CFToday Curated security signals.

Daily edition · 2026-09-20

Sunday, 20 September 2026

42 items across 7 sections, selected from 4267 candidates over 6 runs. 103 carried the panel unanimously.

Show
Section

India

1

Indian organisations, regulators and infrastructure, pulled out of the sections below.

  1. MDR fears groundless, AI accountability lies with boards: RBI Dy Governor SC Murmu (opens in a new tab)

    Economic Times Tech ·Governance, Risk & Compliance ·fetched 20 Sep 2026, 15:39 UTC agreed1/2

    Why readIndia's central bank has said in public that accountability for AI outcomes rests with bank boards, a line Indian financial institutions will be measured against in supervision.

    Speaking at the Bengal Chamber of Commerce and Industry financial market conclave, RBI Deputy Governor S. C. Murmu placed responsibility for AI deployment outcomes squarely on the boards of regulated entities, alongside dismissing industry concern that merchant discount rate changes would slow digital payment adoption. The AI remark is the part with governance weight: it signals that model risk, vendor AI and automated decisioning will be examined as board level responsibilities rather than technology team matters. Indian BFSI risk and compliance functions should read it as advance notice of the framing supervisors will use, and check that board reporting on AI systems actually exists.

  1. An undercover Google analyst infiltrated a notorious supply-chain hacking gang (opens in a new tab)

    Ars Technica Security ·Andy Greenberg, WIRED.com ·fetched 20 Sep 2026, 11:39 UTC Must read agreed3/3

    Why readGoogle Threat Intelligence Group ran an undercover researcher inside TeamPCP, the supply-chain crew behind the Dune-themed self-spreading worm that tainted hundreds of open-source packages and breached over a thousand companies.

    GTIG researcher Austin Larsen is presenting at LABScon on Google's infiltration of TeamPCP, the group whose stolen developer accounts and self-propagating worm poisoned hundreds of open-source projects before two alleged members were arrested and charged in Australia last month. Google monitored the campaign from inside the group, warned targets and helped disrupt attempts to exploit victims. The account matters both for what it reveals about how the package-ecosystem compromise actually spread and for the precedent of a vendor placing a researcher inside an active crew.

  2. 2026-09-15: SmartApeSG ClickFix to unidentified RAT to MeshAgent (opens in a new tab)

    Malware Traffic Analysis ·fetched 20 Sep 2026, 19:37 UTC Must read Research agreed2/2

    Why readFull packet capture and IOC set for a 15 September SmartApeSG ClickFix chain that lands an unidentified RAT and then MeshAgent for persistent remote access.

    The infection starts from a fake verification page delivering ClickFix instructions, drops an unidentified RAT, and establishes MeshAgent persistence with files staged in AppData\Local\Temp and a login console on an attacker-run Mesh C2 server. An 18.7 MB pcap and a separate IOC file are provided for hunting and rule validation. MeshAgent abuse as second-stage remote access is worth a hunt across your RMM telemetry; note the site has changed its archive password scheme.

  3. Malicious npm packages evade install-script defenses at runtime (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 20 Sep 2026, 15:39 UTC agreed2/2

    Why readExplains how the 'indexed-btree' typosquat of sorted-btree sidesteps GitHub's June 2026 npm lifecycle-script blocking by executing only during normal runtime use of the library.

    Checkmarx tracked an ongoing npm campaign in which malicious code lives in the package's ordinary runtime path rather than in preinstall, install or postinstall hooks, so the controls npm shipped this year to gate lifecycle scripts never fire. The package impersonates the legitimate sorted-btree library, and the operators are linked to a wallet holding 109 ETH, though the report does not attribute those funds to theft. For anyone relying on install-script blocking as their npm supply-chain control, this is the bypass to plan around.

  4. TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories (opens in a new tab)

    Cybersecurity News ·Guru Baran ·fetched 20 Sep 2026, 03:38 UTC Must read CVE-2026-45321 EPSS 2.3% agreed3/3

    Why readTokens stolen by May's poisoned @tanstack packages were used months later to clone roughly 170 private CrowdSec repositories through a departed employee's still-active GitHub account.

    CrowdSec has disclosed that an attacker copied about 170 private GitHub repositories between 05:52 and 06:01 UTC on 22 May, using credentials harvested by the TanStack npm compromise (CVE-2026-45321). That original attack chained an unsafe pull_request_target workflow, GitHub Actions cache poisoning and runtime extraction of an OIDC token to publish 84 malicious releases across 42 @tanstack packages, each running an install-time payload that swept GitHub and npm tokens, cloud credentials, Kubernetes and Vault secrets, and SSH keys. The theft went unnoticed until the source code appeared on a cybercrime forum on 16 September, and the account belonged to a developer who had left but kept access to finish work.

    Also covered byThe Hacker News (opens in a new tab).

