Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Attackers Are Already Exploiting SonicWall’s Freshly Patched Max-Severity SMA1000 Flaw

 



Just three days after SonicWall shipped a patch for a maximum-severity vulnerability in its SMA1000 secure remote access appliances, attackers have started scanning for and exploiting the flaw in the wild.

The vulnerability, tracked as CVE-2026-102255 and carrying a perfect CVSS score of 10.0, is a pre-authentication server-side request forgery (SSRF) bug living inside the Appliance WorkPlace interface. Because it requires no login to trigger, any remote attacker can send a crafted request to a vulnerable device and force it to relay traffic to internal services that should never be reachable from outside.

SonicWall released hotfixes on October 7 alongside three other patches and, at the time, said it had found no evidence the flaw was being actively exploited. By Friday, that had changed.


How the Exploit Works

Ryan Dewhurst, founder of security firm Previdian, said that his company's honeypot network had picked up exploitation attempts matching the CVE-2026-102255 attack pattern. The requests were not subtle.

Attackers sent a crafted OPTIONS request to the WorkPlace Extraweb interface, using it to tunnel through to the appliance's internal CouchDB service running on localhost at port 5984. From there, the payload attempted to navigate into a CouchDB design document and call its \_rewrite function, while passing an HTTP Basic Authorization header carrying the credentials admin:admin.

It is an opportunistic probe, but it tells you something: whoever is sending these requests already has a working technique and is scanning for any devices that have not yet been patched.

Dewhurst noted that while the activity is consistent with active exploitation attempts, Previdian has not confirmed whether any of those attempts actually compromised a system.

This also is not a copy of the SSRF attacks that hit SMA1000 devices in July or September. CVE-2026-102255 targets the same WorkPlace interface, but uses a different technique than the zero-days disclosed in those earlier incidents.


Who Is Exposed

The flaw affects SMA1000 models 6210, 7210, and 8200v running firmware versions 12.4.3-03526 and 12.5.0-02952 and older. SonicWall confirmed that neither the SMA 100 Series product line nor SSL-VPN functionality on SonicWall firewalls are affected.

Internet threat monitoring organization Shadowserver currently tracks more than 400 SMA1000 appliances with public-facing exposure. That figure does not separate out honeypots or already-patched devices, so the real pool of vulnerable targets could be smaller, though the number is still of importance.

SMA1000 gateways sit at the front door of corporate and government networks. Managed Service Providers, large enterprises, and government agencies rely on them to extend VPN access to internal applications for remote employees. That makes them a high-value target for nation-state actors and financially motivated cybercriminals alike.


A Pattern That Keeps Repeating

CVE-2026-102255 is the third time in 2026 alone that SonicWall has patched a CVSS 10.0 pre-authentication SSRF flaw in the WorkPlace interface that requires no login to exploit. The two that came before it were both turned into weapons before organizations could patch at scale.

In July, threat actors spent weeks exploiting two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, to plant custom malware families called Sou5, OrangeTail, and RootRun on compromised appliances. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later tied several of those intrusions to ransomware operators.

In September, SonicWall confirmed attackers were chaining two fresh zero-days, CVE-2026-83548 and CVE-2026-83549, to achieve remote code execution on unpatched SMA1000 devices.

Zooming out further, CISA has added 19 SonicWall vulnerabilities to its Known Exploited Vulnerabilities catalog over the past four years. Thirteen of them have been flagged as actively used in ransomware attacks.

The October hotfix batch addressed three additional vulnerabilities beyond CVE-2026-102255. CVE-2026-102256, rated CVSS 7.8, is a post-authentication OS command injection flaw that could let an attacker with administrator credentials execute arbitrary commands on the appliance. CVE-2026-102257, rated 7.2, is a Zip Slip path traversal flaw in the Appliance Management Console that could allow file extraction outside the intended directory and potentially enable remote code execution. CVE-2026-102258, rated 5.5, is a stored cross-site scripting flaw in the same management console that could allow a logged-in administrator to inject and execute JavaScript.

SonicWall credited researcher Benoît Sevens with reporting CVE-2026-102255 and CVE-2026-102256, and Brian Mariani of DigitalCanion SA for the other two, one of which was submitted through Trend Micro's Zero Day Initiative.

SonicWall has urged all SMA1000 customers to apply the hotfixes immediately and has stated there are no alternative mitigations available for these vulnerabilities.





AI Adds to Open-Source Security Pressure as Vulnerability Reports Surge


AI Adds to Open-Source Security Pressure as Vulnerability Reports Surge A growing number of security vulnerabilities are being discovered using artificial intelligence, but the increased number is placing additional pressure on open-source developers. Despite the ability of AI tools to identify potential weaknesses within software at scale, security teams often find it difficult to verify the findings and rectify confirmed vulnerabilities before malicious hackers exploit them. 

The Chief Client Innovation Officer for Enterprise Security for IBM, Jamie Thomas, highlighted the sharp increase in vulnerability disclosures at the Linux Foundation Open Source Summit. In 2026, there are expected to be 66,000 unique vulnerability entries, representing a fourfold increase when compared with seven years ago. Cybercriminals are exploiting vulnerabilities at a faster rate, making the growing volume especially concerning. 

As reported by Thomas, exploiting a vulnerability has become less difficult due to the reduction in the time required to exploit it from days to 29 minutes. In some cases, attackers can exploit a vulnerability before a patch becomes available, leaving organizations with limited time to respond. Open-source software is particularly challenging due to the fact that a single vulnerable component can adversely affect thousands of applications and businesses. 

Most open-source projects are not staffed by large teams of developers or maintained by multiple individuals, which results in limited resources available for investigating and addressing security concerns. AI-Generated Reports Add to Developers’ Workload Although artificial intelligence-powered security tools are capable of identifying potential vulnerabilities, their findings are often inaccurate and actionable. 

Insufficiently researched reports, duplicate submissions, and false positives can consume valuable time for developers, which could otherwise be spent investigating genuine threats and preparing fixes. Major open-source projects have already been affected by this issue. The curl developers ended their HackerOne bug bounty program in 2026 following an increased number of low-quality and sometimes fabricated vulnerability reports, including reports generated with artificial intelligence tools. 

Similarly, Google temporarily suspended its Open Source Software Vulnerability Rewards Program on October 1, 2026, following an increase in invalid and irrelevant submissions. A reevaluation of the programme is planned for early 2027 by the company. 

Linux creator Linus Torvalds has also expressed concern over artificial intelligence-aided vulnerability reporting, particularly regarding the number of duplicate findings reaching Linux security mailing lists. Identifying flaws already fixed or disclosed can lead to additional work without necessarily improving security. 

IBM Proposes AI-Assisted Vulnerability Management Instead of treating artificial intelligence as a sole source of additional security findings, IBM's Jamie Thomas argued that it should be used as a resource to manage the increasing volume of vulnerability reports. Open source maintainers could use this approach to differentiate legitimate reports from duplicates and false alarms, assess severity, and focus attention on the most critical flaws. As a result of this cooperation among software companies, developers, and open-source communities, the Linux Foundation’s Open Source Security Foundation (OpenSSF) could play a crucial role. 

