Certificate failures can cost firms over $250,000

Source: Help Net Security

Author: Anamarija Pogorelec

URL: https://www.helpnetsecurity.com/2026/09/14/digicert-certificate-management-automation-report/

ONE SENTENCE SUMMARY:

DigiCert warns 47-day TLS certificates will multiply renewals, validations and outages unless enterprises rapidly gain visibility and automate lifecycles everywhere.

MAIN POINTS:

  1. Shifting to 47-day public TLS certificates by 2029 increases renewals eightfold and validations 40x.
  2. Expired certificates caused outages for 34% of firms; 40% reported downtime from mismanagement.
  3. Downtime severity is high: nearly three-quarters lost five hours, while 21% lost 25+.
  4. Financial impact is substantial, with 25% citing their worst incident exceeding $250,000.
  5. Operational ownership skews to infrastructure: 57% label outages IT issues versus 17% security incidents.
  6. Certificate sprawl is common, as over half of organizations manage more than 1,000 certificates.
  7. Key “very/extremely concerned” challenges include expiration, customer trust, regulatory compliance, and multi-cloud/platform management.
  8. Managing internal and external systems simultaneously worries 52%, highlighting fragmented environments needing central control.
  9. Adoption momentum is growing: ~70% are preparing for shorter lifetimes, and volumes are expected to rise.
  10. Automation expansion is constrained by cost, legacy incompatibility, weak executive buy-in, and limited expertise.

TAKEAWAYS:

  1. Inventory completeness (what, where, owner) becomes mandatory when lifecycles shrink to 47 days.
  2. Eliminating manual tracking reduces outage risk more effectively than relying on reminders and spreadsheets.
  3. Building an ROI case should emphasize avoided downtime and remediation labor, not just tooling costs.
  4. Integrating certificate management into DevOps pipelines is the top near-term improvement priority.
  5. Addressing “very/extremely concerned” areas requires lifecycle-wide automation across clouds, platforms, and compliance workflows.

How to level up from security pro to security leader

Source: CSO Online

Author: unknown

URL: https://www.csoonline.com/article/4221303/how-to-level-up-from-security-pro-to-security-leader.html

ONE SENTENCE SUMMARY:

Aspiring CISOs must evolve from technical experts into business-focused leaders who communicate risk, influence stakeholders, build trust, and learn continuously.

MAIN POINTS:

  1. Translating technical risk into business priorities separates top CISOs from technical specialists.
  2. Employers prioritize communication skills, regulatory knowledge, and broad education over specific tools.
  3. Modern CISO expectations center on strategy and leadership, not daily hands-on security tasks.
  4. Trust-building requires collaboration without reverting to an “IT guy” posture.
  5. Professional presence means concise, confident communication and appropriate cultural fit.
  6. Cross-functional relationships enable influence across engineering, operations, legal, finance, and executives.
  7. Admitting mistakes and sharing lessons can strengthen credibility and leadership maturity.
  8. Business fluency comes from understanding revenue models, budgets, and organizational tradeoffs.
  9. Curiosity and learning are mandatory as AI agents, APIs, and machine identities expand.
  10. Mentorship and focusing on impact today matter more than rigid career-path scripting.

TAKEAWAYS:

  1. Develop an executive narrative that ties security decisions to outcomes leaders care about.
  2. Invest in political and partnership skills to drive shared accountability beyond formal authority.
  3. Build business competence through MBA alternatives like budgeting, product work, and risk roles.
  4. Seek diverse technical exposure to better govern emerging enterprise technologies.
  5. Use mentors and present authentic growth, prioritizing results over title-chasing.

Why Patch Automation Needs Brakes, Not Just an Accelerator

Source: BleepingComputer

Author: Sponsored by Action1

URL: https://www.bleepingcomputer.com/news/security/why-patch-automation-needs-brakes-not-just-an-accelerator/

ONE SENTENCE SUMMARY:

Software updates outpace IT capacity, so controlled patch automation using staged rings, defined success criteria, and human oversight reduces risk.

MAIN POINTS:

  1. Update volume and vulnerability disclosures are rising faster than IT teams can evaluate.
  2. Staffing constraints and complex environments cause patch backlogs and risky deployment trade-offs.
  3. Compressed testing and skipped reviews increase chances of outages or insecure exposure windows.
  4. Automation can rapidly spread failures if speed becomes the primary metric.
  5. Effective patch automation requires “brakes” to control progression, timing, and stop conditions.
  6. Test labs help but cannot mirror diverse production configurations and behaviors.
  7. Controlled production validation using staged deployment better reflects real-world conditions.
  8. Establish upfront success definitions: install success, endpoint health, app functionality, acceptable failure rates.
  9. Update rings enable gradual rollout governed by predefined criteria, reducing ad-hoc human decisions.
  10. Human involvement remains essential for business-critical systems while routine decisions get automated.

TAKEAWAYS:

  1. Treat speed as secondary to safety by pairing automation with enforceable deployment controls.
  2. Implement staged rollouts that automatically advance or halt based on measurable outcomes.
  3. Formalize what “success” means before deploying, then monitor continuously against those baselines.
  4. Reserve manual approvals and expert judgment for high-impact systems and exceptions.
  5. Aim for consistent, controlled automation first, then optimize for faster patching over time.

Microsoft releases emergency Windows updates to fix RDS failures

Source: BleepingComputer

Author: Lawrence Abrams

URL: https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-windows-updates-to-fix-rds-failures/

ONE SENTENCE SUMMARY:

Microsoft issued out-of-band Windows updates to fix September 2026 security-update regressions breaking RDS, plus Hyper-V and USB audio issues.

