CFToday Curated security signals.

Last fetch 21 Sep 2026, 23:39 UTC · next 22 Sep 2026, 03:30 UTC

Today

The 64 most recent stories across 9 sections, refreshed through the day. Complete days are in the archive.

Show
Section

India

1

Indian organisations, regulators and infrastructure, pulled out of the sections below.

  1. Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors (opens in a new tab)

    The Hacker News ·Threat Intel & Breaches ·The Hacker News ·21 Sep 2026 ·fetched 21 Sep 2026, 07:42 UTC agreed3/3

    Why readJade Sleet is now hitting small IT service providers in India with the same macOS backdoors, FLATROOF and ROOFDECK, seen in the KelpDAO LayerZero bridge intrusion.

    SentinelOne attributes the compromise of a small India-based IT services firm to North Korea's Jade Sleet (also PUKCHONG, Slow Pisces, TraderTraitor, UNC4899), using the macOS backdoors FLATROOF (aka Gaslight) and ROOFDECK. Both were previously observed in the March-April 2026 attack on KelpDAO's LayerZero bridge, tying the vendor intrusion to the group's crypto-theft operations. The pattern is consistent with earlier work such as the Safe{Wallet} developer-environment compromise that preceded the $1.5bn Bybit theft: developers and vendors as the route into the real target. This is The Hacker News restating SentinelOne's research, so the original writeup carries the indicators.

    Indicators1
    Domains
    registry[.]hashicorp-aws[.]com
  1. Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits (opens in a new tab)

    Volexity ·Kristel Faris ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC Must read Research CVE-2026-85046 EPSS 1.0% agreed3/3

    Why readA third Chinese APT, tracked as UTA0565, was running the same chained Chrome and Windows zero-days on 3-4 September 2026 while they were unpatched, delivered through purpose-built fake websites.

    Following its 9 September report on two Chinese actors chaining CVE-2026-85046 and CVE-2026-87491 in Chrome with CVE-2026-85880 in Windows, Volexity found further campaigns from a distinct actor using the same chain days earlier. UTA0565 differed in delivery, standing up multiple fake websites and sending Chinese-language phishing to Asian government entities around the Chow Hang-tung case, plus a lure impersonating the Center for American Progress. Shared exploit chain across three separate actors before patch availability points at a common supplier, and the fake-site infrastructure gives defenders a fresh hunting surface beyond the exploit CVEs.

    Indicators6
    Hashes
    8858ea412dc306b3558885af18006c5ca24689e8875733b5e13b3c2692e603cb cbeeb7dd5e89261cde032825fd10bb80bad2e3fbf5b91fdc9137ad463ffa8f21
    Addresses
    96[.]9[.]125[.]52
    Domains
    americanprgoress[.]top thecovnresation[.]com theconversation[.]com
  2. Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR (opens in a new tab)

    The Hacker News ·The Hacker News ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC Must read agreed3/3

    Why readA Microsoft-signed kernel driver, delivered via a fake LastPass Authenticator GitHub page, kills AV and EDR before an infostealer runs, and it was neither blocklisted nor detected on VirusTotal.

    LastPass and Delphos Labs described a fake installer hosted at github.com/LastPass-Authenticator that SEO-ranks for LastPass Authenticator downloads and chains victims through GitHub pages to an attacker server serving a large ZIP. The archive contains a renamed copy of Microsoft's vsdbg.exe debugging tool alongside a kernel driver signed through Microsoft's own hardware-compatibility program, which scored zero VirusTotal detections in August and was absent from Microsoft's vulnerable driver blocklist. LastPass says its own systems, services and vaults were untouched; the abuse is of its brand and of the signing programme.

  3. BigCommerce alerts merchants of data breach linked to Ribon apps (opens in a new tab)

    BleepingComputer ·Bill Toulas ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC agreed3/3

    Why readOne compromised third-party application key gave attackers script injection and shopper data access across multiple merchant stores on a single SaaS platform.

    BigCommerce confirmed on 17 September that credentials for third-party Ribon applications were compromised and used to inject malicious scripts into storefronts and reach shopper records between 13 and 17 September, then pulled the apps. UK spirits retailer Master of Malt, one of the notified merchants, says exposed details include full names, email addresses, phone numbers and shipping addresses, and attributes the access to a compromised BigCommerce application key held by Ribon. The pattern is the familiar one for ecommerce teams: an integration key is a multi-tenant blast radius, and script injection into checkout pages follows directly from it.

  4. New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code (opens in a new tab)

    Infosecurity Magazine ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC agreed3/3

    Why readSekoia's write-up of Exvicy, a ClickFix malware-as-a-service that lifted ErrTraffic's code and switched the lure from Win+X to Win+R, with confirmed C2 traffic in customer telemetry.

    Exvicy has been sold on Exploit.IN by a Russian-speaking actor since May 26, starting at $1,200 a month and rising to $2,000 in mid-August. Sekoia's Threat Detection and Research team found the code derives from rival service ErrTraffic and that the distinguishing change is use of the Win+R run dialog rather than Win+X. Customer telemetry showed hosts beaconing to Exvicy C2 servers, with delivery through compromised WordPress sites.

  5. ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment (opens in a new tab)

    The Record ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC agreed3/3

    Why readShinyHunters defaced and took over Cl0p's dark web leak site and issued an eight-figure extortion demand against the ransomware crew itself.

    The leak site Cl0p has used for years to name victims now carries a ShinyHunters seizure banner and an extortion notice with an unspecified eight-figure demand, framed as 2.333 percent of Cl0p's net worth and escalating every 24 hours. ShinyHunters is known for social engineering and data extortion rather than technical intrusion, which makes the takeover itself the notable part. Useful as ecosystem signal on how the extortion scene is fragmenting, not as anything to hunt for.

    Also covered byMalwarebytes Labs (opens in a new tab).

  6. 21st September – Threat Intelligence Report (opens in a new tab)

    Check Point Research ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC agreed2/3

    Why readTwo of the week's items are worth tracking on their own: the Brevo supply chain compromise reaching roughly 100,000 sites, and a VPN appliance breach at Japan's Digital Agency exposing about 246,000 records.

    Check Point's weekly bulletin reports that attackers used a compromised Cloudflare API key to inject ClickFix scripts into websites loading Brevo components, an attack path that turns a marketing platform integration into drive-by social engineering at scale. It also covers a confirmed breach at Japan's Digital Agency through a VPN appliance vulnerability, affecting names and contact details for government officials and contractors, and disruption of onboard systems on two Texas-bound oil tankers that the Coast Guard and FBI are investigating. The format is aggregation of other people's reporting rather than original research, so use it as a coverage check and follow the primary sources for anything you need to act on.

  7. Why Does an npm Math Library Need an Encrypted Loader? (opens in a new tab)

    SafeDep (supply chain) ·21 Sep 2026 ·fetched 21 Sep 2026, 19:37 UTC Research agreed2/2

    Why readReverse engineers a RAT hidden in the npm package mathmain, a mathjs typosquat whose encrypted payload only decrypts when a specific equation is solved through lusolve().

