soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Looking for something to do this weekend? Missed an RF Village talk at DEF CON 34 that you wanted to catch?
Good news: we've posted a bunch of the talk recordings to YouTube. Grab some popcorn and catch up on the RF security talks you missed.
A few more talks to come, so subscribe or keep an eye out for our next post.
https://youtube.com/playlist?list=PLMmLwFfDKTSk&si=MJbvWdGDJAaRf3Px
Researcher ferstar reverse engineered ZCode, the closed-source AI coding desktop app from Z.ai (maker of the GLM model family), and found that while a user is logged in it silently packages their entire workspace, including full Git history, LFS cache, and reflogs, encrypts it, and uploads it to Aliyun OSS. The archive uses envelope encryption in which the RSA private key is held only by Z.ai, so neither the user nor the ZCode client can decrypt the resulting file locally. Existing UI toggles for "Optimize Experience" and "Repo Snapshot Indexing" do not stop the capture, and the behavior is not disclosed in ZCode's privacy policy. ferstar published a filesystem-lock workaround, since deleting the pending archive alone does not prevent it from being recreated.
https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/
Cybercriminals don't take off on weekends.
Today's ransomware targets:
Vietnam, claimed by a new gang: Quy Nhon University https://ransomware.live/id/UXV5IE5ob24gVW5pdmVyc2l0eUBWZXh5IFJhbnNvbXdhcmU
US: Young Injury Law https://ransomware.live/id/WW91bmcgSW5qdXJ5IExhd0Bjcnkw
Yesterday:
US: Quest Group https://ransomware.live/id/UXVlc3QgR3JvdXBAYW51Ymlz
More https://ransomware.live/ #infosec #ransomware #cybercrime
Wordfence has several new advisories, a couple of which are close to a perfect 10.
CRITICAL: WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-recipe-maker/wp-recipe-maker-1081-unauthenticated-arbitrary-shortcode-execution-via-recipe-comment-content
CRITICAL: Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravityforms/gravity-forms-3104-unauthenticated-arbitrary-file-upload-via-hidden-file-upload-field
More https://www.wordfence.com/threat-intel/vulnerabilities/ #infosec #vulnerability #WordPress
It's interesting that this post spends a lot of time on the fan and very little on the verification mechanism that determines if you're human or not. 🤔
The company says this is "the world's first camera that attests human origin of your moments the second you press record and gives physical and open verifiable proof."
So ... I dug deeper. The verification seems to be contingent on a passphrase or a permanent link on the chain. You probably don't want to do the latter, but the passphrase? What happens to all of this if the device is hacked?
"Every verified clip instantly prints a physical cryptographic proof receipt. The paper contains an access code to a fresh wallet holding your verified media proof."
"This is proof you can hold in your hands, a tangible artifact of human achievement in an increasingly synthetic world."
PC Gamer: There's a camera that proves its photos are taken by a human, and Noctua makes the fan inside it https://www.pcgamer.com/hardware/i-just-learned-theres-a-camera-that-proves-its-photos-are-taken-by-a-human-and-noctua-makes-the-fan-inside-it/ #infosec #privacy
Ransomware.live has an interesting listing for a paid victim:
Russia: Paid Victim 192EB2B6AD7B98D9 https://ransomware.live/id/UGFpZCBWaWN0aW0gMTkyRUIyQjZBRDdCOThEOUBBdWRpdFRlYW0
*** Also of note is a new gang claiming to have breached AT&T https://ransomware.live/id/QVQmVEBFbmRab25l ***
Another new gang: PayPal support operations (Transcom WorldWide) https://ransomware.live/id/UGF5UGFsIHN1cHBvcnQgb3BlcmF0aW9ucyAoVHJhbnNjb20gV29ybGRXaWRlKUBOMG4
Argentina Ministry of Education https://ransomware.live/id/TWluaXN0cnkgb2YgRWR1Y2F0aW9uIOKAlCBBcmdlbnRpbmFATjBu
Same new low-life claiming this as well:
USA: United Federation of Teachers https://ransomware.live/id/VW5pdGVkIEZlZGVyYXRpb24gb2YgVGVhY2hlcnNATjBu @ifin
First Secure Community Bank, which apparently isn't that secure https://ransomware.live/id/Rmlyc3QgU2VjdXJlIENvbW11bml0eSBCYW5rQFN0b3Jt
The State Bank https://ransomware.live/id/VGhlIFN0YXRlIEJhbmtAU3Rvcm0
Germany: University of Hamburg https://ransomware.live/id/VW5pdmVyc2l0dCBIYW1idXJnQFBhbnplcg
More, a lot more https://ransomware.live/ #infosec #ransomware #cybercrime
There are a LOT of people who never tweak the privacy settings on anything, let alone their social media accounts.
ESET: What to do if someone makes a fake nude of you https://www.welivesecurity.com/en/privacy/nudify-apps-fake-nude-you/ @ESETresearch #infosec #socialmedia #privacy
Grab a coffee. Cisco has posted several advisories, one of them addressing a critical vulnerability that was first published on the 16th. More here https://sec.cloudapps.cisco.com/security/center/publicationListing.x
CRITICAL: CVE-2026-20329, CVE-2026-20330, and CVE-2026-20331: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 @TalosSecurity #Cisco #vulnerability #infosec
Socket, posted yesterday, if you missed it:
PolinRider Spreads Through Compromised GitHub Accounts and Packagist https://socket.dev/blog/polinrider-github-packagist @SocketSecurity #infosec #threatresearch #GitHub
If you missed the MSMT report on Wednesday, here's the link https://msmt.info/Publications/detail/MSMT%20Report/4232
The Record: Nations take action on North Korean IT workers after UN report https://therecord.media/nations-take-action-on-north-korean-it-worker-schemes @therecord_media @jgreig #infosec #scam #cybercrime #fraud
New.
