❌

Reading view

[0day-rubbish] StreamSets Transformer 3.17.0 auth-mode none fallback and un-sandboxed ScalaDTransform execution to container root (8.1 primary)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in
StreamSets Transformer, the Spark-engine data-pipeline platform from
StreamSets Inc. (subsequently acquired by IBM), verified on version 3.17.0
analysed from the official container image.

Type: failing-open authentication plus un-sandboxed code injection. On the
web tier, CWE-306 and CWE-1188 with CWE-285 on the authorisation side: when
the effective http.authentication value...
  •  

[0day-rubbish] RCDevs WebADM 2.4.14 authenticated log viewer sid command injection to webadm uid 999 code execution (7.2)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in RCDevs WebADM
2.4.14, Freeware Edition, the closed-source IAM/MFA management platform from RCDevs
Security SA (Luxembourg) that fronts the vendor's OpenOTP, SpanKey and TiQR
authentication products.

Type: OS command injection (CWE-78, with CWE-20 and CWE-116 contributing, and
CWE-732/CWE-276 and CWE-250 added for two auxiliary conditions). The administrator
console log...
  •  

[0day-rubbish] Maian Cart 3.8 addBanners unrestricted banner upload to PHP webshell and administrator command execution (7.2 primary, PR:H)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in Maian
Cart 3.8, the self-hosted PHP shopping-cart system from Maian Media (Maian
Script World), verified end to end against a real installation of that
version.

Type: unrestricted upload of a file with a dangerous type (CWE-434), realized
as OS command execution (CWE-78) through an attacker-supplied PHP webshell,
with CWE-269 bearing on the execution privilege context. The...
  •  

[0day-rubbish] IPConfigure Orchid VMS 26.3.0 authenticated DNF repository GPG-key property command injection to root (7.2)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in
IPConfigure Orchid VMS, installed as Orchid Recorder, version 26.3.0.

Type: OS command injection (CWE-78, with CWE-20 bearing on it because no
character validation exists anywhere on the path; CWE-250 bears on the
result). The server property package.dnf.repo.gpg_key, the URL or path of
the GPG key signing the vendor RPM repository, is written through the
authenticated...
  •  

[0day-rubbish] Circutor LineEds 24.11.14-r0 unauthenticated pwrstudio events.xml shellExecute command injection (9.8)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in the pwrstudio
daemon shipped in Circutor LineEds (Line Energy Data System) industrial energy gateway
firmware 24.11.14-r0, engine variant pss0. Circutor S.A. is in Spain; the appliance sits
between metering and power-quality instrumentation on one side and an energy-management
or SCADA back office on the other.

Type: operating-system command injection (CWE-78) reached without...
  •  

[0day-rubbish] Asustor ADM 3.5.9.RWM1 (AS602T) music.cgi act=live stored-filename command injection reaching system() (8.8 primary, PR:L)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in the
media handler of the ADM (ASUSTOR Data Master) management portal, verified by
static analysis on the AS602T running ADM 3.5.9.RWM1 (x86-64, first-
generation G1 firmware line, from the distributed image
ADM_X64_G1_3.5.9.RWM1_AS602T.img).

Type: OS command injection (CWE-78), enabled by an argument-quoting breakout
(CWE-88) and by an incomplete list of disallowed values...
  •  

[0day-rubbish] Advantech WebAccess Node 9.2.3 unauthenticated CrystalRpt.aspx file upload and path traversal to code execution in w3wp.exe (9.8)

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in Advantech
WebAccess Node 9.2.3, the closed-source industrial SCADA/HMI web server from
Advantech (Taiwan).

