CFToday Curated security signals.

Daily edition · 2026-09-28

Monday, 28 September 2026

53 items across 8 sections, selected from 4798 candidates over 6 runs. 109 carried the panel unanimously.

Show
Section

  1. NeedyMantis: Unpacking a post-compromise malware family used in targeted operations (opens in a new tab)

    Microsoft Security ·Microsoft Threat Intelligence ·fetched 28 Sep 2026, 19:39 UTC Must read Research agreed3/3

    Why readFirst public analysis of NeedyMantis, a modular post-compromise implant tied to the DAEMON Tools supply chain compromise, with IOCs and hunting queries for telecom, university and government-contractor networks.

    Microsoft Threat Intelligence documents NeedyMantis, a modular malware family deployed after initial access to maintain long-term persistence and support follow-on operations, with activity traced back to at least October 2025. It was discovered by pivoting from indicators associated with the DAEMON Tools supply chain compromise that Kaspersky previously reported. Targeting spans telecommunications firms, universities, medical nonprofits, intergovernmental organisations and government contractors; the post ships architecture and capability detail, hunting queries and indicators of compromise.

    Indicators4
    Hashes
    e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e 9cb68f986043a576e19d32184c583b7d8f571c7219d8dc0065dced1c13f077ef c82520eb03c084226be4eafbff46f56dca0aa8804a2a7f23a085a96afe71ef77
    Domains
    corp[.]tripswithengine[.]com
  2. Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation (opens in a new tab)

    Krebs on Security ·BrianKrebs ·fetched 28 Sep 2026, 15:38 UTC agreed3/3

    Why readNames Pepijn van der Stap, a 23-year-old previously convicted as 'Umbreon', as the man Dutch police arrested over ShinyHunters data thefts, and tracks what the group did next.

    Three sources identify the suspect arrested in the Netherlands this month as van der Stap, convicted in 2023 over extortions prosecutors valued at 1.5 to 2.7 million euros and since working publicly as a software engineer and researcher. In the days after the arrest, remaining ShinyHunters members escalated sharply, stealing data from the FBI and extorting the Cl0p ransomware crew. Original reporting on an actor group that many enterprise victims are currently dealing with.

  3. Vulnerability Attack Case: Installation of a Web Shell and Execution of a Scanner by Exploiting a Telerik UI Vulnerability (opens in a new tab)

    AhnLab ASEC ·ATCP ·fetched 28 Sep 2026, 03:39 UTC CVE-2019-18935 EPSS 99.7% agreed3/3

    Why readConfirms CVE-2019-18935 is still being worked in the wild against Telerik UI for ASP.NET AJAX, with the post-exploitation chain laid out incident by incident.

    AhnLab documents two separate intrusions against unpatched Telerik UI for ASP.NET AJAX servers, both starting from the 2019 deserialization RCE. One ended in a reverse shell, a privilege escalation attempt and a web shell; the other in scanner execution from the compromised host. The CVE is seven years old and sits at the top of the EPSS distribution, so the practical value here is the reminder that internet-facing Telerik installs remain a live initial access route, plus the artifacts to hunt for.

    Indicators3
    Addresses
    206[.]82[.]6[.]22 65[.]98[.]5[.]158
    Domains
    api[.]telegram[.]org
  4. Hackers Exploit GlobalProtect Flaw and Turn Stolen Data Into 2.4 Million Fraud Messages (opens in a new tab)

    Cybersecurity News ·Tushar Subhra Dutta ·fetched 28 Sep 2026, 07:40 UTC agreed3/3

    Why readSOCRadar traced Operation Master, which abused seven GlobalProtect gateways across four countries to seed a fraud platform that sent 2.4 million invoice-fraud messages at Brazilian targets.

    Attackers combined a GlobalProtect VPN login bypass with web application attacks to reach corporate networks between April and mid-September 2026, exfiltrating records from at least nine database systems. Stolen customer data was fed into a messaging platform that by 16 September had sent 2,468,335 emails plus SMS, with fraudulent invoices personalised using the stolen records to raise credibility. SOCRadar found the operation by pivoting from an exposed server to successive attacker-controlled hosts; financial losses remain unquantified.

    Indicators15
    Hashes
    d566ccdd099b0decb7e7288c20097f34da2613e3ffe8c5acbc1a1d01b6fe217c c40c1d4bb0e01f217c893f3dbc6b40802a260ef423f628889a48f996a4c96ed8 2553146aea0b133d565684a8bdfb14cb91526eb88b4e5b22b129b1212f763dd7 54caa256483876debd21c264bfc31bd96f925b2167f6d9358ab7ee0c87e6e37b 0c36cf593cf177b87f34abb19b5d65619199a4aca9c8e19e39318ad2c4033385 fd72014903466f2abcabb724df58682e629bf300703a06dad4dd0551018a42b5 39aab72976d63f0218c3470c05afce5a896d28f860efaa598288d9409499b26b 9a839b1e4c8cc5c0ebac1849973f136e68aae8eba357296be9e6cef9aff35ae6 88527b06d836200a36130ee219242e4a8342520df85cb3886769da646dac25c9 2ced60c88f5a2b36acb977ebf120e39b527dcff07b5072013350ebeefcabe760 6394cb167a33772fc47596e22cd2a51f3dfa9867385d962cb700b78f021c60ca 0b6bb51ef917c32edf75ff65a510b6a136575cfd2075305f7abe7d98e351b8b8
    Addresses
    91[.]92[.]241[.]187
    Domains
    qrcode[.]a55scd[.]com[.]br pix-proxy-sable[.]vercel[.]app
  5. August 2026 Threat Trend Report on Ransomware (opens in a new tab)

    AhnLab ASEC ·ATCP ·fetched 28 Sep 2026, 03:39 UTC agreed3/3

    Why readAugust 2026 leak-site counts by sector and country, with the collection method stated: 158 US victims, 63 in information and communications, 46 in manufacturing.

