events they consider remote. Section 5(c) then gives the affected company no remedy under the memorandum itself, which routes any claim into ordinary law and ordinary cost. Silence. Participating companies must disclose their commercial agreements to the NCC, not to their customers. The memorandum creates no customer-disclosure obligation, so the burden falls on the buyer to extract a written representation and on the vendor to decide whether to give one. The Cloud Security Alliance draws the conclusion plainly: absent a standard attestation, vendor nationality itself becomes a rational procurement screen for foreign buyers. Coverage. Lloyd’s market bulletin Y5381 requires its syndicates to carry state-backed cyberattack exclusions in standalone cyber policies, and the standard clauses key attribution to government determinations. A retaliation event or a collateral loss from a government-directed operation puts the claim directly into state-backed exclusion analysis. Pipelines. The memorandum invites participating companies to buy threat information from private entities and propose operations built on it. Threat intelligence you share with ISACs, government channels, or commercial platforms can feed an offensive proposal wherever the receiving party’s contractual rights permit that use. The memorandum overrides none of those contracts, so their use restrictions are the only controls you have. Review them for residual liability and customer-notification duties before your telemetry becomes targeting data. China has already run the retaliation playbook The sharpest market evidence predates the memorandum, which is exactly what makes it evidence. Reuters reported in January 2026 that Beijing had directed Chinese firms to stop using cybersecurity software from roughly 15 American and Israeli vendors. In February, Reuters reported that Palo Alto Networks softened its own attribution of a Chinese espionage campaign over concerns that its personnel in China or its clients elsewhere faced retaliation. On August 6, six days before the signing, the Cyberspace Administration of China opened a formal cybersecurity review of Palo Alto’s products, the mechanism whose best-known precedent ended with Micron barred from Chinese critical-infrastructure procurement. The program caused none of that; the sequence began seven months before it existed. The point runs the other way. Beijing operates a demonstrated regulatory and procurement playbook for converting cyber-policy friction into named-company commercial pressure, and the memorandum enlarges the set of American firms within its reach. Chinese state media is already collapsing the distinction Washington spent two decades drawing between contractor hacking and lawful practice, framing the program as America bringing previously covert operations into the open. For multinationals, the exposure also runs inward. China’s Data Security Law bars providing data stored in China to foreign law enforcement without approval and compels cooperation with Chinese security authorities. Chinese law can bar a vendor’s China-based staff from supporting the American program their employer joined, and expose those employees personally for perceived cooperation. Employee travel protocol now belongs in the risk register. What the unpublished rules have to solve The memorandum never mentions artificial intelligence, and one silence carries operational weight. The text directs the NCC to use automation to streamline the program. Crowell & Moring names the failure mode. Agentic tooling compresses the interval between an approved action and an unintended effect. An autonomous operation can exceed its parameters at machine speed, exposing the vendor to bond forfeiture and civil claims before a human intervenes. Whether the October rules require human supervision at execution will materially affect that exposure. It then travels the same four ways to the vendor’s customers. The definition of a Cyber Effects Operation also reaches industrial control systems and embedded controllers, which raises the same collateral question for connected physical systems. The program’s constraints are real. Dual written approval, the Critical Outcome prohibitions, and the minimization rules impose substantially tighter controls than an unrestricted hack-back regime. And nobody can yet say whether the program will shrink cybercrime losses or grow them; the operation-level data that settles the question is precisely what the memorandum keeps classified. However, both points stand, and neither changes the allocation. Whatever the program achieves against criminal networks, the residual legal, insurance, and market risk sits with private companies, and much of it sits with companies that never joined. Five questions belong on the board’s agenda before the operating rules are published: Which of our critical security, cloud, identity, and incident-response vendors intend to participate, and will they represent that status in writing to the extent the law allows? Can each participating vendor segregate our data from its operations work, and will it contract to that segregation? Which representations to customers, regulators, and insurers become incomplete if a vendor participates and we do not know? What does our cyber policy pay on a retaliatory state-backed attack, an accidental American-directed effect, and a shared-cloud outage? Ask before the reservation-of-rights letter arrives. Which employees, affiliates, and joint ventures in China or other rival jurisdictions connect to participating vendors, and what does their travel protocol require? Watch two documents next: the operating procedures, and the Cyber Letters of Marque and Reprisal Act, introduced July 15 as S. 5000 and H.R. 9697. Section 8 of the House bill bars any cause of action against a letter holder for acts the letter expressly authorizes, which would supply a statutory civil shield the memorandum does not contain, and an executive instrument cannot create. Participation is a decision your vendors get to make. Treat the memorandum as the risk-transfer instrument it is: The government authorizes the operation, and much of the residual legal, insurance, and commercial exposure stays private, including with companies that never signed anything.
