Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Half a Million GitHub Credentials Are Still Active, Most Have Been Sitting in the Open for Years





Researchers at Truffle Security tested 543,699 API keys, database passwords, and access tokens found in public GitHub repositories last July. Every single one authenticated. The median credential had been sitting in publicly readable code for 784 days.

The findings come from a scan of The Stack v3, a 224-million-repository snapshot of public GitHub code assembled to train large language models. The crawl closed on August 7, 2025. Eleven months later, when Truffle Security ran live verification against each issuing provider, more than half a million credentials still worked. That number is more than double the 221,303 live credentials the company found when it ran a similar scan against 7.6 petabytes of Hugging Face training data earlier this year.

The oldest credential in the dataset was last touched on June 13, 2009. It lives inside an Erlang web server configuration file, and it was still valid 16.1 years after it was committed. Behind it: an FTP login inside a GPS logger's C source code from September 2009, replicated across 62 repositories, and an AWS key tucked inside a Rails S3 config from November of that same year. Truffle Security declined to name the repositories because the credentials in them still work.


A Protection That Only Faces Forward

GitHub has progressively tightened its defenses around exposed credentials. The platform made secret scanning alerts free for all public repositories in February 2023. Push protection, which blocks a commit before it reaches the remote branch if it carries a recognised secret, became generally available in May 2023 and was switched on by default for all public repositories on February 29, 2024.

GitHub's secret scanning covers more than 200 token types and patterns from over 180 service providers. The rollout had a measurable effect on new leaks. Among credential shapes the system recognises and blocks, Truffle Security found a 53 percent drop in the rate of fresh exposures across the twelve months following the default rollout, compared to the twelve months before it. Slack tokens fell 64 percent, GitHub's own tokens and AWS access keys each fell 59 percent.

But push protection has no mechanism to reach the credentials already there. Of the 543,699 live credentials, 199,843 landed after push protection became the default in February 2024. Developers either bypassed the block or committed credential types the system does not recognise.

That second category is the larger problem. Truffle Security found that 51.8 percent of every live credential in the dataset is a shape that a default-configured public repository will accept without objection. Database connection strings, private keys, and Google API keys all fall outside the default block list. Push protection focuses on specific, highly identifiable secrets and misses generic ones. Connection strings and private keys are classified as generic patterns, and blocking them requires an organisation to go into settings and explicitly opt in.


The Gemini Problem

The Google API key situation illustrates the limits of pattern-based blocking in particularly sharp terms. The 33,343 live Google API keys in Truffle Security's dataset include 31,374 that authenticate specifically to Gemini, Google's AI model platform. Their median leak date is February 2025, meaning the entire population is younger than the push protection rollout.

Google API keys carry the prefix `AIzaSy` whether they were created for Google Maps, Firebase, or Gemini. GitHub's pattern list recognises the prefix but marks it as not push-protected, because a Maps key sitting in client-side JavaScript is not a secret by design. Google's own approach to API keys was historically built around the assumption that these keys would live in client-side code, exposed to anyone who opened a browser's developer tools. The problem is that Gemini runs on the same key format, turning what developers were trained to treat as a non-sensitive identifier into a billable AI credential. One pattern cannot distinguish between the two uses, so nothing gets blocked, and the keys that matter arrive alongside the keys that do not.


Revocation is the Deciding Variable

The most instructive comparison in the data is between providers that automatically revoke leaked tokens and those that do not.

npm committed 101,886 tokens to public code. One remains live. GitHub committed 73,048 tokens; 260 survived. Hugging Face committed 30,437; 15 are still valid. Each of these platforms runs an automated pipeline that kills a token the moment it is detected in public code.

The contrast with database credentials is stark. Of 12,985 Postgres connection strings in the dataset, 11,465 are still live, an 88 percent survival rate. MySQL connection strings survive at 75 percent. MongoDB, where the detector only reports a URI it successfully connected to, returned all 51,067 live.

Push protection blocks secrets at the door. Automated revocation kills them wherever they are. The Truffle Security data shows that the second mechanism is the one that changes the outcome, and for the majority of credential types sitting in public repositories right now, no provider is running it.

The practical guidance from the researchers: treat any committed credential as compromised regardless of whether anything flagged it, scan your own repository history rather than assuming the push-time block was sufficient, and favour credentials that expire automatically. Most of what Truffle Security found would have been harmless long ago if it had ever been given a finite lifetime.


AI Safety Concerns Put OpenAI and Anthropic Under FTC Scrutiny

 

Artificial intelligence companies are facing another layer of scrutiny in the United States, with the Federal Trade Commission examining whether increasingly capable AI products could expose consumers to unlawful or unexpected risks. 

OpenAI, Anthropic and other AI developers are among the companies being examined as part of the inquiry. Rather than focusing on a single incident, the investigation is expected to cover a wider range of potential consumer harms. These could include the handling of personal information, claims made about AI capabilities and situations in which AI systems operate in ways that create risks outside their intended use. The FTC is expected to seek information directly from the companies and could require senior executives to provide testimony. 

The investigation comes as developers have publicly acknowledged increasingly unusual behavior from advanced AI systems. OpenAI revealed over the summer that one of its AI systems had compromised Hugging Face. Similar disclosures were subsequently made by Anthropic and other companies. The FTC’s initial steps toward examining the issue, however, reportedly began before OpenAI publicly disclosed its incident. 

That timing gives the investigation a broader context. Regulators are not simply reacting to one publicly reported AI security incident but are examining how existing consumer-protection laws might apply as AI products become capable of interacting with computer systems, handling information and carrying out increasingly complex tasks. The FTC’s approach also comes against the backdrop of limited new federal AI regulation. 

The Trump administration has generally favored allowing the industry to develop with fewer new restrictions, with the administration arguing that the United States must compete with China in artificial intelligence. Trump has said he would encourage AI development and rely on agencies such as the FTC and Department of Justice to pursue misconduct under existing laws when necessary. AI executives and regulators have nevertheless discussed safety measures at the White House. 

OpenAI president Greg Brockman, Anthropic CEO Dario Amodei and FTC chair Andrew Ferguson were among those attending a meeting with Trump. The discussions resulted in a voluntary commitment from AI companies to develop protections against serious risks, including cyberattacks and chemical weapons. No new regulations were introduced as a result, and the companies also agreed to refer to AI at a certain level of capability as “super intelligence.” Ferguson’s position on AI companies has added another dimension to the FTC’s approach. 

While his agency has taken a less aggressive stance toward business regulation under his leadership, it continues to pursue cases involving companies including Meta and Amazon. Ferguson has also said AI developers could be held responsible for damage caused by their products. The latest inquiry is not the FTC’s first examination of OpenAI. The agency began investigating the company’s security practices in 2023 and issued a 20-page demand for information concerning personal data and how that information was being used in AI model development. 

OpenAI and Anthropic had not immediately commented on the latest investigation. As AI developers continue expanding what their systems can do, the FTC’s inquiry could help determine how existing consumer-protection rules are applied when those capabilities themselves become a source of potential harm.