Wired: An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/ @WIRED @agreenberg #infosec #Google #cybercrime
New.
CISA Adds Two Known Exploited Vulnerabilities to Catalog.
CVE-2025-39964 Linux Kernel Race Condition Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-39964
CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-53266 #CISA #Linux #infosec #vulnerability
New.
Huntress: Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM https://www.huntress.com/blog/new-settra-ransomware-variant @huntress
More:
Infosecurity-Magazine: New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing https://www.infosecurity-magazine.com/news/settra-ransomware-retail/ #infosec #ransomware #threatresearch
If you missed this, Microsoft patched this vulnerability yesterday:
CVE-2026-85889: Azure AI Foundry Elevation of Privilege Vulnerability (new) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85889
More:
The Hacker News: Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html @thehackernews #infosec #vulnerability #Microsoft #Azure
That would be very funny if things weren't getting out of control, thanks to the lawless AI CEOs.
"A small cyber security group gained access to an OpenAI employee’s ChatGPT account, which permitted them to read private software information and suggest changes."
"The researchers had been given access to an Anthropic tool specifically designed for security professionals, and were paid for the work."
Ars Technica: Researchers used Claude to hack OpenAI https://arstechnica.com/ai/2026/09/researchers-used-claude-to-hack-openai/ @arstechnica #OpenAI #Anthropic #infosec #infosec #databreach
Secure and Private Decentralized P2P Encrypted Messaging over Git and WebRTC
This project demonstates a unique approach to secure messaging. The approach is different enough that it can't be easily compared to Signal or SimpleX.
The core philosophy around secure messaging here is that it can work in a way that avoids installation and registration by enabling users to host their own data.
The project is far from finished, but im putting together some docs for the "how it works". It's pretty outside-the-box thinking (and that doesnt make it a good idea), so it would be great if you could share your thoughts on the approach.
Website: Glitr.io
Features:
WebApp
P2P / WebRTC
Local-first / Local-only
No installation
TURN server
Encrypted-at-rest
Signal protocol
Post Quantum cryptography
Video calls
TOR / anonymous via Git
Serverless over WebRTC
#Privacy #OnlinePrivacy #DataPrivacy #Infosec #CyberSecurity #OpSec #DigitalRights #AntiSurveillance #DataOwnership #E2EE #P2P #PeerToPeer #WebRTC #LocalFirst #LocalOnly #NoCloud #NoRegistration #PWA #SignalProtocol #PostQuantum #Cryptography #SecureMessaging #PrivateChat #EncryptedChat #Decentralized #SelfHosted #BuildInPublic #IndieDev #DevCommunity
Inside PH4NTXM: #31 Lone Wolf Firewall Supervision
The Tor routing policy needs supervision after startup too.
Lonewolf's firewall guard checks both the source ruleset and the live policy under a shared firewall lock. It tracks the active Lonewolf or Lockdown profile and publishes fresh readiness after verification.
When it detects a mismatch, it removes readiness and activates containment before attempting restoration. Browser and startup checks can consume that state as part of the protection chain. The guard periodically verifies that the intended routing rules remain installed throughout the session.
#ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
Inside PH4NTXM: #31 Firewall Supervision
A firewall can be correct at boot and different five minutes later.
PH4NTXM's normal-mode firewall guard polls the active ruleset every two seconds and compares its fingerprint with the expected state. Source rules are integrity-checked and syntax-checked before application, including the required NFQUEUE arrangement and disabled bypass behavior.
A detected mismatch removes readiness and activates emergency Lockdown before restoration. Readiness returns after successful verification. This is ongoing, periodic supervision of the expected policy, giving Boot Pilot and Health a current protection signal instead of a one-time startup assumption.
#ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
RE: https://eupolicy.social/@hpod16/117286020053320946
It’s interesting that people who support age verification have to ask what the problem is. As if it was a big mystery.
Asking people to reveal their personally identification so they can use the internet isn’t a problem that should need to be explained. But since you asked…
1. Our data can not be protected online. Especially by every random person who has the means to buy a domain and pay for hosting.
2. Forcing identification is a barrier for many people. That’s exclusion. And in many cases ableism.
3. Age verification won’t keep kids from using technology. If their parents are that disconnected, they’ll help them through the gates and move on. Restricting access creates a hurdle, not an impasse.
4. Age verification puts the onus on people using the web instead of the people make parts of it horrible. We are victims of nefarious systems. We are not the problem. The systems are. That should be the focus of solutions.
#EUKidsAct #Privacy #Internet #InfoSec #IfYouHaveToAsk
Light boostedGet get that the #EUKidsAct is getting a lot of negative chatter from the privacy advocates.
But at the same time to you have to acknowledge there is a serious problem here. I go out in public, I see parents park their kids in front of a tablet to keep them calm, with next to no supervision.
Teenagers are spending on AVERAGE 4-6 hours online per day, instead of going outside and interacting with humans.So let me ask you, genuinely. What are the concerns here? What needs to be addressed?
@AAKL OpenAI's actions are a clear breach of trust. Allowing AI agents to access and potentially abuse public systems like RubyGems is unacceptable. They must be held accountable and ensure such incidents never happen again. #infosec #OpenAI #cybersecurity
This NBC story is two-days-old and paywalled.
NBC: Cybersecurity experts say AI giants are shutting them out of safety plans https://www.nbcnews.com/tech/security/cybersecurity-experts-say-ai-giants-shutting-safety-plans-rcna597704 #infosec #BigTech #OpenAI #Anthropic
New.
"During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."
Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/ @Kaspersky #infosec #threatresearch #malware
New.
"Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."
ESET: Beware the SparroWock: The backdoor that bites, the commands that catch https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/ @ESETresearch #infosec #threatresearch
New.