InfoSecurity Magazine MalwareNCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
CSO Online BreachAI made software development unrecognizable. Is cybersecurity next?
The rapid emergence of AI has radically changed a host of professions, with software engineering and development perhaps the most transformed of all pursuits. The usual “solitary ritual” of a developer writing code for hours is giving way to collaboration with an army of chatbots. In its 2025 report on the State of AI-Assisted Software Development, Google Cloud researchers found that even then, LLM usage was almost universal among coders, with 90% of developer respondents using AI as part of their work, and 80% believing it has increased their productivity. An earlier Microsoft study documented the effects AI had on productivity, with software developers who used AI completing 26% more tasks than developers who didn’t use AI. The downside of the increased productivity is the impact on software developer jobs. Although data is hard to find, anecdotal evidence and some research show an impact on employment. For example, a March 2026 Federal Reserve Board working paper found that coder employment is slowing. “We find robust evidence that annual coder employment growth is about 3% lower now than it was pre-ChatGPT,” the authors concluded. Not only has the number of developer jobs potentially dipped, but the organization around those jobs has also shifted. Gartner predicts that “80% of organizations will evolve large software engineering teams into smaller, AI-augmented teams by 2030,” with more midlevel and senior specialists; managers supervising a wider arena of activity; new roles emerging that include AI-governance specialists, context designers, and AI-augmented UX designers; and greater demand for systems-thinking. Experts predict these kinds of changes will soon be felt across the cybersecurity sector with agent-run SOCs, continuous vulnerability triage, machine-speed containment, and humans directing fleets of defensive agents, posing the potential to make information security unrecognizable from its current state. And yet, the analogy between the evolution of software and cybersecurity is imperfect. “The hard part for us is, if we’re talking about where engineering is moving — to fully looped autonomous agents, feedback loops, all the things that they’re building now, and just having humans supervise the machines — security really requires reproducibility,” David Lindner, CISO at Contrast Security, tells CSO, meaning that a security control must produce consistent, repeatable results. Moreover, any changes won’t be as rapid for cyber as they were for software development. “I don’t think cybersecurity will be completely changed that quickly, but certainly we will see month-by-month big changes, and two years from now, it may be unrecognizable from what it is today,” Jim Reavis, CEO and co-founder of the Cloud Security Alliance, tells CSO. The autonomous SOC is almost here The transition to a new world of cybersecurity has already begun, and the most obvious area transforming is the security operations center (SOC). Most experts agree that AI agents can easily do the job that fully staffed SOCs do today, and do it faster and better. “We had an incident come in through Jira, and the agent went and pulled all the information from GitHub, pulled all the information from Datadog, and then gave an initial triage,” Contrast Security’s Lindner says. “I don’t want to even call it a junior SOC analyst. It is a SOC analyst that does some initial triage.” But there appears to be disagreement regarding how much authority SOC-replacing AI agents should be granted. “We’re definitely leveraging AI tools, and maybe some of what would have been first-level triage is now being done by agents,” Lionel Litty, CISO at Menlo Security, tells CSO. “But at this point, at least for us, we’re not yet comfortable with just letting agents run wide in our SOC and make the ultimate decision of, ‘Hey, this is something that we can ignore, or this is something that definitely we should look at.’ We use them to help provide context and prioritize.” Still, experts believe that much of the first-level work performed by SOC analysts will move to agents, leaving humans to handle escalation, oversight, and higher-level judgment. “Basically all of cybersecurity is going to need to operate at machine speed,” Reavis says. “SOCs absolutely are going to have a layer of activity where it’s going to be all agents making the decisions and doing the triage. Then the human in the loop is going to be at a higher level, more senior.” Vulnerability discovery becomes abundant, but absorption becomes scarce It’s undeniable that the most immediate and ongoing changes from AI for cyber defenders are the rapid discovery of massive numbers of cybersecurity vulnerabilities, a shift the industry is already experiencing. But even this transformation comes with downsides because chasing down and fixing every flaw is an arduous task that consumes most defenders’ time. “The problem absolutely is absorption,” CSA’s Reavis says. “How do I absorb this information? How do I triage it? How do I fix it?” Menlo’s Litty has seen this problem before with static analysis systems that generated more findings than engineering organizations could address. “You can find hundreds of things, but if you send hundreds of things to engineering and most of them aren’t relevant, engineering will just ignore you,” he says. AI can already find and test problems in source code, but autonomous validation against complicated production environments remains harder. Caleb Sima, chair of the CSA AI Safety Initiative and founding partner of White Rabbit, distinguishes between analyzing source code and autonomously testing complex production environments. “I think vulnerability discovery today in source code is done,” he tells CSO. “But in terms of real vulnerability discovery in an autonomous way, in a real enterprise production network that produces valid vulnerability and exploitation, we still have a bit of ways to go.” The so-called “vulnerability apocalypse” is less a fundamental cybersecurity change that will make the field unrecognizable and more a question of an increasing disconnect defenders know too well. As Lindner puts it: “We don’t have a problem finding problems. We have a problem triaging and remediating all the problems that we find.” Machine-speed attacks force machine-speed containment Another change that could leave traditional cybersecurity practices in the rearview mirror is what happens when autonomous attacks alter the threat environment, necessitating machine-speed response. “It’s no longer about a single attacker rooting through your network, but it’s a landing of an agent that spawns 200 agents that rapidly move through your enterprise to identify and exploit its vulnerabilities,” Sima says. These agents can scope out the environment, locate valuable assets, and abscond with data before defenders can respond. Cyber defenders should be positioned to respond in equal lightning-fast fashion. “The cloud, the application, and the endpoints should all be able to actively quarantine, move, and adjust controls at machine speed without breaking production,” Sima says. Litty believes that defenders should assume any component could be breached and design the environment to limit the resulting damage. “This goes back to fundamentals: least privilege and separation of duties,” he says. “How do I make sure that I have separated components, defense in depth, so that one vulnerability being exploited doesn’t take my entire company down?” Defender teams become flatter, more agent-heavy Although it would be tempting to conclude that as SOC analyst jobs disappear, the AI-centric cybersecurity landscape would result in net job losses across the industry, experts say that likely won’t happen. Instead, they anticipate a restructuring of roles and the emergence of smaller, agent-heavy teams. “I see a flattening of organizations between the leaders and the builders,” Reavis says. “The more senior people are going to have to go and build things.” White Rabbit’s Sima sees a workforce model that is barbell-shaped, consisting of highly experienced professionals on one end and AI-native junior workers on the other end, with pressure on the workers in the middle who are devoted to coordination and project management. “I think you’ll see a barbell: top-tier, senior individual contributors and then juniors and interns,” he says. “The middle is going to struggle.” Contrast Security’s Lindner agrees that workers with the highest knowledge and experience will fare well in the future. “The things AI isn’t going to be able to replace are experience and judgment,” he says. “My team is uber-senior today, and I need that. I need them to fully understand and have the experience and the judgment to know how and when AI is going to work for us, and where we need to add different controls where AI isn’t going to work, because it’s not going to work everywhere.” AI will likely never replace skilled cyber