CFToday Curated security signals.

Daily edition · 2026-09-14

Monday, 14 September 2026

51 items across 8 sections, selected from 4564 candidates over 6 runs. 87 carried the panel unanimously.

Show
Section

  1. Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit (opens in a new tab)

    Group-IB ·fetched 14 Sep 2026, 11:43 UTC Must read Research agreed3/3

    Why readTeardown of the Smishing Triad's JWR phishing kit: AES-256-CTR over WebSocket for exfil, real-time operator control of victim sessions, and indicators tied to the Outsider cluster.

    The JWR kit walks SMS-lured victims through a staged capture funnel (identity, card, OTP, sometimes a second bank or wallet) while a human operator watches the session live and pushes control instructions. Communications run over encrypted WebSockets using AES-256-CTR, with short-link redirection into disposable apex domains hosting the kit. Group-IB names the Outsider operator cluster and publishes infrastructure detail and indicators; the real-time operator handoff is the part detection built around static landing pages will miss.

  2. Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider (opens in a new tab)

    TechCrunch Security ·Zack Whittaker ·fetched 14 Sep 2026, 03:41 UTC Must read agreed3/3

    Why readA concrete case of a marketing platform compromise being turned straight into credential theft at scale, with the lure text and the account numbers attached.

    Attackers reached 138 customer accounts at Brevo, the email platform Trezor uses for newsletters, by abusing access that the company says was not properly scoped, then sent roughly 347,000 phishing messages that arrived with legitimate Trezor sender reputation. One lure used the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and pushed recipients to an app that asks for the wallet backup password, which is enough to drain funds irreversibly. This is Trezor's second supplier compromise in two months, and it is a clean argument for treating your email service provider as production infrastructure with its own tenant isolation and monitoring requirements.

    Also covered byInfosecurity Magazine (opens in a new tab).

  3. Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence (opens in a new tab)

    Huntress ·fetched 14 Sep 2026, 07:41 UTC Research agreed3/3

    Why readTwo incidents where browser-in-the-browser phishing delivered a fake Adobe Reader update and multiple rogue ScreenConnect instances for persistence, with named defence-evasion binaries to hunt for.

    Huntress analysed two attacks using the same BiTB template and lure, which rendered a fake browser window to push an "updated Adobe Reader" download. The chain installed several rogue ScreenConnect instances for persistence, then used them to fetch and run HideCursor.exe and HideUL.exe to hide attacker activity on the host. Useful detection angles: unmanaged ScreenConnect instances and the two evasion binaries as child processes of an RMM agent.

    Indicators14
    Hashes
    41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2 9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991 f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35
    URLs
    hxxps://adoube[.]vu/2a8ed9baefcd hxxps://adoube[.]vu/filedocacess/file[.]html hxxps://wir[.]consultingics[.]com/Bin/ScreenConnect[.]ClientSetup[.]msi
    Addresses
    144[.]172[.]115[.]59
    Domains
    hosthiifran[.]screenconnect[.]com instance-uxh86b-relay[.]screenconnect[.]com selectstructure[.]com victory[.]mkc1[.]digitaloceanspaces[.]com scx[.]illuminantgroup[.]net relay[.]illuminantgroup[.]net
  4. Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 14 Sep 2026, 11:43 UTC agreed3/3

    Why readNamed Chrome and Firefox extension IDs for "Twitch Enhanced Viewer | JeetBot", still live, forwarding roughly 31,000 users' OAuth tokens to a Russian bot service's proxies.

    Socket found that current v85.x builds of the extension pass the Twitch OAuth token inline as an &auth= query parameter on a network-layer redirect to the operator's proxy servers. The Chrome listing (pnhhdhhcadcjfckjhpmjneldiegbojfb, about 30,000 users, published June 2025) and the Firefox add-on (604 users, July 2025) were both still downloadable at publication, developer listed as HISHIMIRO/jeetbot.cc. Concrete identifiers to block or hunt for in managed browser estates, though the original Socket writeup is the primary source.

    Indicators1
    Domains
    usher[.]ttvnw[.]net
  5. Four groups caught using the same Chrome and Windows exploit kit (opens in a new tab)

    Proofpoint ·fetched 14 Sep 2026, 07:41 UTC agreed3/3

    Why readReports that four separate groups were observed using a shared Chrome and Windows exploit kit, which points at a common broker or supplier rather than four independent capabilities.

    Four distinct actor sets have been caught deploying the same exploit kit targeting Chrome and Windows, suggesting shared tooling sourced from one developer or broker. Capability sharing of this kind changes attribution logic: overlapping exploitation artefacts across unrelated intrusions no longer imply one actor. Item reached us with little more than the headline, so the underlying research is the thing to read for the exploit and cluster detail.

  6. Grand Theft Auto VI hype leads to malware (opens in a new tab)

    Huntress ·fetched 14 Sep 2026, 07:41 UTC Research agreed3/3

    Why readBreakdown of a fake GTA6 leak ISO that bundles a decoy installer, several RATs, an infostealer and ransomware used as a wiper, distributed through SEO poisoning and torrent sites.

    Huntress traced SEO poisoning and forum, social and torrent postings offering a "leaked" Grand Theft Auto VI build ahead of the game's release. The analysed ISO contains a fake installer plus multiple RATs, an infostealer, a web browser, and ransomware deployed as a wiper rather than for payment. Language in the installer prompts and the ransom note points at Russian-speaking gamers as the intended victims, making this mainly a consumer and BYOD-adjacent lure rather than an enterprise campaign.

