❌

Normal view

Someone's attacking a critical 0-day RCE in F5 BIG-IP APM

23 September 2026 at 18:09
F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code. BIG-IP APM is a centralized access management and security proxy that allows users to connect to enterprise networks, applications, APIs, and cloud services via a single login. The flaw, tracked as CVE-2026-94127, is a heap-based buffer overflow that affects BIG-IP APM systems configured as an OAuth Authorization Server, with an access policy and OAuth profile on the same virtual server. It received a critical 9.3 CVSS v4.0 score - so patch now. “We have learned that this vulnerability has been exploited,” F5 said in a Tuesday security advisory. F5 did not immediately respond to our questions, including how many systems have been compromised, and whether criminals are abusing the vulnerability to deploy ransomware. Also on Tuesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, and gave federal agencies a Friday deadline to apply patches. This warning comes about a year after F5 and CISA warned “highly sophisticated nation-state" hackers broke into the vendor’s network and stole BIG-IP source code, zero-day vulnerability details, and customer configuration data belonging to some users. The attack posed an "imminent risk" to federal agencies, US cybersecurity officials said at the time. The US Justice Department allowed F5 to delay disclosing the intrusion after determining that delayed public disclosure was warranted. This only happens if public disclosure poses a substantial risk to national security or public safety. Neither the feds nor private researchers have publicly attributed the intrusion to a particular group or country, but a year earlier Google's Mandiant threat hunters linked exploitation of the critical F5 BIG-IP flaw CVE-2023-46747 to UNC5174, an access broker it assessed with moderate confidence as operating from China. The group attempted to sell access to US defense contractor appliances and UK government entities.®

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

23 September 2026 at 18:06
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/

Academic publisher Elsevier hit by LAPSUS$ redirect attack

23 September 2026 at 15:08
Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew's leak page. One Reddit user, a self-described nursing student, highlighted the issue on September 22, posting a screenshot of LAPSUS$’s leak site after trying to access “homework and textbooks.” “Every time I try to open the Elsevier website, I am met with this,” they wrote. “Anyone know anything or have any explanation? Totally creepy.” Amsterdam-based Elsevier told The Register it was briefly compromised following an attack Monday, but played down the wider impact. “On September 21, Elsevier identified that visitors to select platforms were being redirected to a third-party page,” a spokesperson said. “Our cybersecurity team responded immediately, resolving the issue and restoring normal service. “Our investigation indicates that this was a narrowly scoped, limited-duration event involving the temporary redirection of traffic for certain web properties. There is no indication that core platforms, customer data, research content, or operational systems were compromised.” Elsevier did not respond to additional questions related to the specific platforms that were affected or for how long LAPSUS$’ redirect was in place. The company is best known for its ScienceDirect platform, which hosts scientific, technical, and medical journal articles. It is also behind ClinicalKey, an AI-powered platform designed to provide medical professionals fast answers to care queries, and LeapSpace – an AI-assisted workspace for academic researchers. LAPSUS$, meanwhile, is better known for its criminal enterprises, namely big-name cyberattacks on the likes of Rockstar Games, which led to the earliest high-profile Grand Theft Auto VI leaks, and more recently, attacks on Adidas and GitHub. The online assault on Rockstar Games was part of a wider spree of crimes carried out when the group was in its pomp between 2020 and 2022. Other victims included BT, Microsoft, Okta, Samsung, and Vodafone, which in turn stoked a concentrated law enforcement operation to disrupt the teenage criminals behind it. After a protracted break, the LAPSUS$ name returned in 2025, partnering with Scattered Spider and ShinyHunters in another string of cyberattacks affecting household names, before splitting up and activity dropping to a modest six attacks per month, according to SOCRadar. ®

