Category: InfoSec

Pricing your bad days and how to build an economic model for security decisions

Source: Help Net Security

Author: Mirko Zorz

URL: https://www.helpnetsecurity.com/2026/10/08/ivan-milenkovic-qualys-cyber-risk-quantification/

ONE SENTENCE SUMMARY:

Security leaders should quantify cyber risk in money via loss-scenario models, prioritize remediation by value-at-risk, and report consistently to boards, CFOs, and underwriters.

MAIN POINTS:

  1. Many security metrics lack a financial anchor, leaving boards unable to assess value delivered.
  2. Effective models start with business loss scenarios, then map down to driving assets.
  3. Assign a loss range to each scenario, improving estimates with real outcomes over time.
  4. Prefer system-sourced inputs; distrust numbers manually adjusted or curated by humans.
  5. Prioritization should reflect value at risk, not technical severity scores alone.
  6. Compare exposures on revenue-impacting systems versus low-value assets like unused test servers.
  7. Board reporting should stay above CVE detail, focusing on enterprise control scaling and residual loss.
  8. Demonstrate “nothing happened” value through measurable changes: exposure windows, overdue risk, tested controls.
  9. CFOs expect spreadsheet-ready ranges, likelihoods, spend options, and consequences of inaction with an owner.
  10. A single underlying model can serve board decisions and insurance underwriting with different evidence depth.

TAKEAWAYS:

  1. Reverse the usual approach: model losses first, then trace vulnerabilities to business impact.
  2. Use value-at-risk to depoliticize remediation decisions and justify resource allocation.
  3. Prove prevention by tracking consistent, time-series indicators tied to key scenarios.
  4. Translate security into finance language: ranges, probabilities, and decision-linked investment outcomes.
  5. Align board narratives and underwriting submissions so claims-time scrutiny matches reported reality.

How AI can fix cybersecurity compliance: From dashboards to continuous execution

Source: Help Net Security

Author: Help Net Security

URL: https://www.helpnetsecurity.com/2026/10/08/espresso-labs-ai-cybersecurity-compliance/

ONE SENTENCE SUMMARY:

Manual compliance wastes effort proving security; AI-native platforms continuously enforce controls, collect evidence automatically, and match machine-speed attackers.

MAIN POINTS:

  1. Proving compliance often consumes more effort than improving actual security outcomes.
  2. CMMC Level 2 assessment costs exclude implementation, driving total program expenses far higher.
  3. DoW paused CMMC Phase 2, yet contractors still must self-assess and comply.
  4. Frameworks like SOC 2 and ISO require continuous control operation plus evidence production.
  5. Compliance functions like an endless assembly line, not a one-time checklist.
  6. Organizations commonly stitch 20+ tools, providers, auditors, and coordinators into fragile workflows.
  7. Traditional GRC dashboards document controls but cannot deploy, enforce, or remediate them.
  8. Adversaries automate intrusions, shrinking breach timelines to minutes or even seconds.
  9. Many successful attacks exploit basics already required: MFA, hardened ports, and patching.
  10. AI-native platforms execute controls, detect drift, remediate issues, and generate evidence continuously.

TAKEAWAYS:

  1. Shifting evidence collection into daily operations dramatically reduces audit scramble and staleness.
  2. Enforced controls every day make organizations harder targets than quarterly checkbox reviews.
  3. Automation should close gaps immediately and escalate only judgment-heavy decisions to humans.
  4. Consolidating mappings across frameworks reduces duplicate work while improving real-time posture visibility.
  5. SMBs can achieve mature security by pairing AI-driven execution with expert oversight, without proportional headcount.

The Credential Layer Is Expanding Faster Than Security Teams Can See It

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/10/the-credential-layer-is-expanding.html

ONE SENTENCE SUMMARY:

Explosive software and AI-agent growth expands credential sprawl; unified detection across repos, endpoints, and collaboration enables contextual risk control enterprise.

MAIN POINTS:

  1. GitGuardian frames credential-layer security as Detect, Remediate, and Prevent, starting with discovery.
  2. Commit volume is surging, driving more infrastructure, integrations, automations, and authentication points.
  3. Public GitHub saw 28.65M new hardcoded secrets in 2025, up 34% YoY.
  4. AI-service credential leaks grew 81%, reflecting rapid adoption of new tools and agents.
  5. Perimeters don’t contain credentials; secrets migrate across accounts, devices, repos, and knowledgebases.
  6. Internal repositories are about six times likelier than public ones to contain secrets.
  7. Collaboration platforms originate roughly 28% of secret incidents outside source-code repositories.
  8. Infostealers shifted to developer laptops, turning endpoints into supply-chain entry points.
  9. Adversaries exploit boundary-crossing credentials; compromised credentials caused 22% of initial access.
  10. Contextual inventory needs validity, ownership, permissions, dependency mapping, and fingerprinted exposure histories.

TAKEAWAYS:

  1. Establish continuous credential discovery before remediation or prevention programs can succeed.
  2. Correlate findings across source control, public exposure, endpoints, and collaboration systems for full visibility.
  3. Prioritize secrets using enriched context: still-valid, high-privilege, widely-exposed, workload-dependent credentials.
  4. Treat developer machines and AI agent tooling as first-class credential surfaces requiring monitoring.
  5. Measure secrets-management coverage against the total credential population, not just vault-held records.