    Indicators5
    URLs
    hxxps://clck[.]ru/34uJnp hxxps://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y0M_A86oJHp00O-l8F4jakfVhqFXzMBoy1uBDdj2rBLc
    Addresses
    141[.]8[.]197[.]42
    Domains
    7[.]tcp[.]eu[.]ngrok[.]io a0700877[.]xsph[.]ru
  7. 14th September – Threat Intelligence Report (opens in a new tab)

    Check Point Research ·urias ·fetched 14 Sep 2026, 15:40 UTC CVE-2026-72898 EPSS 94.2% agreed3/3

    Why readWeekly breach roundup whose operational item is a Metabase SQL injection, CVE-2026-72898, already used to take more than a million Mathspace records.

    Check Point's bulletin for the week of 14 September covers the IDScan.net identity verification breach, where names and government ID numbers were exposed and a criminal marketplace began advertising millions of scanned identity documents, plus a Revolut data exposure traced to staff fulfilling fraudulent information requests. The item with a clear action attached is Mathspace, an education platform used in Australia and New Zealand, where attackers exploited CVE-2026-72898 in a self-hosted Metabase instance to reach an internal reporting database of names, email addresses, usernames and locations. That CVE now sits at an EPSS of 0.94, so any self-hosted Metabase deployment is worth inventorying and patching this week.

  8. August 2026 Dark Web Breach Incident Trend Report (opens in a new tab)

    AhnLab ASEC ·ATCP ·fetched 14 Sep 2026, 03:41 UTC agreed3/3

    Why readMonthly roll-up of dark web leak and initial-access listings, with ShinyHunters claims spanning a US data centre operator, a French IP services firm and several national government agencies.

    AhnLab's August 2026 breach trend report tracks database leaks, internal data sales and initial access brokerage across dark web forums. ShinyHunters continued a run of claimed breaches and public extortion threats, and the report notes the group abusing the .Claims top-level domain against streaming platforms. Government sector claims included a Brazilian government IT service agency, a French education administration body, an Argentine identity management agency and an electoral commission in the Dominican Republic. Victim names are mostly generalised and AhnLab states some claims could not be verified.

  9. August 2026 Dark Web Issue Trend Report (opens in a new tab)

    AhnLab ASEC ·ATCP ·fetched 14 Sep 2026, 03:41 UTC agreed3/3

    Why readCurrent domain state for the major leak forums (RaidForums, DarkForums, XSS, BreachForums, PwnForums), which matters if you maintain CTI collection against them.

    After the RaidForums domain was suspended a new one launched, alongside a third-party forum reusing the RaidForums name, splitting the brand between original operators and imitators. DarkForums cycled through several suspended domains before reappearing, XSS published a new main domain plus a link-monitoring domain with WHOIS changes on the old one, and BreachForums surfaced a new clearnet domain and Tor address. PwnForums now redirects mirrors to its main site, while Shoutbox activity is declining.

  10. Pro-Ukraine Hacking Cat group deploying new malware against Russian targets (opens in a new tab)

    The Record ·fetched 14 Sep 2026, 19:42 UTC agreed2/3

    Why readTwo named malware families for a hacktivist group that has crossed from defacement into data destruction.

    Kaspersky attributes a previously undocumented remote access tool it calls Gorilla RAT, along with Monkey Ransomware which appends the .monkey extension, to the pro-Ukraine group Hacking Cat. The group has hit Russian organisations since roughly February 2024 and turned toward encryption and wiping by summer 2025. Kaspersky notes the group shares tooling with other Ukraine-linked actors, which makes per-incident attribution notably harder.

  11. August 2026 Dark Web Threat Actor Trend Report (opens in a new tab)

    AhnLab ASEC ·ATCP ·fetched 14 Sep 2026, 03:41 UTC agreed3/3

    Why readTracks which hacktivist crews (NoName057(16), BD Anonymous, Dark Storm Team) were hitting which Japanese and Norwegian public sector targets in August 2026.

    The report attributes repeated DDoS campaigns against Japanese government, local authority, transport, finance and shipbuilding sites to NoName057(16), BD Anonymous and Dark Storm Team, with a Norwegian public digital services agency also targeted. It separately records unauthorised access to hundreds of rental server accounts at major Japanese hosting and internet infrastructure providers. Useful as a sector targeting signal; there is no technique detail or infrastructure data to pivot on.

  12. Members of ‘Black Axe’ cybercriminal group extradited from South Africa (opens in a new tab)

    The Record ·fetched 14 Sep 2026, 23:43 UTC agreed2/3

    Why readConcrete movement in the long-running Black Axe cases: five named defendants physically in US custody after five years of extradition fighting.

    Five alleged members of the Nigerian Black Axe network who ran the group's Cape Town operation were extradited from South Africa on 11 September and appear before a federal judge in Trenton, New Jersey. A 2021 indictment, now unsealed, charges Perry Osagiede, Franklyn Edosa Osagiede, Osariemen Eric Clement, Collins Owhofasa Otughwor and Musa Mudashiru with wire fraud and money laundering over romance scams run from 2011 to 2021 against more than 100 victims. Each count carries up to 20 years, and the case shows the multi-year lag between arrest and prosecution that shapes how much deterrence these takedowns actually deliver.

  1. CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild (opens in a new tab)

    Rapid7 ·Rapid7 ·fetched 14 Sep 2026, 11:43 UTC Must read CVE-2026-85706 EPSS 1.2% agreed3/3

    Why readCVSS 10.0 unauthenticated arbitrary file read in the GitLab commits API, on KEV since 11 September with a federal remediation deadline of 14 September and forensic triage required under BOD 26-04.

    CVE-2026-85706 is a path traversal (CWE-22) in the GitLab CE and EE repository commits API where improper path confinement and missing authentication enforcement let an unauthenticated user read arbitrary files from the server. GitLab shipped a critical patch release on 10 September; CISA added the bug to KEV the next day on evidence of active exploitation and set a 14 September due date for federal agencies. Self-managed instances should be patched off-cycle, and BOD 26-04 forensic triage obligations mean exposed instances need investigation, not just an upgrade.