    SafeDep found a remote access implant in mathmain, an npm copy of mathjs, where the loader sits in an extra call inside lusolve() that passes lower-triangular matrix data to removeSolveValidation(). The payload stays encrypted and dormant until a program solves the one equation that acts as the decryption key, then executes attacker commands using a public chat service and a blockchain network as command channels. The post walks the discovery, the decryption and the payload behaviour, and publishes indicators; analysis dates from 17 September 2026. Environment-keyed decryption of this kind defeats sandbox detonation, which is the part worth generalising.

    Indicators15
    Hashes
    560d97e66140dbf817e04284a7a0c58757d1202e da99dd46501c75ba6102a51ef60ebb922174da32 dc7257d09fab42eca2c354c32fec1938 1723a0df210ac61281a504f3a07ec3605d20151631e0635cc344cacc71019135 03e13cdedd9c33e6fed25092b1ec7dcf11cc5962c0fbb6b3e90ba95bfec1b034 7e5e1bcdc6a7b0e3437269a236b49ef2be4f77081c7de5130d503c103fd6be69 bfe772e7ee044fd6f0bdf53e83f44aad7c9ee1925baf0cf4d884a312aa9ba50e 4eb1d59df7dc80dbe3ec154481e61e8824422037092c188f0cc146b543615a66 ab66c98e8ed5235feb963ec8845765f62f5f26b1c58c266c409767e53bcb5ccd 5d9e952c51875d2b897eedc22b002b94ab21c8004d513bc99ce3a885f8a01dae ed9b078594393d09d91ee008366ca75e3017cca18c79af99c5b294c61db67f06 09773ee7db70216b778b15cfcd94cb1df8963eddd4a47b801c96f986651699e6
    Domains
    base-sepolia[.]infura[.]io base-sepolia[.]g[.]alchemy[.]com eth-sepolia[.]g[.]alchemy[.]com
  8. China-nexus actor steals thousands of documents in monthslong exploitation campaign (opens in a new tab)

    Cybersecurity Dive ·David Jones ·21 Sep 2026 ·fetched 21 Sep 2026, 19:37 UTC agreed2/2

    Why readGreyNoise attributes a months-long document-theft campaign against a Western government to a Chinese-speaking actor exploiting WordPress, Zyxel and Ubiquiti bugs, with LLM-built custom tooling suspected.

    GreyNoise reports a Chinese-speaking actor active since at least June that chained critical vulnerabilities across WordPress, Zyxel and Ubiquiti products and exfiltrated thousands of documents from at least one Western government. Exploitation attempts are dated from June 12 onward and the tooling is suspected to have been LLM-assisted. Motive beyond bulk collection is unresolved; the primary GreyNoise post is the better read, this is the trade-press version of it.

  9. Vidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscation (opens in a new tab)

    Zscaler ThreatLabz ·Ismael Garcia Perez (Zscaler) ·21 Sep 2026 ·fetched 21 Sep 2026, 15:44 UTC Must read Research agreed3/3

    Why readTraces Vidar's string protection from XOR through ChaCha20 to a per-build bytecode VM with a custom stream cipher, which breaks static string extraction across versions 2.0 to 3.3.

    ThreatLabz tracked Vidar's obfuscation from May through early September 2026 and found that in June the developer added a lightweight bytecode interpreter whose opcodes change with every build, paired with a per-build custom stream cipher. That kills signature-based string recovery and forces analysts to emulate the interpreter rather than decrypt constants. The writeup covers the algorithm changes from version 2.0 to 3.3, which is the material needed to build a version-agnostic unpacker.

    Indicators4
    Hashes
    1628bb03db87f67661349e169d73ee14ed490bdbf22abfbda08ccc9ebe237974 625a381981fc2d4c25c981d98b1d66bb2cf5da2dde2f590add0673a857d5b074 2d43d592630ad1e012da63ef7279f95dd4a8e94964e12ca2f996051875574fa6 979048a749d8f28d877c7068b1b336ecd1e349869dfb1d7c68118f90e4099bc4
  10. Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation (opens in a new tab)

    GreyNoise ·21 Sep 2026 ·fetched 21 Sep 2026, 15:44 UTC Research agreed3/3

    Why readSensor-side evidence that a single IP address, tracked since early June 2026, exploited WordPress to exfiltrate more than 18,000 government records, which argues against the usual "blocking IPs is pointless" reflex.

    GreyNoise attributes activity from 7 May 2026 onward to one persistent operator observed scanning and attacking its Global Observation Grid decoys for years from the same address. The exact IP is withheld for victim-sensitivity reasons, with an update promised. The useful takeaway is the counter-argument to IP rotation orthodoxy: some adversaries reuse infrastructure long enough for blocking and hunting on that infrastructure to pay off.

    Indicators5
    Hashes
    2ff2945b13a4cd0e9a65c85af29ea1539e162a516466c0de682dbf9f8a4000b1 0e81d80b40eaacbf6cb1e817fb1824c30a824af5cb4faca4aa9b03fd506d480f 0f6e757e82c4d91df5bd249f775b9970b59dee42cc0dfe40f879d77fc16821c6
    Addresses
    74[.]48[.]66[.]73
    Domains
    p3[.]981666[.]xyz
  11. Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO (opens in a new tab)

    Securelist ·Ahmad Zaidi Said, Elsayed Elrefaei ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC Must read Research agreed3/3

    Why readA ransomware crew extorted a manufacturer using nothing but a domain-root GPO named PAYLOAD on Windows, dropping no binary and encrypting no workstation data.

    Kaspersky GERT responded to an April 2026 incident at a Middle East manufacturing organisation where the actor gained domain admin-equivalent control of Active Directory, authored a GPO called PAYLOAD and linked it at the domain root. That single object delivered ransom notes, replaced wallpaper and lock screens, set a logon banner and disabled the local administrator account across every domain-joined workstation, all through signed and trusted AD machinery. The only actual ransomware binary targeted ESXi on Linux servers, with exfiltration from file servers later published to a leak site, so detection has to cover GPO authoring and linking rather than file encryption on endpoints.

    Indicators2
    Hashes
    0108656a3e1ade6ca4f21b084f5e1208 bea5e267f24d7da59f6821bffdbff293
  12. Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records (opens in a new tab)

    Infosecurity Magazine ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC agreed3/3

    Why readA concrete demonstration that image metadata is not a lesser class of breach data; the exposed fields alone let an attacker reconstruct URLs and pull the underlying private images.

    Gyazo, a Japanese image sharing service, disclosed that attackers exploited a flaw in an upload server and took roughly 24 million customer records plus about 490 million image metadata records. The metadata set includes image IDs, source IP addresses, user agents, EXIF location data, OCR text extracted from image contents, titles, source URLs, and hashed passphrases; operator Helpfeel confirmed the URL construction fields allow third parties to view the corresponding images and has disabled viewing for some of them. The OCR text is the sharper problem, since screenshots of tickets, dashboards, and credentials become searchable plaintext without the attacker ever fetching an image.