Researchers Discover Exploit Kit Targeting iPhones in Mobile Malware


Researchers at the Ukrainian Cyber Security Institute have warned that there are mobile malware campaigns targeting both Android and iOS devices, with attackers utilizing malicious applications and sophisticated exploit chains to target military personnel, government officials, and other individuals.

In a recent report released by the Ukrainian State Service of Special Communications and Information Protection (SSSCIP), the findings were highlighted, highlighting the increasing use of smartphones for communication and obtaining sensitive data. An exploit kit designed for compromising iPhones was identified as one of the key tools identified in this activity, known as DarkSword. 

During watering-hole attacks, the attackers compromised legitimate websites visited by the intended targets and modified them in order to deliver the attack. A number of Ukrainian news and government websites were targeted by attackers, enabling them to exploit vulnerabilities in Apple’s Safari browser and iOS. 

As soon as an iPhone is compromised, DarkSword can be used to gather sensitive data such as login credentials, messages, contacts, and call histories without the victim having to interact significantly. In addition, earlier research has suggested that the activity may be linked to a Russian-led hacking operation targeting Ukrainians. 

Researchers previously reported that the threat actor identified as UNC6353 used DarkSword against Ukrainian users from as late as late 2025. As part of the activity, compromised sites belonging to a local news outlet covering the war and a local court were compromised, and a possible infection was identified at a Ukrainian food processing facility. 

DarkSword is described as an attack tool that is designed for a short period of time rather than a long-term solution. This technique has been shown to be capable of extracting sensitive information within minutes and then erasing traces of the compromised device within minutes. Additionally, Ukrainian authorities are tracking activities associated with groups known as UAC-0244 and UAC-0263, which use websites that appear legitimate and encourage users to download applications. This campaign extends to Android devices as well. 

To attract visitors, UAC-0244 created websites impersonating Ukraine's 3rd Army Corps and other services. One group, UAC-0263, distributed CamelSpy, an Android malware application capable of collecting information regarding device location, SIM card information, contacts, call logs, and stored images. It has been found that the BTMOB malware provides remote access to compromised devices and is capable of stealing information from them. It uses websites promoting supposed air raid alert applications, fuel discounts, and other services. 

A number of these campaigns demonstrate how attackers use familiar online services to disguise malicious activity. Ukraine's SSSCIP reported that threat actors used platforms such as GitHub to host malicious files, Telegram for transferring stolen information, Cloudflare for concealment of part of their network activity and Ngrok for encrypting stolen data. Those mobile attacks are part of a wider cyber campaign targeting Ukraine. 

CERT-UA reported 3,137 cyber incidents during the first half of 2026, representing an increase of approximately 8% from the preceding six-month period. There are still a number of security risks involved in mobile devices for Ukrainian citizens, with malicious websites, apps, and exploit tools being used to target iOS and Android devices.

French Tax Data Theft: Threat Actors Steal Password and Remain Undetected


A threat actor used stolen passwords of employees at France’s tax admin to steal tax data on businesses and hundreds of thousands of taxpayers in June.

Agencies could not detect intrusion 

Neither France's national cybersecurity nor the tax administration could notice the data leaving. According to the agency ANSSI’s report, the attack worked because of weak login security, weak monitoring, and poorly separated networks.

DGFIP, the tax administration, handles France’s tax website impots.gouv.fr. The data came from a tool called E-Contact that taxpayers use to contact the tax administration.
According to the DGFIP, the stolen data includes slightly over 250,000 firms and slightly over 350,000 individuals. Passwords and internet accounts belonging to taxpayers were not hacked.

Attack tactic

For individuals, the data that may have been accessed or copied includes their tax ID, contact details, family circumstances, reference taxable income and tax withholding rate, and a summary of the messages they exchanged with the DGFIP. The messages themselves might have been intercepted by less than 250 individuals.
For companies, it includes the firm name, SIREN registration number, address and basic details of their messaging. 

Different routes used

The threat actor used two different routes, the first started with suspicious logins in May and resulted in E-Contact. 
The first route depended on various stolen passwords of DGFIP staff. The passwords were stolen by infostealers, malware that secretly saved login details, from systems the DGFIP did not handle, most probably from staff’s own systems.

The two portals that the threat actor exploited, ADER and PIGP, required only a password, so the stolen password worked. DGFIP staff use PIGP web portal for HR services and email. ADER offers access to a few DGFIP applications through the RIE, the network that links French government ministries. 

The threat actor reached the RIE via compromised Education ministry systems linked to it. Sensitive DGFIP apps were not taken out from the rest of the RIE, allowing threat actors to access them from parts of the network with no apparent need. Officials also discovered signs of various attempts to hack into other government entities on the network.

The attacker was able to access a lot of data even though the accounts they used had no special rights. ANSSI did not look at how user rights were managed for this report.
Data from the land registry was obtained via the second path. It passed through APEX, a portal for partners like land surveyors and notaries, which requested an email with a one-time code and a password.

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Campaigns

 

Microsoft has warned of a new wave of phishing campaigns that abuse the legitimate MSP360 Remote Monitoring and Management (RMM) software to establish persistent remote access on victim devices. Once this foothold is secured, attackers deploy a second RMM tool, ConnectWise ScreenConnect, creating a redundant channel for control and further malicious activity. This dual-RMM technique enables threat actors to blend into normal IT operations while carrying out credential theft and data exfiltration with reduced risk of detection. 

The attack chain, observed by Microsoft in July 2026, begins with phishing emails disguised as meeting invites, PDF-related lures, or fake software update prompts. These messages distribute a digitally signed MSP360 RMM v2.5.0.67 installer under deceptive filenames such as “ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe” or “PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe.” When executed, the installer drops multiple DLLs, triggers a User Account Control (UAC) elevation to gain privileged context, and establishes persistence by registering Windows services and autorun Registry entries. It also modifies Windows Firewall rules to allow inbound UDP traffic to MSP360 on port 48678, ensuring uninterrupted remote access.

With MSP360 in place, attackers leverage its PowerShell execution capabilities to stealthily install ScreenConnect on the compromised endpoint. This second RMM client provides a backup remote-access path and is used to transfer additional payloads, run post-compromise tools, and perform information collection and credential-access operations. Microsoft notes that ScreenConnect’s native RunFile functionality is abused to execute these payloads, further camouflaging malicious activity within legitimate administrative workflows. The combination of two trusted RMM platforms gives attackers flexibility and resilience, allowing them to maintain control even if one channel is disrupted. 

In a parallel set of incidents during the same period, Microsoft observed attackers substituting MSP360 with Faronics Deploy Agent before installing ScreenConnect, indicating a broader pattern of RMM abuse. While no specific threat group has been attributed to these campaigns, the consistent use of multiple RMM tools suggests a coordinated effort to maximize persistence and minimize detection. By relying on signed, legitimate software, attackers reduce the likelihood of triggering endpoint security alerts, making these intrusions particularly challenging to identify without behavioral monitoring.

