F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code. BIG-IP APM is a centralized access management and security proxy that allows users to connect to enterprise networks, applications, APIs, and cloud services via a single login. The flaw, tracked as CVE-2026-94127, is a heap-based buffer overflow that affects BIG-IP APM systems configured as an OAuth Authorization Server, with an access policy and OAuth profile on the same virtual server. It received a critical 9.3 CVSS v4.0 score - so patch now. “We have learned that this vulnerability has been exploited,” F5 said in a Tuesday security advisory. F5 did not immediately respond to our questions, including how many systems have been compromised, and whether criminals are abusing the vulnerability to deploy ransomware. Also on Tuesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, and gave federal agencies a Friday deadline to apply patches. This warning comes about a year after F5 and CISA warned “highly sophisticated nation-state" hackers broke into the vendor’s network and stole BIG-IP source code, zero-day vulnerability details, and customer configuration data belonging to some users. The attack posed an "imminent risk" to federal agencies, US cybersecurity officials said at the time. The US Justice Department allowed F5 to delay disclosing the intrusion after determining that delayed public disclosure was warranted. This only happens if public disclosure poses a substantial risk to national security or public safety. Neither the feds nor private researchers have publicly attributed the intrusion to a particular group or country, but a year earlier Google's Mandiant threat hunters linked exploitation of the critical F5 BIG-IP flaw CVE-2023-46747 to UNC5174, an access broker it assessed with moderate confidence as operating from China. The group attempted to sell access to US defense contractor appliances and UK government entities.®
Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew's leak page. One Reddit user, a self-described nursing student, highlighted the issue on September 22, posting a screenshot of LAPSUS$’s leak site after trying to access “homework and textbooks.” “Every time I try to open the Elsevier website, I am met with this,” they wrote. “Anyone know anything or have any explanation? Totally creepy.” Amsterdam-based Elsevier told The Register it was briefly compromised following an attack Monday, but played down the wider impact. “On September 21, Elsevier identified that visitors to select platforms were being redirected to a third-party page,” a spokesperson said. “Our cybersecurity team responded immediately, resolving the issue and restoring normal service. “Our investigation indicates that this was a narrowly scoped, limited-duration event involving the temporary redirection of traffic for certain web properties. There is no indication that core platforms, customer data, research content, or operational systems were compromised.” Elsevier did not respond to additional questions related to the specific platforms that were affected or for how long LAPSUS$’ redirect was in place. The company is best known for its ScienceDirect platform, which hosts scientific, technical, and medical journal articles. It is also behind ClinicalKey, an AI-powered platform designed to provide medical professionals fast answers to care queries, and LeapSpace – an AI-assisted workspace for academic researchers. LAPSUS$, meanwhile, is better known for its criminal enterprises, namely big-name cyberattacks on the likes of Rockstar Games, which led to the earliest high-profile Grand Theft Auto VI leaks, and more recently, attacks on Adidas and GitHub. The online assault on Rockstar Games was part of a wider spree of crimes carried out when the group was in its pomp between 2020 and 2022. Other victims included BT, Microsoft, Okta, Samsung, and Vodafone, which in turn stoked a concentrated law enforcement operation to disrupt the teenage criminals behind it. After a protracted break, the LAPSUS$ name returned in 2025, partnering with Scattered Spider and ShinyHunters in another string of cyberattacks affecting household names, before splitting up and activity dropping to a modest six attacks per month, according to SOCRadar. ®
The modern enterprise is a digital enterprise. From the back office to the factory floor, connected systems and digital services form the operational backbone on which all else depends. So when disruption hits, it can have a huge financial, reputational, productivity, and even compliance impact. This has raised observability to a board-level issue. "For a public company, a material cyber incident is a disclosure obligation. You're on a four-business-day clock from the moment you determine its material," explains NETSCOUT director of enterprise strategy, Jack Callahan. "So when you have a disruption, whether that's a cyber-attack, a DDoS attack, or someone pushing a bad update to the network, the first executive problem is the same: figuring out whether it’s material." With each technical team pointing fingers at each other, observability becomes the single source of truth that organizations need to identify root cause, accelerate resolution, and improve reliability. Yet in many enterprises, it’s not having the desired impact. The long-established data foundation of metrics, events, logs, and traces (MELT) can’t by itself keep pace with the complexity and scale of today’s