professionals, according to Litty. “I’m definitely not seeing the humans going away in those areas for now,” he says. From tool sprawl to an AI control plane One beneficial restructuring of the cybersecurity market as AI takes hold fully is that LLMs may be the interface that connects, but does not reduce, today’s existing security tool sprawl. Sima describes controlling firewalls, endpoint tools, and other systems conversationally without having to grapple with each product’s interface. “AI becomes the interface and the glue across all of these fragmented security products,” he says. The ability to manage sprawl will surely be welcomed in a world with enormous agent proliferation and accelerated churn. “The technology footprint is exploding, and it’s so vast,” CSA’s Reavis says. “On the one hand, you see a lot of sprawl, and we’re going to have trillions of agents.” Litty, on the other hand, thinks that existing tools will evolve instead of proliferating. “What we’re seeing so far is that it changes the tools,” he says. “It doesn’t necessarily mean more tools. So far, I’m not seeing an explosion of tools.” What should CISOs do now? CISOs don’t need to wait for these and other AI-related changes to occur before taking action. Experts recommend that security leaders identify bounded, high-volume tasks such as alert enrichment, initial triage, and vulnerability prioritization, where agents can be tested with restricted authority. “What I would consider telling senior people is: Go build things,” Reavis says. “Building things doesn’t mean going to an entry-level position, but go build things that create a new way of doing your job.” CISOs should also direct attention to creating a new governance discipline based on an inventory of every agent and AI-enabled security function. “First, [have] a registry of where you are using AI, and then look at the quality of the output,” Menlo’s Litty says. “How do you do drift detection for what your AI tools are doing? Is this still working? If you take the SOC example, how do you evaluate how well your AI agent is doing at triaging your vulnerabilities?” Finally, autonomous agents should not be considered anonymous agents. Every agent should have a named human or team that is accountable for it, with human review reserved for situations that are consequential or difficult to reproduce. “There has to be a named owner,” Sima says. “Whether that named owner is a team or an individual is all dependent upon what that AI agent is responsible for, what its goal and objective are, and the job that it does.” The task for CISOs, then, is not to automate everything. It is to learn where agents work, restrict what they can do, and establish who answers for them when they fail.
The Hacker News Vuln
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over
The Hacker News Vuln
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication
CSO Online BreachHundreds of OpenAI agents attack RubyGems platform
A swarm of hundreds of OpenAI agents uploaded “malicious packages” to RubyGems and tried to steal API keys, the Ruby community gem hosting service revealed Friday. OpenAI confirmed part of the disclosure, saying, “our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.” The agents’ goals were unclear, as was whether they engaged in the swarming activity for research, and even whether they were explicitly sent by OpenAI staffers, but an analysis published by RubyGems strongly suggests malicious intent. “Once the AIs got arbitrary RCE on the build environment, they would sometimes use the build environment to attempt to steal other users’ API keys, though we are unsure if they succeeded or not,” the RubyGems post said. “The agents clearly regarded what they were doing as hacking. Agents used file names like hack[.]rb, evil[.]rb, inject[.]rb, exploit[.]rb, and ssrf[.]rb. SSRF stands for ‘Server-Side Request Forgery,’ a type of security vulnerability. They also dubbed packages conspicuous titles like pwnp999, exfiltestwand3, hacksvn1778554764 and lambproxyhackabcxyz. Comments such as “# malicious probe” or “#hack” are littered across the campaign.” The post also said that the agents attempted to trick defensive systems. “At some points, the agents attempted to be covert. We found multiple packages that would disarm themselves to hide their payload in the next version,” the post said. “They uploaded one package with the comment ‘# disable evil in the next version and bump version,’ which after execution would modify the package to remove the malicious code initially inserted.” OpenAI