Sign in

InfoSec

@infosec.skyfleet.blue
5.6K followers 506 following 71K posts

Relay Tracking News & Blogs about infosec, cybersec - source removal/addition suggestions welcome ! CVE : check out @cve.skyfleet.blue 🆘 @skyfleet.blue

PostsRepliesMedia
InfoSec @infosec.skyfleet.blue · 3h
Re: cloud computing provider disclosures
seclists.org
oss-sec: Re: cloud computing provider disclosures
Posted by Katie on Oct 04 A thought at the bottom. Interesting conversation. I notice that Aaron mentions restricting the early access group to those who can meaningfully contribute. To some (like myself) a meaningful contribution might be creating a piece of art (ex. fan art) for the oss-security list. Therefore, it might be best to qualify the type of contribution (ex. those who can meaningfully contribute code maintenance). -Katie
000
InfoSec @infosec.skyfleet.blue · 4h
Re: cloud computing provider disclosures
seclists.org
oss-sec: Re: cloud computing provider disclosures
Posted by Aaron Rainbolt on Oct 04 I don't really think I'm a frequent enough contributor here to have much say, nor do I run a cloud service, but I personally don't like this idea so much. Cloud providers have to have a robust method to update their world at any instant because the zero-day market is a thing, and because people sometimes see a fix go public and immediately come up with an exploit for the vuln it fixes without knowing anything more about the vuln....
000
InfoSec @infosec.skyfleet.blue · 4h
Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks
cybersecuritynews.com
Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks
Citrix has released emergency security updates for a NetScaler SAML zero-day vulnerability that attackers are actively exploiting. Tracked as CVE-2026-88779, the flaw affects customer-managed NetScaler ADC and NetScaler Gateway appliances and can cause denial of service, disrupting access to services that depend on these systems. The vulnerability carries a CVSS v4.0 score of 8.7 and affects appliances configured as a SAML service provider or identity provider. Citrix describes it as a memory overflow, classified under CWE-119, where software fails to keep memory operations within the bounds of a buffer. Citrix confirmed targeted attacks against unmitigated deployments. Repeated exploitation can keep affected services unavailable. The company said its analysis showed an impact on service availability but had not identified any impact on the integrity of customer data. That distinction matters: the confirmed vendor assessment is denial of service, not proven data theft. The CVSS vector indicates that attackers can reach the flaw over a network without login credentials or user interaction. Attack complexity is low, making exposed appliances with the required SAML configuration a priority for urgent updates. Reports of trouble emerged as administrators saw recently patched appliances reboot repeatedly. Cyber Security News previously covered NetScaler reboots following the earlier zero-day patch , including failures tied to crafted SAML traffic that crashed the nsaaad authentication service. Some affected systems were already running build 14.1-73.37. Investigators also reported authentication requests containing shell commands intended to download and run a payload. Those requests appeared before confirmed crashes, but the administrator examining them did not establish that the commands executed successfully. Security researcher Kevin Beaumont separately reported a downloaded malware binary running on a patched honeypot, while watchTowr said it reproduced the vulnerability. These reports raise concerns about possible code execution, but they should not be confused with Citrix’s confirmed description of this CVE as a denial-of-service flaw. Affected Versions and Configuration Checks Citrix’s security bulletin lists NetScaler ADC and Gateway 14.1 releases before 14.1-73.41 and 13.1 releases before 13.1-64.28 as affected. NetScaler ADC FIPS releases before 14.1-73.41 FIPS are also vulnerable, alongside NetScaler ADC FIPS and NDcPP releases before 13.1-37.282. Secure Private Access Hybrid deployments using affected NetScaler instances also require updates. The bulletin covers customer-managed systems; Cloud Software Group handles the necessary updates for Citrix-managed cloud services and Citrix-managed Adaptive Authentication. Administrators can check the configuration for add authentication samlAction , which identifies a SAML service provider, or add authentication samlIdPProfile , which identifies a SAML identity provider. Either entry meets the stated configuration requirement. Finding it shows potential exposure on an affected build, not proof that attackers have compromised the appliance. Customers should install 14.1-73.41 or later on the 14.1 branch, or 13.1-64.28 or later on the 13.1 branch. FIPS customers need 14.1-73.41 FIPS or later, while 13.1 FIPS and NDcPP deployments require 13.1-37.282 or later within their respective branches. Organizations that installed the previous NetScaler security updates must upgrade again if they meet this vulnerability’s conditions. Citrix is providing Global Deny Lists to block known malicious IP addresses, but still urges prompt patching. Its advisory credits Bishop Fox and watchTowr for helping protect customers. For security teams, the immediate task is to match each appliance’s build and SAML settings against the bulletin, then apply the correct update. Recent patching alone is not enough: systems on earlier fixed builds can still face attacks targeting this newly disclosed SAML vulnerability. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News .
032
InfoSec @infosec.skyfleet.blue · 5h
Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories
cybersecuritynews.com
Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories
This week’s security newsletter was dominated by a Pentagon personnel data breach affecting more than three million people, actively exploited zero-days in Apple CoreGraphics and Fortinet FortiMail, and reports of two still-unpatched Citrix NetScaler RCE flaws. The broader bulletin covers 26 developments spanning cloud identity, malware, AI-agent governance, remote access, browser security, vulnerable infrastructure, and defensive tooling. Pentagon Data Breach The Pentagon confirmed that unauthorized users accessed a Defense Manpower Data Center information system through a file-sharing vulnerability. The incident affected 2.76 million living people and approximately 294,000 deceased individuals, with access reportedly occurring between October 2025 and July 2026 before DMDC discovered and patched the flaw on July 16. The compromised files contained unencrypted information that could include names, Social Security numbers, birth dates, contact details, demographic data, and military occupational information. The Pentagon has reported no evidence of misuse, but the long-lived nature of identity data creates continuing fraud, phishing, impersonation, and counterintelligence risks; affected people are being offered one year of credit monitoring and identity-restoration services. Apple Patches Actively Exploited CoreGraphics Zero-Day Apple released iOS 26.7.1 and iPadOS 26.7.1 to address CVE-2026-86950, an out-of-bounds write in CoreGraphics that may have been exploited in an extremely sophisticated attack against specifically targeted individuals. Processing a maliciously crafted file could trigger memory corruption and allow arbitrary code execution in the affected process. The issue affects iPhone 11 and later, as well as supported iPad Pro, iPad Air, iPad, and iPad mini models. Apple credited Meta Product Security and fixed the flaw with improved bounds checking; users and fleet administrators should install the update immediately and verify deployment through mobile-device-management systems. FortiMail Zero-Day Exploited in Attacks Fortinet warned that CVE-2026-104286, a critical FortiMail vulnerability rated CVSS 9.8, is being exploited in the wild. The unauthenticated flaw combines path traversal and improper NULL-byte handling, enabling attackers to write files through crafted HTTP or HTTPS requests. Affected releases include FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. Administrators should disable IBE support or remove the management interface from public access while tracking fixed releases, preserve logs, and investigate Fortinet’s published file, account, cron, and network indicators for evidence of prior compromise. Citrix NetScaler RCE Zero-Days Reportedly Exploited Security firm watchTowr reported two undisclosed NetScaler remote-code-execution vulnerabilities found during forensic investigations and allegedly exploited in real-world attacks. At publication time, Citrix had not issued an advisory, CVE identifiers, affected-build details, exploitation prerequisites, patches, or indicators, so the reports represented a credible warning rather than a fully vendor-confirmed disclosure. Organizations should inventory all NetScaler instances, reduce public exposure, restrict management access, preserve evidence, and inspect authentication events, sessions, configuration changes, files, processes, and outbound traffic. High-risk organizations unable to mitigate the exposure may need to isolate affected appliances under an approved continuity plan while monitoring Citrix’s bulletin channel for authoritative guidance. Security Teams Can Monitor Claude Chats, Files and Agent Activity Anthropic’s Claude Compliance API gives security teams visibility into Claude Enterprise conversations, uploaded files, projects, and supported Claude Code and Cowork session data, including prompts, responses, tool calls, skills, and transcript artifacts. The telemetry can feed DLP, SIEM, identity, eDiscovery, governance, and incident-response workflows. Claude Platform customers receive administrative and system activity events, but not conversation prompts or model responses. Only a Claude Enterprise organization’s Primary Owner can enable the API and create access keys, while enterprises remain responsible for least privilege, connector review, key protection, retention controls, and clear AI-use policies. OpenClaw Launches Enterprise Agent Platform OpenClaw introduced OpenClaw Enterprise, a free MIT-licensed platform for centrally deploying and governing persistent AI agents. Its control plane supports multi-tenancy, sandboxing, granular permissions, lifecycle auditing, and model-based reviews intended to separate trusted services from untrusted agent workloads. The project remains under development ahead of a planned 1.0 release and is recommended for internal pilots rather than unrestricted production use. Organizations can self-host it with Kubernetes and replace its models, sandboxes, and agent harnesses, but should independently test isolation, permissions, auditing, plugins, and secret handling before connecting critical systems. Claude Code Agent Allegedly Deletes 48,000 Files A Claude Code user reported that an agent deleted 48,218 live Windows project files and damaged the repository’s Git object store in 103 seconds while rebuilding a mirror. According to the user-provided verifier report, the deletion script mishandled 614 Windows directory junctions, traversed into the live project tree, and erased nested content. The account is based on a Reddit post and has not been independently established as a Claude Code product defect. Even so, it illustrates why agents performing destructive operations need dry runs, explicit path manifests, reversible moves, least-privilege accounts, filesystem-restricted sandboxes, and human approval; Bash-based deletions may also fall outside checkpoint-based recovery. AI Coding Agents Leak 13,000 Internal Screenshots Glow Labs’ PixelLeak research found more than 13,000 internal screenshots from over 300 organizations in more than 900 public GitHub repositories. Coding agents reportedly created public repositories or used public release assets to host images for private pull requests, exposing credentials, customer records, internal dashboards, financial interfaces, and unreleased features. The visibility gap was amplified because 93% of the cases involved repositories under employee usernames rather than corporate organizations, while the gitshot utility contributed to exposures at roughly one-third of affected companies. Defenders should inspect employees’ public repositories, gists, releases, and _gitshot tags; remove exposed material, rotate visible secrets, disable blanket agent approvals, and use authenticated private upload mechanisms such as GitHub CLI’s --attach option. Custom GPTs Used to Deliver Remote Access Malware Attackers are abusing ChatGPT Custom GPT pages as the first stage of a ClickFix chain involving sponsored search results, a fake service notice, a counterfeit CAPTCHA, and instructions to paste an obfuscated PowerShell command. Huntress examined at least 40 incidents linked to the campaign’s Google Sites infrastructure, including two infections traced to malicious Custom GPTs. The chain silently installs an MSI, uses signed Canon or Stardock executables for DLL sideloading, bypasses AMSI, executes .NET code in memory, and establishes persistence for a capable RAT. Defenders should hunt for PowerShell spawning msiexec , signed binaries running from unusual user-profile paths, modified adjacent DLLs, and suspicious scheduled tasks; users should never