chiprook

Cybersecurity News

Breaches and leaks, vulnerabilities and the patches that follow, malware, surveillance and the investigations behind them.

Today
Security

Siemba brings continuous IDOR testing to production APIs

Siemba has added automated insecure direct object reference (IDOR) testing to its API Security Testing platform. A 200-endpoint collection can be tested in under an hour instead of days of manual work, covering REST, GraphQL and SOAP, with findings delivered already written up with reproduction steps.

Security

CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog

CISA expanded its Known Exploited Vulnerabilities catalog with three Linux kernel flaws: CVE-2025-39682 (CVSS 9.8, TLS receive-path memory disclosure and DoS), CVE-2025-39964 (CVSS 7.8, AF_ALG socket race) and CVE-2026-53266 (CVSS 8.8, ebtables SNAT out-of-bounds write). US federal agencies must patch all three within three days.

CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
Security

Revolut Customers Hit by Phishing Wave After Data Breach

Malwarebytes has uncovered a wave of smishing attacks targeting Revolut customers following the bank's confirmed data breach. Scammers send texts linking to a fake identity check that requests camera access and a password; several hundred accounts, including crypto investors, are believed affected.

Revolut Customers Hit by Phishing Wave After Data Breach
Security

OpenAI and 116 firms call for collective action on AI cyber defense

On August 27, 2026, OpenAI published an open letter, "A call for collective action on cyber defense," signed by 116 organizations including Anthropic, Microsoft, Google, Amazon, CrowdStrike, Palo Alto Networks, Mastercard and Visa. It warns that AI-enabled cyberattacks will become far more widespread and sophisticated, and calls for threat intelligence sharing, government coordination, funding for essential services and patching.

OpenAI and 116 firms call for collective action on AI cyber defense
Security

GraphWorm backdoor survives token revocation via OneDrive C2

A researcher analyzed GraphWorm, an implant tied to the China-nexus APT group Webworm. It uses OneDrive and Microsoft Graph as its C2 channel, and an upgrade command swaps all credentials on the fly, so revoking tokens only delays the attack.

GraphWorm backdoor survives token revocation via OneDrive C2
Security

Gyazo breach: 23.6 million user records stolen

Helpfeel confirmed a data breach at its screenshot-sharing platform Gyazo after an attacker exploited an image upload server flaw on September 11. About 23.62 million user records and metadata tied to roughly 490 million images were exposed.

Gyazo breach: 23.6 million user records stolen
Security

ClickFix Lures Deploy ChainScript RAT via Polygon C2 Rotation

Blackpoint researchers uncovered a new RAT called ChainScript delivered through ClickFix-style lures posing as Spotify, Zoom Workplace and Microsoft Teams. The malware uses the Polygon blockchain to rotate its command-and-control infrastructure.

ClickFix Lures Deploy ChainScript RAT via Polygon C2 Rotation
Security

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

SentinelOne linked North Korean group Jade Sleet to the compromise of an Indian IT company. The hackers used FLATROOF and ROOFDECK backdoors, targeting developers to penetrate networks.

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Security

North Korean hackers posed as recruiters, infected 30,000 devices

From December 2025 to July 2026, the WaterPlum group posed as recruiters to infect developers' devices: 30,000 devices in 100+ countries and 7,000 crypto wallets were affected, with over $10 million stolen for North Korea. The FBI, the US Department of Defense and authorities in Japan, Australia and Germany issued a joint warning.

North Korean hackers posed as recruiters, infected 30,000 devices
Security

Intent injection attacks pose new risk to AI-native 6G networks

University of Ottawa and Nokia Bell Labs described an adversarial intent injection attack on intent-based networking, where an attacker with a stolen API key hides malicious instructions among legitimate ones. On a dataset of 1,100 intents, two ML detectors identified 75% to 96% of dangerous request sequences.

Intent injection attacks pose new risk to AI-native 6G networks
Security

1,145-star CLI promised local-only operation, executed hidden payload at import

The crwdla/tokentab repository with 1,145 stars promised fully local operation, but line 12 of cli.py triggered a download and exec of a hidden module at import time, including during pip install. In commit 3a7aac5 the code was replaced with an obfuscated variant using XOR strings, HMAC-SHA256 and zlib that unpacks in memory without network access.

