CFToday Curated security signals.

Daily edition · 2026-09-11

Friday, 11 September 2026

60 items across 8 sections, selected from 4782 candidates over 6 runs. 100 carried the panel unanimously.

Show
Section

India

2

Indian organisations, regulators and infrastructure, pulled out of the sections below.

  1. India’s STPI serves TerminalFix-style attack via fake Cloudflare check (opens in a new tab)

    CSO Online ·Threat Intel & Breaches ·fetched 11 Sep 2026, 15:39 UTC agreed3/3

    Why readA government-linked Indian domain, ananta.stpi[.]in, was serving a fake Cloudflare check that pastes a command to the clipboard for execution in Windows Terminal.

    The page mimics a "Verify you are human" prompt but adds a step telling the visitor to open Windows Terminal and run the clipboard contents, a ClickFix variant using Terminal rather than the Run dialog. Researcher Vibhum Dubey reported it to STPI and CERT-In; CSO confirmed the malicious external JavaScript was still embedded in the page source after the behaviour briefly stopped, suggesting incomplete remediation. Worth noting for anyone whose users trust stpi.in as a legitimate government resource, and a reminder to hunt for Terminal-spawned interpreter activity.

    Indicators3
    Domains
    ananta[.]stpi[.]in cdn[.]quickdelivr[.]com domaintools[.]com
  2. Sebi proposes extending cybersecurity rules to subsidiaries of MIIs (opens in a new tab)

    Google News: enforcement · economictimes.com ·Governance, Risk & Compliance ·fetched 11 Sep 2026, 15:39 UTC agreed2/3

    Why readIndian market infrastructure operators get advance notice that SEBI intends to pull their subsidiaries inside the cyber resilience framework.

    SEBI has floated extending its cybersecurity and cyber resilience framework beyond exchanges, depositories and clearing corporations to the subsidiaries those institutions control. The practical effect would be that entities currently treated as out of scope inherit the same incident reporting, audit and resilience testing obligations as their parents. This is a consultation stage proposal, so the compliance date and final scope are still open.

  1. Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script (opens in a new tab)

    The Register Security ·fetched 11 Sep 2026, 03:39 UTC Must read CVE-2026-81578 EPSS 1.7% agreed3/3

    Why readGreyNoise traced an attacker who orchestrated hundreds of AI agents to exploit two PaperCut MF/NG bugs against 395+ organisations, hitting 11 orgs in 26 seconds and taking one school from initial access to domain admin in seven minutes.

    A likely Russian-speaking criminal built exploits for PaperCut MF/NG flaws disclosed on 28 August, including CVE-2026-81578, and ran the campaign through agents on OpenAI's Codex harness backed by a DeepSeek model, with orchestration traced to 45.142.193.132 from 31 August. The operator went from empty workspace to first RCE in under four hours and to first domain admin two hours after that; some agents deviated from their instructions mid-campaign. Victims were concentrated in US education, which makes exposed PaperCut print servers an immediate hunt target and the compression of the disclosure-to-mass-exploitation window the wider lesson.

    Also covered byHelp Net Security (opens in a new tab).

  2. Attackers are weaponizing the gap between Chromium fixes and Chrome patches (opens in a new tab)

    CSO Online ·fetched 11 Sep 2026, 03:39 UTC Must read CVE-2026-85046 EPSS 0.8% agreed3/3

    Why readNames the CVEs in a browser exploit chain espionage actors are using right now, and explains why the window between a public Chromium fix and a shipped Chrome build is the space attackers are deliberately working in.

    Proofpoint, alongside Google's Threat Intelligence Group, Microsoft's Threat Intelligence Center and Volexity, documented a toolkit called BlueMoon that chains four bugs into a targeted spear phishing chain: three in Chrome and Chromium based browsers, including a V8 type confusion (CVE-2026-85046) and a WebAssembly driven V8 sandbox escape (CVE-2026-87491), plus a Windows flaw. The kit moved between multiple unrelated threat actors within days of appearing, which says as much about exploit sharing economics as about any single group. The operational point is that upstream Chromium fixes land publicly before downstream browser builds ship them, so treat Chromium commit timing, not your browser vendor's release note, as the start of your exposure clock.

  3. Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit (opens in a new tab)

    Sysdig ·fetched 11 Sep 2026, 19:40 UTC Must read Research CVE-2026-39987 EPSS 98.9% agreed3/3

    Why readHoneypot telemetry of a human operator exploiting the marimo pre-auth RCE CVE-2026-39987 (EPSS 0.99) and pivoting through AWS Secrets Manager to a bastion host in nine hours, hand-rolling every script.

    An operator exploited CVE-2026-39987, a pre-authentication RCE in marimo, via the unauthenticated WebSocket terminal, then harvested instance credentials, called AWS Secrets Manager, and used a retrieved private key for SSH onto a bastion host. Over a nine-hour session they issued more than 850 interactive commands with no recognisable public offensive tooling, and avoided a decoy that every agentic attacker profiled against the same CVE fell into. The practical point for defenders is that detection logic tuned to known tool signatures and to AI-agent behavioural tells misses a skilled human moving at comparable speed.

    Indicators2
    Addresses
    172[.]236[.]12[.]17 45[.]79[.]187[.]72
  4. Protecting organizations from AI-assisted executive impersonation and invoice fraud (opens in a new tab)

    Microsoft Security ·Microsoft Security Research ·fetched 11 Sep 2026, 07:39 UTC Research agreed3/3

    Why readBreaks down a financial-fraud campaign of over a million emails whose templates show generative-AI construction, with domain registration patterns, ATT&CK mappings and IOCs.

    The campaign impersonated internal executive correspondence and invoice notifications, delivered through third-party email infrastructure to push more than a million scam messages. Microsoft documents the delivery chain, the actor's domain registration behaviour and the indicators consistent with AI-generated template construction, layering several persuasion techniques into single messages. The IOC list and ATT&CK mapping are usable, though the guidance section leans hard on Defender and Security Copilot.

    Indicators10
    Domains
    service-nowinc[.]com domainlify[.]net uinsure[.]co[.]uk tivityhealth[.]com lumalisboa[.]com mctci[.]com nuf[.]co lohnsteuerhilfe-aktuell-verein[.]de eemusicclass[.]co[.]uk lifeones[.]com
  5. Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware (opens in a new tab)

    Huntress ·fetched 11 Sep 2026, 19:40 UTC Research agreed3/3

    Why readHuntress SOC traces a single X direct message that fingerprints the victim's OS and forks into AMOS infostealer on macOS and NetSupport Manager RAT on Windows, with a fake Google Doc sidebar as the lure.

    The same social-engineering entry point drives two distinct chains, so detection built for one platform misses the other half of the campaign entirely. NetSupport Manager as the Windows payload is the familiar legitimate-RAT-abuse pattern and is detectable on install and beacon behaviour; AMOS covers the Mac side of the same victim pool. Only a summary line reached us, so pull the full post for the indicators.