The use of artificial intelligence-based tools may provide developers with assistance in understanding vulnerable code and preparing patches, as well as assessing incoming reports, identifying vulnerabilities that are likely to be exploited, and recommending appropriate fixes. It is important to review automated remediation carefully, as a flawed fix can introduce new bugs or leave the original weakness unresolved. 

For validating vulnerability reports and proposed solutions, human expertise remains essential. It is important to note that the challenge extends beyond vulnerability management to the long-term sustainability of open-source projects as well. Technology companies rely heavily on open-source components, often without maintaining direct relationships with developers whose responsibility it is to secure those components. 

When critical flaws emerge, limited funding and engineering resources can delay investigation and patch development. An increase in open-source security investment could contribute to alleviating this imbalance. Those businesses that rely on widely used software are strongly committed to supporting the projects that underpin their products and services, whether through financial contributions, engineering assistance, or a closer collaboration with the maintainers. 

AI has the potential to accelerate vulnerability discovery, but that advantage will not be as valuable if developers are unable to keep up with the resulting workload. To transform AI-driven discoveries into significant improvements in security, it is essential to combine automated analysis with reliable human review, as well as to strengthen coordination and sustain support for open-source projects.

Fake Ransomware Recovery Firm Charged Over $11M Decryption Markup

 

The owner of a US cybersecurity company has been charged with running a ransomware recovery fraud that allegedly involved secretly paying attackers for decryption keys and then charging victims a large markup. Zohar Pinhasi, 50, owner of MonsterCloud and also known as “Zack Silver” and “Zack Green,” appeared in a New York court on wire fraud charges. Prosecutors say his company claimed it could recover encrypted data without paying ransom, while it actually relied on ransom payments obtained from the same criminal groups.

According to the indictment, Pinhasi marketed MonsterCloud as a ransomware remediation service that used proprietary tools and advanced decryption techniques. He reportedly warned victims not to pay ransomware operators directly, positioning his firm as a safer alternative. In reality, investigators allege that he contacted the ransomware groups responsible for the attacks, paid them for decryption keys, and then used those keys to restore clients’ files while charging them for supposedly independent recovery work.

The alleged financial gap was substantial. Pinhasi is accused of paying more than $8 million in ransoms while billing clients over $19 million, creating an estimated $11 million markup. In one example, he allegedly paid a ransomware affiliate about $8,200 for a decryption key and then charged the affected client approximately $150,000. Prosecutors say the scheme effectively caused victims to pay twice—first through inflated recovery fees and indirectly through the ransom payments made on their behalf.

The case highlights a serious trust problem in the ransomware incident-response market. Organizations under pressure to restore operations may accept claims of “guaranteed decryption” without verifying the technical basis for those claims. Genuine recovery can sometimes be possible through free decryptors, backups, or known flaws in ransomware strains, but no legitimate provider can promise recovery for every attack. Businesses should therefore ask providers for transparent methods, written scopes of work, references, and clear pricing before signing emergency contracts.

Pinhasi has been charged with wire fraud and wire fraud conspiracy and could face decades in prison if convicted. The allegations remain accusations until proven in court, but the case is a warning to ransomware victims: recovery services should be scrutinized as carefully as the original cyberattack. Independent legal counsel, cyber insurance guidance, law-enforcement reporting, and verified incident-response specialists can help organizations avoid becoming victims a second time 


Public Exploit Reveals Critical AnyDesk Linux Vulnerability That Could Allow Root Access


Security experts have released a functional exploit demonstrating how a vulnerability in AnyDesk for Linux could be abused to gain the highest level of system privileges without authentication. The flaw could put computers running vulnerable versions of the remote desktop software at risk if attackers can reach the affected service.

The exploit, called AnyPwn, shows a weakness in the way AnyDesk processes certain connection data. Researchers demonstrated that the vulnerability could be exploited to execute code with root-level permissions on a targeted Linux machine.

AnyDesk is widely used for remote access, technical support and system administration. A security weakness in such software can be particularly dangerous because it may provide attackers with a route into systems that would otherwise be protected by authentication mechanisms.

How the flaw works

The security issue stems from a heap buffer overflow associated with AnyDesk's session protocol. Researchers linked the problem to an integer overflow that can cause the application to allocate an insufficient amount of memory when processing incoming data.

A buffer overflow occurs when a program writes more data into a memory area than it was designed to hold. This can damage adjacent memory and, under certain circumstances, allow an attacker to influence the program's execution.

In the reported case, the integer overflow affects the memory allocation process, creating conditions that can be exploited to compromise the application. The researchers developed AnyPwn to demonstrate that the weakness could be triggered before authentication.

The exploit was tested against AnyDesk for Linux version 8.0.2. Researchers demonstrated exploitation through direct TCP connections on port 7070. However, they did not establish that the same attack could be completed through AnyDesk's relay infrastructure.

Risks for Linux systems

The possibility of obtaining root privileges makes the vulnerability especially dangerous. Root access gives a user or process extensive control over a Linux system, including the ability to modify protected files, change configurations and install software.

An attacker who successfully exploits the flaw could potentially gain control of an affected computer, access confidential information or deploy malicious tools. In an organizational environment, a compromised machine could also become a foothold for further attacks against internal systems.

Updates and security recommendations

According to the report, AnyDesk fixed the vulnerability in version 8.0.3, released in June 2026. Users running earlier Linux versions should update to version 8.0.3 or a newer supported release.

Atlassian CVE-2026-21589 Exploited Hours After Public Disclosure

 

Attackers started scanning the systems vulnerable to the Atlassian flaw several hours after the researchers published the technical details and proof-of-concept code. Assigned the identifier CVE-2026-21589, the vulnerability impacts several self-hosted Data Center products and could allow unauthorized access to the credentials in some circumstances. 

The problem was disclosed by Atlassian on October 5, 2026, with a CVSS score of 9.3. The products affected by the bug are Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. The company already released fixes for all software versions. The flaw allows the adversaries to access some files in the application root directory without providing proper authentication. 

However, it is only possible if the attacker knows the exact name and location of the file because the vulnerability does not allow listing the contents of a directory. Therefore, the attack surface is limited, but there is still a potential risk if the adversary somehow manages to guess the file location. The security researchers from WatchTowr posted the proof-of-concept code and technical details of the discovered flaw on October 6, 2026. 

They managed to identify the origin of the issue – a popular library used in all Atlassian products mentioned above. More importantly, they found out that the vulnerability could be chained to get access to the configuration file with Crowd application credentials in some circumstances. According to WatchTowr, Crowd is Atlassian’s identity management system, and the mentioned scenario involves Jira Software connected to it. 

In this case, the attacker could use the credentials to create a new administrative account and assign it to the Jira administration group. As a result, the adversary would be able to attain full privileged access to the targeted Jira Software instance. In addition, the security company showed how the proof-of-concept code could be used to take over a victim’s account in case of success. Moreover, the researcher added that the attacks are not random, but rather targeted. 