digital infrastructure. Organizations have defaulted to gathering more data, increasing sampling, and extending retention. But they’re not getting better insight. “Executives who would expect to have a lot of data in front of them with which to make a decision don't always find that that data is as conclusive as they'd want it to be,” Callahan continues. “And therefore, they’re trusting their gut more than they’d expect, given how much they’re spending.” The costs of this observability debt are building. One study by NETSCOUT reveals that 81 percent of organizations believe insufficient data increases incident resolution time. Over two-fifths (42 percent) estimate downtime at $500,000 to$999,000 per hour. These costs are unsustainable, both economically and otherwise. To harness the power of autonomous AI in operations, organizations need a data foundation they can trust implicitly. This demands a fresh approach; economically viable and grounded in observability data that’s consistent, comprehensive, enriched, and real time. And delivered in a way that complements rather than replaces existing observability investments — extending the value of the platforms already embedded in the enterprise stack. Where visibility fails MELT data is still essential to observability. But it wasn’t designed for today’s complex, distributed and dynamic operations. Metrics explain that something has changed over time. Events surface when something changed. Logs tell teams that something happened at a specific time. But they don’t provide the context that explains what actually happened on a network and why. Traces come closest, as distributed tracing is built to follow a request across services. But a trace only shows what has been instrumented, which leaves it blind at un-instrumented components, third-party dependencies, and the infrastructure in between. And those are exactly where things tend to break down, meaning the context of what actually happened and why isn’t captured. Context essentially means being able to reconstruct a single, complete and ordered chain of events across different systems — including what kick-started an event, how it propagated, and what happened at each step. This is where MELT-only observability techniques often fail. Timestamps can be inconsistent across different systems. Identifiers might not be preserved across architectural boundaries. Sampling and aggregation remove vital detail needed for reconstruction. And data may be stored across different tools with incompatible schemas. Research reveals that 96 percent of organizations use metrics and logs, yet 82 percent report visibility gaps, and nearly all (96 percent) lack sufficient data to determine root cause during incidents. They tend to lose visibility where systems meet, such as between on-premises and cloud (58 percent), the edge (51 percent), or in service-to-service interactions (39 percent). AI sharpens the challenge These issues become more serious in an AI context. Organizations are already embracing AI-driven operations to improve efficiency, decision making and customer experiences. But when systems start operating autonomously, making decisions and taking action at machine speed, they need forensic-grade data with high-fidelity context to produce reliable outcomes. That means continuous, unsampled records that preserve system interactions across environments. Higher levels of autonomy demand higher levels of confidence in network data. But telemetry can lose fidelity through sampling and abstraction — common techniques used in MELT to manage high data volumes. The resulting incomplete and fragmented data can lead to false correlation, ambiguity over root cause, inconsistent outputs, and overconfidence in partial signals. “An agent is not going to apply human intelligence to troubleshoot an issue. It's going to make a decision based on the data it has,” says Callahan. “So if you are feeding it partial, or periodic, or sampled data, you're at risk of scaling that uncertainty really quickly.” It’s a challenge that many organizations are just waking up to. According to NETSCOUT, only 41 percent describe AI-assisted insights as “very or extremely consistent.” A similar share (38 percent) admits to lacking forensic-grade data to validate automated actions. Some 29 percent say they don’t have real-time visibility across environments, and 28 percent don’t fully trust automation output. Closing the observability gap A better approach would be to build observability around MELT data enriched to provide the context that IT teams need, but without the bloat that adds unsustainable extra cost. This starts with packet data: the authoritative record of what actually traversed the network. It provides visibility into the transactions, dependencies and interactions (human and machine-based) across the IT ecosystem. Using deep packet inspection (DPI) techniques, this visibility can be distilled into metadata that, added to MELT, produces what NETSCOUT calls “MELT+”. “Digital services become observable through the exchanges among their components. NETSCOUT Smart Data transforms those observed interactions into transaction-level evidence: whether communication succeeded, how the transaction performed, where delay or failure appeared, which services were affected and, when identity context is available, which users experienced the impact. That gives operations teams and AI systems a more