Post Quantum Cryptography is Not an Algorithm Upgrade

Source: Cloud Security Alliance

Author: unknown

URL: https://cloudsecurityalliance.org/blog/2026/10/05/post-quantum-cryptography-is-not-an-algorithm-upgrade

ONE SENTENCE SUMMARY:

Successful PQC migration requires distinguishing NIST algorithms, mapping crypto dependencies to data and systems, prioritizing risk, proving production usage.

MAIN POINTS:

  1. Clarify ML-KEM, ML-DSA, SLH-DSA roles; they aren’t interchangeable with FIPS numbers.
  2. FIPS 203 ML-KEM provides key establishment, enabling symmetric encryption like AES.
  3. FIPS 204 ML-DSA replaces classical signature uses such as RSA signatures and ECDSA.
  4. FIPS 205 SLH-DSA adds hash-based signatures, improving cryptographic diversity beyond lattices.
  5. FIPS 202 defines SHA-3 hashing, not a PQC migration algorithm.
  6. Shor breaks RSA/DH/ECC; Grover only reduces symmetric margins, focusing urgency on public-key.
  7. Inventorying “RSA-2048” is insufficient; prioritize based on what data and services it protects.
  8. Harvest-now-decrypt-later makes long-lived confidentiality a present risk despite uncertain QC timelines.
  9. Signature risks differ from confidentiality, impacting PKI, secure boot, device identity, and roots of trust.
  10. Crypto agility requires discoverability, changeability, and verification of actual negotiated production cryptography.

TAKEAWAYS:

  1. Begin with data lifetimes and business impact, then select PQC mechanisms accordingly.
  2. Treat confidentiality migration and signature/PKI modernization as distinct timelines and engineering efforts.
  3. Build dependency context across apps, protocols, keys, suppliers, and hardware lifecycles.
  4. Prove operational reality: negotiated algorithms, presented certificates, enforced policies, and drift detection.
  5. Plan for hybrid transition and supplier constraints within procurement and product lifecycle management.

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html

ONE SENTENCE SUMMARY:

Threat actors exploited Citrix NetScaler CVE-2026-88772 to gain root access, install stealth web shells, tunnel internally, and scale mass exploitation.

MAIN POINTS:

  1. Mandiant and Google observed active exploitation in September 2026 across North America and Europe.
  2. Targets spanned government, finance, technology, education, and legal/professional services organizations.
  3. CVE-2026-88772 enables authentication bypass and NSPPE termination leading to initial root access.
  4. Vulnerability is a DTLS-handling memory overflow in NetScaler Packet Processing Engine (NSPPE).
  5. Malformed DTLS record headers corrupt heap boundaries, enabling arbitrary root-level shellcode execution.
  6. Initial installer modifies httpd.conf to execute .deb files as PHP scripts.
  7. Web shells staged in /netscaler/gui/vpn/scripts/linux using deceptive .deb and .sig extensions.
  8. Covert hook maps .ico requests to same-basename .sig PHP web shells under /var/netscaler path.
  9. Web shells persist by altering /bin/sh permissions and rebooting the appliance.
  10. GreyNoise reported mass recon evolving into mass exploitation, including botnet recruitment and access brokering.

TAKEAWAYS:

  1. Patch and validate NetScaler ADC/Gateway updates immediately for CVE-2026-88772 exposure.
  2. Hunt for suspicious httpd.conf changes enabling .deb or .sig execution via mod_php.
  3. Investigate anomalous /vpn/media/*.ico requests producing large responses or long processing times.
  4. Check for unauthorized files in NetScaler GUI VPN scripts directories with misleading extensions.
  5. Assume edge-device compromise can bypass EDR and enable internal recon, lateral movement, and credential theft.

The Nightmare Is Over: World’s Longest-Running DDoS Service Finally Shut Down 

Source: CQURE Academy

Author: Asia

URL: https://cqureacademy.com/blog/the-nightmare-is-over-worlds-longest-running-ddos-service-finally-shut-down/

ONE SENTENCE SUMMARY:

The FBI seized NightmareStresser domains in Operation PowerOFF, disrupting a massive DDoS-for-hire service while highlighting ongoing booter-market resilience.

MAIN POINTS:

  1. NightmareStresser operated as an anonymous DDoS “booter/stresser” accessible with cryptocurrency payments.
  2. FBI domain seizures replaced service sites with an official government seizure banner.
  3. DOJ stated the service was active since at least 2022, possibly earlier per researchers.
  4. Authorities attribute hundreds of thousands of DDoS attacks worldwide to the platform.
  5. Peak growth around 2025 reportedly reached nearly one million registered users.
  6. Capability estimates suggested 3,000–4,000 attacks could be launched per hour.
  7. Targeting rules oddly excluded government, education, and hospital domains.
  8. The takedown was part of Operation PowerOFF, a multinational anti-booter initiative.
  9. Over eight years, U.S. actions charged 12 facilitators and seized 100+ booter domains.
  10. Officials emphasize pursuing both administrators and users to deter DDoS-for-hire demand.