Several hours after the publication of the results, the exploitation framework started scanning corporate websites to find the instances of the affected applications. On October 8, 2026, Previdian, the exploitation intelligence company, counted 190 attempts from 32 IP addresses in 10 countries. Although the United States Cybersecurity and Infrastructure Agency (CISA) has not included the vulnerability in the Known Exploited Vulnerabilities list, the attacks indicate that the problem needs urgent attention. 

The companies using Atlassian’s products should make sure that the affected applications are updated to the latest versions. Those who are not able to do it right away should take the vulnerable instances of the software offline or follow the recommendations stated by Atlassian. In particular, the company suggests deploying the blocking rules to the firewalls or using the Web Server rewrite rules. 

In addition, the organizations with Jira Software and Crowd should make sure that the mentioned applications are not at risk of compromise as well. As seen from the recent incident, the response to the exposure of the flaw may take too long. Moreover, the attacks are often launched right after the proof-of-concept code is published. Therefore, it is critical to apply the necessary security updates as soon as possible.

Japan Reports Sharp Rise in Web Data Leaks

 

Japan is experiencing a sharp rise in personal-data leaks from web systems, according to an October 2026 alert from the JPCERT Coordination Center. The incidents, which surged around September, are separate from ransomware and other routine breaches, and JPCERT/CC says they may be increasing. While the agency did not identify attackers or affected organizations, it described the available evidence as limited and fragmentary, and cautioned that the same technique was not necessarily used in every case. The pattern points to attackers systematically probing web applications and APIs for basic security weaknesses rather than relying on one universal exploit.

The scale is substantial. Security firm Macnica counted 119 publicly disclosed incidents in Japan through October 6 in which personal data was stolen or leaked through organizations’ web systems—up from 84 in all of 2025 and 62 in 2024. Eighty-one of this year’s cases occurred in July or later. Targets have ranged from online shops and member services to business systems and customer-support platforms, including a library catalog and a tourist train booking system. High-profile examples include Park24’s Times Car service, where data on about 6.6 million accounts was obtained, and Yakiniku King’s app, where more than 10.7 million records reportedly leaked. 

JPCERT/CC identified three main intrusion patterns. First, attackers analyze publicly released mobile apps to discover API endpoints and keys, then send unauthorized requests—sometimes to internal APIs that should not be reachable through the app. These requests have been used to alter user privileges, create unauthorized accounts, test authentication behavior, and extract data through blind NoSQL injection. Attackers have also used API keys stolen in earlier compromises. In other cases, they exploit weak administrator passwords, known software vulnerabilities, excessive data exposure, broken access controls, and session-management flaws. 

A particularly serious vector involves Metabase, an open-source business-intelligence tool. Attackers exploited CVE-2026-72898, a maximum-severity SQL injection flaw that requires no account to abuse and can grant administrator access to Metabase’s application database. From there, an intruder could steal credentials for connected databases and export their contents. Metabase patched the issue on August 6, but attacks continued afterward; the company has urged users to move to newer minimum-safe releases and, where upgrading is not immediately possible, to block the affected password-reset endpoint. 

For defenders, JPCERT/CC recommends applying access controls to every API endpoint, including internal ones; enforcing least-privilege permissions; rate-limiting sensitive functions such as login, password reset, and search; and ensuring tokens expire and can be revoked quickly. Organizations should also avoid embedding API keys or database credentials in shipped apps, review admin functions in vulnerability testing, restrict regional access where appropriate, and remove data no longer needed. Japan’s Personal Information Protection Commission issued a parallel alert, urging businesses to reassess whether the personal data they hold remains necessary. The message is clear: basic API hygiene, configuration review, and prompt patching remain decisive defenses.

Rubrik Expands Project Hourglass to Bring AI-Powered Code Security to Enterprise

 



When Rubrik launched Project Hourglass at its FORWARD 2026 conference in Las Vegas back in June, the initiative set out to answer a question CISOs were already losing sleep over: what happens when an AI agent writing and deploying your code does something catastrophic and nobody can stop it in time?

On Thursday, at its GSI Summit in Goa, India, the cybersecurity firm announced the next step. Rubrik has expanded Project Hourglass to include a new tool called Rubrik Code Guardian, and has welcomed AHEAD, Trace3, and World Wide Technology (WWT) into the alliance, joining the six systems integrators that signed on at launch. The new capability is powered by Anthropic's Claude Mythos 5 and extends the alliance's reach from securing AI agents during execution to proactively identifying vulnerabilities in software code before deployment.


The Problem Driving All of This

Rubrik Zero Labs surveyed more than 1,600 IT and security leaders for its State of the Agent report and found that 86 percent expect AI agents to outpace their security guardrails within a year, while only 23 percent report full visibility into agents operating in their environments. More than 80 percent said agents require more manual oversight than the efficiency they save.

A separate Rubrik and Economist Enterprise study found 88 percent of enterprises experienced an AI agent security breach in 2026. The picture those numbers paint is one of organizations racing to deploy autonomous systems while the controls meant to govern them are still catching up.


What Code Guardian Does

The original Project Hourglass, which launched with Cognizant, Deloitte, LTM, HCLTech, NTT DATA, and Wipro as founding partners, focused on protecting AI agents at runtime through Rubrik Agent Cloud. That platform operates across three layers: Runtime Agent Security for behavioral guardrails and blast-radius control, Agent Rewind for fast repository recovery, and AI Context Guard for prompt integrity and control-plane protection.

Code Guardian shifts the security lens earlier in the development cycle. Rather than running against live production environments, the system tests a cloned, air-gapped copy of customer repositories. Claude Mythos 5 operates inside Rubrik's security harness to evaluate code against sophisticated, multi-step threat scenarios.

Three core capabilities define the product: isolated red-team analysis inside the air-gapped environment; attack chain discovery that reasons across files, services, identity roles, and cloud perimeters to find chained vulnerabilities that conventional static tools miss; and business impact prioritization that filters findings by actual exploitability and business criticality to reduce alert fatigue.

Alok Agrawal, Chief Solutions Officer at Rubrik, put the challenge plainly. "Engineering teams are turning to AI models to accelerate software delivery, but speed cannot compromise security or architectural integrity. By incorporating Rubrik Code Guardian into Project Hourglass, we are ensuring engineering teams are able to conduct red-team analysis, prioritize business impact and reduce risk."


The New Partners

Each of the three incoming partners brings a different angle to the coalition.

AHEAD, which builds enterprise technology architectures for large clients, framed the problem as one of inherited risk. Steven Sorensen, Specialty Solutions Engineer for Cyber Resiliency at AHEAD, said the goal is to get code attacked, tested, and validated in a safe environment before it ships, so teams can move faster knowing Rubrik's recovery capabilities sit underneath them as a safety net.

WWT's Chris Konrad, Vice President of Global Cyber, pointed to the company's Advanced Technology Center, where isolated threat testing has long been part of how it validates security solutions before recommending them. He said Code Guardian integrates naturally with that process.

Trace3 brought a perspective the others did not: its own teams have been running Rubrik Agent Cloud internally to protect their own agentic AI work before recommending it to clients. Sandy Salty, Chief Marketing Officer at Trace3, said that experience as both a user and a partner gives the firm a clearer view of what actually makes agentic environments more resilient at scale.