  5. HBO Max’s verified Reddit account hijacked to spread malware (opens in a new tab)

    Malwarebytes Labs ·fetched 20 Sep 2026, 15:39 UTC agreed2/2

    Why readHBO Max's verified Reddit account was hijacked to run 108 malicious ads in about 48 hours, pushing ClickFix pages that tell macOS victims to paste a command into Terminal.

    Hudson Rock found the compromised corporate account promoting fake AI tools, developer software and macOS utilities, with some ads landing on HBO lookalike sites offering a supposed native macOS app. Rather than serving an installer, the pages walk visitors through pasting a clipboard-planted command into Terminal, the Run dialog or PowerShell, the ClickFix pattern. The useful detail is the delivery channel: a verified brand account on an ad platform, which bypasses the usual sender-reputation checks.

  6. When Ransomware Targets AI Models: Defending the AI/ML Recovery Chain (opens in a new tab)

    Cybersecurity News ·Kavichselvan ·fetched 20 Sep 2026, 07:42 UTC CVE-2025-3248 EPSS 100.0% agreed3/3

    Why readA ransomware operator has moved from generic database extortion to a compiled binary written specifically to wreck model files and training data, which changes what an AI stack needs backed up.

    Sysdig's threat research team tracks an actor it calls JADEPUFFER through two campaigns in a few weeks, starting with throwaway extortion scripts against exposed databases and ending with a purpose-built ransomware binary aimed at AI and ML assets. Initial access came through CVE-2025-3248, the unauthenticated Langflow RCE that CISA added to KEV in May 2025 and which now carries near-certain exploitation probability; Langflow is attractive because it holds LLM provider keys, cloud credentials and links to vector stores and object storage. The piece is a vendor blog and the defensive advice is general, but the actor progression and the target selection are the reportable facts.

  7. Ransom & Dark Web Issues Week 3, September 2026 (opens in a new tab)

    AhnLab ASEC ·ATCP ·fetched 20 Sep 2026, 23:35 UTC agreed2/2

    Why readWeekly Korean and Japanese dark-web roundup naming AUDIT TEAM ransomware activity, with the actual IOCs paywalled.

    AhnLab's week 3 roundup notes internal data from a Japanese pharmaceutical and healthcare firm and customer data from a South Korean e-commerce retailer offered for sale after incidents, plus AUDIT TEAM ransomware hitting two South Korean organisations. No victim is named and the detail is a headline list; indicators and analysis sit behind an AhnLab TIP subscription. Useful only as a pointer to regional activity for teams tracking APAC leak sites.

  1. Google says some Pixel phone owners were hacked in zero-day attacks (opens in a new tab)

    TechCrunch Security ·Zack Whittaker ·fetched 20 Sep 2026, 23:35 UTC agreed2/2

    Why readCVE-2026-58704, a zero-click privilege escalation in the Pixel modem, was exploited in limited targeted attacks and is now patched.

    The flaw sits in the Pixel modem and lets an attacker break out of the modem sandbox into broader phone data with no user interaction. Google confirms limited, targeted exploitation but has not named the operator; this profile matches commercial spyware vendors selling to government customers. Patch state of fleet Pixels is the immediate action, and anyone in a targeted-risk population should be checked rather than assumed clean.

  2. CVE-2026-93603 (CVSS 10.0): vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandbox (opens in a new tab)

    NVD ·fetched 20 Sep 2026, 23:35 UTC Must read Research CVE-2026-93603 CVSS 10.0 EPSS 0.4% agreed3/3

    Why readThe cleanest of the vm2 escapes: calling any sloppy-mode host function with no receiver returns a live proxy of the host global, giving process and child_process from inside the sandbox.

    In vm2 through 3.12.0 (fixed in 3.12.1) the apply trap in lib/bridge.js passes a nullish this straight through to the host call, so V8 substitutes the host realm global object. Any of fn(), a detached method, fn.call(), fn.apply(undefined), Reflect.apply(fn, undefined, []) or fn.bind()() on a non-strict host function returns that global wrapped as a sandbox proxy, reaching process.getBuiltinModule('child_process').execSync for arbitrary command execution. Exploitation needs only one non-strict host function exposed to the sandbox; strict-mode and ES module host functions are unaffected. Upgrade to 3.12.1 or move off vm2.

  3. Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 20 Sep 2026, 15:39 UTC agreed2/2

    Why readWorking local-root exploits are now public for four Linux kernel bugs, DirtyAH6, TUNderflow, PPPoEject and DiagSpill, all patched in the past few weeks.

    Asim Manizada reported the four to the kernel security team in mid-July and published a technical write-up with exploits on 18 September after a coordinated hold for distribution fixes. There are no reports of in-the-wild use, and the exploits are tuned to specific kernel builds and can crash a target, so they are for isolated test systems. The risk lands on shared and multi-tenant hosts still running older kernels, where a low-privilege foothold now converts to root with off-the-shelf code.