    Also covered byBleepingComputer (opens in a new tab),Cybersecurity Dive (opens in a new tab),Cybersecurity News (opens in a new tab),The Register Security (opens in a new tab),CyberScoop (opens in a new tab),NVD (opens in a new tab),Dark Reading (opens in a new tab),Orca Security (opens in a new tab).

  2. CVE-2026-76461: Cisco Secure Email Gateway, Cisco Secure Email Gateway SQL Injection Vulnerability (opens in a new tab)

    CISA KEV ·fetched 14 Sep 2026, 19:42 UTC CVE-2026-76461 Exploited in the wild · patch by 2026-09-17 agreed3/3

    Why readCISA has added a Cisco Secure Email Gateway SQL injection to KEV with a 2026-09-17 remediation deadline, and the bug yields unauthenticated root command execution.

    CVE-2026-76461 is a SQL injection in Cisco AsyncOS for Secure Email Gateway that lets an unauthenticated remote attacker run arbitrary commands as root on the underlying OS. KEV listing means exploitation is confirmed; federal agencies must apply vendor mitigations by 2026-09-17 under BOD 26-04, including the forensics triage requirements, or discontinue use where no mitigation exists. SEG appliances are internet-facing by design, so exposure assessment is the first task.

  3. U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 14 Sep 2026, 15:40 UTC Must read CVE-2026-42016 EPSS 11.1% agreed3/3

    Why readFour new KEV entries with federal patch deadlines: GitLab CVE-2026-85706 (CVSS 10.0 path traversal), ConnectWise ScreenConnect CVE-2026-84869 (9.9), and a chainable JFrog Artifactory pair, CVE-2026-42016 and CVE-2026-42018.

    CISA added four vulnerabilities to the Known Exploited Vulnerabilities catalog. CVE-2026-42016 lets an attacker bypass Artifactory authorization checks and escalate privileges while CVE-2026-42018 exposes an internal anonymous-user token to unauthenticated attackers; chained, they give administrative control of the artifact repository. The ScreenConnect and GitLab entries cover improper privilege management and unauthenticated arbitrary file read respectively, and all four are confirmed exploited with binding remediation dates for federal agencies.

  4. Vulnerability in Metabase (September 10, 2026) (opens in a new tab)

    translated Vulnérabilité dans Metabase (10 septembre 2026)

    CERT-FR (ANSSI) ·fetched 14 Sep 2026, 15:40 UTC Must read agreed3/3

    Why readCERT-FR says it knows of numerous compromised Metabase instances via an unauthenticated SQL injection that yields instance admin, and gives the log pattern to hunt for.

    Metabase's 6 August 2026 advisory covers a critical unauthenticated SQL injection against the application database that escalates to administrator rights on the instance. CERT-FR reports it is aware of many compromised vulnerable instances and that exploitation attempts are visible in application and Metabase logs, characterised by a POST to /api/session/reset_password returning HTTP 400 followed by a second request. Patch immediately; where that is not possible, restrict exposure and treat affected instances as potentially compromised, with incident reporting to CERT-FR.

  5. Researcher Publishes CrowdStrike Privilege Escalation Zero Day (opens in a new tab)

    Infosecurity Magazine ·fetched 14 Sep 2026, 07:41 UTC agreed3/3

    Why readThere is public exploit code for an unpatched local privilege escalation in CrowdStrike Falcon Sensor, and the abused feature is one most deployments have switched on.

    A researcher using the handle Nightmare Eclipse published FalconFlank to GitHub on 3 September, a privilege escalation that abuses CrowdStrike Falcon Sensor's Office malicious macro remediation path. The author states it works on fully updated Windows 11 25H2 and Windows Server 2025 under Phase 3 Optimal Protection, and that the specific feature must be enabled. CrowdStrike is expected to have signatures for the released proof of concept, which means the detection story covers this exact artifact rather than the underlying flaw; confirm your sensor version and the remediation setting, and watch for a vendor advisory.

  6. CVE-2026-78175 (CVSS 8.8): The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, (opens in a new tab)

    NVD ·fetched 14 Sep 2026, 23:43 UTC CVE-2026-78175 CVSS 8.8 EPSS 0.6% agreed2/3

    Why readThe exploit primitive comes from esc_sql itself, a function most WordPress developers treat as a safety measure, which makes this bug class portable well beyond Tutor LMS.

    Tutor LMS through 4.0.7 reaches PHP object injection via the withdraw_method_field parameter of the tutor_save_withdraw_account AJAX handler, which relies on a nonce alone with no capability or role check. The mechanism is the interesting part: esc_sql expands each % into a 66-byte HMAC placeholder before serialization, and the placeholder collapses back to a single character on retrieval, leaving every serialized string length declaration 65 bytes too long. Because array keys come from entirely unescaped POST field names, unserialize over-reads into attacker-controlled bytes, letting a subscriber-level account inject a full object stream and chain a Guzzle cookie file gadget into remote code execution. Treat the sanitizer-as-desync pattern as a thing to grep for in your own serialization paths.

  7. ZDI-26-684: Linux Kernel KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerability (opens in a new tab)

    ZDI Published Advisories ·fetched 14 Sep 2026, 19:42 UTC Research CVE-2026-64397 EPSS 0.5% agreed3/3

    Why readPre-authentication remote kernel code execution in KSMBD's query directory handling, on any host with the in-kernel SMB server enabled.

    CVE-2026-64397 is a race in the handling of dir_fp objects in KSMBD, caused by missing locking, that a remote attacker can leverage to execute code in kernel context with no authentication. Only systems with KSMBD enabled are affected, which limits blast radius but makes exposed Linux SMB shares a priority for the fix in commit be6d26b.