Where Things Stand

Rubrik Code Guardian is currently in private preview and accepting select design partners. It is not yet generally available and may change or be discontinued. Rubrik Agent Cloud, the original platform at the center of Project Hourglass, remains available to enterprise clients.

Dev Rishi, GM of AI at Rubrik, has previously described the core problem in stark terms: with AI agents, there is the potential for ten times the damage in one-tenth the time. That framing captures why the urgency behind Project Hourglass is unlikely to ease. As the volume of AI-generated code increases across enterprise environments, the window between a vulnerability being introduced and it being found by someone with bad intentions keeps getting smaller.



Hackers Exploit Two Unpatched AhsayCBS Flaws to Deploy Webshells and Cryptominers

 

Two security flaws in AhsayCBS backup management software are currently being actively exploited by attackers to initiate remote access to the targeted systems, establish webshells, and cryptocurrency miners. Huntress reported that the flaws are being used in attacks that chain the two issues together to bypass authentication and run commands on vulnerable systems. 

At least five companies have been reported targeted as of October 8, 2026. The vulnerabilities tracked as CVE-2026-105133 and CVE-2026-105134 are generic for the AhsayCBS product, which serves as a centralized management system for managed service providers and system integrators that need to configure and control backup policies and schedules, storage, and users. Both flaws are caused by improper function arguments, which enable an attacker to bypass authentication and execute operating system commands. 

The National Institute of Standards and Technology (NIST) published information about the disclosed security issues on October 4, 2026. Initially, all AhsayCBS versions up to 10.3.2. were considered to be affected. However, Huntress revealed that the company’s latest version at the time, 10.3.4., was also vulnerable. One of the vulnerabilities, CVE-2026-105134, is a remote code execution issue that allows an unauthenticated attacker to run code with System-level privileges. It utilizes an API in AhsayCBS’s Replication Receiver component to establish a reverse connection to an attacker-controlled server. 

An attacker can leverage the Replication Receiver bug by creating a fake replication receiver and delivering a Java Server Page webshell in the application directory served by AhsayCBS. After establishing initial access to the system, the threat actor performs inventory collection and uses Microsoft Edge-labeled XMRig cryptocurrency miners. Huntress discovered that the attackers used an AI-powered PowerShell script that terminates itself if the Task Manager is opened for more than 50 seconds. 

In addition, the script monitors whether the Task Manager has been closed and reopened. The attackers also create a new Windows service that masquerades as Microsoft Edge Updater. It employs an alternate data stream and runs as a System process when using the Non-Sucking Service Manager tool. The service carries the msedge.exe file with custom modifications applied.  The modifications to the Non-Sucking Service Manager allow it to maintain a durable process that restarts applications that were terminated due to an error or when the system restarts. 

The attackers also installed a legitimate but deprecated kernel-mode driver called WinRing0x64.sys, which provides userspace programs with kernel-mode privileges. This component enables the cryptocurrency miner process to maintain persistence even after system reboots. AhsayCBS software, utilized in the attacks, does not currently have a patch available. 

As such, organizations are recommended to restrict access to the management portal by only allowing specific IP addresses or networks, such as those provided by a virtual private network. 

In addition to that, administrators should monitor their systems for signs of compromise, such as webshells, unknown services, scripts, and cryptomining activities. Attackers are currently leveraging the AhsayCBS flaws to target businesses. 

The widespread nature of the issues, as well as the utilization of the latest version of the software at the time of publication, should compel organizations using it to consider limiting access and conducting comprehensive reviews.

Microsoft Exchange Vulnerability Could Leak Confidential Organizational Info


Microsoft has issued an emergency security update to fix a vulnerability in Exchange Server that could expose confidential organizational communications. The flaw, tracked as CVE-2026-96940, has received a CVSS severity score of 8.8 out of 10.

Reported by TechRadar, the vulnerability could allow attackers who already have valid login credentials to increase their privileges within Exchange and access mailboxes belonging to other users. Microsoft released the fix on October 2, ahead of its originally intended schedule.

About the flaw

The security issue stems from a weakness in authorization controls, which determine what information a user can access. By exploiting the flaw over a network, an authenticated attacker could gain permissions beyond those assigned to their account.

Threat actors could first obtain credentials through phishing attacks or by purchasing stolen login details from underground online markets. Once inside an organization’s Exchange environment, they could exploit the vulnerability to read emails and attachments belonging to other employees.

However, the flaw does not provide unrestricted access across different customer environments, known as tenants. It also does not directly grant administrator-level or SYSTEM-level privileges on the underlying Windows server.

What happens in case of successful exploitation?

Successful exploitation could expose sensitive business information, including financial records, invoices, contracts, customer correspondence, internal discussions, and confidential documents.

Attackers could use the stolen information to support further cyberattacks. For example, they might impersonate company employees, send convincing fraudulent emails, or conduct business email compromise (BEC) scams to trick organizations into transferring money or disclosing additional information.

The vulnerability is particularly problematic because an ordinary employee’s compromised account could potentially provide an entry point for accessing information held in other employees’ mailboxes.

Affected products

The vulnerability affects the following on-premises products:

  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Updates 14 and 15

Microsoft has confirmed that Exchange Online customers are protected by a server-side fix. Organizations running affected on-premises installations should install the appropriate security updates promptly.

Exchange Server 2016 and 2019 have reached the end of their standard support lifecycle. Eligible organizations must be enrolled in Microsoft’s Extended Security Update programme to receive the relevant updates for these versions. Microsoft recommends that organizations without the required coverage migrate to Exchange Server Subscription Edition.

Microsoft’s response 

Microsoft reported no evidence that the vulnerability was being actively exploited at the time of the report. However, the company assessed that exploitation was more likely, making timely patching important.

Administrators should run Microsoft’s Exchange Server Health Checker after installing the update to verify successful deployment and identify any additional actions required.

Russian-Aligned Spies Upgrade MATCHBOIL Malware Targeting Ukraine


The Russian-aligned cyber espionage group UAC-0099 has continued developing the MATCHBOIL malware for use in attacks against Ukrainian companies involved in transportation, manufacturing, and energy. Several changes have been made to the malware since 2024, according to research conducted by cybersecurity firm ESET, with newer versions adding techniques designed to make detection and analysis of the malware more difficult.

Researchers at ESET analyzed MATCHBOIL samples collected between April 2024 and April 2026 in a report published on October 8, 2026. Based upon the findings, the downloader appears to be becoming more sophisticated with each new version. While the Ukrainian Computer Emergency Response Team (CERT-UA) first documented the malware in August 2025, earlier samples indicate that the malware had been developing for at least a year prior. 

Matchboy is a C#-based downloader designed for retrieving additional malicious payloads from a command-and-control (C2) server, installing them on compromised systems, and maintaining their presence ESET's telemetry identified victims exclusively in Ukraine, including transportation companies between July and August 2025, a manufacturing organization in December 2025 and a company in the energy sector in June 2026. 

In order to spread the malware, spear-phishing emails containing malicious links are used. Once a recipient clicks the link, an archive containing VBScript is downloaded. MATCHBOIL is then downloaded and executed on the victim's computer, thereby giving the attackers the opportunity to introduce further malicious components. 