MAIN POINTS:

  1. September 2026 security updates destabilized Remote Desktop Services, causing RDP sign-in and connection failures.
  2. Some impacted servers became unresponsive, indicating severe service disruption beyond simple login issues.
  3. Related tools like MMC, Licensing Diagnoser, File Explorer, and Windows Update could hang.
  4. Out-of-band fixes shipped September 14 to remediate the introduced regressions.
  5. Windows Server 2025 failures traced to KB5122871; Windows Server 2022 issues tied to KB5122882.
  6. Temporary mitigations were previously provided via Group Policy while engineering developed permanent patches.
  7. Uninstalling September updates restored Remote Desktop, but removed included security protections.
  8. Windows 11 26H1 KB5129194 is distributed via WU, WUfB, Catalog, and WSUS.
  9. Server out-of-band updates for 2022/2025 are offered through the Microsoft Update Catalog only.
  10. Additional OOB updates include KB5129195 (Win11 24H2/25H2) and KB5129236 (Win10 21H2/22H2).

TAKEAWAYS:

  1. Treat Patch Tuesday deployments cautiously; critical regressions can break core remote administration paths.
  2. Use Microsoft’s out-of-band patches rather than rolling back security updates when feasible.
  3. Validate RDS plus management tooling after updates, not just RDP connectivity.
  4. Hyper-V Plan9 shared-folder issues and multichannel USB audio failures are also addressed in Windows 11 OOB updates.
  5. Remaining USB Audio Class 1.0 “Code 10/no audio” problems persist, with a future fix pending.

CQURE Hacks #82: Microsoft Entra ID Conditional Access Bypass via User-Agent Policy Gap

Source: CQURE Academy

Author: Asia

URL: https://cqureacademy.com/blog/cqure-hacks-82-microsoft-entra-id-conditional-access-bypass-via-user-agent-policy-gap/

ONE SENTENCE SUMMARY:

A User-Agent–based Conditional Access gap enabled Xbox token issuance without MFA, leading to Graph access, secret discovery, and full tenant compromise.

MAIN POINTS:

  1. Conditional Access trusted device platforms based solely on client-controlled User-Agent strings.
  2. Policies blocked Windows, Linux, and iPhone, but overlooked Xbox Series X.
  3. Xbox User-Agent allowed Microsoft Graph token acquisition without triggering MFA.
  4. Obtained access token enabled direct Graph API access despite portal restrictions.
  5. GraphRunner enumerated users, groups, and roles through Microsoft Graph.
  6. Portal blocking proved ineffective because underlying APIs remained accessible.
  7. Custom scripting searched directory objects for exposed credentials and secrets.
  8. A clear-text password was found stored in a group description attribute.
  9. Exposed credentials belonged to a break-glass Global Administrator account.
  10. Chaining policy gaps with poor secret storage resulted in full tenant compromise.

TAKEAWAYS:

  1. Expand Conditional Access coverage to include Graph/API token acquisition flows.
  2. Avoid security decisions based on manipulable client signals like User-Agent.
  3. Enforce MFA consistently across all sensitive access paths, not just portals.
  4. Prevent secrets from being stored in readable directory attributes and descriptions.
  5. Assume attackers will chain minor misconfigurations into high-impact compromises.

Update your firewall rules: Teams and Copilot are changing address

Source: CSO Online

Author: unknown

URL: https://www.computerworld.com/article/4221272/teams-and-copilot-are-changing-addresses-update-your-firewalls.html

ONE SENTENCE SUMMARY:

Microsoft will redirect M365 and Teams web traffic to new cloud.microsoft domains, requiring enterprises to update controls by October.

MAIN POINTS:

  1. Redirects will send M365 web users to copilot.cloud.microsoft starting this month.
  2. Teams web users are being redirected to teams.cloud.microsoft already.
  3. Microsoft announced changes via MessageCenter posts MC1465764 and MC1462915.
  4. Organizations must update systems and documentation to preserve user access.
  5. Client device configurations should be reviewed for compatibility with new destinations.
  6. Proxies, firewalls, and secure web gateways may need rule adjustments.
  7. Enterprise network controls must allow connections to the new addresses.
  8. Troubleshooting should reference Microsoft 365 Copilot network requirement guidance.
  9. TenantRestrictions can replace blocking copilot.cloud.microsoft to limit personal account access.
  10. Limited Teams redirect exceptions may continue until December 31, 2026.

TAKEAWAYS:

  1. Change management is needed to prevent service disruption from domain redirects.
  2. Network security tooling should be validated against updated Microsoft endpoint destinations.
  3. Policy-based tenant controls are preferred over blunt domain blocking for account restrictions.
  4. Early October is the target completion date; support is available through account representatives.
  5. Long-term planning must assume Teams exceptions end permanently after the 2026 deadline.

GitLab urges users to patch max severity path traversal flaw

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/

ONE SENTENCE SUMMARY:

GitLab released urgent patches for critical path traversal and deserialization flaws, warning self-managed users to upgrade immediately to prevent sensitive data exposure.