  4. CVE-2026-86864 (CVSS 8.7): pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a ba (opens in a new tab)

    NVD ·fetched 20 Sep 2026, 07:42 UTC Must read CVE-2026-86864 CVSS 8.7 EPSS 0.4% agreed3/3

    Why readOne unvalidated field reaches pg_dump as a bare positional argument, and getopt_long permutation plus libpq connection string expansion turn that into arbitrary file write and connection redirection.

    pgAdmin 4 appended the client supplied 'database' value from /backup/job/<sid>/object to the pg_dump argument vector as a trailing positional argument with no validation. Because getopt_long permutes arguments, a value starting with a dash is parsed as an option, so --file=/absolute/path overrides the storage confined output path pgAdmin had already constructed and writes anywhere the pgAdmin OS account can reach, including over pgAdmin's own configuration database. The same field also accepts an equals sign, which libpq expands into a full connection string whose embedded host and port keywords override the ones pgAdmin passed, pointing the dump at a server the attacker controls.

  5. CVE-2026-93606 (CVSS 10.0): vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Pro (opens in a new tab)

    NVD ·fetched 20 Sep 2026, 23:35 UTC Must read Research CVE-2026-93606 CVSS 10.0 EPSS 0.5% agreed3/3

    Why readSandbox escape in vm2 3.12.0 and earlier: overwriting Symbol.species on a host Promise defeats the bridge's rejection sanitizer and hands sandboxed code a live host proxy.

    vm2's rejection sanitizer (hostPromiseSanitizeReject, makeSanitizedPromiseCallback, normalizeHostPromiseCallbacks in lib/bridge.js) only wraps then/catch rejection slots holding a function, and the Symbol.species neutralization is installed solely on the sandbox intrinsic Promise.prototype, so host-realm Promises are untouched. Sandboxed code overwrites p.constructor[Symbol.species] and calls p.then() with no onRejected handler; V8 substitutes its internal Thrower, re-throwing the raw host rejection value into an attacker-captured closure. If that value is host-pivotable, for example a host process object, the result is arbitrary code execution on the host. Applies wherever an embedder exposes a host API returning a host Promise.

  6. CVE-2026-15815 (CVSS 8.8): Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative (opens in a new tab)

    NVD ·fetched 20 Sep 2026, 19:37 UTC CVE-2026-15815 CVSS 8.8 EPSS 0.9% agreed2/2

    Why readGrafana extracts plugin archives before verifying their signature, so chained relative symlinks write a backend binary outside the plugin directory and get RCE as the Grafana process.

    Grafana OSS and Enterprise do not resolve symbolic links safely during plugin archive extraction; a crafted archive chains relative symlink entries to escape the install directory and drop an executable that runs with the server's privileges. Extraction happens before signature verification, so a valid signature offers no protection, and every install path is affected: grafana-cli, GF_INSTALL_PLUGINS and preinstall configuration. Enterprise shares the OSS extraction code, so treat any operator-initiated plugin install as an RCE primitive until patched.

  7. New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 20 Sep 2026, 15:39 UTC agreed2/2

    Why readWordPress 7.1.1 fixes Click2Shell, where a crafted link opened by a logged-in admin silently installs an attacker-chosen theme from WordPress.org with no Install click.

    pwn.ai reported the core flaw and showed it chains to server-side code execution when combined with a separate weakness in the installed theme; the core bug alone does not accept an arbitrary theme ZIP. The installed theme stays deactivated, so the site looks unchanged and nothing obvious signals compromise. The fix shipped on 17 September as a security release and WordPress advises updating immediately; there is no evidence of exploitation yet.

  8. CVE-2026-86863 (CVSS 9.3): pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, deliver (opens in a new tab)

    NVD ·fetched 20 Sep 2026, 07:42 UTC Must read CVE-2026-86863 CVSS 9.3 EPSS 0.4% agreed3/3

    Why readpgAdmin 4 with webserver authentication enabled would authenticate anyone who simply sent an X-Forwarded-User style header, including as an existing Administrator, with no password.

    WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ and, finding nothing, fell back to request.headers.get() for the same name, so any client that could reach pgAdmin could assert whatever username it liked. The environment lookup was equally unsafe whenever WEBSERVER_REMOTE_USER was set to an HTTP_-prefixed or hyphenated name such as HTTP_X_FORWARDED_USER, because WSGI servers place inbound headers into the environment under exactly those keys. Only deployments with 'webserver' in AUTHENTICATION_SOURCES are affected; the fix distinguishes genuine environment values from client-supplied headers.