complete and trustworthy basis for understanding what actually happened,” explains NETSCOUT field marketing manager , Steve Horneman. “Most telemetry describes the state of individual components. NETSCOUT observes the interactions among those components and creates meaning from them as the activity occurs. By extracting context early, from independently observed traffic rather than relying only on what individual systems report, we give operations platforms and AI a more consistent account of how a digital service actually behaved. That is the difference between collecting more telemetry and creating evidence that can support a confident decision.” One case illustrates the advantage of this approach. A product manufacturer found that wireless connectivity issues were causing automated guided vehicles (AGVs) to fail in its global facilities, costing the company $500,000 per hour in lost productivity. Outages were occurring roughly every three weeks. Existing robotics telemetry failed to find the root cause. But once NETSCOUT was pulled in, the source of the issue was pinpointed, and a proactive monitoring model adopted which detects AGV failures within seconds. Troubleshooting fell from hours to minutes, saving the company tens of millions of dollars annually. The benefits of MELT+ expand beyond outages and operational incidents to cybersecurity, Horneman continues. “The strategic value extends beyond observability. The same independently observed interaction evidence can support operational assurance at the enterprise perimeter, expose service-to-service behavior and potential lateral movement internally, and give operations, security, and AI systems a common evidentiary foundation. Instead of each team interpreting a different version of events, they can reason from the same observed reality,” he says. NETSCOUT calculates that organizations treating network traffic data as authoritative are nearly three times more likely to report that visibility gaps occur infrequently (50 percent vs.18 percent). It is this level of insight into what’s happening on the network that makes the same packet-derived intelligence valuable to forensic analysis teams. “Once an attacker has privilege on a host, the telemetry that host generates about itself is within reach,,” says Callahan. “Sophisticated attackers hide lateral movement exactly that way. What they can't do is go back and change the packets that already crossed the network. That's a higher level of veracity, and a more complete view.” When metadata is Smart Data NETSCOUT’s approach uses DPI to observe live, unsampled packets directly from the network and then convert it into high-fidelity metadata using Adaptive Service Intelligence (ASI). It’s designed to tackle the main challenges of traditional MELT: scale, efficiency, cost, and data richness. NETSCOUT observes traffic from strategic points in the network rather than monitoring each application or server, reducing telemetry volume, ingestion cost, and complexity. It analyzes and distills packet data into Smart Data, metadata generated at the point of capture, which reduces the volume that needs to be moved, stored or retained downstream. What customers get is an approach that is complementary to MELT but which is economically more sustainable, produces more complete, network-derived data, and which feeds into existing observability platforms to further reduce TCO. It also delivers what analyst firm Futurum describes as the critical foundation for autonomous AI operations. Data that captures verifiable network behavior and observed interactions rather than abstractions. Data that ensures comprehensive visibility regardless of whether individual applications have been instrumented, and a complete view without sampling gaps. And which is consistent across observability, security, and operations teams, while demonstrating sequence and causality across service boundaries. “MELT alone is not going to be a sufficient data foundation to run AIOps on,” says Callahan. “We're able to generate data with more of the context you need earlier in the process, and therefore richer data flows into your platforms.” Just getting started Despite the obvious benefits of MELT+ approaches, NETSCOUT data reveals that only 11 percent of organizations treat full-fidelity network data as authoritative. For CIOs keen to change that statistic, the first step is to evaluate their current observability data by five key criteria, as shared by NETSCOUT COO, Sanjay Munshi. It should be comprehensive; covering any cloud, service, app, network or vendor. It should be curated; with purpose-built feeds optimized for storage and cost. It must be credible in offering a verifiable chain of interactions showing how services, apps and users behave in context. It must be consistent across use cases. And it must provide continuous real-time insight into data in motion. “If you’ve been optimizing to reduce your MELT cost, what you’ve been doing is also reducing the context that your application teams and agents have. But you no longer have to sacrifice one in order to gain the other,” Callahan concludes. “If you’re worried about telemetry costs. If you're worried about having the data you need to make decisions in the moment or for compliance reporting. If you're trying to figure out how to move your AI pilots into production: we can strengthen what you are already doing in the platforms you use every day.” Sponsored by NETSCOUT
