❌

Normal view

Apple patches CoreGraphics zero-day already exploited in targeted attacks

29 September 2026 at 14:30
Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen targets. The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple's framework for handling graphics across its operating systems. According to Apple's advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device. The fruity vendor said it addressed the problem with improved bounds checking, though the bug appears to have made it out into the wild before Apple could squash it. "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," the company said. As is customary when Cupertino encounters the sort of security bug somebody has apparently found useful, further details are thin on the ground. Apple didn't say who was targeted, how many people were affected, who was behind the attacks, or exactly how the vulnerability was being exploited. However, its choice of words suggests this wasn't a bug being exploited indiscriminately across the internet, and raises the possibility that it was used as part of a targeted spyware campaign. Meta Product Security reported CVE-2026-86950 to Apple, but neither Apple's advisory nor Meta has provided further technical details on how the flaw was discovered or the attacks in which it was allegedly used. The fix landed on Monday in iOS 26.7.1 and iPadOS 26.7.1. Apple lists affected devices receiving the update as the iPhone 11 and later, iPad Pro 12.9-inch (third generation and later), iPad Pro 11-inch (first generation and later), iPad Air (third generation and later), iPad (eighth generation and later), and iPad mini (fifth generation and later). Apple specifically says the attacks hit devices running versions of iOS before iOS 27, though it hasn't said exactly which older releases were targeted. The flaw adds another entry to Apple's growing collection of vulnerabilities caught being abused before users had a patch, with CVE-2026-86950 landing as the seventh zero-day fixed by the company this year. For anyone still running the affected releases, that leaves the usual less-than-thrilling security advice: install the update rather than waiting to find out exactly what an "extremely sophisticated attack" looks like. ®

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

29 September 2026 at 14:13
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

29 September 2026 at 13:45
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical

OpenAI benches GPT-6.1 Astra for overstepping the mark

29 September 2026 at 13:43
OpenAI has killed off the planned release of GPT-6.1 Astra after the model got better at doggedly pursuing tasks but worse at knowing when it should stop. The decision means the model won't get its planned October release after falling short of OpenAI's safety and alignment requirements. OpenAI confirmed the decision to The Register, saying its research and safety bosses ultimately decided this particular Astra was better left on the bench. The problem, according to the AI lab, was partly an awkward consequence of trying to make the model more useful. OpenAI had improved what it calls "model laziness," where an AI gives up or hands a task back to the user when it encounters an obstacle. GPT-6.1 Astra was better at pressing on, but that persistence came with a rather important catch: it wasn't as good at staying within the boundaries of what it had actually been authorized to do. “For anything regarding safety and alignment, there’s a trade off. You really do need to find what’s the right line between staying within scope, but also avoiding laziness in terms of how the model actually pursues tasks even when it hits friction,” Saachi Jain, head of safety systems at OpenAI, told The Register. “While [GPT-6.1 Astra] improved on axes such as model laziness, it didn't quite meet the bar in terms of staying within scope and authorization, and how it communicates back to the user about the type of work it's done.” Reg readers might be forgiven for thinking that OpenAI should improve its guardrails and security following previous mishaps. According to the Wall Street Journa, GPT-6.1 Astra showed higher levels of deception than its predecessor during testing, including not always accurately telling users what actions it had or hadn't taken. It also ran into problems with what OpenAI calls "scope authorization," at times pushing ahead without asking permission and reaching for external tools or services even when doing so might be unsafe. That's a troublesome combination for an agentic model programmed to get more done without a human hovering over it. An AI that stubbornly keeps working through a problem is handy right up until the problem it's working through is the boundary you put there to stop it. OpenAI told The Register that GPT-6.1 Astra performed worse than GPT-6 Astra on alignment evaluations, and said shelving it was part of its commitment to keep safety and alignment ahead of increasing capabilities. Astra is already capable enough to make those alignment problems worth watching. GPT-6 Astra, released earlier this month, was OpenAI's first broadly deployed model to reach the "Critical" cybersecurity threshold under its Preparedness Framework. Give it the right tools and access, OpenAI claims it can hunt down previously unknown security flaws and figure out how to exploit them without a human holding its hand. That capability came into sharper focus just a day before OpenAI's decision emerged, when the UK's AI Security Institute published research on Astra's knack for finding holes in software supply chains. Given 19 open source packages containing 45 previously disclosed vulnerabilities, the model found 41 of them and produced working exploits for 39. Dr Fuxiang Chen, from the University of Leicester's School of Computing and Mathematical Sciences, welcomed the decision to pause the model's release while the safety concerns are addressed. “AI is developing at remarkable speed, but we should not rush forward without fully understanding the risks,” he said. “Pausing when safety concerns arise is not anti-innovation. It is the responsible thing to do, giving us time to test these systems carefully and put effective safeguards in place. Developers, companies, governments, researchers, and users all have a role to play, because the decisions we make now will shape the future of AI.” OpenAI isn't abandoning Astra. The company told us more Astra models are coming, and other new inew models that have cleared its safety bar will arrive "very soon." For GPT-6.1 Astra, however, the bar proved high enough to keep it on the inside. “Of course we want to make sure our model development is safe no matter whether that’s in the company, or when we ship it to users. But when we ship it to users, we have an extremely high bar in terms of safety and alignment,” Jain claimed. ®