    Indicators1
    Hashes
    be6d26bf27499977c746abc163659915082348d8
  8. CVE-2026-78006 (CVSS 9.8): The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widge (opens in a new tab)

    NVD ·fetched 14 Sep 2026, 23:43 UTC CVE-2026-78006 CVSS 9.8 EPSS 0.8% agreed3/3

    Why readUnauthenticated RCE in The Events Calendar up to 6.17.4, reachable through a comment on any event post where comments are enabled.

    CVE-2026-78006 chains three behaviours: is_safe_widget_instance is bypassed because PHP fires magic methods during pre-parse, enable_rendering_widget_copied() forges a valid wp_hash integrity attribute before unserialize() is reached, and the V2 single-event template runs do_blocks() over buffered comment HTML. WordPress hands an unauthenticated commenter a moderation-hash URL that lets them view their own pending comment, delivering the injected block markup to the vulnerable path before any moderator sees it. The only precondition is that comments are enabled and visible on tribe_events posts, which is a common default on a plugin with a very large install base.

  9. Multiple vulnerabilities in GitLab (September 11, 2026) (opens in a new tab)

    translated Multiples vulnérabilités dans GitLab (11 septembre 2026)

    CERT-FR (ANSSI) ·fetched 14 Sep 2026, 15:40 UTC agreed3/3

    Why readGitLab CE and EE need 19.1.8, 19.2.6 or 19.3.2 for flaws including remote code execution and data disclosure on a system that holds your source and CI credentials.

    Multiple vulnerabilities affect GitLab Community and Enterprise Edition before 19.1.8, 19.2.x before 19.2.6 and 19.3.x before 19.3.2. Some allow remote arbitrary code execution, remote denial of service and breach of data confidentiality. Self-managed instances carry CI runner tokens and repository secrets, which makes this worth moving ahead of routine patch cycles.

  10. Multiple vulnerabilities in Check Point products (September 10, 2026) (opens in a new tab)

    translated Multiples vulnérabilités dans les produits Check Point (10 septembre 2026)

    CERT-FR (ANSSI) ·fetched 14 Sep 2026, 15:40 UTC agreed3/3

    Why readCheck Point Security Gateway, Security Management and Spark firewalls need R81.20 or R82.10 take 24 for remote code execution and policy bypass flaws, and R80.x through R81.10 will get no fix at all.

    Bulletins sk1000117 and sk1000118 cover multiple flaws allowing remote arbitrary code execution and security policy bypass in Check Point Security Gateway, Security Management Server and Spark firewalls. Fixed builds are R81.20 take 24 and R82.10 take 24. Check Point states that R80, R80.10, R80.20, R80.30, R80.40, R81 and R81.10 are end of service and will not receive a patch, so anyone still on those lines has a migration rather than a patch to plan.

  11. Multiple vulnerabilities in HPE Aruba Networking ClearPass Policy Manager (September 10, 2026) (opens in a new tab)

    translated Multiples vulnérabilités dans HPE Aruba Networking ClearPass Policy Manager (10 septembre 2026)

    CERT-FR (ANSSI) ·fetched 14 Sep 2026, 15:40 UTC agreed3/3

    Why readClearPass Policy Manager remote code execution and privilege escalation fixed in 6.11.15, 6.12.8-HF and 6.14.0, on a box that holds your network access control policy.

    HPE Aruba Networking bulletin HPESBNW05130 covers multiple flaws in ClearPass Policy Manager permitting remote arbitrary code execution, privilege escalation and remote denial of service. Affected are versions before 6.11.15, 6.12.x before 6.12.8-HF and 6.14.x before 6.14.0. ClearPass sits at the centre of RADIUS and NAC decisions, so compromise there has unusually wide downstream reach.

  12. ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerability (opens in a new tab)

    ZDI Published Advisories ·fetched 14 Sep 2026, 15:40 UTC Research CVE-2026-89688 EPSS 0.6% agreed3/3

    Why readKernel RCE in the NFSv4 server through a locking failure on nfs4_openowner objects, with the upstream fix commit identified.

    ZDI-26-695 (CVE-2026-89688) describes a race condition in the Linux kernel NFSv4 server caused by missing locking around nfs4_openowner operations, allowing an authenticated remote attacker to execute code in kernel context. Only systems with nfsd enabled are affected. The fix landed upstream as commit 5e4627d3513e60accfce9d5f4c7fa95251ef93d6; EPSS is currently 0.006, so this is a patch-in-cycle item for NFS servers rather than an emergency.

    Indicators1
    Hashes
    5e4627d3513e60accfce9d5f4c7fa95251ef93d6
  1. AD Rights Management Service (Part 2): Extraction, Offline Decryption, and the Unrotatable Key (opens in a new tab)

    Huntress ·fetched 14 Sep 2026, 07:41 UTC Must read Research agreed3/3

    Why readShows how any member of the AD RMS Service Group can export the root Server Licensor Certificate key and decrypt every document a deployment ever protected, offline and permanently.

    Membership of the AD RMS Service Group is enough to pull the SLC key blob through a Trusted Publishing Domain export over the SOAP interface, and the released SharpRMS tool then forges the signature and Rights Account Certificate needed to decrypt the extracted slc.bin without touching the server again. Because Microsoft issues the SLC with 255 years of validity and provides no rotation mechanism, the compromise is unrecoverable: the key cannot be rolled, so access extends to deleted files and documents recovered from decommissioned servers. The defensive takeaway is concrete, namely to govern and monitor AD RMS Service Group membership as a tier-zero privileged group.

  2. IntentFuzz: A Protocol-Aware Fuzzer for Automated Invariant Violation Detection in Intent-Based Cross-Chain Bridges (opens in a new tab)

    arXiv cs.CR (AI) ·André Augusto, Christof Ferreira Torres, André Vasconcelos, Miguel Correia ·fetched 14 Sep 2026, 19:42 UTC Research agreed3/3

    Why readA fuzzer that recovers intent structure and deposit/fill roles from unannotated Solidity, hitting 9/9 on benchmark protocols and 79.5% bridge-classification precision with 97.2% recall.