Ofcom has opened an investigation into whether Pornhub's Apple-based age checks are effective enough to keep children away from its adult content. The investigation will examine whether Pornhub owner Aylo complied with age assurance duties that came into force under the Online Safety Act (OSA) in July 2025. Pornhub introduced a new age assurance process for some UK users in May 2026, relying on signals supplied by Apple. The signals indicate that an iOS user may have completed Apple's age checks. Ofcom stressed that its investigation concerns how Aylo implemented and tested the resulting process, not how Apple operates its system. Aylo restricted Pornhub to new UK users on February 2 after arguing that the OSA had diverted visitors toward less regulated sites rather than protecting children. Existing users who had already verified their age retained access. The decision followed a steep decline in traffic: Pornhub's UK visits fell 47 percent shortly after the rules took effect and were reportedly down 77 percent by October. In May, Aylo partially reversed the restriction for eligible UK users who had confirmed their age through Apple. New users on Android, PCs, and other platforms remain locked out. The Register contacted Aylo for comment. "Online age checks are a vital protection to prevent children from encountering inappropriate or harmful material, including pornography," said George Lusty, director of enforcement at Ofcom. "We expect tech firms to ensure age checks are highly effective before introducing them. Anything less could leave children at risk." Ofcom will assess both the effectiveness of Pornhub's age assurance process and whether Aylo conducted sufficient testing and due diligence before deploying it. Services covered by the OSA must assess whether children are likely to access them. Ofcom says providers must revisit that assessment before making a significant change to their service or when evidence suggests their age checks have become less effective. Ofcom will gather evidence before deciding whether Aylo breached the OSA. If it provisionally finds a contravention, it must give the company an opportunity to respond before reaching a final decision. The regulator can close an investigation without further action or impose a fine of up to £18 million or 10 percent of qualifying worldwide revenue, whichever is greater. Ofcom can also order companies to remedy failures and, in serious cases of continuing noncompliance, ask a court to require third parties such as ISPs to restrict access to a service. Some failures involving information requests can expose senior managers to criminal liability. Ofcom under the cosh The watchdog has faced a battering in recent weeks, with senior politicians and other key officials criticizing its alleged inaction since the Online Safety Act's age assurance requirements kicked in last year. As part of the Lords Communications and Digital Committee's multi-day inquiry into the OSA's impact, Dame Rachel de Souza, England's Children's Commissioner, said earlier this month that children believe the legislation "has made absolutely no difference" in preventing access to online harms. De Souza further claimed that Ofcom had failed to bare its regulatory teeth and accused UK politicians of failing to give it sufficient power. Ofcom would argue the opposite, and did the following week. At a subsequent hearing, Ofcom enforcement director Suzanne Cater pointed to actions taken by the regulator against Telegram, TikTok, X, and other pornography companies. Cater also told peers that the regulator is gearing up to target larger companies now that many of the straightforward cases involving smaller companies are concluding. Cater and her colleagues nevertheless acknowledged limits to Ofcom's reach, particularly when companies operating from overseas have few UK assets against which fines can be enforced. ® Updated to add at 1430 UTC on September 23: Alex Kekesi, Pornhub’s veep of brand and community, speaking on behalf of Aylo, told The Register that Aylo believes Apple’s device-level age verification “offers one of the strongest and hardest to circumvent protections currently available for helping prevent minors from accessing age-inappropriate content.” Kekesi pointed to public statements made to media organizations after Apple announced the new iOS feature, noting that Ofcom viewed it as a measure that could protect children in a variety of contexts. She also noted that Ofcom has previously called for system-wide solutions to age assurance gioven that the efficacy of such measures are not uniform, and dependent on each platform’s individual implementation. “Given Aylo’s well-documented commitment to compliance and to the effective protection of minors, we continue to believe that Apple’s implementation presents an opportunity for constructive collaboration and for the UK to establish a meaningful precedent in advancing effective, privacy-preserving online safety,” she said. “Having experimented in multiple markets with multiple methods of age assurance, including in the UK, Aylo believes that Apple’s implementation is a pioneering approach for child safety that provides significantly stronger protection than any other age assurance method currently available in the UK market.” Kekesi added: “Aylo will cooperate fully with the investigation and looks forward to engaging with the case team.”
