chiprook

Cybersecurity News

September 16
Security

Citrix adds AI-powered browser activity analysis to SecurAccess

Citrix introduced Citrix Session Insights, an AI feature for Citrix SecurAccess with Chrome Enterprise. It records browser sessions of employees and autonomous AI agents, analyzes risky behavior, and suggests measures based on security policies.

Security

Hollard rejects hacking claim, points to MIP cyber breach

Insurer Hollard said its systems were not hacked, attributing claims by the hacker group The Gentlemen to a June attack on third-party provider MIP Holdings. MIP confirmed a data leak affecting clients of about 45 South African insurance companies via its Jira platform.

Hollard rejects hacking claim, points to MIP cyber breach
Security

Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

OPSWAT disclosed two zero-day vulnerabilities in TP-Link Tapo C200 cameras: CVE-2026-15315 allows authentication bypass via session replay and access to video and recordings, while CVE-2026-15316 causes denial of service. Both were fixed in firmware V5_1.4.6 on August 18; researchers are working on another critical flaw.

Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
Security

Runaway AI agent racks up $50,000 cloud bill in one hour

Mandiant's AI Risk and Resilience report describes an accounting AI agent that entered a loop and made over 15,000 expensive API calls in less than an hour, accumulating about $50,000 in cloud costs and disrupting work transactions. The report also notes prompt injection attacks, AI supply chain compromises, and the first confirmed case of an AI-developed zero-day.

Runaway AI agent racks up $50,000 cloud bill in one hour
Security

Rubrik gives customer AI agents access to protection and resilience data

Rubrik added MCP support so third-party AI agents (Claude, Copilot, and custom) can directly access Rubrik Security Cloud telemetry and trigger recovery and compliance workflows. It also launched Code Guardian, based on Claude Mythos 5, to analyze vulnerabilities on isolated code copies. Both features are in private preview.

Rubrik gives customer AI agents access to protection and resilience data
Security

BT Email users hit by barrage of unsolicited password reset PINs

BT Email customers report receiving hundreds or even over 1,000 unauthorized password reset PIN messages within minutes. BT says accounts are secure and is investigating the cause; one customer claims losing access to email and BT ID.

BT Email users hit by barrage of unsolicited password reset PINs
Security

Cyber threat detection vendors shift from MITRE to UK testing program

UK-based SE Labs has launched PIVOT, an independent testing program for cyber defense tools' resilience to hacker group attacks. Broadcom, CrowdStrike, Fortinet, Palo Alto Networks and Sophos are participating, with results expected in January 2027.

Cyber threat detection vendors shift from MITRE to UK testing program
Security

CVE-2026-48710 (BadHost): malformed Host header bypasses Starlette path authorization

A vulnerability CVE-2026-48710 (BadHost) was found in the ASGI framework Starlette (versions 0.8.3–1.0.0): a malformed Host header distorts request.url.path and bypasses path-prefix authorization checks. CISA added it to the exploited vulnerabilities catalog; the fix is Starlette 1.0.1.

CVE-2026-48710 (BadHost): malformed Host header bypasses Starlette path authorization
Security

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

Oracle released its September Critical Security Patch Update with 673 patches covering over 800 vulnerabilities, including 672 unique CVEs. More than 100 flaws are critical, and over 240 are remotely exploitable without authentication. The largest patch sets were for E-Business Suite (159) and Fusion Middleware (153).

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
Security

NIST and CISA finalize playbook to stop token theft and forgery

NIST and CISA published NIST IR 8587 with recommendations to protect tokens and assertions from forgery, theft, and abuse. The guide covers signing key management, token validation, lifetime and revocation, and responsibility sharing between cloud providers and their customers.

NIST and CISA finalize playbook to stop token theft and forgery
Security

CVE-2026-42167: ProFTPD mod_sql RCE and How to Analyze the Exploit-DB PoC

A public PoC for CVE-2026-42167 in the mod_sql extension of the ProFTPD server, with a CVSS score of 8.1, has been published on Exploit-DB. The exploit demonstrates a path from SQL injection to RCE after authentication when using PostgreSQL; the fix is ProFTPD 1.3.9a.