Type: unrestricted file upload (CWE-434) compounded by path traversal (CWE-22), on
a page that performs no authorization decision at all (CWE-306). CWE-73 and CWE-862
also map; CWE-250/CWE-269 apply conditionally where the pool runs at high
privilege. In the WaCrpt ASP.NET...
  •  

SEC Consult Research 20261001 :: Arbitrary Email sender spoofing in Apple iCloud mail

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 06

SEC Consult Vulnerability Lab Research Announcement < 20261001 >
=======================================================================
title: Arbitrary Email sender spoofing in Apple iCloud mail
product: Apple iCloud mail (SMTP submission service)
vulnerable version: iCloud mail infrastructure (cloud service)
fixed version: Fixed by Apple (verified by SEC Consult, 2025-12-09)
CVE number: None...
  •  

SEC Consult SA-20260924-0 :: Multiple Vulnerabilities in Paessler PRTG Network Monitor #CVE-2026-4637 #CVE-2026-4638

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 06

SEC Consult Vulnerability Lab Security Advisory < 20260924-0 >
=======================================================================
title: Multiple Vulnerabilities
product: Paessler PRTG Network Monitor
vulnerable version: <26.2.120.1449
      fixed version: 26.2.120.1449
         CVE number: CVE-2026-4637, CVE-2026-4638
             impact: high
homepage:...
  •  

Trump Mobile customers' data dumped - and some never even received their gold device

If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the Trump-branded mobile biz and leaked data belonging to 3,615 people, including names, email addresses, phone numbers, home addresses, and order details. BYOD is a new ransomware-as-a-service operation, and Trump Mobile is only the third organization posted on its data-leak site. According to the group’s posted claim, after telling Trump Mobile that it had been breached, the wireless provider replied: “We have no team to handle this" and “Anyone who hacks them are a terrorist.” “Well unfortunately for them, all 3615 customers and their PII, alongside telecom details are now up for grabs,” the leak site says. “Feel free to take a gander at it yourself, don't be shy, we (and them) certainly aren't stopping you.” The hackers reportedly told International Cyber Digest that they first infected a Liberty Mobile employee with an infostealer, and then accessed Trump Mobile via the MVNO. BYOD claims to still have access to Trump Mobile’s systems, and told the publication that neither wireless provider used any form of multi-factor authentication. Neither the Trump Organization nor Liberty Mobile responded to The Register’s questions about the breach. The data dump doesn’t include any details about US President Donald Trump or his family members, according to Straight Arrow News, which first reported the breach and verified some customers’ information. This could mean that the Trump family doesn’t eat its own dogfood. The leak does, however, include personal information about Eric Brunnett, vice president and chief information officer for the Trump Organization. Brunnett’s LinkedIn profile says he oversees “all Information Technology and Information Security for all aspects of the Trump Organization.” Additionally, one customer contacted by Straight Arrow said he paid a $100 pre-order deposit last year for Trump Mobile’s flagship smartphone, the T1, but never received a gold-colored device. Another criminal group, EndZone, also claimed to have breached Trump Mobile and leaked a stolen dataset a week before BYOD’s post in what “appears to be the same original breach,” according to security sleuth Dominic Alvieri. These aren’t the fledgling mobile phone company's only security snafus. Before these two apparent breaches, a security researcher in May claimed he discovered a now-plugged website vulnerability that leaked Trump Mobile customers’ details. The individual behind the discovery, who goes by "Louis" and described himself as "just a nerd between jobs with too much time on my hands," previously told The Register that the website’s data could be scooped up with a simple POST request.®

  •  

Microsoft extends the Outlook naughty step with two more file types

Microsoft is adding two extra file types to its Outlook block list to strengthen security. The file types are .msix and .msixbundle, used for Windows application packages and bundles. The change affects New Outlook for Windows and Outlook on the Web in Exchange Online. By default, users of the affected clients will no longer be able to download or open attachments with these extensions, which is no bad thing because blindly installing a malicious .msix package could compromise a device. That said, although Microsoft noted that the file types were "infrequently used," there are legitimate reasons for their presence in emails. Administrators who need to permit these attachments can add the extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy before the rollout, scheduled for early to mid-November 2026. "This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments," Microsoft said. The Windows giant's application packaging system has come under fire over the years. Microsoft disabled the ms-appinstaller protocol handler by default in December 2023 after attackers abused it to distribute malware. The attachment block adds another layer of protection, unless administrators explicitly allow these file types. Other file types blocked by Outlook on the Web include .py Python files, .ps1 PowerShell files, and .cab files. It's a little surprising that it has taken until now for .msix and .msixbundle to be added to the list, considering the havoc malicious packages can wreak on a system. Renaming an attachment's extension or sending a download link may get around the attachment restriction, but neither makes the package safe. Persuading someone to download and install it remains a route for miscreants, even with Windows' other protections in place. ®

  •  

Teaching network intrusion in the funnest way possible

I wanted to share a project I’ve been working on that I’m super excited about:

Project RedTeam: Contract Offensive

There’s a free Demo that provides a tutorial and lets you play a few contracts (no time limit, play as much as you want). Some players are already pulling some serious hours in the demo!