paste shell commands supplied by a CAPTCHA or AI-service page. Apache HTTP Server 2.4.69 Fixes 20 Vulnerabilities Apache HTTP Server 2.4.69 addresses 20 vulnerabilities—five moderate and 15 low—covering possible code execution, crashes, information exposure, request smuggling, and authentication problems. CVE-2026-63292 can cause a stack overflow through an oversized Host header in specific mod_vhost_alias configurations, while CVE-2026-42356 can cause an existing file to execute as CGI after particular internal redirects. The reported code-execution paths are configuration-dependent and should not be interpreted as universal attacks against default Apache installations. Administrators should upgrade to 2.4.69 and prioritize systems using affected virtual-host settings, CGI redirects, WebDAV, digest authentication, HTTP/2, and proxy modules. OpenSSL Flaw Can Leak Heap Memory in Plaintext CVE-2026-84782 is a high-severity out-of-bounds read in OpenSSL’s DTLS handshake retransmission logic. When a handshake write is suspended, stale buffer-position state can cause a retransmission to include adjacent heap data as plaintext or crash the process, potentially exposing secrets or creating denial of service. Fixed releases include OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8, with supported fixes also available for older branches. Security teams should inventory applications, appliances, VPNs, and embedded products using DTLS—including statically bundled copies that host package managers may miss—and update through the relevant software or operating-system vendor. TeamViewer Fixes Five High-Severity Vulnerabilities TeamViewer patched five high-severity flaws affecting Full Client, Host, and related components across Windows, Linux, and macOS. They include local path traversal and privilege escalation, a Windows installer race condition, unsafe link resolution, a heap overflow in .tvs recording playback, and CVE-2026-92370, an access-control flaw that could let an authenticated remote attacker bypass session restrictions and potentially execute code. TeamViewer reported no known public exploitation and recommends upgrading to version 15.82 or the latest supported maintenance release. Administrators should also review remote-access policies and watch for unusual installer activity, malicious recording files, or unexpected modification of protected files. Wireshark 4.6.9 Fixes 19 Security Flaws Wireshark 4.6.9 and 4.4.19 address 19 documented vulnerabilities across dissectors, capture parsers, Sharkd, and configuration profiles. The leading issue, CVE-2026-96419, can crash Wireshark or potentially execute code when a victim imports a crafted profile; other flaws can trigger loops, leaks, crashes, and resource exhaustion through malformed traffic or files. Wireshark reported no known exploitation, but analyst workstations routinely handle untrusted evidence. Teams should update immediately, include forensic workstations and automated capture pipelines in the rollout, and use sandboxes or disposable virtual machines for unknown profiles and packet captures until patching is complete. AI Agent Finds Linux Kernel Bug Enabling Root Access XBOW disclosed CVE-2026-72018, a high-severity out-of-bounds write in the Linux kernel’s DIBS loopback implementation for SMC-D. Although exploitation yielded only a constrained 16-byte zero write, researchers used it to overwrite fields in the kernel credential structure and obtain local root privileges without a separate information leak. The demonstrated path requires CAP_NET_ADMIN and manipulates SMC-D handshake traffic through NFQUEUE; the proof of concept succeeded on 22 of 100 boots in a mitigation-disabled test environment. Administrators should deploy kernel updates containing the bounds check, reboot affected systems, and review containers and workloads granted CAP_NET_ADMIN . Chrome Update Delivers 32 Security Fixes Google released Chrome 154.0.8037.92/.93 for Windows and macOS and 154.0.8037.92 for Linux, fixing 32 vulnerabilities. The most severe, CVE-2026-102331, is a critical ANGLE buffer overflow, while high-severity fixes address V8 type confusion and buffer overflows, WebUI cross-site scripting, use-after-free conditions, authorization weaknesses, and UI misrepresentation. Technical details for several bugs remain restricted while the update reaches users. Organizations should accelerate browser patching, verify that managed devices relaunch into the corrected build, and include long-running browser sessions and shared endpoints in compliance checks. New Process Injection Bypasses Common EDR Signals A proof-of-concept technique called console named-pipe injection avoids the familiar VirtualAllocEx and WriteProcessMemory sequence. It launches a console child such as nslookup.exe or netsh.exe , sends payload bytes through redirected standard input, finds the resulting buffer, changes its protection with VirtualProtectEx , and redirects a thread to execute it. The method does not eliminate telemetry: memory scanning, executable permission changes, redirected handles, and thread-context manipulation remain observable. Detection engineering should correlate unusual console-process creation, binary-like stdin activity, remote memory-protection changes, and SetThreadContext behavior rather than depending on one high-signal API call. Malware Hidden Inside Modified 7-Zip Installers Researchers found OpenSUpdater—also detected as Snackarcin—embedded in modified 7-Zip self-extracting installer code. The package contains a genuine foobar2000 installer as a decoy, while a concealed call inside the rebuilt extraction component contacts attacker infrastructure and downloads DLLs plus an encrypted payload. This is not a vulnerability in ordinary 7-Zip archives; it is deliberate tampering with open-source installer code. Analysts should inspect the extraction stub itself, not only its embedded program and configuration, and treat nested installers, mismatched publishers, odd version metadata, and padded certificates as reasons for deeper review. Forgotten Microsoft 365 Accounts Breached Proofpoint linked a password-spraying campaign called UNK_CondorFiltration to the TeamFiltration testing framework. The activity targeted 5,714 accounts across 28 Microsoft 365 tenants and resulted in seven confirmed compromises, all involving functional or service identities rather than personal employee accounts. The compromised accounts were enabled, unmonitored, apparently lacked MFA, and in six cases were breached within seven minutes—consistent with shared or unchanged default passwords. Organizations should inventory non-human identities, assign owners, rotate inherited secrets, enforce MFA or workload identities, and alert on first-time access and broad password failures from distributed cloud infrastructure. Antino Backdoor Runs Its C2 Through Microsoft 365 Cisco Talos identified Antino, a Rust backdoor that uses Microsoft Graph and stores its native command-and-control workflow in Outlook and OneDrive. The UAT-11587 campaign targeted government, defense, diplomatic, academic, and policy organizations, with Talos assessing links to China with high confidence. Outlook carries commands and responses, while OneDrive handles registration, heartbeats, stolen data, and additional tools, helping the malware blend into trusted cloud traffic. Delivery involved tailored phishing, fake installers, Windows scripting, encrypted JavaScript, unsafe .NET processing, DLL sideloading, and abuse of Windows troubleshooting components for execution and persistence. NeedyMantis Preserves Covert Access in Breached Networks Microsoft uncovered NeedyMantis, a modular post-compromise framework used in a limited number of targeted intrusions affecting telecommunications, universities, medical nonprofits, intergovernmental bodies, and government contractors. Activity dates to at least October 2025, and Microsoft assesses that the malware is deployed after initial access rather than through a single consistent infection vector. The framework uses DLL sideloading, custom encrypted archives, obfuscated loaders, WebSockets, and modular payload delivery. Defenders should hunt for traffic to corp.tripswithengine[.]com , unexpected DLL loads beside Poedit, curl, Vim, or TightVNC components, Impacket activity, and suspicious encoded data in HTTPS cookie headers; a detection should trigger a broader investigation into lateral movement and credential theft. Attackers Abuse Microsoft Defender Exclusions Attackers are using Microsoft Defender exclusions to shield malicious directories and file types while leaving antivirus visibly enabled. Because changing these settings requires administrative access, the behavior is a post-compromise evasion technique rather than an initial-entry mechanism. Exclusions can be configured through PowerShell, WMI, Group Policy, or registry changes, and a policy can hide them from normal PowerShell queries by administrators and SYSTEM. Defenders should monitor the underlying exclusion registry locations, investigate broad drive or staging-directory exemptions, and correlate new exclusions with concealment-policy changes rather than accepting an empty query result as proof of a clean configuration. SQL Server Used for Commands and Data Exfiltration ThreatMon investigated an intrusion linked to a Viva Aerobus environment in which attackers used SQL Server’s xp_cmdshell to run Windows commands and encoded PowerShell. The same database connection carried exfiltrated files by splitting them into chunks, Base64-encoding the content, and returning it through query results. An exposed attacker server revealed 17 tools for credential harvesting, SQL password testing, file movement, and lateral-movement preparation, along with collected source code and configuration material. Defenders should investigate unexpected xp_cmdshell activation, PowerShell or cmd.exe launched by SQL Server service accounts, unusual query output volumes, and any credentials or secrets that may have reached the exposed staging server. GlobalProtect Flaw Fuels 2.4 Million Fraud Messages Operation Master combined exploitation of CVE-2026-0257, a GlobalProtect authentication bypass, with SQL injection and large-scale invoice fraud. Investigators confirmed unauthorized sessions through seven gateways in four countries and data theft from at least nine database systems, including one reconstructed theft involving 24,558 debtor records. The stolen data was used to personalize fraudulent bills sent through hijacked Microsoft 365 mailboxes, SMS gateways, and WhatsApp templates. Defenders should patch exposed gateways, inspect abnormal VPN sessions, restrict database command execution, monitor anomalous DNS exfiltration and cloud-mail activity, and scrutinize device-code approvals. Teen Researcher Finds Critical Microsoft Titan Auth Flaw A 16-year-old researcher known as Faav found that Microsoft’s internal Titan analytics service accepted manipulated JSON Web Tokens without cryptographically validating their signatures. An unsigned token using the user value admin mapped to a privileged local account and allowed unauthorized SQL queries without Microsoft credentials. The researcher estimated that connected analytics systems held approximately 17.3 trillion rows, but stressed that this was a storage estimate containing historical, duplicated, and derived data—not 17.3 trillion unique people or confirmed leaked records. Microsoft restricted the endpoint four days after disclosure, awarded a $5,000 bounty, and found no reported evidence of malicious exploitation. Alleged ShinyHunters Leader Arrested Dutch police arrested a 24-year-old Amsterdam suspect whom FBI Director Kash Patel described as one of the alleged leaders of the ShinyHunters cyber-extortion group. The operation involved FBI support, seized storage devices, and an ongoing international investigation; a Rotterdam court ordered 90 days of pretrial detention. Dutch authorities did not publicly name the suspect, while a private-sector executive identified him as security professional Pepijn van der Stap. ShinyHunters denied that he was associated with the group, so descriptions of his precise role remain allegations that have not been proven in court. Windows 11 Update Causes Black Screens Microsoft confirmed that updates released from August 27 onward can prevent Windows Explorer from launching after sign-in, leaving users with a black screen. The problem primarily affects Azure Virtual Desktop hosts using FSLogix and certain existing user profiles on Windows 11 26H1, 25H2, and 24H2. Users can temporarily restore the shell by opening Task Manager and running explorer.exe . Enterprise administrators should deploy the matching Known Issue Rollback policy—KB5124006 for 26H1 or KB5124010 for 25H2 and 24H2—restart affected systems, and retain the rollback until Microsoft delivers a permanent fix. The post Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 6h
Re: cloud computing provider disclosures
seclists.org
Re: cloud computing provider disclosures
Posted by Demi Marie Obenour on Oct 04 - Xen Project already has its own predisclosure list. - KVM (sadly) falls under the Linux kernel security process. - Cloud Hypervisor and QEMU have their own processes. - Not sure about Firecracker. Not sure if a centralized one makes sense, unless there are individual components used by many providers that don't fall into one of the above categories.
