Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Cyberattack on Tanker Prompts Coast Guard-FBI Security Boarding

  A tanker crossing the Gulf of Mexico was boarded by U.S. Coast Guard and FBI personnel last month after its onboard network came under att...

All the recent news you need to know

Parallels Desktop Vulnerability Gives Any Local Mac User Full Root Access, Intel Mac Users Left Without a Clear Fix

 




Security researchers at JFrog disclosed the vulnerability on Tuesday, assigning it the identifier CVE-2026-90894 and the nickname "ParaShells." JFrog rates the flaw 7.8 out of 10 on the CVSS severity scale. The bug does not allow remote attacks over a network. An attacker needs code already running on the machine as an ordinary local user, but once that condition is met, exploitation does not require administrator rights, a signed Parallels client, or an active virtual machine. 


What Parallels Desktop Is and Why This Matters

Parallels Desktop runs Windows and Linux inside virtual machines on a Mac. It installs a background service called prl_disp_service that runs as root, because its work includes setting up host networking and unpacking virtual machine packages. The flaw is on the Mac side of the product, so the machine at risk is the Mac itself rather than the virtual machines on it. 

That distinction is important. Many Mac users who run Parallels think of security risks as something that might affect the virtual Windows or Linux environment inside. ParaShells skips the guest entirely and compromises the Mac host directly.


How the Attack Works

The exploit chains together three separate weaknesses, none of which would be enough on its own.

The vulnerability combines three security weaknesses: a world-writable Unix socket, weak local client authentication, and argument injection during appliance extraction. On a default installation, prl_disp_service listens through /var/run/prl_disp_service.socket. JFrog researchers found that the socket could have 0777 permissions, allowing any local process to connect. 

The login call that follows, PrlSrv_LoginLocal, checks only the credentials the kernel reports for the connecting process. It needs no Parallels code signature and works for an account that is not an administrator. 

The third piece is where things get technically interesting. To install a virtual machine appliance, the service builds its unpack command as one line of text, tar -xf "%1" -C "%2". It then splits that text back into separate arguments using Qt's QProcess::splitCommand. The caller chooses part of that text, because it picks the folder the new virtual machine goes into. A double quote inside the folder name closes the quoting early, so whatever the attacker put after it becomes extra options for tar instead of part of a path. 

The option JFrog used was --use-compress-program, which tells macOS tar to hand the archive to another program first. Because tar is running as root here, that program runs as root too. JFrog's test script wrote a passwordless sudo rule and opened a root shell. 

In the lab demonstration, the sequence plays out in seconds: connect to the socket, send a crafted appliance install request with a poisoned directory path, and watch the compression program execute as uid 0. JFrog assembled this into a one-liner but has chosen not to publish that script, releasing the technical breakdown without the ready-to-fire weapon.

Yuval Moravchick, JFrog's vulnerability research team lead, explained: "The chain is short: A world-writable Unix socket, a login that trusts peer credentials rather than a Team ID, and an appliance unpack path that builds tar arguments using Qt string splitting. A quote in the parent path injects --use-compress-program=, and macOS tar runs the attacker's script as uid 0." 


Who Is Most at Risk

The danger is highest on developer laptops, where a single poisoned Homebrew formula or malicious npm preinstall script can go from local user to full control, and on shared university and corporate machines that have many local accounts. 

The threat model here is real and not hypothetical. Software developers routinely run third-party tools through package managers like Homebrew or execute npm scripts from projects they pull from the internet. Every one of those code paths represents a potential entry point for an attacker who knows the machine has Parallels installed. On a shared training lab or university computer lab Mac with a dozen local accounts, a single weak password or compromised student account is all it takes.

"From root, the attacker can replace system software, read other users' data, and persist via launchd," Moravchick noted. That last point about launchd persistence is particularly concerning because an attacker who establishes root access through this chain can survive a reboot by registering their own background processes with macOS's system daemon manager. 

JFrog also confirmed no virtual machine needs to be actively running. The vulnerable service, prl_disp_service, starts automatically via a launch daemon at load, runs as root, and exposes the socket regardless of whether any VM is open. Simply having Parallels Desktop installed is enough to create the exposure. 


The Patch Is Out, With a Catch

JFrog reported CVE-2026-90894 to Parallels maker Alludo, which fixed it in Parallels Desktop v27.0.0, released at the beginning of September 2026. The fix is real, but getting to it is not straightforward for a meaningful portion of Parallels' user base. 