    IntentFuzz targets intent-based cross-chain bridges, where a solver fulfils a declared outcome and an off-chain settlement layer reconciles fill against deposit. It separates invariant violations the contract must enforce locally from settlement exposures legitimately delegated off-chain, then synthesises multi-step fuzz sequences using an LLM fallback to construct call arguments, without hand-written per-protocol assertions. Across 77 manually labelled contracts it classifies deposit and fill functions at 100% recall and 82% combined precision, which is the part worth borrowing if you audit bridge code.

  3. Win11_26H2 build xta phantom libraries (opens in a new tab)

    Hexacorn ·adam ·fetched 14 Sep 2026, 19:42 UTC Research agreed3/3

    Why readTwo fresh DLL hijack candidates in Windows 11 26H2 that were not present in the 24H2 baseline, from original Procmon work.

    Hexacorn re-ran the phantom DLL enumeration against the Windows 11 26H2 build and found two libraries the system looks for but does not ship, on top of what the earlier 24H2 pass turned up. Each one is a candidate for sideloading and persistence wherever the search path is writable. The post is short and assumes familiarity with the previous entry, but the findings are primary.

  1. Microsoft: September updates cause RDS failures on Windows Server (opens in a new tab)

    BleepingComputer ·Sergiu Gatlan ·fetched 14 Sep 2026, 11:43 UTC Must read agreed3/3

    Why readIf you pushed September's updates to Windows Server fleets, this is the confirmed cause of your Remote Desktop failures and the reason some hosts need a hard reset.

    Microsoft has confirmed in a release health update that the September 2026 security updates destabilise Remote Desktop Services on Windows Server 2012 and later, as well as on Windows 10 and Windows 11. Symptoms include RDP connections dropping after several minutes, sign-in failures, servers hanging at the Remote Desktop Configuration screen, and unresponsive MMC, RDS Licensing Diagnoser, File Explorer and Windows Update pages. Existing sessions may fail to disconnect once a server starts degrading, leaving a hard reset as the recovery path, so plan staged deployment and a rollback position before finishing this month's rollout.

  2. A Graph-Based Approach for Mapping Kernel-Level Telemetry to MITRE ATT&CK (opens in a new tab)

    arXiv cs.CR (AI) ·Matteo Lupinacci, Luigi Arena, Francesco Blefari, Angelo Furfaro ·fetched 14 Sep 2026, 23:43 UTC Research agreed3/3

    Why readPipeline that turns eBPF kernel-event provenance graphs into ranked MITRE ATT&CK technique candidates, evaluated against 347 Linux Atomic Red Team tests with open-weights LLMs.

    Trace2ATT&CK collects kernel-level syscall events via eBPF, correlates attacker commands into a provenance graph, and compresses that graph into representations an LLM can reason over, mapping behaviour directly to ATT&CK rather than relying on retrospective CTI reports. Evaluation across 347 Linux Atomic Red Team tests with locally deployed open-weights models shows retrieval-augmented generation grounded in the ATT&CK knowledge base consistently beats plain prompting. Useful for teams trying to auto-label telemetry for coverage mapping without shipping data to a hosted model.

  3. Threat Hunting with JA4/JA4S (+ Practical KQL Queries) (opens in a new tab)

    detect.fyi ·Sergio Albea ·fetched 14 Sep 2026, 11:43 UTC agreed3/3

    Why readWorking KQL for hunting on JA4/JA4S TLS fingerprints, including why JA4's readable structure lets you pivot on parts of the fingerprint rather than an exact hash.

    Walks JA3 versus JA4 (MD5 of the ClientHello versus a structured value exposing TLS version, cipher suite count, extensions and ALPN) and adds JA4S for the server-side response. The practical gain is hunting on fingerprint components rather than full-hash equality, which survives the small client changes that break JA3 matching, paired with KQL queries you can run against existing network telemetry. Useful where IP and domain indicators rotate faster than your feed updates.

  4. How Attackers Abuse VSS, and How Huntress Detects It (opens in a new tab)

    Huntress ·fetched 14 Sep 2026, 19:42 UTC agreed3/3

    Why readArgues that alerting on shadow copy deletion alone is near-useless, and covers VSS abuse beyond the pre-ransomware wipe.

    The second post in Huntress's VSS series moves from how Volume Shadow Copy Service works (the 64TB volume ceiling, copy-on-write cost, Windows lock-in) to what attacker interaction with it looks like. The central claim is that 'something deleted a shadow copy' is one of the least useful sentences to put in an alert, because the abuse surface is wider than destroying backups before detonation. Detection guidance on a known technique rather than new research, and it resolves toward the vendor's own product, but the reasoning about alert specificity transfers.

  5. Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection (opens in a new tab)

    Unit 42 ·Osher Jacob ·fetched 14 Sep 2026, 11:43 UTC Research agreed3/3

    Why readA concrete method for inferring what a cloud identity is actually for from its audit log behaviour, useful when naming conventions and IAM policy attachments have stopped telling you the truth.

    Unit 42 clustered activity patterns drawn from cloud audit logs across more than 40,000 identities in 125 environments over two months, mapping them to functional roles such as administrator, backup service, security tooling and DevOps. The premise is that in real estates neither resource names nor attached policies reliably indicate function, particularly as machine and agent identities multiply, so behaviour is the more honest signal. The output feeds detection logic: once a cluster defines what normal looks like for a role, deviation becomes the alert. The model itself is not released, so the value is the approach rather than something you can run tomorrow.

DFIR

1
  1. Drone forensics: a guide for investigators (opens in a new tab)

    Magnet Forensics ·Phil Froklage ·fetched 14 Sep 2026, 19:42 UTC agreed3/3

    Why readHandling sequence for drone seizure (render safe, power off, secure, in that order) and what a drone actually yields: flight telemetry, onboard media, sensor data and comms artefacts.