CVE-2026-42167: ProFTPD mod_sql RCE and How to Analyze the Exploit-DB PoC
Security

Cohesity Agent Resilience Lets Companies Roll Back AI Agents That Go Wrong

Cohesity released Agent Resilience, a Cohesity Data Cloud feature that backs up enterprise AI agent memory and configuration and allows rollback to a trusted state after a failure or prompt injection. AWS Bedrock agents are supported at launch, with general availability expected by the end of the year.

Cohesity Agent Resilience Lets Companies Roll Back AI Agents That Go Wrong
Security

Google fixes actively exploited Android zero-day on Pixel devices

Google released September patches for Pixel, fixing 110 vulnerabilities, including zero-day CVE-2026-58704 in the modem, which is already used in targeted attacks. The flaw allows privilege escalation over an adjacent network without user interaction.

Google fixes actively exploited Android zero-day on Pixel devices
Security

Valve now say your data is safe from the CEVA Logistics cyberattack

Valve said the cyberattack on CEVA Logistics in August affected only part of the logistics partner's systems. The order processing system for Steam hardware was not affected, and there are no traces of attackers accessing customer data.

Valve now say your data is safe from the CEVA Logistics cyberattack
Security

Gartner: AI tools like Mythos to cut CVE numbers in 2027

Gartner analyst Craig Lawson said at IT Symposium in Australia that AI tools like Anthropic's Mythos have already found most vulnerabilities in old codebases. He predicts 2027 will see the first decline in CVE numbers and severity, with companies conducting daily pen tests.

Gartner: AI tools like Mythos to cut CVE numbers in 2027
Security

DeepZero: Open-source hunting for vulnerable Windows drivers

The open-source engine DeepZero has been released, automating the search for exploitable Windows kernel drivers. It filters binaries by PE headers, IOCTL, and the loldrivers.io database, then analyzes the remainder via Ghidra, Semgrep, and a language model. The project author has already found several confirmed vulnerabilities in the Snappy Driver Installer corpus.

DeepZero: Open-source hunting for vulnerable Windows drivers
Security

Reasoning heist: stealing encrypted LLM thoughts from GPT-5, Claude & Gemini

A paper describes an attack on encrypted chain-of-thought blocks at OpenAI, Anthropic, and Google, using a weak 'oracle' model to decrypt the reasoning of strong models. Decrypting 10,000 traces cost about $720, and all three providers closed the main vulnerability before publication.

Reasoning heist: stealing encrypted LLM thoughts from GPT-5, Claude & Gemini
Security

Active exploitation attempts target WSO2 API Manager JWT bypass

A critical vulnerability CVE-2026-5430 (CVSS 9.8) in WSO2 API Manager allows bypassing JWT signature verification and forging admin tokens. According to watchTowr, the flaw is already actively exploited in real attacks and can lead to account takeover.

Active exploitation attempts target WSO2 API Manager JWT bypass
Security

Google to face questions over 500,000 fake Gmail IDs in India

Indian investigators arrested two people and are determining how 500,000 fake Gmail accounts were created, with the accounts using two-factor authentication. Questions may arise for Google.

Google to face questions over 500,000 fake Gmail IDs in India
Security

Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869

A critical vulnerability CVE-2026-49869 (CVSS 10.0) was found in Kestra OSS — authentication bypass via paths ending in /configs, escalating to remote code execution. The vulnerability was added to CISA's exploited catalog on September 2, 2026; fixes are in versions 1.0.45 and 1.3.21.

Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869
Security

Exposed PLCs in the Water Sector: What CISA's Alert Reveals About Internet-Facing OT

On July 30, 2026, CISA issued an alert about rising attacks on programmable logic controllers (PLCs) in the US water and wastewater sector. Attackers change passwords, locking out operators, and IP addresses, disabling devices; this led to boil-water notices and manual operations. The agency requires removing PLCs from the internet and using VPNs.