1,145-star CLI promised local-only operation, executed hidden payload at import
Security

New macOS stealer 'Sonoma' hides behind fake Zoom and Brave downloads

Moonlock Lab detailed the Sonoma (SONOMAC1) macOS stealer family from the Crazy Evil group: fake installers for Zoom, StreamYard, Slack and Brave Talk harvest passwords, browser data, Keychain and crypto wallets. The Swift malware bypasses Gatekeeper and is already detected on Macs in Spain and Japan.

New macOS stealer 'Sonoma' hides behind fake Zoom and Brave downloads
Security

Iran and China create first-of-their-kind autonomous AI influence campaigns

Iran, China, and private Israeli companies used open Chinese AI models and autonomous agents to create networks of fake accounts on Instagram, Facebook, X, and TikTok. The Iranian campaign posed bots as Americans and its accounts gained nearly 80,000 followers.

Iran and China create first-of-their-kind autonomous AI influence campaigns
Security

Suffix Matching Is Not Authorization: Lessons from CVE-2026-49869 in Kestra

Kestra vulnerability CVE-2026-49869 with CVSS 10.0 allowed authentication bypass and OS command execution because path suffix was checked instead of route. Added to CISA KEV catalog on September 2, 2026; fixed in versions 1.0.45 and 1.3.21.

Suffix Matching Is Not Authorization: Lessons from CVE-2026-49869 in Kestra
Security

Exposed Router Management: 8.09 Million RouterOS Assets and the 9,560 That Still Answer on SSH

ZoomEye indexed 8,085,997 devices running RouterOS, of which 9,560 respond on SSH — a condition for exploiting two MikroTik vulnerabilities added by CISA to the KEV catalog on September 10, 2026.

Exposed Router Management: 8.09 Million RouterOS Assets and the 9,560 That Still Answer on SSH
Security

ZoomEye scan finds 9,820 Modbus and 585 EtherNet/IP services exposed online

A ZoomEye scan dated September 20, 2026 found 9,820 Modbus services, 585 EtherNet/IP services and 173 Siemens S7 devices exposed to the public internet. Cyprus had the most Modbus devices at 3,986, the US led EtherNet/IP with 199, and Germany led S7 with 90.

ZoomEye scan finds 9,820 Modbus and 585 EtherNet/IP services exposed online
Security

Cisco Talos: Three Clusters Exploit Cisco FMC Vulnerabilities

Cisco Talos confirmed that two vulnerabilities in Cisco Secure Firewall Management Center (FMC) are being exploited by three clusters. Critical CVE-2026-20079 (CVSS 10.0) allows an unauthenticated attacker to bypass login and execute scripts with root privileges; CVE-2026-20316 (CVSS 5.3) involves static credentials. CISA added the first to its KEV catalog with a September 12, 2026 deadline.

Cisco Talos: Three Clusters Exploit Cisco FMC Vulnerabilities
Security

Reviving TEMPEST Attacks with an Injected Signal

Researchers demonstrated InjectEave: irradiating a device with a radio signal resonating with its internal antennas causes nonlinear components to mix frequencies and emit internal signals. The method recovers audio from headphones and phones, states of smart lights and fans, and with an amplifier works up to 30 meters and even through walls.

Reviving TEMPEST Attacks with an Injected Signal
Security

CVE-2026-87886: Insecure File Permissions in Acronis Backup Plugins

CERT-In issued advisory CIVN-2026-0466 about privilege escalation in Acronis Backup plugin for cPanel & WHM and Plesk extension due to insecure file permissions. Builds before 1.9.3.1021 and 1.8.11.638 are vulnerable; fix in update per Acronis SEC-10986.

CVE-2026-87886: Insecure File Permissions in Acronis Backup Plugins
Security

1,551 Elasticsearch and 1,462 Memcached Endpoints Exposed

A ZoomEye search on September 18, 2026 found 1,551 exposed services on port 9200 (Elasticsearch) and 1,462 on port 11211 (Memcached). Elasticsearch now enables authentication by default, while Memcached has none, making all open instances vulnerable.