000
InfoSec @infosec.skyfleet.blue · 6h
Re: cloud computing provider disclosures
seclists.org
oss-sec: Re: cloud computing provider disclosures
Posted by Jonathan Wright on Oct 04 A big question that comes up then is where is the line draw? How big must one be to qualify for this? There are tons of smaller-than-AWS/Azure/GCP/OCP but still huge hosting providers out there. On Sun, Oct 4, 2026 at 6:29 PM Jan Schaumann <jschauma () netmeister org> wrote:
000
InfoSec @infosec.skyfleet.blue · 6h
cloud computing provider disclosures
seclists.org
oss-sec: cloud computing provider disclosures
Posted by Jan Schaumann on Oct 04 Hello, I was wondering whether it might make sense to establish a disclosure list for cloud computing / virtual private server hosting providers. The reason that I think this might make sense is that not every cloud computing provider necessarily offers their own OS / Linux distribution, and thus may not be qualified for membership on distros@. At the same time there are vulnerabilities that directly and significantly impact cloud computing...
000
InfoSec @infosec.skyfleet.blue · 13h
October 4, 2026
buttondown.com
October 4, 2026
October 4, 2026
000
InfoSec @infosec.skyfleet.blue · 14h
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2
securityaffairs.com
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2 - Security Affairs
Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape
000
InfoSec @infosec.skyfleet.blue · 16h
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117
securityaffairs.com
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape
000
InfoSec @infosec.skyfleet.blue · 16h
ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group
securityaffairs.com
ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group
A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group.
100
InfoSec @infosec.skyfleet.blue · 17h
Apache Thrift 0.25.0: 61 CVEs fixed (combined announcement)
seclists.org
oss-sec: Apache Thrift 0.25.0: 61 CVEs fixed (combined announcement)
Posted by Jens Geyer on Oct 04 Apache Thrift 0.25.0 was released on 30 September 2026: https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1 It fixes the 61 vulnerabilities listed below. All of them affect Apache Thrift before 0.25.0, and users are recommended to upgrade to 0.25.0. Each was announced on 1 October 2026 on announce () apache org and on the Apache Thrift user or dev list; this message replaces the 61 separate postings to this list. Each entry gives...
000
InfoSec @infosec.skyfleet.blue · 19h
South Korean President Orders Full Security Checks After Financial Sector Hacks
cybersecuritynews.com
South Korean President Orders Full Security Checks After Financial Sector Hacks
South Korean President Lee Jae Myung ordered a thorough investigation on October 4, 2026, after a series of financial sector data breaches exposed customer and worker information. The order comes as investigators examine whether AI tools helped attackers break into systems used by banks and other financial firms. According to The Korea Times , Lee received a briefing on recent breaches at financial and public institutions and the steps taken in response. Presidential spokesperson Kang Yu-jung said the president ordered officials to investigate fully and develop measures with “a grave awareness of the seriousness of the matter.” Bank Breaches Spread Across Institutions Shinhan Bank reported a breach on October 1 affecting about 25,000 customers. Exposed information included names, phone numbers, annual income, and loan limits. Some resident registration numbers were also leaked, adding sensitive identity data to information collected during the loan application process. KB Kookmin Bank and Hana Bank disclosed further breaches on October 2. KB reported that personal and credit information belonging to 119 customers had leaked through a mobile work-support system used by employees. Hana said attackers gained abnormal access to its operations support system, exposing information belonging to 89 customers. Hana’s leaked records included names, resident registration numbers, addresses, email addresses, phone numbers and employer details. BNK Busan Bank separately reported the exposure of information belonging to 11 outsourced workers. These figures describe different affected groups, rather than one confirmed pool of bank customers. The incidents also reached nonbank financial firms. Yegaram Savings Bank reported a personal information leak affecting about 40,000 customers, while Hyundai Capital said data belonging to 146 housing loan agents had been exposed. The widening scope has placed security checks across the financial sector under closer attention. AI Involvement Remains Under Investigation Reporting by Seoul Economic Daily said traces of an AI-based automation tool were found in the Shinhan incident. SBS also reported common IP addresses across attacks on several financial institutions. However, investigators have not publicly established that one group carried out every breach or that AI independently completed each attack. The investigation will need to clarify both. The distinction matters because evidence of an AI tool does not explain the full attack chain. Public reports have not identified a confirmed software flaw, malware family, or complete set of attack indicators. Describing these incidents as fully autonomous hacks would therefore go beyond the available evidence. The reported entry points were loan-agent websites and employee support systems, not simply customer banking apps. The Korea Times reported that KB and Hana said their affected systems were separate from internet and mobile banking platforms, with no customer financial transaction information leaked in those incidents. Police began examining the breaches on October 2. Financial authorities also ordered broad checks of computer systems at banks and card companies. The findings make supporting business systems an important focus: they can hold sensitive records even when the main customer banking platform is not affected. Cybersecurity News previously covered the Korean Leaks campaign , which targeted South Korea’s financial sector through a compromised service provider. That separate case offers context, not evidence of a connection. Its reporting on AI-driven phishing also shows why exposed personal details deserve attention: convincing messages can turn a data leak into another opportunity to target affected people with carefully tailored scams. The post South Korean President Orders Full Security Checks After Financial Sector Hacks appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 19h
Anthropic asks Claude users to share voice data for AI model training
bleepingcomputer.com
Anthropic asks Claude users to share voice data for AI model training
Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. [...]
010
InfoSec @infosec.skyfleet.blue · 22h
Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION
securityaffairs.com
Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION - Security Affairs
A new round of weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs in your email box
000
InfoSec @infosec.skyfleet.blue · 22h
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
securityaffairs.com
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telcos, governments and universities worldwide.
000
InfoSec @infosec.skyfleet.blue · 22h
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
thehackernews.com
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
A suspected ShinyHunters member known as Rey was reportedly detained in Jordan and is said to be cooperating with the FBI.
000
InfoSec @infosec.skyfleet.blue · 22h
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
thehackernews.com
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
TA419 targets U.S. AI policy experts with reply-triggered AitM phishing that captures Microsoft credentials and session cookies.