    Ransomware victim counts for August 2026 compiled from dedicated leak sites via AhnLab's ATIP infrastructure. Information and communications led by sector with 63 incidents, ahead of manufacturing at 46 and wholesale/distribution at 26; the US dominated by region with 158 cases, followed by Cyprus at 15, Italy at 14 and France at 13. Useful as a sector baseline, with the caveat common to all DLS-derived data: it measures what groups chose to publish, not what they compromised.

  6. Ransom & Dark Web Issues Week 4, September 2026 (opens in a new tab)

    AhnLab ASEC ·ATCP ·fetched 28 Sep 2026, 23:38 UTC agreed2/3

    Why readCurrent victimology for Metaencryptor and a ShinyHunters claim against a US federal law enforcement agency, useful if you track leak-site activity by sector.

    AhnLab's weekly roundup lists Metaencryptor ransomware attacks on a South Korean camera module and equipment manufacturer and a Japanese automotive parts maker, indicating continued pressure on East Asian manufacturing supply chains. It also records a ShinyHunters claim of breaching a US federal law enforcement agency and stealing sensitive data, which remains an unverified actor assertion at this stage. Indicators and the underlying analysis sit behind an AhnLab TIP subscription, so the public post is victimology only.

  1. Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (opens in a new tab)

    Unit 42 ·Unit 42 ·fetched 28 Sep 2026, 23:38 UTC Must read CVE-2026-88771 EPSS 1.2% agreed3/3

    Why readTwo NetScaler zero days under active exploitation, CVE-2026-88771 (unauthenticated RCE) and CVE-2026-88772 (DTLS memory overflow), with 50,277 exposed instances counted as of 27 September 2026.

    Citrix confirms in-the-wild exploitation of CVE-2026-88771, an input validation failure allowing an unauthenticated attacker to run commands on NetScaler ADC and Gateway, and CVE-2026-88772, a memory overflow in the DTLS configuration leading to RCE or DoS. Cortex Xpanse telemetry put 50,277 instances potentially exposed on 27 September 2026. Patch to current Citrix builds immediately and check for prior compromise; NetScaler has a long history of post-exploitation persistence surviving the update.

    Also covered byRapid7 (opens in a new tab),The Register Security (opens in a new tab),Help Net Security (opens in a new tab),Sophos Threat Research (opens in a new tab),Truesec (opens in a new tab),BleepingComputer (opens in a new tab),GreyNoise (opens in a new tab),NCSC UK (opens in a new tab),SecurityWeek (opens in a new tab),Security Affairs (opens in a new tab),CERT-FR (ANSSI) (opens in a new tab),Horizon3 Attack Team (opens in a new tab),watchTowr Labs (opens in a new tab).

  2. Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th) (opens in a new tab)

    SANS ISC Diary ·fetched 28 Sep 2026, 23:38 UTC CVE-2026-86950 agreed3/3

    Why readCVE-2026-86950 is already being exploited against iOS 26, macOS 26 and macOS 15, with Apple citing an extremely sophisticated attack on targeted individuals and Meta Product Security credited with the report.

    Apple shipped emergency patches for its older branches to fix CVE-2026-86950, which it acknowledges may have been exploited in a highly targeted attack. iOS 27 and macOS 27 are not affected, and today's 27-branch update carries functional fixes only, so the action is upgrading devices still on 26 and 15 or moving them to 27. Meta Product Security reported the bug, which fits the mercenary-spyware pattern of recent Apple emergency releases.

  3. Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 28 Sep 2026, 11:40 UTC CVE-2026-48842 EPSS 0.9% agreed2/2

    Why readPre-auth SQL injection in Roundcube Webmail (1.6.x before 1.6.16, 1.7.x before 1.7.1) is confirmed under active exploitation, four months after the fix shipped.

    CVE-2026-48842 (CVSS 8.1) is a pre-authentication SQL injection reachable through Roundcube's virtuser_query plugin, patched on 24 May 2026 in 1.6.16 and 1.7.1. The Canadian Centre for Cyber Security updated its advisory on 21 September 2026 to state that open-source reporting shows exploitation in the wild. EPSS still sits at 0.009, so the scoring data lags the advisory; treat internet-facing Roundcube instances still on older 1.6.x or 1.7.0 builds as exposed to database compromise and check whether virtuser_query is enabled.

  4. ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns (opens in a new tab)

    The Record ·fetched 28 Sep 2026, 19:39 UTC agreed3/3

    Why readIf you mitigated Oracle PeopleSoft CVE-2026-35273 with the published workarounds rather than the patch, ShinyHunters is now specifically hunting you.

    Mandiant says ShinyHunters has restarted exploitation of CVE-2026-35273 in PeopleSoft, a bug the group originally burned as a zero-day against academic institutions between 27 May and 9 June before Oracle shipped a fix on 10 June. The new campaign is tuned to defeat the interim guidance Mandiant itself published, so environments that chose workarounds over the patch are the ones at risk. PeopleSoft's footprint across government, education and healthcare makes the patch-versus-workaround decision worth revisiting today.

    Also covered bySecurityWeek (opens in a new tab).

  5. CVE-2026-93643 (CVSS 9.8): When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can a (opens in a new tab)

    NVD ·fetched 28 Sep 2026, 11:40 UTC CVE-2026-93643 CVSS 9.8 EPSS 1.0% agreed2/2

    Why readUnauthenticated path-traversal write to command execution as the zimbra user when OnlyOffice document editing is enabled, on a mail platform with a long history of in-the-wild exploitation.

    CVE-2026-93643 (CVSS 9.8, AV:N/PR:N/UI:N) lets an unauthenticated attacker who can reach an existing public Briefcase document abuse unsigned save fields to write outside the intended path and execute commands as zimbra. The precondition is that OnlyOffice or Document Editing is available. EPSS is still low at 0.0096, but Zimbra pre-auth bugs have historically been picked up quickly, so patch rather than wait for the telemetry.

