Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Attackers Are Already Exploiting SonicWall’s Freshly Patched Max-Severity SMA1000 Flaw

  Just three days after SonicWall shipped a patch for a maximum-severity vulnerability in its SMA1000 secure remote access appliances, attac...

All the recent news you need to know

AI Adds to Open-Source Security Pressure as Vulnerability Reports Surge


AI Adds to Open-Source Security Pressure as Vulnerability Reports Surge A growing number of security vulnerabilities are being discovered using artificial intelligence, but the increased number is placing additional pressure on open-source developers. Despite the ability of AI tools to identify potential weaknesses within software at scale, security teams often find it difficult to verify the findings and rectify confirmed vulnerabilities before malicious hackers exploit them. 

The Chief Client Innovation Officer for Enterprise Security for IBM, Jamie Thomas, highlighted the sharp increase in vulnerability disclosures at the Linux Foundation Open Source Summit. In 2026, there are expected to be 66,000 unique vulnerability entries, representing a fourfold increase when compared with seven years ago. Cybercriminals are exploiting vulnerabilities at a faster rate, making the growing volume especially concerning. 

As reported by Thomas, exploiting a vulnerability has become less difficult due to the reduction in the time required to exploit it from days to 29 minutes. In some cases, attackers can exploit a vulnerability before a patch becomes available, leaving organizations with limited time to respond. Open-source software is particularly challenging due to the fact that a single vulnerable component can adversely affect thousands of applications and businesses. 

Most open-source projects are not staffed by large teams of developers or maintained by multiple individuals, which results in limited resources available for investigating and addressing security concerns. AI-Generated Reports Add to Developers’ Workload Although artificial intelligence-powered security tools are capable of identifying potential vulnerabilities, their findings are often inaccurate and actionable. 

Insufficiently researched reports, duplicate submissions, and false positives can consume valuable time for developers, which could otherwise be spent investigating genuine threats and preparing fixes. Major open-source projects have already been affected by this issue. The curl developers ended their HackerOne bug bounty program in 2026 following an increased number of low-quality and sometimes fabricated vulnerability reports, including reports generated with artificial intelligence tools. 

Similarly, Google temporarily suspended its Open Source Software Vulnerability Rewards Program on October 1, 2026, following an increase in invalid and irrelevant submissions. A reevaluation of the programme is planned for early 2027 by the company. 

Linux creator Linus Torvalds has also expressed concern over artificial intelligence-aided vulnerability reporting, particularly regarding the number of duplicate findings reaching Linux security mailing lists. Identifying flaws already fixed or disclosed can lead to additional work without necessarily improving security. 

IBM Proposes AI-Assisted Vulnerability Management Instead of treating artificial intelligence as a sole source of additional security findings, IBM's Jamie Thomas argued that it should be used as a resource to manage the increasing volume of vulnerability reports. Open source maintainers could use this approach to differentiate legitimate reports from duplicates and false alarms, assess severity, and focus attention on the most critical flaws. As a result of this cooperation among software companies, developers, and open-source communities, the Linux Foundation’s Open Source Security Foundation (OpenSSF) could play a crucial role. 

The use of artificial intelligence-based tools may provide developers with assistance in understanding vulnerable code and preparing patches, as well as assessing incoming reports, identifying vulnerabilities that are likely to be exploited, and recommending appropriate fixes. It is important to review automated remediation carefully, as a flawed fix can introduce new bugs or leave the original weakness unresolved. 

For validating vulnerability reports and proposed solutions, human expertise remains essential. It is important to note that the challenge extends beyond vulnerability management to the long-term sustainability of open-source projects as well. Technology companies rely heavily on open-source components, often without maintaining direct relationships with developers whose responsibility it is to secure those components. 

When critical flaws emerge, limited funding and engineering resources can delay investigation and patch development. An increase in open-source security investment could contribute to alleviating this imbalance. Those businesses that rely on widely used software are strongly committed to supporting the projects that underpin their products and services, whether through financial contributions, engineering assistance, or a closer collaboration with the maintainers. 

AI has the potential to accelerate vulnerability discovery, but that advantage will not be as valuable if developers are unable to keep up with the resulting workload. To transform AI-driven discoveries into significant improvements in security, it is essential to combine automated analysis with reliable human review, as well as to strengthen coordination and sustain support for open-source projects.

