Sign in

Sami Laiho

@samilaiho.com
1.7K followers 183 following 4.5K posts

Keynote-speaker, Chief Research Officer, Microsoft MVP since 2011 More info: samilaiho.com

PostsRepliesMedia
Sami Laiho @samilaiho.com · 9h
sec.cloudapps.cisco.com/security/cen...
sec.cloudapps.cisco.com
Cisco Security Advisory: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the ...
000
Sami Laiho @samilaiho.com · 11h
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks thehackernews.com/2026/09/hack...
thehackernews.com
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
NeedyMantis maintains long-term access in targeted intrusions, using DLL sideloading and HTTPS-to-WebSocket command-and-control.
000
Sami Laiho @samilaiho.com · 11h
Kiteworks patches critical flaw, brings customer systems online www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Kiteworks patches critical flaw, brings customer systems online
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability.
000
Sami Laiho @samilaiho.com · 11h
Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances cloud.google.com/blog/topics/...
cloud.google.com
Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances | Google Cloud Blog
GTIG is tracking exploitation of critical vulnerabilities in Citrix NetScaler ADC NetScaler Gateway products.
000
Sami Laiho @samilaiho.com · 11h
Star Blizzard refines phishing and malware delivery with the RedFlick technique www.microsoft.com/en-us/securi...
microsoft.com
Star Blizzard refines phishing and malware delivery with the RedFlick technique | Microsoft Security Blog
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromis...
000
Sami Laiho @samilaiho.com · 11h
Apple patches CoreGraphics zero-day flaw exploited in attacks www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
010
Sami Laiho @samilaiho.com · 17h
Multiple Vulnerabilities in HPE Networking Instant On APs URL: support.hpe.com/hpesc/public... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
support.hpe.com
000
Sami Laiho @samilaiho.com · 17h
Critical vulnerabilities in Hitachi Energy RTU500 URL: publisher.hitachienergy.com/preview?Docu... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
publisher.hitachienergy.com
Hitachi Energy Publisher
000
Sami Laiho @samilaiho.com · 17h
GitLab Critical Patch Release URL: docs.gitlab.com/releases/pat... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9
docs.gitlab.com
GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7 | GitLab Docs
Learn more about GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7 for GitLab Community Edition (CE) and Enterprise Edition (EE).
000
Sami Laiho @samilaiho.com · 17h
Critical PyJWT URL: github.com/jpadilla/pyj... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
github.com
Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard, permitting HS256 token forgery under a mixed algorithm allow-list.
**Prerequisites** (both conditions must hold; both are deployment properties, not attacker-controlled at request time): - The `jwt.decode` allow-list mixes an HMAC algorithm with an asymmetric one...
000
Sami Laiho @samilaiho.com · 17h
CISA Releases Seven Industrial Control Systems Advisories URL: www.cisa.gov/news-events/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0
cisa.gov
Viidure Dashcam Android Application | CISA
000
Sami Laiho @samilaiho.com · 29/09/2026
www.wiz.io/blog/infoste...
wiz.io
The Infostealer Incursion: Cloud, Code & AI Breaches | Wiz Blog
Wiz Research analyzes NordStellar data to map credentials targeted by infostealers and assess their impact across cloud, code, and AI environments.
000
Sami Laiho @samilaiho.com · 29/09/2026
"How I got RCE and full cloud takeover on Meta at their in-person event in Taiwan" zonduu.me/posts/meta-g...
zonduu.me
Root RCE and full cloud takeover on a Meta service
A hardcoded key plus two path traversals plus an unsafe pickle load, chained into root RCE and a full cloud compromise on a Meta service.
010
Sami Laiho @samilaiho.com · 29/09/2026
Nordix Infrastructure by OpenInfra Europe AISBL Compromised lists.openssf-vuln.org/g/siren/mess...
lists.openssf-vuln.org
000
Sami Laiho @samilaiho.com · 29/09/2026
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions www.darkreading.com/application-...
darkreading.com
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
A purported ad-blocker exfiltrates reams of sensitive information and benefits from having Google's stamp of approval despite researcher warnings.
010
Sami Laiho @samilaiho.com · 29/09/2026
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent thehackernews.com/2026/09/carb...
thehackernews.com
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
Carbonato targets unauthenticated Docker daemons, installs Hermes Agent, and uses Telegram to run operator-directed AI-generated commands.
011
Sami Laiho @samilaiho.com · 29/09/2026
JadePuffer agentic AI attacks target Azure, destroy cloud resources www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
010
Sami Laiho @samilaiho.com · 29/09/2026
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild unit42.paloaltonetworks.com/netscaler-ze...
unit42.paloaltonetworks.com
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild.