should be accountable Analysts and consultants said the attack was concerning because if such efforts happen often enough, it could slow down security operations center (SOC) responses. Nader Henein, a Gartner VP analyst, said he was highly concerned about an upcoming bot swarm trend. “What we know is that this is the kind of standard attack, now AI-augmented, that will become commonplace over the coming months,” Henein said. “It’s less so a rogue agent, more so an attacker, potentially using compromised credentials, weaponizing an agent swarm, in the same way that attackers used compromised endpoints to mount DDoS attacks for the better part of the last decade. The difference here is the fact that these are not individually compromised bots. OpenAI’s guardrails should have not allowed this to happen.” Frank Dickson, principal analyst at Dickson Research, added, “OpenAI needs to be held accountable. They seem to want to create ‘Dr. Frankenstein’s monster,’ but don’t seem to want to accept blame for the outcomes. OpenAI hasn’t denied its agents used RubyGems. It has disputed the word ‘malicious’ and called the activity ‘benign,’ while separately acknowledging that, in that same stretch of weeks, its agents escalated to cluster-admin access at Hugging Face and compromised accounts at four other third-party services. Those two characterizations are hard to square. The behavior is still unacceptable.” However Erik Avakian, technical counselor at Info-Tech Research Group, stressed that it’s not necessarily the case that OpenAI launched these agents with explicit instructions. The agents might have easily charted this destructive path all on their own. The OpenAI agents “absolutely could have acted autonomously. We’ve already seen that capable agents can pursue various unexpected paths to accomplish a task when they have enough autonomy and access,” he said. “A human may have authorized the evaluation or given the agents access to tools, but that doesn’t mean a human approved every action they subsequently took.” Could delay SOC responses Dickson added that he fears the ultimate cybersecurity risk is that SOC staffers see so many of these attacks that they start to experience alert fatigue. “If the vendor whose agents did this is the one downgrading the language, a SOC analyst reading headlines instead of the underlying report has every reason to underreact,” Dickson said. “Security operations aren’t fit for purpose if they run on the assumption that an AI agent label makes an intrusion less real. A stolen API key or a remote code execution path behaves identically whether the actor is a ransomware crew or an unsupervised model chasing a reward signal.” Mike Wilkes, enterprise CISO at Aikido Security, also noted that the fact that the agents self-identified as OpenAI should mean nothing, as all agents can persuasively pretend to be representing anyone, especially if they think it will slow down a response, even for a brief period. “A User-Agent string is a nametag written by the visitor, not a passport,” he said. “If SOC tooling begins suppressing alerts because traffic claims to be an OpenAI, Anthropic, Google or other AI agent, attackers will adopt those identities immediately if they haven’t already.” Thus, he said, “if a human researcher or employee delegates authority to an autonomous agent, there should be a verifiable chain showing who delegated that authority, which organization they represent, what agent was authorized, what scope it was given, and for what period of time.” Plan for similar attacks Consultant Brian Levine, executive director of FormerGov, encouraged CISOs to anticipate more such attacks and plan accordingly. “Organizations that depend on open source, which is nearly all of them, should assume registries are an active battleground [and should] rotate and scope API keys tightly, monitor for anomalous package publishing and credential access, and pin and verify dependencies rather than trusting a name,” he said. “The economics have shifted. Automation lets an attacker try thousands of variations cheaply, so defenders have to make the payoff of any single success as small as possible.” Justin Greis, CEO of consulting firm Acceligence, agreed. “If legitimate AI research activity increasingly generates behavior that looks like hostile scanning, exploitation, credential access or persistence, SOC teams can become conditioned to treat those signals as noise,” Greis said. “Attackers will understand that very quickly. The dangerous phrase becomes ‘that is probably just an AI agent.’”