Parallels Desktop 27 needs a Mac with an Apple silicon chip. Its system requirements list Apple silicon only for the processor and macOS Sonoma 14.7 or newer for the operating system. On earlier releases of macOS, including Ventura 13, the installer sets up an older version of the product instead. Parallels removed Intel Mac support in version 27 and says the change follows Apple's plans rather than its own. 

For Intel Mac users, the situation is murky. Intel users are told to stay on Parallels Desktop 26. "Parallels Desktop 26 fully supports Intel-based Mac computers today, and that will not change," the company wrote on 25 August, three weeks before this flaw became public, adding that Intel users can keep using version 26 and "expect future security and maintenance updates." 

The problem is that according to JFrog, "Hosts that stay on the 26.x line, including 26.4.2, do not have that extract change." JFrog does not say it tested 26.4.1 or 26.4.2, and its writeup says it did not check older builds. 

Parallels has not published a statement about CVE-2026-90894, and its list of security fixes, which maps each flaw to the version that repairs it, has not been reviewed since May 2025 and does not include this one. That leaves Intel Mac users running Parallels in a difficult position: a confirmed flaw, a fix that requires hardware they do not have, and no public acknowledgment from the vendor about plans for their platform. 

The release notes for Parallels Desktop 26.4.2, which shipped on September 8, describe a single change related to Enterprise edition deployment and say nothing about a security fix for the extract path.


What Organizations Should Do Now

JFrog's immediate guidance comes in three parts: find every Mac in your environment running Parallels Desktop, restrict who can log in to those machines locally, and upgrade to version 27.0.0 or later where possible.

Two commands can confirm exposure without making any changes to the system. Running defaults read "/Applications/Parallels Desktop.app/Contents/Info" CFBundleShortVersionString reports the installed version, and ls -l /var/run/prl_disp_service.socket shows the socket permissions. JFrog says a socket showing srwxrwxrwx on a build at or near 26.4.0 should be treated as exposed until a patched build is confirmed. 

Administrators using device management to push updates should check version rules before pushing anything. Parallels warns that a policy which sends out new major versions automatically will try to install version 27 on Intel Macs and fail. 

One more complication: none of the published material says whether installing a fixed build removes access an attacker has already taken. JFrog notes that an attacker who reaches root can keep a foothold through launchd, which a product update would not clear. For any machine where compromise is suspected, an update alone is not enough. 


Vercel Sandbox Challenge Uncovers Linux Kernel Flaws


 Vercel has conducted a two-week security challenge that has uncovered numerous vulnerabilities in the Linux kernel networking stack that is used by its Firecracker microVM sandbox. This program, supported by a $1 million reward pool, examined researchers' abilities to break out of an environment that isolates untrusted artificial intelligence-agent code from other software. There were 1,285 vulnerability reports generated as a result of the challenge running from August 18 to September 1. 


There have been about $325,000 in payouts to date for one critical, seven high-severity, 15 medium-severity, 49 low-severity and 19 informative findings validated by Vercel. Even though there were many submissions, none of them demonstrated access to actual customer data. Two separate flaws were found in the Linux kernel networking stack rather than Vercel's own sandbox code that were the most significant. 

Various issues can lead to memory leaks from the host kernel, while others can cause a host system crash deterministically. It is particularly relevant to cloud environments since Linux kernel isolation layers are used by many infrastructure platforms. Therefore, a vulnerability that crosses the boundary between a microVM and its host may result in consequences that extend beyond a single deployment or service. 

There were roughly two weeks before the Linux kernel maintainers were informed about the kernel issues, according to Vercel. Details remain undisclosed while fixes are in private review, with CVEs expected to be assigned after public disclosure. In addition to white-box testing, Trail of Bits engineers reported 20 findings after participating in the challenge. 

The assessment did not only identify individual vulnerabilities but also highlighted architectural concerns related to the data movement between the host control plane and the guest environment. It was recommended that all values generated within the microVM be treated as untrusted guest input. Vercel acknowledged that certain values returned by software running within a guest had been accepted by its control plane, creating an architectural risk at the boundary of the sandbox. 

AI-Assisted Triage Handles Report Surge 

A separate challenge for Vercel was also presented during the two-week program: handling the staggering number of vulnerability reports generated. When 1,285 submissions were received within a short period of time, the original review process, involving a human assessment of each report, soon became challenging to scale.