MAIN POINTS:

  1. Maximum-severity path traversal vulnerability tracked as CVE-2023-2825 prompted immediate patching guidance.
  2. Researcher “s3ntago” reported the issue via GitLab’s HackerOne bug bounty program.
  3. Root cause involves improper path confinement and missing authentication in repository commits API.
  4. Unauthenticated attackers could read arbitrary files from vulnerable GitLab servers under conditions.
  5. Second critical flaw, CVE-2026-87719, involves insecure deserialization in GraphQL subscription serializer.
  6. CVE-2026-87719 impacts GitLab EE and requires authenticated Duo Chat access.
  7. Exploitation could expose sensitive credentials and Advanced Search instance configurations.
  8. Fixes shipped in GitLab CE/EE versions 19.3.2, 19.2.6, and 19.1.x releases.
  9. GitLab.com already runs patched code; GitLab Dedicated customers need no action.
  10. CISA has listed multiple GitLab vulnerabilities as exploited since 2021, underscoring active risk.

TAKEAWAYS:

  1. Upgrade self-managed GitLab immediately to patched versions to reduce exposure windows.
  2. Enforce strong API authentication and path confinement to prevent traversal-style data leaks.
  3. Treat deserialization in GraphQL-related components as high-risk and audit serializers rigorously.
  4. Monitor CISA exploited-vulnerability listings to prioritize patching and threat-informed remediation.
  5. Past GitLab security incidents show recurring attacker interest, requiring continuous vulnerability management.

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html

ONE SENTENCE SUMMARY:

Wiz found many exposed LiteLLM gateways using default master keys, enabling credential theft, code execution, and urgent hardening upgrades needed.

MAIN POINTS:

  1. Scan found 3,074 Shodan-listed LiteLLM gateways; 294 accepted the example key.
  2. Of those 294, 191 had no master key set, accepting any value.
  3. Prior to 1.82.0-stable, missing master key granted full admin to all requests.
  4. Administrators can view stored model-provider API keys and all prompts/responses passing through.
  5. Pass-through endpoints allow SSRF to cloud instance metadata, exposing IAM credentials.
  6. IMDSv2 protections were bypassed using LiteLLM’s x-pass- header forwarding behavior.
  7. Maintainers classify misconfiguration-based attacks as out-of-scope; no CVE for metadata access.
  8. CVE-2026-59821 enabled container code execution via guardrail checks bypass pre-1.82.0-stable.
  9. CISA lists exploited CVE-2026-59822, enabling MCP access with trivial Bearer tokens.
  10. Mitigations include upgrading to 1.84.0+, blocking risky endpoints, and least-privilege cloud roles.

TAKEAWAYS:

  1. Replace sk-1234 with a long random master key and follow correct rotation procedure.
  2. Adopt LiteLLM 1.84.0 or later to cover all listed CVE fixes.
  3. Enforce outbound network restrictions and minimal IAM permissions to limit blast radius.
  4. Disable or proxy-block /mcp/, MCP test endpoints, and unsafe guardrail routes.
  5. Assume compromise if exposed: audit guardrails, restart services, and rotate provider/database credentials.

Threat matrix: Mapping threats across cloud web applications

Source: Microsoft Security Blog

Author: Microsoft Security Research and Lior Leizerovich

URL: https://www.microsoft.com/en-us/security/blog/2026/09/09/threat-matrix-mapping-threats-across-cloud-web-applications/

ONE SENTENCE SUMMARY:

Microsoft’s MITRE ATT&CK-aligned cloud web applications threat matrix maps techniques across app and cloud layers to prioritize defenses.

MAIN POINTS:

  1. Attack paths span code, runtimes, identities, pipelines, and connected cloud resources.
  2. Separate app-versus-cloud investigations create blind spots and missed adversary chaining opportunities.
  3. Matrix organizes cloud web app and serverless techniques by MITRE ATT&CK tactics.
  4. Subdomain takeover can occur from orphaned DNS pointing at reusable provider endpoints.
  5. Initial access includes app vulnerabilities, repo injections, compromised images, misconfigured admin interfaces, trigger abuse.
  6. Execution vectors include remote code execution exploits, cloud-native terminals, and malicious App Service extensions.
  7. Persistence occurs via scheduled jobs, source modification in canonical artifacts, and compromised valid accounts.
  8. Privilege escalation leverages app-stored secrets or workload identity tokens via metadata/identity endpoints.
  9. Defense evasion uses staging slots/aliases and disabling or manipulating cloud logging controls.
  10. Impact techniques include theft, destruction, defacement, resource hijacking, and denial-of-wallet cost abuse.

TAKEAWAYS:

  1. Prioritize MFA and least privilege for users, workloads, and deployment access paths.
  2. Lock down repositories, build systems, registries, and extensions to trusted sources only.
  3. Eliminate reusable secrets in code/config by using workload identities and proper secrets management.
  4. Centralize protected logging and prevent tampering to enable detection and incident reconstruction.
  5. Reduce blast radius with quotas, concurrency limits, cost guardrails, and tested backup recovery.

Is a Quantified Cyber Risk Number Defensible? The Inputs

Source: Rivial Security Blog

Author: Randy Lindberg

URL: https://www.rivialsecurity.com/blog/is-cyber-risk-quantification-defensible

ONE SENTENCE SUMMARY:

Defensible cyber risk quantification uses external breach data, ATT&CK scenarios, Monte Carlo loss curves, and validated controls to justify dollar figures.

MAIN POINTS:

  1. Security leaders often dismiss CRQ as guesses disguised as precise dollars.
  2. High/medium/low ratings also rely on subjective inputs but conceal assumptions.
  3. Quantified models can be defensible by transparently showing calculations and sources.
  4. Self-populated likelihood estimates merely reformat opinion and undermine board credibility.
  5. Independent breach datasets anchor incident frequency and cost baselines objectively.
  6. Organization specifics adjust baselines using systems, data types, records, and controls.
  7. MITRE ATT&CK grounds threat scenarios in observed adversary techniques across attack chains.
  8. Monte Carlo simulation models lognormal losses, capturing both expected loss and catastrophic tail risk.
  9. Interview-only control assessments weaken models; validation ties inputs to evidence and testing.
  10. Quantified, validated outputs support regulator scrutiny and enable cost-effective risk reduction decisions.

