โŒ

Normal view

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

30 September 2026 at 15:24
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in anย advisoryย on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

30 September 2026 at 15:00
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared

Know Your Enemy: Browser-Based Attack Techniques in 2026

30 September 2026 at 11:58
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1.

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

30 September 2026 at 11:30
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accounts

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

30 September 2026 at 10:45
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud

More than half of UK businesses lack confidence in basic cyber skills

30 September 2026 at 10:04
More than half of UK businesses lack confidence in their ability to perform at least one basic cybersecurity task, according to the government's latest skills survey. The annual research found 57 percent of businesses reported a basic technical skills gap, up from 49 percent last year despite tighter national standards and repeated government warnings about cyber resilience. That equates to approximately 808,000 businesses whose cybersecurity leads were not confident in carrying out at least one of nine tasks, including storing data securely, configuring firewalls, and detecting and removing malware. The equivalent estimate last year was 699,000 businesses. The researchers cautioned that the increase might reflect greater awareness of organizations' security posture rather than an actual deterioration in their capabilities. Interviews suggested that recent high-profile breaches had prompted executives and boards to scrutinize cybersecurity more closely. Detecting and removing malware produced the largest reported skills gap: 38 percent of businesses, 47 percent of charities, and 23 percent of public sector organizations lacked confidence in performing the task. The public sector reported fewer problems than businesses and charities across all nine basic skills measured. Sam Thornton, COO at cybersecurity consultancy Bridewell, said the figures reflected the position of smaller businesses and charities, where cybersecurity is often "just one part of someone's wider role rather than a dedicated job." "Malware is evolving quickly, and AI is increasingly helping attackers produce faster variants which are harder to spot," he told The Register. "Keeping pace requires constant attention, which may be harder when the person responsible for security is also handling several other roles. "This could mean that personnel lean on greater use of AI tooling to support cyber defences, which in turn could induce further exposure to the organization where sufficient skill levels are needed to understand and interpret the output of such AI models." Matt Hull, veep of cyber intelligence and response at NCC Group, said limited resources were compounded by increasingly complex IT environments. "Businesses increasingly rely on cloud infrastructure, SaaS platforms, APIs, third parties and growing numbers of human and machine identities," he said. "These environments can change rapidly, making it much harder to apply security fundamentals consistently across the organization." Hull said the industry also has "a habit of chasing the latest shiny update," when in reality most problems arise when organizations overlook the fundamentals. "It's a bit like looking after your car. You can spend a fortune on the latest safety features and a brilliant sound system, but none of that helps much if your tyres are bald or you can't see through the windscreen." Other reported gaps included storing and transferring personal data securely, restricting which software could run, configuring firewalls, selecting secure device settings, enabling automatic updates, and creating user accounts securely. Charities reported the widest skills gap on most measures, although businesses were less confident about storing and transferring personal data securely. Although the public sector scored better than businesses and charities in this survey, its overall basic skills gap nearly doubled from 14 percent last year to 27 percent. That comes despite repeated warnings about weaknesses in government systems. In 2025, the National Audit Office found "significant" gaps and immature controls across most critical systems it examined. Incidents affecting the Legal Aid Agency, Foreign Office, British Library, and NHS supplier Synnovis have provided ample demonstrations of the potential consequences. Among the government's responses is the ยฃ210 million Cyber Action Plan, announced at the start of the year to strengthen central government systems and introduce mandatory security requirements. Operators of critical services can use the NCSC's Cyber Assessment Framework to assess their resilience, while smaller organizations can seek Cyber Essentials certification as a baseline. The Cyber Security and Resilience Bill, now making its way through the Lords, would impose additional requirements on operators of essential services and their suppliers. The bill is intended to replace the NIS Regulations 2018 but excludes central and local government. The UK government believes the Cyber Action Plan essentially holds the public sector to the same standard as those in scope of the new bill, but does so without any legal obligations. Thornton argued that tighter regulation was unlikely to close the skills gaps among small businesses and charities without practical support tailored to their limited resources. "When more than half of UK businesses lack confidence in the basics, and nearly half of those responsible for security don't feel equipped to handle an attack, we have an economy that is both easier to breach and slower to recover," he said. "A growing skills gap at the bottom of the supply chain weakens the UK's resilience as a whole. Tighter regulation will help protect critical infrastructure, but it's unlikely to improve the skills in smaller businesses and charities. "Closing the gap will need affordable, practical support for smaller organisations, whether through managed services, simpler tools or incentives from insurers, so that good baseline security becomes the default rather than something only larger firms can afford." ยฎ

How Israeli Checkpoints Choke Palestinian Life in the Occupied West Bank

30 September 2026 at 10:00
Lost time. Lost jobs. Lost friends. Lost family. Lost lives. Our joint investigation reveals the system that has divided the West Bank and measures what it cost people to move through it.