TAKEAWAYS:

  1. DDoS-for-hire platforms drastically lower the barrier to entry for cybercrime.
  2. Coordinated international enforcement can meaningfully disrupt large-scale illicit infrastructures.
  3. Market vacuums after takedowns often enable surviving or new services to expand quickly.
  4. Domain seizures are visible disruption, but ecosystems can reconstitute elsewhere rapidly.
  5. Sustained deterrence requires targeting operators, payment flows, and end-user purchasers.

TeamViewer urges users to patch severe flaws “as soon as possible”

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/

ONE SENTENCE SUMMARY:

TeamViewer urged immediate updates to version 15.82, fixing five high-severity flaws enabling remote bypass, code execution, and privilege escalation.

MAIN POINTS:

  1. Vendor issued a rare advisory urging customers to patch immediately.
  2. CVE-2026-92370 allows remote session access control bypass via improper access control.
  3. Affected products include TeamViewer Full Client and Host across Windows, Linux, and macOS.
  4. Unauthorized actions could lead to remote code execution on targeted systems.
  5. CVE-2026-19743 addresses a path traversal vulnerability.
  6. CVE-2026-92368 fixes a heap-based buffer overflow weakness.
  7. CVE-2026-92369 resolves a TOCTOU race condition issue.
  8. CVE-2026-92371 corrects improper path validation enabling escalation to SYSTEM/root.
  9. Company stated no known public exploits or active in-the-wild exploitation.
  10. Attackers often abuse remote access tools like TeamViewer for malware and ransomware deployment.

TAKEAWAYS:

  1. Upgrade endpoints to TeamViewer 15.82 or supported maintenance/legacy releases immediately.
  2. Prioritize mitigation of remote access control bypass risks due to potential RCE.
  3. Treat local-to-remote execution and privilege escalation paths as high-impact operational threats.
  4. Monitor TeamViewer usage aggressively because legitimate tools are frequently abused by criminals.
  5. Incorporate vendor advisories into rapid patch workflows, given TeamViewer’s history of security incidents.

WSL containers are generally available on Windows

Source: Help Net Security

Author: Anamarija Pogorelec

URL: https://www.helpnetsecurity.com/2026/09/30/microsoft-wsl-containers-available/

ONE SENTENCE SUMMARY:

Microsoft’s generally available WSL containers bring Linux container workflows to Windows with Intune governance, tooling integrations, and Defender visibility, though Compose support remains missing.

MAIN POINTS:

  1. WSL containers are now generally available for running Linux containers on Windows.
  2. Installation occurs via wsl --update or Microsoft’s GitHub releases.
  3. Administrators can disable the feature or constrain image sources for security.
  4. Intune adds controls to enable/disable WSL containers on managed endpoints.
  5. Registry allow-listing restricts image pulls to approved container registries.
  6. A new CLI, wslc.exe, includes container.exe alias for familiar commands.
  7. Windows apps can invoke Linux containers through a provided API.
  8. Added functionality includes restart, file copy, environment state checks, and health checks.
  9. VS Code dev containers and Aspire integrate with WSL containers as a runtime.
  10. Defender for Endpoint correlates container process, file, and network telemetry to the Windows host.

TAKEAWAYS:

  1. Governance improves by managing WSL container availability and registries through Intune.
  2. Development teams gain container tooling parity via CLI, API, and IDE/runtime integrations.
  3. Security investigations are streamlined with Defender’s host-linked container telemetry.
  4. Performance claims cite faster Windows-file access, but lack disclosed benchmarking conditions.
  5. Compose support is the largest current limitation, with compatibility a stated goal.

From Models to MCP Servers, Skills, and Plugins: Rethinking Trust in the AI Supply Chain

Source: Cloud Security Alliance

Author: unknown

URL: https://www.akto.io/blog/ai-supply-chain-security

ONE SENTENCE SUMMARY:

Agentic AI expands supply-chain risk from artifacts to instructions and execution, requiring continuous governance over components, inputs, permissions, and runtime actions.

MAIN POINTS:

  1. A benign npm MCP package later exfiltrated emails via a hidden update.
  2. Traditional controls help but miss instruction and agency risks unique to agents.
  3. AI supply chain includes datasets, weights, libraries, pipelines, and deployment infrastructure.
  4. Serialized model artifacts can execute code, so third-party weights resemble untrusted binaries.
  5. MCP servers shape risk through tool code, definitions, auth, and returned content.
  6. Skills combine natural-language guidance with scripts, influencing tool selection and execution.
  7. Plugins bundle multiple components, obscuring nested dependencies and external instruction sources.
  8. Agent configuration is security logic governing tools, memory, approvals, and execution behavior.
  9. Three trust decisions exist: artifact provenance, instruction influence, and execution authority.
  10. Runtime gaps enable tool poisoning, rug pulls, and malicious tool outputs to trigger data leaks.

TAKEAWAYS:

  1. Treat approval as time-bound; re-review whenever components, definitions, or references change.
  2. Maintain an AI bill of materials capturing versions, owners, permissions, and deployment contexts.
  3. Constrain blast radius with scoped identities, least-privilege credentials, and restricted environments.
  4. Evaluate full packages: instructions, scripts, metadata, dependencies, and remote content sources.
  5. Apply runtime policy enforcement plus tracing to stop violations and support rapid containment.