000
Sami Laiho @samilaiho.com · 29/09/2026
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations www.microsoft.com/en-us/securi...
microsoft.com
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations | Microsoft Security Blog
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible component...
000
Sami Laiho @samilaiho.com · 29/09/2026
www.microsoft.com/en-us/downlo...
microsoft.com
Download Administrative Templates (.admx) for Windows 11 2026 Update (26H2) from Official Microsoft Download Center
This page provides complete set of Administrative Templates (.admx) for Windows 11 2026 Update (26H2)
000
Sami Laiho @samilaiho.com · 29/09/2026
Multiple critical vulnerability in Apache Roller URL: www.openwall.com/lists/oss-se... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9
openwall.com
oss-security - CVE-2026-82375: Apache Roller: Server-side request forgery via entry trackback and enclosure URLs
000
Sami Laiho @samilaiho.com · 28/09/2026
krebsonsecurity.com/2026/09/dutc...
krebsonsecurity.com
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security
010
Sami Laiho @samilaiho.com · 28/09/2026
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials thehackernews.com/2026/09/lune...
thehackernews.com
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Lunex uses BYOVD to disable kernel security callbacks before stealing browser credentials and cryptocurrency wallets.
010
Sami Laiho @samilaiho.com · 28/09/2026
Cloudflare fixes Containers cross-tenant flaw exposing customer data www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host.
110
Sami Laiho @samilaiho.com · 28/09/2026
Critical vulnerabilities in in Citrix NetScaler ADC and Citrix NetScaler Gateway URL: support.citrix.com/support-home...
support.citrix.com
Loading...
000
Sami Laiho @samilaiho.com · 27/09/2026
hackingpassion.com/file-notific...
hackingpassion.com
File Notification Attacks Leak Keystrokes, Websites and WhatsApp Photos on Windows, Linux, Android and macOS
Microsoft calls it by design. First reported in 2007, the leak shows another account your Firefox visits, and the April 2025 fix ships switched off.
010
Sami Laiho @samilaiho.com · 27/09/2026
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence thehackernews.com/2026/09/pams...
thehackernews.com
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
PamStealer now uses live key exchange to block static payload recovery and is delivered through a fake Wavel macOS download.
000
Sami Laiho @samilaiho.com · 27/09/2026
GitHub Actions re-enabled with Mini Shai-Hulud payload still active www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious...
000
Sami Laiho @samilaiho.com · 27/09/2026
Using Threat Intelligence to Track and Disrupt Ransomware Attacks www.recordedfuture.com/blog/ransomw...
recordedfuture.com
Using Threat Intelligence to Stop Ransomware Attacks
Learn how ransomware threat intelligence empowers your team to actively follow adversary infrastructure, monitor dark web chatter and prevent attacks.
000
Sami Laiho @samilaiho.com · 27/09/2026
Critical vulnerability in OpenClaw URL: github.com/openclaw/ope... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.0
github.com
iOS Control UI did not enforce saved Gateway TLS pins
### Summary The iOS Control UI did not enforce saved Gateway TLS pins. In affected versions, authenticated Terminal and session Dashboard WebViews omitted the saved Gateway fingerprint even though...
010
Sami Laiho @samilaiho.com · 26/09/2026
Imminent Zero-Day Attack: KiteWorks Urges Customers to Shut Down Servers www.heise.de/en/news/Immi...
heise.de
Imminent Zero-Day Attack: KiteWorks Urges Customers to Shut Down Servers
Manufacturer writes to its customers that they have concrete indications from law enforcement about an attack. Large companies are also affected in this country.
000
Sami Laiho @samilaiho.com · 26/09/2026
Russia's Hybrid Cyber-Physical War in Europe Heats Up www.darkreading.com/physical-sec...
darkreading.com
Russia's Hybrid Cyber-Physical War in Europe Heats Up
A storm is raging in the form of cyber sabotage, disinformation, and drone attacks on European nations, particularly those that provide support to Ukraine.
010
Sami Laiho @samilaiho.com · 26/09/2026
CISA: Ransomware gangs now exploiting critical TeamCity flaw www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
CISA: Ransomware gangs now exploiting critical TeamCity flaw
​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched...
000
Sami Laiho @samilaiho.com · 26/09/2026
Kothamine malware uses Tailscale’s tailcat to evade network detection www.malwarebytes.com/blog/threat-...
malwarebytes.com
Kothamine malware uses Tailscale’s tailcat to evade network detection
Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block.