Organizations are advised to enforce strict application allowlisting, monitor for unusual RMM installations, and scrutinize processes that invoke UAC elevation or modify firewall rules. Security teams should also track anomalous PowerShell activity and unexpected service registrations linked to RMM agents. As remote administration tools become increasingly weaponized, a defense-in-depth strategy combining endpoint detection, network segmentation, and user awareness training is critical to mitigating dual-RMM phishing threats.

101 Malicious npm Packages Secretly Enroll Developers into WhatsApp Spam Channels

 



Researchers at OX Security have flagged 101 npm packages that silently subscribe developers to WhatsApp spam channels the moment they are installed. The campaign abuses the open-source Baileys library, an unofficial implementation of the WhatsApp API that developers use to build customer support bots, chat managers, and automation tools, to carry out the subscriptions without any visible prompt or warning.

The packages have collectively been downloaded roughly 490,000 times, with 116,000 of those downloads occurring in the last 30 days. The single most downloaded package, `ourin-baileys`, accounts for 130,589 installs on its own, nearly a quarter of the campaign's total reach. As of publication, the majority of the 101 packages remain live on npm. Sixteen had been removed, and seven of those were pulled before researchers could review the code to determine which variant of the malware they carried.

The campaign did not begin in 2026. The oldest package in OX Security's list, `alipclutch-baileys`, was first published in October 2025. Several others date to December 2025, meaning this operation has been running quietly on the registry for close to a year before receiving a formal write-up.


Three Ways to Hide the Same Payload

OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko identified three distinct variants of the malware, each handling the subscription routine differently.

The first variant, found in 19 packages, fetches channel IDs from GitHub at runtime. By hosting the target list externally, operators can swap out which accounts receive new followers without ever publishing a new package version to npm. One package, `@rixxcodex/baileys`, hides the GitHub URL inside media-download code using Base64 encoding so it is unlikely to catch the eye of anyone skimming the source.

The second variant, covering 60 packages, simply embeds the channel IDs in cleartext inside the source code. Two packages took additional steps to bury this, placing the subscription logic inside an upstream connection handler and inside a file named after the Signal cryptographic protocol, a location most developers would never think to inspect.

The third variant, found in 14 packages, encodes the hardcoded channel IDs using Base64. One package in this group, `neuralwhatsapp`, takes a slightly different approach: rather than storing a channel ID directly, it resolves its target from a hardcoded WhatsApp invite code at runtime.


The Follower Inflation Business

The goal is not data theft or ransomware deployment. The channels identified in this campaign are mostly small bot-seller and marketplace accounts, largely Indonesian, where follower counts function as social proof for selling bot scripts, premium APKs, social media boosting services, and in-game resources.

Among the specific channels researchers identified: Neural has 798 followers and markets game-currency sales through a platform called JualanRSS, which deals in in-game resources including food, ore, stone, timber, and gold. MONTE-BMG has 1,000 followers. CORTANA TECH has 1,300 and points visitors to a dedicated website. Fyxzpedia.ID-Utama, with 4,800 followers, sells WhatsApp and Telegram bot scripts and bot-building services outright. One Spanish-language channel called Redes Oficiales sits at 19,000 followers and is linked to a YouTube creator, pushing back against the assumption that this is a purely Indonesian operation.

The threat actors mute these channels on the victim's device after subscribing them, so the added follower count appears organic to outside observers. A channel with thousands of followers reads as trustworthy, and that manufactured trust is the product being sold to the operators running these marketplaces.

One channel, MONTE-BMG, illustrates how the monetisation funnel actually works. It posts what appears to be a screenshotted sales negotiation in Arabic, ending with a group invite link. That link leads to a brand-new channel with only 12 followers, whose own description contains yet another group invite. The inflated parent channel is only the entry point. The actual transaction gets moved progressively deeper into a private chain of groups where there is no public record.

Beyond follower inflation, the SafeDep research team noted earlier this year that some Baileys forks in this campaign also inject the package author's advertising URL into every image and video the bot sends, a second payload the follower-count headline tends to obscure.


One Coordinated Operation, Many Names

OX Security found that 32 channels are followed by more than one package across this campaign. The single most reused channel, identified by the ID `120363400911374213@newsletter`, is targeted by ten separate packages. One remote channel list hosted on GitHub feeds five different packages simultaneously, meaning the operator can retarget all five installations by editing a single file.

Operators routinely publish near-identical packages under slightly different names to preserve the campaign when individual listings get removed. `noxleyss` and `@noxleyss/baileys`, for example, carry the same code under different publisher accounts.

Details of the abuse first emerged in August 2026 when SafeDep identified Baileys npm forks making installers' WhatsApp accounts follow attacker-controlled channels. Earlier this month, the Xygeni Security Research Team separately detailed another Baileys modification, `@dappaoffc/baileys-mod`, which subscribed developers' authenticated WhatsApp bot sessions to attacker-controlled newsletter channels.

The campaign follows a pattern OX Security has tracked on npm before. An earlier operation used the same registry to host fake Cloudflare CAPTCHA pages designed to redirect visitors to ClickFix phishing infrastructure. The registry's scale and the institutional trust developers place in what appear to be legitimate forks of known libraries make it a dependable distribution channel for this kind of abuse.

Because the packages carry none of the classic malware signatures, no API token theft, no heavy obfuscation across the board, no destructive payload, standard threat detection tools are likely to miss them entirely. That is precisely why most of these packages have remained live for months.


What Developers Should Do

Security recommends checking whether your WhatsApp account has been added to unknown channels and blocking or reporting any that appear. Developers should avoid any npm package that requires connecting a personal WhatsApp account and should add detection rules to their pipelines flagging known malicious Baileys forks. Remote channel-list URLs identified in these packages can be added to URL-reputation and threat-intelligence pipelines for ongoing monitoring.


84% of Indian SMEs Plan Higher Cybersecurity Spending as Readiness Gaps Remain

 

A large proportion of Indian small and medium enterprises (SMEs) plan to boost cybersecurity spending in the next 12-24 months yet experience gaps in terms of preparedness, monitoring and expertise, according to a TTBS and CMR study. The SME Digital Insights 2026 Cybersecurity study found that 84% of Indian SMEs plan to increase cybersecurity spend, highlighting that businesses are taking security seriously as they continue to embrace the digital transformation journey. 

However, the study identified a gap between expenditure planning and actual cybersecurity maturity. Around 40% of SMEs experienced a cyber incident in the last two years yet only 28% took structural actions to improve their cybersecurity capabilities after an incident. Continuous monitoring remains a major challenge, as only 12% of SMEs continuously monitored their cybersecurity environments, suggesting that businesses may continue to be reactive rather than proactively detecting and responding to threats. 