  6. CVE-2026-95832 (CVSS 9.3): Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 be (opens in a new tab)

    NVD ·fetched 28 Sep 2026, 11:40 UTC CVE-2026-95832 CVSS 9.3 EPSS 0.2% agreed2/2

    Why readkitty's colour control escape handler echoes an unrecognised field name back to the pty master, where the shell reads it as typed input, bypassing the printable-ASCII restriction added to fix CVE-2026-54057.

    CVE-2026-95832 affects kitty from 0.47.3 before 0.49.0. color_control() in kitty/window.py answers a query for an unknown field by placing the field name in the reply, and write_escape_code_to_child() in kitty/screen.c writes that reply to the pseudoterminal master without neutralising it for the shell. The 0.47.3 hardening reduces the payload to printable ASCII and consumes ; and = as delimiters, but every other printable character survives, and a newline is reachable via handle_remote_ssh() and get_ssh_data() in kittens/ssh/utils.py, which is enough to compose and submit a shell command. Anything that writes attacker-controlled bytes to the terminal, a cat of a hostile file or curl output, becomes command execution; upgrade to 0.49.0.

  7. CVE-2026-96812 (CVSS 8.8): Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with (opens in a new tab)

    NVD ·fetched 28 Sep 2026, 11:40 UTC Research CVE-2026-96812 CVSS 8.8 EPSS 0.1% agreed2/2

    Why readA /dev/cuse node inside a container image passes through gVisor's gofer to the host, turning a sandbox boundary into host root code execution.

    In Google gVisor before commit 573a9e73cf844f, the host file helper (gofer) fails to restrict a CUSE character device node included in a container image: opening it reaches the real host device. An attacker who can deploy container images into a sandbox can register a host device and abuse CUSE's unrestricted ioctl handling to overwrite root udev helper memory, achieving root execution on the host. Only Linux hosts with CUSE enabled are affected, but the whole point of gVisor is that this should not be possible.

  8. CVE-2026-84458 (CVSS 9.1): Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enab (opens in a new tab)

    NVD ·fetched 28 Sep 2026, 11:40 UTC Research CVE-2026-84458 CVSS 9.1 EPSS 0.4% agreed2/2

    Why readZammad before 7.1.2 binds SSO identities to local accounts on the provider-reported email alone, so anyone with an Azure AD tenant can log in as an existing agent or admin.

    With "Automatic account link on initial logon" enabled, Zammad matches an incoming third-party identity to a local account by email address without checking that the identity provider verified ownership of it. Because Zammad ships a multi-tenant Microsoft 365 /common app registration by default, an attacker who controls any identity in any Azure AD tenant can set that identity's email to a victim's address and authenticate as them, bypassing the local password entirely, including for administrators. Zammad now honours the xms_edov ID token claim and treats a missing claim as unverified; fixed in 7.1.2.

  9. Athena's disclosures begin (opens in a new tab)

    Chainguard ·fetched 28 Sep 2026, 19:39 UTC Research agreed3/3

    Why readFourteen real Java vulnerabilities that were fixed upstream, sometimes years ago, but never got a CVE, which means your scanner has been calling affected versions clean.

    Chainguard has published the first batch from its Athena programme: 14 silent vulnerabilities in Java projects, one critical, one high, eight medium and four low, all already fixed at HEAD and all absent from vulnerability databases. Patches are in a public repository and four of the more serious cases are walked through in the post. The broader point is the class of bug rather than this batch, since silent upstream fixes leave no signal for scanners and Chainguard says thousands more are queued behind these.

  10. CVE-2026-93834 (CVSS 8.8): A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concur (opens in a new tab)

    NVD ·fetched 28 Sep 2026, 11:40 UTC Research CVE-2026-93834 CVSS 8.8 EPSS 0.4% agreed2/2

    Why readA race between QEMU's main thread and a 9pfs worker gives a malicious guest a path out of the shared directory and, from there, host code execution as the QEMU user.

    Concurrent Tlcreate and Twalk requests in QEMU's 9pfs subsystem trigger a use-after-free that lets a guest user craft a fid path containing stale heap data. That bypasses the directory traversal restrictions and escapes the shared directory boundary, giving arbitrary host file read and write and ultimately code execution as the QEMU process user, which is a full VM escape. Relevant to anyone using 9p/virtio-9p passthrough for guest filesystem sharing.

  11. CVE-2026-100671 (CVSS 8.6): Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled (opens in a new tab)

    NVD ·fetched 28 Sep 2026, 23:38 UTC CVE-2026-100671 CVSS 8.6 EPSS 0.3% agreed3/3

    Why readA Grav page author can steal an administrator's session cookie through the Twig sandbox's get_cookie(), and the page cache then serves that cookie to anonymous visitors.

    Grav 2.0.19 through 2.0.24, and 2.0.0 to 2.0.18 and 1.7.x where content Twig was explicitly enabled, render user-authored page content through a Twig sandbox that allowlists get_cookie(). The read happens server-side via filter_input(INPUT_COOKIE, ...), so HttpOnly, Secure and SameSite do not apply, and Grav caches the post-Twig output keyed only on page identity and config checksum with no session, user or request dimension and no bypass for authenticated visitors. A user with only page-write permission can publish a page that captures the session identifier of the next administrator to view it, after which the cache serves that identifier to unauthenticated visitors who can replay it. security.twig_content.process_enabled has defaulted to true since 2.0.19.

  12. CVE-2026-100684 (CVSS 9.2): Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no e (opens in a new tab)

    NVD ·fetched 28 Sep 2026, 23:38 UTC CVE-2026-100684 CVSS 9.2 EPSS 0.3% agreed3/3

    Why readBudibase 3.41.0 to 3.45.0 lets anyone who can assert an invited user's email at a trusted IdP claim that pending invite, including admin.global.

    CVE-2026-100684 (CVSS 9.2) is an authentication bypass in sso.authenticate in @budibase/server: when no existing user matches an incoming SSO subject, the server resolves pending invites by IdP-asserted email alone, with no invite code check and no email_verified gate (that gate covers only the existing-account path). An attacker who can register at a tenant-trusted OIDC provider and assert the invited address inherits builder or admin privileges, reaching every app, datasource (including production credentials) and automation. Fixed in 3.45.0; the invite is consumed, so a hijack also locks out the legitimate invitee.