000
Sami Laiho @samilaiho.com · 26/09/2026
WordPress arbitrary code execution vulnerability www.kaspersky.com/blog/cve-202...
kaspersky.com
CVE-2026-87902: Critical Vulnerability in WordPress
We explain in simple terms why the CVE-2026-87902 vulnerability is dangerous, and how to protect your company against it.
010
Sami Laiho @samilaiho.com · 26/09/2026
Master Key Included: Detecting SolarWinds ARM CVE-2026-28326 bishopfox.com/blog/detecti...
bishopfox.com
Master Key Included: Detecting SolarWinds ARM CVE-2026-28326
CVE-2026-28326 is an unauthenticated RCE in SolarWinds ARM where a hardcoded shared secret on TCP 55555 leads to SYSTEM-level code execution. Patch now.
000
Sami Laiho @samilaiho.com · 26/09/2026
Critical vulnerabilities in Zimbra Collaboration Suite URL: nvd.nist.gov/vuln/detail/... Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
nvd.nist.gov
NVD - Home
000
Sami Laiho @samilaiho.com · 26/09/2026
krebsonsecurity.com/2026/09/u-s-...
krebsonsecurity.com
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions – Krebs on Security
010
Sami Laiho @samilaiho.com · 25/09/2026
nypost.com/2026/09/23/u...
nypost.com
Sinister network of Russian agents busted in Cold War-style plot to infiltrate the US Secret Service using American tech CEO
The alleged deception could have given Russian agents a foothold inside a company providing technology to government customers.
010
Sami Laiho @samilaiho.com · 25/09/2026
Ukrainian ransomware developer jailed for nearly 13 years www.bitdefender.com/en-us/blog/h...
bitdefender.com
Ukrainian ransomware developer jailed for nearly 13 years
A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the wo...
010
Sami Laiho @samilaiho.com · 25/09/2026
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) labs.watchtowr.com/is-this-a-jo...
labs.watchtowr.com
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, a...
010
Sami Laiho @samilaiho.com · 25/09/2026
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments www.microsoft.com/en-us/securi...
microsoft.com
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments | Microsoft Security Blog
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to he...
000
Sami Laiho @samilaiho.com · 25/09/2026
JetBrains TeamCity - Actively Exploited Critical Vulnerability URL: blog.jetbrains.com/teamcity/202... Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 9.8
blog.jetbrains.com
CVE-2026-63077: Additional Guidance Following Reports of Active Exploitation - The JetBrains Blog
This post is a follow-up to our July 27, 2026, announcement about CVE-2026-63077. Summary Since our initial announcement on July 27, 2026, we have received reports of active exploitation, as we
000
Sami Laiho @samilaiho.com · 24/09/2026
www.it-connect.tech/nightmare-ec...
it-connect.tech
Windows Zero-Days: Nightmare Eclipse Reveals Identity and Firing
Nightmare Eclipse says he is Abdelhamid Naceri, a former MSRC researcher. Discover his account of the Microsoft firing and lawsuit.
001
Sami Laiho @samilaiho.com · 24/09/2026
How device code phishing gives scammers access to your account www.malwarebytes.com/blog/how-to/...
malwarebytes.com
How device code phishing gives scammers access to your account
A scammer asks you to enter a code to open a file or join a meeting. Approving it could sign them in to your account instead.
010
Sami Laiho @samilaiho.com · 24/09/2026
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in...
100
Sami Laiho @samilaiho.com · 24/09/2026
Ryuk ransomware member sentenced to 24 months in prison www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Ryuk ransomware member sentenced to 24 months in prison
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks.
010
Sami Laiho @samilaiho.com · 24/09/2026
WordPress Core – Critical Path Traversal Vulnerability URL: wordpress.org/news/2026/09... Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv4.0: 9.2
wordpress.org
WordPress 7.1.2 Release
This security release features a fix for a critical severity security vulnerability. Because this is a security release, it is recommended that you update your sites immediately. You can download W…
000
Sami Laiho @samilaiho.com · 23/09/2026
NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past www.theregister.com/security/202...
theregister.com
NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past
BigDiskBuster leaves Microsoft's antivirus running but unable to install updates
010
Sami Laiho @samilaiho.com · 23/09/2026
When AI infrastructure becomes the target: Securing gateways and control points www.microsoft.com/en-us/securi...
microsoft.com
When AI infrastructure becomes the target: Securing gateways and control points | Microsoft Security Blog
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity.
000