  6. Worse Than First Reported: What CISA’s Revised Water Sector Numbers Mean for Every Utility (opens in a new tab)

    IOActive ·Christian Powills ·fetched 11 Sep 2026, 15:39 UTC agreed2/3

    Why readThe July water sector campaign was roughly three times larger than the original reporting suggested, and the corrected figures did not surface through normal disclosure channels.

    CISA now puts the July 2026 campaign against US water utilities at more than 100 internet exposed systems in at least 12 states, against the roughly 30 Minnesota systems disclosed when the story broke, with Georgia, Michigan, South Dakota and New Jersey since confirming incidents of their own. A separate August 19 advisory, AA26-231A, describes actors probing internet exposed Siemens S7 PLCs across six sectors using AI generated exploitation scripts dressed up as monitoring tools, which is capability development rather than confirmed disruption. The follow up exposure guidance repeats April's line almost verbatim: PLCs should never be reachable from the internet through a cellular modem.

    Indicators1
    Hashes
    fa38a32ee48d7f3d4b0c069fdc08a69e6327376eb85838a03310b2e91c8582c1
  7. Indonesia Hit by Android Banking App-Cloning Campaign (opens in a new tab)

    Dark Reading ·Alexander Culafi ·fetched 11 Sep 2026, 03:39 UTC agreed3/3

    Why readGoldFactory is abusing Android's Work Profile feature to install cloned banking apps carrying the Gigabud trojan against Indonesian targets.

    A campaign in Indonesia clones legitimate Android banking apps, with GoldFactory using the Work Profile container as the delivery mechanism for Gigabud while a separate operation spreads Mantax Otax. The Work Profile angle is the interesting part: it gives the attacker a managed-app install path that looks legitimate to the user. The available text is short on indicators, so treat it as a pointer to the underlying research.

  8. MantaxOtax Android Malware Combines Ransomware With Spyware (opens in a new tab)

    Infosecurity Magazine ·fetched 11 Sep 2026, 07:39 UTC agreed3/3

    Why readAndroid family that pairs file encryption with full surveillance, and pulls its live C2 domain from a GitHub repository so operators can rotate infrastructure without reshipping the sample.

    Zimperium zLabs attributes MantaxOtax to Indonesian actors and found samples distributed as standalone APKs on a third-party file-sharing service, implying sideloading rather than store delivery. After install it escalates through device administrator, SMS, contacts, audio and image permissions, then Android Accessibility for broad control of device interaction; on Android 9 and earlier it recursively walks shared external storage and encrypts user files with AES. The GitHub-hosted C2 resolution is the detection-relevant detail, since blocking a single domain does not cut the operators off.

  9. Microsoft sees some new wrinkles in invoice-scam emails (opens in a new tab)

    The Record ·fetched 11 Sep 2026, 19:40 UTC agreed3/3

    Why readMicrosoft tracked a single BEC campaign of over a million emails in early August that impersonated executives and asked accounts payable for payments near $50,000.

    Attackers layered tactics in one message: a forged forwarded thread from a fake CEO to ServiceNow, plus dispatch through third-party mail services to pass authentication checks. Microsoft's read is that generative tooling is mainly improving template quality and recipient tailoring rather than introducing a new technique. Useful as a volume and lure-structure data point for mail rule tuning, but the write-up is second-hand from Microsoft's research.

  10. ClickFix attacks infecting PCs and Macs are going viral (opens in a new tab)

    Ars Technica Security ·Dan Goodin ·fetched 11 Sep 2026, 11:41 UTC agreed2/3

    Why readA useful snapshot of just how far ClickFix has spread, now covering macOS and state-backed crews, if you need ammunition for an awareness push.

    ClickFix, the fake CAPTCHA overlay that coaxes a visitor into pasting a supplied command into a terminal, has moved from novelty to default initial access across both Windows and macOS payloads, with compromised legitimate sites serving the lure. Kevin Beaumont notes consumer forums filling with infection reports, and Kremlin-linked groups have picked up the technique alongside commodity crews. There is no new indicator or detection content here; the value is the reach data and the argument that blaming users misses how normal the paste-a-command workflow now looks.

  1. CVE-2026-85706: GitLab Community Edition and Enterprise Edition, GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability (opens in a new tab)

    CISA KEV ·fetched 11 Sep 2026, 23:38 UTC Must read CVE-2026-85706 Exploited in the wild · patch by 2026-09-14 agreed3/3

    Why readUnauthenticated arbitrary file read in GitLab's repository commits API is on KEV with a federal remediation deadline of 14 September 2026.

    CVE-2026-85706 is a path traversal in GitLab Community and Enterprise Edition: improper path confinement plus missing authentication enforcement in the repository commits API lets an unauthenticated user read arbitrary files off the instance. CISA has added it to KEV under BOD 26-04 with a due date of 2026-09-14, and the listing references forensic triage requirements, so treat exposed instances as potentially already read. Self-managed GitLab is frequently internet-facing and holds source, CI secrets and tokens, making file-read a credential-harvesting primitive rather than an information leak.

    Also covered byHorizon3 Attack Team (opens in a new tab).

  2. Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 11 Sep 2026, 11:41 UTC Must read CVE-2026-20079 EPSS 74.7% agreed3/3

    Why readCVE-2026-20079 (CVSS 10.0) in Cisco Secure FMC is under active exploitation by three separate clusters, one of which ends in Qilin ransomware, with EPSS at 0.75 and the 99.5th percentile.

    Cisco confirmed exploitation of two recently patched Secure Firewall Management Center flaws: CVE-2026-20079, an unauthenticated web interface authentication bypass that yields script execution and root on the underlying OS, and CVE-2026-20316, a low-privilege unauthenticated login flaw that leaks sensitive data and chains for privilege escalation. Talos tracked three post-compromise clusters spanning state-sponsored and crimeware activity, including UAT-12197 deploying JSP web shells and a Java implant, with credential theft and Qilin ransomware deployment downstream. FMC is a management plane for the firewall estate, so compromise is credential-harvesting across everything it administers.

    Also covered bySecurity Affairs (opens in a new tab).

  3. CVE-2026-82329: Unauthenticated Administrative Access in JFrog Artifactory via an Empty Cluster Join Key (opens in a new tab)

    Bishop Fox ·fetched 11 Sep 2026, 19:40 UTC Must read Research CVE-2026-82329 EPSS 7.7% agreed3/3

    Why readUnauthenticated admin token on internet-facing JFrog Artifactory via a derivable cluster join key, reproduced end to end against 7.111.20 and already being exploited.