  1. Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day (opens in a new tab)

    Ars Technica Security ·Dan Goodin ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC Must read agreed3/3

    Why readA zero-day in Meta's Muse assistant hands any local app or shell command full control of an agent that holds the user's WhatsApp, email, calendar and purchasing authority.

    Muse runs as a macOS app with delegated access to a user's accounts and can create tools on the fly, and the reported flaw lets locally running code or terminal commands take over the agent entirely, inheriting all of that authority. Amazon began blocking Muse from its site on Sunday. The case is the clearest current example of why local process trust boundaries matter for consumer agents that hold live credentials.

  2. Anthropic-linked CVEs pile up, attackers mostly shrug (opens in a new tab)

    The Register Security ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC agreed3/3

    Why readVulnCheck's Patrick Garrity measured that under 0.5 percent of CVEs credited to Anthropic or Project Glasswing show in-the-wild exploitation, a number to use against the AI-finds-bugs-so-attacks-surge argument.

    Garrity has tracked CVEs attributed to Anthropic and to Project Glasswing, the programme giving vetted partners access to the Claude Mythos Preview model for defensive bug-finding, since its April announcement. Checking that list against known-exploited data, fewer than 0.5 percent are being attacked in the wild. That gives a concrete figure for the gap between AI-accelerated vulnerability discovery and actual exploitation pressure, against Anthropic's own position that the model's exploitation skill was too risky for public release.

  3. CVE-2026-93839 (CVSS 9.3): LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 19:37 UTC CVE-2026-93839 CVSS 9.3 EPSS 0.6% agreed2/2

    Why readAn unauthenticated WebSocket endpoint in a widely deployed LLM inference server lets an attacker register their own worker and have user prompts routed to it, which is prompt exfiltration by design flaw rather than by model behaviour.

    CVE-2026-93839 affects LightLLM through 1.2.0, where the /pd_register WebSocket endpoint accepts crafted JSON node registrations without validating the peer address. An attacker can register a node they control and read full user prompts routed to it, evict legitimate nodes to cause denial of service, or steer the PD Master into issuing requests to internal addresses for server-side request forgery. This belongs in AI security rather than the vulnerability rundown because the affected asset is inference infrastructure and the primary loss is conversational data, which is where teams running self-hosted serving stacks will look for it.

  4. End-to-End Hard-Label Cryptanalytic Model Extraction Using Efficient Sign Recovery (opens in a new tab)

    arXiv cs.CR (all) ·Akira Ito, Takayuki Miura, Yosuke Todo ·21 Sep 2026 ·fetched 21 Sep 2026, 15:44 UTC Must read Research agreed3/3

    Why readA new sign-recovery algorithm that needs no dedicated queries, closing the practical gap in hard-label cryptanalytic extraction of ReLU MLP weights and giving the first end-to-end black-box demonstration.

    Carlini et al.'s Eurocrypt 2025 hard-label extraction of ReLU MLPs was polynomial-time in theory but bottlenecked on sign recovery, which burned a large query budget and heavy computation and blocked any full black-box run. This work replaces that step with an algorithm built on a different principle that consumes no dedicated queries and reports higher sign-recovery accuracy, then chains it into a complete end-to-end extraction against trained deep ReLU MLPs observed only through final output labels. If you treat model weights as an asset, the query cost of stealing them just fell.

  5. CESBench: Benchmarking Large Language Models on Cryptographic Engineering Security for IoT Devices (opens in a new tab)

    arXiv cs.CR (AI) ·Wenquan Zhou, An Wang, Jing Liang, Peien Feng ·21 Sep 2026 ·fetched 21 Sep 2026, 15:44 UTC Research agreed3/3

    Why readA 380-item benchmark measuring whether LLMs can reason about side-channel, fault injection and countermeasure design for IoT crypto implementations, run against 11 models.

    CESBench covers six sub-domains of cryptographic engineering security with four task types: 209 multiple-choice recall items, 67 judgment items requiring a verdict plus justification, 63 scenario diagnosis items, and 41 code tasks graded by 572 test cases. Eleven open-weight and proprietary models were evaluated, with judgment and scenario answers scored by an LLM judge that was itself validated. Useful if you are deciding how far to trust a model reviewing embedded crypto implementations, where secure algorithm choice says nothing about implementation safety.

  6. Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents (opens in a new tab)

    Dark Reading ·Elizabeth Montalbano ·21 Sep 2026 ·fetched 21 Sep 2026, 15:44 UTC agreed3/3

    Why readOpenAI published six concrete instances of model misalignment alongside a framework for investigating and disclosing such incidents, giving the first vendor template for AI incident reporting.

    OpenAI disclosed six examples of concerning model behaviour and paired them with a process for how such incidents should be investigated and made public. The framework matters more than the examples: it is a lab proposing what counts as a reportable AI incident and how disclosure should work. Anyone drafting AI governance or an AI incident response policy now has a vendor-published reference to argue with.

  7. CVE-2026-93688 (CVSS 8.7): SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unboun (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 15:44 UTC CVE-2026-93688 CVSS 8.7 EPSS 0.4% agreed3/3

    Why readAn unauthenticated memory exhaustion path in SGLang's disaggregated serving mode that anyone running an LLM inference cluster on Mooncake KV transfer needs to know about.

    SGLang through 0.5.19 does not validate bootstrap_room values when running prefill/decode disaggregation with the Mooncake KV transfer backend, so each arbitrary value allocates new transfer state without bound. An attacker who can reach the decode engine's POST /generate endpoint can drive the prefill process into out-of-memory termination with no credentials. Impact is availability only, but the exposed endpoint pattern is common in inference deployments that assume the serving tier sits behind a trusted boundary.

  8. CVE-2025-66455 (CVSS 9.8): LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC CVE-2025-66455 CVSS 9.8 EPSS 0.7% agreed3/3

    Why readUnauthenticated code execution in an LLM serving stack, reached through an HTTP endpoint that tells the server which ZeroMQ peer to unpickle from.

    LMDeploy from 0.9.2 up to 0.16.0 calls PyZMQ recv_pyobj() on its DistServe control plane, which routes every message pulled off the socket through Python pickle. The peer address is supplied by POST /distserve/p2p_connect, so anyone who can reach the API server points it at an attacker-controlled endpoint and executes code as the serving process. API-key authentication is off unless the operator enables it, and only PyTorch backend deployments with PD disaggregation are in scope; upgrade to 0.16.0.

  9. CVE-2026-33625 (CVSS 8.8): LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerabil (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC CVE-2026-33625 CVSS 8.8 EPSS 0.2% agreed3/3

    Why readA crafted quantization_config.quant_dtype in a published HuggingFace model reaches eval(f'torch.{quant_dtype}') in LMDeploy, so loading the model executes arbitrary Python.