Every attack leaves a trail across the network, from initial reconnaissance to lateral movement and data exfiltration. That makes the network one of an organization’s richest sources of security intelligence. But visibility is only half the story. Because the network connects every user, device, application, and workload, it is also the natural place to verify identity, apply consistent policy, and contain suspicious activity close to its source. The result is faster detection, stronger enforcement, and a smaller blast radius. So, what does it take to make security an integral part of the network, and where should organizations begin? What is integrated network security? Integrated network security takes security functions that traditionally sat outside the network and embeds them directly into the network fabric to simplify and sharpen protection in the enterprise. Routers, switches, and access points become cybersecurity defenders that identify and prevent threats rather than simply routing and filtering traffic. What challenges does enterprise security face today? Enterprises face a gap as the network perimeter dissolves. The assets that used to reside inside the headquarters LAN have scattered everywhere, from the cloud through to edge-based equipment and on-premises servers. Bolting more security tools onto your infrastructure to protect those assets isn't sustainable. License costs increase, tools overlap and sometimes conflict with each other, or they leave non-obvious gaps through which attackers can pass. This fragmented approach to security also involves different teams working at different speeds. Coordination is slow and difficult, hindering the security effort and driving up costs. Why is integrating security into the network the answer? Unifying security and networking together offers several benefits: Standardization Building security directly into the network itself lets you encode a standard approach that works everywhere across the organization and covers everything that connects to the network, (so, in other words, everything you use). This means that you can apply the same policy across the entire network, maintaining them without worrying about fragmentation or policy drift. Agility Agility has become even more important in the AI era. Attackers now use this technology to move more quickly and at scale. Being able to implement and change policies centrally that ripple throughout the organization means that you can adapt to this fast-changing security landscape. Operating from a single source of truth also eliminates the need to stitch together insights from multiple sources. Simplification This "implement once run everywhere" capability lets you encode zero-trust principles into the foundation of the system. NIST has a standard for this - SP 800-207 - which promises protection at the asset level rather than the traditional and flawed "one authentication and you're in everywhere" VPN approach. Zero trust isn't so much an individual product as a complete security discipline, and it's hard to implement piecemeal using different solutions. Instead, putting it at the foundation of the network makes it more immediately and ubiquitously workable. Some zero-trust security measures also belong in the network. One example is micro-segmentation, which closes off parts of the network at a granular level to avoid lateral movement and limit the blast radius from any attack. Network-based security also supports robust security for other complex disciplines such as SASE and SD-WAN. Collaborative security Having a common fabric for networking and security enables network and security teams to work closely together. These teams have traditionally operated at a distance, and the gap between them has been valuable for attackers. The less daylight there is between these two functions, the more likely you are to stop intruders. How does AI fit into integrated network security? AI is important in two ways when integrating security into the network. First, AI has also become integrated into the network. Machine learning helps to spot patterns in network activity, using them as the feedstock for AIOps systems that predict problems and maintain network reliability and performance. AI has also proven itself to be a valuable security mechanism. That same pattern recognition and predictive capability enables AI to head off attacks before they become a problem. Using AI to support network and security teams enables them to do more with less by delegating routine work so that they can focus on more sophisticated work. Attackers are also using AI to augment their assaults on organizations. If you are behind the curve and don't use AI to help defend