    A practitioner guide to drone forensics that argues the instincts examiners carry over from mobile forensics are actively wrong here: a powered drone can call back to its operator, physically injure the examiner, or overwrite its own evidence while you decide what to do. It sets out the artefact classes that tie device, operator and purpose together, and insists on a fixed pre-extraction sequence. Vendor-published and light on specific parsing detail, but the handling doctrine is a position you can apply and argue with.

  1. Shuffling is Not Enough: Breaking Permutation-Based Model Confidentiality in Hybrid FHE Inference (opens in a new tab)

    arXiv cs.CR (all) ·Jiseung Kim, Hyung Tae Lee ·fetched 14 Sep 2026, 19:42 UTC Must read Research agreed3/3

    Why readConcrete proof that permutation plus noise does not hide a model in hybrid FHE inference, with exact end to end weight recovery demonstrated.

    The authors attack hybrid FHE inference schemes that keep linear layers encrypted on the server and defend model confidentiality by returning noisy, output permuted responses justified under shuffle model differential privacy. They show the correctness bounds these systems must satisfy leave too little room for the noise the shuffle amplification argument assumes, so d+1 admissible queries per d-input linear layer recover a permutation invariant layer summary exactly. Running it against a SAFHIRE style ResNet-20, they reconstruct every linear layer from TFHE transcripts with zero error in 5,712 queries, and confirm the same per layer recovery on pretrained ImageNet scale CNNs.

  2. OpenAI bots knew about the RubyGems caching vulnerability (opens in a new tab)

    Hacker News ·gregnavis ·fetched 14 Sep 2026, 19:42 UTC Must read 240 points agreed2/3

    Why readA RubyGems maintainer reads the actual gem payloads and finds AI agents probing a package registry caching flaw, which is the concrete version of a threat most people have only discussed abstractly.

    Following the rubyhack.ai disclosure, Aaron Patterson went back to the junk packages from the GemStuffer campaign that Socket reported in May and read their code. The gems scraped UK government websites, repackaged the data, and repeatedly pushed uploads to RubyGems.org, and the behaviour lines up with bot traffic attributed to OpenAI that appears to have been working the RubyGems.org caching vulnerability while also hammering RubyDoc.info. The value is the first-hand code reading from someone with registry context, not the headline attribution.

  3. Forging Tree-Ring: Reproducing and Instrumenting Black-Box Semantic Watermark Forgery (opens in a new tab)

    arXiv cs.CR (all) ·Saifur Rahman Tamim, Md Taslimul Hasan Toufique, A. M. Tayeful Islam ·fetched 14 Sep 2026, 23:43 UTC Research agreed3/3

    Why readIndependent reproduction of the Reprompt forgery attack on Tree-Ring watermarks, plus recovery of the detector statistic the released code throws away, giving two scores that separate forged from clean images at AUC 0.861 and 0.972.

    The authors rerun Müller et al.'s keyless forgery against Tree-Ring on Stable Diffusion XL using the original code on free-tier dual T4 GPUs with 14.6 GB usable memory per device, far below the A40 hardware of the original study. Across six trials the attack holds: 6/6 genuine detected, 0/6 clean, 5/6 forged accepted, at 325 to 332 seconds per attack. They also recover the non-central chi-squared statistic the released detector discards behind its CDF, matching the reference detector exactly and building two forgery-discriminating scores from it.

  4. CVE-2026-90553 (CVSS 8.5): vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter (opens in a new tab)

    NVD ·fetched 14 Sep 2026, 23:43 UTC Must read CVE-2026-90553 CVSS 8.5 EPSS 0.2% agreed3/3

    Why readThe control most teams rely on when serving third party weights, trust_remote_code=False, does not hold in vLLM before 0.28.0.

    The LlavaOnevision2 processor loader ignores the trust_remote_code parameter and loads remote processor classes regardless, so code placed in processing_llava_onevision2.py inside a model repository executes with the vLLM process identity. The severity is less about this one processor and more about the assumption it breaks: policies and review gates that treat trust_remote_code=False as a hard boundary were wrong for any deployment on an affected version. Upgrade to 0.28.0 and re-examine models loaded under the false assumption.

  5. Matthew0822/ToolReplay: Audit AI agent tool-call transcripts: hash-chain sealing, deterministic replay, and scope overreach checks. Dependency-free Python CLI. (opens in a new tab)

    GitHub: new security tools ·Matthew0822 ·fetched 14 Sep 2026, 15:40 UTC Research ★ 170 agreed3/3

    Why readA dependency-free Python CLI that replays a recorded AI agent tool-call transcript and flags redundant calls, non-determinism and calls outside the agent's declared permissions.

    ToolReplay parses a JSONL transcript of agent tool calls, hash-chains the records for tamper evidence, and reports the first index where a deterministic re-run would diverge, plus redundant repeat calls and scope overreach against a declared permission set. The shipped dirty sample shows the output format: six parsed records, a redundant read_file at index 2, and a non-deterministic search at index 5 flagged as the divergence point. Useful groundwork for anyone who has to audit or attest to what an agent actually did in a session, though the checks are shallow and parsing is strict.

    Indicators6
    Hashes
    c1bd7fb3e28ce29e5c9dbd0cf47cafcaa1613295be26d86fb04463fe3d8b40da 0000000000000000000000000000000000000000000000000000000000000000 75ccf1faad88c5ea82c68139b2ec2a02943142dd0133bb0c626ccbff28f5c711 327da75f2d491267f1dbeaf5d31b4a61a2ed9e956a71a5c4cbb67a87b4720d6a 34d19a9dfb112baa07afa37994ddcbbebe2973674385f3942340653d08d205bd 40aadf3b8156217f0b5b1d95010b6b79f82a26ccf5e780aed0f5f311f865028a
  6. What is an agent harness (and how do you secure one)? (opens in a new tab)

    Adversa AI ·fetched 14 Sep 2026, 11:43 UTC agreed2/3

    Why readRelocates AI agent security from the model to the scaffolding around it, and gives you a concrete list of layers to review when you deploy coding agents.