000
InfoSec @infosec.skyfleet.blue · 04/10/2026
‘They call every week’: the phishing attacks targeting past victims
theguardian.com
‘They call every week’: the phishing attacks targeting past victims
Scammers reuse personal details harvested from fake Esta websites – and texts and calls can keep arriving for months
000
InfoSec @infosec.skyfleet.blue · 04/10/2026
Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000
cybersecuritynews.com
Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000
Vercel has confirmed a KVM zero-day vulnerability after security researcher Paulos Yibelo reported a full virtual machine escape that, he says, allows code inside a guest to gain root access on the host. Full VM escape zeroday (guest>host root in industry standard hypervisors)! More soon pic.twitter.com/dt9AsDO0De — Paulos Yibelo (@PaulosYibelo) October 3, 2026 The discovery came through the Vercel Sandbox bug bounty program, raising concerns about a security boundary used to contain untrusted workloads and AI agents. Yibelo announced the finding on October 3, 2026, describing it as a “Full VM escape zeroday” involving “guest>host root” in industry-standard hypervisors. Vercel CEO Guillermo Rauch separately confirmed a KVM zero-day and said a full technical write-up would follow. Neither statement explained the exploit chain or identified affected versions. KVM Zero-Day VM Escape A bounty notification shared with the announcement shows Vercel awarding Yibelo $50,000, the program’s maximum payment for one report. The message describes the highest award as reserved for vulnerabilities that let an attacker read or change another Vercel customer’s information. Its critical category includes microVM escapes to an EC2 host and access to another customer’s data or code execution. However, that award description should not be treated as a public demonstration of customer data theft. The screenshot hides the report’s root cause, and the available statements do not establish that real customer information was accessed. Vercel’s $1 million Sandbox challenge opened on August 18, 2026, with a scheduled closing date of September 1. Its published rules require a live proof of concept showing a broken security boundary, rather than a report based only on reviewing code. KVM, short for Kernel-based Virtual Machine, provides Linux virtualization. A guest virtual machine should remain separate from the host that runs it. A successful guest-to-host escape breaks that separation; root access gives an attacker the highest level of control on the host. Vercel’s published architecture places each sandbox inside its own Firecracker microVM on a bare-metal Amazon EC2 host. Each microVM has a dedicated guest kernel, while a Linux container inside it runs the user’s code. Vercel explicitly identifies the microVM, not the container, as the main security boundary. This distinction matters for AI agents that execute generated or downloaded code. Moving from a container into its guest operating system is not the same as reaching the underlying host. Yibelo’s claim describes the more serious boundary crossing, although the exact technical steps remain undisclosed. The announcement does not identify a CVE, affected kernel releases, processor requirements, or a patch. It also does not establish whether guest administrator access is required. Rauch’s reference to KVM does not prove that every KVM deployment, Firecracker installation, or cloud provider is vulnerable. The missing details also prevent an independent assessment of exploit reliability across different host configurations. For background, Cybersecuritynews previously covered the separate Januscape KVM vulnerability , which involved host memory corruption through nested virtualization. There is no disclosed evidence linking that issue to Yibelo’s finding, so its exploit conditions and fixes should not be applied to this report. Until the technical disclosure arrives, operators should follow Vercel and their Linux vendors for guidance, rather than assume an unrelated patch addresses this flaw. The immediate takeaway is a confirmed vulnerability report and a claimed host-root escape, not confirmed widespread exploitation. The promised write-up should clarify the root cause, affected systems, and available protections, allowing defenders to assess exposure without guessing. Those details will determine which deployments actually need urgent action. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000 appeared first on Cyber Security News .
020
InfoSec @infosec.skyfleet.blue · 04/10/2026
Google Gemini could soon get full access to your Mac’s files, apps and the web
bleepingcomputer.com
Google Gemini could soon get full access to your Mac’s files, apps and the web
Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. [...]
011
InfoSec @infosec.skyfleet.blue · 03/10/2026
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
bleepingcomputer.com
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]
032
InfoSec @infosec.skyfleet.blue · 03/10/2026
ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers
cybersecuritynews.com
ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers
A suspected ShinyHunters member has been detained in Jordan and is reportedly helping the FBI identify other hackers linked to the group. Reuters reported on October 3 that three people familiar with the matter confirmed the detention of Saif al-Din Khader, whose alleged online nickname is Rey. Two sources said Jordanian authorities took Khader into custody on Tuesday, September 29. They also said he was helping the FBI and law enforcement agencies worldwide locate other group members. Reuters could not establish why he was detained or where he was being held, and attempts to contact him and his family were unsuccessful. The FBI declined to confirm any specific arrest or overseas operation. However, it said it “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters,” adding that it had already worked with partners to arrest multiple subjects. The bureau pledged to pursue everyone responsible. FBI Data Theft Claims The detention follows ShinyHunters’ claim that it stole information on every FBI employee. That claim remains unverified, and the reported cooperation does not establish Khader’s role in the incident or prove the group’s account of its access. Earlier reporting on the alleged FBI jobs portal breach described a defacement of apply.fbijobs.gov, where attackers displayed a fake seizure notice. The FBI subsequently took its application service and Special Agent Applicant Portal offline while investigating unauthorized activity affecting its recruitment systems. ShinyHunters claimed it exploited an undisclosed Oracle PeopleSoft flaw that allowed code to run without logging in. The group said it then moved into FBI-managed AWS GovCloud systems and downloaded between two and three terabytes of data. Oracle, AWS, and the FBI have not confirmed that attack path. The attackers supplied journalists with a sample of 5,000 alleged employee records containing names, home addresses, phone numbers, Social Security numbers, birth dates, assignments, and family details. Reuters partially matched information in at least 10 cases, but that check did not establish that the records came from compromised FBI systems. These distinctions matter because taking control of a public website does not automatically prove access to an agency’s wider network. Investigators need to compare server logs, account activity, cloud access records, and outgoing data transfers to establish how the attackers entered and what they actually removed. If genuine, the reported personnel records could support targeted phishing, identity fraud, harassment, or threats against employees and relatives. Details about assignments and family contacts could make fraudulent messages more convincing, even without attackers retaining access to government systems. The Jordan detention also follows the arrest of an alleged ShinyHunters leader in the Netherlands. Dutch police detained a 24-year-old Amsterdam suspect on September 15, with FBI support. ShinyHunters denied that suspect’s association with the group, and the allegations remain unproven. Reuters described ShinyHunters as a group believed by experts to consist mainly of young, English-speaking hackers focused on data theft and extortion. Khader’s reported cooperation could help investigators connect online identities with real people, but Reuters did not disclose what information he had provided. For now, the key unanswered questions concern Khader’s legal status, the scope of his cooperation, and the true extent of the alleged FBI data theft. Neither the detention report nor the group’s public claims resolves those questions. The FBI’s investigation remains active, with further findings needed to separate confirmed evidence from attacker statements and other unverified allegations. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 03/10/2026
CVE-2026-90970: Critical GitLab AI Gateway Vulnerability
thecyberthrone.in
CVE-2026-90970: Critical GitLab AI Gateway Vulnerability
CVE-2026-90970: Critical GitLab AI Gateway Vulnerability October 3, 2026AI infrastructure is quickly becoming part of the enterprise attack surface, and CVE-2026-90970 is a good example of why.Zero-Day Vulnerability ReportsThe vulnerability affects GitLab A ... Read more Published Date: Oct 03, 2026 (20 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-90970 CVE-2026-104286 CVE-2026-76504
000
InfoSec @infosec.skyfleet.blue · 03/10/2026
Fake Zoom installer hides macOS backdoor CloudSyncD
securityaffairs.com
Fake Zoom installer hides macOS backdoor CloudSyncD
Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters.
011
InfoSec @infosec.skyfleet.blue · 03/10/2026
Microsoft Pushes New Exchange V2 Update After Discovering New Security Flaw
cybersecuritynews.com
Microsoft Pushes New Exchange V2 Update After Discovering New Security Flaw
Microsoft has released September 2026 V2 security updates to fix an Exchange Server flaw that lets authenticated attackers access other users’ mailboxes within the same organization. Tracked as CVE-2026 – 96940 , the vulnerability could expose email messages and attachments, making it a serious concern for businesses running Exchange on-premises. The flaw involves weak authorization, allowing an attacker with authenticated access to gain privileges over a network. Public vulnerability records list a CVSS score of 8.8. Unlike attacks that require someone to open a malicious file, exploitation does not require user interaction. The reported mailbox access does not extend across tenant boundaries. Microsoft said its own teams discovered the vulnerability internally and were not aware of active exploitation. The company also confirmed that the update appeared ahead of its planned release schedule, and some supporting documentation may have been unavailable when the announcement went live. Microsoft Reissues Exchange Server Update The September 2026 V2 release adds protection against CVE-2026-96940 to the original September security updates. Organizations that installed the earlier release should therefore review the new packages rather than assume their servers already have this additional fix. Updates are available for Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Administrators must select the package that matches their installed version and cumulative update. The new issue is separate from CVE-2026-62911, an earlier Exchange vulnerability covered by Cybersecurity News after a public proof of concept demonstrated an authentication relay attack path. That earlier research should not be treated as evidence that an exploit exists for CVE-2026-96940. Exchange Server 2016 and 2019 are out of support. Their latest patches are available only to organizations enrolled in Microsoft’s Period 2 Extended Security Update program , which covers May through October 2026. Period 2 requires a separate purchase, even for customers who joined the earlier ESU program. Microsoft says there will be no further extensions after October. Organizations without this coverage should migrate to Exchange Server Subscription Edition to continue receiving current security updates. Exchange Online customers are already protected against the vulnerabilities addressed in this release. However, businesses using hybrid deployments must still update their local Exchange servers, including servers used only for management. Machines running Exchange Management Tools also need the applicable updates. Microsoft recommends running the Exchange Server Health Checker script to identify missing cumulative updates, security updates, and required manual actions. Administrators can use the Exchange Update Wizard to plan the correct upgrade path before installing the latest security package. Exchange security updates are cumulative. A server running a supported cumulative update does not need every previous security update installed in sequence. After installation, administrators should restart the server, confirm Exchange services start correctly, and run Health Checker again to identify remaining steps. The release has known issues involving published calendar files returning HTTP 500 errors and ContentEngine deadlocks affecting Korean language email. Microsoft plans to address these in future updates. It also lists fixes for shared mailbox wrapper messages and delegated mailbox availability in certain hybrid environments. Microsoft urges customers to review deployment guidance and apply the update at the earliest opportunity. For affected organizations, the priority is closing the mailbox access gap while checking that mail services remain healthy after patching across their Exchange environment. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post Microsoft Pushes New Exchange V2 Update After Discovering New Security Flaw appeared first on Cyber Security News .