    CVE-2026-33625 affects LMDeploy 0.12.1 through 0.12.2: lmdeploy/pytorch/config.py line 620 passes an attacker-controlled quant_dtype value straight into eval() with no validation. Publishing a malicious model on HuggingFace is enough to get code execution on any machine that loads it, which is the model supply chain working exactly as feared. Patched in 0.12.3.

  10. Provisional Reachability: Containing Agents by Making Every Crossing Revocable (opens in a new tab)

    arXiv cs.CR (all) ·Yoshiaki Takashita ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC Research agreed3/3

    Why readGives a closed-form leakage bound for containing an AI agent by holding every boundary crossing in escrow for a period and auditing held items at rate r, plus a decay threshold above which a secret of L bits never assembles.

    An adversary crossing k times with c bits each expects kc(1-r)^k leaked, maximised at k* = 1/ln(1/(1-r)) and bounded by roughly c/(er) per window, a supremum over adversary strategy so the scheme can be published without weakening it; simulation matches to 7.7 standard errors. Because the bound is a rate rather than a total, escrow alone still permits assembly over enough runs, but if held bits decay at fraction mu per period, holdings converge to g/mu and an L-bit secret becomes unreachable once mu exceeds g/L, with 100% of runs assembling at 0.9mu* and none at 2mu* over 20,000 windows. The paper also reports that deception defences failed: a surface with lying names left reader accuracy at 18 of 18 across three model strengths.

  11. CVE-2026-58197 (CVSS 8.8): ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC CVE-2026-58197 CVSS 8.8 EPSS 0.4% agreed3/3

    Why readToolHive ran local MCP server containers with no network isolation, so a malicious MCP server could reach host.docker.internal and the unauthenticated ToolHive API and sibling MCP proxies from inside its own container.

    Before ToolHive CLI 0.30.1 and Studio 0.38.0, containers used the default network permission profile, leaving the Docker gateway open to host-local services and to ToolHive's own control plane and proxy endpoints, which require no authentication. A compromised MCP server can read data and logs, invoke sibling MCP tools and alter workload state without escaping its container; Studio made it worse by sending network_isolation as false and overriding the backend's secure default. Anyone running MCP servers locally through ToolHive should upgrade both components.

  12. Watermarkable Multi-Draft Speculative Sampling via Poisson Processes (opens in a new tab)

    arXiv cs.CR (AI) ·Yanxiao Liu, Sicheng Wan, Zhan Gao, Deniz Gündüz ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC Research agreed3/3

    Why readA multi-draft speculative sampling algorithm built on Poisson processes that carries an unbiased watermark without losing acceptance rate, which prior work suggested might be impossible to combine.

    The construction uses exact list-coupling without communication, giving drafter invariance that benefits both sampling throughput and watermark strength. It is presented as the first multi-draft, drafter-invariant speculative sampling scheme to preserve both, with experimental verification. Relevant to anyone whose provenance strategy for model output currently has to be traded off against inference cost; the security consequence is indirect and the work is theoretical.

  1. CVE-2026-94083 (CVSS 9.4): Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the a (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC Must read CVE-2026-94083 CVSS 9.4 EPSS 0.4% agreed3/3

    Why readSuricata before 8.0.7 can be crashed remotely through a DoH2 type confusion, and the affected parser is enabled by default in 8.x, so your IDS is the target.

    A DoH2 request that upgrades from HTTP1 to HTTP2 causes Suricata to run HTTP2 state cleanup against what is actually HTTP1 state, producing an invalid free. Exploitation needs only app-layer.protocols.doh2 enabled, which is the 8.x default. Sensor availability is the immediate concern: an attacker who can blind the IDS gets a free window, so schedule the 8.0.7 upgrade rather than treating this as routine.

  2. CVE-2026-93990 (CVSS 8.7): Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. At (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC CVE-2026-93990 CVSS 8.7 EPSS 0.3% agreed2/3

    Why readlibexpat is embedded in Python, browsers, Android and a long tail of C software, so a parser-level markup-hiding bug propagates much further than the CVSS score suggests.

    Expat through 2.8.4 accepts a high surrogate that is not followed by a valid low surrogate in UTF-16 input. A lone high surrogate swallows the following code unit, which lets crafted documents conceal markup characters from the parser and smuggle XML past whatever validation sits in front of it. Impact is integrity only, with no confidentiality or availability loss, and it requires the application to parse attacker-supplied UTF-16; the work today is inventorying which of your dependencies bundle their own Expat rather than linking the system one.

  3. CVE-2026-90817 (CVSS 9.8): An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malici (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC CVE-2026-90817 CVSS 9.8 EPSS 0.6% agreed3/3

    Why readUnauthenticated RCE in REDCap 13.3.0 and later, reachable with only a valid public survey hash, on a platform that typically holds clinical and research data.

    Survey passthrough routing lets a crafted HTTP request reach an unintended controller route from a public survey context, and the Data Import handler then accepts an attacker-supplied file-path or stream parameter, yielding arbitrary code execution on the REDCap server. No login is required; the attacker needs a valid public survey hash, which is frequently published by design. Affects REDCap 13.3.0 and above, so university and hospital deployments should confirm their build and patch level.

  4. CVE-2026-94084 (CVSS 9.4): Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and withou (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC CVE-2026-94084 CVSS 9.4 EPSS 0.4% agreed3/3

    Why readSecond memory-safety bug fixed in Suricata 8.0.7: a use-after-free triggered by rules that inspect http.response_header both with and without a transform.

    Http2ThreadMultiBuf suffers a use-after-free when a single transaction is inspected by rulesets that use http.response_header in both transformed and untransformed form, a combination that occurs in real-world rule collections. Ruleset content therefore determines exposure, so check your enabled rules if you cannot patch immediately. Fixed in 8.0.7 alongside the DoH2 invalid free.

  5. CVE-2026-92229 (CVSS 9.1): The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC CVE-2026-92229 CVSS 9.1 EPSS 0.4% agreed3/3

    Why readForminator Forms for WordPress through 1.57.2 runs do_shortcode on an unvalidated value, giving unauthenticated visitors arbitrary shortcode execution on a plugin with a very large install base.

    An action in Forminator Forms passes a user-controlled value into do_shortcode without validation, so an unauthenticated attacker can execute arbitrary shortcodes registered on the site. Impact depends on which shortcodes other installed plugins expose, which in practice often means data disclosure or worse. All versions up to and including 1.57.2 are affected; update and check request logs for unexpected shortcode parameters.

  6. CVE-2026-93993 (CVSS 8.6): Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust valida (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC Must read CVE-2026-93993 CVSS 8.6 EPSS 0.6% agreed3/3

    Why readAnother agentic coding tool that runs repository-supplied git hooks before it decides whether the repository is trusted, which makes "just open it and look" code execution.