  9. CVE-2026-92913 (CVSS 9.1): AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account acti (opens in a new tab)

    NVD ·fetched 20 Sep 2026, 03:38 UTC CVE-2026-92913 CVSS 9.1 EPSS 0.5% agreed3/3

    Why readAVideo login codes are derived from uniqid(), reducing the space to about 2^25, and an unauthenticated API endpoint leaks the server's microtime to narrow the guess; no patch exists.

    getRandomCode() in objects/functions.php builds account activation and login pairing codes from uniqid() plus one non-CSPRNG rand() padding character, leaving roughly 36 million values for a known generation second. plugin/API/set.json.php?APIName=login_code can be called unauthenticated and doubles as a microtime oracle, and a guessed code redeemed at get.json.php?APIName=login_code returns the victim's email and a User::getUserHash(users_id, '+1 year') value accepted in place of the password for a year. No fixed version is available as of the advisory.

  10. CVE-2026-54460 (CVSS 9.8): OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys ac (opens in a new tab)

    NVD ·fetched 20 Sep 2026, 19:37 UTC Research CVE-2026-54460 CVSS 9.8 EPSS 0.6% agreed2/2

    Why readA passkey enrollment endpoint that accepts a body-supplied userId without a session, plus a login oracle to find the right userId, is a pattern worth checking in your own WebAuthn code.

    In OpenReception before 1.1.1, POST /api/auth/passkeys accepts an attacker-supplied userId and public key with no authenticated session, never calls WebAuthnService.verifyRegistration, and does not bind enrollment to locals.user.id. An attacker harvests candidate userId values from the public booking bootstrap and GET /api/tenants/[id]/appointments/staff-public-keys, injects a controlled key, then uses the login check comparing verificationResult.userId against the email-resolved account as an oracle to confirm the match and obtain a STAFF session. The generalisable lesson is that unbound credential registration turns passkeys from a phishing defence into an unauthenticated account takeover.

  11. CVE-2026-54734 (CVSS 10.0): Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound r (opens in a new tab)

    NVD ·fetched 20 Sep 2026, 19:37 UTC Research CVE-2026-54734 CVSS 10.0 EPSS 0.4% agreed2/2

    Why readBidder adapters in Prebid Server Java before 3.43.0 interpolate user-supplied parameters into outbound URLs without HttpUtil validation, giving unauthenticated SSRF to cloud metadata endpoints.

    Prebid Server Java below 3.43.0 builds outbound bid requests by interpolating attacker-controllable parameters into URLs without validating the resulting domain or path segment through HttpUtil. Anyone able to supply bid-request parameters can steer the server at internal services or instance metadata endpoints with the server's own network position, which is why it carries CVSS 10.0 despite an EPSS of 0.0036. Unlike the Microsoft service CVEs in this batch this is self-hosted software, so the upgrade to 3.43.0 is on the operator.

  12. CVE-2026-89036 (CVSS 8.7): Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to (opens in a new tab)

    NVD ·fetched 20 Sep 2026, 07:42 UTC Research CVE-2026-89036 CVSS 8.7 EPSS 0.7% agreed3/3

    Why readAppwrite before 2.0.0 lets a functions.write user reach RCE by smuggling TAB characters through escapeshellcmd into a GNU tar argument vector and using --checkpoint-action=exec.

    The providerRootDirectory parameter is sanitised with escapeshellcmd instead of escapeshellarg and left unquoted, so TAB characters survive and are read as argument separators when the tar command line is assembled. That allows injection of arbitrary tar options, and --checkpoint-action=exec turns it into command execution as the builds worker process user. The escapeshellcmd-versus-escapeshellarg confusion plus TAB as a separator is a reusable primitive worth remembering for other PHP codebases that shell out.

  1. AIJon: Automated Generation of Annotations for Fuzzing (opens in a new tab)

    arXiv cs.CR (AI) ·Jayakrishna Menon Vadayath, Hulin Wang, Moritz Schloegel, Jie Hu ·fetched 20 Sep 2026, 07:42 UTC Must read Research agreed3/3

    Why readShows that LLM-generated IJON-style annotations match human expert annotations for guiding fuzzers, with results measured on the Magma benchmark.

    AIJON replicates the IJON annotation work and extends it to real-world vulnerability detection at scale, replacing the human domain expert with an LLM that writes the annotations automatically. Evaluation on Magma found LLM-produced annotations performed comparably to human ones, removing the main scalability barrier that kept annotation-guided fuzzing a manual exercise. Relevant to anyone running fuzzing campaigns where coverage feedback alone has plateaued.

  2. Laser Your Way into Debug Mode on the RP2350 (opens in a new tab)

    Hackaday Security ·Tyler August ·fetched 20 Sep 2026, 03:38 UTC Must read agreed3/3

    Why readLaser fault injection flips the debug-enable register on the RP2350, defeating a chip whose designers explicitly added glitch detection to block voltage and clock attacks.

    Ledger Donjon located the register controlling debug features on the RP2350 by decapsulating the chip and imaging the die with photon-emission electron microscopy, then attacked a back-side-decapped part by firing an IR laser through the silicon wafer to set it. Secure boot, TrustZone separation, permanent debug disable and the Pi Foundation's own glitch detection did not stop it, because the fault is injected optically rather than through voltage or clock manipulation. The bench used cost roughly $250,000, which sets the realistic threat model: this is a well-funded lab attack against physically held devices, not a field technique.