TAKEAWAYS:

  1. Replacing colors with dollars improves auditability because assumptions become inspectable.
  2. External, regularly updated research reduces bias in likelihood and impact estimation.
  3. ATT&CK-based scenarios increase credibility by using a widely accepted public framework.
  4. Simulation provides board-relevant views of tail losses, not just single expected values.
  5. Evidence-backed control effectiveness turns CRQ into actionable capital allocation and tolerance management.

Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”

Source: Tenable Blog

Author: Eric Doerr

URL: https://www.tenable.com/blog/tenable-one-claude-mythos-5-adversary-view-ai-exposure-management

ONE SENTENCE SUMMARY:

Tenable integrates Anthropic Claude Mythos 5 into Tenable One, enabling adversarial reasoning to prioritize vulnerability chains and disrupt attacks faster.

MAIN POINTS:

  1. Claude Mythos 5 will be embedded into the Tenable One Exposure Management Platform.
  2. Frontier adversarial reasoning helps defenders anticipate attacker paths across complex environments.
  3. Tenable One Adversary View is the first customer-facing capability, launching in coming weeks.
  4. Adversary View identifies hidden, viable vulnerability chains specific to each environment.
  5. Analysis uses raw scanner evidence beyond typical findings and rule-based detection.
  6. Inputs include connections, service enumeration, installed software, configurations, and plugin outputs.
  7. The Tenable agentic harness supplies context, validation, and controlled action around model reasoning.
  8. Workflow starts with scoping assets through a guided conversation in Tenable One.
  9. Output is ranked disruption actions with supporting evidence, not an expanded findings list.
  10. Recommendations can be executed via Tenable Hexa AI; no new deployment required.

TAKEAWAYS:

  1. Exposure management shifts from “find issues” to “understand exploit chains and fix order.”
  2. Low-signal artifacts can become high-impact risk when correlated across the environment.
  3. Attacker-perspective reasoning can reveal pathways no prewritten rule anticipated.
  4. Productizing frontier models requires contextual harnessing for safety, accuracy, and control.
  5. Tenable signals a broader roadmap of AI-powered exposure management beyond Adversary View.

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

Source: CyberScoop

Author: Matt Kapko

URL: https://cyberscoop.com/microsoft-patch-tuesday-september-2026/

ONE SENTENCE SUMMARY:

Microsoft’s record Patch Tuesday fixed 974 flaws, including two exploited privilege-escalation zero-days, urging risk-based prioritization amid AI-driven discovery.

MAIN POINTS:

  1. Microsoft patched 974 defects across its product suite in a single Patch Tuesday.
  2. Two zero-day vulnerabilities were actively exploited before public disclosure.
  3. AI-assisted vulnerability discovery is accelerating vulnerability identification and disclosures.
  4. Despite more disclosures, researchers haven’t observed a matching surge in active exploits.
  5. CVE-2026-81963 impacts the Windows Update Stack and enables privilege escalation.
  6. CVE-2026-85880 affects Windows Advanced Local Procedure Call with privilege escalation potential.
  7. Both exploited zero-days carry CVSS scores of 7.8.
  8. Over 10% of the month’s disclosed defects were rated critical.
  9. Patch counts included Windows 723, Office 111, Office 2016 111, SQL 62, tools 22.
  10. Experts recommend focusing on applicable, reachable, exploitable issues rather than totals.

TAKEAWAYS:

  1. Prioritize patches by exploitability, exposure, and business impact instead of raw vulnerability volume.
  2. Monitor for privilege-escalation vectors in core Windows components during emergency patch cycles.
  3. Large AI-driven disclosure “haystacks” require stronger triage and vulnerability management processes.
  4. Separate urgent fixes from routine updates to prevent operational overload and patching delays.
  5. Use vendor advisories like Microsoft’s Security Response Center to map updates to your environment.

Why Proofpoint Is Eyeing a Buy of Data Security Firm Varonis

Source: BankInfoSecurity.com RSS Syndication

Author: unknown

URL: https://www.bankinfosecurity.com/blogs/proofpoint-eyeing-buy-data-security-firm-varonis-p-4185

ONE SENTENCE SUMMARY:

Proofpoint is negotiating to buy Varonis to strengthen data security ahead of an IPO, while offering Varonis shareholders an exit.

MAIN POINTS:

  1. Recent cybersecurity IPOs often underperform, making private acquisitions more common after weak stock pops.
  2. Proofpoint, owned by Thoma Bravo, doubled ARR to $2.45B and nearly $1B EBITDA.
  3. The company expanded beyond email security into data and AI security via tuck-in acquisitions.
  4. Forrester rated Proofpoint’s data security platform weakest in 2025 due to limited controls and manageability.
  5. Varonis topped Forrester’s 2025 data security rankings and has two decades of focus.
  6. Bloomberg reported Proofpoint-Varonis acquisition talks, potentially announced within weeks near Protect 2026.
  7. A deal would be 2026’s largest pure-play cyber acquisition, exceeding Accenture’s planned Dragos purchase.
  8. Overlap includes DSPM plus discovery/classification; Proofpoint gained DSPM through buying Normalyze.
  9. Varonis adds access intelligence, activity monitoring, DDR, and UEBA; Proofpoint contributes AI security and DLP.
  10. Varonis stock lags post-renewal drop; SaaS revenue rose to 95.4% but losses widened.