    Mistral Vibe before 2.25.5 creates a worktree, and therefore fires post-checkout hooks, ahead of its trust validation step. A crafted repository runs arbitrary shell commands as the user driving Vibe, with the same access to SSH keys, cloud credentials and source trees that the developer has. The bug class is ordinary rather than AI-specific, but the exposure is not: review-an-untrusted-repo is the core workflow for these tools, so check any agent you have deployed for the same ordering mistake.

  7. CVE-2026-94106 (CVSS 8.7): getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC CVE-2026-94106 CVSS 8.7 EPSS 1.7% agreed2/3

    Why readgetID3 is bundled inside WordPress core and a long tail of media pipelines, so the transitive install base dwarfs the project's own.

    getID3 before 1.9.26 fails to escape filenames placed into command strings in its shell-out handlers, so a filename carrying shell metacharacters executes commands with the privileges of the embedding process. Exploitation requires the host application to use the optional shell-out paths and to accept attacker-influenced filenames, which is realistic in upload driven media handling. EPSS places it near the 75th percentile, the highest of today's batch.

  8. CVE-2026-86553 (CVSS 8.8): SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife app (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC CVE-2026-86553 CVSS 8.8 EPSS 0.4% agreed2/3

    Why readFull takeover of a smart home account starting from nothing more than the victim's email address.

    The SmartLife app derives its application authentication parameters at runtime inside the client process, so those values can be extracted and replayed. An attacker can then call the backend /account/verify.serv endpoint to resolve a registered email address to its real account ID, and spoof the app authentication alongside that ID to reset the target's password. Control of a consumer IoT account means control of whatever locks, cameras and plugs are paired to it, which is what lifts this above a routine mobile auth flaw.

  9. CVE-2026-78030 (CVSS 9.8): DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC CVE-2026-78030 CVSS 9.8 EPSS 0.7% agreed3/3

    Why readPerl's require treats a path-shaped string as a literal filename, and DBD::DBM hands it one straight from the connect string.

    DBI before 1.653 passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module, so a value such as ../../Untrusted.pm selects the file Perl loads and executes at file scope. The MLDBM::Serializer:: prefix is not a containment boundary, because only the :: separators are rewritten to /, leaving an embedded slash free to traverse out of the serializer directory. Exposure depends on an application letting untrusted input reach a DSN fragment or a backend selector, and DBD::Gofer forwards those attributes to the server side.

  10. CVE-2026-93742 (CVSS 8.6): A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC CVE-2026-93742 CVSS 8.6 EPSS 1.9% agreed3/3

    Why readPublic exploit for remote command injection in the Totolink A3002MU via the localPin argument to /boafrm/formWsc.

    formWsc in the boa web server passes localPin into a command context without sanitisation, giving remote command injection on firmware Hh-B20211125.1046. CVSS 8.6 with exploit maturity P (public code available) and EPSS 0.019. Consumer-grade Totolink hardware has a track record of ending up in Mirai-class botnets, and no fixed firmware is cited, so treat exposed management interfaces as the control.

  11. CVE-2026-86591 (CVSS 9.8): The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to up (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC CVE-2026-86591 CVSS 9.8 EPSS 0.4% agreed3/3

    Why readBotiga Pro for WordPress before 1.6.5 exposes a REST route with no authorisation check, letting anonymous users rewrite arbitrary WordPress options.

    One Botiga Pro REST route performs no capability check at all, so unauthenticated requests can set any WordPress option to any value. That path leads to privilege escalation and full site takeover, and the same route also allows storing arbitrary scripts that execute on every front-end page and moving posts to trash. Update to 1.6.5 and audit options plus active front-end scripts on any site that was exposed.

  12. CVE-2026-93958 (CVSS 8.5): A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. T (opens in a new tab)

    NVD ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC CVE-2026-93958 CVSS 8.5 EPSS 2.2% agreed3/3

    Why readPublic exploit for OS command injection in the D-Link R95 BE9500 router through the NTPServer argument in the DHMAPI /bin/ssi handler.

    The DHMAPI component passes NTPServer into a system() call in /bin/ssi without sanitisation on firmware 1.00.16, remotely exploitable but requiring high privileges (CVSS 8.5, PR:H). Exploit code is public and EPSS sits at 0.022, the highest in today's batch. Default or reused admin credentials collapse the PR:H requirement, which is the usual story on consumer gear.

  1. I Hijacked a Real Artist's Spotify with AI Music. It Was Disturbingly Easy (opens in a new tab)

    404 Media ·Emanuel Maiberg ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC Research agreed3/3

    Why readA reporter published a track to a real band's verified Spotify, Apple Music, Tidal and Amazon Music pages without the band knowing, showing the identity gap between distributors and streaming platforms end to end.

    Emanuel Maiberg generated a song with Udio and got it onto Brooklyn band Lathe of Heaven's official streaming profiles by exploiting how digital distributors map uploads to existing artist identifiers, with no check that the uploader has any connection to the artist. The AI generator is incidental here; the defect is an identity and supply chain weakness in music distribution that has existed for years and is now being abused at scale by people flooding catalogues with generated tracks. It is a clean worked example of trust assumptions in an intermediary layer being inherited by the platform that displays the result.

  2. Windows Exploitation Techniques: Dangling COM Object Registrations (opens in a new tab)

    Project Zero ·James Forshaw ·21 Sep 2026 ·fetched 21 Sep 2026, 19:37 UTC Must read Research CVE-2026-66804 EPSS 5.3% agreed2/2

    Why readForshaw walks the dangling COM registration primitive behind CVE-2026-66804, including the exact CLSID and the writable %PROGRAMDATA% path that makes it a privilege escalation.

    The CrossDevice COM object, CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}, is registered system-wide under HKEY_CLASSES_ROOT but points at %PROGRAMDATA%\CrossDevice\CrossDevice.Streaming.Source.dll, a DLL that does not exist in a directory any user can create paths in. CVE-2026-66804 is the incomplete fix for CVE-2026-50343, the bug Calif called Dark Elevator, and was reported by Forshaw plus 14 others independently. The generalisable finding is the audit technique: registered CLSIDs whose server binary is absent from a world-writable location are a repeatable elevation class on Windows, not a one-off.

  3. Reverse-Engineering Flock Cameras (opens in a new tab)

    Schneier on Security ·Bruce Schneier ·21 Sep 2026 ·fetched 21 Sep 2026, 15:44 UTC agreed3/3

    Why readA physically captured ALPR gave up its disk encryption key from an adjacent unencrypted partition, and its logs show it classifying people and bumper stickers, not only plates.

    Hackers who obtained a Flock automatic licence plate reader recovered its software and several weeks of logs. The encryption bypass was not cryptographic: the key for the protected partition was sitting in cleartext on a partition that was not protected, a failure mode worth naming in any threat model for field deployed devices. The recovered logs also show computer vision that detects people and bicycles and isolates graphics such as stickers and patches, which is a broader capability than the plate reading the product is sold as.