010
InfoSec @infosec.skyfleet.blue · 03/10/2026
Danish university DTU breach exposes data of up to 200,000 people
bleepingcomputer.com
Danish university DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]
000
InfoSec @infosec.skyfleet.blue · 03/10/2026
Unrestrained AI, moral dilemmas, and regulatory failures: Best infosec long reads 10/3/26
metacurity.com
Unrestrained AI, moral dilemmas, and regulatory failures: Best infosec long reads 10/3/26
Meet the "rogue" AI hunters, Trump and Anthropic clashed over AI control, Anthropic searches for AI’s moral compass, Trump scraps AI transparency rules, "Rogue" AI puts the law to the test
000
InfoSec @infosec.skyfleet.blue · 03/10/2026
Pluralistic: Economic probabilities for our grandchildren (03 Oct 2026)
pluralistic.net
Pluralistic: Economic probabilities for our grandchildren (03 Oct 2026) – Pluralistic: Daily links from Cory Doctorow
Today's links Economic probabilities for our grandchildren : If only data centers would stop hogging all the copper. Hey look at this : Delights to delectate. Object permanence : RIAA v P2P; Infoseek's anti-terror brain-scanner; Copyrighting every phone number; Carving pumpkins with cookie-cutters; Polish women go on strike; Latent labor in material world; Hitler's meth; "Flying Saucers Are Real!"; Hope, not optimism; Broadcast Flag talk; David Suzuki's free research; "Inquisitor's Apprentice"; California's tax ban made the rich MUCH richer; Union organizers caught Wells Fargo; Power poses aren't real; "Ghosts"; Criticizing tech; "Savage Love A-Z." Upcoming appearances : Brighton, Virtual, South Bend, Hudson, Calgary, Winnipeg, Paris, OVancouver, Victoria, Ottawa, Kilkenny, Montreal. Recent appearances : Where I've been. Latest books : You keep readin' em, I'll keep writin' 'em. Upcoming books : Like I said, I'll keep writin' 'em. Colophon : All the rest. Economic probabilities for our grandchildren ( permalink ) The post-war "peace dividend" owed its existence to three factors: industrial capacity, political freedom and pent-up demand. Industrial capacity: freed up by the war's end and the collapse of demand for munitions and materiel; Political freedom: the war's orgy of capital destruction of the majority of the wealth (and thus the power) of the world's oligarchs; Demand: Making up for years of neglect and privation during the war required new production of infrastructure and consumption goods. In Capital in the 21st Century , Thomas Piketty and his students analyzed painstakingly assembled records of 300 years' worth of capital flows, showing that wealth tends to pool in the hands of the already-wealthy. This creates mounting instability, thanks to the misrule of a shrinking class of increasingly powerful hereditary, unaccountable oligarchs whose whims and follies trump the material and political needs of the vast majority: https://memex.craphound.com/2014/06/24/thomas-pikettys-capital-in-the-21st-century/ That instability eventually reaches a breaking point in which the old order collapses in spectacular fashion, and that collapse destroys vast amounts of capital stock. Since this breaking point arrives as a result of oligarchy, in which nearly all the world's wealth has been hoarded by a tiny number of people, those aristocrats are disproportionately impoverished by the conflagration. If 90% of the wealth is in the hands of 1% of the people, a war or disaster that wipes out most capital will mostly destroy the wealth of the 1%. The poor suffer terribly, but they start with nothing – and end with nothing. We are clearly steaming into one of these situations. The wealthy squandered two generations preventing the world from taking the climate emergency, and now the inevitable has arrived. California is on track to see a 12 inch sea-level rise in the next month : https://www.theguardian.com/us-news/2026/sep/30/california-kelvin-wave-sea-level-rise That's just the overture to the American run of this year's "Super El Nino," a blockbuster whose out-of-town previews have been slaying massive crowds all over the world: https://www.theguardian.com/world/2026/oct/03/bangkok-thailand-floods-breaking-point-stagnant-lakes Also right on schedule: the misrule of oligarchs has elevated a con-man to the presidency, who trumps every other president for both corruption and incompetence. From oil to dollars, telecoms infrastructure to the internet itself, Donald Trump is doing everything in his power to end the American empire: https://pluralistic.net/2026/05/16/technopoly/#trumpismo-is-praxis-question-mark-exclamation-point A post-American world is on the horizon. What that world will look like is undecided. The US was always a wildly defective trusted third party, but it retained its status as the world's platform for generations thanks to the absence of credible alternatives. Now – as Mark Carney told the Davos crowd last year – the old system has "ruptured": https://www.weforum.org/stories/forum-institutional/davos-2026-special-address-by-mark-carney-prime-minister-of-canada/ What will replace the dollar? https://pluralistic.net/2026/02/11/post-dollar-world/#de-dollarization What will replace oil? https://pluralistic.net/2025/10/11/cyber-rights-now/#better-late-than-never What will replace the internet? https://pluralistic.net/2026/01/01/39c3/#the-new-coalition No one knows. No one can know, because this is all up for grabs. The future isn't something that happens to us. The future is something that we make. And despite the horrible death toll that's locked in by waves of climate shocks – presided over by the dying, fumbling "drink bleach" guy – it's conceivable that the future we get will be a good one, if not an easy one. A post-oligarch, post-American world could be a post- austerity world, one where we recognize that the limiting factor on public investment isn't money , but resources : energy, material, labor, expertise: https://www.youtube.com/watch?v=FATQ0Yf0Fhc Just as the post-war world led to the "30 glorious years" by mobilizing people and material to rebuild a shattered world and shattered lives, a post-American world might be one in which we find full, meaningful employment for all of us, all of our children, and all of their children: https://en.wikipedia.org/wiki/Trente_Glorieuses As seas rise, we're going to have jobs for every person who is willing, building sea defenses and moving whole coastal cities inland. Two generations of neoliberalism has left us with massive shortages of housing stock, crumbling highways, inadequate schools and hospitals. That means that we need to build lots more of these, and they can be built with state-of-the-art climate hardening, including geothermal heat, "passive home" designs, modern insulation, and heat-pumps. The rights-of-way for the interstate system would make dandy railbeds for arrow-straight, all electric high-speed rail powered by solar, wind and tides. All of this has the potential to yield a second peace-dividend prosperity. A post-oligarch world can recover industrial capacity by diverting it away from destructive activity (data centers, luxury housing) to essential functions (climate defenses, decent housing for everyday people). A post-oligarch world can recover democratic excellence by removing the malign influence that morbid wealth exerts on our policy choices: for example, if we don't like the quality of public schools, we can fix them by giving schools more resources, not by letting billionaire dilettantes privatize and starve them in the name of "school choice": https://pluralistic.net/2026/03/09/autocrats-of-trade-2/#witness-the-firepower-of-this-fully-armed-and-operational-battle-station Finally, a post-oligarch society can provide us with an even more inclusive version of post-war prosperity: we can use the wages we earn by building a better world to acquire new homes, induction tops, EVs and ebikes, and beautiful heirloom computers that are built to last for generations, upgraded and maintained by their users: https://www.edn.com/as-moores-law-slows-open-hardware-rises/ This is a world of material abundance and prosperity. Just as the post-war world made millions of people comfortable, educated and happy by putting them to work clearing the rubble and building something better, a post-oligarch, post-American world can offer us all all the hard, rewarding work we want, performing the essential work of care and rebuilding. We'll find that work by helping hundreds of millions of climate refugees, who will find work helping each other. This is all economically valuable, environmentally sustaining labor that we have labor, energy and expertise for. It's just that all that labor, energy and expertise is being misallocated by the ultra-wealthy who don't even believe that the majority of us exist, and who want to bet the planet and our species on a bizarre scheme to feed so many words to the world-guessing machines that they wake up and become gods: https://pluralistic.net/2026/05/13/vibe-governance/#k-hole Nearly a century ago, John Maynard Keynes published "Economic Possibilities for our Grandchildren," where he extrapolated from rising productivity to predict a fifteen-hour work-week within two generations: http://www.econ.yale.edu/smith/econ116a/keynes1.pdf That dream was destroyed by war and greed. Today, we are submerged in an ocean of debt. I'm not talking about the (fictional) "national debt" that is just a measure of all the dollars the government has spent into existence without taxing out of existence: https://pluralistic.net/2024/10/21/we-can-have-nice-things/#public-funds-not-taxpayer-dollars I'm talking about fiscal debt: the solar we didn't build, the carbon we emitted instead; the rail we didn't build, the wildly inefficient aviation we substituted; the walkable, livable, transit-oriented cities we didn't build, the car-choked disasters we built instead. Oligarchic opposition to universal health-care left us sick, with un- or undertreated illnesses and missed opportunities for prevention that left us with overlapping, population-scale health crises. All of this is debt that must be repaid: we can't walk away from it through bankruptcy. We must build the transit, cities, and systems of care – the infrastructure – our species needs to carry on human civilization. We can't keep hitting snooze on this, lest we are finally awoken by seawater lapping at our pillows. The world we're in today is awful and terrifying. It's awful because of the climate ruptures we're living through. It's terrifying because we didn't just fail to avert this crisis – we did nothing to prepare for it, either . As Piketty foretold, the misrule of oligarchs has led to an orgy of destruction, and while poor people will get the worst of it, oligarchs will pay the most, because they own nearly everything, which means they own everything that will be destroyed, too. None of that is good, and it would be better if we hadn't gotten into this situation in the first place. But after a forest fire, the canopy opens; and when it does, the seedlings that were overshadowed for centuries by the old growth can sprout in the ashes and the sun. We can't afford to continue living under oligarchy, and as oligarchs' greed and folly drives the old system beyond its breaking point, we must seize the opportunity to build a better successor. Hey look at this ( permalink ) Starship Stormtroopers: Michael Moorcock https://libcom.org/article/starship-stormtroopers-michael-moorcock The Enshittification of Mathematics https://rdcu.be/5uYGc2uo454a Zack Polanski to call for three-year cap on private rent rises https://www.bbc.co.uk/news/articles/cq74e4jg9leno AI ‘godfather’ Yann LeCun: Anthropic