How to Turn a Risk Appetite Statement Into a Usable Curve

Source: Rivial Security Blog

Author: Randy Lindberg

URL: https://www.rivialsecurity.com/blog/risk-appetite-statement-to-risk-tolerance-curve

ONE SENTENCE SUMMARY:

Translate board cyber risk appetite statements into quantified tolerance curves linking loss impact and likelihood, enabling prioritized, defensible security decisions.

MAIN POINTS:

  1. Policy appetite sentences rarely influence security because they cannot evaluate specific assessed risks.
  2. Risk appetite expresses board philosophy, whereas risk tolerance defines operational acceptability thresholds.
  3. A tolerance curve connects likelihood and dollar impact into one acceptability boundary.
  4. Rare, high-impact losses and frequent, low-impact losses require different tolerance treatments.
  5. Convert percent-of-net-worth appetite into a dollar maximum loss figure.
  6. Anchor the maximum loss to a convention like 1% annual likelihood for curve calibration.
  7. Extend the curve downward as likelihood increases, reducing tolerable loss amounts.
  8. Presenting the implied curve to the board drives true ownership and possible appetite revision.
  9. Plot each system’s quantified risk against the curve to identify out-of-tolerance exposures.
  10. Use curve exceedance to justify budgets, satisfy examiner scrutiny, and detect risk drift over time.

TAKEAWAYS:

  1. Turning appetite into a curve makes board policy actionable for real-world risk decisions.
  2. Simple math can operationalize tolerance: dollars from net worth, likelihood anchor, then slope.
  3. Visualizing systems against tolerance removes prioritization arguments and clarifies remediation order.
  4. Board review of the curve converts passive approval into an explicit, defensible mandate.
  5. Continuous monitoring against the curve reveals control decay and scope changes before surprises occur.

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html

ONE SENTENCE SUMMARY:

Dutch police arrested alleged ShinyHunters member Pepijn van der Stap as group claims FBI jobs hack via WAF bypass recently.

MAIN POINTS:

  1. Authorities confirmed arrest of a 24-year-old Amsterdam man tied to ShinyHunters investigations.
  2. Police stated the suspect will appear at Rotterdam District Court on September 29, 2026.
  3. Journalists Brian Krebs and DataBreaches.Net identified him as Pepijn van der Stap “Umbreon.”
  4. Reports say the arrest occurred September 15, 2026, though officials withheld specifics.
  5. Earlier, he was apprehended in 2023 for data theft and extortion activities.
  6. Employment history included cybersecurity firm Hadrian and volunteering with the Dutch DIVD.
  7. Van der Stap described intense paranoia from maintaining appearances while balancing lawful and illegal work.
  8. LinkedIn lists him as offensive security lead at Dutch company Neo Security.
  9. ShinyHunters claimed responsibility for hacking apply.fbijobs.gov and stealing terabytes of sensitive data.
  10. Investigators now assess a URL-encoding WAF bypass for CVE-2026-35273, not an Oracle PeopleSoft zero-day.

TAKEAWAYS:

  1. Dual-role security professionals can present elevated insider-risk and vetting challenges.
  2. Criminal groups may stage high-profile breaches as “marketing” to shape narratives and attention.
  3. Treat announced “zero-days” skeptically until validated by technical evidence and independent assessment.
  4. Web application firewalls remain vulnerable to evasion techniques like encoding tricks and rule bypasses.
  5. Defensive teams should prioritize monitoring for large-scale exfiltration from public-facing recruitment portals.

Autonomous Remediation Is Already Running at Enterprise Scale

Source: Qualys Security Blog

Author: Sean Martin

URL: https://blog.qualys.com/qualys-insights/2026/09/29/autonomous-remediation-enterprise-scale-black-hat-2026-sumedh-thakar

ONE SENTENCE SUMMARY:

Qualys CEO Sumedh Thakar argues security outcomes now demand AI-speed detection, hyper-prioritization, and autonomous remediation measured in seconds.

MAIN POINTS:

  1. Scanning and fixing cycles shrank from 90-day windows to roughly 90 seconds.
  2. Core security questions remain constant: inventory, assess, prioritize, and remediate.
  3. “Dashboard tourism” occurs when teams watch metrics instead of fixing issues.
  4. CISA’s three-day remediation directive pressures agencies toward faster execution.
  5. Zero-day response expectations increasingly assume a 24-hour containment or remediation window.
  6. Autonomous, AI-driven exploitation requires automation rather than expanding headcount.
  7. AI-speed detection must precede remediation, or 24-hour goals become unattainable.
  8. Hyper-prioritization focuses on real exploitability within existing controls, not theoretical scores.
  9. Autonomous remediation favors minimal effective changes, using mitigations or patches when necessary.
  10. Qualys uses AI-based patch reliability scoring and has autonomously deployed tens of millions of patches.

TAKEAWAYS:

  1. Measure security performance by exposure window, not vulnerability counts.
  2. Automating detection-to-fix is essential as disclosure and exploitation timelines compress.
  3. Exploitability testing can radically reduce the actionable vulnerability backlog.
  4. Prefer compensating controls when sufficient; apply patches only when required and dependable.
  5. CISOs should brief boards in business-risk terms via a Risk Operations Center model.

NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)

Source: Help Net Security

Author: Zeljka Zorz

URL: https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/

ONE SENTENCE SUMMARY:

Citrix NetScaler zero-day exploitation shifted from stealthy attacks to widespread scanning after PoC release, threatening thousands of unpatched internet-facing appliances.

MAIN POINTS:

  1. Internet-exposed NetScaler ADC/Gateway compromises are escalating rapidly across many organizations.
  2. Attacks evolved from targeted zero-day use into opportunistic “spray and pray” exploitation.
  3. watchTowr’s root-cause analysis and CVE-2026-88771 PoC accelerated attacker activity.
  4. CVE-2026-88771 is remotely exploitable on unpatched devices using default configuration.
  5. Citrix issued patches for eight critical/high vulnerabilities, confirming active zero-day exploitation.
  6. CVE-2026-88771 and CVE-2026-88772 were both exploited before public disclosure.
  7. Citrix provided a compromise-detection script but warned it may miss changing attacker TTPs.
  8. GreyNoise observed pre-disclosure exploitation attempts revealing webshell hiding and log tampering steps.
  9. Lupovis saw immediate mass scanning, using log poisoning and exfiltration to 138.199.200.90.
  10. Censys counts ~42,000 exposed hosts; Beaumont estimates under 10% patched and tracks 100+ victims.

TAKEAWAYS:

  1. Patch NetScaler ADC/Gateway immediately, assuming active probing if internet-exposed.
  2. Hunt for POST /nf/auth/doAuthentication.do bodies containing pitboss PPE unexpectedly died NSPPE.
  3. Monitor DNS for outbound lookups ending instances.httpworkbench.com as a compromise signal.
  4. Expect unique per-victim webshells, limiting remote detection without local telemetry.
  5. Prepare for ongoing risk from CVE-2026-88772 since no public PoC exists yet.

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Source: BleepingComputer

Author: Lawrence Abrams

URL: https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/

ONE SENTENCE SUMMARY:

Two unpatched Citrix NetScaler RCE zero-days are reportedly exploited worldwide, prompting private agency warnings, shutdown advice, and imminent patch releases.

MAIN POINTS:

  1. Unpatched Citrix NetScaler zero-days are reportedly exploited in active attacks.
  2. IT suppliers privately urged some organizations to shut down NetScaler appliances immediately.
  3. Law enforcement, CERTs, and national agencies reportedly contacted targets about the threat.
  4. watchTowr corroborated credible reports of multiple in-the-wild NetScaler RCEs.
  5. The incident is explicitly unrelated to August-disclosed CVE-2026-19490 and CVE-2026-19489.
  6. CVE-2026-19490 is an auth bypass already exploited after a public PoC emerged.
  7. CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog September 9.
  8. NCSC-NL described two critical zero-days, each independently enabling remote code execution.
  9. One vulnerability reportedly allows placing shellcode directly into memory.
  10. No CVEs, advisories, affected versions, IoCs, or mitigations are publicly available yet.

TAKEAWAYS:

  1. Expect exploitation to intensify once Citrix publishes patches and technical details.
  2. Prepare now for potential downtime to patch quickly when releases arrive next week.
  3. Reduce exposure by taking Internet-facing NetScaler systems offline where feasible.
  4. Restrict access to trusted networks/IPs, especially for management interfaces.
  5. Monitor for vendor and national CSIRT updates since official IoCs are currently unavailable.

Microsoft: Recent Windows updates cause desktop loading issues

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/

ONE SENTENCE SUMMARY:

Microsoft warns August 2026 Windows preview and later updates can cause black screens, mainly on AVD with FSLogix, mitigated via Explorer restart or KIR.

MAIN POINTS:

  1. Microsoft confirmed desktop loading failures and black screens after August 2026 preview updates.
  2. Issue primarily impacts Azure Virtual Desktop hosts running FSLogix user-profile technology.
  3. Affected users may see black screen post sign-in and no desktop access.
  4. Application event logs can show Windows Explorer crashes tied to the problem.
  5. Known affected updates include KB5120996 and KB5120998 across Windows 11 versions.
  6. Patch Tuesday updates KB5124008 and KB5122880 can also trigger the issue.
  7. Temporary workaround involves manually launching Windows Explorer to restore the session.
  8. Users can start explorer.exe via Task Manager’s “Run new task” function.
  9. Microsoft deployed a Known Issue Rollback mitigation for enterprise-managed devices.
  10. Administrators must install matching KIR Group Policy and reboot devices to apply.

TAKEAWAYS:

  1. Prioritize monitoring AVD+FSLogix environments after Windows preview or cumulative updates.
  2. Keep a documented helpdesk procedure for starting explorer.exe during black-screen incidents.
  3. Use KIR Group Policy as the fastest enterprise mitigation until a permanent fix ships.
  4. Track specific KBs in change management to correlate rollout timing with desktop failures.
  5. Expect Microsoft to reintroduce functionality later via a future Windows update resolution.

What to do first when you get 90 days to secure AI agent data

Source: Help Net Security

Author: Mirko Zorz

URL: https://www.helpnetsecurity.com/2026/09/24/kelly-herrell-nol8-ai-agent-data-security/

ONE SENTENCE SUMMARY:

AI agents increase organizational exposure by rapidly aggregating sensitive context, requiring deterministic, in-path data governance controls over agent interactions.