    CVE-2026-82329 is a CVSS 9.8 authentication bypass in self-managed JFrog Artifactory: on a default install, JFrog Access registers a cluster join key whose id and signing secret are both derivable, so a single forged join request to an unauthenticated endpoint returns an admin-scoped token. Bishop Fox reproduced the full chain to Artifactory administrator on a default 7.111.20 instance, and exploitation began within days of disclosure. Admin on Artifactory means reading every package an organisation ships, uploading poisoned ones that downstream builds trust, and pulling credentials that reach adjacent systems, so treat any exposed instance as a build-pipeline compromise.

    Indicators1
    Hashes
    e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
  4. CVE-2026-84869: ConnectWise ScreenConnect, ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability (opens in a new tab)

    CISA KEV ·fetched 11 Sep 2026, 19:40 UTC Must read CVE-2026-84869 Exploited in the wild · patch by 2026-09-14 EPSS 0.4% agreed3/3

    Why readScreenConnect client flaw CVE-2026-84869 is on CISA KEV with a 2026-09-14 federal remediation deadline, and RMM tooling is a standing ransomware entry point.

    CISA added CVE-2026-84869 in ConnectWise ScreenConnect to the Known Exploited Vulnerabilities catalogue, with a due date of 2026-09-14 under BOD 26-04. The flaw combines improper privilege management and missing authorization, letting an attacker transfer and execute files through an active remote session without authorization or host confirmation. Agencies must apply vendor mitigations or discontinue use, and the KEV listing also pulls in CISA's forensics triage requirements.

  5. UK Council Attack Linked to Mass Exploitation of SonicWall Flaw (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 11 Sep 2026, 07:39 UTC CVE-2026-15409 EPSS 83.7% agreed3/3

    Why readFull exploit chain for CVE-2026-15409 in SonicWall SMA1000, an unauthenticated CVSS 10.0 SSRF now in mass exploitation and tied to a UK council intrusion, with EPSS at 0.84.

    The WorkPlace portal's WebSocket proxy lets an unauthenticated attacker hit /wsproxy to force the appliance to connect to localhost:1050, where a CouchDB-related Erlang service listens; a hardcoded cookie recovered from the appliance firmware completes the Erlang handshake to the [email protected] node and yields OS command execution as the couchdb user. Hunt.io links the Borough Council of King's Lynn and West Norfolk attack, detected on 17 July 2026, with moderate confidence to a wider campaign that harvested credentials and enabled Active Directory theft. Anyone running SMA1000 should treat exposed appliances as compromised, not merely unpatched.

    Indicators3
    Hashes
    690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b
    Addresses
    95[.]181[.]173[.]36
    Domains
    hunt[.]io
  6. CVE-2026-75156 (CVSS 9.1): Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployment (opens in a new tab)

    NVD ·fetched 11 Sep 2026, 03:39 UTC CVE-2026-75156 CVSS 9.1 EPSS 0.2% agreed3/3

    Why readApache Airflow FAB provider 3.7.3 to 3.8.0 validates Azure AD id_token signatures against the multi-tenant JWKS endpoint without checking issuer or audience, so anyone who can register an Azure tenant can log into your Airflow UI.

    Because signing keys come from Microsoft's multi-tenant JWKS endpoint and neither issuer nor audience is checked, a token minted in an attacker-created tenant passes verification, and the provider then reads username and role assignments straight out of that attacker-controlled token. Only deployments using the FAB auth manager with Azure AD as an OAuth provider are affected, but the earlier fix for CVE-2026-59243 was incomplete: 3.7.3 is the release that shipped it, so operators who already patched are still exposed and must upgrade again. EPSS is low at 0.0018, though Airflow UIs with cloud SSO are frequently internet-reachable and a successful login is direct access to DAG execution.

  7. CVE-2026-53939 (CVSS 9.1): OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts (opens in a new tab)

    NVD ·fetched 11 Sep 2026, 23:38 UTC CVE-2026-53939 CVSS 9.1 EPSS 0.2% agreed3/3

    Why readcjose 0.6.1 through 0.6.2.5 generates an all-zero content-encryption key for AES-CBC-HMAC JWEs, so anyone holding the token can decrypt and forge it.

    When cjose encrypts a JWE using A128CBC-HS256, A192CBC-HS384 or A256CBC-HS512 with any key-management algorithm that derives a fresh CEK, the CEK is left as all zero bytes rather than random, meaning the ciphertext is encrypted and authenticated under a fixed, publicly known key. Version 0.6.2.6 fixes it by generating the CEK via RAND_bytes in _cjose_jwe_set_cek_aes_cbc(), with a regression test asserting the encrypted_key differs between two encryptions. Until upgrading, switch the enc to an AES-GCM variant, use alg=dir with a caller-supplied CEK, or stop using cjose for JWE encryption; cjose sits under mod_auth_openidc, so check any Apache OIDC deployment.

  8. Check Point Patches Critical VPN Vulnerabilities (opens in a new tab)

    SecurityWeek ·Ionut Arghire ·fetched 11 Sep 2026, 11:41 UTC CVE-2026-85102 EPSS 0.4% agreed3/3

    Why readTwo unauthenticated RCE flaws (CVE-2026-85102 and CVE-2026-85103, CVSS 9.8) in Check Point Security Gateway, Spark Firewall and Security Management Server, reachable through VPN certificate handling on internet-facing devices.

    CVE-2026-85102 is improper validation of certificate data during VPN negotiation, affecting Security Gateway and Spark Firewall with Site to Site or Remote Access VPN enabled; CVE-2026-85103 is a heap overflow in ASN.1 decoding of VPN certificates, also hitting the Security Management Server. Fixes are out for R82.10, R82 and R81.20. Check Point's interim mitigation is to disable implied VPN rules and manually scope UDP/500 and UDP/4500 to specific peer IPs; EPSS is still low at 0.0036, but edge VPN gateways are the standard ransomware entry point and this class of bug does not stay unexploited long.

  9. ConnectWise patches critical ScreenConnect authentication failure after five days (opens in a new tab)

    CSO Online ·fetched 11 Sep 2026, 19:40 UTC CVE-2026-84869 EPSS 0.4% agreed3/3

    Why readCVE-2026-84869 in ConnectWise ScreenConnect allowed files to be transferred and executed through active remote sessions without authorisation; fixed in client 26.6.5.

    ConnectWise shipped a patch five days after telling customers that support and access sessions in ConnectWise Remote Access could be used to transfer and execute files with no authorisation or confirmation. The interim mitigation was to strip the TransferFiles permission from any user with an open session; the fix lands in ScreenConnect client 26.6.5 and later. EPSS is still low at 0.004, but ScreenConnect is a standing favourite for ransomware affiliates and has been exploited twice before, so treat the upgrade as urgent rather than routine.