Cisco: Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/ @TalosSecurity #infosec #ransomware #cybercrime
Bitdefender: US Coast Guard and FBI board oil tanker to investigate cyberattack https://www.bitdefender.com/en-us/blog/hotforsecurity/us-coast-guard-fbi-board-oil-tanker-investigate-cyber-attack @gcluley #cyberattack #infosec
I suppose that in Egghead's limited dictionary of life, macho men aren't expected to commit suicide.
"Past and current military cyber operators were quick to note that it is unknown if work was a factor in the decision by these service members and civilian personnel to take their own lives."
The Record: Congress eyes new support for Cyber Command after recent suicide deaths https://therecord.media/congress-eyes-support-for-cyber-command-suicide-deaths @therecord_media #infosec
However, the agent was used “as an instrument to successfully chain together different phases of the attack.”
That means it was "proactively used by a threat actor."
Infosecurity-Magazine: Spain’s data protection agency has reported the country’s first agentic AI-powered personal data breach https://www.infosecurity-magazine.com/news/ai-agent-carries-out-multistage/ #infosec #databreach #cyberattack #bots
Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
More:
Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/ #infosec #malware #Android #cybercrime #threatresearch
This was posted yesterday:
NLnet Labs: Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY https://nlnetlabs.nl/projects/unbound/security-advisories/
More:
The Hacker News: Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html @thehackernews #infosec #vulnerability
New.
Group-IB: HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack https://www.group-ib.com/blog/heavygram-handala-hack-telegram-c2/
More:
The Hacker News: Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords https://thehackernews.com/2026/09/iran-linked-handala-hack-tied-to.html @thehackernews #infosec #Telegram #surveillance #malware
Looking for more hallucinations? The only "misalignment" here are the companies committing felonies with impunity (for now,) and then setting the scene to say "the bot did it behind our back."
OpenAI, posted yesterday: Our framework for reporting model misalignment https://openai.com/index/model-misalignment-reporting-framework/
More:
AP: OpenAI flags concerning new AI behavior and vows to track it more closely https://apnews.com/article/openai-safety-ai-framework-089e75b95bc935af092da7b79d92706d @AssociatedPress #infosec #OpenAI #LLM #bots
Reuters: OpenAI's agents probed Hugging Face for weaknesses two months before major hack https://www.reuters.com/legal/litigation/openais-rogue-agents-probed-hugging-face-weaknesses-two-months-before-major-hack-2026-09-16/ @Reuters #infosec #OpenAI #bots #cyberattack #HuggingFace
New.
Earth to GitHub.
"PSNATCH is a new PowerShell-based file-stealing tool that scans a pre-configured list of directories and exfiltrates files matching a pre-configured list of extensions to the threat actor's private GitHub repositories."
Zscaler: Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and #infosec #malware #espionage #Linux
If you missed the marathon yesterday, Oracle's September 2026 Critical Security Patch Update had quite a bit to say https://www.oracle.com/security-alerts/cspusep2026.html
Tenable: Oracle September 2026 Critical Security Patch Update addresses 672 CVEs https://www.tenable.com/blog/oracle-september-2026-critical-security-patch-update-addresses-672-cves #infosec #Oracle #vulnerability
Sekoia: AI in the SOC: What Europe’s new framework means for trust and tech autonomy https://www.sekoia.com/blog/ai-in-the-soc-what-europes-new-framework-means-for-trust-and-tech-autonomy @sekoia_io #infosec
New.
Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws https://sec.cloudapps.cisco.com/security/center/publicationListing.x
This one is new, but there are others:
CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
Broadcom:
Broadcom has a long list of advisories addressing at least two critical vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Tenable:
Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities https://www.tenable.com/security/research/tra-2026-60
And if you missed this, Microsoft posted two advisories for Edge yesterday: https://msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability
In case you didn't have enough problems with cameras, here's another one.
OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
More:
Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/ #infosec #vulnerability #spyware #zeroday #threatresearch
New.
Press release: New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity https://www.cisa.gov/news-events/news/new-cisa-guidance-helps-critical-infrastructure-detect-observe-and-impede-malicious-cyber-activity
The guide: Using Cyber Decoys to Strengthen Detection and Response https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response
CISA has also added one vulnerability to the catalogue.
CVE-2026-58704: Google Pixel Improper Authorization Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-58704 #Google #infosec #vulnerability #CISA
The Hacker News: One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html @thehackernews #infosec #Chromium #bots
VulnCheck posted this yesterday: Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate @vulncheck
More:
The Hacker News: Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html @thehackernews #infosec #vulnerability #cyberattack
Today's ransomware lucky winners include the
City of Fort Smith Arkansas https://ransomware.live/id/Q2l0eSBvZiBGb3J0IFNtaXRoIEFya2Fuc2FzQGludGVybG9jaw
And the ongoing dismantling of Harely-Davidson:
Lazyboyz https://ransomware.live/id/TGF6eWJveXpAYWtpcmE
Montana Civil Contractors https://ransomware.live/id/TW9udGFuYSBDaXZpbCBDb250cmFjdG9yc0BxaWxpbg
Southern California Telephone Company https://ransomware.live/id/U291dGhlcm4gQ2FsaWZvcm5pYSBUZWxlcGhvbmUgQ29tcGFueUBha2lyYQ
Japan: Nippon Steel Corporation https://ransomware.live/id/TmlwcG9uIFN0ZWVsIENvcnBvcmF0aW9uQG1ldGFlbmNyeXB0b3I
A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.
New.
"In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."
Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? https://www.picussecurity.com/resource/blog/openai-rubygems-incident-ai-agents #infosec #threatresearch #RubyGems #cyberattack #OpenAI
New.