The study found that 35% of SMEs operate multiple cybersecurity tools in a fragmented manner, with limited visibility over the overall risk, creating difficulty for businesses in gaining a holistic understanding of their cybersecurity landscape. Cybersecurity spending continues to remain low for many businesses, with 46% allocating less than 5% of their overall IT budget to cybersecurity, leaving ample room for increased budget allocation as businesses continue to digitalize operations. Artificial intelligence (AI) is another emerging influence on SMEs’ cybersecurity strategies, as 35% of the businesses identified it as a key enabler to enhance detection, monitoring as well as incident response capabilities. 

Concurrently, 34% of SMEs foresee AI-enabled cyber threats to have a significant impact on their businesses in the next 12-24 months, pointing to the dual impact of AI technologies – as both a tool to secure and a threat enabler. Vishal Rally, Chief Revenue Officer at Tata Teleservices, said the planned increase in cybersecurity investment reflects that SMEs acknowledge the need to integrate security within the overall digital transformation strategy. 

Prabhu Ram, Vice President of the Industry Research Group at CMR, said that the findings reflect the uneven maturity in cybersecurity among Indian SMEs despite the anticipated rise in investment intent. For SMEs, the findings highlight that simply increasing cybersecurity budgets may not be enough to address the existing gaps in security. As businesses expand and become more digitalized, enhanced monitoring, visibility, expertise and integrated practices will also be required to mitigate the rising threats.

MCP Python SDK Flaw Exposes OAuth Credentials

 

A high-severity security vulnerability in the official Model Context Protocol (MCP) Python SDK could allow malicious MCP servers to steal OAuth credentials from artificial intelligence applications. Tracked as GHSA-qx49-fqc8-xw99, the flaw has a CVSS score of 7.5 and affects HTTP-based MCP clients that use OAuth authentication while connecting to servers that are not fully trusted. The issue does not affect local studio clients, MCP servers, or applications that provide their own authentication tokens and headers. 

The vulnerability is linked to the SDK’s OAuth discovery process. During authentication, an MCP client asks a server to identify the authorization server responsible for issuing tokens. A malicious server could return a 404 response for the standard OAuth discovery endpoint, forcing the SDK to use a fallback method. On this unsafe path, the SDK failed to properly validate the authorization server’s issuer, allowing the attacker to redirect the authentication flow to an infrastructure controlled by them. 

As a result, attackers could capture an OAuth client secret, authorization code and PKCE proof key. These credentials may enable the attacker to obtain valid access tokens from the legitimate identity provider, potentially gaining the same permissions as the affected application. Depending on the configured OAuth scopes, the impact could include access to cloud services, internal APIs, databases, deployment systems and other connected resources. Long-lived client secrets and refresh tokens could also support continued access or account takeover. 

The affected releases include MCP Python SDK versions 1.9.1 through 1.29.1 and versions 2.0.0 through 2.1.1. The maintainers fixed the issue in version 1.30.0 for the 1.x branch and version 2.2.0 for the 2.x branch. However, upgrading alone may not be sufficient for deployments using ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider; developers must explicitly configure the expected issuer= value. Users of the deprecated 1.x RFC7523OAuthClientProvider should migrate to another supported provider. 

Organizations should immediately identify affected clients, upgrade the SDK and remove stored OAuth client registrations created by older releases. If a vulnerable client connected to an untrusted MCP server, administrators should rotate client secrets, revoke potentially exposed tokens and review authentication logs for suspicious activity. Teams unable to upgrade should restrict connections to MCP servers they completely control and trust. The advisory highlights the security risks created when AI agents connect external tools to privileged enterprise systems, making strict server verification and issuer validation essential safeguards.

Cybercriminals Misuse ChatGPT Custom GPTs in ClickFix RAT Attacks


ChatGPT Custom GPTs are being abused by threat actors as an entry point for malware campaigns, redirecting users to malicious websites using fake artificial intelligence assistants. A campaign identified by Huntress in which attacker-controlled Custom GPTs were impersonating legitimate ChatGPT offers and directing victims to ClickFix scams has been identified. 

A total of 40 incidents associated with the same Google Sites infrastructure were linked to the campaign, and two of these cases have been confirmed to originate from malicious Custom GPTs. OpenAI reported a GPT that had been identified and removed on September 25, however two days later researchers identified another GPT that had been connected to the same campaign. 

The attack is initiated by a Custom GPT that appears to be a genuine ChatGPT service. It has been reported that some victims have reached the malicious GPT by searching for ChatGPT on Google and clicking a sponsored result. While the page itself remained hosted on the legitimate ChatGPT domain, the GPT was titled Plus 5.6, giving the appearance that it was an official model. 

A false message claiming that the primary domain was restricted to a limited number of users was displayed when the GPT was opened. After that, the website directed users to a fake backup website hosted on Google Sites, where a false Cloudflare CAPTCHA was displayed and a technique known as ClickFix was utilized to entice the victim into manually executing a command. 

PowerShell is launched by the command to retrieve an obfuscated script, which is temporarily saved before executing. After a silent download of a malicious MSI package named ISOSimple.msi, the script silently installs it. During the subsequent attack chain, the installer appears to be a legitimate Canon-signed application that is used to install an “Advanced Printer Configuration Reader”. 

Even when security software detected part of the payload, the infection was designed to remain active. One incident involved Microsoft Defender quarantining ISOSimple.msi as Trojan:Script/Wacatac.H!ml, because it had already set up a Run key and a scheduled task called “Canon Configuration Reader.” These keys and tasks allowed the malware to continue running on the computer. 

DLL sideloading is the next stage. With the MSI, the legitimate Canon COTFileReadApp.exe is installed, which has a valid digital signature, making the malicious package appear less suspicious. Attackers inserted a modified logging library alongside the executable, causing the legitimate Canon application to load malicious code through Windows' DLL search process as a result. 

The sideloaded code then extracts the next payload from a .wav file included in the installer Even though the file contains authentic audio data at the beginning and a valid WAV header, there are later sections that contain encrypted data that is decoded in memory. 

To avoid simple file-based detection, the loader retrieves an encrypted archive containing the malware and its persistence components and eventually eliminates straightforward file-based detection. There are 315 folders and 806 files contained within the archive, known as monitor.raw, which has a custom encrypted file structure. It contains a persistence script that continuously checks the registry for the malware's run entry and scheduled task, and recreates them if they are removed. 

In both instances, the infection can be re-executed by launching the Canon executable under the name "Canon Configuration Reader" by launching the Canon executable. An advanced Remote Access Trojan is attached to the final payload, which can provide access to the computer's desktop and screen, capture input from the camera, microphone, and audio system, and search for files on the computer. 

Additionally, the program collects information regarding security software installed, Windows configuration, network adapters, open ports, software installed and hardware installed. Command-and-control communication is carried out through DNS-over-HTTPS via services such as Cloudflare, Google, and Quad9, allowing its network traffic to blend in with legitimate encrypted web traffic.

In addition to downloading and executing additional EXE, DLL, MSI, PowerShell, and script-based payloads, attackers can extend activity beyond the initial compromise by downloading additional payloads. After removing the first Custom GPT from the campaign, Hunters discovered a second version. In addition to keeping the underlying RAT unchanged, the attackers replaced the Canon-based execution chain with a modified DLL and signed Stardock executables. 