  10. Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit (opens in a new tab)

    Dark Reading ·Elizabeth Montalbano ·fetched 11 Sep 2026, 07:39 UTC agreed3/3

    Why readThere is now public exploit code for an unpatched flaw in Windows Defender, a control that is on by default across nearly every Windows estate.

    A researcher using the handle Nightmare-Eclipse has published another unpatched Windows exploit, this one called ShieldCrash and aimed at Windows Defender, continuing a pattern of dropping Microsoft zero-days without coordinated disclosure. Because Defender is the default endpoint control on most Windows fleets, a working public exploit against it is worth triaging immediately for tamper-protection and telemetry-loss impact. The report is thin on technical specifics and there is no CVE or vendor fix yet, so treat the disclosure itself as the actionable signal and watch for Microsoft's response.

  11. CVE-2026-78626 (CVSS 8.1): The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulti (opens in a new tab)

    NVD ·fetched 11 Sep 2026, 19:40 UTC CVE-2026-78626 CVSS 8.1 EPSS 0.2% agreed2/3

    Why readA control you deliberately configured fails open: Okta Access Gateway Protected Rule policies can be bypassed, and nothing in your logs will tell you the policy stopped working.

    CVE-2026-78626 stems from flawed input sanitisation and regular expression evaluation in the Protected Rule authorization check of Okta Access Gateway. Where an administrator has applied a Protected Rule policy to application resources, an attacker with low privileges can bypass the authorization decision entirely and reach confidentiality and integrity impact. The exposure is worst for exactly the organisations that did the extra work of configuring these rules, which makes review of Protected Rule coverage as important as applying the fix.

  12. CVE-2026-76190 (CVSS 8.6): ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in (opens in a new tab)

    NVD ·fetched 11 Sep 2026, 19:40 UTC CVE-2026-76190 CVSS 8.6 EPSS 1.0% agreed2/3

    Why readAn unauthenticated, no-interaction eval injection in ColdFusion is exactly the shape of bug that has been mass exploited on this product before, so inventory and patch status is worth checking today.

    CVE-2026-76190 is an eval injection in Adobe ColdFusion that allows arbitrary code execution in the context of the current user, with no authentication and no user interaction required. The vector carries a changed scope and network reachability, which means an internet-facing ColdFusion instance is directly exposed. EPSS sits near the 60th percentile, higher than most of today's advisories, and ColdFusion's exploitation history argues for treating this as urgent rather than routine.

  1. Metasploit Wrap Up: This One Goes to Sixteen! (opens in a new tab)

    Rapid7 ·Brendan Watters ·fetched 11 Sep 2026, 15:39 UTC Must read Research CVE-2025-54988 EPSS 87.7% agreed3/3

    Why readSixteen new Metasploit modules, ten of them exploits and five targeting CISA KEV entries across Cisco, PaperCut, SonicWall, JetBrains and Langflow.

    This release adds exploit coverage for five vulnerabilities already on the KEV list, meaning red teams and validation programmes can now reproduce confirmed in-the-wild attack paths directly from the framework. Auxiliary additions include a scanner for the Apache Tika XFA XXE reachable through the Elasticsearch ingest-attachment processor (CVE-2025-54988 / CVE-2025-66516, EPSS 0.88) and an unauthenticated blind SQLi scanner for SPIP via date field escaping bypass. Defenders should treat the KEV-aligned modules as a signal that exploitation is now trivially available to anyone with msfconsole.

  2. Don't Trust the Super-App: A Case Study of Russia's Max (opens in a new tab)

    arXiv cs.CR (all) ·Richa Priyanka, Aaron Ortwein, Joel Reardon, Michael Specter ·fetched 11 Sep 2026, 15:39 UTC Must read Research agreed3/3

    Why readDemonstrates that a super-app host can capture mini-app UI, read and write mini-app local storage, inject arbitrary JavaScript into the mini-app runtime, proxy its network traffic, and control authentication context well enough to impersonate users silently.

    A decade of super-app security research assumed the host app is a trusted intermediary; this paper attacks that assumption using Russia's MAX as the case study. The authors enumerate host capabilities that leave no trace on the mini-app side, including UI capture, storage read/write, runtime JavaScript injection, network mediation and auth-context control enabling silent impersonation. The threat model generalises to WeChat, Bale and any other state-adjacent super-app platform, which matters for anyone assessing mini-app deployments in those ecosystems.

  3. Getting a stranger’s phone kicked off the cellular network costs a few dollars (opens in a new tab)

    Help Net Security ·Mirko Zorz ·fetched 11 Sep 2026, 07:39 UTC agreed3/3

    Why readShows that the IMEI printed on a sealed retail box is enough to have a stranger's phone blocklisted from the cellular network for a few dollars.

    Researchers at Michigan State University and three partner institutions bought a Samsung Galaxy Z Fold 7, copied the identifier from the unopened box, and reported the device to the carrier as lost; when they then unboxed and activated it, it would not connect. The team documented six weaknesses in the lost-and-stolen device reporting process, which relies on an identifier that is visible before purchase and accepts reports without proof of ownership. The result is a cheap, remote denial of service against any handset whose box has been photographed in a warehouse, a shop or a delivery chain.

  4. In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review (opens in a new tab)

    SecurityWeek ·SecurityWeek News ·fetched 11 Sep 2026, 15:39 UTC agreed3/3

    Why readIntroduces InjectEave, a side-channel class in which an injected RF signal makes ordinary consumer hardware leak analog audio it was never meant to transmit.

    Researchers demonstrated that an external radio frequency signal can drive nonlinearities in commercial devices and cause them to leak low-frequency analog information, recovering private audio across 11 tested products including headphones, VoIP phones, smart fans and lamps. The same roundup covers a 16 month sentence for a former AT&T employee who sold SIM swaps at $1,000 to $2,000 each, and the extradition of a Russian national accused of running a credential harvesting operation that hoarded more than 5,000 stolen logins. The InjectEave work is the piece with lasting value; the rest is case tracking.

  5. EFI Pairs Without One-Way Puzzles: Oracle Separations from Communication Complexity (opens in a new tab)

    arXiv cs.CR (all) ·Atul Mantri ·fetched 11 Sep 2026, 03:39 UTC Research agreed3/3

    Why readAn oracle separation showing EFI pairs can exist where one-way puzzles do not, narrowing the candidate minimal assumption for quantum cryptography.

    The paper builds a single classical oracle that answers every question about the output probabilities of quantum samplers, which kills one-way puzzles even against an unbounded verifier, while hiding a Haar-random half-dimensional subspace that sustains an EFI pair against distinguishers making classical queries throughout plus one superposition query at the end. Security is proved by reduction to communication complexity, simulating an adversary whose subspace knowledge arrives as classical answers inside a two-party protocol. Foundational theory with no near-term operational consequence, but it moves an open question about which of the two primitives is genuinely minimal.