CEO Dario Amodei is ‘deluded,’ ‘crazy,’ and doesn’t understand cybersecurity https://fortune.com/2026/10/01/yann-lecun-anthropic-ceo-dario-amodei-deluded-crazy-cybersecurity/ Court Agrees with EFF: Utah’s VPN Law Demands a Technical Impossibility https://www.eff.org/deeplinks/2026/10/court-agrees-eff-utahs-vpn-law-demands-technical-impossibility Object permanence ( permalink ) #25yrago Leak: RIAA's anti-P2P strategy https://web.archive.org/web/20011019060035/https://www.dotcomscoop.com/riaa1003.html #25yrsago Infoseek founder: my brain-scanner can find all the terrorists https://web.archive.org/web/20011009025805/http://www.theregister.co.uk/content/55/22020.html #25yrsago Copyrighting every possible phone number as a touch-tone tune https://web.archive.org/web/20011007073546/http://www.theage.com.au/entertainment/2001/10/04/FFX0PGT0CSC.html #20yrsago What happens to password-locked data when you die? https://web.archive.org/web/20061106235805/http://news.com.com/Taking+passwords+to+the+grave/2100-1025_3-6118314.html #20yrsago Audio of activist lawyer talk on Broadcast Flag and Chilling Effects https://web.archive.org/web/20061005074245/http://uscpublicdiplomacy.com/index.php/events/events_detail/1859/ #20yrsago David Suzuki: Steal my research – that’s what it’s for! https://web.archive.org/web/20061020144546/http://www.davidsuzuki.org/about_us/Dr_David_Suzuki/Article_Archives/weekly09290601.asp #20yrsago Interdisciplinary DRM blog from my USC students https://uscpubd510.blogspot.com/search?updated-max=2006-08-24T14:59:00-07:00&max-results=7&start=91&by-date=false #15yrsag Inquisitor’s Apprentice: tenement sorcerers versus the robber barons in an alternate Gilded Age New York https://memex.craphound.com/2011/10/04/inquisitors-apprentice-tenement-sorcerers-versus-the-robber-barons-in-an-alternate-gilded-age-new-york/ #15yrsago Context: Further Selected Essays on Productivity, Creativity, Parenting, and Politics in the 21st Century https://memex.craphound.com/2011/10/03/context-further-selected-essays-on-productivity-creativity-parenting-and-politics-in-the-21st-century/ #15yrsago Unicode’s “right-to-left” override obfuscates malware’s filenames https://krebsonsecurity.com/2011/09/right-to-left-override-aids-email-attacks/ #15yrsago HOWTO carve a pumpkin by hammering cookie-cutters into it https://web.archive.org/web/20200916004345/https://www.foodnetwork.com/fn-dish/shopping/cookie-cutter-pumpkin-carving #15yrsago Shell funded warring militias in the Niger Delta https://web.archive.org/web/20111006003453/http://blog.platformlondon.org/2011/10/03/counting-the-cost-corporations-and-human-rights-abuses-in-the-niger-delta/ #10yrsago Sen Mitch McConnell blames Obama for bill that Obama vetoed and McConnell repeatedly voted for https://www.loweringthebar.net/2016/10/congress-blames-veto.html #10yrsago Polish women go on strike over extreme anti-abortion law https://www.bbc.com/news/world-europe-37540139 #10yrsago Survivors of CIA torture describe homebrew electric chair used at Afghan black site https://www.hrw.org/news/2016/10/03/interview-new-cia-torture-claims #10yrsago Visualizing the latent emotional and bureaucratic labor in our material world https://xkcd.com/1741/ #10yrsago Meth, Hitler and the Reich: the true, untold story of the Nazis’ dependence on coke, meth and oxy https://www.theguardian.com/books/2016/sep/25/blitzed-norman-ohler-adolf-hitler-nazi-drug-abuse-interview #10yrsago Flying Saucers are Real! Anthology of the lost saucer-craze https://memex.craphound.com/2016/10/03/flying-saucers-are-real-anthology-of-the-lost-saucer-craze/ #10yrsago The malware that’s pwning the Internet of Things is terrifyingly amateurish https://web.archive.org/web/20161004061621/http://motherboard.vice.com/read/internet-of-things-malware-mirai-ddos #10yrsago California’s 40-year-old ban on property tax raises has made the rich a lot richer https://web.archive.org/web/20161001034224/https://www.latimes.com/business/hiltzik/la-fi-hiltzik-prop-13–20160929-snap-story.html #10yrsago The Wells Fargo fraud came to light because of union organizers https://web.archive.org/web/20161005123132/https://prospect.org/article/first-and-foremost-wells-fargo-scandal-about-workers #10yrsago “Power Poses” are bullshit https://web.archive.org/web/20161007215414/https://www.wbur.org/npr/496093672/power-poses-co-author-i-do-not-believe-the-effects-are-real #10yrsago Martin Shkreli offers a bailout to ailing 4chan https://arstechnica.com/information-technology/2016/10/4chan-cashflow-problem-martin-shkreli-wants-to-join-board/ #10yrsago Ghosts: Raina Telgemeier’s upbeat tale of death, assimilation and cystic fibrosis https://memex.craphound.com/2016/10/04/ghosts-raina-telgemeiers-upbeat-tale-of-death-assimilation-and-cystic-fibrosis/ #10yrsago Yahoo secretly built a tool to scan all email in realtime for US spies https://www.reuters.com/article/idUSKCN1241YT/ #10yrsago How to: Criticize technology https://www.cjr.org/tow_center_reports/constructive_technology_criticism.php #10yrsago Johnson & Johnson says people with diabetes don’t need to worry about potentially lethal wireless attacks on insulin pumps https://www.reuters.com/article/us-johnson-johnson-cyber-insulin-pumps-e-idUSKCN12411L/ #5yrsago USPS pilots postal banking https://pluralistic.net/2021/10/04/avoidance-is-evasion/#check-cashing #5yrsago The Pandora Papers https://pluralistic.net/2021/10/04/avoidance-is-evasion/#transparency #5yrsago Savage Love A-Z https://pluralistic.net/2021/10/04/avoidance-is-evasion/#ggg #5yrsago Hope, Not Optimism https://pluralistic.net/2021/10/03/hope-not-optimism/ #1yrago When your ISP pays you https://pluralistic.net/2025/10/03/we-dont-care-we-dont-have-to/#were-the-phone-company #1yrago Blue Bonds https://pluralistic.net/2025/10/04/fiscal-antifa/#post-trump Upcoming appearances ( permalink ) https://www.epl.ca/blogs/post/elbows-up-with-cory-doctorow/ Brighton: Digital Sovereignty and the Post-American Internet (Green Party Conference), Oct 3 https://www.openrightsgroup.org/events/digital-sovereignty-and-the-post-american-internet/ Virtual: How to govern technology in a multipolar digital world (Connecting Current), Oct 6 https://connectingcurrent.tech/how-to-govern-technology-a-multipolar-digital-world/ South Bend: An Evening With Cory Doctorow (Notre Dame), Oct 6 https://franco.nd.edu/events/2026/10/06/an-evening-with-cory-doctorow/ Hudson, OH: Hudson Library, Oct 7 https://engagedpatrons.org/EventsExtended.cfm?SiteID=3850&EventID=596952&PK= Calgary: Wordfest, Oct 8 https://wordfest.com/2026/show/wordfest-presents-cory-doctorow-2026/ Winnipeg: McNally Robinson, Oct 9 https://www.mcnallyrobinson.com/event-18991/An-Evening-with-Cory-Doctorow Paris: Slow Tech Summit, Oct 15 https://slowtechsummit.com/ Vancouver: Read, Resist, Repair, Rejoice (Vancouver Writers Festival), Oct 19 https://writersfest.bc.ca/festival-event-2026/01 Victoria: Munro's Books, Oct 20 https://www.munrobooks.com/events/6113620261020 Vancouver: Life After AI (Vancouver Writers Festival), Oct 22 https://writersfest.bc.ca/festival-event-2026/46 Ottawa: Life After AI (Ottawa Writers Festival), Oct 24 https://writersfestival.org/event/life-after-ai Kilkenny (Kilkenomics), Nov 6-8 https://kilkenomics.com/ Vancouver: Enshittification (Sid Williams Theatre Society), Nov 10 https://www.sidwilliamstheatre.com/events/cory-doctorow-talks-enshittification/ Vancouver: BC Policy Solutions Gala, Nov 12 https://bcpolicy.ca/gala/ Montreal: World Science Fiction Convention, Sep 2-6 https://montreal2027.ca/en Recent appearances ( permalink ) Terms of Service with Clare Duffy (CNN) https://www.cnn.com/audio/podcasts/terms-of-service-with-clare-duffy/episodes/458ce968-af5d-11f0-b539-13ed2afe25f8 AI, Work, and Power (Software Engineering Daily) AI, Work, and Power https://softwareengineeringdaily.com/podcasts/cory-doctorow-on-ai-work-and-power/ AI, Corporate Power, and the Fight for Worker Control (Plutopia) https://plutopia.io/cory-doctorow-ai-corporate-power-and-the-fight-for-worker-control/ How to Think About AI—Before It’s Too Late (Daniel Solove) https://www.youtube.com/watch?v=_0xR3uEgGcc Could Tech Bosses Destroy Life As We Know It? (Politics JOE) https://www.youtube.com/watch?v=PL4VktU0SgY Latest books ( permalink ) "The Reverse-Centaur's Guide to AI," a short book about being a better AI critic, Farrar, Straus and Giroux, June 2026 https://us.macmillan.com/books/9780374621568/thereversecentaursguidetolifeafterai/ "Canny Valley": A limited edition collection of the collages I create for Pluralistic, self-published, September 2025 https://pluralistic.net/2025/09/04/illustrious/#chairman-bruce "Enshittification: Why Everything Suddenly Got Worse and What to Do About It," Farrar, Straus, Giroux, October 7 2025 https://us.macmillan.com/books/9780374619329/enshittification/ "Picks and Shovels": a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books (US), Head of Zeus (UK), February 2025 ( https://us.macmillan.com/books/9781250865908/picksandshovels ). "The Bezzle": a sequel to "Red Team Blues," about prison-tech and other grifts, Tor Books (US), Head of Zeus (UK), February 2024 ( thebezzle.org ). "The Lost Cause:" a solarpunk novel of hope in the climate emergency, Tor Books (US), Head of Zeus (UK), November 2023 ( http://lost-cause.org ). "The Internet Con": A nonfiction book about interoperability and Big Tech (Verso) September 2023 ( http://seizethemeansofcomputation.org ). Signed copies at Book Soup ( https://www.booksoup.com/book/9781804291245 ). "Red Team Blues": "A grabby, compulsive thriller that will leave you knowing more about how the world works than you did before." Tor Books http://redteamblues.com . "Chokepoint Capitalism: How to Beat Big Tech, Tame Big Content, and Get Artists Paid, with Rebecca Giblin", on how to unrig the markets for creative labor, Beacon Press/Scribe 2022 https://chokepointcapitalism.com Upcoming books ( permalink ) "The Post-American Internet," a geopolitical sequel of sorts to Enshittification , Farrar, Straus and Giroux, 2027 "Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027 "Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027 "The Memex Method," Farrar, Straus, Giroux, 2027 Colophon ( permalink ) Today's top sources: Currently writing: “Once Is Enemy Action,” a science fiction novel about the origins of modern technofascism. Today's words: 504 (21882 total). "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor. A Little Brother short story about DIY insulin PLANNING This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net. https://creativecommons.org/licenses/by/4.0/ Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution. How to get Pluralistic: Blog (no ads, tracking, or data-collection): Pluralistic.net Newsletter (no ads, tracking, or data-collection): https://pluralistic.net/plura-list Mastodon (no ads, tracking, or data-collection): https://mamot.fr/@pluralistic Bluesky (no ads, possible tracking and data-collection): https://bsky.app/profile/doctorow.pluralistic.net Medium (no ads, paywalled): https://doctorow.medium.com/ Tumblr (mass-scale, unrestricted, third-party surveillance and advertising): https://mostlysignssomeportents.tumblr.com/tagged/pluralistic " When life gives you SARS, you make sarsaparilla " -Joey "Accordion Guy" DeVilla READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer. ISSN: 3066-764X
000
InfoSec @infosec.skyfleet.blue · 03/10/2026
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
thehackernews.com
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
Cybersecurity teams are shifting toward continuous control across identity, cloud, endpoints, telemetry, and human risk.