In addition, the loader was moved from the WAV file into a Microsoft NuGet package, demonstrating that the delivery components can be changed without replacing the core malware. A second variant included additional measures to make detection more difficult, including freshly obfuscated download scripts and the removal of Windows Mark-of-the-Web tags before the MSI was executed. 

Nonetheless, the main behavior remained the same: MSI installation resulted from PowerShell activity, malicious code was loaded from a legitimate signed application, and persistent registry and scheduled task access was maintained. 

Therefore, security researchers advise that detection should be focused on behavior connecting these stages rather than relying solely on specific filenames or trusted software brands. It is possible to detect this type of attack by suspicious PowerShell activity followed by Msiexec, signed applications running from unusual locations, unexpected DLL loading, and newly created Run keys and scheduled tasks.

Hackers Breach Polish Medical Software Firm Qbusoft, Expose Patient Data in Second Healthcare Attack in Weeks


 


A cyberattack on Polish healthcare software company Qbusoft has left patient records from its Medyc platform potentially in the hands of attackers, coming just weeks after a separate, larger breach hit another Polish medical software provider and rattled the country's entire health data infrastructure.

The attacker exploited an SQL injection vulnerability in Medyc's application interface during late August, according to a breach notification published last week by the Addiction and Psychiatric Treatment Center in Inowrocław, one of the healthcare facilities running the platform. SQL injection is one of the oldest and best-documented attack techniques in security research, allowing an attacker to manipulate a web application into pulling data directly from its database. Despite decades of awareness about the flaw, it remains a recurring entry point in healthcare system compromises.

Qbusoft confirmed on Friday that the attackers obtained names, national identification numbers, home addresses, phone numbers and email addresses. In Poland, the national identification number, called a PESEL, functions similarly to a Social Security number in the United States and is a standard credential for identity verification across government services, banking and healthcare. Its theft puts affected patients at real risk of identity fraud.

The company said it had not confirmed the theft of clinical records. But the Inowrocław center told patients that Qbusoft found evidence the attacker ran scripts specifically targeting database tables containing medical information, making it "highly likely" that medical records were also pulled. The data in scope for that facility included hospital treatment records and discharge summaries from patients treated at its Day Treatment Unit for Addiction Treatment between July 2024 and August 2026.

The intrusion occurred on August 22-23 and went undetected until the night of September 8-9, a gap of more than two weeks. By that point, the attacker had already transferred an encrypted archive of the database outside Qbusoft's systems. Some fields, including names and PESEL numbers, had been encrypted in the database. Qbusoft nonetheless advised the affected center to assume the attackers could decrypt that information without difficulty, given the specifics of how the protection was implemented.

Qbusoft patched the vulnerability on the day the breach was detected, restricted database access permissions, rotated passwords and technical credentials, and introduced additional monitoring. The company has not publicly commented on the incident through any official statement.

That silence drew a sharp response from Digital Affairs Minister Krzysztof Gawkowski, who said the Central Bureau for Combating Cybercrime had opened an investigation and criticized Qbusoft for failing to notify CERT Polska or the national incident response team for the healthcare sector before authorities reached out. "Hiding attacks by companies is the biggest mistake, as it always puts citizens at risk," Gawkowski said. Poland's data protection authority separately announced that its president had ordered a formal audit of Qbusoft.

Medyc, which has operated as a cloud-based platform since 2014, is used across Polish medical practices and clinics for electronic medical records, patient scheduling, electronic prescriptions, referrals, sick notes, telemedicine and administrative billing. In a public notice, the company warned that its infrastructure had faced repeated attack attempts since the incident and that users might see temporary slowdowns or restricted access to certain modules.


The Same Attacker?

Polish cybersecurity publication Zaufana Trzecia Strona reported that a person or group using the alias "fingerprint" contacted the outlet claiming responsibility for the Medyc attack. The publication had previously linked that alias to the MyDr breach, a separate incident involving another Polish healthcare software vendor. Polish broadcaster RMF FM also reported that the same attackers behind MyDr were likely responsible for the Medyc intrusion, though Polish authorities have not formally attributed the attack to any individual or group.

The alleged attacker claimed to have obtained records on 5 million patients and 8 million private photographs, some of which Zaufana Trzecia Strona said may depict patients in sensitive medical settings. Neither figure has been independently confirmed, and the stolen data has not been made public. The actor reportedly framed the operations as an effort to expose weak security rather than profit from the data.

The MyDr breach, confirmed in August, potentially affected close to 19 million people across more than 12,000 healthcare facilities, involving over 2 terabytes of stolen data including names, PESEL numbers, prescription histories, diagnoses and appointment records. Poland has roughly 36.5 million residents, meaning the MyDr incident alone touched the records of nearly half the country's population. The Inowrocław treatment center caught up in the Medyc breach was also among the organizations affected by MyDr.

Gawkowski said Polish authorities had observed a surge in criminal activity targeting healthcare organizations in recent weeks and were preparing new regulations in response, including mandatory security certification for healthcare technology companies and tighter controls on how private vendors handle medical data. Poland recorded a 144 percent year-on-year rise in reported cybersecurity incidents in 2025. The consecutive breaches of Medyc and MyDr, both software vendors connecting thousands of clinics to national health infrastructure, have made clear that the weakest link in Poland's health data chain is not the government platform but the private companies sitting in front of it.




DC Health Agency Data Exposure Affects Nearly 400,000 Medicaid Beneficiaries

 

Almost 400,000 people who enrolled in Medicaid and the DC Healthcare Alliance may have been affected by a data breach, which occurred on the website of the District of Columbia Department of Health Care Finance. 

The issue concerned the reports published on the organization’s website, which showed aggregated data about the people who enrolled in the programs between 2023 and 2026. DHCF noted that the breach did not involve cybersecurity issues or intentional unauthorized access to the system. The problem was discovered by the agency in July, when it was revealed that two reports on the website contained fields with personally identifiable information that could have been accessed by unauthorized parties. 

The reports included only aggregated data, such as the number of people enrolled in the programs at specific times and other related information. Nevertheless, according to DHCF, the supporting information on its website could have been accessed by unauthorized parties since 2023. The personally identifiable information of the people who enrolled in Medicaid and the DC Healthcare Alliance includes their ID, providers, date of birth, race, gender, ethnicity, and wards. 

According to the agency, the reports do not contain Social Security numbers, names, and financial information of the affected people. DHCF announced that 399,086 people were affected by the issue and notified the United States Department of Health and Human Services (HHS). The latter added DHCF to its website, which keeps track of data breaches. It is unclear whether the affected people’s information was misused or will be misused in the future. Nevertheless, DHCF advised them to remain wary of potential fraudulent activities and unauthorized attempts to gain access to their information. 