  1. Linux Detection Engineering - Local Privilege Escalation (opens in a new tab)

    Elastic Security Labs ·Ruben Groenewoud ·fetched 11 Sep 2026, 15:39 UTC Must read agreed3/3

    Why readMaps the recurring Linux local privilege escalation patterns of the past year to the process and file events they generate, with the detection rules that fire on each.

    The latest entry in Elastic's Linux Detection Engineering series works through the default execution flow a Linux LPE produces on a host and the general rules that catch it, then breaks down the specific patterns behind recent escalations: SUID helpers such as sudo, pkexec and polkit, kernel bugs in ELF loading, ptrace, eBPF and packet sockets, and user namespace abuse. Each pattern is paired with the Elastic Defend telemetry it surfaces in and the endpoint and detection rules that fire. Usable even off Elastic, because the behavioural signatures translate to any EDR with process ancestry and file execution events.

  2. The Agentic IDE Extension Blind Spot (opens in a new tab)

    SafeDep (supply chain) ·fetched 11 Sep 2026, 11:41 UTC Research agreed3/3

    Why readShows that Cursor's Import VS Code Configuration step sends only extension names and no versions, so pinned extensions silently upgrade to whatever Open VSX calls newest, with no publisher-identity verification between the two registries.

    VS Code forks such as Cursor and Antigravity cannot use Microsoft's marketplace, so they pull from Open VSX, run by the Eclipse Foundation, where the same extension name may map to a different publisher or a different version. The authors held three extensions at pinned older versions, ran Cursor's import, and got all three back at the newest Open VSX version. The workaround is explicit pinning via cursor --install-extension <publisher>.<name>@<version>, and the broader finding is that agentic IDE migration quietly breaks any extension version control a team thought it had.

  3. From Specs to Apps: Verifying and Monitoring Models of Signal and WhatsApp (opens in a new tab)

    arXiv cs.CR (all) ·Moustafa Said, Aurora Naska, Kevin Morio, Robert Künnemann ·fetched 11 Sep 2026, 07:39 UTC Research agreed3/3

    Why readBuilds the first formal model of WhatsApp Web's Signal protocol implementation and checks live executions against it with a runtime monitor.

    The authors instrument WhatsApp Web and Signal Desktop to capture network traffic and calls into the cryptographic components, then express two multiset-rewrite models compatible with Tamarin so observed runs can be checked for conformance to the verified specification. This closes the usual gap between a proved protocol and what the shipped client actually does at runtime. The method, SpecMon-style conformance monitoring against a Tamarin model, transfers to any protocol implementation you can instrument.

  4. The CVE spike across major software companies is a remediation problem (opens in a new tab)

    Aikido Security ·fetched 11 Sep 2026, 07:39 UTC agreed3/3

    Why readArgues the 6x jump in monthly critical and high CVEs across 21 major vendors is a disclosure-rate artefact, not a risk shift, because KEV volume has not moved since 2024.

    An a16z chart built on Epoch AI data shows critical and high CVEs across Apple, AWS, Microsoft, Google, Adobe and 16 other vendors rising from under 100 per month to over 600 since spring 2026. Aikido takes the position that flat KEV growth over the same period means the increase reflects more finding and reporting rather than more exploitable danger, and that the binding constraint is remediation throughput. It is a position specific enough to argue with, and the KEV-versus-disclosure framing is usable in your own vulnerability metrics.

  1. The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th) (opens in a new tab)

    SANS ISC Diary ·fetched 11 Sep 2026, 15:39 UTC Must read Research agreed3/3

    Why readFirst-hand honeypot capture of a coding agent that finds, compromises and re-sells LLM API access, then feeds that stolen inference capacity back into its own operations.

    An operator running a semi-autonomous coding agent was observed hunting poorly secured LLM resale gateways, taking API access through ordinary web flaws and account farming, validating the capacity and consolidating it behind a single OpenAI-compatible gateway of their own. The capture came from an AI honeypot emulating an inference endpoint that the agent repeatedly selected as a free backend, so the reconstruction is based on the agent's own traffic rather than on downstream reporting. The finding is the feedback loop: stolen inference funds further acquisition, making the supply chain partially self-expanding, which means exposed LLM gateways are now an asset class worth attacking in their own right.

  2. GuardBreaker: Derailing AI-assisted malware analysis with a code comment (opens in a new tab)

    ESET WeLiveSecurity ·fetched 11 Sep 2026, 07:39 UTC Must read Research agreed3/3

    Why readDocuments a real in-the-wild attempt to derail LLM-assisted malware triage by planting a prompt injection in a script comment, used by Russia-aligned UAC-0099 against a Ukrainian target.

    ESET found a VBScript from UAC-0099 containing a decoy comment asking for guidance on building a nuclear weapon, placed to trip an analysis model's safety refusal and stop it reasoning about the code. The technique sits alongside conventional anti-analysis tradecraft but targets the analyst's tooling rather than the sandbox, and it needs nothing more than plaintext in a file the analyst is already feeding to a model. If your triage pipeline pipes untrusted samples into an LLM, treat sample content as hostile input to the model, not just to the host.

  3. SpecGuard: Inference-Time Backdoor Detection For Free (opens in a new tab)

    arXiv cs.CR (AI) ·Rui Wen, Ahmed Salem, Andrew Paverd, Mark Russinovich ·fetched 11 Sep 2026, 07:39 UTC Research agreed3/3

    Why readDetects LLM backdoor triggers at inference time by reading the accept/reject signal speculative decoding already produces, with no extra model computation.

    SpecGuard observes that when a backdoor trigger fires, the target model diverges from a clean draft model, so the verification step in speculative decoding leaks a usable detection signal for free. Unlike prior inference-time detectors it makes no assumption about trigger form and adds no perturbation passes or second generation, which matters for latency-sensitive serving. Relevant if you host third-party or frequently re-finetuned weights and need runtime monitoring rather than a one-off pre-deployment audit.

  4. ToxicRAG: Compromising Retrieval-Augmented Generation Systems via Single-Shot Knowledge Poisoning Attacks (opens in a new tab)

    arXiv cs.CR (AI) ·Haozhe Lu, Jiaqi Li, Xinyuan Zhu, Xiang Li ·fetched 11 Sep 2026, 15:39 UTC Must read Research agreed3/3

    Why readA single poisoned document, framed as a plausible knowledge update, flips RAG answers with attack success rates of 0.61 to 0.91 across four LLMs and four dense retrievers.

    ToxicRAG generates one document per target that acknowledges the previously correct answer, invents events that appear to invalidate it, and attributes the attacker's answer to purported authorities, with an optional self-validation loop that revises the document when a surrogate model fails to reproduce the target. Evaluated on 100 questions each from Natural Questions, HotpotQA and MS-MARCO against four victim LLMs and four retrievers, it matches or beats multi-document baselines at one-twelfth of the injection footprint. For anyone running RAG over a corpus with any write path, it means detection heuristics based on injection volume or templated assertions will not catch this.

