❌

Reading view

Trump Mobile customers' data dumped - and some never even received their gold device

If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the Trump-branded mobile biz and leaked data belonging to 3,615 people, including names, email addresses, phone numbers, home addresses, and order details. BYOD is a new ransomware-as-a-service operation, and Trump Mobile is only the third organization posted on its data-leak site. According to the group’s posted claim, after telling Trump Mobile that it had been breached, the wireless provider replied: “We have no team to handle this" and “Anyone who hacks them are a terrorist.” “Well unfortunately for them, all 3615 customers and their PII, alongside telecom details are now up for grabs,” the leak site says. “Feel free to take a gander at it yourself, don't be shy, we (and them) certainly aren't stopping you.” The hackers reportedly told International Cyber Digest that they first infected a Liberty Mobile employee with an infostealer, and then accessed Trump Mobile via the MVNO. BYOD claims to still have access to Trump Mobile’s systems, and told the publication that neither wireless provider used any form of multi-factor authentication. Neither the Trump Organization nor Liberty Mobile responded to The Register’s questions about the breach. The data dump doesn’t include any details about US President Donald Trump or his family members, according to Straight Arrow News, which first reported the breach and verified some customers’ information. This could mean that the Trump family doesn’t eat its own dogfood. The leak does, however, include personal information about Eric Brunnett, vice president and chief information officer for the Trump Organization. Brunnett’s LinkedIn profile says he oversees “all Information Technology and Information Security for all aspects of the Trump Organization.” Additionally, one customer contacted by Straight Arrow said he paid a $100 pre-order deposit last year for Trump Mobile’s flagship smartphone, the T1, but never received a gold-colored device. Another criminal group, EndZone, also claimed to have breached Trump Mobile and leaked a stolen dataset a week before BYOD’s post in what “appears to be the same original breach,” according to security sleuth Dominic Alvieri. These aren’t the fledgling mobile phone company's only security snafus. Before these two apparent breaches, a security researcher in May claimed he discovered a now-plugged website vulnerability that leaked Trump Mobile customers’ details. The individual behind the discovery, who goes by "Louis" and described himself as "just a nerd between jobs with too much time on my hands," previously told The Register that the website’s data could be scooped up with a simple POST request.®

  •  

Microsoft extends the Outlook naughty step with two more file types

Microsoft is adding two extra file types to its Outlook block list to strengthen security. The file types are .msix and .msixbundle, used for Windows application packages and bundles. The change affects New Outlook for Windows and Outlook on the Web in Exchange Online. By default, users of the affected clients will no longer be able to download or open attachments with these extensions, which is no bad thing because blindly installing a malicious .msix package could compromise a device. That said, although Microsoft noted that the file types were "infrequently used," there are legitimate reasons for their presence in emails. Administrators who need to permit these attachments can add the extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy before the rollout, scheduled for early to mid-November 2026. "This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments," Microsoft said. The Windows giant's application packaging system has come under fire over the years. Microsoft disabled the ms-appinstaller protocol handler by default in December 2023 after attackers abused it to distribute malware. The attachment block adds another layer of protection, unless administrators explicitly allow these file types. Other file types blocked by Outlook on the Web include .py Python files, .ps1 PowerShell files, and .cab files. It's a little surprising that it has taken until now for .msix and .msixbundle to be added to the list, considering the havoc malicious packages can wreak on a system. Renaming an attachment's extension or sending a download link may get around the attachment restriction, but neither makes the package safe. Persuading someone to download and install it remains a route for miscreants, even with Windows' other protections in place. ®

  •  

Teaching network intrusion in the funnest way possible

I wanted to share a project I’ve been working on that I’m super excited about:

Project RedTeam: Contract Offensive

There’s a free Demo that provides a tutorial and lets you play a few contracts (no time limit, play as much as you want). Some players are already pulling some serious hours in the demo!