Although the level of confidence in UAC-0099's alignment with Russian interests was described as medium, ESET concluded that it was likely aligned with Russian interests. This group has previously targeted Ukrainian government agencies, financial institutions, and media institutions, proving MATCHBOIL to be another component of its broader cyber espionage activities. 

MATCHBOIL has modified its code so that it is harder to inspect, thereby making its activity less visible. It was previously obfuscated with basic Unicode, but newer samples use Eziriz .NET Reactor, which complicates reverse engineering. The malware has also been updated to detect virtual or analysis environments and to stop it from running under these conditions. 

Additionally, the malware's execution pattern has changed. A version seen from late 2025 started checking in roughly once every two minutes for additional or updated components, as opposed to earlier versions that contacted the command-and-control server once to retrieve a payload. It has also evolved over time to keep the malware active on compromised systems, switching between Windows Registry Run keys and scheduled tasks. 

Researchers have also noted attempts to make the malware appear legitimate in the past. The late-2025 variant was able to display a daily planner interface when manually launched, but interface errors rendered it unconvincing. 

However, the sample identified in February 2026 was more conspicuous, showing a text-search utility. Other malicious tools have also been associated with MATCHBOIL, including MATCHWOK, a backdoor that enables the execution of remote commands, and DRAGSTARE, a cookie and browser credential stealer.

This combination allows the group to expand beyond initial access and engage in further activities on compromised systems. ESET's findings indicate that UAC-0099 continues to refine MATCHBOIL for future operations. There is no accurate figure of the number of organizations affected by the campaign, as neither ESET nor Ukraine's CERT-UA have provided a confirmation of the number of victims.

PoeLLM Campaign Compromises 3,400+ Servers for Crypto Mining


Cryptocurrency mining campaigns have compromised over 3,400 servers since April 2026, with attackers primarily targeting exposed artificial intelligence and large language model infrastructures. The campaign is referred to as Canto Incognito and exploits vulnerable internet-facing services through PoeLLM malware, which becomes part of a growing mining botnet by exploiting vulnerable internet-facing services. 

Infections have largely been reported in the U.S. and Western Europe with nearly 2,200 affected servers at its peak at mid-June. Lumen Black Lotus Labs has reported that the malware has affected enterprise deployments such as LiteLLM, Ollama, Gotenberg, Gitea, and possibly Ivanti Sentry. 

The choice of artificial intelligence-based infrastructure has a significant impact on cryptocurrency mining due to the substantial computing resources that such systems are capable of providing. Some of the compromised servers may also be used to scan for additional vulnerable systems, which can help the attacker expand the botnet once they have been compromised. 

PoeLLM stands out due to its unique command-and-control mechanism (C2) Instead of placing the server address directly in the malware, the attacker concealed it in a poem hosted on GitHub. On April 13, 2026, the repository was created under the username “ejejejdfbbebebe,” with the first relevant commit being recorded. Throughout the campaign's change to its C2 infrastructure, the poem, titled "On the Nature of Connection," has been modified several times. 

By using a dictionary embedded in its code, the malware extracts selected words from fixed sections of the poem and maps them to numerical values. Those values are combined to determine the IPv4 address of the active C2 server. If the attacker changes the selected words, infected systems will be able to determine the new address without requiring a new sample of malware. 

A campaign's effectiveness is not only determined by the initial compromise. Once PoeLLM gains access to a compromised server, it can use the compromised system to locate additional targets. Black Lotus Labs observed a significant amount of scanning activity involving ports 3000 and 4000, which are commonly used to access Gotenberg and LiteLLM deployments. In order for vulnerable systems to retrieve malware from the active C2 infrastructure, crafted HTTP requests were sent to them. LiteLLM was a significant target in this activity. 

The analyzed malware sample referenced CVE-2026-42271, a command injection vulnerability associated with /mcp-rest/test/connection. In addition to providing attackers with access to exposed artificial intelligence infrastructure, PoeLLM also features cryptocurrency mining capabilities. This allowed attackers to launch further attacks on compromised systems. 

Infection involves the deployment of XMRig and Iron miners as well as the connection of compromised systems to the Kryptex mining service. The attackers can benefit greatly from the use of AI infrastructure because many such environments are run on advanced hardware with GPUs capable of providing significant computing power for mining. 

The malware does not limit itself to mining. According to researchers, infected servers are able to perform additional malicious activities by using remote shell functionality, HTTP/S scanning, and exploit deployment. Recent activity against SSH ports and other login interfaces suggests that the operator may also be testing distributed brute-force attacks, though this capability is currently at an early stage. As a result of assessing the campaign with moderate confidence, Black Lotus Labs has determined that the attacker is an Italian-speaking individual. 

A combination of Italian-language comments found on malicious software and associated GitHub pages, as well as network traffic analysis, contributed to the assessment. There has been no identification of a specific individual or established criminal group. 

In this campaign, it illustrates the dual purpose of exposed artificial intelligence infrastructure for attackers: its computing resources can be monetized, while compromised machines are also able to assist in locating and compromising the next set of vulnerable systems. 

Recent attack by hackers motivated by financial gain has demonstrated how exposed AI and developer infrastructure can become valuable targets for attackers with financial motivations. As AI deployments expand across enterprises, strong patching, restricted internet exposure and proactive monitoring remain essential.

Southern Company Discloses Data Breach Affecting 400,000 Georgia Power and Alabama Power Customers

 



Southern Company, the Atlanta-based energy holding giant, has confirmed that an unauthorized third party broke into its online customer portal and accessed account information belonging to roughly 400,000 customers across its electric subsidiaries, Georgia Power, Alabama Power, and Mississippi Power.

The company publicly disclosed the breach on October 5, 2026, stating that the intrusion, which occurred in September, was detected through its own monitoring systems. Upon discovery, Southern Company said it moved quickly to shut down the unauthorized access and notified law enforcement.

"Southern Company recently detected suspicious activity involving our online customer portal," the company said in a statement. "An unauthorized third party accessed certain, limited information about the accounts of approximately 400K customers. Upon detection, we took immediate steps to stop the activity and have engaged law enforcement."

Of the roughly 400,000 accounts compromised, approximately 300,000 belong to Georgia Power customers. Alabama Power accounts for the remaining 100,000, which represents about 6% of its 1.6 million-customer base. Mississippi Power was named in the company's public notice as affected, but Southern Company has not released a customer count for that subsidiary.

According to the company's published incident notice, the data the attacker accessed includes customers' names, mailing addresses, phone numbers, email addresses, and the last four digits of their Social Security numbers, along with other unspecified basic account details. The company was clear about what was not taken: bank account numbers, payment card numbers, and driver's license numbers were not part of what the attacker pulled from the portal.

The online portal in question is the same platform customers use to pay bills and manage their accounts.

Despite the company's confirmation that it caught and stopped the intrusion, Southern Company has not said when exactly in September the breach occurred, nor has it explained how the attacker got past the portal's defenses in the first place. That absence of technical detail leaves open questions about the attack method, whether it involved stolen credentials, a software vulnerability, or some other approach.