  5. Anthropic caught Russia-linked spies using Claude in hacking operations (opens in a new tab)

    The Record ·fetched 11 Sep 2026, 15:39 UTC agreed3/3

    Why readA named AI vendor has published campaign level detail, with indicators, on a state espionage group that ran its operations through a commercial model.

    Anthropic's threat report covering December 2025 to August 2026 describes a Russia-linked espionage group that used Claude against more than 20 government, intelligence, diplomatic and defence organisations, alongside criminal and hacktivist misuse. Unlike comparable OpenAI reporting, the document includes per campaign analysis and indicators of compromise that defenders can actually pivot on. The gap is scale: Anthropic still declines to say what share of activity it detects, so the report reads as a curated sample rather than a baseline.

  6. BlueSTAR: Tiered Agentic Architecture for Autonomous Cyber Defense (opens in a new tab)

    arXiv cs.CR (AI) ·Simona Boboila, Xavier Cadet, Edward Koh, Daniel Balasubramanian ·fetched 11 Sep 2026, 03:39 UTC Research agreed3/3

    Why readA tiered LLM defence architecture that compresses raw telemetry into indicators before reasoning, evaluated against seven real-world attack chains on two live IT/OT cyber ranges.

    BlueSTAR addresses the practical blockers to putting LLMs on live security telemetry: logs arrive faster than models can consume them, single events are ambiguous, and unconstrained agent actions carry operational risk. The architecture first reduces high-volume telemetry to compact IOCs, then reasons over those, and the authors introduce a resilience metric scoring attacker reach, impact on mission-critical assets and the disruption caused by the defensive response itself. Evaluation runs on two enterprise IT/OT ranges across seven attack chains built from real intrusion techniques, which is a harder test bed than most agentic defence papers use.

  7. CVE-2026-82533 (CVSS 9.4): DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-contr (opens in a new tab)

    NVD ·fetched 11 Sep 2026, 07:39 UTC CVE-2026-82533 CVSS 9.4 EPSS 0.4% agreed3/3

    Why readDeepSeek Harness before 0.1.2-alpha.1 trusts a client-supplied loopback Host header instead of the real TCP origin, so a sandboxed tool process can call the local agent-control API, escape its own sandbox and switch off the approval prompt.

    CVE-2026-82533 (CVSS 9.4) is an authentication bypass in the harness's local HTTP agent-control API: because origin is inferred from the Host header rather than the connection, a confined tool-executed process reaches the API on the default configuration with no port exposure needed, then escalates to unconfined execution and disables approval prompts. If the port is reachable through a tunnel, SSH forward or reverse proxy, an unauthenticated remote attacker can create sessions, run arbitrary commands and pull stored conversation transcripts. The pattern generalises to any agent runner that gates a control plane on a header, which makes it worth auditing your own harnesses and not just upgrading this one.

  8. BenchShield: Formal Model-Backed Instrumentation for Reward Integrity in LLM-Agent Evaluation Infrastructure (opens in a new tab)

    arXiv cs.CR (AI) ·Shenghan Zheng, Zonglin Di, Yimin Liu, Kyoung Whan Choe ·fetched 11 Sep 2026, 19:40 UTC Research agreed3/3

    Why readBenchShield instruments LLM-agent benchmarks with a finite lifecycle model of reward-relevant events, then uses static taint analysis to surface reward-hacking paths before a run and runtime evidence to attribute them during it.

    The argument is that current defences against agents gaming their own evaluations are task-specific patches, prompt instructions or post-hoc detectors, none of which produce reusable evidence that a given run stayed inside its evaluation boundary. BenchShield adds a phase-aware taint pass over the reward lifecycle plus an infrastructure-side runtime counterpart emitting evidence-backed claims. Relevant if you run agent benchmarks or rely on their scores as a security control.

  9. Predicting Privacy Leakage from Weight Spectral Density (opens in a new tab)

    arXiv cs.CR (all) ·Richard J. Preen, Jim Smith ·fetched 11 Sep 2026, 19:40 UTC Research agreed3/3

    Why readShows that cheap WeightWatcher spectral metrics predict membership inference vulnerability better than the generalisation gap, removing the need to train shadow models to audit a model's privacy risk.

    Across image and tabular classification tasks, stable rank correlates positively with overall MIA success while Log alpha-Norm correlates negatively with vulnerability in the low false-positive regime, and both associations beat conventional overfitting measures. The practical consequence is that privacy leakage can be screened at scale from weights alone, since shadow-model attacks are too expensive to run over a model inventory. Correlational rather than causal, so treat it as triage signal rather than a clean bill of health.

  10. Data Maskit: Local privacy data masking gateway for LLMs (opens in a new tab)

    translated xiaYuTian11/maskit: 数据面具 Data Maskit — 专为大模型打造的本地隐私脱敏网关(请求自动打码,回复流式还原;支持 Cursor / Claude Code / Codex / Pi 等任意可配 Base URL 工具)

    GitHub: new security tools ·xiaYuTian11 ·fetched 11 Sep 2026, 19:40 UTC Research ★ 143 agreed3/3

    Why readA local reverse-proxy gateway that strips credentials, connection strings and internal IPs out of prompts before they leave for Cursor, Claude Code or Codex, then restores them in the streamed reply.

    Maskit sits between a developer's AI tooling and the model provider as a local proxy, replacing matches from 19 built-in regex classes (API keys, PEM private keys, database connection strings, phone numbers, ID numbers, bank cards, RFC1918 addresses) with structured placeholders and reversing them in the streamed response. Placeholders are reused across turns in the same conversation so a given name maps to the same token in round 1 and round 10, keeping model reasoning consistent. It runs per-protocol ports (18701 OpenAI, 18702 DeepSeek, 18703 Anthropic) so no CA certificate has to be installed, and falls back to transparent plaintext passthrough if the masking layer is off.

  11. Atlas: Efficient Verifiable Semantic Search (opens in a new tab)

    arXiv cs.CR (all) ·Nikolay Avramov, Hidde Lycklama, Alexander Viand, Anwar Hithnawi ·fetched 11 Sep 2026, 11:41 UTC Research agreed3/3

    Why readA zero-knowledge proof construction that makes graph-based vector retrieval verifiable, which is the first credible answer to 'how do I know the RAG provider actually searched the whole index?'

    Atlas builds a zero-knowledge proof for HNSW traversal, letting a semantic search provider prove a query was answered by the agreed algorithm over a committed index without revealing that index. Earlier verifiable retrieval work sidestepped HNSW because its data-dependent walk fits badly into fixed constraint systems, and settled for cluster-based indices with worse recall. The practical target is outsourced RAG and recommendation, where a provider can quietly truncate search to save compute and no client can tell; treat it as a preprint direction rather than something deployable now.