Vercel developed the Eve framework as a means of implementing an agentic triage system. Using Vercel Sandbox, the system can evaluate submitted reports against program rules, identify duplicates, access relevant source code, and execute researchers’ proof-of-concept code. This approach was implemented to alleviate the manual workload that was created by the unusually high number of submissions. 

The volume itself was partly influenced by the challenge structure, which encouraged researchers to actively seek ways to avoid the sandbox boundaries. As Vercel noted, the experience also demonstrated the effectiveness of AI-assisted security research in facilitating the discovery of new vulnerabilities more quickly. 

The white box assessment, in addition to identifying technical vulnerabilities, also revealed architectural findings concerning the trust relationship between microVM guest hosts and control planes. According to the assessment, some values returned by software running inside a microVM were accepted by the control plane.

A Vercel representative stated that such values should not be treated as trusted data, but rather as tenant-controlled inputs. This company recommends obtaining sensitive values from the server end or encrypting them with cryptographic signatures with keys that cannot be accessed from the guest environment in order to protect them. According to the company, the findings have resulted in changes to the security controls and sandbox architecture. 

While the Linux kernel issues remain under coordinated disclosure, technical details and CVE identifiers will be kept confidential until the fixes are published publicly. There was no evidence of customer data access as a result of the challenge, however, the kernel findings remain significant as the affected networking layer sits beneath isolation mechanisms in many cloud environments. 

After patches are released and technical disclosures are made, the scope of affected systems will be determined and remediation requirements will be determined for Linux-based infrastructures.

US Lawmakers Raise Alarm Over Alleged Hacking by India-Based Firms


Three Indian-based companies have been accused of conducting hacking campaigns and stealing data from thousands of Americans and US businesses, according to a bipartisan group of US senators. As part of the request, the lawmakers sought restrictions that could limit companies' access to American technology and services in a letter to U.S. Commerce Secretary Howard Lutnick. 

Among the companies named in the letter are Sunkissed Organic Pvt Ltd, BellTrox Ltd, and CyberRoot Ltd. Democratic Senator Ron Wyden and Sheldon Whitehouse, along with Republican Senator Pat Harrigan, allege that the groups had engaged in targeted espionage activities against US citizens, businesses and legal professionals over the past fifteen years. 

A number of senators cited investigations conducted by Reuters and The Citizen Lab, in which they claimed that the companies had been involved in hacking campaigns targeting pharmaceutical companies, private equity firms, and attorneys employed by major law firms. It was stated in the letter that the groups operated under the direction of the Qatari government and some of these operations were intended to influence ongoing litigation. 

According to the senators, the alleged activities included targeting individuals who oppose Qatar's bid for the World Cup, as well as the family members of the former Republican Chairman of the House Permanent Select Committee on Intelligence. 

A number of allegations go beyond the hacking activities themselves, as well. A number of foreign legal actions were taken by legislators that were intended to restrict public reporting of the alleged activities. One such case involved Appin, in which executives related to the company obtained a global court order from an Indian court requiring Reuters to cease investigating the company. The order was subsequently lifted, allowing the investigation to be republished by Reuters. According to the senators, the episode illustrates the possibility of restricting the availability of American information through foreign legal proceedings. Additionally, previous reporting has documented legal threats to media outlets that cover alleged hack-for-hire operations related to Appin. The US Commerce Department has now requested that BellTroX, CyberRoot, and Sunkissed Organic Farms be added to the Entity List by the Bureau of Industry and Security of the US Commerce Department. By making such a designation, US companies may not export or transfer certain technologies, software, and other controlled items to these listed entities without a license. The requested restrictions would specifically target access to American software, cloud infrastructure, and cybersecurity tools. This move remains a request from Congress, and any Entity List designation requires the Commerce Department to take action. US authorities are now considering possible restrictions on the three firms' access to American technology and services in light of the lawmakers' request for the three firms to be under renewed scrutiny.

Acronis Discloses Actively Exploited Privilege Escalation Bug in Its cPanel Backup Plugin

 




Acronis has confirmed that attackers are actively exploiting a high-severity security flaw in its backup plugin for cPanel and WebHost Manager (WHM), urging system administrators to install available patches without delay.

The vulnerability, tracked as CVE-2026-87886 and rated high severity, allows local privilege escalation through insecure file permissions. Classified under CWE-276 (incorrect default permissions), the flaw affects Linux-based installations of the Acronis backup plugin and, if exploited successfully, could allow a threat actor to compromise system confidentiality, integrity, and availability. 