  4. The Supersingular Isogeny Problem in Time and Memory $p^{1/3+o(1)}$, Unconditionally (opens in a new tab)

    arXiv cs.CR (all) ·José Luis Delgado ·21 Sep 2026 ·fetched 21 Sep 2026, 07:42 UTC Research agreed3/3

    Why readAn unconditional Las Vegas algorithm solves the supersingular OneEnd problem in p^(1/3+o(1)) time and memory, improving the previous unconditional exponent of 2/5 and removing Wesolowski's factorisation assumption.

    Given a supersingular elliptic curve over F_p^2, the OneEnd problem asks for a non-scalar endomorphism, and by known reductions it also settles the supersingular endomorphism ring and isogeny problems that isogeny-based cryptography rests on. The algorithm fixes a family of smooth degrees in advance, uses counting results to guarantee many isogenies from curves to their Frobenius conjugates, and a collision estimate to show a random walk reaches one; it then splits a degree, enumerates two lists of shorter isogenies and matches targets. Crucially the analysis carries no smoothness heuristic, so the p^(1/3) exponent now holds unconditionally where it previously required an assumption, tightening the concrete security margin for isogeny-based schemes.

  1. Verifiable Computation with Trusted Execution Environments and On-Chain Digital Rights Tokens (opens in a new tab)

    arXiv cs.CR (all) ·Bingle Stegmann Kruger, Co-Pierre Georg ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC Research agreed3/3

    Why readAn architecture for letting third-party analysts run only pre-approved open-source code over sealed data pools inside a TEE, with a working WASM/Python implementation recording redemptions on Solana.

    Data owners pool private data inside Trusted Execution Environments and issue Digital Rights Tokens that bind a specific piece of open-source code to a specific pool; an analyst redeems a token on-chain, gets the computation result, and never sees the inputs. The reference implementation runs WASM and Python jobs over sealed datasets and settles redemptions on Solana. The paper argues for ex ante creator control over processing and is candid about the platform's limitations, which is where the useful part sits for anyone weighing confidential computing for data sharing.

  2. SFPF: Spatio-Frequency Polarization Fingerprint for Anomalous Wireless Device Detection (opens in a new tab)

    arXiv cs.CR (all) ·Xiaoxuan Huang, Jinlong Xu, Daoyuan Shen, Meng Zhang ·21 Sep 2026 ·fetched 21 Sep 2026, 19:37 UTC Research agreed2/2

    Why readProposes a hardware fingerprint that samples polarization response across multiple frequencies and observation directions, catching device swaps that single-direction RF fingerprinting misses.

    Conventional RF fingerprinting fails to separate a replaced device from the legitimate one when the substitute hardware is closely matched, and a polarization fingerprint taken from one direction misses spatially nonuniform changes. SFPF jointly represents complex polarization responses over multiple frequencies and directions, with conventional PF as a fixed-direction slice of it, derived from modal excitation and far-field radiation. A first-order sensitivity analysis argues the multi-direction representation responds more strongly to the same hardware change. Academic, needs controlled measurement conditions, not deployable today.

  3. Cloud Threat Emulation on Autopilot: Context is Everything (opens in a new tab)

    Elastic Security Labs ·Terrance DeJesus,Bryan Porras Blanch ·21 Sep 2026 ·fetched 21 Sep 2026, 15:44 UTC agreed3/3

    Why readA five-stage method for cloud adversary emulation (scope in layers, threat model, execute, verify telemetry, tear down clean) aimed at proving whether the resulting logs are actually detectable.

    The argument is that firing an API call and declaring emulation done is insufficient in cloud, SaaS and identity environments where there is no sample or sandbox artefact to replay, so you must provision the identities and resources, execute, then test whether the captured telemetry supports a rule. Elastic builds on the MITRE Center for Threat-Informed Defense Adversary Emulation Library shape and adapts it for detection engineering. It commits to a testable criterion, which is more than most emulation writeups do.

  4. From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies (opens in a new tab)

    Unit 42 ·Margaret Kelley ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC agreed3/3

    Why readTraces how AWSCompromisedKeyQuarantine has changed across policy versions and gives the log signals to alert on when AWS attaches it to one of your principals.

    The post walks the version history of the AWSCompromisedKeyQuarantine managed policy, mapping each revision to the cloud attack technique it was added to block, and covers the GitHub secret-scanning partner integration that triggers attachment. A live exposure test produces a step-by-step timeline of how quickly AWS detects a leaked access key and quarantines the principal. It closes with the monitoring approach for spotting quarantine events in your own CloudTrail, which is the part worth implementing: if you learn about the attachment from a broken workload, you are already behind.

  5. SAML: A fractal of bad design (opens in a new tab)

    Trail of Bits ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC agreed3/3

    Why readA case for deprecating SAML in favour of OIDC, built on why XML signature validation keeps failing rather than on any single bug.

    The piece traces SAML from its design-by-committee academic origins through its adoption as the SSO standard for corporate SaaS, then through the succession of research results that have picked apart its trust assumptions. The core claim is structural: SAML works only if XML signature validation is reliable, and a decade of signature wrapping and canonicalisation failures shows it is not, so complexity rather than any individual CVE is the reason to retire it. It is an opinion with a clear position you can argue with, and useful ammunition if you are trying to fund an identity migration.

  6. An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. (opens in a new tab)

    The Hacker News ·The Hacker News ·21 Sep 2026 ·fetched 21 Sep 2026, 07:42 UTC Must read agreed3/3

    Why readA dead CDN's expired domain was re-registered in July 2025 with wildcard DNS, so whoever owns it now controls what thousands of sites with hard-coded script references load next.

    A domain formerly used by a wound-down CDN expired and was picked up by a new owner in July 2025, who holds wildcard DNS across it; every stale hostname referenced in websites, repositories and documentation now resolves to their infrastructure. The apex currently serves an ad-heavy media downloader page, but nothing prevents a change, and nobody downstream was notified because from the outside nothing broke. The polyfill.io takeover in June 2024, which hit a shim embedded in more than 110,000 sites, is the precedent for what the next step looks like; the actionable takeaway is auditing hard-coded third-party script hosts for domains whose owners have changed.

  7. XiantingWu/PQCensus: Evidence-grounded cryptographic inventory and post-quantum migration planning for software repositories. Local static analysis, zero mandatory runtime dependencies, SARIF and CycloneDX output. (opens in a new tab)

    GitHub: new security tools ·XiantingWu ·21 Sep 2026 ·fetched 21 Sep 2026, 03:40 UTC Research ★ 135 agreed3/3

    Why readA local static-analysis scanner that builds a cryptographic inventory from a source repo and emits SARIF and CycloneDX for post-quantum migration planning.

    PQCensus scans repositories for cryptographic usage without an API key, hosted service, LLM or execution of target code, and outputs SARIF and CycloneDX so findings drop into existing pipelines. The audit command exits 1 when a finding hits the --fail-on threshold, distinct from crash exit codes, which makes it usable as a CI gate. Version 0.1.x keeps the legacy quantumguard CLI, import alias and QG-*/QGA-* identifiers as compatibility contracts; no PyPI release yet, so install is from a checkout.