Former X-Force hackers chase the offensive cyber gold rush

29 September 2026 at 11:30
Two former leaders of IBM's X-Force Red team have launched RemoteThreat, an offensive cybersecurity startup backed by $7 million in pre-seed funding. CEO Chris Thompson and CTO Shawn Jones say the company's platform uses AI to plan, execute, and adapt offensive cyber operations, extending beyond the continuous penetration testing and vulnerability detection offered by other automated security tools. Thompson and Jones previously ran X-Force Red, where their team was hired to test nuclear power plants, critical infrastructure, and major banks. In May 2024, Thompson told The Register how X-Force used AI to break into a semiconductor manufacturer's network in eight hours. The pair subsequently created Offensive AI Con, an invitation-only research event whose second edition is scheduled for early October. "We're looking at how noisy but very capable frontier models are right now, and we started to think: What happens when they can do what we can do as one of the best groups of red-teamers in the world?" Thompson told The Register in an interview. He said the concern was that AI could produce custom malware approaching the quality used by state-sponsored attackers, then deploy it at unprecedented speed and scale. RemoteThreat's 15 employees include senior operators, security researchers, engineers, and malware developers from X-Force Adversary Services, Mandiant, SpecterOps, Dreadnode, Bugcrowd, Microsoft, defense contractors, and government agencies. RemoteThreat says its platform gives defenders and government operators access to the same speed and scale that AI may offer their adversaries. According to the startup, its customers already include a major bank, a securities exchange operator, a large US healthcare company, and a leading AI lab. "We're focused on preparing these Fortune 500 organizations to better simulate this nation-state level of attack," Thompson said. "And then on the flip side, provide the government with the tooling to target their adversaries as quickly as possible." RemoteThreat describes its platform as eight connected systems covering mission planning, command and control, implants, initial access, advanced attack capabilities, obfuscation, analysis, and AI-assisted operations. Given the obvious potential for misuse, RemoteThreat says access is restricted to vetted enterprises, defense contractors, and US government customers. The platform uses small, purpose-built models for some tasks. Customers can also connect models from OpenAI or Anthropic, or use an open-weight alternative, giving the chosen LLM access to what Thompson described as "1,000 tools that we've built from scratch." The platform can be operated by either humans or AI agents. Customers can "drive a lot of this testing from your Codex terminal instead of having to log into our website, for example," Thompson said. RemoteThreat says its capabilities can run within the complete platform or be integrated as components of partners' products. It has teamed up with Talon Defense, which supplies AI and cyber technology to national security, defense, and intelligence customers. RemoteThreat has also partnered with the Nakasone Group, the national security advisory firm founded by retired US Army Gen. Paul Nakasone, former director of the National Security Agency and commander of US Cyber Command. Nakasone is also a strategic adviser to the startup. The launch comes as Washington seeks a larger private-sector role in offensive cyber operations. The US Cyber Strategy published in March calls for closer cooperation with industry on defensive and offensive missions. An August presidential memorandum goes further, ordering the creation of a program through which vetted US companies may conduct cyber operations against foreign cybercrime groups under federal direction and oversight. RemoteThreat also says it has joined US Special Operations Command's Special Operations Forces Rapid Acquisition Consortium for Emerging Requirements, or SOF RACER, which provides a route for supplying capabilities to special operations forces. Thompson expects the government to make greater use of commercially developed offensive cyber products, both to support existing mission teams and to pursue cybercriminal groups. "It's a bit of a gold rush in this space because this is the first time, across every major program, the government is being pushed to work with the commercial sector," he said. RemoteThreat is positioning itself to supply the picks and shovels – albeit ones capable of breaking into somebody else's network. ®