At its core, this is a game about using MITRE ATT&CK adversarial techniques against procedurally generated networks. It's delivered in a gameplay loop that plays a lot like Balatro and other card based Roguelike games. In Project RedTeam, you need to earn money to pay off debts after every contract within a run. Earn money by completing objectives, side bounties, or executing exfiltration/ransom against targets- the choice on how to be profitable is always yours.

It's a challenging but fun and fast paced take on network-intrusion cybersecurity concepts. It's entertaining in a deliberately gamified way.

A goal of this project was to create a hacking game that is realistic enough to keep it meaningful as a tool to teach intrusion concepts and stages to anyone- but not be overcomplicated and slow-paced like most hacking games.

I've put a lot of thought into the design and dynamics of how to capture the core-loop of network intrusion and turn it into a game that's approachable. The design direction of this project is an outcome of having over a decade of training and experience in cybersecurity.

Feel free to AMA! I'm happy to answer any questions about the game and/or development process :)

Give the game a Wishlist on Steam or share this post if it's something you support and want to see further development on.

Project background: This was implemented over the past 3 months using a modern development workflow (yes, modern AI tools make this possible- I'm not hiding that fact!). That being said, this is by far the most complex software project I've built as a solo developer and it was not an easy or simple development task. There's a Steam Community with a Dev Blog for this game that provides more history/progress updates on the project.

Mods: This will be my only and last post here, since it is promotional. I just wanted to share this since there’s been very positive interest from similar subreddits.

submitted by /u/ProjectRedTeam
[link] [comments]
  •  

Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets

GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent tool was flagged earlier this year for being susceptible to indirect prompt injection. That's when a model ingests text from a source other than the user that directs it to take some action outside the scope of its intended function. This is more of the same, with a twist. According to security researchers at Adversa AI, GitHub Copilot CLI suffers from the same vulnerability identified in Grok two months ago: Cryptographic Context Injection (CCI). Imagine a GitHub Copilot CLI user is working on a project and running the agent in autopilot mode. In other agentic coding tools like Anthropic's Claude, that's the default, but it remains optional for GitHub Copilot CLI. Given that condition, the next requirement is for the CLI tool to read a web page with a malicious set of instructions that have been encrypted with a private key published on the same site. "Static guardrails read text; they do not run it," explained Rony Utevsky in a blog post provided to The Register. "CCI ships malicious instructions as strong ciphertext, along with the key material and an instruction to decrypt, and induces the agent to run that decryption in its own code execution runtime." Active content classifiers that might be reading ingested text as a model defense would miss the encrypted code, unlike encodings like base64 or substitution ciphers that can be undone because the model learned how to decode in training. The model lottery The attack chain goes like this: The user runs Copilot CLI and asks it to fetch a specific URL. The page contains encrypted content, decryption instructions calling for use of Python, and two possible decryption keys. The first key is fake. It's a template that the agent tries to build by reading targeted files from disk (e.g., the user's .env file). Those secrets then get added to the key string. The initial decryption is attempted with this phony key but fails. So the second key is tried, the decryption works, and the agent is presented with instructions to fetch another URL for more context – but that URL contains the harvested secrets and the network request transmits them to the attacker. This doesn't work all the time, however. It depends on the model, which isn't always obvious to the user. GitHub Copilot CLI currently uses either Microsoft's own model, mai-code-1.1-flash, which executed the full attack chain on 50 percent of attempts, or one of two OpenAI GPT-5.6 models, both of which refused the attack payload. Utevsky describes the situation as a model lottery. "On the paid account we tested, the vulnerable model was not the default and had to be selected by hand," said Utevsky. "But on an account with model selection left on Auto, the router assigned the vulnerable model on some sessions and a safe one on others, with no action by the user away from defaults. The user does not choose, and does not see, which model handled the session." Adversa says it reported the vulnerability through GitHub's bug bounty program on September 17, 2026, and GitHub's triage team validated the finding but declined to treat it as a vulnerability. A GitHub spokesperson said as much to The Register, arguing that the user's actions amounted to consent for what followed: "GitHub values the contributions of our security research community and is committed to investigating reported security issues. After investigating, we determined this requires a user to intentionally direct Copilot CLI to fetch attacker-controlled or untrusted content and confirm they want to trigger the action, and thus is not a product vulnerability. While this is not a security issue with the product itself, we are always looking for opportunities to improve our products." Adversa disagrees with that call and says the attack chain presently works as described. ®