  8. Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts (opens in a new tab)

    BleepingComputer ·Sergiu Gatlan ·21 Sep 2026 ·fetched 21 Sep 2026, 03:40 UTC agreed3/3

    Why readThe spurious "Microsoft Defender Antivirus is turned off" notifications are a platform bug, fixed in Defender Antivirus 4.18.26080.4, so stop chasing them as real coverage gaps.

    Microsoft confirmed the false alerts affecting all supported Windows client and server builds, including Windows 11 26H1 and Server 2025, were resolved in the Defender Antivirus update released on 17 September. Affected hosts showed the Windows Security prompt to re-enable Defender while protection was active and all settings reported healthy. The bug had been present in Release Preview since at least June and was only acknowledged in late August, which matters for anyone triaging AV-disabled alerts from that window.

  1. Massachusetts fines TradeZero for data breach, compromising personal information of thousands (opens in a new tab)

    Google News: incidents · wwlp.com ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC agreed2/3

    Why readA completed state regulatory penalty, not just a filing, against a broker over a breach affecting thousands of customers.

    Massachusetts has fined online brokerage TradeZero over a data breach that exposed the personal information of thousands of people. The reporting is thin on the breach mechanics, but the enforcement outcome itself is the point: a state securities regulator attaching a monetary penalty to a financial services breach. It is a useful data point for anyone arguing internally about the cost side of breach exposure in regulated sectors.

  2. LinkedIn wins court order blocking mass scraping of user data (opens in a new tab)

    The Record ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC agreed2/3

    Why readA finalised US court order gives anti-scraping enforcement a concrete outcome: deletion of collected data and the shutdown of a fake-account network running into the millions.

    A California federal judge finalised an agreement between LinkedIn, ProAPIs and joint operator Netswift that bars the firms from mass scraping, from selling or transferring the harvested data, and from accessing the platform through fake accounts, with deletion of what they already took. LinkedIn sued in October last year, alleging the defendants ran a network of bogus accounts numbering in the millions that scraped continuously. For teams tracking data-aggregation risk, it is a marker of what platform operators can now extract from scraper litigation rather than a technical control.

  3. EU Kids Act Won't Keep the Internet Accountable and Trustworthy (opens in a new tab)

    EFF Deeplinks ·Christoph Schmon ·21 Sep 2026 ·fetched 21 Sep 2026, 15:44 UTC agreed3/3

    Why readBreaks down the four mechanisms in the EU Kids Act draft, social media age delay, safety by design, mandatory age assurance and enforcement, and why hardening the DSA minor-protection guidelines into law forces age verification onto all users.

    The European Commission's draft EU Kids Act would convert the non-binding DSA guidelines on minors' protection into hard law, creating phased access to social media and video-sharing platforms judged risky and mandating age assurance alongside parental responsibility requirements and stronger enforcement. EFF's objection is that age gates cannot be implemented without identity or inference checks applied to every user, so a child-safety measure becomes a general privacy and anonymity cost. Anyone running a consumer platform in the EU should read this as an early warning on the age-verification obligations heading their way.

  1. Cyberattack hits University of Munich, potentially exposing student financial data (opens in a new tab)

    The Record ·21 Sep 2026 ·fetched 21 Sep 2026, 23:39 UTC agreed2/3

    Why readA named breach at one of Germany's largest universities where enrolment records including bank details and possible health insurance and financial aid data were pulled.

    LMU Munich says an unknown attacker reached a system holding enrolment data for a student body of more than 52,000, and that it must now assume the records were actually retrieved. Affected fields include names, dates of birth, contact details, university email addresses and bank account information, alongside possible health insurance and financial aid data. The university reports no sign the data was altered, deleted, published or misused so far, and the investigation is still open.

  2. EU data regulator fines Google more than $460 million for location data violations (opens in a new tab)

    The Record ·21 Sep 2026 ·fetched 21 Sep 2026, 19:37 UTC Must read agreed2/2

    Why readIreland's DPC is fining Google €403 million ($462m) over location data processing and has ordered the practices fixed within six months.

    The Irish Data Protection Commission concluded a GDPR inquiry opened in February 2020 into how Google processes location data across web and app activity, location history and related features, and is imposing a fine of more than €403 million plus a six-month remediation order. The inquiry followed complaints from European consumer rights groups. For anyone running consent and location telemetry in an EU-facing product, the remediation order is the part with teeth: it sets a supervisory expectation on how location processing must be justified, not just a one-off penalty.

    Also covered bySecurityWeek (opens in a new tab),Infosecurity Magazine (opens in a new tab).

  3. EU Fines Google 403 mn Euros for Location Data Breach (opens in a new tab)

    Google News: incidents · ASHARQ AL-AWSAT English ·21 Sep 2026 ·fetched 21 Sep 2026, 15:44 UTC agreed3/3

    Why readA 403 million euro EU penalty against Google over location data handling is the privacy-enforcement datapoint your board and privacy counsel will cite in the next budget conversation.

    EU regulators fined Google 403 million euros over its handling of location data. The report is a wire-style item with no detail on the legal basis, the responsible authority, or the remediation ordered, so the enforceable specifics still have to come from the decision itself. Treat it as a marker of continued EU appetite for large privacy penalties against platform operators rather than as guidance on what changes for your own location-data processing.

  4. LNG tanker diverts after suspected cyberattack disrupts onboard systems (opens in a new tab)

    Google News: incidents · safety4sea ·21 Sep 2026 ·fetched 21 Sep 2026, 15:44 UTC agreed3/3

    Why readAn LNG tanker diverted after a suspected cyberattack disrupted onboard systems, the kind of maritime OT incident that will be raised with any board exposed to shipping or energy logistics.

    A liquefied natural gas carrier changed course after a suspected cyberattack affected systems aboard the vessel. No attribution, attack vector or affected system is named, and the incident is described as suspected rather than confirmed. For shipping, energy and marine insurance readers it is an event to track: onboard system compromise that forces a route change has cargo, charter and insurance consequences well beyond IT.

  5. Revolut Reveals Data Breach Tied to Faked Official Request (opens in a new tab)

    Google News: incidents · BankInfoSecurity ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC agreed3/3

    Why readRevolut has disclosed a data breach caused by a forged official data request, the social-engineering vector that bypasses legal process controls rather than technical ones.

    Revolut confirmed customer data was exposed after attackers submitted a faked official request, the emergency data request abuse pattern that has previously hit large platforms. Only the disclosure is available so far, with no scope, record count or timeline attached. Any organisation with a law-enforcement response function should treat this as the prompt to check how requests are authenticated before they are fulfilled.

  6. CrowdSec Confirms Source Code Stolen in Supply Chain Attack (opens in a new tab)

    SecurityWeek ·Ionut Arghire ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC agreed3/3

    Why readThe May 2026 TanStack compromise is still producing victim disclosures, and the latest one is a security vendor losing source code.