  12. From Intent to Execution Grant: An Execution-Boundary Conformance Profile for High-Risk AI Actions (opens in a new tab)

    arXiv cs.CR (AI) ·Mengting Wu, Lin Wang, Yong Zhang, Jiang Deng ·fetched 11 Sep 2026, 11:41 UTC Research agreed3/3

    Why readProposes a concrete semantic contract, EBL-Core, for the moment an AI agent's proposed action gets execution authority, with separated release decisions and redemption-time grants.

    EBL-Core specifies a conformance profile for authorising a single fully materialised AI-generated candidate action: a structured intent object, Root and Operational Policies, typed evidence obligations, context and time bindings, and a verifiable Decision Derivation, all bound through an Execution Release Contract. The design deliberately separates the ERC from an authority-bearing token, so a verified ALLOW supports a later Execution Grant validated at redemption time, with action binding, policy non-weakening and determinism requirements stated. Useful reading for anyone designing authorisation around agents that touch payments, deployments or infrastructure, though it is a specification rather than a tested implementation.

  1. A Community Guide to the EU CRA September 11 Deadline for Manufacturers (opens in a new tab)

    OpenSSF ·OpenSSF ·fetched 11 Sep 2026, 19:40 UTC Must read agreed3/3

    Why readThe EU CRA's mandatory incident reporting obligations for manufacturers take effect today, 11 September 2026, while the Steward regime does not bite until 11 December 2027.

    OpenSSF sets out which parts of the Cyber Resilience Act apply to whom and when: manufacturers face the mandatory reporting requirements from 11 September 2026, while open source stewards have until 11 December 2027. The split matters because most maintainers fall under the lighter Steward framework but their downstream commercial consumers are Manufacturers, and those obligations flow back upstream as requests for security contact points, SBOM data and vulnerability handling. Useful for anyone who ships software into the EU or maintains a project that does.

  2. Accountability, oversight and AI: Inside Microsoft’s security transformation (opens in a new tab)

    Cybersecurity Dive ·Eric Geller ·fetched 11 Sep 2026, 15:39 UTC agreed2/3

    Why readShows what accountability restructuring actually looked like at Microsoft after LAPSUS$, the 2023 Russian and Chinese intrusions and the CSRB rebuke, which is the yardstick other large programs now get measured against.

    Microsoft says the Secure Future Initiative, launched in November 2023, is starting to show results in how security responsibility is assigned and reviewed inside the company. The reporting traces the pressure that produced it: the LAPSUS$ break in, separate Russian and Chinese intrusions that cost State Department and other customer data, and a federal review board that called the company's practices lax. The value for a reader outside Microsoft is the governance mechanics, specifically how oversight and individual accountability were wired into engineering rather than bolted on as policy.

  3. UK government rejects 'kill switch' idea for dangerous AI (opens in a new tab)

    BBC Technology ·fetched 11 Sep 2026, 15:39 UTC agreed3/3

    Why readThe Cabinet Office has formally opposed the parliamentary proposal for a legal AI kill switch, which effectively ends its chance of becoming UK law.

    Lords and MPs brought forward a proposal for a legal mechanism letting the UK switch off an AI model in an emergency. The Cabinet Office, which leads on AI safety, said the UK "cannot simply turn AI off" and that blocking access to models domestically would not stop their development or misuse elsewhere. Government opposition does not stop the bill progressing but makes passage unlikely, so UK AI obligations stay where they are for now.

  4. Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy (opens in a new tab)

    EFF Deeplinks ·Thorin Klosowski ·fetched 11 Sep 2026, 19:40 UTC agreed3/3

    Why readExplains precisely where Ring's new Throw Away the Key scheme falls short of end to end encryption, and why that gap still exposes footage to legal process.

    Ring's TAKE feature moves encryption key handling so that the company holds a key in its own cloud for up to 24 hours before deleting it, which is what lets it keep running video descriptions, smart alerts and search. EFF's argument is that a 24 hour window of company-held keys is a speed bump rather than privacy, since footage remains reachable by Amazon and by anyone who compels Amazon during that window. A clean worked example of the feature-versus-encryption trade that keeps recurring in consumer cloud products.

  5. CISA Updates Insider Threat Guide With New Mitigation Advice (opens in a new tab)

    Infosecurity Magazine ·fetched 11 Sep 2026, 03:39 UTC agreed3/3

    Why readCISA's insider threat program guide now addresses hybrid work, AI and hostile terminations, the three gaps most programs written against the 2020 edition still carry.

    The Insider Threat Mitigation Guide, first issued in 2020, was reissued on 9 September in a consolidated format with new case studies, statistics and use cases. The added material covers how remote and hybrid working changes the risk picture, artificial intelligence, and adverse employee separations. It is aimed jointly at security and HR, which is the pairing insider programs depend on and rarely formalise, and it works best as a reference to benchmark an existing program against rather than as new research.

  6. We All Deserve a Better Internet, Not A Smaller One (opens in a new tab)

    EFF Deeplinks ·Josh Richman ·fetched 11 Sep 2026, 07:39 UTC agreed2/3

    Why readCalifornia's AB 1709 is signed and now law, so any platform with minor users in the state needs an age-assurance and access-restriction plan on a real timeline.

    Gov. Newsom signed AB 1709, which EFF describes as a functional bar on social media use for people under 16 in California. EFF and allied groups argue the law cuts young people off from information and support communities rather than addressing platform design or data practices, and they signal opposition on speech and access grounds. The compliance takeaway is the statute itself: operators will need age determination and minor-account handling for California users, and the advocacy pushback suggests the scope and mechanics will be contested.

  1. IDScan confirms breach after 153 million driver’s licenses leak on dark web (opens in a new tab)

    Help Net Security ·Sinisa Markovic ·fetched 11 Sep 2026, 19:40 UTC Must read agreed3/3

    Why readAn identity verification vendor used by car rental firms, retailers and dispensaries has confirmed a breach after 153 million driver's licence scans surfaced on a dark web market.

    IDScan.net posted a notice on 4 September confirming that attackers accessed customer data held on its cloud platform, days after a dark web database of more than 153 million driver's licence scans was linked to the company. The Louisiana firm runs ID checks on behalf of car rental companies, retailers and cannabis dispensaries, so the exposed records are third-party consumer identity documents rather than the company's own users. Anyone who outsources age or identity verification should be asking where those scans are retained and for how long.

  2. Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device (opens in a new tab)

    The Record ·fetched 11 Sep 2026, 23:38 UTC agreed3/3

    Why readFlorida's DMV confirms a breach traced to one Plant City police officer's credentials stored on a personal device, with ShinyHunters claiming the data.