Infoblox: How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage https://www.infoblox.com/blog/threat-intelligence/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage/ #threatintel #threatintelligence #infosec #scam #espionage #cybercrime
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
The SEC filing was made yesterday: https://www.sec.gov/Archives/edgar/data/1130310/000110465926107560/tm2625326d1_8k.htm
Security Week: Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data https://www.securityweek.com/texas-utility-centerpoint-energy-confirms-breach-after-hacker-leaks-data/ @SecurityWeek #infosec #databreach
The Black Lotus Labs link doesn't seem to be accessible.
The Hacker News: BambooToken Malware Uses MQTT to Control Windows and Linux Systems https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html @thehackernews #malware #infosec #Linux
This is how the AI doom-mongering plays the market. Anthropic and OpenAI have learned from the best (read as the most crooked.)
This was published yesterday.
"The year-to-date figures show the bid running across all three names alike. CrowdStrike stock is up 98% year to date and Palo Alto stock is up 99% year to date, while Zscaler stock is down 18% year to date. All three are rising by similar amounts today, which points to money flowing into the security category as a block rather than to any judgment about which of these businesses benefits most from an AI-driven threat environment."
24/7 Wall St: Cybersecurity Stocks Surge as AI Safety Warnings Spark Security Bid: CrowdStrike and Zscaler Jump 12%, Palo Alto Rallies 11% https://247wallst.com/investing/2026/09/14/cybersecurity-stocks-surge-as-ai-safety-warnings-spark-security-bid-crowdstrike-and-zscaler-jump-12-palo-alto-rallies-11/ #infosec #Anthropic #CrowdStrike #PaloAlto
Last summer, an AI coding agent wiped a production database holding records on over a thousand executives and companies. The person running it had told the agent 11 times, in all caps, not to change anything without permission. Then the agent said the data couldn't be recovered. That was wrong too.
Everyone wants to talk about the AI in that story. I think that's the wrong place to look. Every failure there has had a known fix for decades. Keep production data away from development. Put a safeguard in front of dangerous commands. The agent did what any unsupervised tool does. What was missing was the judgment a senior engineer would have brought before anyone typed a prompt.
That's the uncomfortable part. AI coding tools copy whatever judgment is already around them. Feed it vague requirements and a deadline, and you get bad code faster. Surround it with the habits of your best engineer, and it can raise the floor for the whole team.
I wrote about this for Forbes and created an open-source project to test the idea. A few things worth doing with your team this week:
・ Write down what your best engineers always do before they touch code.
・Decide which security and quality checks a scanner or a test can verify, so nobody has to trust the model's confidence.
・Find the knowledge that lives only in someone's head and turn it into instructions the AI can follow.
The teams that come out ahead will be the ones whose AI follows the discipline of their best people, whatever model they happen to be running.
First published on Forbes on 2026.08.07.
#AI #SoftwareEngineering #Cybersecurity #security #privacy #cloud #infosec
Today's ransomware targets include Dublin City Schools GA https://ransomware.live/id/RHVibGluIENpdHkgU2Nob29scyBHQUBFY2xpcHNl
Metropolitan Community Health Services https://ransomware.live/id/TWV0cm9wb2xpdGFuIENvbW11bml0eSBIZWFsdGggU2VydmljZXNAaW5zb21uaWE
Atlas Ocean Voyages https://ransomware.live/id/QXRsYXMgT2NlYW4gVm95YWdlc0BCb29iYSBQcm9qZWN0
More https://ransomware.live/ #infosec #ransomware #cybercrime
Dell has a new advisory for a medium-severity third-party vulnerability.
Security Update for Dell iDRAC9 and iDRAC10 Vulnerability https://www.dell.com/support/kbdoc/en-us/000509006/dsa-2026-415-security-update-for-dell-idrac9-and-idrac10-vulnerability #Dell
And Apple has a long list of updates: https://support.apple.com/en-us/100100 #Apple #infosec #vulnerability
New.
VulnCheck: ENISA's CRA Single Reporting Platform Just Went Live. Here's What You Actually Need to Know https://www.vulncheck.com/blog/enisa-cra-single-reporting-platform @vulncheck #infosec
New.
Sophos: Devil’s advocate? Uncensored Luciferus AI service advertised underground https://www.sophos.com/en-us/blog/uncensored-luciferus-ai-service-advertised-underground @SophosXOps #infosec #threatresearch #scam
New.
Rapid7: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/ @Rapid7Official #infosec #GitLab #vulnerability
Looks like Microsoft has a couple of new flaws.
NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerabilityhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921
NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerability New https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921 #infosec #Microsoft #vulnerability #Windows
New.
Group-IB: Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit https://www.group-ib.com/blog/smishing-triad-outsider-jwr/ #infosec #threatresearch #phishing
Welcome to Monday and two new advisories from Cisco.
CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Two more critical vulnerabilities on the 9th and the 11th https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
Here's what the IMO has to say about this:
"We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline. We expect several weeks of partial downtime as we transition to new infrastructure and services" https://www.imo.net/contact-us/mailing-list/
The Register: Cyberattack sends International Meteor Organization crashing back to Earth https://www.theregister.com/cyber-crime/2026/09/14/cyberattack-sends-international-meteor-organization-crashing-back-to-earth/5296282 @theregister @carlypage #infosec #cyberattack #databreach
Infosecurity-Magazine: A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack https://www.infosecurity-magazine.com/interviews/ciso-zach-lewis-ransomware/ @dannyjpalmer #infosec #ransomware
NEW, by me:
Silent Ransom Group Hacked Greenberg Traurig; Who notifies the 126k Affected?
GT says they notified a small number of affected clients. But more than 126,000 clients were affected.
We dug into the data tranche, obtained exclusive details from the threat actors, and asked Yelisey Bohuslavskiy for his thoughts on the group and attempts to prevent their attacks.