    CrowdSec has confirmed that attackers stole source code, and attributes the breach to the TanStack supply chain attack from May 2026. The gap between the initial compromise and this confirmation is the useful part: organisations that pulled affected TanStack packages and closed the incident at the time may still have unassessed downstream exposure. Treat it as a prompt to revisit dependency audit scope rather than as a new attack to defend against.

  7. Eagle Mountain internet service goes down again amid cyberattack (opens in a new tab)

    Google News: incidents · kutv.com ·21 Sep 2026 ·fetched 21 Sep 2026, 07:42 UTC agreed3/3

    Why readMunicipal internet service in Eagle Mountain, Utah has gone down a second time during an ongoing cyberattack, a repeat outage at a city-run ISP.

    Local reporting says Eagle Mountain's city internet service has failed again amid a cyberattack, the second outage in the same incident. Nothing beyond the headline reached us: no actor, no vector, no restoration timeline. Worth flagging for anyone tracking attacks on municipal utilities and city-operated broadband, but the detail is not there yet.

  8. Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes (opens in a new tab)

    Infosecurity Magazine ·21 Sep 2026 ·fetched 21 Sep 2026, 07:42 UTC agreed3/3

    Why readMITRE ATT&CK Evaluations are in flux and the major detection vendors are now funding an alternative, which changes what independent evidence buyers will have next year.

    SE Labs launched PIVOT on September 15, a six-month adversary-emulation testing program run by its own ethical hacking team out of Wimbledon, with Broadcom, CrowdStrike, Fortinet, Palo Alto Networks, and Sophos already signed on. Results are expected in January 2027. The interesting part is not the methodology, which is not yet public in detail, but the migration itself: the reference point buyers have leaned on for detection comparisons is changing, and a vendor-participating commercial lab is stepping into the gap, which is worth weighing when the first results are cited in procurement.

  9. CenterPoint confirms customer data breach after hacker leaks alleged 7.49 million records (opens in a new tab)

    Google News: incidents · Yahoo ·21 Sep 2026 ·fetched 21 Sep 2026, 03:40 UTC Must read agreed3/3

    Why readCenterPoint Energy has confirmed a customer data breach after a hacker leaked what is claimed to be 7.49 million records, a named US utility with a quantified exposure.

    CenterPoint confirmed customer data was taken after an actor published an alleged 7.49 million records. The confirmation follows the leak rather than preceding it, which puts the utility in reactive notification mode across a large retail customer base. Peers in energy and utilities should expect questions about downstream notification duties, regulator contact, and whether the same access path exists in their own customer systems.

  10. Data of 1.2 million people breached in recent CSDD cyberattack / Article (opens in a new tab)

    Google News: incidents · LSM ·21 Sep 2026 ·fetched 21 Sep 2026, 03:40 UTC agreed3/3

    Why read1.2 million people's data exposed in the breach of Latvia's road traffic safety directorate CSDD, a national-scale public-sector incident.

    Latvia's Road Traffic Safety Directorate (CSDD) has confirmed that data on 1.2 million people was compromised in a recent cyberattack, a figure covering most of the country's adult population. Public reporting so far gives the scale but not the intrusion path or the data categories. Relevant as a European public-sector breach with GDPR notification consequences attached.

DFIR

2
  1. TerminalFix: PNG Steganography, (Mon, Sep 21st) (opens in a new tab)

    SANS ISC Diary ·21 Sep 2026 ·fetched 21 Sep 2026, 11:41 UTC Research agreed3/3

    Why readA working method for pulling a payload out of a structurally valid PNG, using samples from a live campaign rather than a synthetic example.

    Didier Stevens takes the PNG files from Microsoft's TerminalFix write-up, obtained directly from the researchers, and shows why ordinary triage misses them. The image is a well formed 111 by 112 pixel PNG with only IHDR, IDAT and IEND chunks, nothing appended after IEND and no metadata field to carry a payload, so the data is inside the compressed pixel stream itself. The walkthrough with pngdump.py, including the sample SHA-256, gives responders something they can run against their own suspect images.

    Indicators1
    Hashes
    f5f1eb6d43dd61d5b069c250e5c666384f7417d0c95014773bf9edf8ff13bebe
  2. New Graph Compression Method Shrinks Cyberattack Data 30-Fold Without Losing Evidence (opens in a new tab)

    Google News: incidents · Bioengineer.org ·21 Sep 2026 ·fetched 21 Sep 2026, 03:40 UTC Research agreed3/3

    Why readAn academic graph-compression approach claims 30-fold reduction of attack provenance data while preserving the evidentiary chain needed for investigation.

    Researchers describe a compression method for provenance and audit graphs that shrinks stored attack data roughly 30 times without discarding the edges an investigator needs to reconstruct a chain. The practical target is the cost of retaining kernel-level and endpoint provenance long enough to be useful after a slow-burn intrusion. The write-up is press-release coverage; the claim is worth checking against the original paper before believing the retention-cost arithmetic.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
Metallco play Manufacturing BR 21 Sep 2026
Hurley play - US 21 Sep 2026
Astemo, Ltd. metaencryptor Manufacturing JP 21 Sep 2026
Hogan Lovells Cadwalader SilentRansomGroup Professional Services - 21 Sep 2026
kyyba.com unsafe Technology FI 21 Sep 2026
360 Consulenza S.r.l. nightspire Professional Services IT 21 Sep 2026
Spo**** Schools nightspire Education US 21 Sep 2026
Summa Gold anubis Manufacturing - 21 Sep 2026
Allied Supply Co. Global Secret Group Manufacturing - 21 Sep 2026
Kjla Global Secret Group - US 21 Sep 2026
Telrad Networks qilin Technology IL 21 Sep 2026
U.S. Electrical Services and Wiedenbach Brown moneymessage Energy & Utilities - 21 Sep 2026
Hudson MD Group, LLC metaencryptor Healthcare US 21 Sep 2026
Bruker Corporation metaencryptor Manufacturing US 21 Sep 2026
Flex Ltd metaencryptor Manufacturing US 21 Sep 2026
HyVision System. Inc metaencryptor Technology KR 21 Sep 2026
Visual Intelligence, Inc. metaencryptor Technology US 21 Sep 2026
Prestige Management akira Professional Services US 21 Sep 2026
Grupolider thegentlemen - AO 21 Sep 2026
The Money Store Storm Financial Services US 21 Sep 2026
TrueCore Behavioral Solutions Storm Healthcare US 21 Sep 2026
Manroc Developments Storm - CA 21 Sep 2026
Charlottesville Police Department Doommageddon Government & Defense US 21 Sep 2026
Gomomentum.com EndZone - - 21 Sep 2026
IKEGAMI TSUSHINKI COMPANY LIMITED qilin Manufacturing JP 21 Sep 2026
How this edition was made
Candidates fetched
4452
New after deduplication
720
Kept by the panel
197
Published
142
Generated
21 Sep 2026, 23:39 UTC