At its core, this is a game about using MITRE ATT&CK adversarial techniques against procedurally generated networks. It's delivered in a gameplay loop that plays a lot like Balatro and other card based Roguelike games. In Project RedTeam, you need to earn money to pay off debts after every contract within a run. Earn money by completing objectives, side bounties, or executing exfiltration/ransom against targets- the choice on how to be profitable is always yours.

It's a challenging but fun and fast paced take on network-intrusion cybersecurity concepts. It's entertaining in a deliberately gamified way.

A goal of this project was to create a hacking game that is realistic enough to keep it meaningful as a tool to teach intrusion concepts and stages to anyone- but not be overcomplicated and slow-paced like most hacking games.

I've put a lot of thought into the design and dynamics of how to capture the core-loop of network intrusion and turn it into a game that's approachable. The design direction of this project is an outcome of having over a decade of training and experience in cybersecurity.

Feel free to AMA! I'm happy to answer any questions about the game and/or development process :)

Give the game a Wishlist on Steam or share this post if it's something you support and want to see further development on.

Project background: This was implemented over the past 3 months using a modern development workflow (yes, modern AI tools make this possible- I'm not hiding that fact!). That being said, this is by far the most complex software project I've built as a solo developer and it was not an easy or simple development task. There's a Steam Community with a Dev Blog for this game that provides more history/progress updates on the project.

Mods: This will be my only and last post here, since it is promotional. I just wanted to share this since there’s been very positive interest from similar subreddits.

submitted by /u/ProjectRedTeam
[link] [comments]
  •  

Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets

GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent tool was flagged earlier this year for being susceptible to indirect prompt injection. That's when a model ingests text from a source other than the user that directs it to take some action outside the scope of its intended function. This is more of the same, with a twist. According to security researchers at Adversa AI, GitHub Copilot CLI suffers from the same vulnerability identified in Grok two months ago: Cryptographic Context Injection (CCI). Imagine a GitHub Copilot CLI user is working on a project and running the agent in autopilot mode. In other agentic coding tools like Anthropic's Claude, that's the default, but it remains optional for GitHub Copilot CLI. Given that condition, the next requirement is for the CLI tool to read a web page with a malicious set of instructions that have been encrypted with a private key published on the same site. "Static guardrails read text; they do not run it," explained Rony Utevsky in a blog post provided to The Register. "CCI ships malicious instructions as strong ciphertext, along with the key material and an instruction to decrypt, and induces the agent to run that decryption in its own code execution runtime." Active content classifiers that might be reading ingested text as a model defense would miss the encrypted code, unlike encodings like base64 or substitution ciphers that can be undone because the model learned how to decode in training. The model lottery The attack chain goes like this: The user runs Copilot CLI and asks it to fetch a specific URL. The page contains encrypted content, decryption instructions calling for use of Python, and two possible decryption keys. The first key is fake. It's a template that the agent tries to build by reading targeted files from disk (e.g., the user's .env file). Those secrets then get added to the key string. The initial decryption is attempted with this phony key but fails. So the second key is tried, the decryption works, and the agent is presented with instructions to fetch another URL for more context – but that URL contains the harvested secrets and the network request transmits them to the attacker. This doesn't work all the time, however. It depends on the model, which isn't always obvious to the user. GitHub Copilot CLI currently uses either Microsoft's own model, mai-code-1.1-flash, which executed the full attack chain on 50 percent of attempts, or one of two OpenAI GPT-5.6 models, both of which refused the attack payload. Utevsky describes the situation as a model lottery. "On the paid account we tested, the vulnerable model was not the default and had to be selected by hand," said Utevsky. "But on an account with model selection left on Auto, the router assigned the vulnerable model on some sessions and a safe one on others, with no action by the user away from defaults. The user does not choose, and does not see, which model handled the session." Adversa says it reported the vulnerability through GitHub's bug bounty program on September 17, 2026, and GitHub's triage team validated the finding but declined to treat it as a vulnerability. A GitHub spokesperson said as much to The Register, arguing that the user's actions amounted to consent for what followed: "GitHub values the contributions of our security research community and is committed to investigating reported security issues. After investigating, we determined this requires a user to intentionally direct Copilot CLI to fetch attacker-controlled or untrusted content and confirm they want to trigger the action, and thus is not a product vulnerability. While this is not a security issue with the product itself, we are always looking for opportunities to improve our products." Adversa disagrees with that call and says the attack chain presently works as described. ®