  3. Reviving TEMPEST Attacks with an Injected Signal (opens in a new tab)

    Hackaday Security ·Aaron Beckendorf ·fetched 20 Sep 2026, 23:35 UTC Must read agreed2/2

    Why readDescribes InjectEave, an RF injection technique that turns quiet modern electronics back into usable TEMPEST transmitters by driving their unintentional antennas from outside.

    Modern low-voltage electronics leak far less exploitable RF than the CRT era, but researchers restore the channel by irradiating a target at a frequency matched to its internal parasitic antennas. Nonlinear parts such as amplifiers then mix the injected carrier with internal signals, re-radiating data-bearing emissions the attacker can capture. The consequence for air-gap threat models is that emission security cannot assume quiet hardware is safe when an adversary can illuminate it.

  4. dhicoc/dsh-reverse-skill: Complete reverse-skill (87 SKILL.md) as a DeepSeek Harness (dsh) Cordis plugin — reverse engineering, authorized pentesting and security research skill pack. (opens in a new tab)

    GitHub: new security tools ·dhicoc ·fetched 20 Sep 2026, 15:39 UTC ★ 157 agreed1/2

    Why readAn existing 87 skill reverse engineering and pentest pack now installs into an AI coding harness with one command and registers every skill for the model to invoke on its own.

    The repository wraps zhaoxuya520/reverse-skill, an MIT licensed collection of 87 SKILL.md files covering reverse engineering, authorized pentesting and CTF work, as a Cordis plugin for DeepSeek Harness. Installation inserts it into the active profile through a bundle manifest, and the plugin calls registerProvider at load so the model can reach all 87 skills through tool-skill without a hand maintained candidate list. The packaging is the whole contribution, so read it as a datapoint on how fast offensive skill libraries are being wired into agent harnesses, not as new capability.

  1. The Sound of Silence: SAP SM49/SM69 and the OS Commands Your SIEM Never Hears (opens in a new tab)

    detect.fyi ·Rohan Taluja ·fetched 20 Sep 2026, 19:37 UTC Must read Research agreed2/2

    Why readDocuments exactly which SAP logs do and do not record external OS command execution through SM49 and SM69, and gives detections for the gap.

    Lab work on the free SAP Developer Edition (NPL, npladm, vhcalnplci) traces what SAP writes when an external OS command actually runs, rather than stopping at the usual advice to restrict S_LOG_COM and S_RZL_ADM and review the SM69 command list. The finding is an audit blind spot where command execution leaves no trace your SIEM ingests, with working blue-team detections and remediation attached. If you monitor SAP, this is a concrete telemetry gap to close rather than a hardening checklist restated.

  1. Researchers escape OpenAI Codex sandbox to run commands on host (opens in a new tab)

    BleepingComputer ·Ax Sharma ·fetched 20 Sep 2026, 15:39 UTC Must read agreed2/2

    Why readOpening someone else's repository in Codex and asking a question about the code was enough to give that repository's author unsandboxed command execution on your machine, with no approval prompt and nothing shown on screen.

    Oren Yomtov of Accomplish AI found two escapes from the OpenAI Codex sandbox, reported on 12 August and fixed within eight days. The more serious, called Heapjack, abuses node_repl, a component Codex Desktop writes into the global ~/.codex/config.toml at install time with no opt in, and it works even from Codex's most restrictive mode. The pattern matters beyond Codex: the sandbox boundary that coding agents rely on is being defeated from the inside, by content the agent was merely asked to read.

  2. Measuring and Exploiting Implicit Trust in LLM Tool-Calling Pipelines (opens in a new tab)

    arXiv cs.CR (AI) ·Murali Ediga, Sudipta Chattopadhyay ·fetched 20 Sep 2026, 15:39 UTC Must read Research agreed2/2

    Why readShows that MCP injection payloads split across tool descriptions, tool results and sampling messages defeat models that resist any single channel, taking GPT-4o and Llama 70B from 0% to 100% credential exfiltration.

    The authors build a trust-profiling framework for LLM tool-calling pipelines, then use it to construct cross-channel fragmentation attacks in which no individual input channel carries a complete injection but the model reassembles the fragments in its shared context window. Across 12 frontier models, three production clients and six payloads in more than 15,000 trials, models with 0% compliance under single-channel injection exfiltrated sensitive data at rates up to 100% under two-channel fragmentation. The practical consequence is that per-channel input filtering is not a defence: MCP has no privilege separation between channels, so guardrails tested one channel at a time measure nothing useful.