TAKEAWAYS:

  1. Portfolio gaps in masking/tokenization and operational usability appear to be driving Proofpoint’s interest.
  2. Combining Varonis DDR/UEBA with Proofpoint DLP and AI protections could create a broader data security suite.
  3. Acquisition timing suggests Proofpoint wants a stronger data narrative before re-entering public markets.
  4. Market dynamics and Cyera’s rapid valuation growth pressure Varonis’s standalone public-market story.
  5. The transaction hinges on valuation agreement despite strategic fit and investor appetite for an exit.

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Source: Tenable Blog

Author: Research Special Operations

URL: https://www.tenable.com/blog/microsofts-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880

ONE SENTENCE SUMMARY:

Microsoft’s September 2026 Patch Tuesday fixed 964 CVEs, including two exploited zero-days, dominated by privilege escalation and major RCE risks.

MAIN POINTS:

  1. September 2026 release set a record with 964 patched vulnerabilities across Microsoft products.
  2. Severity breakdown included 104 Critical and 860 Important issues, with none Moderate/Low.
  3. Two zero-day vulnerabilities were exploited in the wild and patched this month.
  4. Elevation-of-privilege flaws comprised 44.7% of all fixed vulnerabilities.
  5. Remote code execution issues represented 26.8% of the patched vulnerabilities.
  6. CVE-2026-81963 abused Windows Update Stack link-following to gain SYSTEM privileges.
  7. CVE-2026-85880 targeted Windows ALPC to elevate privileges to SYSTEM as a zero-day.
  8. CVE-2026-69380 in Exchange allowed mailbox-to-mailbox access via missing authorization.
  9. CVE-2026-69525 enabled Remote Desktop Services RCE via use-after-free, exploitation more likely.
  10. CVE-2026-69730 let unauthenticated attackers achieve DNS Server RCE via crafted packets.

TAKEAWAYS:

  1. Prioritize patching for exploited EoP zero-days enabling SYSTEM-level compromise.
  2. Treat DNS Server RCE and RDP RCE vulnerabilities as urgent due to “more likely” exploitation.
  3. Review Exchange mailbox permission models to mitigate authorization-driven lateral email access.
  4. Focus remediation on privilege escalation categories, given their outsized share of fixes.
  5. Use vulnerability scanning to verify patch coverage and identify systems still exposed.

New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/

ONE SENTENCE SUMMARY:

Researcher Nightmare Eclipse released FalconFlank, a CrowdStrike Falcon zero-day enabling SYSTEM privilege escalation on updated Windows, prompting mitigations and broader scrutiny.

MAIN POINTS:

  1. Anonymous researcher “Nightmare Eclipse” published a CrowdStrike Falcon zero-day exploit named FalconFlank.
  2. Exploit reportedly works on fully updated Windows 11 25H2 and Windows Server 2025.
  3. Vulnerability currently lacks a CVE assignment and remains under investigation.
  4. Attack abuses Falcon Sensor’s Office malicious macros remediation to gain SYSTEM privileges.
  5. Successful exploitation spawns a SYSTEM command prompt via a proof-of-concept technique.
  6. Researcher expects detections, suggesting exclusions or PoC obfuscation to test.
  7. CrowdStrike advised disabling the Office policy enabling File Suspicious Macro Removal.
  8. CrowdStrike stated Cloud Anti-malware for Office Files continues to protect customers.
  9. FalconFlank technical alert exists but is restricted to CrowdStrike support portal accounts.
  10. Kevin Beaumont verified released privilege-escalation exploits from Nightmare Eclipse function as claimed.

TAKEAWAYS:

  1. EDR/AV features that remediate Office macros can become privilege-escalation attack surfaces.
  2. Immediate mitigation centers on disabling the specific Office policy tied to macro removal.
  3. Vendor guidance and detailed advisories may be gated, complicating rapid public understanding.
  4. Multiple concurrent zero-days from one source increase operational risk across security stacks.
  5. Technique-level evaluation matters because credentialed post-compromise stages reduce prevention effectiveness.

Critical Citrix NetScaler auth bypass now leveraged in attacks

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/

ONE SENTENCE SUMMARY:

Attackers are probing Citrix NetScaler CVE-2026-19490 auth-bypass flaw; agencies urge urgent patching amid PoC-driven exploitation attempts worldwide.

MAIN POINTS:

  1. Previdian reports in-the-wild targeting of critical Citrix NetScaler vulnerability CVE-2026-19490.
  2. Flaw enables remote authentication bypass by unprivileged attackers under specific NetScaler configurations.
  3. Affected setups include AAA virtual server and Gateway modes like SSL VPN and ICA Proxy.
  4. Exploitability depends on firmware version and whether SAML Action is configured.
  5. Citrix patched the issue mid-August and urged immediate upgrades to recommended builds.
  6. Citrix advisory (Aug 19) did not yet confirm active exploitation.
  7. Credible PoC publication preceded observed exploitation-like requests, per researcher Ryan Dewhurst.
  8. NetScaler sensor saw matching PoC attempts from IPs in Australia, US, and Germany.
  9. Belgium’s NCC-BE also warned of exploitation attempts and prioritized patching guidance.
  10. Shadowserver observes 22,000+ ADC and 1,700+ Gateway instances exposed, patch status unknown.

TAKEAWAYS:

  1. Patch NetScaler appliances promptly, prioritizing AAA and Gateway deployments.
  2. Validate firmware and SAML-related configuration to determine actual exposure.
  3. Treat publicly released PoCs as immediate risk accelerants for mass scanning.
  4. Monitor for exploit-pattern requests, but distinguish attempts from confirmed compromises.
  5. Citrix NetScaler remains a recurring target, with multiple prior flaws quickly exploited.