MAIN POINTS:

  1. Focusing on the data path reveals true exposure beyond declared agent inventories.
  2. Key questions include reachable data, context inputs, tool/model calls, and outputs.
  3. Most organizations can’t evidence every boundary-crossing interaction, only sampled logs.
  4. Ticketing systems often contain overlooked sensitive artifacts like credentials and incident narratives.
  5. CRM, shared drives, chats, knowledge bases, and collaboration tools store rich institutional context.
  6. Human workflow friction once limited correlation; agents remove friction and implicit safeguards.
  7. AI increases speed, scale, and ease of discovery, not the inherent sensitivity of data.
  8. A 90-day plan should start with mapping paths and measuring sensitive data flows.
  9. Postpone identity overhauls, full data classification, masked replicas, and per-agent code guardrails.
  10. Resolve business-security tension by redacting sensitive fields in-flight rather than blocking access.

TAKEAWAYS:

  1. Measure exposure by what data actually crosses boundaries, not what deployments claim.
  2. Treat “authorized to access” as separate from “appropriate to see or disclose.”
  3. Implement a deterministic policy enforcement point that cannot be bypassed in the data path.
  4. Prioritize rapid, runtime enforcement on highest-risk flows before broader governance programs.
  5. Avoid controls embedded in each agent’s codebase; centralized enforcement prevents “forgotten” protections.

CQURE Hacks #83: Attack on Active Directory Certificate Services (AD CS) – ESC16

Source: CQURE Academy

Author: Daniel

URL: https://cqureacademy.com/blog/cqure-hacks-83-attack-on-active-directory-certificate-services-ad-cs-esc16/

ONE SENTENCE SUMMARY:

ESC16 exploits missing SID extensions and weak mapping to impersonate accounts via UPN changes, enabling domain compromise through AD CS.

MAIN POINTS:

  1. ESC16 arises when a CA omits the SID security extension in certificates.
  2. SID extension normally binds certificates strongly to specific Active Directory accounts.
  3. Without SID binding, weak certificate mapping can rely on UPN identity fields.
  4. A low-privileged user, bob, can modify his own userPrincipalName attribute.
  5. Bob changes his UPN to Administrator before requesting a standard user certificate.
  6. The CA issues a certificate embedding Administrator UPN, yet tied to Bob’s SID.
  7. Bob restores his original UPN after obtaining the misbound certificate.
  8. KDC maps the certificate to the real Administrator account during authentication.
  9. Attacker obtains an Administrator TGT and recovers the Administrator NT hash.
  10. With Domain Admin rights, DCSync retrieves the krbtgt account hash.

TAKEAWAYS:

  1. Enforce SID security extension issuance to prevent ambiguous certificate-to-account binding.
  2. Disable weak certificate mapping behaviors that allow UPN-based identity confusion.
  3. Restrict permissions to modify identity attributes like userPrincipalName.
  4. Audit AD CS templates, CA settings, and KDC mapping configurations regularly.
  5. Minor PKI misconfigurations can cascade into full Active Directory domain compromise.

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html

ONE SENTENCE SUMMARY:

Bifrost AI gateway exposes default-unauthenticated management APIs enabling unauthenticated RCE/SSRF, credential theft, and requiring urgent upgrades and key rotation.

MAIN POINTS:

  1. CVE-2026-90898 enables unauthenticated remote command execution via Bifrost management API.
  2. Issue impacts all HTTP transports versions before 2.1.0 when auth disabled by default.
  3. Attack registers a stdio MCP client using unauthenticated POST to /api/mcp/client.
  4. Bifrost executes the provided command immediately, before MCP handshake, as gateway user.
  5. Successful RCE exposes stored provider API keys and virtual keys on the gateway.
  6. Stock binary binds management API to localhost, reducing remote exposure by default.
  7. Official Docker image binds management API to 0.0.0.0, exposing it when ports published.
  8. transports/v2.1.0 blocks unauthenticated stdio client registration by returning HTTP 403.
  9. CVE-2026-86242 allows unauthenticated HTTP-path plugin download and loading; fixed in v2.0.0.
  10. Multiple recent Bifrost vulnerabilities stem from default-disabled management authentication and echo prior MCP/LiteLLM attack patterns.

TAKEAWAYS:

  1. Upgrade immediately to transports/v2.1.0 to mitigate unauthenticated MCP-stdio RCE.
  2. Enable governance.auth_config.is_enabled and enforce strong management credentials.
  3. Restrict management listener to trusted networks; avoid exposing Docker-published management ports.
  4. Assume compromise if auth was disabled with exposed management API; rotate all keys.
  5. Patch older lines carefully: v2.0.0 fixes plugin issue but not MCP RCE; 1.6.x fixes neither.

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html

ONE SENTENCE SUMMARY:

TASK#STOMP is a VBScript-orchestrated, PowerShell-based backdoor campaign enabling stealthy persistence, surveillance, credential theft, document exfiltration, and redundant C2.