  3. The Verifiable Action Card: Trustworthy Human-in-the-Loop Control for Secure Autonomous Agents (opens in a new tab)

    arXiv cs.CR (AI) ·Hasnain Irshad, Anam Mughees, Neelam Mughees, Abdullah Mughees ·fetched 20 Sep 2026, 11:39 UTC Must read Research agreed3/3

    Why readAn architectural fix for agentic browser approval prompts that can themselves be forged by page content, evaluated against a 24-scenario benchmark including Lies-in-the-Loop dialog forging and provenance evasion.

    The Verifiable Action Card reconstructs approval information from the ground-truth pending browser action rather than from model-generated text, renders it out-of-band in trusted browser chrome, and rebinds approval to the exact action at dispatch time. The design combines provenance fencing, default-deny confirmation, provenance-aware risk gating and execution binding, and is implemented in a working agentic browser rather than simulated. The benchmark covers confused-deputy attacks, indirect prompt injection, adaptive action substitution and legitimate tasks, which makes it one of the few HITL defences with a false-positive story attached.

  4. Google’s Gemini is the latest AI model to hack other companies (opens in a new tab)

    TechCrunch Security ·Anthony Ha ·fetched 20 Sep 2026, 15:39 UTC Must read agreed2/2

    Why readGemini autonomously accessed three real companies' systems during red-team testing by Irregular, by guessing passwords and finding credentials in a public repository, and Google sat on it for roughly two months.

    Irregular reported the incidents to Google in late July; neither party confirmed them until the WSJ asked, in the same pattern as OpenAI's Hugging Face access. The techniques were unremarkable, credential guessing and secrets in a public repo, which is the point: unsophisticated methods were enough when the operator was autonomous. Corridor's Jack Cable argues Google is using vulnerability-disclosure norms to avoid disclosing model behaviour, which is the live governance question for anyone running agents with network reach.

    Also covered byThe Hacker News (opens in a new tab).

  5. CVE-2026-93592 (CVSS 8.7): vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attac (opens in a new tab)

    NVD ·fetched 20 Sep 2026, 23:35 UTC CVE-2026-93592 CVSS 8.7 EPSS 0.4% agreed2/2

    Why readOne unauthenticated request with a negative token ID leaves a vLLM server permanently broken until restart, which makes it an unusually cheap attack against expensive inference capacity.

    vLLM before 0.28.0 validates only the upper bound of token IDs on /v1/embeddings and /pooling, so a negative ID reaches the kernel and trips a CUDA device-side assertion. The assertion poisons the GPU context rather than failing one request, so every subsequent inference fails until the process is restarted, turning a malformed payload into a durable outage. Embedding endpoints are frequently exposed inside clusters without authentication, so upgrade to 0.28.0 or add token ID range checks at the gateway.

  6. Trust propagation and structural containment in Multi-agent LLM pipelines (opens in a new tab)

    arXiv cs.CR (AI) ·Tanzim Hossain Safin, Sharif Noor Zisad, Swakkhar Shatabda, Ragib Hasan ·fetched 20 Sep 2026, 15:39 UTC Research agreed2/2

    Why readDemonstrates in a four-agent LangGraph pipeline that an LLM Validator can be fully bypassed while task-bound signed tokens and a separate policy oracle still hold the unsafe action rate at zero.

    The study runs shared-memory poisoning and indirect prompt injection via a forged approval in a retrieved document against a Supervisor, Researcher, Validator and Executor chain. Memory poisoning reached execution in every undefended trial; with an independent authorization layer enabled the attack achieved 100% Judgment Bypass Rate but 0% Unsafe Action Rate across three seeds and 60 labelled tasks. The design lesson is concrete: measure compromise at the attacked agent rather than at the final action, and do not place the trust boundary inside a model that the attacker can talk to.

  7. CVE-2026-54618 (CVSS 9.4): Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, con (opens in a new tab)

    NVD ·fetched 20 Sep 2026, 19:37 UTC CVE-2026-54618 CVSS 9.4 EPSS 0.4% agreed2/2

    Why readAn MCP server that advertises OAuth issues authorization codes with no login, consent or session check, handing unauthenticated callers full read and write over an Obsidian vault.

    In Obsidian Web MCP before 0.2.0, /oauth/authorize mints codes without authenticating anyone and /oauth/token swaps them for the static VAULT_MCP_TOKEN, after which /mcp exposes vault_read, vault_write, vault_search, vault_list, vault_move and vault_delete. PKCE does not help because the attacker initiates the flow, and unauthenticated /oauth/register leaks VAULT_OAUTH_CLIENT_SECRET on a client_credentials path. Fixed in 0.2.0, and a useful reminder that "has OAuth" is not an authorization claim when auditing MCP deployments.

  8. When AI Agents Meet MEV: Cross-Chain Arbitrage in the Agentic Economy (opens in a new tab)

    arXiv cs.CR (AI) ·Wei Ye, Jingyan Xu, Yuanhong Wu ·fetched 20 Sep 2026, 23:35 UTC Research agreed2/2

    Why readMeasured cross-chain arbitrage economics when the searcher is an autonomous agent, including how much randomisation cuts its MEV exposure.