Closing the observability gap for the AI-ready enterprise

23 September 2026 at 15:00
The modern enterprise is a digital enterprise. From the back office to the factory floor, connected systems and digital services form the operational backbone on which all else depends. So when disruption hits, it can have a huge financial, reputational, productivity, and even compliance impact. This has raised observability to a board-level issue. "For a public company, a material cyber incident is a disclosure obligation. You're on a four-business-day clock from the moment you determine its material," explains NETSCOUT director of enterprise strategy, Jack Callahan. "So when you have a disruption, whether that's a cyber-attack, a DDoS attack, or someone pushing a bad update to the network, the first executive problem is the same: figuring out whether it’s material." With each technical team pointing fingers at each other, observability becomes the single source of truth that organizations need to identify root cause, accelerate resolution, and improve reliability. Yet in many enterprises, it’s not having the desired impact. The long-established data foundation of metrics, events, logs, and traces (MELT) can’t by itself keep pace with the complexity and scale of today’s digital infrastructure. Organizations have defaulted to gathering more data, increasing sampling, and extending retention. But they’re not getting better insight. “Executives who would expect to have a lot of data in front of them with which to make a decision don't always find that that data is as conclusive as they'd want it to be,” Callahan continues. “And therefore, they’re trusting their gut more than they’d expect, given how much they’re spending.” The costs of this observability debt are building. One study by NETSCOUT reveals that 81 percent of organizations believe insufficient data increases incident resolution time. Over two-fifths (42 percent) estimate downtime at $500,000 to$999,000 per hour. These costs are unsustainable, both economically and otherwise. To harness the power of autonomous AI in operations, organizations need a data foundation they can trust implicitly. This demands a fresh approach; economically viable and grounded in observability data that’s consistent, comprehensive, enriched, and real time. And delivered in a way that complements rather than replaces existing observability investments — extending the value of the platforms already embedded in the enterprise stack. Where visibility fails MELT data is still essential to observability. But it wasn’t designed for today’s complex, distributed and dynamic operations. Metrics explain that something has changed over time. Events surface when something changed. Logs tell teams that something happened at a specific time. But they don’t provide the context that explains what actually happened on a network and why. Traces come closest, as distributed tracing is built to follow a request across services. But a trace only shows what has been instrumented, which leaves it blind at un-instrumented components, third-party dependencies, and the infrastructure in between. And those are exactly where things tend to break down, meaning the context of what actually happened and why isn’t captured. Context essentially means being able to reconstruct a single, complete and ordered chain of events across different systems — including what kick-started an event, how it propagated, and what happened at each step. This is where MELT-only observability techniques often fail. Timestamps can be inconsistent across different systems. Identifiers might not be preserved across architectural boundaries. Sampling and aggregation remove vital detail needed for reconstruction. And data may be stored across different tools with incompatible schemas. Research reveals that 96 percent of organizations use metrics and logs, yet 82 percent report visibility gaps, and nearly all (96 percent) lack sufficient data to determine root cause during incidents. They tend to lose visibility where systems meet, such as between on-premises and cloud (58 percent), the edge (51 percent), or in service-to-service interactions (39 percent). AI sharpens the challenge These issues become more serious in an AI context. Organizations are already embracing AI-driven operations to improve efficiency, decision making and customer experiences. But when systems start operating autonomously, making decisions and taking action at machine speed, they need forensic-grade data with high-fidelity context to produce reliable outcomes. That means continuous, unsampled records that preserve system interactions across environments. Higher levels of autonomy demand higher levels of confidence in network data. But telemetry can lose fidelity through sampling and abstraction — common techniques used in MELT to manage high data volumes. The resulting incomplete and fragmented data can lead to false correlation, ambiguity over root cause, inconsistent outputs, and overconfidence in partial signals. “An agent is not going to apply human intelligence to troubleshoot an issue. It's going to make a decision based on the data it has,” says Callahan. “So if you are feeding it partial, or periodic, or sampled data, you're at risk of scaling that uncertainty really quickly.” It’s a challenge that many organizations are just waking up to. According to NETSCOUT, only 41 percent describe AI-assisted insights as “very or extremely consistent.” A similar share (38 percent) admits to lacking forensic-grade data to validate automated actions. Some 29 percent say they don’t have real-time visibility across environments, and 28 percent don’t fully trust automation output. Closing the observability gap A better approach would be to build observability around MELT data enriched to provide the context that IT teams need, but without the bloat that adds unsustainable extra cost. This starts with packet data: the authoritative record of what actually traversed the network. It provides visibility into the transactions, dependencies and interactions (human and