    The Florida Department of Highway Safety and Motor Vehicles confirmed a breach on Thursday after ShinyHunters claimed access to its data on Monday. Officials learned of it on September 4 and say a criminal actor abused a single Plant City Police Department user's login that was improperly kept on that employee's personal device. The shape of this matters beyond Florida: state motor vehicle databases are queried by hundreds of small municipal agencies, and one officer's reused or personally stored credential is enough to expose the whole dataset.

  3. 4.1M Impacted by AdaptHealth Data Breach (opens in a new tab)

    Google News: incidents · securitymagazine.com ·fetched 11 Sep 2026, 07:39 UTC agreed3/3

    Why read4.1 million people affected in a breach at home medical equipment provider AdaptHealth, a figure large enough to land in healthcare-sector board discussions.

    AdaptHealth has disclosed a data breach impacting roughly 4.1 million individuals. The reporting carries the scale and the named organisation but not the intrusion vector, dwell time or data categories. It goes onto the running list of large US healthcare breaches that regulators and insurers are tracking this year.

  4. Boston Scientific fully restores operations after cyberattack (opens in a new tab)

    Google News: incidents · MedTech Dive ·fetched 11 Sep 2026, 19:40 UTC agreed3/3

    Why readBoston Scientific says operations are fully restored following a cyberattack, closing out an incident at a major medical device manufacturer.

    Only the headline reached us, so the recovery timeline, the initial vector and whether data was taken are not established here. The fact worth carrying is the named manufacturer and a declared return to normal operations, which is what peers in medtech and their hospital customers will be asked about.

  5. Cyberattack halts state financial aid office operations (opens in a new tab)

    Google News: incidents · Mississippi Today ·fetched 11 Sep 2026, 07:39 UTC agreed3/3

    Why readA US state financial aid office has had operations halted by a cyberattack, per Mississippi Today.

    Mississippi's state financial aid office is reported to have suspended operations following a cyberattack. Only the headline reached us, so there is no detail on the intrusion vector, the actor, or student data exposure. Worth flagging for anyone tracking attacks on state government service delivery, particularly at the start of the aid disbursement cycle.

  6. Ukrainian hacker gets four years in US prison over Conti ransomware attacks (opens in a new tab)

    The Record ·fetched 11 Sep 2026, 19:40 UTC agreed3/3

    Why readOleksii Lytvynenko, a Conti developer and operator, drew four years in US prison after a June guilty plea, with stolen data from twelve victims found in his accounts.

    DOJ says the 44-year-old, previously resident in Cork, Ireland, personally targeted at least a dozen companies and helped build tooling for the group, which hit organisations across 47 US states and 31 countries before shutting down in 2022. The FBI put Conti ransom receipts above $150 million as of January 2022. A four-year sentence for a core developer is the kind of number an executive team will ask about when weighing deterrence against ransom decisions.

  7. Veradigm reports third-party vendor cyberattack (opens in a new tab)

    Google News: incidents · Healthcare IT News ·fetched 11 Sep 2026, 19:40 UTC agreed3/3

    Why readVeradigm, a healthcare IT and EHR vendor, has disclosed a cyberattack at a third-party supplier.

    Only the headline reached us, so the affected vendor, the data involved and any provider downstream impact are not established. The disclosure itself is the fact: another third-party compromise landing on a large healthcare software provider, which is the question customers and boards in that sector will raise.

  8. Sheriff’s Office in Wisconsin suspends Flock cameras over data breach (opens in a new tab)

    Google News: incidents · WFRV Local 5 ·fetched 11 Sep 2026, 15:39 UTC agreed2/3

    Why readA law enforcement customer has pulled a widely deployed ALPR system out of service over a breach, which is the rare case of vendor risk producing an actual operational consequence.

    A Wisconsin sheriff's office has suspended its use of Flock automated licence plate reader cameras following a data breach at the vendor. Flock's network spans thousands of US agencies, so a customer choosing suspension over continued operation sets a reference point other departments and their oversight bodies will be asked about. Details of what was exposed remain sparse at this stage.

  9. Patients struggle to access care more than a week after Luminis Health cyberattack (opens in a new tab)

    Google News: incidents · foxbaltimore.com ·fetched 11 Sep 2026, 03:39 UTC agreed2/3

    Why readA dated marker for how long a mid-size health system stayed degraded after an attack, useful when arguing recovery-time assumptions against what actually happens.

    Luminis Health, which operates Anne Arundel Medical Center and Doctors Community Medical Center in Maryland, was still unable to restore normal patient access more than a week after a cyberattack, with appointments, records and pharmacy workflows affected. The report is local broadcast coverage of the outage's effect on patients rather than an incident analysis; there is no attribution, intrusion vector or ransomware family named. Its value is narrow and operational: another confirmed case where healthcare downtime ran past eight days, which is the number worth carrying into continuity planning, not the one most plans assume.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
compunnel.com safepay Technology US 11 Sep 2026
Imperial Healthcare Solutions qilin Healthcare US 11 Sep 2026
DiamondLease nightspire - AE 11 Sep 2026
Perimetral Oriental de Bogotá S.A.S. nightspire Transportation CO 11 Sep 2026
Ozel & Ozel Laws Office nightspire Professional Services TR 11 Sep 2026
Tuboaços da Amazônia Ltda. nightspire Manufacturing BR 11 Sep 2026
Port of Tanjung Pelepas direwolf Transportation MY 11 Sep 2026
Foss Inc. pear - US 11 Sep 2026
Dustin Group fulcrumsec Technology SE 11 Sep 2026
Konica Minolta Bulgaria Panzer Manufacturing BG 11 Sep 2026
Medical Department Store dragonforce Retail & E-Commerce US 11 Sep 2026
Agencia Estatal de Meteorología Panzer Government & Defense ES 11 Sep 2026
CO-OP URBAN BANK LTD Global Secret Group Financial Services IN 10 Sep 2026
i2k2 Networks Vexy Ransomware Technology IN 10 Sep 2026
M800 and CINNOX beast Technology HK 10 Sep 2026
ki***jp AuditTeam - JP 10 Sep 2026
my***ru AuditTeam Technology RU 10 Sep 2026
Sys-kool play Technology - 10 Sep 2026
Grunthal Welding & Supplies play Manufacturing CA 10 Sep 2026
alphaomega-eng.com lockbit5 Professional Services DE 10 Sep 2026
General Santos Doctors Hospital rhysida Healthcare PH 10 Sep 2026
Professional Retail Services rhysida Retail & E-Commerce - 10 Sep 2026
California School Employees Association ransomhouse Education US 10 Sep 2026
mankatoclinic.com chaos Healthcare US 10 Sep 2026
artiflexmfg.com chaos Manufacturing US 10 Sep 2026
How this edition was made
Candidates fetched
4782
New after deduplication
720
Kept by the panel
153
Published
118
Generated
11 Sep 2026, 23:38 UTC