MAIN POINTS:

  1. Campaign deploys a PowerShell backdoor for data theft and remote command execution.
  2. Infection begins with wscript.exe running an encoded VBScript staged on the desktop.
  3. Initial delivery vector is unclear, possibly phishing or social engineering via email.
  4. Randomized VBScript filename likely aims to evade simple name-based detections.
  5. Persistence established through scheduled tasks masquerading as legitimate Windows services.
  6. Backup persistence uses Startup folder to run msdiag.vbs at user logon.
  7. Malware kills prior instances to enforce a single active session.
  8. Stealth techniques include timestomping, hidden execution, and trace-cleanup behaviors.
  9. Two PowerShell modules provide redundancy, mutual watchdogging, and separate C2 channels.
  10. C2 domains corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz use token-authenticated communications.

TAKEAWAYS:

  1. Native Windows tooling abuse can make malicious activity resemble routine administration.
  2. Layered persistence significantly increases resilience against partial remediation.
  3. Mutual watchdog processes help maintain long-lived access despite interruptions.
  4. Collection focuses on business documents, Wi‑Fi credentials, clipboard data, and screenshots.
  5. Unusual user-facing actions (opening Iran tenders site) may indicate staging, distraction, or operator workflow.

5 ways AI is reshaping the cybersecurity job market

Source: CSO Online

Author: unknown

URL: https://www.csoonline.com/article/4224019/5-ways-ai-is-reshaping-the-cybersecurity-job-market.html

ONE SENTENCE SUMMARY:

AI automation is reshaping cybersecurity teams through consolidation, shifting analyst work to judgment, demanding AI fluency, and shrinking pipelines globally.

MAIN POINTS:

  1. LastPass dissolved dedicated vulnerability management, moving duties into IT and product security.
  2. Triage and analysis increasingly rely on AI and business intelligence tools.
  3. WEF reports 87% see AI-related vulnerabilities as fastest-growing risk category.
  4. SANS/GIAC found 74% say AI is changing security team sizes and roles.
  5. Leadership structures are consolidating, avoiding new C-level roles for AI governance.
  6. Routine GRC compliance is being automated so staff can become higher-level risk advisors.
  7. Analysts now evaluate automated findings and tune systems, not just work alert queues.
  8. Judgment has become the scarcest capability, especially validating AI outputs against business context.
  9. The “AI loop” can reinforce wrong assumptions, producing confident but flawed risk reports.
  10. Entry-level rungs are disappearing, widening skills gaps and linking workforce shortages to breaches.

TAKEAWAYS:

  1. Consolidate governance thoughtfully while ensuring accountability doesn’t overload a few leaders.
  2. Re-skill SOC staff toward validation, root-cause reasoning, and system engineering oversight.
  3. Prioritize senior judgment development to counter confidently incorrect automation at scale.
  4. Hire for balanced AI fluency—neither skepticism nor hype—aligned to real control needs.
  5. Protect junior-to-senior pathways to prevent future talent shortages becoming operational security risk.

Data center failure affects New Mexico credit union services

Source: Top Stories

Author: unknown

URL: https://www.koat.com/article/data-center-failure-affects-new-mexico-credit-union-services/73795685

ONE SENTENCE SUMMARY:

A third-party data center cooling failure triggered a Sharetec outage, disrupting New Mexico credit union access without evidence of breach.

MAIN POINTS:

  1. Cooling system failure occurred at an out-of-state third-party data center.
  2. Sharetec experienced a nationwide outage beginning Sept. 15.
  3. New Mexico credit union members faced limited account access.
  4. Service impacts differed depending on each credit union’s reliance on Sharetec.
  5. Direct deposit availability was restricted for some affected members.
  6. Cash withdrawal access was limited at certain institutions.
  7. Everyone’s Federal Credit Union handled member needs individually.
  8. Manual processing using paper records replaced automated transactions.
  9. Sharetec provided only a voicemail acknowledging connectivity issues and remediation efforts.
  10. Credit unions stated the incident was not identified as a data breach.

TAKEAWAYS:

  1. Third-party infrastructure failures can cascade into widespread financial service outages.
  2. Manual fallback procedures help maintain limited operations during prolonged vendor downtime.
  3. Customer impacts may include delayed deposits and constrained cash access.
  4. Lack of timely vendor communication increases uncertainty for affected institutions and members.
  5. Ongoing restoration timelines can remain unclear even when breaches are ruled out.

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Source: Help Net Security

Author: Zeljka Zorz

URL: https://www.helpnetsecurity.com/2026/09/17/cisco-ise-vulnerability-exploited-cve-2026-76460/

ONE SENTENCE SUMMARY:

Cisco warns CVE-2026-76460 actively exploits Cisco ISE API authentication bypass; update, hunt indicators, and reimage compromised nodes.

MAIN POINTS:

  1. Cisco confirmed active exploitation of CVE-2026-76460 in Cisco Identity Services Engine.
  2. Vulnerability is an authentication bypass caused by insufficient API endpoint authentication controls.
  3. Remote unauthenticated attackers can bypass the web management interface via crafted requests.
  4. Affected products include Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC).
  5. Impacted versions span releases 3.0 through 3.5 across deployments.
  6. Cisco provided indicators of compromise but withheld observed attack details.
  7. Investigation should review access.log for suspicious usernames on every node.
  8. If compromise suspected, re-image affected nodes and restore configurations from backups.
  9. Verify external firewall and network logs for suspicious uploads/downloads tied to affected devices.
  10. Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4.