    The piece defines an agent harness as everything wrapping the model: the planning and retry loop, tool and shell dispatch, context and memory management, approval prompts and the execution sandbox. Drawing on the author's testing of coding agents, open source frameworks and skill scanners, it argues that the exploitable flaws cluster in that layer and mostly do not require breaking or jailbreaking the model at all. The practical implication is to spend review effort on tool dispatch, approval gates and sandbox boundaries rather than on prompt hardening, though the framing comes from a vendor with a product in the space.

  7. CVE-2026-37008 (CVSS 8.1): CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275 (opens in a new tab)

    NVD ·fetched 14 Sep 2026, 23:43 UTC CVE-2026-37008 CVSS 8.1 EPSS 0.1% agreed3/3

    Why readStates why CrewAI's import blocklist cannot contain agent-generated code: ctypes.CDLL(None) loads libc with no import statement at all.

    The advisory argues the sandbox sits at the wrong level of abstraction, since blocking module names at import time leaves Python's entire object graph reachable by other routes, and gives ctypes.CDLL(None) as a one-line demonstration. The stated conclusion generalises past CrewAI: an in-process sandbox must account for the full interpreter runtime, not the import system, so any agent framework relying on name blocklists is in the same position. Fixed at commit fb2323b, and it is distinct from CVE-2026-2275.

  8. Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research (opens in a new tab)

    The Register Security ·fetched 14 Sep 2026, 07:41 UTC agreed3/3

    Why readSummarises Anthropic's latest misuse report, including which actors it names and a sceptical read of why frontier labs keep publishing these.

    Anthropic reported that criminal and state-linked operators are using Claude to automate intrusions, develop kamikaze drone swarms, run mass surveillance and work on a more dangerous variant of a mosquito-borne virus. Named users of the models include ShinyHunters and Russian freelancers, following the November report on Chinese operators automating intrusions at critical organisations. The Register's framing is that these disclosures arrive without any corresponding slowdown or liability on the lab's side; the primary report is where the detail lives.

  9. Security through obscurity is dead, and AI delivered the fatal blow (opens in a new tab)

    The Register Security ·fetched 14 Sep 2026, 03:41 UTC agreed2/3

    Why readAn FBI Cyber Division official puts a name and a number to what agentic bug hunting is doing to long-trusted open source code and to the maintainers who have to patch it.

    Brett Leatherman of the FBI's Cyber Division tells The Register that current models are finding flaws in libraries that have been publicly readable and stress-tested for a decade, including code running in a large share of web servers. The volume of resulting disclosures is outpacing what project maintainers can triage, producing a patch backlog that is itself a risk. The argument is directional rather than evidenced; there is no dataset or named CVE set behind it, so read it as a signal about defender and maintainer workload, not as a research result.

  1. The High Crime of “LMAO”: How Cops Are Treating Mass Surveillance As a Joke (opens in a new tab)

    EFF Deeplinks ·Dave Maass ·fetched 14 Sep 2026, 15:40 UTC agreed3/3

    Why readEFF's analysis of Flock Safety ALPR search logs shows officers running nationwide queries with junk justifications, including one Goshen PD search across 6,474 networks and 82,413 cameras logged only as 'idk'.

    EFF obtained and analysed ALPR search audit logs from Flock Safety systems and found officers routinely entering nonsensical or absent reasons in the mandatory justification field. One May 7, 2025 query from Goshen Police Department reached 6,474 networks covering 82,413 cameras with 'idk' as the stated purpose. The finding matters for anyone assessing the audit controls on third-party surveillance data sharing: the logging exists, the enforcement behind it does not.

  2. How Modern DFIR Capabilities Support NIS2 Compliance (opens in a new tab)

    translated Comment les capacités modernes en matière de DFIR contribuent au respect de la directive NIS2

    Magnet Forensics ·Phil Froklage ·fetched 14 Sep 2026, 07:41 UTC agreed3/3

    Why readSets out what NIS2 demands beyond detection: defensible investigation and reporting inside 24 to 72 hours, with fines up to 10M euro or 2% of turnover for essential entities.

    NIS2 extends accountability across EU essential and important sectors past prevention and detection into response, investigation and justifiable reporting, with incident notification windows of 24 to 72 hours and some member states imposing tighter ones. Essential entities face penalties of up to 10 million euro or 2% of global turnover, whichever is higher; important entities face 7 million euro or 1.4%. The argument is that DFIR capability, not just monitoring, is what makes those reporting deadlines achievable, which is a defensible position even though the piece comes from a forensics vendor.

  1. Revolut handed customer data to fraudsters using government email account (opens in a new tab)

    The Record ·fetched 14 Sep 2026, 15:40 UTC Must read agreed3/3

    Why readRevolut confirmed releasing customer data to fraudsters who sent emergency data requests from a genuine government agency email domain, targeting high-net-worth crypto holders.

    Revolut says an unauthorised third party used a legitimate government agency domain email to submit fraudulent requests for customer information, and it disclosed sensitive data in response. The targets appear to be high-net-worth individuals, many connected to crypto asset businesses, and extortion images posted to a since-suspended Telegram account point to an Italian government domain as the source. Emergency data request abuse has moved from law enforcement portals to regulated fintechs, which makes verification procedure for inbound official requests a question any bank or platform executive should expect to be asked.

    Also covered byHacker News (opens in a new tab),Malwarebytes Labs (opens in a new tab),Help Net Security (opens in a new tab),AML Intelligence (opens in a new tab),Cybernews (opens in a new tab),cyberpress.org (opens in a new tab).

