Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Docker Fixes Critical Sandboxes Flaw That Could Expose Host Files

  Docker has patched two vulnerabilities in Docker Sandboxes that could allow malicious code running inside an isolated sandbox to cross its...

All the recent news you need to know

FBI Seizes NightmareStresser DDoS-for-Hire Domains in Global Crackdown

 

The U.S. Department of Justice has announced the court-authorized seizure of internet domains linked to “NightmareStresser,” one of the world’s longest-running Distributed Denial of Service (DDoS) for-hire services. The operation, led by the FBI Anchorage Field Office with support from the Royal Canadian Mounted Police, targets so-called “booter” and “stresser” platforms that enable paying customers to launch powerful cyberattacks against individuals, organizations, and critical online infrastructure across Alaska and globally. 

According to the seizure warrant affidavit, NightmareStresser was used to carry out hundreds of thousands of actual or attempted DDoS attacks worldwide since 2022. These services lower the barrier to entry for cybercrime by allowing users with minimal technical expertise to disrupt internet connections, knock targeted devices offline (“booting”), and degrade or completely interrupt access to websites and online services. Victims have included schools, government agencies, gaming platforms, and millions of everyday users whose connectivity was affected by these coordinated attacks.

The takedown forms part of Operation PowerOFF, an ongoing international law enforcement initiative aimed at dismantling criminal DDoS-for-hire infrastructures and holding both administrators and users accountable. Over the past eight years, federal prosecutors and investigators in Anchorage and Los Angeles have charged twelve defendants involved in facilitating DDoS-for-hire services and seized more than 100 associated domains. This latest action expands on those efforts by targeting all known booter sites, shutting down as many as possible, and coupling enforcement with a public education campaign on the harms caused by illegal DDoS activity. 

Assistant U.S. Attorneys Adam Alexander and Ainsley McNerney are prosecuting the case in the District of Alaska. The Justice Department emphasizes that booter and stresser services not only harm direct targets but also undermine broader internet reliability and safety. As digital dependence grows, such crackdowns signal a sustained push to disrupt the ecosystem enabling low-cost, high-impact cyberattacks—and to deter would-be offenders by removing the domains and infrastructure these services rely on to operate.

Unbound 1.26.1 Patches Critical RCE, DoS, and DNSSEC Flaws

 

A major security update has been issued for Unbound, the widely used validating DNS resolver developed by NLnet Labs. On September 16, 2026, the project disclosed a batch of high-severity vulnerabilities affecting versions up to and including 1.26.0, with fixes released in version 1.26.1. These flaws range from heap buffer overflows and use-after-free bugs to DNSSEC validation bypasses, any of which could allow attackers to crash servers or, in some cases, achieve remote code execution. 

RCE and denial-of-service risks 

Among the most serious issues is a heap buffer overflow in Unbound’s DNSSEC validator that can be triggered by a malicious DNSKEY record containing a self-referential compression pointer. This bug, credited to researchers from Nankai University, can lead to denial of service and potential remote code execution because the digest buffer overflows when processing such crafted records. Two additional memory-corruption bugs were also reported: one in DNSSEC canonicalization that affects long query names over TCP, and another in CNAME synthesis that can progressively corrupt heap memory and, under specific conditions, allow code execution. All three vulnerabilities are fixed in the 1.26.1 release, and manual patches are available for administrators who cannot immediately upgrade. 

Unbound’s support for encrypted DNS transports is also affected. A use-after-free bug in the DNS-over-QUIC (DoQ) implementation can be triggered by a malicious client that sends a RESET_STREAM and withholds ACKs, eventually causing the server to exit abnormally after as few as 20 queries. Similarly, a use-after-free in the DNS-over-HTTPS (DoH) cleanup path can be exploited when RPZ drops queries or under heavy traffic, potentially leading to process termination on hardened allocators. In addition, a degradation-of-service flaw in TCP/DoT handling allows an attacker to monopolize a worker’s event loop by streaming distinct uncached queries over a single connection, with no limit on consecutive reads. Fixes for these issues adjust stream shutdown behavior, correct DoH mesh accounting, and introduce read limits similar to those already used for UDP. 