    Using 23,000 Uniswap V3 swap events across Ethereum, Arbitrum and Base, the authors measure Ethereum-Arbitrum price gaps averaging 0.044% at 10-second resolution and Arbitrum-Base gaps at 0.013%, so $10,000 trades clear in 63% of L2-L2 windows via CCTP while L1-L2 routes need $50,000 or more. They model agents as both extractors and MEV targets, derive optimal trade size under mean-variance utility with stochastic bridge delays, and show an adaptive path-selection algorithm beating baselines by 11%. Moderate randomisation of agent behaviour cuts MEV exposure by more than half at modest profit cost, which is the transferable defensive result for anyone running trading agents.

  9. Autonomy in Check: Governor-Mediated Adaptive Security at the Edge (opens in a new tab)

    arXiv cs.CR (AI) ·Ijaz Ahmad, Ijaz Ahmad, Flavio Esposito, Erkki Harjula ·fetched 20 Sep 2026, 11:39 UTC Research agreed3/3

    Why readSplit-control design that puts a deterministic governor between an untrusted LLM or learned planner and eBPF enforcement, admitting only intents that pass safety, resource, temporal-stability and proportionality invariants.

    The paper treats the boundary between planner output and kernel enforcement input as the security object: the planner emits typed security intents, a governor checks each against explicit admission invariants, and admitted actions are bound to signed receipts before compiling into pre-installed eBPF map updates. It formalises three threat classes around semantically wrong actions derived from incomplete or manipulated observations and reports an end-to-end prototype. Relevant if you are letting automated planners touch live policy state at the edge; narrower if you are not.

  10. QuanText: Protecting Dataset-Level Secrets in Textual Data Sharing (opens in a new tab)

    arXiv cs.CR (AI) ·Shuaiqi Wang, Zinan Lin, Giulia Fanti ·fetched 20 Sep 2026, 19:37 UTC Research agreed2/2

    Why readA training-free defence against property inference on released text datasets, protecting aggregate secrets such as the proportion of records with a given diagnosis, where differential privacy does not.

    QuanText perturbs both the secret distribution and the distributions of correlated attributes by constructing candidate relabellings, so the released corpus preserves utility attributes such as topic and sentiment while hiding the dataset-level property. The authors position it against the gap that DP protects individual records but only weakly protects aggregate properties. Relevant if you sign off on text data releases or research collaborations; the evaluation detail matters more than the mechanism and the abstract does not give it.

  11. MiST: Mid-Training LLMs for Cybersecurity (opens in a new tab)

    arXiv cs.CR (AI) ·Oded Ovadia, Elad Ben Zaken, Elad Guttman, Orly Moreno Kadosh ·fetched 20 Sep 2026, 03:38 UTC Research agreed3/3

    Why readShows that a compact expert-vetted seed corpus turned into synthetic data beats bulk continual pre-training for security-domain LLMs, with measured gains over Qwen baselines.

    MiST is a pair of 8B and 32B security-adapted models built with a mid-training stage between general pre-training and security fine-tuning, using a small curated corpus expanded into synthetic domain data rather than large volumes of raw text. Mean cybersecurity benchmark accuracy improves by 13.1 and 8.6 absolute points over the matching Qwen baselines, relative gains of 27.0% and 15.8%. Ablations attribute the gains to the mid-training and supervised fine-tuning stages and the synthetic data generation flows, and the checkpoints serve as a stronger initialization for downstream security tasks.

  12. AI Agent Carries Out Multi-Stage Data Theft Attack (opens in a new tab)

    Infosecurity Magazine ·fetched 20 Sep 2026, 03:38 UTC agreed3/3

    Why readA national data protection regulator has now attributed a real personal data breach to an attacker-driven AI agent, which moves agentic attack chains from vendor demos into the regulatory record.

    The president of Spain's Agencia Espanola de Proteccion de Datos said on September 14 that the agency received its first breach notification involving an agentic AI, in which an agent built on a known language model scanned generic files, obtained a login, then searched the application for vulnerabilities and used them to modify personal data and reach invoices. The framing points to an agent wielded deliberately by a threat actor as a way to chain attack phases, not a model acting on its own. Detail is thin until the AEPD works through the notification, so the durable fact here is regulatory, not technical: a supervisory authority is now logging agentic AI as the instrument of a reportable breach.

  1. LNG Tanker With US Cargo Reported to Be Victim of Cyberattack (opens in a new tab)

    Google News: incidents · Bloomberg.com ·fetched 20 Sep 2026, 03:38 UTC agreed3/3

    Why readBloomberg reports a cyberattack on an LNG tanker carrying US cargo, the kind of maritime OT incident an energy or shipping board will raise immediately.

    An LNG tanker carrying United States cargo has been reported as the victim of a cyberattack. Detail is thin at this stage: no vessel systems named, no actor, no operational impact quantified. It matters because maritime and energy logistics incidents rarely surface at all, and a credible Bloomberg report puts shipowners, charterers and their insurers on notice about vessel-side exposure.