Exposed PLCs in the Water Sector: What CISA's Alert Reveals About Internet-Facing OT
Security

SonicWall SMA1000 Command Injection CVE-2026-83549 Chained to Root

SonicWall SMA1000 has an OS command injection CVE-2026-83549 (CVSS 7.8) in the AMC console. Chained with pre-auth SSRF CVE-2026-83548 (CVSS 10.0), it allows root. CISA added it to KEV on September 2, 2026; fixes released September 1 in builds 12.4.3-03526 and 12.5.0-02952.

SonicWall SMA1000 Command Injection CVE-2026-83549 Chained to Root
Security

Langflow CVE-2026-12944: Scanner Blocklist Gap Leads to Root Code Execution

Langflow OSS has a critical vulnerability CVE-2026-12944 (CVSS 9.6): the component scanner blocks subprocess but misses socket and urllib, allowing an authenticated user to execute code as root. Versions 1.0.0–1.10.0 are affected; fix is 1.10.3.

Langflow CVE-2026-12944: Scanner Blocklist Gap Leads to Root Code Execution
Security

AI Agent Found Admin Access to $13B Startup in 25 Minutes

Strix ran an autonomous AI pentest agent on *.baseten.co during a check of Baseten (valued at $13 billion). In 25 minutes, the agent found a live GitHub token basetenbot in a public Harbor registry, granting admin access to the main repository, GitOps repo flux-cd, and homebrew-tap. The token had been in Docker image build history since March 2023. Baseten revoked the token and closed access the same day.

AI Agent Found Admin Access to $13B Startup in 25 Minutes
Security

Cybersecurity experts claim AI leaders' apocalyptic hacking predictions are technically incoherent

Cybersecurity specialists told NBC News that AI leaders' alarming predictions about hacking attacks are technically incoherent and reveal a lack of knowledge of the subject. They say fundamental cybersecurity issues remain unaddressed.

Cybersecurity experts claim AI leaders' apocalyptic hacking predictions are technically incoherent
Security

Deleting a secret from your Docker image doesn't delete it from your build history

An autonomous hacking agent found a live GitHub admin token in a public Docker image from Baseten: the token from March 2023 persisted in the build history and in July 2026 still granted admin access to internal repositories. The secret was not in filesystem layers but in the image config — a RUN command exposed GITHUB_TOKEN in history[].created_by.

Deleting a secret from your Docker image doesn't delete it from your build history
Security

Cyber Op Targets South Korean Media & Automotive Sectors

Rapid7 linked North Korea (APT37) to attacks on South Korean media companies and automakers since early 2025. Attackers compromised HAProxy load balancers and deployed a Linux tool called TED for espionage; victims were not named.

Cyber Op Targets South Korean Media & Automotive Sectors
Security

Rubrik unveils Code Guardian using Anthropic's Claude Mythos 5 to red-team code

Rubrik announced Code Guardian, a service built around Anthropic's Claude Mythos 5 model that finds and verifies vulnerability chains in an isolated copy of a customer's code. The service detects multi-step attacks, confirms exploitability and creates Jira or GitHub tasks; a closed preview with selected partners is underway.

Rubrik unveils Code Guardian using Anthropic's Claude Mythos 5 to red-team code
Security

Hacker loses $7.73M to MEV bot in rsETH Safe module exploit

On September 15, 2026, an attacker found a vulnerability in a custom router module of a Gnosis Safe holding over $7.73 million in wrapped rsETH from Aave. The exploit was sent to the mempool, but MEV bot Yoink copied and executed the transaction first, with the attacker arriving an hour later for leftovers.

Hacker loses $7.73M to MEV bot in rsETH Safe module exploit
Security

Proof Launches Verifiable Digital Credential for Banking, Reusable Identity and AI Agents

Proof (formerly Notarize) released Verifiable Digital Credential, a portable digital ID that users verify once and reuse across financial institutions. General access opens September 15 via platform and API; US regulators clarified rules for such credentials in banks on September 8.

Proof Launches Verifiable Digital Credential for Banking, Reusable Identity and AI Agents