Beyond memory safety, several logic errors undermine Unbound’s security guarantees. A ZONEMD verification bypass creates a window where tampered zone data can be served or written to disk before integrity checks complete, affecting zones below a trust anchor. A cross-zone cache-poisoning bug allows a malicious actor controlling one delegated zone under an NSEC-signed parent to inject insecure wildcard DS records for unrelated sibling domains, effectively forging delegations. Another flaw lets the “serve-expired” feature bypass the wait-limit counter introduced for the DNSBomb mitigation (CVE-2024-33655), enabling pulsing DoS amplification attacks from a single IP. The “ReTrap” family of algorithmic-complexity attacks (TagTrap, DelegationTrap, NsecTrap, AdditionalTrap) can also degrade service by forcing excessive DNSSEC validation work; Unbound 1.26.1 adds throttles and disables validation of the additional section by default to mitigate this. 

Role of administrators 

All users running Unbound 1.26.0 or earlier are urged to upgrade to version 1.26.1 as soon as possible, especially on internet-facing resolvers or those handling DNSSEC-validated traffic. If immediate upgrade is not feasible, NLnet Labs provides individual patches for each CVE that can be applied manually to the source tree. Operators should also review configurations for features like DNS-over-QUIC, DNS-over-HTTPS, DNSCrypt, response-ip/RPZ, and serve-expired, since several vulnerabilities require these options to be enabled. Given Unbound’s role in the DNS infrastructure of countless networks, prompt patching is critical to prevent outages and exploitation in the wild.

Cyberattack Knocks International Meteor Organization Website Offline

 

A cyberattack has forced the International Meteor Organization (IMO), one of the leading providers of meteor observation, to take much of the website offline. Founded in 1988, the Belgium-based independent organization reported that the cyberattack caused severe damage to the aging infrastructure and left the organization dealing with several weeks of partial downtime as it transitions to new infrastructure. 

The organization has replaced its website with a static notice informing the visitors about the incident and warning that features will return gradually. “We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline,” the organization said. It explained that it expects several weeks of partial downtime while transitioning to new infrastructure and services. The IMO has prioritized restoring its fireball reporting system which is already available for users to submit their observations. The organization also shared its meteor and asteroid-related information on its Facebook page. 

The IMO was formed to bring amateur and professional meteor observers and scientists together. The organization has played an essential role in the development of international standards for meteor observations and the maintenance of a global database of meteor and fireball reports containing photographs, videos and telescopic observations. The organization has not publicly identified those responsible for the attack, and no hacking group had claimed responsibility as of Wednesday afternoon. The organization also did not respond to requests for additional comment. The incident comes shortly before the IMO’s annual international conference that is set to take place next week in France. 

It is unclear if the cyberattack will impact the event or the organization’s other activities. The incident also shows the growing interest of cybercriminals in targeting organizations involved in space and scientific research. U.S. agencies have warned that the rising economic importance of the space industry can attract attackers and organizations that engage in space-related activities can become potential targets. Attackers have targeted the National Science Foundation’s National Optical-Infrared Astronomy Research Laboratory in Hawai’i and the Atacama Large Millimeter Array observatory in Chile in 2023. 

The American Meteorological Society was also targeted by ransomware in the same year. For now, the IMO is focused on rebuilding its infrastructure and restoring the services after the attack, with additional website features expected to return as the transition progresses.

Brevo Breach Exposes Customer Websites to ClickFix Malware


Email marketing and customer relationship management platform Brevo, formerly known as Sendinblue, suffered a supply chain attack in which malicious code was able to reach Brevo's own websites as well as customers' websites utilizing embedded Brevo services. 

Researchers at Sansec discovered that the incident was much more extensive than the six accounts previously revealed. When Brevo infrastructure was compromised on September 14, 2026, malicious JavaScript began to be served. In addition, Sansec found evidence that more than 100,000 customer websites utilizing Brevo components may have been exposed as a result of the attack. 

There were two main infection paths used in the campaign: a malicious WordPress plugin that targeted site administrators and a ClickFix overlay that was displayed to visitors. 

Malicious Code Reached Embedded Brevo Components

Brevo-hosted pages as well as JavaScript resources commonly embedded in customer websites were identified as containing the injected code. These included Brevo trackers, Conversations chat widgets, as well as other forms hosted on Brevo servers. 