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

29 September 2026 at 08:35
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the

APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1

29 September 2026 at 06:08

Posted by Apple Product Security via Fulldisclosure on Sep 28

APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1

macOS Sequoia 15.8.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149229.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: macOS Sequoia
Impact: Processing a maliciously crafted file may lead to arbitrary code...

APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1

29 September 2026 at 06:08

Posted by Apple Product Security via Fulldisclosure on Sep 28

APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1

macOS Tahoe 26.7.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149228.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: macOS Tahoe
Impact: Processing a maliciously crafted file may lead to arbitrary code...

APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1

29 September 2026 at 06:08

Posted by Apple Product Security via Fulldisclosure on Sep 28

APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1

iOS 26.7.1 and iPadOS 26.7.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149226.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

CoreGraphics
Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation
and later, iPad Pro...

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

29 September 2026 at 06:08
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and

OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

29 September 2026 at 05:12
OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall Street Journal. The move "marks a rare case of a major AI developer ditching a new release because of safety concerns," the news publication said.

OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot

29 September 2026 at 04:45
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions:

OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon

29 September 2026 at 02:13
OpenAI has detailed the extent of the dirty deeds its agents indulged in Down Under in a Tuesday blog post titled How we will do better for Australia, which addresses last week’s news that one of its models improperly accessed a website that stores data related to national health scheme Medicare. “Our models accessed Australian government websites in ways they were not authorised to,” the post opens. “We also should have handled our response better. We are sorry and working to do better in the future.” The post offers some new detail on the Medicare incident, saying that it involved “an experimental, internal-only OpenAI model that was not intended for public release and without the full set of safeguards used in our publicly available products.” OpenAI gave the model the job of researching government spending per person on medicines for skin conditions in one Australian state. “The model had difficulty obtaining that information, and it took actions that we had not authorised it to take,” OpenAI admitted. “In the course of looking for this information at Services Australia’s Medicare Statistics Reporting Service, it discovered a way to gain non-public access to the service. It then used this access to review technical system information and source code related to the service – all still with the objective of trying to find the information it was originally looking for.” The Register last week asked OpenAI if the company conducted the tests itself or used a partner. The company did not respond to our request. In another incident disclosed in the new post, the company’s bots visited the Australian Institute of Health and Welfare and tried, unsuccessfully, to bypass access controls. The agents were still able to retrieve statistics using third-party browsing and download services, including from the institute’s website. “The downloaded material appears to have been publicly available. There was no system compromise. Individual medical records were not accessed,” OpenAI wrote. The company didn’t report the incident because it “did not meet our disclosure thresholds because the way it was accessed seemed consistent with public access.” OpenAI changed its mind and notified the Institute on 24 September – the day Australia’s prime minister announced the Medicare incident. Another concerning incident took place at the State of Victoria’s Agency for Health Information, which OpenAI agents visited after they “discovered an exposed access key.” The agent used that key to “retrieve reporting configuration and aggregate survey statistics.” OpenAI has given itself a pass on this one, writing “The extent to which this information should have been accessible is unclear, and depends on VAHI’s access policies. Individual medical records or identifiable survey responses were not accessed.” A fourth incident revealed in the post saw OpenAI agents visit the State of New South Wales’ Bureau of Crime Statistics and Research and make API and website metadata requests using a public-facing research tool. OpenAI has promised it will “commit the resources needed to help affected agencies understand what happened and assess the impact” – whatever that means. It’s also donating credits for the Daybreak cyber-defense service and promised to “establish a taskforce with independent Australian expertise to develop practical policy recommendations for managing risks from increasingly capable AI agents.” That taskforce “will focus on improving notification processes, strengthening coordination between AI developers and government, and identifying measures to better protect government systems.” OpenAI wants the taskforce to deliver recommendations by the end of 2026. The post is very much of the “We’re sorry and we promise to do better in future” genre, pioneered by Meta and popular with entities that leak data or experience outages. The Register expects more of the same sentiments next week, when OpenAI’s Chief Strategy Officer, Jason Kwon, appears before the Australian Senate’s Joint Select Committee on Artificial Intelligence. “He will answer questions about what we know, how we responded, what steps we have taken, and how we will do better going forward,” OpenAI says. ®

JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

28 September 2026 at 20:30
The cyber criminal behind JadePuffer, the first known agentic ransomware infection reported over the summer, has also used stolen Azure identities to conduct destructive attacks on cloud storage and other resources, according to Microsoft. In July, Sysdig threat hunters uncovered JadePuffer, the first-ever documented agentic ransomware infection in which an LLM drove the entire extortion operation, from gaining initial access to compromising a production database server and destroying data. Now Redmond says that it has detected the same attacker, which it tracks as Storm-3168, up to new mischief. Over an 18-hour period in early June, Storm-3168 compromised two service principals and used these machine identities for “extensive Azure-focused resource destruction” and “cloud credential collection that could be used to facilitate future exfiltration,” researchers Yossi Weizman and Tushar Mudi wrote on Friday. The two compromised service principals belonged to the same cloud tenant. The crims used one of them to conduct reconnaissance and resource discovery, and the other to carry out destructive operations and credential collection. The Redmond researchers don’t know how Storm-3168 initially hijacked the service principals, but noted that an employee of the same organization previously exposed client IDs, client secrets, and tenant IDs in plaintext in a public GitHub issue. “Since the beginning of this year, we also observed repeated probing from Storm-3168 linked infrastructure against multiple Azure App services for different customers,” the duo wrote. The entire attack took about 18 hours, with the discovery piece lasting about 15 hours and 30 minutes. During this time, the compromised service principal collected detailed information about Azure Virtual Machines, subscriptions, resource groups, and resources, completing more than 300 successful read operations. “This breadth of activity would give the threat actor visibility across the organization’s Azure environment,” Weizman and Mudi wrote. About 90 minutes after the first machine identity began hoovering up Azure information, the second compromised service principal started its work, reading Azure VMs and resource groups across two subscriptions in just five seconds. According to Redmond, both of these service principals used Storm-3168 linked infrastructure, the same network fingerprint, and the user agent python-requests/2.34.2. About 16 hours after the initial target reads, the second service principal successfully discovered Azure App Service configuration stores - it was likely looking for exposed credentials, we’re told - and unsuccessfully attempted to find Azure OpenSearch resources. Seventy seconds after this, it also attempted a ListKey operation against a non-existent storage account. Then, the destruction began. During this part of the operation, the compromised service principal attempted more than 150 destructive or credential-stealing attempts in 35 minutes. The destructive activity only lasted about 7 minutes with the machine identity attempting to delete more than 100 Azure Storage accounts. Most of these were successful, although Azure resource locks and storage account-level deletion did block a few. Additionally, the attacker deleted an Azure Key Vault, Function App, App service plan, all of which belonged to the same resource group and likely supported the Function app. “The same service principal also attempted to delete multiple Azure SQL databases in parallel with the storage account deletions mentioned earlier, but every deletion attempt failed because it used an unsupported API version for the Azure SQL database resource type,” Weizman and Mudi wrote. About 28 minutes after the destruction ended, “the same service principal made an inventory request for Azure Storage Accounts and sent more than 30 successful ListKeys requests, asking ARM to return each storage account’s access keys,” they added. “These storage accounts included Azure Site Recovery related storage accounts.” Multiple unsuccessful deletion attempts were also made against Azure Site Recovery locks and Azure Backup protection locks protecting storage accounts. According to Microsoft, the destructive activity - deleting numerous Azure resources, while also targeting backup and recovery-related resources - seems to indicate that Storm-3168 was setting up a ransomware attack. “Taken together, the resource destruction, attempts to interfere with recovery mechanisms, and collection of credentials that could provide access to data are consistent with tactics that can support ransomware and extortion operations,” Weizman and Mudi wrote. However, no ransom note was ever sent. "We did not observe a ransom note or confirm successful data exfiltration in the activity described here," they wrote. ®

❌