  •  

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in

  •  

Asos app delivers a data leak threat instead of fast fashion

Asos customers have reported receiving a rogue app notification claiming the online clothing retailer's Snowflake instance has been compromised and threatening to leak data. The notification included a link to a Telegram channel named "Xuanye Wen Gateway" and addressed Asos's data protection officer and IT team. "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," it says. The notification does not, by itself, establish that the sender accessed Asos's Snowflake instance or sensitive customer data. How the message was sent remains unclear. Asos's share price fell by around 12 percent following reports of the notification, although it has recovered slightly since. Several hours after publication, an Asos spokesperson confirmed the attack and claimed it had limited impact, telling The Register, "Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted. Our website and app are operating as normal, with no current disruption to any aspects of our operations." The spox added, "The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading." Snowflake did not immediately return a request for comment. Customers of Snowflake, a cloud platform for storing and analyzing data, were targeted in a major data theft campaign in 2024, including Ticketmaster, Santander, AT&T, and dozens of others. Connor Riley Moucka, 26, of Kitchener, Ontario, later pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges over a hacking spree that compromised more than 165 organizations, exposed billions of customer records, and brought in about $2.5 million in ransom payments. Snowflake subsequently introduced controls allowing administrators to require multi-factor authentication. A Snowflake spokesperson said: "At this time, we can report that we have found no compromise of the Snowflake platform. We take customer privacy and security very seriously. The investigation is ongoing and we will provide further updates as soon as more information becomes available." ® Updated Oct 6 at 1742 UTC: To add Asos' confirmation of the attack and comment. Updated October 7 0845 UTC: To add Snowflake's statement.

  •  

Denmark's ID register spills more people's details than the country has residents

An unauthorized party abused a private Danish company's legitimate access to the country's Central Population Register (CPR), exposing names, addresses, identification numbers, and other personal information about approximately 8.8 million people. The CPR administration said in a statement [PDF] that it became aware on October 2 of irregular activity during September and established the scale of the breach over the weekend. In a TV interview last night, digitization minister Christina Egelund said it was too soon to say whether the country would issue all-new CPR numbers, one of the solutions proposed following the breach. Danish cybersecurity specialist Jan Kaastrup told TV 2 that treating CPR numbers as secrets was a "broken" approach and argued that a number alone should not be accepted as proof of identity. "We live in a digitalized society, and therefore we should have much better identification systems," he said. Egelund described the company whose access was abused as "small." Private businesses can obtain CPR data under section 38(1) of the Danish Civil Registration System Act, subject to restrictions set out in the ministry's access terms [PDF]. Eligible recipients include companies, foundations, other legal entities, and individuals conducting business. However, access concerns a defined group of people identified individually in advance, and recipients must be legally entitled to process the information under the GDPR and Danish data protection law. The Register asked the ministry why such broad access was given. CPR numbers underpin access to public services and many everyday transactions in Denmark, which has a population of around 6 million people. The database includes the information of over 55,000 people living in Greenland who also use CPR numbers for healthcare, tax services, and banking. The ministry said the register contains approximately 11 million records, including people who have died or moved abroad, which explains why the affected total exceeds Denmark's current population. The ministry also noted that names and addresses of persons who chose to register with name and address protection were not exposed. The CPR administration blocked the unnamed company's access and said it was working with specialists and relevant authorities to establish what happened. It has notified the Danish Data Protection Agency, and police are investigating. ®

  •  
❌