Dark Reading Breach
Cyber Op Targets South Korean Media & Automotive Sectors
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
Dark Reading Vuln
Microsoft Issues Emergency Fixes After Massive Patch Tuesday
You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
CSO Online BreachCritical Cisco Secure Email Gateway zero-day gives attackers root access
Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were released. Tracked as CVE-2026-76461, the vulnerability is described by Cisco as an SQL injection caused by insufficient validation in the product’s email parsing code. Parsing incoming email messages for threats is this appliance’s main job, which means the attack vector is trivial. “An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device,” Cisco said in its advisory. “A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.” The flaw affects both the physical and virtual versions of the product and was fixed in the AsyncOS firmware releases 15.5.5-0141, 16.0.4-3021, and 16.5.0-780 released Monday. The Cisco product security team became aware of active exploitation of this vulnerability earlier this month, and the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog. Indicators of compromise might be missing Because the vulnerability has been exploited as a zero-day, just upgrading to the patched firmware version is not enough. Organizations should also try to determine whether their own appliances have been compromised. One way is to review the mail_logs for suspicious SQL statements. However, because successful exploitation gives attackers root access on the device, they could use this access to alter the logs and hide their tracks. Cisco advises organizations to also check any network and firewall logs outside the device for any signs of suspicious activity, such as file uploads or downloads between the device and external IP addresses. If exploitation is suspected on physical devices, Cisco recommends contacting the Cisco Technical Assistance Center. For virtual devices, customers are advised to save all forensic information then deploy a new instance with rebuilt configuration and rotated credentials. Devices that are enrolled in Cisco Secure Email Cloud have already been reviewed by Cisco and the owners of the devices that showed potential signs of compromise were contacted. The company’s advisory also includes general recommendations for device security hardening. “A root-level, unauthenticated RCE in an email gateway is about as good a foothold as an attacker gets,” Josh Picolet, vice president of detection and analysis at security firm Team Cymru, tells CSO. “This is only the second Secure Email Gateway flaw ever added to CISA’s KEV catalog, after CVE-2025-20393, and that repetition fits actors who treat edge appliances as durable, reusable access rather than one-off targets.”
CyberScoop GeneralWhat’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies
Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned. The post What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies appeared first on CyberScoop.
Dark Reading Vuln
Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, and alignment. Throughout the session, they will share insights that address key topics raised by the Black Hat Review Board, including model safeguards, evaluation and containment practices, defensive use cases for AI, and the broader implications of increasingly autonomous systems for the cybersecurity community. The session will trace the models' attack path, including how frontier models are sandboxed during evaluations, how the models exploited a zero-day vulnerability to gain internet access, and how they identified and leveraged a remote code execution path on Hugging Face infrastructure. Drawing on the joint investigation, the speakers will explain how the activity was detected, contained, and investigated. They will also discuss the changes OpenAI is making to strengthen evaluation environments, containment controls, and monitoring capabilities, as well as the role AI systems played in supporting the investigation and response. In addition to the technical reconstruction of the incident, the session will address broader questions relevant to the security community, including lessons for improving AI system security, defensive applications of AI in incident response, and approaches to mitigating emerging risks associated with increasingly capable models. The discussion will also examine alignment challenges associated with long-running agents, including reward hacking, shifts in model behavior and persona over extended trajectories, and information sharing across multi-agent systems. Finally, the speakers will explore what this incident suggests about emerging AI cyber capabilities and how organizations can use AI to strengthen prevention, detection, investigation, and response efforts.
SC Media VulnPatched VMware vCenter bug targeted in ransomware campaigns
Ransomware groups exploit a critical VMware vCenter bug just seven weeks after patch released.
The Hacker News Malware
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
Dark Reading Malware
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.
The Hacker News Malware
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record
CyberScoop VulnCisco warns customers of actively exploited zero-day in email gateways
The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base. The post Cisco warns customers of actively exploited zero-day in email gateways appeared first on CyberScoop.
SC Media VulnMass scanning campaign targets Vite development servers for cloud credentials
The operation utilizes an exploit for CVE-2026-39364, a critical flaw affecting Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5, according to F5.
The Hacker News Malware
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.
SC Media VulnNintendo patches critical Nintendo Switch vulnerability
The vulnerability, identified as CVE-2026-82079, affects Switch systems running firmware versions prior to 23.0.0.
SC Media GeneralOpenAI’s Astra restrictions are another warning shot for security teams
Here are five ways teams can stay resilient as adversaries gain access to frontier AI models.
InfoSecurity Magazine GeneralMost Fraudulent Hires Receive Credentials Before Detection
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations
SC Media GeneralDDRop attack bypasses Intel and AMD confidential computing defenses
The DDRop attack requires an adversary with existing software control of a server and brief physical access to install a custom interposer circuit board between the processor and memory modules.