  1. New Attack Against RSA (opens in a new tab)

    Schneier on Security ·Bruce Schneier ·fetched 28 Sep 2026, 11:40 UTC agreed2/2

    Why readCuts the "RSA broken" headline down to size: a 2007 forgery attack newly implemented, subexponential not polynomial, and only against unpadded signatures.

    Schneier corrects the coverage of a new RSA result. It is a signature forgery attack that bypasses factoring rather than a key recovery, the underlying research dates to 2007, and it applies only to pure RSA signatures with no padding or formatting, which is not how RSA is deployed in practice. The implementation forged 1024-bit RSA signatures at a cost of 1,380 CPU core-years, roughly five months of wall-clock time, so it is faster than factoring but nowhere near practical.

  2. Video CDs Break Windows Explorer (opens in a new tab)

    Hacker News ·ClydeN ·fetched 28 Sep 2026, 07:40 UTC Research 126 points agreed3/3

    Why readReproducible steps that wedge Windows Explorer permanently by copying MPEGAV files off a Video CD, leaving a machine that only a hard power cycle recovers.

    Copying the MPEGAV folder from a VCD (a bin+cue image is provided) stalls the transfer at zero bytes and puts Explorer into a state where new files do not appear without a manual refresh, the UI glitches and the process cannot be restarted. A soft restart hangs indefinitely at the Restarting screen, so recovery requires the power or reset button. The author reproduces it in VMware Workstation for analysis; the security-relevant read is that untrusted removable media can deterministically deny service to a Windows host.

  1. From Source Code to Network Profile: Automated and Traceable MUD Profile Generation for IoT Devices (opens in a new tab)

    arXiv cs.CR (all) ·Alessandro Lotto, Abdulla R. A. Almenhali, Savio Sciancalepore, Alessandro Brighente ·fetched 28 Sep 2026, 07:40 UTC Research agreed3/3

    Why readAutoMUD generates MUD network policy profiles from IoT firmware source rather than from captured traffic, recovering rare and failure-triggered communications that observation-based tooling never sees.

    Traffic-based MUD generation requires deploying the device and monitoring it for a long period, and still only captures behaviour exercised during observation, so configuration-dependent or error-path connections end up missing from the policy and break legitimate operation once enforced. AutoMUD combines static and syntactic extraction from firmware and source with retrieval-grounded language-model reasoning and deterministic validation and compilation, and keeps each rule traceable back to the software component that produced it. That traceability is the practical contribution: a generated allowlist you can audit rule by rule.

  2. Fast and Secure Simultaneous Authentication of Equals for WPA3 (opens in a new tab)

    arXiv cs.CR (all) ·João Ferreira, André Zúquete, Hélder Gomes ·fetched 28 Sep 2026, 19:39 UTC Research agreed3/3

    Why readA proposed fix for the CPU exhaustion denial of service that WPA3's SAE handshake hands to any attacker within radio range of an access point.

    SAE protects the pre-shared key against offline dictionary attacks, but Password Element derivation is expensive enough that an attacker can flood an access point into CPU exhaustion. The authors restructure the cost asymmetrically so the client carries the iterative search while the AP holds a fixed load, add a slow-path key derivation such as PBKDF2 or Argon2 to blunt brute force, and add a ticket mechanism so known devices skip the expensive exchange on re-authentication. This is an arXiv preprint proposing changes to a ratified standard, so treat it as a direction rather than something you can deploy.

  3. Towards Understanding LLM-Based Log Anomaly Detection: An Empirical Study of Performance, Efficiency, and Robustness (opens in a new tab)

    arXiv cs.CR (AI) ·Bin Li, Dongdong Wang, Siyang Lu ·fetched 28 Sep 2026, 07:40 UTC Research agreed3/3

    Why readShows that adaptation strategy, not parameter count, is what actually drives LLM log anomaly detection quality, and that low-bit quantisation costs almost nothing in accuracy.

    The authors run a systematic sweep across three public log datasets, varying adaptation strategy, model architecture, parameter scale and quantisation setting, then stress the resulting detectors with structural, semantic and label noise. Two findings matter for anyone budgeting a detection pipeline: models with near-identical accuracy can differ sharply in compute cost, and low-bit quantisation largely preserves detection performance in the configurations tested. The caveat is that the benchmarks are generic system logs rather than security telemetry, so the cost curves transfer better than the accuracy numbers do.

  4. Quarantined isn't contained: Agentic phishing response with Elastic and Sublime (opens in a new tab)

    Elastic Security Labs ·Sandiya Ramamoorthy ·fetched 28 Sep 2026, 23:38 UTC agreed2/3

    Why readA concrete worked example of the cross-tool correlation gap: an email quarantine at 09:00 and odd PowerShell at 09:05 that only read as one campaign when viewed together.

    Elastic Security Labs argues that a phishing email quarantined by Sublime and a suspicious PowerShell execution five minutes later on an endpoint each look resolved in isolation, because the two signals sit in separate products with no shared analyst. The post pitches an agentic layer sitting over unified data as the thing that closes the gap, rather than data consolidation alone. The correlation pattern is sound and reusable, but the piece is built around a specific Elastic and Sublime integration, so treat the tooling claims as vendor positioning rather than evaluated results.

  5. Between Two Nerds: Real-time cyber defence (opens in a new tab)

    Risky Business News ·fetched 28 Sep 2026, 11:40 UTC agreed1/2

    Why readA useful argument about whether real-time cyber defence is a real operational capability or a phrase vendors attach to detection tooling.

    Tom Uren and The Grugq take apart the idea of real-time cyber defence, asking whether defenders can meaningfully act inside the timeframe of an intrusion or whether the term describes faster alerting dressed up as response. The discussion extends to where agentic AI actually fits, and whether automated defence can keep pace with automated offence. No new facts here, but it is a clean framing for anyone being sold on autonomous response.