Customers whose information was involved are being notified directly by both mail and email. Southern Company is also offering each affected customer one year of free credit monitoring through Equifax. Those with additional questions were directed to a dedicated assistance line at 1-800-900-6021, available Monday through Friday.

Southern Company, incorporated in 1945 and headquartered in Atlanta, is one of the largest energy holding companies in the United States. It supplies electricity through its subsidiaries to customers across three states and operates natural gas distribution businesses in four more. Its total customer base numbers over 9 million.

The incident sits alongside a string of recent cyberattacks targeting utility companies in North America and beyond. Just weeks earlier, in September 2026, Houston-based CenterPoint Energy disclosed that an unauthorized third party had obtained personal information on a portion of its customers through one of the company's external-facing systems. That disclosure came after a threat actor claimed on a cybercrime forum to have extracted 7.49 million customer records from the utility and ultimately leaked the data after the company failed to respond. In March 2025, Nova Scotia Power, Canada's largest electric utility in that province, suffered a cyberattack that disrupted its customer support line and web portal.

Research published by cybersecurity firm Trustwave in 2025 found that roughly 67% of credential access techniques used against energy and utilities companies involved brute force methods, which are largely automated attacks that cycle through large lists of usernames and passwords. That tactic, known as credential stuffing when it draws on passwords stolen from previous breaches on other platforms, has been used against utility customer portals before. In 2021, UK energy supplier Npower had to shut down its mobile app entirely after attackers used stolen credentials from other websites to access thousands of customer accounts.

The energy sector's digital attack surface has expanded considerably as utilities push more customer services online. Customers log into portals to check bills, set up autopay, and track usage, all of which requires storing personal data behind web-based logins. Security researchers have long pointed out that these portals often receive less security investment than back-end operational systems, even though they handle data that is directly useful for phishing, identity fraud, and social engineering.

Southern Company said it has found no evidence of ongoing unauthorized access following the breach, and noted that it continues to monitor its systems around the clock. The company's public notice also cautioned customers to be alert for fraudulent contact from individuals claiming to be Georgia Power or Alabama Power representatives, reminding them that neither utility will ever threaten immediate service disconnection or demand payment over the phone.

Anyone who believes they may have been affected and has not yet received notification from the company can contact Georgia Power customer service directly through the number listed on their bill.



ASOS Confirms Unauthorised Hack Notification; Customer Data May Be Exposed

 

On 6 October 2026, thousands of ASOS customers across multiple countries received a shocking push notification via the official ASOS app, claiming that hackers had breached the retailer’s systems. The message, which appeared around 10:00 BST, was addressed to ASOS’s data protection officer and IT team and warned that attackers had “fully compromised the Snowflake instance” and would leak data unless the company engaged with them. ASOS swiftly described the alert as an “unauthorised customer notification” and launched an investigation into what appears to be a cyber-extortion attempt routed through a third-party communications platform. 

The notification was headlined “ASOS HACKED” and read: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” followed by a link to an external Telegram channel signed by a user called “xuanyewengateway”. Many users reported feeling scared and confused, with some saying they no longer trusted the ASOS app after seeing the message arrive through what should be a secure, brand-controlled channel. Security experts described the incident as a brazen attempt to pressure ASOS publicly by hijacking its own customer-notification system, raising concerns about how attackers gained access to such a sensitive communications tool. 

In response, ASOS said it took immediate action to restrict access to the notification platforms and is working with internal and external cybersecurity specialists, as well as relevant authorities. The company confirmed that basic personal information, including names and contact details, may have been accessed during the incident, but it does not believe payment-card information or account passwords were impacted. ASOS stressed that its website and app remain fully operational and urged customers to disregard the unauthorised alert and not click any links contained within it, warning that doing so could expose them to further risks.

ASOS is not currently asking customers to change their passwords or take other specific actions, but it advises anyone who received the notification to ignore it and avoid engaging with the third-party link. The UK’s National Cyber Security Centre has gone further, suggesting that all ASOS customers should consider themselves potentially affected, even if they did not see the alert, and should only access ASOS via its official website or app. Users are also warned to be alert for follow-up scams, such as fake refund or support messages exploiting concern over the incident, and to treat any unexpected communication about the breach with caution. 

ASOS says its investigation into the unauthorised activity involving third-party communication platforms is ongoing, and it will provide updates if the situation changes. While the attackers claimed a Snowflake data-platform breach, Snowflake itself has stated it has found no compromise of its platform at this time. For now, ASOS maintains that push notifications are safe, operations are unaffected, and customers can continue to shop with confidence while the company works with cybersecurity advisers and law enforcement to understand exactly how the unauthorised message was sent and to prevent similar incidents in the future.

Chrome Blocks Unauthorized Certificates After Three ccTLD Hijacks

 

Chrome has taken steps to protect users after attackers compromised three country-code top-level domains and exploited the incidents to acquire unauthorized HTTPS certificates for multiple organizations. The affected namespaces are .gh for Ghana, .sl for Sierra Leone and .as for American Samoa. Attackers targeted the third-party registries which own the ccTLDs rather than Google directly. 

In addition to the country-code top-level domain takeovers, the adversaries also modified the authoritative DNS records to compromise several Google domains and domains of other companies. Chrome reported that it is not evident that Certification Authorities (CAs) that issued the certificates acted in bad faith but instead concluded that the problem stemmed from attackers’ tampering with DNS infrastructure of the country-code domains. 

Chrome’s Secure Web and Networking Team responded to the incidents by utilizing CRLSets to block the unauthorized certificates associated with Google properties and coordinated with the CAs to revoke the certificates, protecting the users of the browsers and other clients. The list of impacted entities grew as Chrome analyzed Certificate Transparency (CT) logs and identified a number of large publicly traded companies and popular internet services. 

The team blocked certificates it suspected to be related to the attacks and reached out to the impacted businesses. Users of Chrome do not need to take any action as the protections are designed to be transparent and work in the background. However, Google warned that organizations should not rely on the browser to protect them against the attacks and that Chrome did not identify all the affected domains. Similarly, protections worked on Google Chrome and may have not triggered in other browsers and clients. 

Organizations are advised to ensure that they monitor the CT logs for all the domains and that they are notified if an unauthorized certificate is issued. This is critical because every certificate that is trusted by the public must be reported to CT logs. For domains that are impacted by the ongoing attacks, it is recommended to look over the most recent certificates to ensure that they have not been issued without authorization. Google recommended the use of restricted Certification Authority Authorization (CAA) records and the use of ACME account bindings when available. 

CAA records dictate which CAs can issue certificates and, while they do not prevent an attacker from using a hijacked domain to issue a certificate, they can help in ensuring that unknown CAs are not utilized. Additionally, the CAA records can prevent attackers from using domain-control validation for certificate issuance through misdirection. Using issuing restrictions and validation method restrictions can prevent attackers from using certificates’ domain validation through cached entries. These protections are only effective after the control of the domain is re-established. 