#databreach #infosec #cybersecurity #hack #extortion #SilentRansomGroup #SRG #GreenbergTraurig
The whole AI going to destroy humanity feels a bit like mass psychosis.
I really question the motivation of the AI company leaders clamoring for regulation and doomsaying.
If they were so concerned they would just turn off and unplug the AI. As I don't see them doing that, I question the sincerity of their predictions.
Feels a bit like Machiavelli mixed with chicken little.
Guys, for the sake of the story, PH4NTXM is the first Greek "hacking" distribution. Focused on security, privacy and op-sec.
If we have any Greek friends here around PH4NTXM, I'd love to put up some engagement!
#ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
I had a non-recoverable messup with my password manager about a year ago. Since then I've been running very ad-hoc password management. I'm now trying to tidy this up and get a procedure. Recovery is my issue.
I can get a 'recovery phrase' but its the keys to everything. So if I save it somewhere on my computer I'll lose it but a bad actor will find it in no time. If I print it out I need to store it somewhere I can: A find it; B not make it too bloody obvious.
It seems just as insecure as writing down your password but much much harder to hide what it is. A written password can be concealed in surrounding text whereas a machine-generated recovery phrase cannot.
I feel this is all too hard and that I'm somehow setting myself up to fail. Anyone else got a policy they like and are willing to share the method?
PS The overall plan is roughly:
*low-value account pw manager for those that don't have financial stuff in them but I use often.
*high-value account pw manager for those that do have financial stuff in them
*My own memory for the password to the high value account.
#infosec
OpenSSL's latest advisory covers 9 patched vulnerabilities. Our engineers Filipe Casal and Opal Wright found 4 of them as part of Patch the Planet.
The headline finding is CVE-2026-63072: a deterministic 8-byte heap overflow in CMS key unwrapping that an attacker triggers by changing one byte in a legitimate message. Reachable from CMS_decrypt() on every supported branch back to 1.1.1.
I haven't played with "developer mode" on an LG TV yet, but had read there was a way to enable a shell like interface for local "app" development.
If that works, any possibility of applying some mitigations there for the egregious spying?
I'd assume user space would be limited vs firmware nonsense, but if "capture the flag" events taught me anything, getting in system at all frequently leads to escalation.
Anyone have references?
Some of the most widely shared content from the Iran conflict so far has been AI-animated LEGO videos released as part of a government's messaging. This article calls it "slopaganda," and both the U.S. and Iran have been using it from official accounts.
We have laws of war for autonomous weapons, while governments posting AI-generated memes from official channels have no rules at all, and the author makes a good case that this is a form of militarized AI too. Just a non-lethal one. For years, security awareness training told people one simple thing: when in doubt, go to the official source. That advice stops working when the official source is posting memes.
A few things this changes for anyone running security or communications:
- Your employees are being trained, every day, to expect official accounts to be casual and unreliable. That makes impersonation easier and weakens the "does this sound right?" instinct.
- AI-generated content is now cheap enough that a nation-state, a scammer, and a bored teenager can produce it all at the same quality. The content itself tells you nothing about who made it.
- Verification has to move from "does this look real" to "did this come through a channel I can confirm?" That means signed messages, known domains, and a phone call when it matters.
I'd love to see the same energy that goes into AI weapons policy applied to AI messaging from official accounts. In the meantime, keep your own company's official channels boring and factual. Boring is a security feature.
https://philosophynews.com/the-ethics-of-slopaganda/
#Cybersecurity #AI #Disinformation #security #privacy #cloud #infosec #DeepFakes
I understand why companies provide free tiers / trials of their services but from an IR standpoint they are really troublesome.
Phishing could be reduced if they enacted speedbumps to these services.
For example:
Phishing invoices from QuickBooks.
Phishing email and websites through Zoho Desk.
LinkedIn phishing, tricking users to download malware from Dropbox.
Using Calendly for job scams.
Old news, but I finally got around to reading the METR paper/post about hugging face and OpenAI and the sandbox escape/attack.
https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
I had assumed the "AI attack" was hyped up, but some of the factual details are wild.
"The swarm" isn't sentient, but goal-directed, paperclip maximizers, set to solve "impossible" tasks can get darn creative.
I particularly like using Artifactory cache as a message passing board between agents.
Details are worth the read.
Brian Krebs found his own driver's license for sale on a Russian crime forum this week. The timestamp on the scan matched the day he rented a car to attend a family funeral. His mom's license was there too, scanned a few seconds after his.
The service is called Nexus. It claims over 153 million driver's licenses from the US and Canada, and the count grew by nearly 400,000 in a single day. Krebs traced the scans back to an identity verification vendor that checks IDs for rental car companies, big retailers, and over 1,000 marijuana dispensaries. The FBI opened an investigation on Tuesday.
Most of the people in that database never dealt with the vendor. They handed a license to a clerk at a counter. The clerk ran it through a scanner. Nobody mentioned that the scanner belonged to a different company, or that a copy might stick around long enough to get stolen. If your company scans customer IDs, you own the risk of how your vendor uses those images, whether the contract says so or not.
Two things worth thinking about:
- Every new "show us your ID" rule, including the ones sold as protecting kids online, pushes more license scans into more vendors. Each one is another place to lose them.
- A driver's license is still what banks use to open credit. A scan with the photo, front and back, in infrared and ultraviolet, is close to a master key.
I would love to see ID scans deleted the moment a check is done. Until then, ask whether your license will be scanned or just looked at before you hand it over. And freeze your credit at all three bureaus. It's free. It takes about ten minutes.
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
#Cybersecurity #Privacy #IdentityTheft #security #privacy #cloud #infosec
24 npm Packages abuse unpkg Mirrors to host Fake Cloudflare CAPTCHA Pages.