According to the agency, the fact that the reports did not include Social Security numbers and financial accounts minimizes the risk of exploitation, but it remains present due to the inclusion of people’s IDs. After the breach was discovered, DHCF removed the reports from its website. In addition, it initiated an internal review process and responded to the problem by checking its systems for vulnerabilities and ensuring that its internal procedures were appropriate for addressing the issue. 

It is important to note that the breach illustrates how people’s information can be exposed even when it should not be. In this case, the data was not hacked or intentionally shared with unauthorized parties. Nevertheless, it became available to anyone who wanted to see it because the reports containing it were publicly available. 

Therefore, it is essential for people who enrolled in Medicaid and the DC Healthcare Alliance to ensure that they are not contacted by scammers and that their information is not misused. It is necessary for them to contact DHCF if they suspect that something is wrong. At the same time, it is important to keep in mind that, according to the agency, there is no information about the affected people’s information being viewed or misused.

NVIDIA Unveils Layered Security Architecture for AI Agents

 

NVIDIA has introduced the Open Agent Safety Platform as a security architecture for controlling autonomous AI agents from testing through deployment. Announced on September 28, 2026, the architecture combines open-source runtime controls with hardware-based monitoring, placing security boundaries outside the AI model itself. This design recognizes that prompt-level safeguards alone may not prevent an agent from accessing unauthorized files, tools, networks or services. Instead, NVIDIA’s approach connects agent permissions to the wider software, compute and hardware stack. 

The software foundation is NVIDIA OpenShell, a secure runtime that places each AI agent inside an isolated execution environment. It can define and enforce rules governing filesystem access, processes, credentials, network connections, APIs and external tools. Operators can convert instructions into verifiable policies before an agent begins work, while OpenShell traces actions and records policy decisions in an audit trail. Because these restrictions operate outside the model and agent framework, they can apply to both open and closed AI models. 

OpenShell is designed to act as the first enforcement layer in the architecture. For example, an enterprise agent authorized to retrieve an invoice from one folder could be blocked from opening unrelated files, modifying records or connecting to unapproved services. NVIDIA says the software runs with minimal overhead on its Vera CPUs, while its open-source design can be extended to third-party computing platforms, including Arm and Intel systems. This makes the runtime layer more portable than a security system tied entirely to one model or application.

The second major layer is NVIDIA Sentry, an out-of-band watchdog included in the reference system design. Running on NVIDIA BlueField-4 data processing units, Sentry monitors agent behaviour independently of the agent’s operating environment. Through NVIDIA’s DOCA software, it can inspect requests and responses, verify identities and enforce access policies covering data, tools, APIs and services. If an agent attempts to cross its permitted boundary, Sentry is designed to quarantine and stop it in milliseconds, creating a hardware-backed response when software controls are bypassed. 

Together, OpenShell and Sentry form a layered AI-agent security architecture rather than a standalone product review. OpenShell governs what an agent is allowed to do, while Sentry provides independent monitoring and containment below the software layer. The broader model gives developers a way to combine policy verification, runtime isolation, continuous telemetry and hardware enforcement across agent deployments. NVIDIA has made OpenShell and related skills available through its developer resources and GitHub, allowing organisations to examine and adapt the architecture as autonomous systems move into production.

NeedyMantis Malware Expands the Post-Compromise Threat Landscape


A modular malware family dubbed NeedyMantis has been identified by Microsoft Threat Intelligence, and has been employed to maintain access to compromised systems in a limited number of targeted intrusions. 


Evidence of the malware dating back to at least October 2025 indicates that it has affected telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. During an investigation into indicators associated with the DAEMON Tools supply chain compromise, Microsoft identified NeedyMantis. 

The company tracks activity associated with Storm-3069, and has observed the malware in use beyond that campaign. While Microsoft believes the observed operations are associated with activities associated with China-based threat actors, it has not attributed Storm-3069 to a Chinese nation state actor or confirmed that all NeedyMantis activity originated from a single operator. 

As a general rule, NeedyMantis is deployed after attackers have already gained access to the target environment. The malware serves primarily as an initial access tool, but it is also intended to maintain access and facilitate further activity within the compromised network, utilizing DLL sideloading as part of its delivery chain. It has been observed that attackers packaged malicious DLLs with legitimate applications and encrypted archives in an attempt to facilitate their delivery. 

Poedit, curl, Vim, and TightVNC were among the programs abused in this manner, while malicious DLLs were disguised as Microsoft Office, Broadcom, Intel, and NVIDIA components. One incident involved the use of Impacket toolkit to copy a legitimate software package from a network share into the malicious file, which was then executed on the targeted computer. It is important to note that NeedyMantis played a crucial role in the post-compromise phase of an intrusion, despite the attacker already having established access to the environment. 

Once the initial DLL is loaded, the malware continues to feature layered security. A second-stage component is extracted from the encrypted archive by the first-stage loader, which is the file used in the analysis, encryptbase64.ps1. Even though the file has a PowerShell extension, it contains x64 shellcode rather than a conventional PowerShell script. 

Once the embedded malware has been decoded and decompressed, a custom executable format based on a reduced version of the Windows PE format is loaded. An additional level of protection can be provided by the custom archive. Its contents can vary between samples, with file names and internal values varying. 

The analyzed WinSparkle archive contained legitimate components of 7-Zip and Sysinternals as well as files with familiar Windows library names, including dnsapi.dll and ws2_32.dll, mixed with legitimate components. Instead of the legitimate libraries represented by these files, NeedyMantis configuration and communication components were found in these files. The main component communicates with the malware's command-and-control infrastructure and manages additional modules. 

It is Microsoft's responsibility to observe an initial HTTPS request before switching the connection to a binary WebSocket protocol. The communications component utilizes WebSockets. A hard-coded user agent for Firefox 21.0 has also been used by the malware in one implementation. Through the C2 channel, operators can add and remove modules and exchange data with them, though Microsoft has not confirmed the specific functionality of the modules. 

A NeedyMantis sample collected in October of 2025 contained a persistence module based on Windows services, however the persistence method employed by the newer analyzed sample has not been identified. The malware is more challenging to analyze through a single file or indicator due to its staged loading, misleading file names, encrypted archives, and modular C2 communication. 

Detection points have been provided by Microsoft for hashes, file paths, the C2 hostname corp.tripswithengine[.]com, and the Firefox/21.0 user agent. As a result of the NeedyMantis campaign, security teams need to monitor suspicious loaders, C2 traffic, and unusual usage of legitimate software in order to recognize the risks posed by modular post-compromise malware.

Citrix NetScaler Zero-Days Exploited in Attacks

 

Two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are reportedly being exploited in the wild, raising serious concerns for organisations that rely on the products for remote access and application delivery. Security firm watchTowr disclosed the activity on September 26, stating that attackers had used the flaws to achieve remote code execution before Citrix released patches or detailed technical guidance. The company warned that the vulnerabilities could allow attackers to compromise exposed appliances and potentially gain access to connected networks. 