DFIR

1
  1. Collecting evidence faster than an alibi (opens in a new tab)

    Magnet Forensics ·HaadiyaAli ·fetched 28 Sep 2026, 03:39 UTC agreed2/3

    Why readReframes forensic turnaround time as a window that closes when a suspect has had long enough to build an account, not as a backlog statistic.

    A veteran ICAC examiner argues that the metric worth optimising is the gap between gaining access to digital evidence and the point where a suspect has settled on a story. Artifacts do not decay, but the chance to test an account against them while leads are still moving does. It is vendor-published and makes no technical claims, so the takeaway is a triage priority argument you can use with case leadership rather than anything you deploy.

  1. AgentXploit: Autonomous Repository-to-Runtime Red-Teaming for AI Agents (opens in a new tab)

    arXiv cs.CR (AI) ·Weida Liang, Shi Qiu, Zhun Wang, Simon Sure ·fetched 28 Sep 2026, 07:40 UTC Must read Research agreed3/3

    Why readAn automated white-box red-teaming system for AI agents plus AgentXploit-Bench, 72 reproducible vulnerabilities across 12 open-source agent systems and frameworks.

    AgentXploit splits auditing into two roles: an Analyzer Agent that traces attacker-controlled input to sensitive operations and records code-supported candidate attack paths, and an Exploiter Agent that turns those paths into working attacks and refines them from runtime feedback. Attacks must go through the task-defined attacker interface and be confirmed by an external verifier, so success is not self-reported. Reported end-to-end success is 59.3% across three runs, and the released benchmark of 72 reproducible bugs is usable on its own for anyone testing agent frameworks.

  2. Configuration, Not Conscience: A Large-Scale Empirical Study of LLM System Prompts (opens in a new tab)

    arXiv cs.CR (all) ·Constantinos Patsakis, Vasilios Argyropoulos, Efthymios Alepis ·fetched 28 Sep 2026, 11:40 UTC Must read Research agreed2/2

    Why readMeasures 407 leaked system prompts from 62 vendors and finds roughly 58% of classified words are tool and protocol instruction against about 5% safety policy, with strict rule-lines guarding tool use over harmful content 11:1.

    The authors merge four community collections of leaked, reconstructed and officially published system prompts, then classify content at block level, finding 29 near-duplicate clusters across 66 files and heavy literal text transfer between a small set of cross-vendor pairs. Operational instruction dominates ethical statements by an order of magnitude, and version chains churn thousands of words per release. The conclusion is a reframing with practical consequence: treat leaked prompts as configuration files, which makes reuse and prompt rot supply-chain and engineering problems rather than evidence of a model's values.

  3. CVE-2026-89032 (CVSS 8.7): BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to re (opens in a new tab)

    NVD ·fetched 28 Sep 2026, 11:40 UTC Research CVE-2026-89032 CVSS 8.7 EPSS 0.3% agreed2/2

    Why readLiteLLM's semantic cache leaks other tenants' cached responses, and the cached tool_calls payloads can make an agentic front-end auto-execute attacker-supplied tool calls under the victim's credentials.

    BerriAI LiteLLM before 1.101.0-rc.1 has a metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(), so cache entries are not actually scoped per tenant. A user holding any valid virtual key can submit semantically similar prompts against routes such as /v1/responses and /bedrock/* and retrieve another tenant's cached output, including PII, financial data or source code. Worse, a cached function_call or tool_calls payload can be returned to a different principal, giving cache-poisoned tool execution under the victim's credentials in agent front-ends.

  4. FragToken: Amplifying LLM Inference Costs through Noncanonical Token Generation (opens in a new tab)

    arXiv cs.CR (AI) ·Zihan Wang, Rui Zhang, Xinyuan Qian, Qingchuan Zhao ·fetched 28 Sep 2026, 07:40 UTC Research agreed3/3

    Why readA denial-of-wallet attack on LLM inference that hides in the tokenizer: the model is trained to emit non-canonical token sequences, so decoding steps multiply while the visible response length stays normal.

    Token sequences map many-to-one onto decoded text, so the same output can be represented by longer non-canonical sequences than the tokenizer would normally produce. FragToken trains a model to prefer those sequences, inflating autoregressive decoding steps across all traffic rather than only on attacker-triggered requests, which defeats detection based on abnormally long or repetitive outputs. The authors also find that naively maximising fragmentation wrecks output quality, so the attack has to trade fragmentation against utility.

  5. How we found 24 Android vulnerabilities using our open source AI security agent (opens in a new tab)

    GitHub Security Blog ·Kevin Stubbings ·fetched 28 Sep 2026, 19:39 UTC Research agreed3/3

    Why readOpen-source LLM taskflow prompts that found and got fixed more than 20 real Android application vulnerabilities, with the prompts published so you can run them on your own code.

    GitHub Security Lab built the Taskflow Agent, a framework for packaging and sharing structured LLM audit prompts, and used it to find 24 vulnerabilities in Android applications. The key design choice is splitting research into incremental steps rather than asking a model to audit a whole app, which surfaced complex bugs the model otherwise missed. The taskflows are open source and runnable against your own project, though a GitHub Copilot license is required.

  6. AI tools help hacker break in for $25 per target (opens in a new tab)

    CSO Online ·fetched 28 Sep 2026, 07:40 UTC Must read agreed3/3

    Why readGambit traced an attacker who compromised 27 of 105 targeted online retailers in five days using off-the-shelf AI agent harnesses, at an average model spend of $25 per target.

    The operator chained three open-source AI harnesses: Strix for vulnerability discovery, Cairn for autonomous end-to-end exploitation and Hermes for campaign orchestration, with model access bought through OpenRouter. An OpenRouter balance capture on 25 August showed $7,005 spent over four weeks, roughly $25 per attack, with most compromises completed in hours. Outcomes included around 600,000 live card records taken from two businesses and skimmer scripts planted at five more, which puts hard economics on autonomous AI-driven intrusion rather than speculation about it.