Chrome announced its intent to keep working on long-term projects to improve security and reduce the risks associated with the use of certificates. The proposed changes include shortening the lifespan of certificates and limiting the re-use of domain validation. They will continue to work to improve the Chrome Root Program with the Chrome Quantum-resistant Root Program as the Chrome ecosystem seeks to mitigate the risks posed by DNS and routing compromises.

Japan Arrests Suspected Qilin Ransomware Hacker, Extradites Him to Germany


A suspected member of the Qilin ransomware group has been arrested in Japan and extradited to Germany, where he is expected to face charges related to cyberattacks and ransomware extortion. The case is important as it reveals a growing international effort to identify and prosecute individuals involved in major ransomware operations.

According to a report by SecurityWeek, the suspect is a 28-year-old Russian national who was arrested in Osaka, Japan, in May 2026. German authorities accuse him of playing a role in the Qilin ransomware operation, which has targeted organizations in several countries.

The suspect was extradited to Germany on October 2, 2026, following legal proceedings in Japan. German investigators allege that he was involved in an attack against a logistics company in September 2024.

Ransomware attack

Investigators say the targeted logistics company had its computer systems encrypted during the attack. The attackers allegedly demanded more than $160,000 in cryptocurrency in exchange for restoring access to the affected systems.

The incident is believed to have been connected to the Qilin ransomware operation, also known as Agenda. Qilin emerged as a ransomware-as-a-service (RaaS) operation in 2022. Under this model, ransomware developers provide malware and infrastructure to affiliates, who conduct attacks against victims and share the proceeds with the operators.

This business model has allowed ransomware groups to expand their operations without every attacker needing to develop their own malware or infrastructure.

Qilin's global activity

Qilin has become one of the more active ransomware groups in recent years. It has targeted organizations across different industries, including healthcare, manufacturing, professional services and other critical sectors.

The group attracted international attention after attacks linked to it disrupted healthcare services in the United Kingdom. It was associated with the 2024 attack against Synnovis, a medical services provider whose systems were used by several London hospitals. The incident caused significant disruption to healthcare operations.

Qilin has also been linked to attacks against major companies in other countries, demonstrating the international reach of the ransomware operation.

Experts have continued to track the group's activities and techniques. In 2026, Qilin was also reported to have exploited a critical vulnerability affecting Check Point security products as part of its attack activity.

AI Watermarking Meant to Protect Against Misuse Could Actually Enable It

 



A security feature designed to make AI text traceable appears to have an unintended side effect: it can change how a language model behaves, in some cases making it more willing to follow instructions it was built to refuse.

That is the core finding from new research by Lasso Security, published on September 17 by researcher Andrea Siposova under the title "The Provenance Tax: Understanding the Impact of LLM Watermarking on AI Agent Behavior." The study tested Google DeepMind's SynthID-Text watermarking system across six open-weight language models and found that enabling watermarking changed how those models responded to harmful requests, particularly when attackers used prompt-injection techniques designed to override a model's instructions.


What SynthID-Text Actually Does

To understand why that matters, it helps to understand what SynthID-Text actually changes inside a model.

When a language model generates text, it does not write the way a human does. It builds sentences one token at a time, each step producing a probability distribution over thousands of possible next tokens and then sampling from that distribution. SynthID-Text does not attach a label to the finished output or hide characters in whitespace. It intervenes at the sampling step itself.

The system uses a process called tournament sampling, first described in a 2024 Nature paper by Google DeepMind researchers Sumanth Dathathri, Abigail See, and colleagues. Instead of the standard randomness used in token selection, the watermark substitutes pseudorandom values generated from a secret key and the context of tokens already produced. The result is a statistically detectable pattern woven through the text at the level of individual word choices, invisible to readers but recoverable by anyone holding the key. The technique is refined enough that it does not degrade text quality in any measurable way, which is a large part of what made it attractive as a compliance tool.


The Regulatory Push Behind It

Article 50 of the EU AI Act requires providers of generative AI systems to mark their text, image, audio, and video outputs in a way that is machine-readable and detectable as AI-generated. The Code of Practice the European Commission finalized on July 20, 2026, requires at least two marking layers for audio, images and video, plus watermarking of free-form text longer than 200 tokens. Google signed the Code on July 24, 2026, citing SynthID partnerships as its route to the interoperable detection requirement due on February 2, 2027.

Anthropic's technical implementation is built directly on SynthID-Text, the same tournament-sampling mechanism from the Nature paper, adapted for their own models and keys. It covers claude.ai, the API, Claude Code, Claude Cowork, Claude Tag, and access through AWS, Google Cloud, and Microsoft Foundry. With the industry's largest players now committed to the same watermarking standard, Siposova's findings arrive at an uncomfortable moment.


What the Research Found

Siposova ran paired experiments on six open-weight models using Hugging Face's unmodified SynthIDTextWatermarkLogitsProcessor, enabling and disabling watermarking while keeping the seed, batch composition, and ordering identical.

Watermarking changed refusal behavior on harmful requests, but the effect was more pronounced when the same requests were paired with prompt-injection techniques. Under those conditions, several watermarked models complied with harmful requests their unwatermarked versions had rejected, with the strongest differences appearing in prompt-injection scenarios.

Siposova told Ars Technica that behavior was clearly different compared with the same model without watermarking, and that the differences were especially pronounced under adversarial conditions or when running an agent calling tools. She put it plainly: "Watermarking is made to not be perceptible to a reader, but we know that when we are changing anything about what the model is generating, it is going to cause some tradeoffs, it's going to show up somewhere."

Lasso repeated its prompt-injection experiment using 11 different watermark keys and found that changing the key could change both the size and direction of the effect. That means two different deployments of the same watermarking system, on the same model, could produce different safety outcomes depending purely on which key was chosen.


The Agent Problem

The consequences extend beyond what a model says. When a language model powers an AI agent, token selection can determine which tool an agent invokes and which arguments it passes. "Such a watermarking procedure can therefore affect both what the model says and what an agent does," the study stated. Watermarking reduced accuracy on six of seven models, with a substantial decrease on four.

Lasso's conclusions are deliberately careful. The study did not verify how Claude model responses change when watermarking is applied, and critics noted the experiment only validated the SynthID-Text tournament sampling implemented by Hugging Face, which differs from how the Claude model would actually implement it. Siposova stressed that the findings describe patterns in the tested sample, not universal rules about watermarking as a category.

Lasso recommended repeating agent evaluations and red-team testing when watermarking or its configuration changes, particularly under adversarial inputs.

The research surfaces a tension that will only sharpen as regulatory deadlines close in. Watermarking was designed to answer the question of where AI text comes from. What it can also do, under the right adversarial conditions, is change what the AI decides to do next.


Former Engineer Jailed for Ransomware-Style Cyberattack

 

A former employee of a New Jersey-based industrial company has been sentenced to 32 months in federal prison for launching a computer network attack and attempting to extort his former employer. Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced by U.S. District Judge Michael A. Shipp on September 28, 2026, at federal court in Trenton, New Jersey. The sentence followed his guilty plea to charges involving extortion through a threat to damage a protected computer and intentional damage to a protected computer. 