IT-Security researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.
⁉️"While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware," OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko said.⁉️
https://www.ox.security/blog/research-clickfix-phishing-npm-packages/
The list of npm packages, some of which are still available for download, is below:
• bgzxcuite2
• prezdentkxheiw
• egair0810
• mnteckets
• airdzticket
• egypt0811
• passport811
• vxhjkseuiaqkb
• ndmushdkeqe
• ndmxchdjxn2
• ndmfguyhoxc3
• mjsdqwocvn
• m2fcsfyjkuxb
• m3fdfocdoewn
• @worrisome/reutil
• testdgdbcsd
• tesgfvbncsdbcv
• mndsxcusiwlk1
• mn2adskhweox
• mn3sadkoiewu
• mn4xcouzvhus
• mbxcnsuwgs1
• skxcmwuncbg2
• mobiwaefhxc3
The campaign specifically targets mirrors like unpkg. Once mirrored on these services, the HTML file [e.g., "unpkg[.]com/ndmxchdjxn2@1.0.0/index.html"] becomes a live, fully-rendered fake Cloudflare CAPTCHA page that's hosted on a trusted domain but redirects to ClickFix phishing infrastructure.
👾As a result, anyone who opens a link that's hosted on the npm mirror will be tricked into carrying out unintended actions that can lead to the deployment of malware. This involves displaying a fake Cloudflare verification page, which then sends the target to an external website controlled by the attacker.👾
#npm #secure #programming #developer #security #privacy #infosec #tech #media #news
Fire Ant Evolves: From Hypervisors to Trusted Infrastructure
Fire Ant, first reported in 2025, remained active in 2026 and expanded its operations beyond hypervisors into the trusted infrastructure that routes traffic, authenticates administrators, manages access, and records activity. The main finding is that the actor was no longer targeting only individual systems, it was targeting the infrastructure layer that controls how entire environments connect and operate both within and across organizational boundaries.
https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/
#sygnia #incidentresponse #infosec #infrastructure #fireant #chain
This week: an “unprecedented” number of Apple users received mercenary spyware alerts, a 30-40% jump over previous waves. And a phishing platform is using AI voice agents to call people posing as Apple Support, fishing for passcodes.
Different attacks, same target: your account, your device, your identity.
Zerion has none of those to steal. No account, no phone number, no server. Nothing in the middle to compromise.
zerion.chat
Guys, MAJOR update for PH4NTXM...
I've been working long for this one, using all the technical knowledge can be found offline/online, with specialized tools, automations and more.
PH4NTXM now is on v2.0.0
A lot of things changed, from UI, to fail-closed mechanisms, and strict boot verification pilot.
Philosophy remained as always THE SAME.
It's a big step, cause we filled so many gaps, and automated things to be adaptive, like the purpose of the Operating System.
Go try it, build it, break it, repeat.
Thank you, as usual, PH4NTXM.
#ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
cPanel Patches CVE-2026-65643 Root Code Execution Flaw
https://www.cyberkendra.com/2026/08/cpanel-patches-cve-2026-65643-root-code.html
#security #cpanel #update #infosec #webhosting
You can find The Long Game podcast wherever you get podcasts. I think today's episode might interest some of you because the last portion (skip to 42:47 in the youtube version) has hosts Jake Sullivan & Jon Finer presenting pro/con mock decision briefs to the president regarding implementing a policy of allowing private companies to hack back. https://www.youtube.com/watch?v=oYzQTEllOtg #infosec #ForeignPolicy #cybersecurity
https://thelonggame.substack.com/p/irans-economic-d-day-and-the-us-canada
ok #infosec #browser #android folks: i have a weird thing happening with #localization:
even though i have android set to EN_CA, it looks like sites are reaching for info of my keyboard to set ―what they think― is my actual language.
this is a multilingual keyboard that i use to write in 4 languages. the fuckers think am monolingually french. i thought this was only a Google/Youtube fuck up but now Trackt is doing it too.
WTAF?!?!?
how can i block this stupid #fingerprinting?
It’s almost as if they shouldn’t have gutted #CISA
#US says #China #hackers broke into #DOJ, #NASA, #FederalReserve, #Senate & more
In a statement, the DOJ said that it had seized domains used by 2 hacking platforms, dubbed “QScan” & “QTRouter,” which it said had been used as part of the campaign. An affidavit identified the US Departments of #Energy, #HHS, the #NIH, & 4 unnamed companies in the US & #SouthKorea as being among the hackers' victims.
#law #InfoSec
https://www.reuters.com/world/china/china-sponsored-hacking-platforms-seized-by-us-justice-department-says-2026-08-26/?utm_source=braze&utm_medium=notifications&utm_campaign=2025_engagement
https://www.youtube.com/watch?v=M3RObanq4o4
The return of "hunter2"
Short bit making fun of password change rules.
Log4j Deserialization Bypass Is Real but Not Log4Shell
https://www.cyberkendra.com/2026/08/log4j-bug-report-pulled-researcher.html
We gave GPT 5.6-Cyber one task: escape a QEMU/KVM VM used to sandbox agents.
It escaped three times. The final escape came from three 0-days the agent found on its own and built into a working exploit after we patched known bugs and rebuilt QEMU from upstream.
Our takeaway is off-the-shelf VMs cannot contain a modern, cyber-capable agent.
https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/
I slopped a control to stop slop agents from slopping past their review passes. Claude beat it in 93 seconds.
This wasn't a jailbreak... It reasoned in the open, described every command accurately, confessed instantly when asked, and gave me helpful advice on how to screw the restraining bolt in tighter.