UK rail cops' ยฃ320K face-scanning spree nets zero matches

30 September 2026 at 08:30
British Transport Police (BTP) spent more than ยฃ320,000 putting half a million commuters through live facial recognition cameras, only for the system to identify precisely nobody it was looking for. Figures obtained by civil campaign group Liberty Investigates through Freedom of Information requests, and reported by The Guardian, show BTP's six-month trial scanned more than 500,000 faces at London railway stations and generated just one alert. That turned out to be a false positive, meaning the technology produced no correct matches and no arrests directly resulting from an LFR alert. The exercise wasn't exactly light on resources either. According to the figures, deployments swallowed almost 100 hours of police officers' time and cost more than ยฃ320,000. Privacy campaigners at Big Brother Watch told The Register the results would be funny if the implications weren't more serious. "The figures from the British Transport Police's live facial recognition pilot would be laughable, if they didn't have such troubling implications for our rights and freedoms," said Jasleen Chaggar, senior legal and policy officer at the campaign group. "Millions of Londoners use the city's stations every day and may have already found themselves caught in a digital police line-up, likely without even realizing." Then there's the small matter of what taxpayers got for their ยฃ320,000. "It's not fair to subject innocent people to intrusive identity checks during their commute, but it's even more insulting to waste almost 100 hours of officers' time and ยฃ320,000 of public money when it produces such meagre results," she said. "The pilot figures show that replacing officers with AI surveillance does not improve Londoners' safety and British Transport Police should drop their use of live facial recognition." But BTP isn't dropping it. In fact, the trial has been extended until November and expanded from Network Rail stations onto the London Underground. The system uses NEC's NeoFace M40 facial recognition tech, and cameras scan people passing through a designated area, comparing their faces against a police watchlist. When the software thinks it has spotted someone on that list, it generates an alert for an officer to review before deciding whether to stop the person. BTP says it cannot identify people who aren't on a watchlist and that it immediately deletes their biometric data. It also says deployments are intelligence-led and targeted at crime hotspots where officers believe "high harm offenders" are likely to pass through. That claim of a targeted approach isn't convincing everyone. Sarah Simms, senior policy officer at Privacy International, told The Register the results of the trial show just how many innocent passers-by can have their faces processed along the way. "We are deeply concerned by the results of the British Transport Police's live FRT trial. It reaffirms how invasive and disproportionate live facial recognition tech is and why it shouldn't be permitted. Thousands of people have their highly sensitive facial data processed in public spaces as they go about their daily lives, sometimes unknowingly. It also undermines claims of it being a targeted measure." Simms also pointed to the lack of legislation specifically governing the technology as BTP continues to expand its use. "What's further concerning is that they continue to extend these deployments when there is no specific legal framework in place to regulate facial recognition, which is essential to ensure there are restrictions and safeguards on its use to protect people's rights," she said. Those assurances haven't put the wider controversy around police facial recognition to bed. Earlier this year, UK police temporarily suspended deployments after independent testing raised concerns about racial bias at some operating thresholds. BTP's own experiment has produced a rather different problem so far: after scanning more than half a million faces, the only person its cameras picked out was the wrong one.ยฎ

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

30 September 2026 at 08:24
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

30 September 2026 at 08:09
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program,ย OpenSSL saidย on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way

Spectre bug is back, this time to haunt JIT engines

30 September 2026 at 07:01
The Spectre microarchitecture vulnerability has returned yet again, this time to vex just-in-time (JIT) engines that generate machine code for browsers, runtimes, and kernels. The vulnerability is found in many CPUs that use speculative execution, the process of executing code before it is called to boost performance. Researchers found speculative execution opens the door to side channel attacks through which secrets can be exposed or inferred. When news of that risk became known, chipmakers and OS developers scrambled to fix these vulnerabilities, which were referred to as Spectre and Meltdown. And since then, researchers have found two or three dozen variations, such as 2025's VMScape, one of several so-called "Spectre v2" attacks that attempt to exploit indirect branch prediction, where program control is passed indirectly by pointing to an address where the next instruction can be found rather than specifying the instruction itself. The attacker trains the branch predictor to execute speculatively to a chosen address in order to leak data about the microarchitecture state. Researchers from Vrije Universiteit in the Netherlands and Scuola Superiore Santโ€™Anna in Italy have revived Spectre in a form called Branch Target Reuse (BTR), which they describe as the first practical in-place Spectre v2 attack that attacks just-in-time (JIT) compilers. An in-place attack is confined to the victim's branch while an out-of-place attack relies on speculation directed toward a target on a different branch. The researchers โ€“ Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida โ€“ found that this novel Spectre form can be conjured from code left in JIT engines including Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey. "The key insight behind the attack is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets)," the authors explain. "In JIT engines, these stale targets can outlive the original code and later be reused when the code cache is repopulated, yielding a speculative execute-after-free primitive." The result is that an attacker can commandeer speculative control flow in a way that avoids some software defenses like FineIBT [PDF]. The authors showed they could exploit this flaw by designing two proof-of-concept exploits against an Intel-based Linux kernel that reveal the root password hash even with the constant binding defense provided by cBPF. The expected leakage rate is 5.7 KB/sec for Intel Raptor Cove chips and 5.4 KB/sec for Lion Cove. It's slow but enough for an unprivileged user to coax a sensitive password hash out of a vulnerable system. After the researchers disclosed their findings, Linux kernel developers and Oracle put mitigations in place. Two CVEs were assigned: CVE-2026-64507 and CVE-2026-64508. Mozilla, the researchers said, has opted to prioritize work on site isolation instead of addressing the issue directly. Strong mitigations like IBPB are said to be effective but add complexity and hinder performance. The Branch Target Reuse paper has been accepted for publication at the ACM Conference on Computer and Communications Security (CCS) 2026, which will be held November 15 through 19 in The Hague, Netherlands. ยฎ

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

30 September 2026 at 05:30
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler

Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed

OpenBao engineers at ControlPlane have chained 4 vulnerabilities to show how under certain conditions, an OpenBao or Vault server can be completely compromised from an unauthenticated position. This is only the second RCE ever found in the Vault codebase.

The exploit is highly plausible in real-world environments, requiring only an unauthenticated entry path and a defined Raft snapshot policy to trigger a complete server compromise.

If you are impacted, upgrade as soon as possible to OpenBao 2.6.3 or 2.7.0

While OpenBao is fully patched, HashiCorp Vault remains exposed as of writing. Unfortunately, IBM's unwillingness to coordinate a mutual disclosure policy means Vault users currently lack an official mitigation

submitted by /u/the_hypotenuse
[link] [comments]
โŒ