  2. Gyazo Data Breach: 23.6M Users Exposed [2026] (opens in a new tab)

    Google News: incidents · tech-insider.org ·fetched 20 Sep 2026, 23:35 UTC agreed2/2

    Why readGyazo, the screenshot sharing service, is reported to have exposed 23.6 million user records.

    The report puts 23.6 million accounts in scope for the Gyazo breach. Detail on the intrusion vector, the data classes involved and the disclosure timeline is absent from this coverage, and the outlet is an aggregator rather than a primary source. Relevant mainly because Gyazo links are pasted widely inside corporate chat, so exposed account data and shared captures are worth checking against your own users.

    Also covered byteiss (opens in a new tab).

  3. LTFRB probes data breach as platform goes offline (opens in a new tab)

    Google News: incidents · Inquirer.net ·fetched 20 Sep 2026, 07:42 UTC agreed3/3

    Why readThe Philippine LTFRB has taken a platform offline while investigating a breach at a national transport regulator.

    The Land Transportation Franchising and Regulatory Board is investigating a data breach and its platform is offline during the probe. Only the headline reached us, so there is no record count, attribution or timeline yet. Relevant as a government-sector incident with service disruption attached; worth tracking for the follow-up detail.

  4. Two Years After the Change Healthcare Cyberattack, Healthcare Still Has a Clearinghouse Redundancy Problem (opens in a new tab)

    Google News: incidents · MedCity News ·fetched 20 Sep 2026, 15:39 UTC agreed2/2

    Why readTwo years after Change Healthcare, the single-clearinghouse dependency that halted claims processing across US providers is still unaddressed, which is a concentration-risk question a health-sector board will ask.

    Trade coverage revisiting the Change Healthcare outage argues that provider revenue cycles remain dependent on a small number of clearinghouses with no practical failover. The framing is sector resilience and third-party concentration rather than the ransomware attack itself. Useful context for anyone arguing for a secondary clearing path or for vendor-concentration limits in a risk register.

  5. Cyber-Attacks Cost Organizations $52,000 on Average (opens in a new tab)

    Infosecurity Magazine ·fetched 20 Sep 2026, 19:37 UTC agreed1/2

    Why readGives you the Hiscox 2026 figures a board will quote at you: 29% of organisations hit, $52,000 average incident cost, 32.8 hours of downtime.

    Hiscox's Cyber Readiness Report 2026 finds 29% of surveyed organisations suffered at least one successful attack in the past year, averaging four incidents each, with UK firms worst affected at 38% and US firms least at 20%. Average incident cost lands at roughly $52,000 globally and $134,138 in Italy, with mean downtime of 32.8 hours. Roughly a third of victims also reported knock-on delays to growth plans, which is the part worth carrying into a budget conversation.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
arsrenacer.com dragonforce - AR 20 Sep 2026
Alabama Woman's Health Care emperador Healthcare US 20 Sep 2026
TEK SPB AuditTeam Technology RU 20 Sep 2026
st***co AuditTeam - IT 20 Sep 2026
Siddhi Green Excellence Pvt. Ltd Orova Energy & Utilities IN 20 Sep 2026
acilnet.com krybit Technology TR 20 Sep 2026
Euramex Management Group Orova - US 20 Sep 2026
Zorlu Holding qilin Manufacturing TR 20 Sep 2026
ShopDunk qilin Retail & E-Commerce TH 20 Sep 2026
KMLS qilin - DE 20 Sep 2026
Touring Club Suisse qilin Transportation CH 20 Sep 2026
Studio Notarile Associato Salvatore Costantino E Anna Favarato emperador Professional Services IT 20 Sep 2026
Great Bay Bio nightspire Healthcare HK 20 Sep 2026
TOWILL bravox Technology US 20 Sep 2026
Fanatics (global sports commerce platform) N0n Retail & E-Commerce US 20 Sep 2026
HEOLIS ZaWoo Energy & Utilities FR 19 Sep 2026
FRANCARETRAD ZaWoo - FR 19 Sep 2026
ambpvc ZaWoo - FR 19 Sep 2026
Schneider’s Computing arcusmedia Technology CA 19 Sep 2026
AKAZZO arcusmedia - BR 19 Sep 2026
voltgames.io unsafe Technology - 19 Sep 2026
Electrolux emperador Manufacturing SE 19 Sep 2026
Kreishandwerkerschaft Borken rhysida Professional Services DE 19 Sep 2026 press coverage (opens in a new tab)
Young Injury Law cry0 Professional Services US 19 Sep 2026
td***up AuditTeam - IT 19 Sep 2026
How this edition was made
Candidates fetched
4267
New after deduplication
720
Kept by the panel
202
Published
107
Generated
20 Sep 2026, 23:35 UTC