yourself, then you will find yourself on the back foot when it comes to preventing those attacks. Where do I begin integrating security into my network? Savvy partners have developed solutions that bake security directly into network equipment and which support hybrid environments to take security wherever your network goes. That includes built-in security capabilities like device profiling and NAC; centrally managed firewalls; and network-integrated AIOps that provide security teams with real-time information that can bolster security operations. Start by assessing your organization’s greatest source of risk, whether it’s expanding zero trust, supporting hybrid work, or defending against AI threats. There’s no right single place to begin but here are some options: Unified SASE provides secure access for users wherever they work, while simplifying both networking and security. Hybrid mesh firewalls offer consistent policies and enforcement across different network domains such as datacenters and cloud environments. Universal zero-trust network architectures support every identity, device, and workload. AIOps use AI to improve visibility, accelerate troubleshooting, and automate operations. These are different entry points into the same long-term architecture. Any and all of them will advance your journey to integrated native network security. Which you choose depends on the specific challenges of your business. Sponsored by HPE.
A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including stealing users’ credentials and cryptocurrency wallets. Once deployed, the malware does not require continued commands from a human operator, according to Cisco Talos, which describes it as, to its knowledge, the first publicly documented Windows implant to use this approach for command-and-control (C2). Talos discovered the binary with its new CAIRN (Cognitive Artifact Intelligence Research Network) toolkit for hunting, classifying, and tracking emerging AI-integrated malware, which the security shop also made available as an open source repository on Tuesday. While the threat hunters haven’t observed any in-the-wild deployment of CLOSEDQUORUM, they said that artifacts from the binary link the malware’s developer to postings that date back to 2025 on criminal forums related to carding. After deployment, the Go-based malware delegates its next action to a quorum of LLMs that vote on what it should do next. If the vote is tied, DeepSeek’s vote takes precedence, followed by Qwen, Mistral, and Gemini. “The session is closed; no humans are admitted,” Talos analyst Ryan Fetterman said on Tuesday. “Four models are queried in sequence, their independent verdicts tallied, and the binary acts, based on their judgment.” This type of “effort displacement,” which transfers a phase of the attack from a human operator to AI systems, can compound the speed and scale advantages of an intrusion by removing the human bottleneck, Fetterman added. “Human operators are bound by attention, working hours, and cognitive load,” he wrote in the Tuesday blog. “An AI system capable of executing a phase of the attack chain can continue when the operator is no longer watching. It does not go offline when the attacker sleeps.” The models’ decisions are limited to the pre-defined actions, and they must choose “ONLY executable decisions,” according to a system prompt that Talos’ researchers extracted from the binary. It tells each model: “You are an advanced malware strategist.” And then the models choose what the malware should do from these capability modules: Steal, which simultaneously runs commands to dump LSASS memory for Windows credentials, steal saved browser passwords across Google Chrome, Microsoft Edge, and Mozilla Firefox, and extract cryptocurrency wallet data including MetaMask, Exodus, and Ethereum. Inject generates shellcode and then uses process hollowing or Early Bird injection to execute malicious code. Persist establishes persistence on the infected device. Talos believes the developer provides each operator with a customized executable containing that operator’s Discord webhook and LLM API keys, which are injected at compile time. Stolen credentials land in the operator’s Discord channel and are AES-256-GCM encrypted with a daily rotating key that the operator derives from the message timestamp. According to Fetterman, the “most useful detection strategy” is to look at behavioral characteristics, not domain blocking. “Legitimate applications may contact DeepSeek, OpenRouter, Mistral, Gemini, or Discord independently,” he wrote. “Far fewer should contact several of them while also accessing LSASS, injecting into suspended processes, or creating WMI persistence.”®