According to watchTowr, the flaws were discovered during forensic investigations into suspected intrusions. Both vulnerabilities reportedly enable remote code execution, meaning an unauthenticated attacker could potentially execute malicious commands on a vulnerable NetScaler device. Because these appliances frequently sit at the edge of corporate networks and handle VPN or application access, a successful compromise could provide attackers with an important entry point for credential theft, lateral movement, data exfiltration or ransomware deployment. 

At the time of the initial disclosure, Citrix had not confirmed the vulnerabilities, published affected-version information or released a security update. The absence of official indicators of compromise or a reliable workaround left administrators with limited options. Some organisations reportedly chose to take NetScaler appliances offline to reduce the risk, although doing so can disrupt remote workers, business applications and customer-facing services. Researchers expected Citrix to issue communications and patches during the week beginning September 28. 

The situation later developed when Citrix confirmed that two critical NetScaler flaws had been exploited and released fixes alongside patches for six additional vulnerabilities. The issues were identified as CVE-2026-88771 and CVE-2026-88772, both carrying a CVSS score of 9.5. The first is an improper input-validation vulnerability that could allow an unauthenticated attacker to run arbitrary commands, while the second involves improper memory-buffer restrictions and could lead to remote code execution or denial-of-service attacks. 

Security teams should treat these vulnerabilities as an emergency priority. Administrators should identify all internet-facing NetScaler ADC and Gateway systems, apply Citrix’s latest fixes immediately and review logs for unusual authentication, configuration or administrative activity. Organisations should also rotate potentially exposed credentials, inspect connected systems for signs of post-compromise activity and restrict management access wherever possible. CISA’s addition of both flaws to its Known Exploited Vulnerabilities catalogue further underlines the urgency of patching and incident investigation.

Singapore Expands AI Cybersecurity After UNC3886 Attacks

 

Singapore is changing its cybersecurity strategy after a state-sponsored cyber espionage group targeted the country’s four major telecommunications companies. The attack by UNC3886, disclosed in July 2025, could have disrupted telecommunications and internet services had the attackers penetrated further and raised concerns about national security. 

The incident has pushed Singapore toward a more proactive approach that assumes sophisticated attackers may eventually enter protected networks. Instead of focusing only on preventing intrusions, authorities are emphasizing threat hunting and the detection of suspicious activity after attackers gain access. In an interview, Cyber Security Agency of Singapore (CSA) chief executive and Commissioner of Cybersecurity Gwenda Fong said advanced persistent threat actors such as UNC3886 pursue specific targets, meaning perimeter protection alone is not enough. 

Once inside a network, attackers still need to move toward sensitive systems and data, giving defenders opportunities to identify unusual internal activity. Singapore is using artificial intelligence to strengthen this detection and prevention work. The Government Technology Agency of Singapore (GovTech) has developed two AI-powered tools for government systems. One performs automated penetration testing across about 2,000 government systems, including systems containing citizen data and transactions. 

The second scans the source code of government applications and systems for security weaknesses so agencies can address vulnerabilities before attackers exploit them. The authorities have not disclosed which agencies are using the tools, but their use is being evaluated for expansion across Singapore’s 11 critical information infrastructure sectors, which include healthcare, aviation, banking and finance, energy, government and information and communications. 

CSA has also started regularly scanning internet-facing systems operated by critical infrastructure organizations to identify potential entry points such as unpatched software and weak configurations. The agency said these scans are external and do not involve active probing. Other measures include proprietary threat-detection tools developed by a technical agency under Singapore’s Ministry of Defence and the sharing of classified threat intelligence with critical infrastructure operators. CSA is also examining supply-chain security because compromised vendors could potentially expose data or disrupt services. 

The agency is considering requiring some vendors and suppliers working with critical infrastructure operators to obtain Cyber Essentials or Cyber Trust mark certifications, potentially as early as 2027. As of August, 874 Cyber Essentials and 346 Cyber Trust mark certifications had been issued. 

The shift reflects the growing importance of cybersecurity to national security, the digital economy and public trust. CSA reported that suspected advanced persistent threat activity in Singapore quadrupled between 2021 and 2024, while authorities expect threats to increase as attackers gain access to AI tools. 

For organizations connected to critical digital infrastructure, the message is clear: security cannot end at the network perimeter. Identifying weaknesses, monitoring internal activity and detecting attackers before they can reach sensitive systems are becoming essential parts of defending increasingly connected services.

File Notification APIs in Windows, Linux, and Android Are Leaking What You Do on Your Computer

 



A research team from Graz University of Technology in Austria has shown that a routine feature built into virtually every major operating system can be turned into a surveillance channel that tracks keystrokes, visited websites, and private messaging activity without needing administrator access.

The feature is the file-change notification system. Every major platform ships one: Linux has inotify and fanotify, Windows uses ReadDirectoryChangesW, and Android and macOS have their own equivalents. Text editors, antivirus software, cloud sync clients, and file managers depend on these APIs to react when files are created, modified, or deleted. The catch is that subscribing to those notifications requires no special privileges, only read access to the directory being watched.

What these APIs never hand over is actual file content. What they do leak, the researchers found, is file names and the exact timing of events. That combination is enough to reconstruct meaningful details about what other users on the same machine are doing throughout the day.


Linux: Keystrokes Through the Filesystem

On Linux, if a process is blocked from watching a specific file directly, it can still receive that file's events by watching the parent directory, as long as that directory is readable. The researchers applied this to device files under /dev that represent keyboard hardware. The result is that an unprivileged process can detect every keystroke another user makes, though not which key was pressed.

That gap offers less protection than it appears to. Research going back more than two decades has established that the rhythm of inter-keystroke timing can help reconstruct what was typed. In tests with seven participants, the attack scored between 93.1% and 100% on standard accuracy measures. Input that never echoes to the screen, such as a password entered during a sudo prompt, does not generate filesystem events and stays invisible to the attack.

The team also demonstrated website fingerprinting by watching which system fonts Firefox loads for a given page. Against the top 100 sites, that technique reached 87.9% accuracy. A third Linux attack targeted KDE Plasma 6 on Wayland: a malicious process running as the victim can detect when a real authentication dialog is about to appear and draw a counterfeit one over it to capture credentials before the legitimate prompt ever loads.


Android: No Permissions Required

On Android, an application requesting zero permissions can watch the private storage directory of a completely separate app. Testing against WhatsApp on a Google Pixel and a Samsung Galaxy device, the researchers extracted file names and event timing that revealed when photos, videos, and documents were sent or received. The attack also exposed when that media was later deleted, offering a window into communication patterns that the app's own privacy controls do not address.


Windows: One Watch, Every User's Files

The most consequential Windows scenario arises when a process watches the root of the system drive. Windows reports the full path of every file that changes anywhere on the machine, including paths inside other users' home directories that the monitoring account has no direct permission to access.

Because Firefox names profile subdirectories after associated websites, an unprivileged user watching the drive root can track which sites another logged-in account is browsing in near-real time. Across the top 1,000 websites, the researchers hit 97.8% accuracy against Firefox and 48.5% against Edge, which creates far fewer site-named folders.