Fake Ransomware Recovery Firm Charged Over $11M Decryption Markup

 

The owner of a US cybersecurity company has been charged with running a ransomware recovery fraud that allegedly involved secretly paying attackers for decryption keys and then charging victims a large markup. Zohar Pinhasi, 50, owner of MonsterCloud and also known as “Zack Silver” and “Zack Green,” appeared in a New York court on wire fraud charges. Prosecutors say his company claimed it could recover encrypted data without paying ransom, while it actually relied on ransom payments obtained from the same criminal groups.

According to the indictment, Pinhasi marketed MonsterCloud as a ransomware remediation service that used proprietary tools and advanced decryption techniques. He reportedly warned victims not to pay ransomware operators directly, positioning his firm as a safer alternative. In reality, investigators allege that he contacted the ransomware groups responsible for the attacks, paid them for decryption keys, and then used those keys to restore clients’ files while charging them for supposedly independent recovery work.

The alleged financial gap was substantial. Pinhasi is accused of paying more than $8 million in ransoms while billing clients over $19 million, creating an estimated $11 million markup. In one example, he allegedly paid a ransomware affiliate about $8,200 for a decryption key and then charged the affected client approximately $150,000. Prosecutors say the scheme effectively caused victims to pay twice—first through inflated recovery fees and indirectly through the ransom payments made on their behalf.

The case highlights a serious trust problem in the ransomware incident-response market. Organizations under pressure to restore operations may accept claims of “guaranteed decryption” without verifying the technical basis for those claims. Genuine recovery can sometimes be possible through free decryptors, backups, or known flaws in ransomware strains, but no legitimate provider can promise recovery for every attack. Businesses should therefore ask providers for transparent methods, written scopes of work, references, and clear pricing before signing emergency contracts.

Pinhasi has been charged with wire fraud and wire fraud conspiracy and could face decades in prison if convicted. The allegations remain accusations until proven in court, but the case is a warning to ransomware victims: recovery services should be scrutinized as carefully as the original cyberattack. Independent legal counsel, cyber insurance guidance, law-enforcement reporting, and verified incident-response specialists can help organizations avoid becoming victims a second time 


Public Exploit Reveals Critical AnyDesk Linux Vulnerability That Could Allow Root Access


Security experts have released a functional exploit demonstrating how a vulnerability in AnyDesk for Linux could be abused to gain the highest level of system privileges without authentication. The flaw could put computers running vulnerable versions of the remote desktop software at risk if attackers can reach the affected service.

The exploit, called AnyPwn, shows a weakness in the way AnyDesk processes certain connection data. Researchers demonstrated that the vulnerability could be exploited to execute code with root-level permissions on a targeted Linux machine.

AnyDesk is widely used for remote access, technical support and system administration. A security weakness in such software can be particularly dangerous because it may provide attackers with a route into systems that would otherwise be protected by authentication mechanisms.

How the flaw works

The security issue stems from a heap buffer overflow associated with AnyDesk's session protocol. Researchers linked the problem to an integer overflow that can cause the application to allocate an insufficient amount of memory when processing incoming data.

A buffer overflow occurs when a program writes more data into a memory area than it was designed to hold. This can damage adjacent memory and, under certain circumstances, allow an attacker to influence the program's execution.

In the reported case, the integer overflow affects the memory allocation process, creating conditions that can be exploited to compromise the application. The researchers developed AnyPwn to demonstrate that the weakness could be triggered before authentication.

The exploit was tested against AnyDesk for Linux version 8.0.2. Researchers demonstrated exploitation through direct TCP connections on port 7070. However, they did not establish that the same attack could be completed through AnyDesk's relay infrastructure.

Risks for Linux systems

The possibility of obtaining root privileges makes the vulnerability especially dangerous. Root access gives a user or process extensive control over a Linux system, including the ability to modify protected files, change configurations and install software.

An attacker who successfully exploits the flaw could potentially gain control of an affected computer, access confidential information or deploy malicious tools. In an organizational environment, a compromised machine could also become a foothold for further attacks against internal systems.

Updates and security recommendations

According to the report, AnyDesk fixed the vulnerability in version 8.0.3, released in June 2026. Users running earlier Linux versions should update to version 8.0.3 or a newer supported release.

Atlassian CVE-2026-21589 Exploited Hours After Public Disclosure

 

Attackers started scanning the systems vulnerable to the Atlassian flaw several hours after the researchers published the technical details and proof-of-concept code. Assigned the identifier CVE-2026-21589, the vulnerability impacts several self-hosted Data Center products and could allow unauthorized access to the credentials in some circumstances. 

The problem was disclosed by Atlassian on October 5, 2026, with a CVSS score of 9.3. The products affected by the bug are Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. The company already released fixes for all software versions. The flaw allows the adversaries to access some files in the application root directory without providing proper authentication. 