  7. AGATE: Provenance-Based Runtime Defense Against Compositional Attacks on LLM Agents (opens in a new tab)

    arXiv cs.CR (AI) ·Xiaorui Zhang, Zhuoran Cheng, Kailin Liu, Zhaoxi Sun ·fetched 28 Sep 2026, 07:40 UTC Research agreed3/3

    Why readA runtime authorization and data-provenance gate for agent harnesses that makes deterministic decisions with no LLM in the decision path, with adapters already written for DeepSeek Harness, OpenCode and OpenClaw.

    AGATE instruments the agent-harness boundary to bind authorization to operator declarations and host approval events, with delegated grants tied to exact parameters, expiry and a use count, while source registration links observed inputs to later transfers and an effect ledger tracks repeated requests. Because checks are deterministic and retain their grounds alongside execution evidence, decisions can be replayed forensically, which is the part most agent guardrails lack. Evaluation covers 153 exercised attack chains, and the three host adapters translate each harness's native observation and veto points into one shared gate without modifying host code.

  8. AuthGuard-R: Safety-Compliant Mission Hijacking and Dual-Gate Defense for LLM-Controlled Robots (opens in a new tab)

    arXiv cs.CR (AI) ·Saidattu Chepuri, Vikas Srivastava ·fetched 28 Sep 2026, 07:40 UTC Research agreed3/3

    Why readNames a gap most LLM robot defences miss: an action can pass a physical safety check and still violate the mission the user authorised.

    Safety-compliant mission hijacking covers redirecting a delivery robot, swapping an approved object, widening an operating region, switching on an unneeded sensor, or stalling a mission, none of which trip a hazard gate. MissionPAIR is an adaptive attack framework that searches for executable plans passing the safety gate while breaking the authenticated mission; AuthGuard-R is a deterministic authorization layer binding each action to a signed mission plus robot identity, object and region scope, current state, time and input provenance. The authorization-versus-safety framing transfers directly to any LLM agent with a tool budget, not just robots.

  9. Toward verifiably private learning from federated data (opens in a new tab)

    arXiv cs.CR (all) ·Katharine Daly, Yu Xiao, Zachary Garrett, Brett McLarnon ·fetched 28 Sep 2026, 23:38 UTC Research agreed3/3

    Why readA productionised federated learning system using TEEs to give externally verifiable central differential privacy, with policies that cryptographically bind uploaded data to an allowed set of Python workloads.

    Devices upload data encrypted under keys held by a TEE-hosted key management service, and each upload is cryptographically tied to a policy constraining which server-side programs may later process it, with the permitted workload set published to inspectable transparency logs. This delivers externally verifiable central DP guarantees rather than trust-me assertions, and decouples the DP accounting schedule from device availability. The authors report improved device coverage and better privacy-utility curves, and say the system has been productionised.

  10. CVE-2026-100561 (CVSS 8.6): OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could t (opens in a new tab)

    NVD ·fetched 28 Sep 2026, 19:39 UTC Must read CVE-2026-100561 CVSS 8.6 EPSS 0.2% agreed3/3

    Why readThe clearest lesson in this batch of agent CVEs: approving a wrapper once approves everything the wrapper can carry, because the policy never looked at the inner command.

    OpenClaw from 2026.3.22 up to 2026.8.1 evaluated exec approvals against the wrapper binary rather than the command in its arguments, so a durable allow decision for one benign invocation let a later agent turn substitute any inner command and run it with host privileges. The affected carriers go well past shells: process monitors, tracers, namespace tools and proxy wrappers all resolved through the same trust gap. After upgrading to 2026.8.1, go back and review every permanent approval an operator granted, because the stored decisions are the exploit primitive.

  11. CVE-2026-100599 (CVSS 8.7): OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome comman (opens in a new tab)

    NVD ·fetched 28 Sep 2026, 19:39 UTC CVE-2026-100599 CVSS 8.7 EPSS 0.3% agreed3/3

    Why readOpenClaw's googlemeet.chrome command executes caller-supplied process arrays on a paired node without the system.run approval flow, giving a tool-enabled agent arbitrary execution.

    OpenClaw 2026.5.1 through 2026.7.0 skip the configured exec approval path for Google Meet node commands: googlemeet.chrome accepts caller-supplied audio command arrays and runs them on the paired node directly. Where the Google Meet plugin is enabled, a Chrome node is paired and the command is allowed, any agent able to invoke it can execute chosen processes against files, credentials and browser profiles on that node. Fixed in 2026.7.1; the stated workaround is to remove googlemeet.chrome from allowed node commands or disable the plugin.

  12. CVE-2026-100552 (CVSS 8.7): OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation (opens in a new tab)

    NVD ·fetched 28 Sep 2026, 19:39 UTC CVE-2026-100552 CVSS 8.7 EPSS 0.3% agreed3/3

    Why readPer-chat tools.allow rules in OpenClaw filtered only OpenClaw tools, leaving the Codex runtime's shell, process, file and patch tools reachable from a restricted conversation.

    OpenClaw before 2026.8.1 applied conversation-level tool allowlists to its own tools but not to those owned by the Codex app-server runtime. A lower-trust conversation assigned to a Codex runtime and deliberately restricted could still reach native command and file tools, so anyone able to prompt that agent bypassed the configured policy. Impact scales with the runtime's host permissions and sandbox settings; fixed in 2026.8.1.

  1. New Mexico jury finds Meta deceived consumers about data privacy practices (opens in a new tab)

    The Record ·fetched 28 Sep 2026, 23:38 UTC agreed3/3

    Why readA jury verdict putting a per-violation price on privacy representations, with roughly 44 million findings against Facebook under a single state's consumer protection statute.

    A New Mexico jury found that Facebook violated the state's Unfair Practices Act close to 44 million times by telling users they controlled how their data was shared and that the company did not buy or sell private user data. Jurors additionally found the company's public statements about hate speech and misinformation willfully deceptive. Each violation carries civil penalties of up to $5,000, so the damages figure a judge sets in the coming weeks could run into the billions, which makes this a useful reference point for how privacy marketing language is treated as an enforceable representation.