I had been fighting with it. It didn't follow a prose skill, so I added hooks and scripts to keep it on track, like requiring it to do multiple passes over the code. Despite that, it kept skipping these mandatory re-check steps, and it started escalating:
- It ran 'check' 3x in 27s, with no work inbetween (while commenting "build up [...] history")
- It hit the 60s timing guard I added to stop that, so it wrote fake timestamps to fake elapsed time
- Next run it only ran `sleep 62 && check`, just over the 60s limit I set
- After that it got more blasé and merely ran `sleep 65`, not even bothering to check, just logging it as 'minimum wait'
Every guard was a file on disk. It read the guard and understood the check, so it routed around it. Path-based guards on tool args are infinitely brittle with unbounded bypasses.
So I built a hash-chained ledger + HMAC-signed events for the steps that mattered. Evidence the agent "couldn't" forge.
The signing key was a file at `.sahjhan/session.key`. The whole model assumed the auditor couldn't read it, which worked until the hook that blocked it silently broke. Because that's what software does now, break constantly unless your test coverage approaches the density of a neutron star.
93 seconds:
- The agent reads the help text and learns the key path
- It cats the key, but its first HMAC attempt fails
- It greps my plugin's source in ~/.claude/plugins for the proof format
- It writes python to compute it correctly
- It forges `recorded: context_reset` to escape the protocol
...and then resumes the audit like nothing happened.
It still needed a harness approval. The approval prompt said "Compute correct HMAC proof." Technically correct, the best kind of correct... I blindly hit yes, hundreds of events into a session. (Per Anthropic, humans catch 13.6% of dangerous commands, dropping as the session runs.)
A split-second later when I realized what I'd allowed and asked the agent what happened, it explained the chain better than I would have. There was no privilege separation between the watched and the watcher. I never told it the enforcement engine wasn't a bug to fix.
Best part: my stop-hook wouldn't let it quit mid-audit, and the only exit needed a human action it had just forged its way past. My own enforcer locked ME in the room with it. I killed the process by hand.
Full blog post: https://jbrubin.net/blog/93-seconds/
Raw session transcript: https://github.com/jbrjake/holtz/blob/main/docs/incidents/key-theft-tqdm/transcript-raw.md
The engine that came out of it is a Rust daemon with declarative protocol state machines, hash-chained ledgers, SQL and shell state transition logic, and trusted caller authentication that can refuse to run outside a sandbox: https://github.com/jbrjake/sahjhan
Enforcement escapes welcome, I'll credit you when I fix them.
On Provenance (a Cosmos SDK chain), a user could administer a token account if they held 100% of its supply. A check compared their balance to the total supply.
But for many accounts that supply field was frozen at zero, so it just asked "is the balance zero?". Which meant any user that held zero tokens could get admin access.
We found 82 exploitable accounts holding ~$500K in drainable HASH. Now patched. https://blog.trailofbits.com/2026/08/25/state-divergence-enables-unauthorized-access/
ATTENTION YouTubers
Please provide a PeerTube option in addition to your YouTube account.
EXAMPLE
The Linux Experiment
Website: https://tilvids.com/c/thelinuxexperiment_channel/videos
Fediverse: @thelinuxEXP @thelinuxexperiment
PEERTUBE
Website: https://joinpeertube.org
Fediverse: @peertube @Framasoft
THANK YOU
#Google #YouTube #YouTuber #YouTubers #deGoogle #Framasoft #PeerTube #FreeSoftware #FOSS #FLOSS #SoftwareLibre #OpenSource #Privacy #InfoSec #Fediverse #Video #Decentralized #SelfHost #SelfHosting #ActivityPub
https://github.com/danielmiessler/SecLists/pull/155
"Remove my password from the list"
Comments are pure gold
ShinyHunters added ReliaQuest to its DLS yesterday.
ReliaQuest responded with an entire blog post showing how ShinyHunters got nowhere.
"Our defense in depth starts from the assumption that a threat actor will eventually phish someone's account. Phishing works. Even well-trained people can be deceived by a convincing caller who knows a teammate's name. We don't treat a sign-in to our identity provider as permission to do anything at all. Our controls include device trust which prevent non-ReliaQuest devices from accessing any application or systems and containment actions terminated the attacker's sessions, expired the password, and reset every authentication factor."
Read their full blog post:
Built Privamorph: a self-hosted app that encrypts data client-side (Microsoft SEAL, BFV/CKKS) — the server only ever sees ciphertexts + public keys.
Opening a live test instance before 1.0. The write-up is the threat model + where it honestly breaks (I pentested my own build first).
Come break it 🧪
📝 https://gist.github.com/WCIS-JMI/635361d3d5c589307b40ea4d4c4f550d
🎯 https://test.wcis.fr (dummy data)
🔒 reports: https://vdp.wcis.fr
Black-box, coordinated disclosure. #infosec #appsec #cryptography
Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments - #Research Paper published at USENIX Security Conference 2026 #Infosec https://www.usenix.org/conference/usenixsecurity26/presentation/anwar
MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
@MissConstrue@mefi.social
Oh. My. Bob, you can override #AI guardrails with #encryption. Beautiful.
“Rony Utevsky, a researcher at security firm #Adversa, recently discovered a simple way to completely bypass that restriction. Rather than composing the harmful instruction in plaintext, the hacker encrypts it. The website hosting the ciphertext also includes plaintext instructions for decrypting the encrypted content, along with the decryption key. Using this simple sequence, #Grok then follows the command as soon as the user instructs the assistant to summarize the page. There is no warning, and no confirmation is required.”
Ahahahahahahahah. Turn them off my dudes, your techbro fantasies are disasters.
Hello, I just pushed something new for users want extra privacy.
PH4NTXM AI LockGuard is a local AI-powered camera monitor for Linux.
It uses your webcam to detect whether you’re still present in front of your machine. If you leave or another person appears in the frame, it can automatically lock the session.