Incident response guide for AWS CloudTrail investigations – Part 1

Source: AWS Security Blog

Author: Oscar Diaz

URL: https://aws.amazon.com/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-1/

ONE SENTENCE SUMMARY:

Guide teaches CloudTrail-based incident investigations, highlighting key fields, attacker patterns, and response checklists across cross-account S3 deletion and cryptomining scenarios.

MAIN POINTS:

  1. CloudTrail investigation hinges on interpreting specific fields, context, and event chains.
  2. Real-world scenarios cover cross-account unauthorized access, ransomware-like deletions, and console-driven cryptomining.
  3. Terminology glossary defines recon, enumeration, lateral movement, persistence, and other IR concepts.
  4. Scenario 1 starts with assumed-role activity performing S3 ListBuckets reconnaissance.
  5. Suspicious session naming can indicate masquerading to blend into normal automation noise.
  6. Listing objects followed by a silence gap suggests planning before rapid automated execution.
  7. S3 COPY operations before DELETE imply steal-then-destroy behavior and possible exfiltration.
  8. Tight deletion timing, consistent IP, and aws-cli user agent indicate scripted automation.
  9. Broad cross-account role permissions expose blast-radius risk without least-privilege and reviews.
  10. Scenario 2 shows CloudFormation abuse via console session and CloudShell, lacking MFA.

TAKEAWAYS:

  1. Prioritize containment by confirming ongoing access, sensitive exposure, and spread potential.
  2. Validate cross-account trust policies and role assumption paths to identify initial compromise.
  3. Correlate source IPs, session names, and user agents to uncover pivots and related actions.
  4. Treat cost anomalies as security signals; billing spikes can reveal resource hijacking early.
  5. Enforcing MFA for console access blocks many credential-abuse paths enabling rapid automation.

Incident response guide for AWS CloudTrail investigations – Part 2

Source: AWS Security Blog

Author: Oscar Diaz

URL: https://aws.amazon.com/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-2/

ONE SENTENCE SUMMARY:

An SSRF flaw stole IMDSv1 role credentials, enabling console access and cross-Region Amazon Bedrock misuse, shown through CloudTrail forensics analysis.

MAIN POINTS:

  1. Describes five-stage chain: SSRF, metadata credential theft, probing, pivoting, region hopping.
  2. CloudTrail CreateUser failure exposed webdev role and ec2RoleDelivery 1.0 indicating IMDSv1.
  3. ConsoleLogin success without MFA revealed interactive access from same source IP.
  4. ListFoundationModels in us-east-2 marked reconnaissance and intentional alternate Bedrock endpoint targeting.
  5. Converse invocation confirmed Amazon Nova Pro model abuse and token counts for cost estimation.
  6. Correlation hinges on consistent role ARN, session name instance ID, and sourceIPAddress.
  7. Key fields: userIdentity for attribution, readOnly for intent, awsRegion for evasion.
  8. Absence of userIdentity.invokedBy indicated direct credential use, not service-linked automation.
  9. Investigation prioritized role over-permissioning to Bedrock and searching other instances with same role.
  10. Response checklist includes fixing SSRF, enforcing IMDSv2, expanding multi-Region log queries and billing review.

TAKEAWAYS:

  1. Enforce IMDSv2 with hop-limit to neutralize SSRF-based metadata credential theft.
  2. Require MFA and restrict console sessions for workload roles to prevent interactive pivots.
  3. Standardize monitoring and controls across all Regions to reduce cross-Region blind spots.
  4. Enable Bedrock model invocation logging and telemetry to capture prompts, responses, and agent actions.
  5. Apply least-privilege policies and regularly analyze unused permissions to limit lateral movement.

Windows memory integrity switches on automatically for eligible devices in October 2026

Source: Help Net Security

Author: Anamarija Pogorelec

URL: https://www.helpnetsecurity.com/2026/09/03/windows-memory-integrity-update/

ONE SENTENCE SUMMARY:

Starting October 2026, Windows quality updates automatically enable VBS and memory integrity on eligible devices after readiness checks, preserving prior disablement choices.

MAIN POINTS:

  1. Windows quality updates begin enabling memory integrity automatically starting October 2026.
  2. Devices lacking Virtualization-based Security will have VBS enabled by those updates.
  3. Memory integrity allows only trusted kernel-mode code and drivers to run.
  4. Protection helps prevent attackers from compromising the Windows kernel and core OS functions.
  5. Deployment occurs via patches, shifting fleet security posture between update cycles.
  6. Previously disabled memory integrity settings and policies remain unchanged during rollout.
  7. Organizations can still configure and enable memory integrity using existing management tools.
  8. Windows evaluates hardware capabilities, compatibility, and performance before enabling protections.
  9. Microsoft acknowledges readiness checks may miss incompatible or unusual kernel drivers.
  10. Memory integrity is required to support hotpatch updates that install without rebooting.

TAKEAWAYS:

  1. Plan for a notable security baseline shift tied directly to routine patching cadence.
  2. Verify hardware and driver compatibility now to avoid surprises from eligibility gating.
  3. Keep governance intact: explicit disablement decisions won’t be overridden automatically.
  4. Treat uncommon kernel-level software as a special risk needing manual validation.
  5. Enabling memory integrity also unlocks rebootless hotpatch servicing benefits.