Modified versions of the JavaScript assets directed browsers to infrastructure controlled by attackers, which served the malicious malware loader. Sansec identified several malicious subdomains under the Brevo domain sendibt1.com. A number of hostnames were affected, including cdn.sendibt1.com, cdn2.sendibt1.com, cdn3.sendibt1.com, cdn4.sendibt1.com, cdn9.sendibt1.com, cdn10.sendibt1.com, and cdn11.sendibt1.com. 

A SSL certificate for cdn.sendibt1.com was also discovered on August 25, which indicates that the attackers had gained access to Brevo's DNS records. A malicious content display was observed on September 14 from approximately 16:05 until 20:13 UTC, which was observed by researchers. 

A total of 2,549 breaches of Content Security Policy were reported across 12 sites during and after the attack window. These hosts stopped resolving on September 15, while the affected files were reported clean at the site of origin. 

ClickFix Campaign Targeted Website Visitors

Injected malware delivered different payloads depending on the visitor. When a visitor was detected as a WordPress administrator, it attempted to install a plugin from a Brevo subdomain controlled by the attacker. A fake verification prompt was displayed using the ClickFix technique to visitors, instructing them to copy a command and execute it under the pretext of demonstrating their humanity. According to Sansec, the malware did not activate for crawlers, developers, or automated scanners, therefore preventing it from being detected during routine inspections. 

WordPress Sites Faced a Deeper Threat 

A more significant risk was posed to WordPress administrators by the attack. When the compromised Brevo script identified an administrator already logged into a WordPress site, it attempted to download and install plugins from attacker-controlled infrastructure. 

BleepingComputer examined a copy of the plugin, which was disguised as Web Media Optimizer, but was actually a JavaScript loader and persistent backdoor. Installing this plugin allowed it to hide from the normal WordPress plugin list and copy itself into the must-use plugins directory, making its removal more difficult. Additionally, the plugin contacted attacker-controlled infrastructure to obtain additional JavaScript, allowing malicious content to continue loading even if the remote server was unavailable, as researchers discovered. 

A critical feature of the plugin was that it contained a hardcoded authentication mechanism capable of creating a valid administrator session without requiring the legitimate administrator password. This allowed attackers to continue access to a compromised WordPress installation beyond Brevo's original exposure period. 

Brevo Took Down the Malicious Infrastructure

After detecting the intrusion, Brevo removed the malicious Cloudflare Worker and associated routes. As a result of the compromise, Brevo revoked its API key and credentials, removed attacker-controlled hostnames and purified edge caches. Additionally, the hardcoded Cloudflare credential was removed from the source code of the company. 

Sansec reports that malicious hosts began to cease resolving on September 15 and Brevo's affected files were restored to their original versions. Although the delivery window ended, the malware was not removed from WordPress sites where the rogue plugin had already been installed. Additionally, Brevo SSO security incident reported on September 10 also occurred following the incident. It was reported that six customer accounts were accessed unauthorised and were used for phishing, as well as contact data exported from 43 other accounts in that incident. 

A public connection has not been established between Brevo's earlier incident and Cloudflare's subsequent compromise. The Brevo incident illustrates the threat of third-party services that extend beyond the infrastructure of the provider and affect websites which utilize embedded scripts. Additionally, the combination of ClickFix lures and persistent WordPress backdoors creates a higher risk for website administrators and visitors alike.

Cyberattack on Tanker Prompts Coast Guard-FBI Security Boarding

 

A tanker crossing the Gulf of Mexico was boarded by U.S. Coast Guard and FBI personnel last month after its onboard network came under attack from hackers, the Coast Guard has confirmed. The confirmation followed a Wall Street Journal report indicating that at least two U.S.-bound tankers had been targeted in separate cyber incidents. Bloomberg News named one of the affected vessels as VL Prosperity, while Iran's state-backed outlet Mehr reported the ship went dark for a day and a half after losing its communications systems. Neither the FBI nor several other federal agencies contacted for comment addressed the incident directly, instead referring inquiries to the Coast Guard. 