machine-based) across the IT ecosystem. Using deep packet inspection (DPI) techniques, this visibility can be distilled into metadata that, added to MELT, produces what NETSCOUT calls “MELT+”. “Digital services become observable through the exchanges among their components. NETSCOUT Smart Data transforms those observed interactions into transaction-level evidence: whether communication succeeded, how the transaction performed, where delay or failure appeared, which services were affected and, when identity context is available, which users experienced the impact. That gives operations teams and AI systems a more complete and trustworthy basis for understanding what actually happened,” explains NETSCOUT field marketing manager , Steve Horneman. “Most telemetry describes the state of individual components. NETSCOUT observes the interactions among those components and creates meaning from them as the activity occurs. By extracting context early, from independently observed traffic rather than relying only on what individual systems report, we give operations platforms and AI a more consistent account of how a digital service actually behaved. That is the difference between collecting more telemetry and creating evidence that can support a confident decision.” One case illustrates the advantage of this approach. A product manufacturer found that wireless connectivity issues were causing automated guided vehicles (AGVs) to fail in its global facilities, costing the company $500,000 per hour in lost productivity. Outages were occurring roughly every three weeks. Existing robotics telemetry failed to find the root cause. But once NETSCOUT was pulled in, the source of the issue was pinpointed, and a proactive monitoring model adopted which detects AGV failures within seconds. Troubleshooting fell from hours to minutes, saving the company tens of millions of dollars annually. The benefits of MELT+ expand beyond outages and operational incidents to cybersecurity, Horneman continues. “The strategic value extends beyond observability. The same independently observed interaction evidence can support operational assurance at the enterprise perimeter, expose service-to-service behavior and potential lateral movement internally, and give operations, security, and AI systems a common evidentiary foundation. Instead of each team interpreting a different version of events, they can reason from the same observed reality,” he says. NETSCOUT calculates that organizations treating network traffic data as authoritative are nearly three times more likely to report that visibility gaps occur infrequently (50 percent vs.18 percent). It is this level of insight into what’s happening on the network that makes the same packet-derived intelligence valuable to forensic analysis teams. “Once an attacker has privilege on a host, the telemetry that host generates about itself is within reach,,” says Callahan. “Sophisticated attackers hide lateral movement exactly that way. What they can't do is go back and change the packets that already crossed the network. That's a higher level of veracity, and a more complete view.” When metadata is Smart Data NETSCOUT’s approach uses DPI to observe live, unsampled packets directly from the network and then convert it into high-fidelity metadata using Adaptive Service Intelligence (ASI). It’s designed to tackle the main challenges of traditional MELT: scale, efficiency, cost, and data richness. NETSCOUT observes traffic from strategic points in the network rather than monitoring each application or server, reducing telemetry volume, ingestion cost, and complexity. It analyzes and distills packet data into Smart Data, metadata generated at the point of capture, which reduces the volume that needs to be moved, stored or retained downstream. What customers get is an approach that is complementary to MELT but which is economically more sustainable, produces more complete, network-derived data, and which feeds into existing observability platforms to further reduce TCO. It also delivers what analyst firm Futurum describes as the critical foundation for autonomous AI operations. Data that captures verifiable network behavior and observed interactions rather than abstractions. Data that ensures comprehensive visibility regardless of whether individual applications have been instrumented, and a complete view without sampling gaps. And which is consistent across observability, security, and operations teams, while demonstrating sequence and causality across service boundaries. “MELT alone is not going to be a sufficient data foundation to run AIOps on,” says Callahan. “We're able to generate data with more of the context you need earlier in the process, and therefore richer data flows into your platforms.” Just getting started Despite the obvious benefits of MELT+ approaches, NETSCOUT data reveals that only 11 percent of organizations treat full-fidelity network data as authoritative. For CIOs keen to change that statistic, the first step is to evaluate their current observability data by five key criteria, as shared by NETSCOUT COO, Sanjay Munshi. It should be comprehensive; covering any cloud, service, app, network or vendor. It should be curated; with purpose-built feeds optimized for storage and cost. It must be credible in offering a verifiable chain of interactions showing how services, apps and users behave in context. It must be consistent across use cases. And it must provide continuous real-time insight into data in motion. “If you’ve been optimizing to reduce your MELT cost, what you’ve been doing is also reducing the context that your application teams and agents have. But you no longer have to sacrifice one in order to gain the other,” Callahan concludes. “If you’re worried about telemetry costs. If you're worried about having the data you need to make decisions in the moment or for compliance reporting. If you're trying to figure out how to move your AI pilots into production: we can strengthen what you are already doing in the platforms you use every day.” Sponsored by NETSCOUT