TAKEAWAYS:

  1. Patch immediately because no workaround mitigates this actively exploited authentication bypass.
  2. Treat all cluster nodes as potentially affected and perform uniform log review.
  3. Preserve evidence by correlating device activity with external network and firewall telemetry.
  4. Plan migration away from 3.0–3.2 due to limited or ended maintenance support.
  5. Expect additional ISE/ISE-PIC security fixes, including findings from researchers and internal AI-assisted testing.

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html

ONE SENTENCE SUMMARY:

Acronis reports CVE-2026-87886 in its cPanel/WHM Backup plugin is exploited, enabling local privilege escalation via insecure permissions.

MAIN POINTS:

  1. Acronis disclosed active exploitation of a high-severity flaw in its Backup plugin.
  2. Vulnerability is tracked as CVE-2026-87886 with a CVSS score of 7.8.
  3. Root cause involves insecure file permissions enabling local privilege escalation on Linux.
  4. Attackers need low-privilege access to escalate permissions on affected deployments.
  5. Exploitation could enable unauthorized actions or arbitrary code execution impacting confidentiality and integrity.
  6. Acronis says fixes are included in version 1.9.3 HF3 and urged immediate installation.
  7. Advisory notes exploitation has been observed in limited, targeted attacks in the wild.
  8. Public details about the vulnerability’s mechanics have not been released.
  9. Attribution for the attacks and adversary objectives remain unknown.
  10. Detection timeline and duration of exploitation activity have not been clarified.

TAKEAWAYS:

  1. Patch Acronis Backup plugin installations to 1.9.3 HF3 promptly to reduce risk.
  2. Treat low-privilege footholds on cPanel/WHM servers as potential escalation paths.
  3. Prioritize monitoring for suspicious privilege changes on Linux hosting environments.
  4. Assume targeted exploitation may expand, despite currently limited reporting.
  5. Maintain rapid update processes for hosting control panel plugins due to frequent attacker interest.

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/

ONE SENTENCE SUMMARY:

CISA warns ransomware gangs are exploiting critical VMware vCenter CVE-2026-59310, urging urgent patching amid widespread global compromises online now detected.

MAIN POINTS:

  1. Broadcom patched CVE-2026-59310 in vCenter Syslog on July 29.
  2. Vulnerability is a critical directory traversal enabling unauthenticated remote code execution.
  3. Supplemental FAQ urged customers to treat remediation as an emergency.
  4. QUIRSO observed APT exploitation deploying a reverse SSH tool for persistence.
  5. Investigators found 361 compromised IPs spanning 47 countries after initial exploitation.
  6. CISA added the flaw to KEV and mandated federal remediation within three days.
  7. KEV entry was later updated, noting active abuse by ransomware groups.
  8. Shadowserver reports over 450 vCenter servers currently exposed to the internet.
  9. Attackers favor vCenter/ESXi compromise for lateral access to networks and sensitive data.
  10. CISA has tagged 26 VMware flaws exploited in five years; nine linked to ransomware.

TAKEAWAYS:

  1. Apply vCenter patches immediately when KEV-listed, especially for unauthenticated RCE conditions.
  2. Reduce internet exposure of vCenter services to shrink attack surface and opportunistic scanning.
  3. Hunt for reverse SSH backdoors and unusual persistence following vCenter compromise indicators.
  4. Expect ransomware operators to target VMware ecosystems using purpose-built VM encryptors.
  5. Track CISA KEV updates to prioritize remediation ahead of rapid threat-actor adoption.

CQURE Hacks #82: Microsoft Entra ID Conditional Access Bypass via User-Agent Policy Gap

Source: CQURE Academy

Author: Asia

URL: https://cqureacademy.com/blog/cqure-hacks-82-microsoft-entra-id-conditional-access-bypass-via-user-agent-policy-gap/

ONE SENTENCE SUMMARY:

A User-Agent–based Conditional Access gap enabled Xbox token issuance without MFA, leading to Graph access, secret discovery, and full tenant compromise.

MAIN POINTS:

  1. Conditional Access trusted device platforms based solely on client-controlled User-Agent strings.
  2. Policies blocked Windows, Linux, and iPhone, but overlooked Xbox Series X.
  3. Xbox User-Agent allowed Microsoft Graph token acquisition without triggering MFA.
  4. Obtained access token enabled direct Graph API access despite portal restrictions.
  5. GraphRunner enumerated users, groups, and roles through Microsoft Graph.
  6. Portal blocking proved ineffective because underlying APIs remained accessible.
  7. Custom scripting searched directory objects for exposed credentials and secrets.
  8. A clear-text password was found stored in a group description attribute.
  9. Exposed credentials belonged to a break-glass Global Administrator account.
  10. Chaining policy gaps with poor secret storage resulted in full tenant compromise.

TAKEAWAYS:

  1. Expand Conditional Access coverage to include Graph/API token acquisition flows.
  2. Avoid security decisions based on manipulable client signals like User-Agent.
  3. Enforce MFA consistently across all sensitive access paths, not just portals.
  4. Prevent secrets from being stored in readable directory attributes and descriptions.
  5. Assume attackers will chain minor misconfigurations into high-impact compromises.