A spokesperson there said the boarding was carried out to verify that the ship's technology systems remained intact after signs emerged that the network had been infiltrated by actors operating from outside the country. The operation took place on August 21 and involved a joint team: Coast Guard law enforcement officers, a cyber protection unit, a vessel inspector, and cyber specialists from the FBI. The spokesperson emphasized that no disruptions to the ship's operations, structural stability, crew safety, or the surrounding environment had been identified so far. Coast Guard officials declined to elaborate on how the breach occurred, who may have been responsible, or whether the tanker boarded that day was in fact VL Prosperity. 

A second vessel was reportedly boarded three days later, on August 24, per the Journal's reporting. Mehr's account places the origin of the attack earlier, on August 7, while the Liberian-flagged VL Prosperity was passing through the Strait of Gibraltar en route from Egypt to a U.S. port. One crew member described to Mehr how the intruders were reportedly able to remotely increase engine speed and shut down tanks holding fuel and engine oil. Analysts cited by the outlet, without offering direct evidence, tied the episode to broader tensions between the U.S. and Iran, though no group has publicly claimed involvement. Bloomberg later placed the tanker off the Texas coastline. The Coast Guard said it remains in contact with port operators, ship owners, and regional maritime partners to keep operations running smoothly. 

A separate incident struck just a day earlier, when North Carolina Ports disclosed that an external hacker or group had breached its IT infrastructure, pushing staff to switch to manual processes. The organization said it activated emergency protocols and looped in both state agencies and the Coast Guard. Maritime infrastructure worldwide has increasingly become a target for ransomware operators over the past several years, a trend tied to the sector's growing reliance on connected systems. 

The Port of Seattle famously refused to pay hackers who disrupted its airport and seaport operations around Labor Day in 2024. Similar attacks hit European ports and shipping firms Royal Dirkzwager and DNV in 2023, while Oiltanking and Mabanaft both declared force majeure after 2022 cyber incidents. Freight company Expeditors International also spent months recovering operational systems following its own attack.

Parallels Desktop Vulnerability Gives Any Local Mac User Full Root Access, Intel Mac Users Left Without a Clear Fix

 




Security researchers at JFrog disclosed the vulnerability on Tuesday, assigning it the identifier CVE-2026-90894 and the nickname "ParaShells." JFrog rates the flaw 7.8 out of 10 on the CVSS severity scale. The bug does not allow remote attacks over a network. An attacker needs code already running on the machine as an ordinary local user, but once that condition is met, exploitation does not require administrator rights, a signed Parallels client, or an active virtual machine. 


What Parallels Desktop Is and Why This Matters

Parallels Desktop runs Windows and Linux inside virtual machines on a Mac. It installs a background service called prl_disp_service that runs as root, because its work includes setting up host networking and unpacking virtual machine packages. The flaw is on the Mac side of the product, so the machine at risk is the Mac itself rather than the virtual machines on it. 

That distinction is important. Many Mac users who run Parallels think of security risks as something that might affect the virtual Windows or Linux environment inside. ParaShells skips the guest entirely and compromises the Mac host directly.


How the Attack Works

The exploit chains together three separate weaknesses, none of which would be enough on its own.

The vulnerability combines three security weaknesses: a world-writable Unix socket, weak local client authentication, and argument injection during appliance extraction. On a default installation, prl_disp_service listens through /var/run/prl_disp_service.socket. JFrog researchers found that the socket could have 0777 permissions, allowing any local process to connect. 

The login call that follows, PrlSrv_LoginLocal, checks only the credentials the kernel reports for the connecting process. It needs no Parallels code signature and works for an account that is not an administrator. 

The third piece is where things get technically interesting. To install a virtual machine appliance, the service builds its unpack command as one line of text, tar -xf "%1" -C "%2". It then splits that text back into separate arguments using Qt's QProcess::splitCommand. The caller chooses part of that text, because it picks the folder the new virtual machine goes into. A double quote inside the folder name closes the quoting early, so whatever the attacker put after it becomes extra options for tar instead of part of a path. 

The option JFrog used was --use-compress-program, which tells macOS tar to hand the archive to another program first. Because tar is running as root here, that program runs as root too. JFrog's test script wrote a passwordless sudo rule and opened a root shell. 