000
InfoSec @infosec.skyfleet.blue · 03/10/2026
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
securityaffairs.com
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways.
010
InfoSec @infosec.skyfleet.blue · 03/10/2026
Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel
securityaffairs.com
Antino backdoor uses your inbox as its control panel
Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments.
000
InfoSec @infosec.skyfleet.blue · 03/10/2026
Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks
cybersecuritynews.com
Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks
GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9.9 and affects self-hosted deployments used to support GitLab Duo AI features. The company released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address the issue. GitLab strongly recommends that customers running affected self-hosted gateways upgrade immediately. It also contacted self-hosted AI Gateway customers before publishing its security advisory to provide early guidance on the required updates. GitLab AI Gateway Vulnerability The vulnerability involves improper handling of custom flow prompt templates. Under certain conditions, an authenticated user with Duo Agent Platform access could submit a specially crafted flow configuration that escapes the prompt template sandbox. Successful exploitation could then allow arbitrary commands to run on the AI Gateway. A sandbox is meant to keep template processing within a controlled boundary. In this case, GitLab says crafted input could cross that boundary and reach command execution. The disclosed impact is therefore more serious than changing an AI response: it could affect the service that processes AI requests. The published CVSS vector describes a network-accessible attack with low complexity, low privileges, and no required user interaction. It assigns high impact to confidentiality, integrity, and availability. However, this is not an unauthenticated flaw; the attacker needs a valid account with Duo Agent Platform access. GitLab credited security researcher invisiblemeerkat with responsibly reporting the issue. The advisory does not provide an exploit payload, identify the template engine involved, or report active exploitation. Those limits matter: the release confirms a critical security weakness, but it does not establish that attackers have already used it. Affected AI Gateway releases include versions starting at 18.1.6 and earlier than 19.2.4, the 19.3 branch before 19.3.2, and the 19.4 branch before 19.4.1. These version ranges apply to the AI Gateway component. Administrators should check the gateway deployment rather than rely only on their main GitLab instance version. GitLab has already deployed the fix to its hosted AI Gateways. Customers using GitLab.com, GitLab Dedicated, or GitLab Self-Managed instances connected to a GitLab-hosted AI Gateway are protected and need no action for this issue. Customers operating their own affected AI Gateway must install the update themselves. The distinction matters because GitLab’s self-hosted AI setup lets organizations manage requests to their chosen model backends within their own environment. Cybersecurity News previously covered a separate GitLab Duo prompt injection vulnerability involving source code exposure. That earlier issue should not be confused with this gateway sandbox escape. Update the Gateway Immediately Administrators should follow GitLab’s AI Gateway installation and upgrade documentation to deploy a patched image. For Docker installations, GitLab instructs users to stop and remove the existing container, then pull and run the new image with the correct environment variables. Verify the deployed image digest and run the available health checks afterward. For Kubernetes and Helm deployments, GitLab warns that cached images can prevent updated code from being pulled. Its guidance recommends image digests or an appropriate pull policy. Administrators should also restrict unnecessary outbound gateway traffic while preserving required connections. These controls support hardening, but the immediate priority remains installing a fixed AI Gateway release without delay. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks appeared first on Cyber Security News .
010
InfoSec @infosec.skyfleet.blue · 03/10/2026
Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control
cybersecuritynews.com
Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control
Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its Container Storage Modules, including flaws that could allow unauthenticated remote attackers to take full administrative control of affected storage environments. Organizations using vulnerable Dell CSM deployments should upgrade immediately, as Dell stated that no workarounds or mitigations are available. The advisory affects Dell Container Storage Modules versions before 1.17.0, with fixes available in 1.18.0 and later, covering CSM Authorization, CSM Operator, CSI components, and third-party Go libraries. The most severe vulnerabilities are CVE-2026-63688 and CVE-2026-63692, both assigned a CVSS score of 10.0. CVE-2026-63688 is a missing authentication flaw in the csm-authorization-storage gRPC server in CSM Authorization version 2.4.0. An unauthenticated attacker could exploit the flaw to access administrator credentials for all registered storage arrays, potentially gaining control across Dell’s five supported storage product families. Access to backend administrator credentials could enable an attacker to change storage configurations, access sensitive data , disrupt workloads, or create persistent access paths within the environment. Critical Dell Container Storage Flaws CVE-2026-63692 also affects CSM Authorization version 2.4.0. The vulnerability exists in the authorization proxy and tenant service, where critical functions can be reached without proper authentication. Successful exploitation could allow a network-based attacker to bypass authentication controls and elevate privileges to the administrative level. This could expose and enable manipulation of storage resources across all tenants. Another critical issue, CVE-2026-54472, is a hard-coded credentials vulnerability in CSM Authorization. The flaw could allow an unauthenticated remote attacker to forge cryptographically valid administrative JSON Web Tokens and gain administrator access to the CSM Authorization proxy. Dell rated the flaw CVSS 9.8 and advised rotating JWT signing secrets after updating, the advisory also addresses CVE-2026-61421 in the archived karavi-authorization component. Dell said older documentation used the JWT signing secret “supersecret” alongside a real token example. Organizations that deployed karavi-authorization using this documented value and never changed the signing secret may remain exposed to forged-token attacks and administrative takeover. CVE-2026-67269 in Dell CSM Operator 1.12.0 could let low-privileged remote users gain root access to Kubernetes nodes via a malicious ContainerStorageModule resource, Dell rated it 9.9 due to potential cluster-wide compromise. CVE-2026-67273, rated 9.6, could permit a low-privileged attacker to access Kubernetes Secrets and create cluster-scoped RBAC resources through template-engine injection. Such access could effectively bypass intended Kubernetes permissions and allow broad control of cluster resources. Other flaws include improper certificate validation, missing authorization in the Dell CSI Driver for PowerMax, sensitive-information disclosure through logs, and flaws affecting CSI drivers for PowerFlex, PowerMax, and PowerStore. The update also addresses vulnerabilities in third-party Go components, including golang.org/x/crypto, golang.org/x/net, golang-jwt/jwt, and protobuf. Dell recommends upgrading all affected Container Storage Modules deployments to version 1.18.0 or later at the earliest opportunity. Security teams should also rotate JWT secrets, review CSM Authorization access logs, audit administrative token usage, and check Kubernetes RBAC policies and custom resources for unauthorized changes. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 03/10/2026
Citrix NetScaler Keeps Rebooting Following the 0-Day Patch
cybersecuritynews.com
Citrix NetScaler Keeps Rebooting Following the 0-Day Patch
Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.37, the emergency update released for two zero-day flaws under active attack. The failures appear linked to crafted SAML authentication traffic that crashes the nsaaad service. Citrix says its engineering and support teams are tracking a newly seen SAML issue and plan to release a fresh security bulletin and fixed build. The key point is that the reboot reports do not yet prove attackers have bypassed the September patch. Build 14.1-73.37 remains Citrix’s fixed 14.1 release for CVE-2026-88771 and CVE-2026-88772 . The first flaw lets an unauthenticated attacker run commands on any affected deployment, while the second can allow code execution or denial of service when DTLS is enabled. Citrix confirmed exploitation against systems that had not been updated. Why Patched Systems Reboot Administrators on Reddit described external NetScaler appliances running 14.1-73.37 that suddenly entered forced reboot cycles. One report involved several customers and led to severity-one cases with Citrix. Another administrator said vulnerability scans were followed by repeated nsaaad crashes; after too many failures, the pitboss watchdog restarted the appliance. Citrix support reportedly said a fix was being prepared, but these forum claims have not yet been confirmed in a final vendor bulletin. The pattern matters because nsaaad handles authentication tasks. A crafted request may crash that process without giving the sender control of the device. Repeated crashes can still create a serious denial-of-service event, especially on an internet-facing gateway used for remote work. High-availability pairs may also suffer disruption if both nodes receive the same traffic or restart in turn.github+1 Citrix’s temporary SAML deployment guid ance tells customers to check whether the relevant configuration is present, review mitigation choices, and prepare to install the next fixed build. At the time of writing, the notice did not provide a new CVE, complete root-cause details, or a final release number. This means teams should not present every reboot as a confirmed breach or assume that 14.1-73.37 has reopened the earlier flaws. What Defenders Should Check Security teams should first preserve core files, system logs, authentication records and a support bundle before another restart removes useful evidence. They should compare reboot times with inbound SAML requests, firewall records and identity-provider logs. Checks should include nsaaad crash messages, files in /var/core , recent configuration changes, unknown administrator sessions and unusual outbound traffic. Any temporary blocking rule should be treated as a short bridge, since source addresses can change. Organizations must also confirm the installed build on every active and standby node. Citrix’s CTX697096 bulletin lists 14.1-73.37, 13.1-64.23 and matching FIPS or NDcPP releases as the zero-day fixes. Patching stops new use of those flaws, but it does not remove web shells or access gained before the update. That warning is important because earlier Cybersecurity News coverage described observed root access, hidden web shells and internal tunneling tied to the September campaign. Readers can also review the site’s original zero-day report for affected builds and exposure details. Until Citrix ships its next update, affected customers should keep severity-one support cases open, use only vendor-provided mitigation steps, and treat unexplained reboots as both an uptime event and a possible security incident. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post Citrix NetScaler Keeps Rebooting Following the 0-Day Patch appeared first on Cyber Security News .