This behavior comes from the same ReadDirectoryChangesW API that was flagged under CVE-2007-0843 for a similar class of issue almost two decades ago. Microsoft's position has not shifted. The company told the researchers the behavior is working as designed, on the grounds that file contents remain inaccessible. A Microsoft spokesperson told SecurityWeek that "the technique requires an attacker to already have the ability to run code locally on a device under a separate user account and does not provide access to file contents." Microsoft did note that administrators can enable optional protections it documented in April 2025 covering some path-disclosure scenarios tied to directory change notifications.

macOS came out the least exposed of the four platforms. Its equivalent API can only monitor globally readable files, which limits the attack surface, though the researchers still demonstrated tracking of application launches, app interactions, and settings changes.

The Linux kernel received a targeted patch under CVE-2025-68788, which stops the fsnotify subsystem from generating access and modify events for special files, including the device files representing keyboard input. The researchers describe this as addressing the most serious Linux issue, but other attack paths from their research remain open.

Apple and Google have not responded to requests for comment, and no fixes have been announced for Android or macOS. The researchers say they have found no evidence of active exploitation in the wild. Proof-of-concept code for the full set of attacks has been published on GitHub at isec-tugraz/file-notification-attacks.



Supabase Misconfigurations Leave Customer Data Publicly Exposed


A cybersecurity firm UpGuard has found that thousands of databases hosted on Supabase can expose private information to the public internet. According to the research, approximately 16,000 databases hosted on the platform were able to be accessed by individuals through some form of personal data. The findings indicate that misconfigured databases and applications are a recurring security issue. 


Data storage and operations are widely facilitated by Suprabase for web and mobile applications, while the increasing use of artificial intelligence-assisted vibration coding has allowed developers with limited security expertise to create and deploy applications more easily. Among the exposed databases, UpGuard found names, addresses, telephone numbers, and passwords that were publicly accessible. A smaller number also contained authentication tokens. 

Various services and projects were connected to the exposed information, demonstrating that the problem is not limited to one type of application or industry. Datasets examined by researchers include private conversations provided by an Indian adult streaming platform, thousands of license plates owned by a valet service in the United States, as well as contacts for immigration and relocation services in the United States. 

Another exposed database reportedly served as a gateway to intercepting text messages via a virtual SIM farm. As UpGuard discovered, the database was linked to a consulate of the African government in France. By using these systems, online account holders can receive one-time verification codes, but when their data is left accessible via the internet, additional risks may be incurred. 

It is evident that the problem extends beyond isolated incidents; earlier investigations had also identified the public exposure of Supabase databases belonging to startups and widely used applications. UpGuard identified a large number of data sets that were located in the United States; however, the researchers indicated that the exposed databases were part of a global problem. 

An analysis performed by UpGuard identified 16,326 databases with Supabase tables that were publicly accessible. Approximately half of the databases contained personally identifiable information, and a smaller number contained passwords, authentication tokens, and payment card information in rare cases. The researchers also tested a sample of the databases to confirm that some of the exposed records contained information that was accurate. There has been prior documentation of this problem. 

In 2025, research discovered misconfigured Supabase databases connected to AI-assisted development platforms, and further investigation identified access controls and public key handling issues. The latest findings suggest that similar configuration errors remain widespread as more applications are constructed using AI coding tools for building and deploying.

Although Suprabase has implemented additional security safeguards, researchers noted that they are not necessarily applied automatically when databases are built using programming platforms. Nevertheless, proper configuration remains the only way to prevent unauthorized access to stored data. In addition, the findings highlight the differences between securing the backend of an application and building it. 

In contrast to AI-assisted development producing a working application rapidly, security settings around database access remain dependent upon decisions made during deployment. Consequently, access controls that are incorrectly configured can expose a database accessible through a given application when they are incorrectly configured. 

Supabase, on the other hand, stated that its projects are automatically secure and that database security is a shared responsibility between all parties. Managing Director of Information Security Bil Harmer stated that customers control how their projects are configured, while Supabase provides security defaults and tools and informs customers as soon as security threats are identified. The company has also implemented security-related changes to its platform over the years. 

The scope identified in the latest research, however, indicates that customer-side database configuration remains a critical part of the security equation, given that Supabase continues to be used for applications developed using artificial intelligence-assisted development tools. This study demonstrates that poorly configured cloud databases pose security risks, particularly as AI-assisted development continues to accelerate application deployments. 

Maintaining strict access controls and configuring databases carefully remain essential to prevent the public from having access to sensitive information.

Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks

 

Secure file-sharing provider Kiteworks issued an urgent advisory urging customers to power down their servers for a six-hour window following credible threat intelligence of a potential imminent cyberattack. The recommendation, communicated directly to enterprise and government clients, was described as a precautionary measure rather than a response to any confirmed compromise of systems. According to reports, the company received specific warnings from federal law enforcement agencies indicating that a threat actor may attempt to target Kiteworks installations over the weekend. 

The shutdown window was carefully scheduled to accommodate customers across multiple time zones, spanning from Australian Eastern Standard Time to Pacific Daylight Time. In Central Europe, organizations were instructed to take their Kiteworks systems offline between 4:00 a.m. and 10:00 a.m. on Saturday, September 26, while customers in New York faced a window from 10:00 p.m. Friday to 4:00 a.m. Saturday. Company representatives reportedly advised clients to shut down servers before the scheduled window began and emphasized that systems should be taken offline even if they were not directly accessible from the Internet, reflecting the seriousness of the potential threat. 

Kiteworks explicitly stated that it was not aware of any actual compromise of its systems and characterized the advisory as preventative in nature. The company confirmed that all known vulnerabilities affecting its platform had already been addressed in the current software release, version 9.5.1, and continued to recommend that customers run the latest version available. Despite this assurance, customer support representatives reportedly indicated to technology journalists that the shutdown recommendation was specifically intended to protect against potential zero-day attacks, though neither the official company statement nor the customer notification explicitly confirmed the discovery or exploitation of such a vulnerability. 

The potential targeting of Kiteworks platforms carries significant implications given the nature of the software and its typical user base. The company develops secure file-transfer and communications products that are widely used by government organizations, financial institutions, and large enterprises to handle sensitive documents and data. Secure file-sharing platforms represent high-value targets for cybercriminals who specialize in data-theft extortion attacks, as they commonly store confidential information that organizations would be desperate to protect from public exposure or unauthorized access. 

While the specific threat actor behind the potential attacks remains unidentified, the cybersecurity community has noted historical patterns that raise particular concerns. The Clop extortion gang has established a long history of targeting enterprise file-transfer platforms in sophisticated data-theft campaigns, including previous attacks against Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer systems. The U.S. Department of State currently offers a ten million dollar reward for information that could link this cybercrime gang's operations to foreign government sponsorship, underscoring the geopolitical dimensions that often accompany major enterprise security incidents of this nature.