  •  

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in

  •  

Asos app delivers a data leak threat instead of fast fashion

Asos customers have reported receiving a rogue app notification claiming the online clothing retailer's Snowflake instance has been compromised and threatening to leak data. The notification included a link to a Telegram channel named "Xuanye Wen Gateway" and addressed Asos's data protection officer and IT team. "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," it says. The notification does not, by itself, establish that the sender accessed Asos's Snowflake instance or sensitive customer data. How the message was sent remains unclear. Asos's share price fell by around 12 percent following reports of the notification, although it has recovered slightly since. Several hours after publication, an Asos spokesperson confirmed the attack and claimed it had limited impact, telling The Register, "Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted. Our website and app are operating as normal, with no current disruption to any aspects of our operations." The spox added, "The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading." Snowflake did not immediately return a request for comment. Customers of Snowflake, a cloud platform for storing and analyzing data, were targeted in a major data theft campaign in 2024, including Ticketmaster, Santander, AT&T, and dozens of others. Connor Riley Moucka, 26, of Kitchener, Ontario, later pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges over a hacking spree that compromised more than 165 organizations, exposed billions of customer records, and brought in about $2.5 million in ransom payments. Snowflake subsequently introduced controls allowing administrators to require multi-factor authentication. A Snowflake spokesperson said: "At this time, we can report that we have found no compromise of the Snowflake platform. We take customer privacy and security very seriously. The investigation is ongoing and we will provide further updates as soon as more information becomes available." ® Updated Oct 6 at 1742 UTC: To add Asos' confirmation of the attack and comment. Updated October 7 0845 UTC: To add Snowflake's statement.

  •  

Denmark's ID register spills more people's details than the country has residents

An unauthorized party abused a private Danish company's legitimate access to the country's Central Population Register (CPR), exposing names, addresses, identification numbers, and other personal information about approximately 8.8 million people. The CPR administration said in a statement [PDF] that it became aware on October 2 of irregular activity during September and established the scale of the breach over the weekend. In a TV interview last night, digitization minister Christina Egelund said it was too soon to say whether the country would issue all-new CPR numbers, one of the solutions proposed following the breach. Danish cybersecurity specialist Jan Kaastrup told TV 2 that treating CPR numbers as secrets was a "broken" approach and argued that a number alone should not be accepted as proof of identity. "We live in a digitalized society, and therefore we should have much better identification systems," he said. Egelund described the company whose access was abused as "small." Private businesses can obtain CPR data under section 38(1) of the Danish Civil Registration System Act, subject to restrictions set out in the ministry's access terms [PDF]. Eligible recipients include companies, foundations, other legal entities, and individuals conducting business. However, access concerns a defined group of people identified individually in advance, and recipients must be legally entitled to process the information under the GDPR and Danish data protection law. The Register asked the ministry why such broad access was given. CPR numbers underpin access to public services and many everyday transactions in Denmark, which has a population of around 6 million people. The database includes the information of over 55,000 people living in Greenland who also use CPR numbers for healthcare, tax services, and banking. The ministry said the register contains approximately 11 million records, including people who have died or moved abroad, which explains why the affected total exceeds Denmark's current population. The ministry also noted that names and addresses of persons who chose to register with name and address protection were not exposed. The CPR administration blocked the unnamed company's access and said it was working with specialists and relevant authorities to establish what happened. It has notified the Danish Data Protection Agency, and police are investigating. ®

  •  

Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,

  •  

Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security,  traced critical vulnerabilities in Anthropic's MCP

  •  

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are

  •  

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and

  •  

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​

  •  

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to

  •  

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.