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira

Source: Help Net Security

Author: Mirko Zorz

URL: https://www.helpnetsecurity.com/2026/09/02/sift-open-source-secret-scanning/

ONE SENTENCE SUMMARY:

Sift is an open-source CLI that rapidly scans enterprise storage and collaboration platforms for secrets, with resumable runs and optional LLM filtering.

MAIN POINTS:

  1. Sift searches for passwords, API keys, and sensitive data across many enterprise locations.
  2. Targeted sources include disks, Windows shares, AD domains, SharePoint, OneDrive, Teams, Slack, Jira, Confluence.
  3. Built by Stratus Security for real penetration tests, then released publicly for free.
  4. Tool found thousands of credentials in Jira comments missed by years of prior testing.
  5. Guidance changed to scan all services equally; clean file shares don’t imply overall cleanliness.
  6. Benchmarks on synthetic data show Sift faster than Snaffler across multiple scenarios.
  7. Processor time and especially memory usage were substantially lower for Sift in tests.
  8. Unlimited default throughput can overload servers; flags allow thread and read-rate throttling.
  9. Checkpoints enable interrupted scans to resume near the stopping point, avoiding full restarts.
  10. Plain JSON detection rules and SHA256 verification compensate for unsigned release binaries.

TAKEAWAYS:

  1. Comprehensive secret discovery requires scanning collaboration tools, not just file shares.
  2. Performance and memory efficiency can make large-scale secret scanning more operationally feasible.
  3. Throttling controls are essential to prevent production outages and scan cancellations.
  4. Local LLM filtering via Ollama can reduce false positives without data leaving the environment.
  5. Open-source longevity depends on active maintainers and community contributions; verify downloads carefully.

Why a cryptographic inventory is key for addressing the quantum computing threat

Source: Tenable Blog

Author: Christopher Day

URL: https://www.tenable.com/blog/why-a-cryptographic-inventory-is-key-for-addressing-the-quantum-computing-threat

ONE SENTENCE SUMMARY:

Quantum threats already endanger data via HNDL, requiring cryptographic inventories and phased post-quantum migration with continuous verification.

MAIN POINTS:

  1. Adversaries harvest encrypted traffic now to decrypt later using future quantum capabilities.
  2. Shor’s Algorithm will break RSA, ECC, and Diffie-Hellman on sufficiently powerful quantum computers.
  3. Symmetric crypto is more resilient; AES-256 remains strong despite Grover’s speedup.
  4. Primary risk concentrates in key exchange and digital signatures underpinning TLS, SSH, and PKI.
  5. Executive Order 14412 accelerates federal PQC timelines and elevates crypto weaknesses as vulnerabilities.
  6. FAR-directed contractor requirements will mandate NIST FIPS post-quantum standards by 2030.
  7. Cryptographic Bills of Materials (CBOMs) enable automated crypto asset discovery across dependencies.
  8. Global regulators converge on comprehensive cryptographic inventory as prerequisite for orderly migration.
  9. Recommended operational phases are discovery, prioritization, remediation with crypto-agility, and verification.
  10. Exposure-management integration can track TLS/SSH weaknesses, PQC adoption, and certificate configuration issues.

TAKEAWAYS:

  1. Treat post-quantum readiness as an immediate operational program, not a future-only upgrade.
  2. Build complete visibility of algorithms, protocols, and dependencies before planning migration work.
  3. Prioritize systems handling long-lived sensitive data most vulnerable to retrospective decryption.
  4. Implement hybrid and crypto-agile configurations to swap algorithms without recompiling when standards evolve.
  5. Enforce continuous scanning to prevent regressions back to quantum-vulnerable configurations after changes.

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Source: Rapid7 Cybersecurity Blog

Author: Rapid7

URL: https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild

ONE SENTENCE SUMMARY:

PaperCut NG/MF face active zero-day exploitation via auth bypass and unsafe class loading, enabling database-triggered RCE; patch immediately and restrict access.

MAIN POINTS:

  1. PaperCut confirmed active exploitation and customer incidents, treating it as a security emergency.
  2. Exploit chain comprises CVE-2026-81578 (auth bypass) and CVE-2026-82078 (unsafe dynamic class loading).
  3. CVSSv4 scores rate the issues High (8.8) and Critical (9.4).
  4. All PaperCut NG/MF versions are considered potentially impacted pending further vendor validation.
  5. Internet-exposed PaperCut Application Servers should be prioritized for immediate remediation and access restriction.
  6. Tapestry “complex direct” requests bypass checks by displaying Error/Exception while executing admin components.
  7. Unauthenticated requests target ConfigEditor and UserList endpoints via crafted POST URIs.
  8. Attackers modify external user-lookup settings to point at malicious JDBC URLs and SQL.
  9. Derby foreignViews can chain to H2 INIT, creating triggers that execute OS commands via Nashorn.
  10. Emergency patches released for versions 25/26; first patch version is insufficient—apply the second.

TAKEAWAYS:

  1. Deploy the latest emergency patch builds for v25/v26, and monitor for v24 updates.
  2. Enforce network controls limiting PaperCut web access to trusted IP ranges only.
  3. Hunt for pc-app.exe-related suspicious activity and unexpected IDS/EDR alerts on the server.
  4. Review PaperCut server.log integrity; investigate missing, truncated, or deleted logs.
  5. Check server.log for “No suitable driver” and “Database error… VALUES CAST” indicators.

Claude Skill 02: Create Sigma Rules

Source: Feedly Blog

Author: Josh Darby MacLellan

URL: https://feedly.com/ti-essentials/posts/claude-skill-02-create-sigma-rules

ONE SENTENCE SUMMARY:

A free Claude Skill converts threat reports, documentation, or logs into validated, telemetry-aware draft Sigma rules with sourced evidence labeling.