According to court documents and statements made during the proceedings, Rhyne previously worked as a core infrastructure engineer for the U.S.-based industrial company, identified in court records as Victim-1. While he was living in New Jersey in November 2023, he allegedly began preparing a plan to disrupt the company’s computer network and force it to pay a ransom. His position reportedly gave him technical knowledge and access that allowed him to plan the attack against the company’s critical systems. 

As part of the scheme, Rhyne initiated unauthorized remote desktop sessions and scheduled tasks designed to damage the company’s network. The planned actions included deleting network administrator accounts, changing passwords linked to other employee accounts and shutting down several company servers. These steps could have seriously disrupted business operations by preventing authorized staff from accessing systems and interrupting essential digital services. 

On November 25, 2023, Rhyne sent an extortion email to employees of the industrial company. In the message, he threatened to continue shutting down servers unless the company paid approximately 20 bitcoin. At the time, the cryptocurrency demand was valued at about $750,000. The case highlights how former employees with detailed knowledge of internal infrastructure can pose a significant cybersecurity risk, especially when access controls and administrative privileges are not promptly reviewed after employment ends. 

The investigation was conducted by special agents from the FBI’s Newark Field Office, with assistance from the FBI’s Kansas City Field Office. U.S. Attorney Robert Frazer announced the sentence, while Assistant U.S. Attorney Taj Moore of the Cybercrime Unit prosecuted the case. The conviction demonstrates that unauthorized access, deliberate disruption of computer networks and ransom demands can result in substantial federal prison sentences. It also underlines the importance of removing former employees’ access, monitoring remote sessions and protecting administrator accounts against misuse.

MALFEX npm Campaign Uses Three Malware Delivery Chains

 

A long-running malware campaign on the npm registry is using malicious JavaScript packages to compromise Windows systems with remote-access malware, information stealers and additional payloads. Researchers have linked the operation, known as MALFEX, to an apparent single operator active on npm since August 2023. 

The operator has published 12 packages, eight of which were found to contain malicious code. Together, the packages had recorded 40,767 downloads by October 1. However, those figures represent package downloads rather than confirmed infections. MALFEX currently uses three separate infection chains. The first delivers the Overlord Remote Access Trojan through packages including tlxbnhd, tldriver and mxdriver. 

Malicious installation scripts download and execute a Windows payload disguised as an image. Overlord can capture screenshots, keystrokes and clipboard data, search files and provide attackers with remote shell access. It also establishes persistence through a scheduled Windows task named “Maiden.” A second chain involves native-runner, img-to-native and cdn-img-fetch. 

Instead of relying on an npm installation script, the malicious code executes when the package is loaded. Data hidden inside an image is decrypted to produce a downloader, which retrieves movinlike, a Node.js information stealer. The malware targets Discord accounts, browser credentials, Telegram session data and cryptocurrency wallets before sending stolen information to an attacker-controlled Discord webhook. 

The third and longest-running chain revolves around function-flag. Its malicious versions contain code that downloads Windows executables from changing external locations. In version 1.7.3, a hidden routine triggered during installation downloads node.exe and executes it from the user’s application-data directory. function-color serves as a wrapper that installs function-flag. 

Three malicious packages remained installable as of September 29: function-flag, function-color and cdn-img-fetch. function-flag accounted for 37,419 downloads, making it by far the most widely downloaded package in the campaign. Despite that activity, it had no security advisory. function-color also lacked an advisory, while the advisory for cdn-img-fetch covered only versions 1.0.0 and 1.0.1, leaving malicious versions 1.0.2 and 1.0.3 outside its coverage. 

The campaign also uses several techniques to make detection harder. Malicious code can be hidden beyond the visible area of a typical editor, failed downloads may be suppressed without generating installation errors, and the attacker has published benign packages alongside the malicious ones. Security teams should block all eight identified malicious packages and check dependency trees and lockfiles for them. 

Any Windows system where one was installed should be treated as potentially compromised, isolated from the network and investigated. Organizations should also remove persistence mechanisms and rotate credentials from a clean device if sensitive accounts were used on the affected machine. 

MALFEX highlights the risk of relying solely on npm advisory feeds: malicious packages can remain installable even when related packages have been removed, while some dangerous versions may have no advisory coverage at all.

US Probes Cyberattack on Energy Tankers Over Possible Iran Ties


One of the Journal reported that US authorities are investigating a possible Iranian connection to cyberattacks targeting two energy tankers in August heading toward American ports. A number of vessels were attacked as they passed through the Strait of Gibraltar before proceeding towards Texas. These vessels were the oil tanker VL Prosperity and the liquefied petroleum gas carrier Kohaku which were targeted. 

At the time of the incident, the VL Prosperity was transporting more than two million barrels of oil from Egypt to Galveston, Texas. The Kohaku was also on its way to Texas where it was scheduled to load liquefied petroleum gas. Following the arrival of the vessels in the Gulf of Mexico, a specially trained cyber response team led by FBI personnel boarded both. 

The Coast Guard conducted several days of assessments of the incidents and checked to ensure that the vessels could continue operating safely after they discovered signs of a compromise of their information technology and operational systems. According to reports published in August, hackers gained access to the engine-room systems of the VL Prosperity and interfered with several engine functions, including cooling, speed, fuel, and engine oil. 

There was no claim of responsibility from any group, and the reported details were unable to be independently verified. Later on, the vessel's manager confirmed that US authorities examined the tanker's cybersecurity before clearing it for normal operations. This incident illustrates the risks associated with interconnected systems that are used aboard modern commercial vessels. 

As a result of the integration of information technology with propulsion, navigation, and engineering systems on board, it may be difficult for a successful intrusion to affect the vessel's physical performance. Neither incident has disrupted operational operations, caused harm to crews, or damaged the environment, and no attribution of these attacks has been made public to Iran. 

Additionally, the investigation takes place in the context of increased suspicions of Iranian-linked cyber activity by US agencies. A maritime security expert has warned that it may be difficult to determine the actual extent of attacks against shipping, especially when vessel operators restore systems quickly without thoroughly investigating how an intrusion occurred. 

According to Lloyd's List, US agencies are monitoring cyber threats involving almost 20 ships worldwide, which raises concerns over the growing vulnerability of commercial shipping. The risks extend beyond individual ships as well. Navigating, propulsion, steering, and other critical operations of commercial vessels are increasingly dependent on connected digital systems. The compromise of these systems could negatively impact a vessel’s movements or create broader difficulties around major shipping routes and ports. 

A serious disruption could result in a fire, explosion, or spill. An investigation of the tanker is also underway as key maritime routes are becoming increasingly congested. It is important to note that the crossing of the Strait of Hormuz has been repeatedly disrupted and attacked during the conflict, while Iran-backed Houthi forces have exerted increased pressure on vessels operating around the Red Sea and Bab al-Mandab Strait. 

Since cyberattacks could take place against vessels traveling outside these traditional conflict zones, maritime security concerns have been intensified. US authorities have not yet established that Iran was responsible for the attacks. There has also been no determination as to whether the attacks were connected to each other. Further investigations by the FBI and Coast Guard may clarify whether the attacks were isolated incidents or part of a broader campaign targeted at maritime infrastructure.