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

23 September 2026 at 16:53
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

23 September 2026 at 16:06
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

23 September 2026 at 14:17
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

23 September 2026 at 13:52
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions

Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw

23 September 2026 at 12:54
Meta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do “whatever” they wanted on a victim’s Mac, highlighting the inherent dangers of AI helpers.

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

23 September 2026 at 12:16
A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both,

British regulator takes a hard look at Pornhub's Apple-powered age checks

23 September 2026 at 11:53
Ofcom has opened an investigation into whether Pornhub's Apple-based age checks are effective enough to keep children away from its adult content. The investigation will examine whether Pornhub owner Aylo complied with age assurance duties that came into force under the Online Safety Act (OSA) in July 2025. Pornhub introduced a new age assurance process for some UK users in May 2026, relying on signals supplied by Apple. The signals indicate that an iOS user may have completed Apple's age checks. Ofcom stressed that its investigation concerns how Aylo implemented and tested the resulting process, not how Apple operates its system. Aylo restricted Pornhub to new UK users on February 2 after arguing that the OSA had diverted visitors toward less regulated sites rather than protecting children. Existing users who had already verified their age retained access. The decision followed a steep decline in traffic: Pornhub's UK visits fell 47 percent shortly after the rules took effect and were reportedly down 77 percent by October. In May, Aylo partially reversed the restriction for eligible UK users who had confirmed their age through Apple. New users on Android, PCs, and other platforms remain locked out. The Register contacted Aylo for comment. "Online age checks are a vital protection to prevent children from encountering inappropriate or harmful material, including pornography," said George Lusty, director of enforcement at Ofcom. "We expect tech firms to ensure age checks are highly effective before introducing them. Anything less could leave children at risk." Ofcom will assess both the effectiveness of Pornhub's age assurance process and whether Aylo conducted sufficient testing and due diligence before deploying it. Services covered by the OSA must assess whether children are likely to access them. Ofcom says providers must revisit that assessment before making a significant change to their service or when evidence suggests their age checks have become less effective. Ofcom will gather evidence before deciding whether Aylo breached the OSA. If it provisionally finds a contravention, it must give the company an opportunity to respond before reaching a final decision. The regulator can close an investigation without further action or impose a fine of up to £18 million or 10 percent of qualifying worldwide revenue, whichever is greater. Ofcom can also order companies to remedy failures and, in serious cases of continuing noncompliance, ask a court to require third parties such as ISPs to restrict access to a service. Some failures involving information requests can expose senior managers to criminal liability. Ofcom under the cosh The watchdog has faced a battering in recent weeks, with senior politicians and other key officials criticizing its alleged inaction since the Online Safety Act's age assurance requirements kicked in last year. As part of the Lords Communications and Digital Committee's multi-day inquiry into the OSA's impact, Dame Rachel de Souza, England's Children's Commissioner, said earlier this month that children believe the legislation "has made absolutely no difference" in preventing access to online harms. De Souza further claimed that Ofcom had failed to bare its regulatory teeth and accused UK politicians of failing to give it sufficient power. Ofcom would argue the opposite, and did the following week. At a subsequent hearing, Ofcom enforcement director Suzanne Cater pointed to actions taken by the regulator against Telegram, TikTok, X, and other pornography companies. Cater also told peers that the regulator is gearing up to target larger companies now that many of the straightforward cases involving smaller companies are concluding. Cater and her colleagues nevertheless acknowledged limits to Ofcom's reach, particularly when companies operating from overseas have few UK assets against which fines can be enforced. ® Updated to add at 1430 UTC on September 23: Alex Kekesi, Pornhub’s veep of brand and community, speaking on behalf of Aylo, told The Register that Aylo believes Apple’s device-level age verification “offers one of the strongest and hardest to circumvent protections currently available for helping prevent minors from accessing age-inappropriate content.” Kekesi pointed to public statements made to media organizations after Apple announced the new iOS feature, noting that Ofcom viewed it as a measure that could protect children in a variety of contexts. She also noted that Ofcom has previously called for system-wide solutions to age assurance gioven that the efficacy of such measures are not uniform, and dependent on each platform’s individual implementation. “Given Aylo’s well-documented commitment to compliance and to the effective protection of minors, we continue to believe that Apple’s implementation presents an opportunity for constructive collaboration and for the UK to establish a meaningful precedent in advancing effective, privacy-preserving online safety,” she said. “Having experimented in multiple markets with multiple methods of age assurance, including in the UK, Aylo believes that Apple’s implementation is a pioneering approach for child safety that provides significantly stronger protection than any other age assurance method currently available in the UK market.” Kekesi added: “Aylo will cooperate fully with the investigation and looks forward to engaging with the case team.”

545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent

23 September 2026 at 11:47
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security background then sits down and checks every claim against the target. Which findings are real,

Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests

23 September 2026 at 11:47
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands

Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

23 September 2026 at 11:12
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst 

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

23 September 2026 at 08:29
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.

❌