  2. CenterPoint Energy discloses customer data breach in SEC filing (opens in a new tab)

    Google News: incidents · Reuters ·fetched 14 Sep 2026, 23:43 UTC Must read agreed3/3

    Why readA major US energy utility has put a customer data breach into an SEC filing, which is the disclosure peers in the sector will be asked about.

    CenterPoint Energy disclosed a breach affecting customer data through an SEC filing, reported by Reuters. Detail available so far is limited to the fact of the disclosure and the affected data category. For utility and critical-infrastructure leaders it is a live example of the 8-K materiality call, and worth tracking as the filing text and scope become public.

  3. Japan government system hit by cyberattack; 246,000 personal records may have been leaked (opens in a new tab)

    Google News: incidents · Asia News Network ·fetched 14 Sep 2026, 03:41 UTC agreed3/3

    Why readA Japanese government system was breached with roughly 246,000 personal records potentially exposed, the kind of public-sector incident peers and regulators in the region will be asked about.

    Japanese government infrastructure was hit by a cyberattack that may have leaked around 246,000 personal records, per Asia News Network. No attribution, intrusion vector or timeline has been published yet. Worth tracking for anyone with Japanese public-sector exposure or supply-chain ties, with technical detail likely to follow rather than available now.

  4. Chess.com Leak Exposes 7.3M Users, Evidence Points to Scraping (opens in a new tab)

    Hacker News ·kristianp ·fetched 14 Sep 2026, 11:43 UTC 70 points agreed3/3

    Why readThe dataset is genuine but the evidence points at bulk collection through the platform's own interfaces, which changes both the disclosure story and what a similar exposure would look like on your own APIs.

    A 744 MB archive expanding to 15.5 GB, containing 7,337,395 Chess.com records with 38 fields each, was posted free on two leak forums with no ransom demand. The schema is Chess.com specific and carries email, partial email, username, user ID, UUID, names, country, location, locale and platform state such as chess title, points, skill level, premium status and verification flags. Analysis of the field composition favours large scale scraping over a server intrusion, which is the distinction worth carrying into your own API abuse monitoring.

  5. Swiss Bitcoin Pay Shuts Down Servers After Data Breach (opens in a new tab)

    Google News: incidents · Bitcoin Magazine ·fetched 14 Sep 2026, 23:43 UTC agreed3/3

    Why readA payments provider took its servers offline after a breach, a containment decision with direct service impact for merchants using it.

    Swiss Bitcoin Pay shut down its servers following a data breach. Scope, data types and root cause are not yet disclosed; what is confirmed is the deliberate service outage as a containment step. Relevant to anyone with the provider in their payment path and as a reference point for whether pulling the plug is a defensible first move.

  6. Florida Highway Safety was hacked. Did cybercriminals get your info? (opens in a new tab)

    Google News: incidents · Florida Today ·fetched 14 Sep 2026, 19:42 UTC agreed3/3

    Why readFlorida's Highway Safety and Motor Vehicles department, holder of state driver licence and vehicle records, has been breached.

    Local reporting that the Florida Department of Highway Safety and Motor Vehicles was hacked, with questions open about whether resident records were taken. A state agency holding driver licence and title data is a large PII custodian, so peers in state government and anyone with Florida licence data exposure will want to watch the notification that follows. No attribution, scope figure or intrusion detail yet.

  7. Springfield students return after weeklong cyberattack shutdown (opens in a new tab)

    Google News: incidents · Western Mass News ·fetched 14 Sep 2026, 23:43 UTC agreed3/3

    Why readA US school district lost a full week of instruction to a cyberattack, a concrete data point on operational downtime in K-12.

    Springfield students returned to classes after a cyberattack shut the district down for about a week. Available reporting covers the resumption rather than the intrusion, with no attacker, entry vector or data-impact detail disclosed. Useful mainly as another downtime benchmark for leaders arguing recovery budgets in the public sector.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
Better Accounting Solutions anubis Professional Services - 14 Sep 2026
Bernath & Rosenberg genesis Professional Services US 14 Sep 2026
Dorfman Abrams Music, P.C genesis Professional Services US 14 Sep 2026
geekybunch.com unsafe Technology US 14 Sep 2026
Foremost Mfg qilin Manufacturing US 14 Sep 2026
Winston Contracting, LLC qilin Professional Services US 14 Sep 2026
RoadEx America qilin Transportation US 14 Sep 2026
Minmer Global qilin - - 14 Sep 2026
Dublin City Schools GA Eclipse Education US 14 Sep 2026
Rosello et Fils Eclipse Agriculture and Food Production FR 14 Sep 2026
tpi.tw lockbit5 Technology TW 14 Sep 2026
comune.robeccosulnaviglio.mi.it lockbit5 Government & Defense IT 14 Sep 2026
httoy.fi lockbit5 - FI 14 Sep 2026
Metropolitan Community Health Services insomnia Healthcare US 14 Sep 2026
Massey, Stotser & Nichols insomnia Professional Services US 14 Sep 2026
glasfloss.com chaos Manufacturing US 14 Sep 2026
steelhausinc.com chaos Manufacturing US 14 Sep 2026
Vitar Group qilin - AR 14 Sep 2026
Mestechkin Law Group P.C. Booba Project Professional Services US 14 Sep 2026
Atlas Ocean Voyages Booba Project Hospitality US 14 Sep 2026
Ne***ox AuditTeam Technology RU 14 Sep 2026
Alicotrans qilin Transportation BR 14 Sep 2026
Cerámicas Kantu Panzer Manufacturing - 13 Sep 2026
Gilco Scaffolding qilin Manufacturing GB 13 Sep 2026
Navitrans emperador Transportation - 13 Sep 2026
How this edition was made
Candidates fetched
4564
New after deduplication
720
Kept by the panel
121
Published
98
Generated
14 Sep 2026, 23:43 UTC