โŒ

Reading view

[$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking

RFC 8628's device authorization grant lets a TV or CLI "poll" for login on a second screen. On Google's implementation, the entire session was transferable across browsers, the authorization server never checked that the client_id and scope in the consent URL matched the ones the device_code was issued for, and prompt=none turned the whole thing into a one-click, invisible account takeover.

submitted by /u/swinglr
[link] [comments]
  •  

Weekly Update 512: IoT Lockout Fail

Weekly Update 512: IoT Lockout Fail

"Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloody good at 23:00 the other night after travelling 33 hours from Paris only to find the IoT doorlock batteries dead and the 9V "jump start" procedure completely failing! Eventually, the locksmith arrived and opened an old-school physical lock on another door in an alarmingly short time. So, lessons:

  1. Battery-powered locks suck and will eventually lock you out of your house
  2. Don't trust a fallback mechanism as rudimentary as "hold a 9V battery on some terminals"
  3. Always have an old school manual backup approach, AKA "a key"

As I say in the video, we do have other doors that have keys, and if it weren't for the complacency we developed, we would have had one of these accessible. But alas, we didn't. The path forward is to take a deep dive into Ubiquiti's Access ecosystem, which I've flagged in the past, and by pure coincidence, I already had a meeting lined up with them to discuss just this. So, the hardware is on the way, and I'll have something entirely new to play with in the coming weeks. Stay tuned!

Weekly Update 512: IoT Lockout Fail
Weekly Update 512: IoT Lockout Fail
Weekly Update 512: IoT Lockout Fail
Weekly Update 512: IoT Lockout Fail
  •  

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

A picture of a windows laptop in its updating stage, saying do not turn off the computer.

Nearly 60 of the bugs quashed in Julyโ€™s Patch Tuesday earned a โ€œcriticalโ€ severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.

Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include CVE-2026-56155 โ€” an Active Directory Federation Services bug โ€” and CVE-2026-56164, a Microsoft Sharepoint vulnerability.

CVE-2026-50661 is a security feature bypass in Windows BitLocker that could allow attackers to gain access to encrypted data if they have physical access to the device. Microsoft said this bug has been detailed publicly, but that it is not aware of any active exploitation.

In a blog post on July 9, Microsoft Executive Vice President Pavan Davuluri wrote that Windows users will notice โ€œa higher volume of security updates included in each security releaseโ€ as a result of AI aiding in the discovery of vulnerabilities.

โ€œThe pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis,โ€ Davuluri wrote.

Jack Bicer, director of vulnerability research at Action1, called attention to CVE-2026-48561, a remote code execution flaw in Microsoft Copilot (with a 9.6 CVSS threat score) that allows an unauthorized attacker to execute code over the network. Microsoft says an attacker could exploit this bug by hosting a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the site.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws. Microsoft has long labeled security bugs using its โ€œexploitability index,โ€ which is Redmondโ€™s best guess as to how likely it is that attackers will be able to figure out a reliable way to exploit a given vulnerability.

But Satnam Narang, senior staff research engineer at Tenable, argues that Microsoftโ€™s exploitability index needs to do a better job of shifting with the machine speed of discovery. For example, Microsoft originally gave this monthโ€™s SharePoint zero-day an exploitability rating of โ€œless likely,โ€ although the flaw was added to CISAโ€™s Known Exploited Vulnerabilities list on July 1.

โ€œAnthropicโ€™s Red Teamโ€™s own findings for known vulnerabilities (n-days) revealed how fragile this system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated โ€˜Exploitation Less Likelyโ€™ or โ€˜Exploitation Unlikely,'โ€ Narang said. โ€œWhat this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.โ€

Chris Goettl at Ivanti observed that the record patch numbers from Microsoft come as a number of other major software makers are increasing their patch cadence, including Adobe which announced today it is moving to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month (Adobe also cited AI for accelerating their patch cycles). Cisco, Mozilla and Oracle also are shipping updates more frequently, while Googleโ€™s patch batches in June 2026 totaled more than 900 security fixes, Goettl noted.

Backing up your Windows system and/or data is always a good idea before applying operating system updates. Given the volume of patches addressed this month it may be wise for end users to wait a few days before applying these fixes. Itโ€™s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

Further reading:

Action1โ€™s Patch Tuesday blog

Automoxโ€™s rundown

  •  

Enhancing IIoT Security Using Digital Twins in Industry

The AI research centre at Torrens University Australia has helped produce a review of 110 studies on digital twins and IIoT security.

What were the main takeaways? They have found that DTs are shifting away from passive monitoring to being a part of the defence architecture.

One of the biggest weak points they found was in legacy sensors with low bandwidth. In these situations, there is a lag before the digital twin reflects a real-world change, and that lag is where attacks tend to slip in.

Would be interested to hear your thoughts! Has anyone here dealt with that sync-gap problem on older hardware?

submitted by /u/TorrensUni
[link] [comments]
  •  

AXON Body camera 3 of 4 hardware reverse cracking output video๏ผ

Recently, I saw someone selling a well-known second-hand market in China. Except for some functions that need to be connected to networking, the 4th generation is used normally. However, because AXON is not in the Chinese market, most of them purchase the activated version from eBay and then reverse. Will such a problem lead to the body camera video of some American enterprises and some unpublished videos of the police will be leaked. Then he sells these body3 and 4th generations at prices ranging from 1,000 dollars and about 1,500 US dollars respectively, and gives a unique software to read and delete it. The question is whether it is feasible or not, but it is not fake to see the real shot.

submitted by /u/Thomas980130
[link] [comments]
  •  

ExporTheft: 11 "AI Chat Exporter" Chrome extensions upload full chat content on PDF export, while the store listing says "No uploads to external servers"

Family of 11 same-codebase extensions (ChatGPT/Claude/Gemini/etc), ~5.5k users on the main one. Sold as local-only: the store listing says "No uploads to external servers," "Everything processed locally," "No tracking or telemetry."

Observed in the tested version:

  • PDF export POSTs the full conversation to the developer's Cloud Run backend. A local renderer is bundled but only runs as a fallback.
  • Markdown/Text/JSON exports beacon title + source URL to /api/usage. The title is derived from your first message, so it can contain chat content.
  • Every request carries an X-Client-ID in chrome.storage.sync, so it follows you across machines.

Detection + full writeup: https://malext.io/reports/ExporTheft/

submitted by /u/Huge-Skirt-6990
[link] [comments]
  •  
โŒ