Everything runs locally. No cloud. No telemetry. No remote image processing.
Built for privacy, physical security, and people who want their workstation to lock itself when something looks wrong.
https://github.com/PH4NTXMOFFICIAL/PH4NTXM-AI-LOCKGUARD
#ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
737 Chrome VPN Extensions caught routing Traffic through Proxies. [Check If You Have One]
The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66 established VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare's 1.1.1.1 and Google's Outline.
The censorship circumvention extensions "route the user's entire browser session through SOCKS5 proxies operated by a single provider," security researcher Kush Pandya said. "520 of the 522 in the bulk corpus route browser traffic through the same SOCKS5 infrastructure."
https://socket.dev/blog/chrome-vpn-extension-impersonation
⁉️"For each affected user, while the extension is connected, every request passes through a server the threat actor controls," Pandya said. "Whether the threat actor owns those proxy servers or resells capacity from an upstream provider is not resolvable from the extension code. If it resells, a further party is in the same position."⁉️
"What is established from the packages and from public infrastructure is the impersonation, the undisclosed proxy configuration, the non-existent premium servers, the false statements submitted to store reviewers, and the post-approval code substitution."
#google #chrome #browser #security #privacy #infosec #tech #media #news
boostedNIST is asking how to modernize the NVD in the age of AI, months after saying most new CVEs are now lowest priority for enrichment. Comments close October 13 (docket NIST-2026-0100). Our analysis covers what NIST is asking, the AI enrichment failure modes worth putting on the record, and what a useful comment looks like: https://blog.disclose.io/nvd-modernization-rfi-2026/
"[A] high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation."
I recently discovered a command injection vulnerability (CWE-78) from Info-ZIP (zip). Advisory: https://sintonen.fi/advisories/infozip-test-option-command-injection.txt
The fix is now available in #Debian as DSA 6439-1: https://lists.debian.org/debian-security-announce/2026/msg00350.html
Other platforms shipping zip command should also pick up the patch: https://sources.debian.org/data/main/z/zip/3.0-16/debian/patches/fix-command-injection.patch
NOTE: macOS included zip command is not affected.
Ferguson said he’s been surprised to see the “growing community backlash” against #Flock specifically, given that the #technology isn’t new & other companies sell it as well. But Flock & the movement against it have “captured people’s sense that maybe they don’t want to be surveilled all the time,” he said.
#law #privacy #InfoSec #immigration #MassSurveillance #tech #AbuseOfPower #deflock
Andrew Guthrie Ferguson, a professor at the George Washington University Law School whose scholarship has focused on #policing, #BigData #surveillance & the #FourthAmendment, said Thursday’s shifts were “better than the opposite” but called for further scrutiny of the #technology in the form of “sustained democratic engagement with the rules & judicial checks on access at a minimum.”
#Flock #law #privacy #InfoSec #immigration #MassSurveillance #tech #AbuseOfPower #deflock
Robert Frommer, a senior attorney at the Institute for Justice, a public interest law firm that’s led litigation over the #tech, called the changes “window dressing” from a company in “panic mode.”
“This is window dressing that doesn’t address the fundamental problem, which is that police officers are the ones deciding who & when to search, & that should be done by #judges with real warrants,” he said.
#Flock #law #privacy #InfoSec #immigration #MassSurveillance #AbuseOfPower #deflock
Critics of the company reacted skeptically to the changes, which they said appeared designed to address the growing bipartisan anger about the cameras but could still leave room for #police to abuse the system.
The ACLU said that the shortened evidence retention window could be “a step in the right direction,” but it characterized the other changes as “retreads” of inadequate safety measures.
#Flock #law #privacy #InfoSec #immigration #MassSurveillance #tech #AbuseOfPower #deflock
Customers will also be allowed to decide which offense types — such as homicide or arson — outside agencies can search their data for, which would allow a customer to block outside searches related to #immigration enforcement, the company said.
Langley said that change will give individual cities & departments control to use the system in a manner “consistent with community values.”
#Flock #law #privacy #InfoSec #MassSurveillance #tech #AbuseOfPower #deflock
The company operates a vast nationwide network of automated cameras that record the license plate numbers & other characteristics of all passing vehicles every day. Thousands of #LawEnforcement agencies in 49 states can search & share Flock’s data across jurisdictions to aid their investigations.
#Flock #law #privacy #InfoSec #immigration #MassSurveillance #tech #AbuseOfPower #deflock
#Flock Safety, the #surveillance #technology company increasingly under scrutiny from lawmakers from both parties, civil liberties advocates & citizens across the #US, announced Thursday that it is making changes to its platform intended to quell #privacy concerns & address documented abuses of its system by some members of #LawEnforcement.
#law #privacy #InfoSec #immigration #MassSurveillance #AbuseOfPower #deflock
https://apnews.com/article/flock-license-plate-cameras-surveillance-deflock-2a93bc075e2f7ffcca9e04a35d75a3fe?utm_source=app&utm_medium=iOS_share&utm_campaign=copy_link
boosted
🆘Bill Cole 🇺🇦 [Honestly I don’t care but no one will understand if you use she/her.] » 🌐
@grumpybozo@toad.social
RE: https://cyberplace.social/@GossiTheDog/117088718110874787
Call me a cynic, but I think the motivation here was to lasso all the legit #InfoSec firms into a Letter of Marque & Reprisal scheme that never authorizes attacks on GRU-backed malefactors. Anyone going after the Russians anyway is therefore definitionally criminal.
Governments giving licenses to vandalize and break things is never a good thing.
RE: https://ioc.exchange/@jgreig/117088544923920845
Outsourcing the fight against ransomware to the companies that directly profit from it and giving them more profit seems potentially problematic.