The flaw received its CVE designation on Tuesday, September 16, after Acronis quietly published a brief initial advisory over the weekend. The company assigned it a CVSS severity score of 7.8.


What the Plugin Does

To understand the risk here, it helps to know what this software actually sits on top of. The Acronis Backup plugin for WHM and cPanel gives hosting providers and web professionals cloud backup capabilities and granular, self-service recovery for end clients, including the ability to back up an entire cPanel server to cloud storage. 

Acronis is a cybersecurity and data protection technology company that is popular among web hosting providers and managed service providers, since its platform lets them offer backup and security to their clients under their own branding. Its backup add-ons connect cPanel and Plesk to Acronis' cloud infrastructure, letting administrators back up and recover sites, databases, and mailboxes. 

That puts the plugin in a particularly sensitive position on any server it runs on. An attacker who can escalate privileges inside this kind of environment has a direct path to the backup data of every customer account on that server.

The market footprint here is worth noting. According to the 2026 Web Hosting Trends Report by WebPros, cPanel/WHM leads the hosting control panel market with 64% adoption, while Plesk accounts for 31%. Both platforms are affected by this vulnerability, though active exploitation so far appears confined to cPanel and WHM deployments. 


How the Attack Works

CVE-2026-87886 stems from insecure file permissions and allows authenticated attackers to achieve local privilege escalation without any user interaction. The vulnerability's CVSS string indicates that it can be exploited in low-complexity attacks, meaning the attack does not require special conditions or circumstances beyond the attacker's control to succeed. 

In plain terms: an attacker who already has a low-level foothold on a vulnerable Linux server running this plugin can use this flaw to climb to higher privilege levels, without needing to trick a user or wait for any specific system event. Depending on the access gained, this could allow sensitive data to be accessed or modified and could potentially disrupt the server. 

The type of data at risk includes backup data, system files, and customer account data. 


Targeted Attacks, Limited Disclosure

Acronis' advisory language around the exploitation is measured but direct. The company stated that "exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel and WHM deployments." 

However, the disclosure comes with some important caveats. BleepingComputer reported that Acronis based that assessment on a single report from a potentially affected customer. That is enough to justify urgent patching, but it is not the same as evidence of broad, automated exploitation across hosting providers. 

There are currently no signs of active exploitation on Plesk deployments. Still, the extension for Plesk remains vulnerable and should be patched regardless. 

Acronis has not published detailed technical information about the flaw, saying it wants to give system administrators time to apply available patches before sharing further details. The company has also identified no specific indicators of compromise and has not disclosed when the activity occurred or what attackers achieved beyond the privilege escalation impact described in the advisory.


What Needs to Be Patched

Acronis pushed out security updates for the affected plugins before the CVE was formally assigned. The versions administrators need to be on are:

Acronis Backup plugin for cPanel and WHM builds earlier than 1.9.3.1021, now fixed in version 1.9.3 HF3, and Acronis Backup extension for Plesk builds earlier than 1.8.11.638, fixed in version 1.8.11. 

For shared hosting providers, the guidance is to check every server image and automation path, rather than assuming the version on one control-plane node represents the entire fleet. Once patched, administrators should also focus review on systems where initial access was plausible: servers hosting compromised sites, accounts with recent credential resets, and hosts that allow customers to upload or execute code. 

One additional note worth flagging: a cPanel or Plesk server without the Acronis plugin or extension is outside the scope of CVE-2026-87886. This is an Acronis integration issue, not a blanket advisory for every cPanel, WHM, or Plesk installation. 


Acronis is a Swiss cybersecurity company headquartered in Schaffhausen and operates a global network of cloud data centers, supporting over 20,000 service providers that protect approximately 750,000 businesses worldwide. That scale makes vulnerabilities in its hosting integrations a high-priority concern for the managed service provider community, where a single compromised server can cascade into customer data across dozens or hundreds of accounts. 

The company has not indicated whether it plans to release a more detailed post-mortem on the exploitation activity once patching rates improve, which is a common practice after actively exploited flaws. For now, the immediate priority is getting affected installations onto the fixed builds before whatever foothold attackers have found gets wider use.