However, it is only possible if the attacker knows the exact name and location of the file because the vulnerability does not allow listing the contents of a directory. Therefore, the attack surface is limited, but there is still a potential risk if the adversary somehow manages to guess the file location. The security researchers from WatchTowr posted the proof-of-concept code and technical details of the discovered flaw on October 6, 2026. 

They managed to identify the origin of the issue – a popular library used in all Atlassian products mentioned above. More importantly, they found out that the vulnerability could be chained to get access to the configuration file with Crowd application credentials in some circumstances. According to WatchTowr, Crowd is Atlassian’s identity management system, and the mentioned scenario involves Jira Software connected to it. 

In this case, the attacker could use the credentials to create a new administrative account and assign it to the Jira administration group. As a result, the adversary would be able to attain full privileged access to the targeted Jira Software instance. In addition, the security company showed how the proof-of-concept code could be used to take over a victim’s account in case of success. Moreover, the researcher added that the attacks are not random, but rather targeted. 

Several hours after the publication of the results, the exploitation framework started scanning corporate websites to find the instances of the affected applications. On October 8, 2026, Previdian, the exploitation intelligence company, counted 190 attempts from 32 IP addresses in 10 countries. Although the United States Cybersecurity and Infrastructure Agency (CISA) has not included the vulnerability in the Known Exploited Vulnerabilities list, the attacks indicate that the problem needs urgent attention. 

The companies using Atlassian’s products should make sure that the affected applications are updated to the latest versions. Those who are not able to do it right away should take the vulnerable instances of the software offline or follow the recommendations stated by Atlassian. In particular, the company suggests deploying the blocking rules to the firewalls or using the Web Server rewrite rules. 

In addition, the organizations with Jira Software and Crowd should make sure that the mentioned applications are not at risk of compromise as well. As seen from the recent incident, the response to the exposure of the flaw may take too long. Moreover, the attacks are often launched right after the proof-of-concept code is published. Therefore, it is critical to apply the necessary security updates as soon as possible.

Japan Reports Sharp Rise in Web Data Leaks

 

Japan is experiencing a sharp rise in personal-data leaks from web systems, according to an October 2026 alert from the JPCERT Coordination Center. The incidents, which surged around September, are separate from ransomware and other routine breaches, and JPCERT/CC says they may be increasing. While the agency did not identify attackers or affected organizations, it described the available evidence as limited and fragmentary, and cautioned that the same technique was not necessarily used in every case. The pattern points to attackers systematically probing web applications and APIs for basic security weaknesses rather than relying on one universal exploit.

The scale is substantial. Security firm Macnica counted 119 publicly disclosed incidents in Japan through October 6 in which personal data was stolen or leaked through organizations’ web systems—up from 84 in all of 2025 and 62 in 2024. Eighty-one of this year’s cases occurred in July or later. Targets have ranged from online shops and member services to business systems and customer-support platforms, including a library catalog and a tourist train booking system. High-profile examples include Park24’s Times Car service, where data on about 6.6 million accounts was obtained, and Yakiniku King’s app, where more than 10.7 million records reportedly leaked. 

JPCERT/CC identified three main intrusion patterns. First, attackers analyze publicly released mobile apps to discover API endpoints and keys, then send unauthorized requests—sometimes to internal APIs that should not be reachable through the app. These requests have been used to alter user privileges, create unauthorized accounts, test authentication behavior, and extract data through blind NoSQL injection. Attackers have also used API keys stolen in earlier compromises. In other cases, they exploit weak administrator passwords, known software vulnerabilities, excessive data exposure, broken access controls, and session-management flaws. 

A particularly serious vector involves Metabase, an open-source business-intelligence tool. Attackers exploited CVE-2026-72898, a maximum-severity SQL injection flaw that requires no account to abuse and can grant administrator access to Metabase’s application database. From there, an intruder could steal credentials for connected databases and export their contents. Metabase patched the issue on August 6, but attacks continued afterward; the company has urged users to move to newer minimum-safe releases and, where upgrading is not immediately possible, to block the affected password-reset endpoint. 

For defenders, JPCERT/CC recommends applying access controls to every API endpoint, including internal ones; enforcing least-privilege permissions; rate-limiting sensitive functions such as login, password reset, and search; and ensuring tokens expire and can be revoked quickly. Organizations should also avoid embedding API keys or database credentials in shipped apps, review admin functions in vulnerability testing, restrict regional access where appropriate, and remove data no longer needed. Japan’s Personal Information Protection Commission issued a parallel alert, urging businesses to reassess whether the personal data they hold remains necessary. The message is clear: basic API hygiene, configuration review, and prompt patching remain decisive defenses.