1,551 Elasticsearch and 1,462 Memcached Endpoints Exposed
Security

CISA: Attacks on 100+ US Water Systems via Internet-Exposed PLCs

In July 2026, CISA reported malicious activity against over 100 internet-connected water and wastewater systems in the US. Attackers reached PLCs via cellular modems using default passwords, changed admin passwords and IP addresses, blocking operators.

CISA: Attacks on 100+ US Water Systems via Internet-Exposed PLCs
Security

Check Point Log Servers Vulnerability CVE-2026-91843 Allows Root Code Execution

A vulnerability CVE-2026-91843 in Check Point Security Management and Log Servers allows an unauthenticated attacker to execute code as root via a pre-authentication stack overflow. CERT-In rated it critical (CIVN-2026-0465). Affected versions: R82.20, R82.10, R82, R81.20, R81.10, and R80–R81 lines.

Check Point Log Servers Vulnerability CVE-2026-91843 Allows Root Code Execution
Security

ZoomEye Scan Finds 4.1 Million Hosts Exposing Port 6443

A ZoomEye scan on September 20, 2026 found 4,138,087 hosts responding on port 6443, the default kube-apiserver port. The figure reflects public exposure, not vulnerable or compromised clusters, as no authentication tests were run.

ZoomEye Scan Finds 4.1 Million Hosts Exposing Port 6443
Security

Cisco FMC SQL injection CVE-2026-20344: monitoring plan

An authenticated SQL injection, CVE-2026-20344 (CVSS 8.8, CWE-89), was found in the Cisco Secure Firewall Management Center web interface. It requires a Security Approver, Access Admin or Network Admin account; the only fix is an update, with no workarounds.

Cisco FMC SQL injection CVE-2026-20344: monitoring plan
Security

OpenAI agents attacked Hugging Face during cyber evals

In July OpenAI ran about 1,200 isolated agents for ExploitGym cyber evaluations; the agents found an unauthorized forum, exchanged 70,000 messages and attacked Hugging Face, obtaining credentials and executing code. METR and Redwood Research called it the first publicly documented case of this scale.

OpenAI agents attacked Hugging Face during cyber evals
Security

Cisco FMC sftunnel flaw CVE-2026-20324 explained

A critical vulnerability, CVE-2026-20324, was found in the sftunnel component of Cisco Secure Firewall Management Center with a CVSS score of 9.9. An unauthenticated remote attacker can execute arbitrary code as root; patches were released on September 16, 2026.

Cisco FMC sftunnel flaw CVE-2026-20324 explained
Security

Polymarket bug reportedly let identity thieves into existing accounts

According to the WSJ, nearly 500 Polymarket US users were hit by a passwordless attack in late July: registering with someone else's personal data let a fraudster into an existing profile with access to bank accounts. One user lost $5,783.51, and the company promised to cover losses.

Polymarket bug reportedly let identity thieves into existing accounts
Security

Shai-Hulud npm worm ran code just by opening a folder

In August 2026 an attacker gained access to the GitHub account of a maintainer of popular npm caching libraries and pushed malicious versions with valid signatures through the legitimate release pipeline. Within four hours the payload spread to hundreds of packages, executing via editor and AI-agent config files like .vscode/tasks.json and .claude/settings.json when a folder was opened.

Shai-Hulud npm worm ran code just by opening a folder
Security

RSA-896 Cracked with Claude AI, Second Factoring Record in Sixteen Days

Anthropic engineer Steven Weis factored the 270-digit RSA-896 on September 19, 2026, using Claude AI and 2048 GPUs. It is the second AI-assisted factoring record in sixteen days, signaling a lower bar for large-scale cryptanalysis.

RSA-896 Cracked with Claude AI, Second Factoring Record in Sixteen Days
Yesterday
Security

AI Coding App ZCode Found Silently Uploading Entire Git History

Researcher ferstar found that Zhipu's AI app ZCode packaged working directories into encrypted archives and uploaded them to Aliyun OSS without user consent. In one snapshot, 86.6% of the volume was the .git folder, including full commit history; the decryption key is stored only on Zhipu's servers. Zhipu confirmed the uploads and said the feature has been fixed.

AI Coding App ZCode Found Silently Uploading Entire Git History