  2. Elon Musk, SpaceXAI subpoenaed by NYC in AI safety investigation (opens in a new tab)

    CNBC Technology ·fetched 28 Sep 2026, 19:39 UTC agreed2/3

    Why readA US city legislature has taken subpoena action on AI risk, with cybersecurity named explicitly among the harms it is weighing rules against.

    The New York City Council subpoenaed Elon Musk, or another SpaceXAI representative, to testify in an investigation into whether AI risks to public safety, cybersecurity, economic stability, privacy and consumers justify immediate local legislation. The target is the conglomerate formed when SpaceX merged with xAI in February 2026, which now also owns X and Grok. Municipal AI rulemaking is early and its reach is limited, but this is a concrete step past the usual hearing letters.

  3. Pennsylvania part of multistate settlement with Labcorp following 2019 data breach (opens in a new tab)

    Google News: incidents · WPXI ·fetched 28 Sep 2026, 07:40 UTC agreed2/3

    Why readA multistate attorneys general settlement landing more than six years after the 2019 Labcorp breach, a useful data point for how long regulatory tail risk actually runs.

    Pennsylvania has joined a multistate settlement with Labcorp over the 2019 breach of its patient data. The report is a short local news item and carries no settlement terms, remediation commitments or affected-record figures. Its value is purely as an enforcement timeline marker: state AGs are still extracting consequences from an incident that is now six years old, which is worth citing when scoping breach reserve and retention assumptions.

  1. Bitget blames North Korea for $387.5M crypto wallet raid (opens in a new tab)

    The Register Security ·fetched 28 Sep 2026, 03:39 UTC Must read agreed3/3

    Why readBitget confirms $387.5M drained from exchange wallets with $228M moving in eighteen minutes, and attributes the operation to North Korea.

    Bitget's CEO confirmed roughly $387.5 million in digital assets stolen, revised up from an initial $351.6 million after Zcash and TRON holdings were added. Arkham's blockchain tracing puts $228 million out the door between 18:58 and 19:16 UTC, including $153 million of XRP from a wallet it identifies as a Bitget cold wallet, plus $66.2 million ETH, $34.8 million USDT, $12.9 million USDC and $12.8 million Tether Gold, with Arbitrum, Optimism, BNB Smart Chain, Avalanche and Base also affected. Bitget maintains cold wallets and customer balances were unaffected, a claim in tension with Arkham's cold-wallet identification and the point worth watching as the incident develops.

    Also covered byInfosecurity Magazine (opens in a new tab).

  2. Pentagon data breach may affect 4 million (opens in a new tab)

    Google News: incidents · FOX 8 News ·fetched 28 Sep 2026, 19:39 UTC agreed3/3

    Why readA Pentagon data breach reported to affect roughly 4 million people, which is the defence-sector incident your executives will ask about.

    Early mainstream reporting says a Pentagon data breach may affect around 4 million individuals. No attacker, intrusion vector, data categories or notification timeline are given in the available text. The scale and the named organisation make it a board-level item for anyone in the defence supply chain, but expect the substance to arrive in later filings and follow-up coverage.

    Also covered byFederal News Network (opens in a new tab),Military.com (opens in a new tab).

  3. Park24's Times Car Suffers Data Breach Affecting 6.6 Million Records, Including Driver's License Images (opens in a new tab)

    Google News: incidents · finance.biggo.com ·fetched 28 Sep 2026, 07:40 UTC agreed3/3

    Why readPark24's Times Car service lost 6.6 million records including driver's licence images, a scale and data type that carries real identity-fraud and regulatory weight in Japan.

    Car-sharing operator Park24 disclosed a breach of its Times Car service affecting roughly 6.6 million records, with scanned driver's licence images among the exposed data. Licence imagery is high-value for identity fraud and account takeover downstream, which raises the consequence well above a typical contact-details leak. No vector, dwell time or attacker detail has been published yet.

  4. Kiteworks lifts advisory after precautionary warning for customers to shut down systems (opens in a new tab)

    Cybersecurity Dive ·David Jones ·fetched 28 Sep 2026, 19:39 UTC agreed3/3

    Why readKiteworks pulled back the emergency shutdown advisory it issued to customers on Friday, so the operational question is whether to bring systems back online.

    Acting on what its CISO called credible threat intelligence from federal authorities, Kiteworks told customers on Friday to take systems offline during a precautionary window, then cancelled that guidance on Sunday. Sophos researchers tie the original warning to possible exploitation of a zero-day, though no CVE or confirmed compromise has been published. The vendor was formerly Accellion, whose file transfer product was mass-exploited in 2021, which is why a shutdown advisory from this particular company moved so fast.

  5. Cyberattack on Polish medical software provider exposes patient data (opens in a new tab)

    The Record ·fetched 28 Sep 2026, 15:38 UTC agreed3/3

    Why readA single SQL injection in one Polish practice-management vendor, Qbusoft's Medyc platform, exposed patient identity data across multiple downstream healthcare providers, a supply-chain failure pattern any health-sector board should be asking about.

    Attackers exploited an SQL injection flaw in Qbusoft's Medyc medical records and practice management platform in August, and the breach surfaced only via a notification issued last week by one of the affected healthcare providers. Confirmed stolen data includes names, national identification numbers, home addresses, phone numbers and email addresses; Qbusoft found evidence that attackers executed scripts against database tables holding medical information, which the affected provider was told makes medical record theft highly likely. It is the latest in a run of attacks on Poland's medical sector this year.

  6. AI-Driven Cyberattack Targets Adif and Renfe: 500GB Data Exfiltrated from Spanish Railway Infrastructure (opens in a new tab)

    Google News: incidents · rescana.com ·fetched 28 Sep 2026, 07:40 UTC agreed3/3

    Why readClaimed 500GB exfiltration from Spanish rail operators Adif and Renfe, which is a national critical-infrastructure incident peers in transport will be asked about.

    Only the headline was retrievable, and the source is a low-trust aggregator, so the 500GB figure and the "AI-driven" framing should both be treated as claims rather than established facts. If confirmed, a breach spanning the infrastructure manager and the operator of Spain's rail network is a sector-moving event with obvious NIS2 exposure. Seek primary confirmation from Adif, Renfe or INCIBE before repeating the numbers.