Rubrik Expands Project Hourglass to Bring AI-Powered Code Security to Enterprise

 



When Rubrik launched Project Hourglass at its FORWARD 2026 conference in Las Vegas back in June, the initiative set out to answer a question CISOs were already losing sleep over: what happens when an AI agent writing and deploying your code does something catastrophic and nobody can stop it in time?

On Thursday, at its GSI Summit in Goa, India, the cybersecurity firm announced the next step. Rubrik has expanded Project Hourglass to include a new tool called Rubrik Code Guardian, and has welcomed AHEAD, Trace3, and World Wide Technology (WWT) into the alliance, joining the six systems integrators that signed on at launch. The new capability is powered by Anthropic's Claude Mythos 5 and extends the alliance's reach from securing AI agents during execution to proactively identifying vulnerabilities in software code before deployment.


The Problem Driving All of This

Rubrik Zero Labs surveyed more than 1,600 IT and security leaders for its State of the Agent report and found that 86 percent expect AI agents to outpace their security guardrails within a year, while only 23 percent report full visibility into agents operating in their environments. More than 80 percent said agents require more manual oversight than the efficiency they save.

A separate Rubrik and Economist Enterprise study found 88 percent of enterprises experienced an AI agent security breach in 2026. The picture those numbers paint is one of organizations racing to deploy autonomous systems while the controls meant to govern them are still catching up.


What Code Guardian Does

The original Project Hourglass, which launched with Cognizant, Deloitte, LTM, HCLTech, NTT DATA, and Wipro as founding partners, focused on protecting AI agents at runtime through Rubrik Agent Cloud. That platform operates across three layers: Runtime Agent Security for behavioral guardrails and blast-radius control, Agent Rewind for fast repository recovery, and AI Context Guard for prompt integrity and control-plane protection.

Code Guardian shifts the security lens earlier in the development cycle. Rather than running against live production environments, the system tests a cloned, air-gapped copy of customer repositories. Claude Mythos 5 operates inside Rubrik's security harness to evaluate code against sophisticated, multi-step threat scenarios.

Three core capabilities define the product: isolated red-team analysis inside the air-gapped environment; attack chain discovery that reasons across files, services, identity roles, and cloud perimeters to find chained vulnerabilities that conventional static tools miss; and business impact prioritization that filters findings by actual exploitability and business criticality to reduce alert fatigue.

Alok Agrawal, Chief Solutions Officer at Rubrik, put the challenge plainly. "Engineering teams are turning to AI models to accelerate software delivery, but speed cannot compromise security or architectural integrity. By incorporating Rubrik Code Guardian into Project Hourglass, we are ensuring engineering teams are able to conduct red-team analysis, prioritize business impact and reduce risk."


The New Partners

Each of the three incoming partners brings a different angle to the coalition.

AHEAD, which builds enterprise technology architectures for large clients, framed the problem as one of inherited risk. Steven Sorensen, Specialty Solutions Engineer for Cyber Resiliency at AHEAD, said the goal is to get code attacked, tested, and validated in a safe environment before it ships, so teams can move faster knowing Rubrik's recovery capabilities sit underneath them as a safety net.

WWT's Chris Konrad, Vice President of Global Cyber, pointed to the company's Advanced Technology Center, where isolated threat testing has long been part of how it validates security solutions before recommending them. He said Code Guardian integrates naturally with that process.

Trace3 brought a perspective the others did not: its own teams have been running Rubrik Agent Cloud internally to protect their own agentic AI work before recommending it to clients. Sandy Salty, Chief Marketing Officer at Trace3, said that experience as both a user and a partner gives the firm a clearer view of what actually makes agentic environments more resilient at scale.


Where Things Stand

Rubrik Code Guardian is currently in private preview and accepting select design partners. It is not yet generally available and may change or be discontinued. Rubrik Agent Cloud, the original platform at the center of Project Hourglass, remains available to enterprise clients.

Dev Rishi, GM of AI at Rubrik, has previously described the core problem in stark terms: with AI agents, there is the potential for ten times the damage in one-tenth the time. That framing captures why the urgency behind Project Hourglass is unlikely to ease. As the volume of AI-generated code increases across enterprise environments, the window between a vulnerability being introduced and it being found by someone with bad intentions keeps getting smaller.



Featured