  •  

Atlassian warns of critical file access flaw in its datacenter products

Atlassian has told its users to patch its datacenter products, pronto, to prevent attackers accessing their files. The Australian collaborationware company on Monday sent users an email that opens with the words “Action required” and points to a security bulletin that explains CVE-2026-21589. The 9.3-rated arbitrary file access vulnerability is present in the datacenter versions of its Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye products. Atlassian says the vulnerability “allows an unauthenticated attacker to access specific files within the web application root directory in affected versions.” That’s scary because Atlassian warns “In some configurations, there may be sensitive files present that increase your risk.” There’s also some good news in that attackers must know the exact filename and path to exploit the vulnerability, and the mess doesn’t allow anyone to see the contents of a directory. Another piece of good news is that Atlassian has updated its products – so users only need to find a change window in which to upgrade to a safe version of their software. Atlassian advised those who can’t patch ASAP to remove their instances from the internet, if possible. “Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action,” the company warned. Its advisory also includes mitigations and advice on how to determine if your instances need the fix. Users who made the move from datacenter products to the Atlassian cloud have nothing to do, as Atlassian fixed the flaws in its own SaaS. That state of affairs rather vindicates Atlassian’s 2020 decision to stop developing its low-end server products and require users to shift into its cloud, and last year’s sequel in which it decided to discontinue its datacenter software, too. Atlassian admitted it hasn’t made that migration easy, because it somehow released a lift and shift tool that was worse than an earlier version. In March 2026, Atlassian axed ten percent of staff. The company’s share price was on a year-long slide at the time, as pundits suggested it might fall victim to the SaaSPocalypse, a theory that AI would replace business software. The price of Atlassian scrip has tripled since then, suggesting investors are more confident the company’s plan to use AI to power workflows represents a moat LLMs cannot cross. ®

  •  

Security researcher claims they found KVM guest-host escape flaw

Linux KVM, the hypervisor favoured by hyperscale clouds, apparently has a full VM escape bug. That nasty news came from security researcher Paulos Yibelo, who on X shared a screenshot of a bug bounty award he won for discovering what he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!” The bug bounty Yibelo participated in is run by Vercel, a company that provides MicroVMs as sandboxes for AI agents to work inside. The company’s Sandbox uses Firecracker MicroVMs, a technology created by AWS, which relies on Linux KVM – the kernel level hypervisor in Linux. Vercel CEO Guillermo Rauch named KVM as the hypervisor identified by Yibelo. “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization,” he wrote. And that’s all the info that has made it into the public view at this time. The Register can find no chat on relevant mailing lists. We have asked Rauch and Yibelo for additional details. Hopefully, we don’t hear from either of them for days or weeks, for two reasons. One is that guest-host escapes are the nightmare virtualization scenario because they mean whoever runs a guest VM could take over an entire server, and perhaps gain the ability to control other guests. The other is that KVM is astoundingly prevalent: AWS and Google both use it to power their public clouds. Enterprise virtualization players Nutanix, HPE, and Proxmox also rely on KVM. And of course KVM is also in Firecracker, which is open source and could therefore be running in all sorts of places. Whatever Yibelo discovered therefore very much needs a responsible disclosure process, because if hints about the flaw emerge it could allow attackers to do a lot of damage. Once a fix is found, the next question is whether implementing it will require disruption or downtime. It’s possible to hot-patch KVM, and to migrate live VMs from vulnerable hosts to machines running a patched version of Linux. Hopefully those techniques will work. This might be the second nasty bug discovered in KVM this year, after the so-called Januscape flaw. Beyond the potential risks this bug created, observers have suggested the potential seriousness of the flaw means Yibelo’s reward should exceed the $50,000 available under Vercel’s bug bounty program. ®

  •  
❌