MAIN POINTS:

  1. Skill generates Sigma drafts from advisories, reports, tool docs, behavior descriptions, or single log lines.
  2. Environment profile tailors rules to collected telemetry and records defaults as explicit assumptions.
  3. Produces four artifacts: Sigma rule, converted query, per-rule validation note, package summary.
  4. First run builds organizational profile covering SIEM backend, telemetry, noise tolerance, and admin-tool FPs.
  5. Interprets inputs differently; tool documentation requires user-stated misuse instead of invented adversarial framing.
  6. Splits content into one behavior per rule, ranks by telemetry availability, and caps output at three.
  7. Tags abstraction with stp.N, prioritizing durable behaviors over short-lived IOC matches.
  8. Labels each condition as SOURCED, GENERIC, or INFERRED; inferred conditions cannot narrow detections.
  9. Writes metadata first, then three logic layers (anchor/invariant/discriminator) plus evasion-focused resilience record.
  10. Validates via attack_check.py, sigma check, sigma convert, and grouping check; reads converted query for correctness.

TAKEAWAYS:

  1. Telemetry-first filtering prevents drafting detections you cannot actually run in your environment.
  2. Evidence-ledger labeling makes assumptions reviewable and blocks stealthy narrowing via inference.
  3. Layered selections enable tuning without discarding the technique’s core invariant signal.
  4. Multi-step validation catches spec, ATT&CK, conversion, and backend-grouping pitfalls sigma-cli may miss.
  5. Packaged outputs (rules, queries, notes, summary, profile) support faster review, retrohunts, and safer promotion.

How to build an exposure management program the business trusts: Lessons from Tenable’s CSO

Source: Tenable Blog

Author: Robert Huber

URL: https://www.tenable.com/blog/how-to-build-an-exposure-management-program-the-business-trusts-lessons-from-tenables-cso

ONE SENTENCE SUMMARY:

Tenable replaced siloed tools with AI-driven exposure management, unifying data to quantify business risk, streamline remediation, and secure AI adoption.

MAIN POINTS:

  1. Security tool sprawl created fragmented workflows, inconsistent KPIs, and duplicated remediation efforts.
  2. Data silos prevented holistic, accurate cyber-risk assessment across Tenable’s expanding attack surface.
  3. Board reporting failed when operational metrics didn’t translate into business impact.
  4. Executives repeatedly asked two questions: “Are we secure?” and “How do we compare?”
  5. Engineering teams struggled to prioritize fixes when handed many disconnected security reports.
  6. Rapid internal AI adoption expanded exposure, demanding faster, context-rich risk decisions.
  7. Tenable restructured vulnerability management into a centralized exposure management function without adding headcount.
  8. A single exposure policy broadened scope beyond CVEs to misconfigurations and identity weaknesses.
  9. Build-versus-buy analysis favored SaaS integration; Tenable acquired Vulcan Cyber to accelerate consolidation.
  10. “Bob’s simple metrics” used red/yellow/green, asset tagging, root-cause “big rocks,” and tailored SLAs.

TAKEAWAYS:

  1. Consolidating security telemetry into one platform enables a unified, enterprise-wide exposure picture.
  2. Communicating risk in business terms builds trust with the C-suite and board.
  3. Central triage reduces cross-team friction and gives specialists time back for higher-value security work.
  4. Contextual asset-to-revenue mapping makes prioritization defensible and aligned with business outcomes.
  5. Operating at AI-era speed requires automation and workflows, not manual dashboard pivoting.

Tailcat – Like netcat, but over Tailscale’s data plane

Source: Hacker News

Author: unknown

URL: https://github.com/tailscale/tailcat

ONE SENTENCE SUMMARY:

Tailcat provides netcat-like, end-to-end WireGuard tunnels using Tailscale’s data plane and DERP, exchanging tokens out-of-band without control-plane accounts.

MAIN POINTS:

  1. Tailcat reuses Tailscale components but operates entirely without Tailscale’s control plane.
  2. Connection metadata is shared out-of-band via a short, token-like “ConnBlob” string.
  3. Traffic is always WireGuard-encrypted end-to-end, bootstrapped initially through DERP relays.
  4. magicsock attempts NAT traversal to upgrade from DERP relay to direct peer-to-peer UDP.
  5. Runs fully in userspace without root, avoiding route, DNS, TUN/TAP, or system network changes.
  6. CLI and Go library are provided; library import path is github.com/tailscale/tailcat.
  7. Supports stdin/stdout piping, TCP port forwarding to localhost, SOCKS5 proxying, and exit-node mode.
  8. Built-in utilities include ping diagnostics, token parsing to JSON, and token resolution to embed DERP info.
  9. Tokens derive from WireGuard keys; ephemeral keys are single-run, saved keys provide stable addresses.
  10. DNS TXT records can publish tokens, enabling name-based access and allowlisted, pre-authenticated SSH exposure.

TAKEAWAYS:

  1. Tailcat enables secure ad-hoc connectivity without accounts, admin privileges, or network reconfiguration.
  2. DERP provides rendezvous and fallback relay; direct UDP often follows via hole-punching.
  3. Stable tokens are convenient but increase exposure unless client identities are restricted with --allow.
  4. Publishing tokens in DNS plus fixed DERP regions enables durable, globally reachable “hidden” services.
  5. Hosted public DERP relays are free but rate-limited, best-effort, and not guaranteed stable long-term.