chiprook

Cybersecurity News

September 15
Security

Georgia Tech paper cuts quantum attack cost on elliptic curve encryption

Georgia Tech researchers published an algorithm that simultaneously reduces qubit count and circuit complexity for attacking P-256 and secp256k1. It is the first result compressing both hardware parameters at once, changing timelines for post-quantum migration.

Georgia Tech paper cuts quantum attack cost on elliptic curve encryption
Security

Human attacker exploits Marimo RCE, reaches SSH bastion in eight seconds

Sysdig described an attack in which an intruder went from exploiting an RCE flaw in a Marimo notebook to an SSH bastion in 8 seconds. The study shows experienced humans act no slower than AI agents.

Human attacker exploits Marimo RCE, reaches SSH bastion in eight seconds
Security

240,000 hit by data breach at Japan's Digital Agency

Japan's Digital Agency disclosed a personal data leak affecting about 240,000 people. Attackers accessed the Government Solution Service through a support employee's account by exploiting a VPN product flaw. More than 246,000 records with names, addresses, emails and phones were compromised.

240,000 hit by data breach at Japan's Digital Agency
Security

LG releases 2000-word statement to deny smart TVs spy on users

LG issued a 2000-word statement denying a Gamers Nexus report that its smart TVs record conversations and collect data on Wi-Fi and devices. The company claims recording only starts after voice control activation and audio is processed locally. The report's authors accused LG of lying.

LG releases 2000-word statement to deny smart TVs spy on users
Security

Post-quantum key exchange proved unsecurable in 1,700 queries

Five cryptographers proved that MQV-style lattice-based AKE protocols cannot achieve eCK security: two research schemes were broken in about 1,700 queries, and a hardened variant in 180 queries. Deployed systems based on the standardized NIST ML-KEM are not affected.

Post-quantum key exchange proved unsecurable in 1,700 queries
Security

GreyNoise details PaperCut campaign using hundreds of AI agents

GreyNoise described a campaign in which an attacker used hundreds of AI agents based on Codex and DeepSeek to exploit PaperCut NG/MF vulnerabilities. Since August 31, 2026, at least 440 PaperCut installations across 395 organizations in 48 countries were compromised, with credentials stolen from 280 victims.

GreyNoise details PaperCut campaign using hundreds of AI agents
Security

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

F5 Labs disclosed a mass-scanning campaign targeting Vite development servers exposed to the internet. Attackers steal AWS and Azure cloud credentials, configurations, and infrastructure state files.

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Security

Cisco Patches Actively Exploited Email Gateway Zero-Day (CVE-2026-76461)

Cisco confirmed active exploitation of a zero-day SQL injection, CVE-2026-76461, in Cisco Secure Email Gateway on AsyncOS 16.5, 16.0, and 15.5 and earlier. An unauthenticated attacker can execute arbitrary SQL code via an email and gain root access to the OS. CISA added the flaw to its exploited catalog and requires US federal agencies to fix it by September 17.

Cisco Patches Actively Exploited Email Gateway Zero-Day (CVE-2026-76461)
Security

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

Apple released iOS 27, iPadOS 27, and macOS Golden Gate 27 with a record number of patches: about 126 vulnerabilities in the mobile OSes and 210 in macOS, roughly 100 of them shared. iOS 26.7, macOS Tahoe 26.7, and Sequoia 15.8 also shipped. No signs of exploitation in the wild.

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
Security

Royal Navy drone cameras contained Chinese components, cyber test finds

Cyber testing revealed that Royal Navy drone cameras contained Chinese components that sent automatic heartbeat signals to an IP address in China. No MoD data leaks were confirmed; internet access for affected subsystems was disabled and vulnerabilities were closed.

Royal Navy drone cameras contained Chinese components, cyber test finds
Security

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

Volexity uncovered two China-linked groups, UTA0560 and JungleBamboo, which since September 1, 2026, used a single zero-day chain in Chrome (CVE-2026-85046) and Windows against NGOs. The patch was in Chromium source but not released to Chrome users, making the exploit zero-day.

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Security

Obsolete programs power 97% of US database systems, report finds

According to a Percona report, 97% of database administrators in the US run outdated software. The main barriers to upgrading are cost, with 31% citing cloud expenses, and migration complexity, which can carry more operational risk than running unsupported software.

Obsolete programs power 97% of US database systems, report finds
Security

Suspected Black Axe leaders extradited to US face cybercrime charges

Five suspected leaders of the cybercrime syndicate Black Axe were extradited to the US from South Africa. They are accused of advance-fee fraud and romance scams from 2011 to 2021; maximum penalty is up to 20 years for fraud and money laundering.

Suspected Black Axe leaders extradited to US face cybercrime charges
Security

Hacked HBO Reddit Account Used for Malware Delivery via ClickFix Attack

Hackers compromised HBO Max's official Reddit account and posted 108 malicious ads over 48 hours as part of the PasteSwitch campaign. macOS and Windows users were lured to a fake site hbomaxx.us, where ClickFix prompted them to paste a command into the terminal to install malware.

Hacked HBO Reddit Account Used for Malware Delivery via ClickFix Attack
Security

What the NetNut Takedown Reveals About Residential Proxy Sourcing

After the FBI and Google shut down the NetNut residential proxy network in July 2026, HackerNoon examines the market's structural problem: most providers resell others' IP pools without controlling their origin. A significant portion of NetNut's ~2 million devices turned out to be compromised consumer gadgets.

What the NetNut Takedown Reveals About Residential Proxy Sourcing
September 14
Security

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

WordPress is launching automated security analysis of every plugin release before publication in the WordPress.org update API. New plugins were already reviewed, but updates were released without checks.

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution