Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

101 Malicious npm Packages Secretly Enroll Developers into WhatsApp Spam Channels

 



Researchers at OX Security have flagged 101 npm packages that silently subscribe developers to WhatsApp spam channels the moment they are installed. The campaign abuses the open-source Baileys library, an unofficial implementation of the WhatsApp API that developers use to build customer support bots, chat managers, and automation tools, to carry out the subscriptions without any visible prompt or warning.

The packages have collectively been downloaded roughly 490,000 times, with 116,000 of those downloads occurring in the last 30 days. The single most downloaded package, `ourin-baileys`, accounts for 130,589 installs on its own, nearly a quarter of the campaign's total reach. As of publication, the majority of the 101 packages remain live on npm. Sixteen had been removed, and seven of those were pulled before researchers could review the code to determine which variant of the malware they carried.

The campaign did not begin in 2026. The oldest package in OX Security's list, `alipclutch-baileys`, was first published in October 2025. Several others date to December 2025, meaning this operation has been running quietly on the registry for close to a year before receiving a formal write-up.


Three Ways to Hide the Same Payload

OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko identified three distinct variants of the malware, each handling the subscription routine differently.

The first variant, found in 19 packages, fetches channel IDs from GitHub at runtime. By hosting the target list externally, operators can swap out which accounts receive new followers without ever publishing a new package version to npm. One package, `@rixxcodex/baileys`, hides the GitHub URL inside media-download code using Base64 encoding so it is unlikely to catch the eye of anyone skimming the source.

The second variant, covering 60 packages, simply embeds the channel IDs in cleartext inside the source code. Two packages took additional steps to bury this, placing the subscription logic inside an upstream connection handler and inside a file named after the Signal cryptographic protocol, a location most developers would never think to inspect.

The third variant, found in 14 packages, encodes the hardcoded channel IDs using Base64. One package in this group, `neuralwhatsapp`, takes a slightly different approach: rather than storing a channel ID directly, it resolves its target from a hardcoded WhatsApp invite code at runtime.


The Follower Inflation Business

The goal is not data theft or ransomware deployment. The channels identified in this campaign are mostly small bot-seller and marketplace accounts, largely Indonesian, where follower counts function as social proof for selling bot scripts, premium APKs, social media boosting services, and in-game resources.

Among the specific channels researchers identified: Neural has 798 followers and markets game-currency sales through a platform called JualanRSS, which deals in in-game resources including food, ore, stone, timber, and gold. MONTE-BMG has 1,000 followers. CORTANA TECH has 1,300 and points visitors to a dedicated website. Fyxzpedia.ID-Utama, with 4,800 followers, sells WhatsApp and Telegram bot scripts and bot-building services outright. One Spanish-language channel called Redes Oficiales sits at 19,000 followers and is linked to a YouTube creator, pushing back against the assumption that this is a purely Indonesian operation.

The threat actors mute these channels on the victim's device after subscribing them, so the added follower count appears organic to outside observers. A channel with thousands of followers reads as trustworthy, and that manufactured trust is the product being sold to the operators running these marketplaces.

One channel, MONTE-BMG, illustrates how the monetisation funnel actually works. It posts what appears to be a screenshotted sales negotiation in Arabic, ending with a group invite link. That link leads to a brand-new channel with only 12 followers, whose own description contains yet another group invite. The inflated parent channel is only the entry point. The actual transaction gets moved progressively deeper into a private chain of groups where there is no public record.

Beyond follower inflation, the SafeDep research team noted earlier this year that some Baileys forks in this campaign also inject the package author's advertising URL into every image and video the bot sends, a second payload the follower-count headline tends to obscure.


One Coordinated Operation, Many Names

OX Security found that 32 channels are followed by more than one package across this campaign. The single most reused channel, identified by the ID `120363400911374213@newsletter`, is targeted by ten separate packages. One remote channel list hosted on GitHub feeds five different packages simultaneously, meaning the operator can retarget all five installations by editing a single file.

Operators routinely publish near-identical packages under slightly different names to preserve the campaign when individual listings get removed. `noxleyss` and `@noxleyss/baileys`, for example, carry the same code under different publisher accounts.

Details of the abuse first emerged in August 2026 when SafeDep identified Baileys npm forks making installers' WhatsApp accounts follow attacker-controlled channels. Earlier this month, the Xygeni Security Research Team separately detailed another Baileys modification, `@dappaoffc/baileys-mod`, which subscribed developers' authenticated WhatsApp bot sessions to attacker-controlled newsletter channels.

The campaign follows a pattern OX Security has tracked on npm before. An earlier operation used the same registry to host fake Cloudflare CAPTCHA pages designed to redirect visitors to ClickFix phishing infrastructure. The registry's scale and the institutional trust developers place in what appear to be legitimate forks of known libraries make it a dependable distribution channel for this kind of abuse.

Because the packages carry none of the classic malware signatures, no API token theft, no heavy obfuscation across the board, no destructive payload, standard threat detection tools are likely to miss them entirely. That is precisely why most of these packages have remained live for months.


What Developers Should Do

Security recommends checking whether your WhatsApp account has been added to unknown channels and blocking or reporting any that appear. Developers should avoid any npm package that requires connecting a personal WhatsApp account and should add detection rules to their pipelines flagging known malicious Baileys forks. Remote channel-list URLs identified in these packages can be added to URL-reputation and threat-intelligence pipelines for ongoing monitoring.


84% of Indian SMEs Plan Higher Cybersecurity Spending as Readiness Gaps Remain

 

A large proportion of Indian small and medium enterprises (SMEs) plan to boost cybersecurity spending in the next 12-24 months yet experience gaps in terms of preparedness, monitoring and expertise, according to a TTBS and CMR study. The SME Digital Insights 2026 Cybersecurity study found that 84% of Indian SMEs plan to increase cybersecurity spend, highlighting that businesses are taking security seriously as they continue to embrace the digital transformation journey. 

However, the study identified a gap between expenditure planning and actual cybersecurity maturity. Around 40% of SMEs experienced a cyber incident in the last two years yet only 28% took structural actions to improve their cybersecurity capabilities after an incident. Continuous monitoring remains a major challenge, as only 12% of SMEs continuously monitored their cybersecurity environments, suggesting that businesses may continue to be reactive rather than proactively detecting and responding to threats. 

The study found that 35% of SMEs operate multiple cybersecurity tools in a fragmented manner, with limited visibility over the overall risk, creating difficulty for businesses in gaining a holistic understanding of their cybersecurity landscape. Cybersecurity spending continues to remain low for many businesses, with 46% allocating less than 5% of their overall IT budget to cybersecurity, leaving ample room for increased budget allocation as businesses continue to digitalize operations. Artificial intelligence (AI) is another emerging influence on SMEs’ cybersecurity strategies, as 35% of the businesses identified it as a key enabler to enhance detection, monitoring as well as incident response capabilities. 

Concurrently, 34% of SMEs foresee AI-enabled cyber threats to have a significant impact on their businesses in the next 12-24 months, pointing to the dual impact of AI technologies – as both a tool to secure and a threat enabler. Vishal Rally, Chief Revenue Officer at Tata Teleservices, said the planned increase in cybersecurity investment reflects that SMEs acknowledge the need to integrate security within the overall digital transformation strategy. 

Prabhu Ram, Vice President of the Industry Research Group at CMR, said that the findings reflect the uneven maturity in cybersecurity among Indian SMEs despite the anticipated rise in investment intent. For SMEs, the findings highlight that simply increasing cybersecurity budgets may not be enough to address the existing gaps in security. As businesses expand and become more digitalized, enhanced monitoring, visibility, expertise and integrated practices will also be required to mitigate the rising threats.

MCP Python SDK Flaw Exposes OAuth Credentials

 

A high-severity security vulnerability in the official Model Context Protocol (MCP) Python SDK could allow malicious MCP servers to steal OAuth credentials from artificial intelligence applications. Tracked as GHSA-qx49-fqc8-xw99, the flaw has a CVSS score of 7.5 and affects HTTP-based MCP clients that use OAuth authentication while connecting to servers that are not fully trusted. The issue does not affect local studio clients, MCP servers, or applications that provide their own authentication tokens and headers. 

The vulnerability is linked to the SDK’s OAuth discovery process. During authentication, an MCP client asks a server to identify the authorization server responsible for issuing tokens. A malicious server could return a 404 response for the standard OAuth discovery endpoint, forcing the SDK to use a fallback method. On this unsafe path, the SDK failed to properly validate the authorization server’s issuer, allowing the attacker to redirect the authentication flow to an infrastructure controlled by them. 

As a result, attackers could capture an OAuth client secret, authorization code and PKCE proof key. These credentials may enable the attacker to obtain valid access tokens from the legitimate identity provider, potentially gaining the same permissions as the affected application. Depending on the configured OAuth scopes, the impact could include access to cloud services, internal APIs, databases, deployment systems and other connected resources. Long-lived client secrets and refresh tokens could also support continued access or account takeover. 

The affected releases include MCP Python SDK versions 1.9.1 through 1.29.1 and versions 2.0.0 through 2.1.1. The maintainers fixed the issue in version 1.30.0 for the 1.x branch and version 2.2.0 for the 2.x branch. However, upgrading alone may not be sufficient for deployments using ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider; developers must explicitly configure the expected issuer= value. Users of the deprecated 1.x RFC7523OAuthClientProvider should migrate to another supported provider. 

Organizations should immediately identify affected clients, upgrade the SDK and remove stored OAuth client registrations created by older releases. If a vulnerable client connected to an untrusted MCP server, administrators should rotate client secrets, revoke potentially exposed tokens and review authentication logs for suspicious activity. Teams unable to upgrade should restrict connections to MCP servers they completely control and trust. The advisory highlights the security risks created when AI agents connect external tools to privileged enterprise systems, making strict server verification and issuer validation essential safeguards.

Cybercriminals Misuse ChatGPT Custom GPTs in ClickFix RAT Attacks


ChatGPT Custom GPTs are being abused by threat actors as an entry point for malware campaigns, redirecting users to malicious websites using fake artificial intelligence assistants. A campaign identified by Huntress in which attacker-controlled Custom GPTs were impersonating legitimate ChatGPT offers and directing victims to ClickFix scams has been identified. 

A total of 40 incidents associated with the same Google Sites infrastructure were linked to the campaign, and two of these cases have been confirmed to originate from malicious Custom GPTs. OpenAI reported a GPT that had been identified and removed on September 25, however two days later researchers identified another GPT that had been connected to the same campaign. 

The attack is initiated by a Custom GPT that appears to be a genuine ChatGPT service. It has been reported that some victims have reached the malicious GPT by searching for ChatGPT on Google and clicking a sponsored result. While the page itself remained hosted on the legitimate ChatGPT domain, the GPT was titled Plus 5.6, giving the appearance that it was an official model. 

A false message claiming that the primary domain was restricted to a limited number of users was displayed when the GPT was opened. After that, the website directed users to a fake backup website hosted on Google Sites, where a false Cloudflare CAPTCHA was displayed and a technique known as ClickFix was utilized to entice the victim into manually executing a command. 

PowerShell is launched by the command to retrieve an obfuscated script, which is temporarily saved before executing. After a silent download of a malicious MSI package named ISOSimple.msi, the script silently installs it. During the subsequent attack chain, the installer appears to be a legitimate Canon-signed application that is used to install an “Advanced Printer Configuration Reader”. 

Even when security software detected part of the payload, the infection was designed to remain active. One incident involved Microsoft Defender quarantining ISOSimple.msi as Trojan:Script/Wacatac.H!ml, because it had already set up a Run key and a scheduled task called “Canon Configuration Reader.” These keys and tasks allowed the malware to continue running on the computer. 

DLL sideloading is the next stage. With the MSI, the legitimate Canon COTFileReadApp.exe is installed, which has a valid digital signature, making the malicious package appear less suspicious. Attackers inserted a modified logging library alongside the executable, causing the legitimate Canon application to load malicious code through Windows' DLL search process as a result. 

The sideloaded code then extracts the next payload from a .wav file included in the installer Even though the file contains authentic audio data at the beginning and a valid WAV header, there are later sections that contain encrypted data that is decoded in memory. 