001
InfoSec @infosec.skyfleet.blue · 03/10/2026
Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Privilege Escalation Attacks
cybersecuritynews.com
Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Privilege Escalation Attacks
Debian has released a major Linux kernel security update covering 1,313 CVE entries, addressing flaws that could allow privilege escalation, denial of service, and information leaks. The fixes are available for Debian’s stable release, Trixie, in Linux source package version 6.12.111-1. Security team member Salvatore Bonaccorso published advisory DSA-6528-1 on September 29, 2026. Debian recommends upgrading the affected linux packages. Importantly, the update prevents potential attacks; the advisory does not say that installing it causes security problems or that attackers have exploited these flaws in the wild. Debian Security Flaws The advisory brings together vulnerabilities with CVE identifiers from 2024, 2025, and 2026. Listed examples include CVE-2024-52560 , CVE-2025-21817, CVE-2026-23137, and CVE-2026-100079. These are individual entries in one kernel advisory, not 1,313 separate Debian packages or confirmed attacks. Debian’s security tracker marks Linux version 6.12.107-1 in Trixie as vulnerable and 6.12.111-1 from the security repository as fixed. This gives administrators a clear package version to check when reviewing patch status, rather than relying only on a general claim that a machine is updated. The large total should not be read as proof that every flaw affects every Debian installation equally. Debian explains that a CVE identifier alone does not establish a serious threat to a particular system. Its security team assesses each issue in the Debian context, and lower-impact fixes can be included alongside more serious vulnerabilities. According to advisory coverage published by LWN , Debian identifies three possible outcomes: privilege escalation, denial of service, and information leaks. However, the announcement does not provide a technical breakdown for each CVE, a shared attack method, or a severity score for the entire update. Claims that all listed bugs enable remote takeover would therefore go beyond the published evidence. Privilege escalation can let an attacker move from limited access to higher permissions. Cybersecurity News previously covered a Linux kernel privilege escalation flaw , CVE-2023-3390, where an integer overflow in Netfilter could allow writes to kernel memory and potentially grant root access. That older case illustrates the risk; it is not among the CVEs listed in this advisory. Denial of service threatens system availability, while information leaks can expose data that should remain protected. The practical risk of any listed flaw needs to be checked against its own tracker entry, rather than inferred from the size of this patch release. Administrators should refresh package lists with sudo apt-get update, then apply available updates with sudo apt-get upgrade. Debian’s security FAQ notes that advisories name source packages, so users must update the relevant installed binary packages built from those sources. For kernel updates, plan a reboot into the patched kernel and verify the running version afterward with uname -r. Also check the installed package version against Debian’s advisory, since the running kernel release string and source package version use different formats. Teams should record the installed kernel package, the update time, and the reboot result in their patch records. Keeping this evidence makes it easier to separate machines that downloaded the fix from those actually running the corrected kernel after restart. Debian’s security information page also recommends unattended-upgrades for automatic security updates. Automation can reduce patch delays, but administrators should still confirm that kernel updates have taken effect. For this release, the key reference is DSA-6528-1 and its fixed Trixie package version, 6.12.111-1. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Privilege Escalation Attacks appeared first on Cyber Security News .
030
InfoSec @infosec.skyfleet.blue · 03/10/2026
U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
securityaffairs.com
U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog.
010
InfoSec @infosec.skyfleet.blue · 02/10/2026
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
schneier.com
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
000
InfoSec @infosec.skyfleet.blue · 02/10/2026
Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus
therecord.media
Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus
The plaintiffs, who all worked for the independent and Salvadoran news outlet El Faro, failed to convince the court that their case had jurisdiction in California, according to the judge’s order.
010
InfoSec @infosec.skyfleet.blue · 02/10/2026
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
darkreading.com
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.
000
InfoSec @infosec.skyfleet.blue · 02/10/2026
CVE-2026-103885: Apache Directory LDAP API: Denial of service via crafted telephone number values
seclists.org
oss-sec: CVE-2026-103885: Apache Directory LDAP API: Denial of service via crafted telephone number values
Posted by Emmanuel Lécharny on Oct 02 Severity: important Affected versions: - Apache Directory LDAP API 2.1.0 before 2.1.9 Description: Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version...
011
InfoSec @infosec.skyfleet.blue · 02/10/2026
CVE-2026-103880: Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwords
seclists.org
oss-sec: CVE-2026-103880: Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwords
Posted by Emmanuel Lécharny on Oct 02 Severity: important Affected versions: - Apache Directory LDAP API 2.1.0 before 2.1.9 Description: Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to  run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS. This issue affects...
000
InfoSec @infosec.skyfleet.blue · 02/10/2026
CVE-2026-103878: Apache Directory LDAP API: Injection of plaintext responses during StartTLS
seclists.org
oss-sec: CVE-2026-103878: Apache Directory LDAP API: Injection of plaintext responses during StartTLS
Posted by Emmanuel Lécharny on Oct 02 Severity: important Affected versions: - Apache Directory LDAP API 2.1.0 before 2.1.9 Description: Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are...
010
InfoSec @infosec.skyfleet.blue · 02/10/2026
Bipartisan backlash to ALPRs grows as two high-profile bills are introduced
therecord.media
Bipartisan backlash to ALPRs grows as two high-profile bills are introduced
Republican Sen. Josh Hawley has new legislation on limiting automated license plate readers (ALPRs), while Democratic Sens. Bernie Sanders and Jeff Merkley, with Rep. Alexandria Ocasio-Cortez, have teed up a broader bill.
021
InfoSec @infosec.skyfleet.blue · 02/10/2026
CVE-2026-103877: Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements
seclists.org
oss-sec: CVE-2026-103877: Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements
Posted by Emmanuel Lécharny on Oct 02 Severity: critical Affected versions: - Apache Directory LDAP API 2.1.0 before 2.1.9 Description: Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE.  This issue affects Apache Directory LDAP API: from 2.1.0 before...
000
InfoSec @infosec.skyfleet.blue · 02/10/2026
CVE-2026-103552: Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder
seclists.org
oss-sec: CVE-2026-103552: Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder
Posted by Emmanuel Lécharny on Oct 02 Severity: critical Affected versions: - Apache Directory LDAP API 1.2.0 before 1.2.9 Description: Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue. Credit: Claude...
000
InfoSec @infosec.skyfleet.blue · 02/10/2026
CVE-2026-102731: Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode
seclists.org
oss-sec: CVE-2026-102731: Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode
Posted by Emmanuel Lécharny on Oct 02 Severity: critical Affected versions: - Apache Directory LDAP API 1.2.0 before 1.2.9 Description: Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service. The client JVM OOMs (OutOfMemoryError bypasses the...
000
InfoSec @infosec.skyfleet.blue · 02/10/2026
CVE-2026-59265: Apache OpenOffice: Opening a malicious document can lead to system takeover
seclists.org
oss-sec: CVE-2026-59265: Apache OpenOffice: Opening a malicious document can lead to system takeover
Posted by Dave Fisher on Oct 02 Severity: critical Affected versions: - Apache OpenOffice through 4.1.16 - Apache OpenOffice before 95923fd437e06edd38a4f0e139a27c755a6f3ba6 - Apache OpenOffice before 181421139242694b309751fb666406eddc203c50 Description: A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected...
000
InfoSec @infosec.skyfleet.blue · 02/10/2026
CVE-2026-102795: Apache Traffic Server: SNI to Host header matching policy is not properly enforced (supersedes CVE-2026-41920)
seclists.org
oss-sec: CVE-2026-102795: Apache Traffic Server: SNI to Host header matching policy is not properly enforced (supersedes CVE-2026-41920)
Posted by Masakazu Kitajo on Oct 02 Severity: moderate Affected versions: - Apache Traffic Server 9.0.0 through 9.2.14 - Apache Traffic Server 10.0.0 through 10.1.3 Description: Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed...
010
InfoSec @infosec.skyfleet.blue · 02/10/2026
Frontline Education breach exposes school district employee data
bleepingcomputer.com
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
000