Spanish Data Watchdog Publicises First AI Agent-Linked Data Breach Report

Spain's data protection watchdog said it has received the first reported notification of a personal data breach allegedly carried out by an artificial intelligence agent, a case suggesting autonomous systems are beginning to play a direct role in cyberattacks. The Spanish Data Protection Agency (AEPD) said in a blog post Monday that the incident involved an AI agent using a widely known large language model to identify vulnerabilities, gain access to a system, and subsequently modify personal data and access invoices. 

The agency said the alleged breach was reported by the affected organization and remains under review. It clarified that the use of a particular AI model does not imply the model itself or its provider's infrastructure was compromised, nor that the technology was built for malicious purposes. AEPD did not immediately respond to a request for comment and did not identify the large language model or the targeted organization. 

According to AEPD, the case is significant because a third party allegedly used an AI agent to carry out multiple stages of an attack with limited human intervention, underscoring the growing role autonomous systems are playing in cybersecurity incidents. The notification submitted by the affected organization indicated that the agent successfully logged into the system, autonomously searched for application weaknesses, and after identifying a vulnerability, altered personal information and viewed billing records. 

The incident emerges as regulators and cybersecurity authorities across the United States and Europe intensify scrutiny of risks posed by increasingly capable AI systems, even as businesses continue adopting the technology at a rapid pace. Spain has positioned itself as one of Europe's most vocal advocates for a "trustworthy AI" model — one that prioritizes protecting privacy, democracy, minors, and public safety over speed or industry profit. 

While AEPD acknowledged that a single case is insufficient to establish a broader trend, it said the notification suggests AI-assisted attacks are moving beyond the theoretical stage and beginning to affect real-world processing of personal data. The watchdog did not indicate when it would complete its review of the reported breach. 

AEPD noted that AI does not create fundamentally new threats but increases the speed, scale, and adaptability of existing malicious techniques, thereby reducing the time available to detect and contain them. The agency added that data controllers, processors, and data protection officers must prepare for a scenario in which the speed of attacks will continue to accelerate.

Homebrew 7.0.0 Ships With Fixes for Eight Security Advisories

 

Homebrew, a popular package manager for installing command-line tools and desktop apps on macOS and Linux, released version 7.0.0 on Sunday, with eight security advisories closed in the process. The most severe of the 18 reported issues is an unsigned removal metadata vulnerability for a cask, a formula in Homebrew's format for prebuilt app installs, allowing arbitrary sudo commands.

Homebrew removed the vulnerable recovery code and associated API accessors. Seven of the advisories were addressed in earlier 6.0.x releases, which means auto-updating machines already carry those fixes. The eighth is new and would let a malicious cask execute code outside the sandbox of a macOS via LaunchServices. Homebrew classified the issues as one High, two Moderate, and five Low. The High severity sudo path issue was fixed in 6.0.12, where a Moderate was also addressed for preventing the installer from reading Git config owned by the Homebrew prefix, which could run programs as root. 

The second Moderate is the LaunchServices escape mentioned earlier, which is fixed in 7.0.0 by restricting launching of applications, Mach services, and Unix socket connection. The five Low-level issues were fixed earlier and involved redirects and file paths pointing to unintended locations, including headers leaks, tap-restriction bypasses, and files being written outside of staged source trees. The new 7.0.0 brings a built-in scanner (`brew vulns`) that checks for known vulnerabilities in installed formulae, with flags such as `--severity=high` and `--fix-available` to narrow the results, against a database of known vulnerabilities in formulae versions that have been shipped. 

It includes backported fixes for some issues and minimizes false positives, with Homebrew's data on vulnerabilities being in the OSV format with a CC0 license and published through the Homebrew API. Provenance checks are now performed for third-party tap bottles, in addition to the Homebrew core tap, with new taps publishing these by default. Homebrew notes that tap trust remains the primary defense against malicious casks, with sandboxing not making "untrusted software safe to run" due to apps running with the user's privilege and a vendor's installer not running inside the sandbox. 

Nonetheless, 7.0.0 provides sandboxing of formula and cask operations, provides setup instructions as signed data instead of arbitrary Ruby code, and deprecates old post-install blocks in favor of declaring steps. On Linux, Bubblewrap sandboxing is replaced with Landlock, a new kernel feature that requires no additional dependencies. Intel Macs are moved to Tier 3 status following the end of reliable build infrastructure and cessation of routine Intel bottles, with support continuing until September 1, 2027, and MacPorts suggested as an alternative. macOS 10.15 is dropped with the release, while Sonoma 14 is moved to Tier 3.

Featured