In the lab demonstration, the sequence plays out in seconds: connect to the socket, send a crafted appliance install request with a poisoned directory path, and watch the compression program execute as uid 0. JFrog assembled this into a one-liner but has chosen not to publish that script, releasing the technical breakdown without the ready-to-fire weapon.

Yuval Moravchick, JFrog's vulnerability research team lead, explained: "The chain is short: A world-writable Unix socket, a login that trusts peer credentials rather than a Team ID, and an appliance unpack path that builds tar arguments using Qt string splitting. A quote in the parent path injects --use-compress-program=, and macOS tar runs the attacker's script as uid 0." 


Who Is Most at Risk

The danger is highest on developer laptops, where a single poisoned Homebrew formula or malicious npm preinstall script can go from local user to full control, and on shared university and corporate machines that have many local accounts. 

The threat model here is real and not hypothetical. Software developers routinely run third-party tools through package managers like Homebrew or execute npm scripts from projects they pull from the internet. Every one of those code paths represents a potential entry point for an attacker who knows the machine has Parallels installed. On a shared training lab or university computer lab Mac with a dozen local accounts, a single weak password or compromised student account is all it takes.

"From root, the attacker can replace system software, read other users' data, and persist via launchd," Moravchick noted. That last point about launchd persistence is particularly concerning because an attacker who establishes root access through this chain can survive a reboot by registering their own background processes with macOS's system daemon manager. 

JFrog also confirmed no virtual machine needs to be actively running. The vulnerable service, prl_disp_service, starts automatically via a launch daemon at load, runs as root, and exposes the socket regardless of whether any VM is open. Simply having Parallels Desktop installed is enough to create the exposure. 


The Patch Is Out, With a Catch

JFrog reported CVE-2026-90894 to Parallels maker Alludo, which fixed it in Parallels Desktop v27.0.0, released at the beginning of September 2026. The fix is real, but getting to it is not straightforward for a meaningful portion of Parallels' user base. 

Parallels Desktop 27 needs a Mac with an Apple silicon chip. Its system requirements list Apple silicon only for the processor and macOS Sonoma 14.7 or newer for the operating system. On earlier releases of macOS, including Ventura 13, the installer sets up an older version of the product instead. Parallels removed Intel Mac support in version 27 and says the change follows Apple's plans rather than its own. 

For Intel Mac users, the situation is murky. Intel users are told to stay on Parallels Desktop 26. "Parallels Desktop 26 fully supports Intel-based Mac computers today, and that will not change," the company wrote on 25 August, three weeks before this flaw became public, adding that Intel users can keep using version 26 and "expect future security and maintenance updates." 

The problem is that according to JFrog, "Hosts that stay on the 26.x line, including 26.4.2, do not have that extract change." JFrog does not say it tested 26.4.1 or 26.4.2, and its writeup says it did not check older builds. 

Parallels has not published a statement about CVE-2026-90894, and its list of security fixes, which maps each flaw to the version that repairs it, has not been reviewed since May 2025 and does not include this one. That leaves Intel Mac users running Parallels in a difficult position: a confirmed flaw, a fix that requires hardware they do not have, and no public acknowledgment from the vendor about plans for their platform. 

The release notes for Parallels Desktop 26.4.2, which shipped on September 8, describe a single change related to Enterprise edition deployment and say nothing about a security fix for the extract path.


What Organizations Should Do Now

JFrog's immediate guidance comes in three parts: find every Mac in your environment running Parallels Desktop, restrict who can log in to those machines locally, and upgrade to version 27.0.0 or later where possible.

Two commands can confirm exposure without making any changes to the system. Running defaults read "/Applications/Parallels Desktop.app/Contents/Info" CFBundleShortVersionString reports the installed version, and ls -l /var/run/prl_disp_service.socket shows the socket permissions. JFrog says a socket showing srwxrwxrwx on a build at or near 26.4.0 should be treated as exposed until a patched build is confirmed. 

Administrators using device management to push updates should check version rules before pushing anything. Parallels warns that a policy which sends out new major versions automatically will try to install version 27 on Intel Macs and fail. 

One more complication: none of the published material says whether installing a fixed build removes access an attacker has already taken. JFrog notes that an attacker who reaches root can keep a foothold through launchd, which a product update would not clear. For any machine where compromise is suspected, an update alone is not enough. 


Featured