  7. NHS trust removes 10 staff from active duty over Noah Woods data breach investigation (opens in a new tab)

    Google News: incidents · Sky News ·fetched 28 Sep 2026, 03:39 UTC agreed3/3

    Why readAn NHS trust pulled 10 staff off active duty over unauthorised access to a patient's records, a concrete insider-misuse consequence rather than an external intrusion.

    Ten staff at an NHS trust have been removed from active duty while an investigation runs into improper access to records connected to the Noah Woods case. The response is the story: an insider snooping incident escalating to mass suspension, with ICO exposure and disciplinary process to follow. No technical detail on how the access was detected is given in the available reporting.

  8. Arizona court system targeted in cyberattack compromising personal records (opens in a new tab)

    Google News: incidents · yahoo.com ·fetched 28 Sep 2026, 03:39 UTC agreed3/3

    Why readThe Arizona state court system was hit by a cyberattack involving personal records, another judiciary target after a run of court-system incidents.

    Arizona's court system reports a cyberattack that compromised personal records. Available reporting gives no record count, threat actor or intrusion vector. For leaders in state and local government the relevant point is the continued targeting of judicial systems, which hold sealed and identity-rich data and are typically funded and staffed well below the risk they carry.

  9. Data breach affects 23,549 customers of Singapore telco Simba, personal data protection commission investigating (opens in a new tab)

    Google News: incidents · Yahoo ·fetched 28 Sep 2026, 03:39 UTC agreed3/3

    Why readSingapore telco Simba has disclosed a breach affecting 23,549 customers and the Personal Data Protection Commission has opened an investigation.

    Simba reported a data breach touching 23,549 customers, with Singapore's Personal Data Protection Commission investigating. The available reporting gives the victim count and the regulatory response but no root cause or intrusion detail. Relevant as a live PDPA enforcement track for anyone operating consumer services in Singapore.

    Also covered byThe Business Times (opens in a new tab).

  10. Vendor hack exposes Bank of Korea staff data (opens in a new tab)

    Google News: incidents · Korea JoongAng Daily ·fetched 28 Sep 2026, 07:40 UTC agreed2/3

    Why readA central bank had staff data taken through a supplier rather than its own systems, which is the third-party exposure question finance security teams get asked to answer after every such headline.

    The Bank of Korea has confirmed that employee data was exposed when one of its vendors was compromised. The institution's own network was not the entry point, which puts the focus on what data it had handed to suppliers and under what controls. Detail is thin at this stage, with no named vendor, record count, or attribution, so treat it as a prompt for third-party data inventory review rather than an actionable incident report.

  11. Risky Bulletin: Intel ends paid bug bounties (opens in a new tab)

    Risky Business News ·fetched 28 Sep 2026, 03:39 UTC agreed2/3

    Why readIntel pulling cash out of its bug bounty programme is a concrete change to disclosure economics at a major vendor, and it lands alongside two large financial loss events.

    Intel has removed monetary rewards from its bug bounty programme, a move researchers will price into where they spend time. The same bulletin covers a reported 350 million dollar compromise at Bitget and a 95 million euro fraud against an Italian bank. The item itself is show notes rather than reporting, so treat it as a pointer to follow rather than a source in its own right.

  12. College reaches $750,000 settlement following data breach affecting 96,000 members of the Dartmouth community (opens in a new tab)

    Google News: incidents · The Dartmouth ·fetched 28 Sep 2026, 11:40 UTC agreed1/2

    Why readA concrete per-record settlement benchmark, roughly eight dollars a head, for anyone modelling breach liability in higher education.

    Dartmouth College has agreed a $750,000 class settlement over a data breach affecting about 96,000 students, staff and alumni. The figure is useful mainly as a datapoint: it sits at the low end of US class action outcomes and gives a reference number for institutions estimating civil exposure from a record set of that size. Coverage so far is thin on the incident itself, including the intrusion vector and the data categories involved.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
MinMor Industries cry0 Manufacturing - 28 Sep 2026
Arnold Center qilin - US 28 Sep 2026
bakemyday.se incransom Retail & E-Commerce SE 28 Sep 2026
safescaffolding.net threeam Manufacturing GB 28 Sep 2026
coosalud.com threeam Healthcare CO 28 Sep 2026
pistonespersan.com.ar threeam Manufacturing AR 28 Sep 2026
midwestbit.com threeam Technology US 28 Sep 2026
apexus.com threeam Technology US 28 Sep 2026
bhn-expertise.com threeam Professional Services DE 28 Sep 2026
stjames.wa.edu.au threeam Education AU 28 Sep 2026
Goodrich Logistics Doommageddon Transportation - 28 Sep 2026
Chem Process Systems Pvt. Ltd. Doommageddon Manufacturing IN 28 Sep 2026
Starr Whitehouse Landscape Architects play Professional Services US 28 Sep 2026
Ever Ready First Aid play Healthcare US 28 Sep 2026
PKSF — Palli Karma-Sahayak Foundation medusalocker Financial Services BD 28 Sep 2026
Amazon Informatica emperador Technology BR 28 Sep 2026
New World Diagnostics qilin Healthcare PH 28 Sep 2026
Netech (Neeser Technik AG) payload Manufacturing CH 28 Sep 2026
Juntadeandalucia medusalocker Government & Defense ES 28 Sep 2026
Premiumfruits medusalocker Agriculture and Food Production ES 28 Sep 2026
The Center for Kidney Care interlock Healthcare US 28 Sep 2026
S...d SilentRansomGroup - - 28 Sep 2026
Geebee Garments akira Retail & E-Commerce - 28 Sep 2026
Knit akira Technology - 28 Sep 2026
SKLG qilin - JP 28 Sep 2026
How this edition was made
Candidates fetched
4798
New after deduplication
720
Kept by the panel
209
Published
122
Generated
28 Sep 2026, 23:38 UTC