Sender spoofing in Proton Mail via display-name homograph
Proton Mail confirmed and paid for an email-spoofing bug, then left it unfixed for 16 months
[link] [comments]
Proton Mail confirmed and paid for an email-spoofing bug, then left it unfixed for 16 months

How's that view?! With NDC Oslo now done, it's a little bit of sightseeing before heading to Denmark for GOTO in Copenhagen for Scott's and my "Cyber-broken" talk. In the meantime, this week is mostly about the ShinyHunters trajectory targeting both Cl0p and the FBI, which does feel a little like a crescendo in their activities. Time will tell, but poking the feds in this way doesn't seem great for your longevity.
In my disorganised travel state, I also forgot to touch on a brand new sponsor for this week and the weeks to come: Origin. They build tooling to monitor what your AI agents are doing, which is obviously pretty timely given the current climate. They're running a free CISO briefing on 1 Oct, so go check that out if you think maybe your agents might need some oversight.
Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Sep 26
SEC Consult Vulnerability Lab Security Advisory < 20260923-0 >Posted by Matthias Deeg via Fulldisclosure on Sep 26
Advisory ID: SYSS-2026-071Posted by Matthias Deeg via Fulldisclosure on Sep 26
Advisory ID: SYSS-2026-070Posted by Matthias Deeg via Fulldisclosure on Sep 26
Advisory ID: SYSS-2026-069Posted by Matthias Deeg via Fulldisclosure on Sep 26
Advisory ID: SYSS-2026-068Posted by Matthias Deeg via Fulldisclosure on Sep 26
Advisory ID: SYSS-2026-067Posted by Khashayar Fereidani on Sep 26
# harness Gitspace hardcoded password for every user account