To avoid simple file-based detection, the loader retrieves an encrypted archive containing the malware and its persistence components and eventually eliminates straightforward file-based detection. There are 315 folders and 806 files contained within the archive, known as monitor.raw, which has a custom encrypted file structure. It contains a persistence script that continuously checks the registry for the malware's run entry and scheduled task, and recreates them if they are removed. 

In both instances, the infection can be re-executed by launching the Canon executable under the name "Canon Configuration Reader" by launching the Canon executable. An advanced Remote Access Trojan is attached to the final payload, which can provide access to the computer's desktop and screen, capture input from the camera, microphone, and audio system, and search for files on the computer. 

Additionally, the program collects information regarding security software installed, Windows configuration, network adapters, open ports, software installed and hardware installed. Command-and-control communication is carried out through DNS-over-HTTPS via services such as Cloudflare, Google, and Quad9, allowing its network traffic to blend in with legitimate encrypted web traffic.

In addition to downloading and executing additional EXE, DLL, MSI, PowerShell, and script-based payloads, attackers can extend activity beyond the initial compromise by downloading additional payloads. After removing the first Custom GPT from the campaign, Hunters discovered a second version. In addition to keeping the underlying RAT unchanged, the attackers replaced the Canon-based execution chain with a modified DLL and signed Stardock executables. 

In addition, the loader was moved from the WAV file into a Microsoft NuGet package, demonstrating that the delivery components can be changed without replacing the core malware. A second variant included additional measures to make detection more difficult, including freshly obfuscated download scripts and the removal of Windows Mark-of-the-Web tags before the MSI was executed. 

Nonetheless, the main behavior remained the same: MSI installation resulted from PowerShell activity, malicious code was loaded from a legitimate signed application, and persistent registry and scheduled task access was maintained. 

Therefore, security researchers advise that detection should be focused on behavior connecting these stages rather than relying solely on specific filenames or trusted software brands. It is possible to detect this type of attack by suspicious PowerShell activity followed by Msiexec, signed applications running from unusual locations, unexpected DLL loading, and newly created Run keys and scheduled tasks.

Hackers Breach Polish Medical Software Firm Qbusoft, Expose Patient Data in Second Healthcare Attack in Weeks


 


A cyberattack on Polish healthcare software company Qbusoft has left patient records from its Medyc platform potentially in the hands of attackers, coming just weeks after a separate, larger breach hit another Polish medical software provider and rattled the country's entire health data infrastructure.

The attacker exploited an SQL injection vulnerability in Medyc's application interface during late August, according to a breach notification published last week by the Addiction and Psychiatric Treatment Center in Inowrocław, one of the healthcare facilities running the platform. SQL injection is one of the oldest and best-documented attack techniques in security research, allowing an attacker to manipulate a web application into pulling data directly from its database. Despite decades of awareness about the flaw, it remains a recurring entry point in healthcare system compromises.

Qbusoft confirmed on Friday that the attackers obtained names, national identification numbers, home addresses, phone numbers and email addresses. In Poland, the national identification number, called a PESEL, functions similarly to a Social Security number in the United States and is a standard credential for identity verification across government services, banking and healthcare. Its theft puts affected patients at real risk of identity fraud.

The company said it had not confirmed the theft of clinical records. But the Inowrocław center told patients that Qbusoft found evidence the attacker ran scripts specifically targeting database tables containing medical information, making it "highly likely" that medical records were also pulled. The data in scope for that facility included hospital treatment records and discharge summaries from patients treated at its Day Treatment Unit for Addiction Treatment between July 2024 and August 2026.

The intrusion occurred on August 22-23 and went undetected until the night of September 8-9, a gap of more than two weeks. By that point, the attacker had already transferred an encrypted archive of the database outside Qbusoft's systems. Some fields, including names and PESEL numbers, had been encrypted in the database. Qbusoft nonetheless advised the affected center to assume the attackers could decrypt that information without difficulty, given the specifics of how the protection was implemented.

Qbusoft patched the vulnerability on the day the breach was detected, restricted database access permissions, rotated passwords and technical credentials, and introduced additional monitoring. The company has not publicly commented on the incident through any official statement.

That silence drew a sharp response from Digital Affairs Minister Krzysztof Gawkowski, who said the Central Bureau for Combating Cybercrime had opened an investigation and criticized Qbusoft for failing to notify CERT Polska or the national incident response team for the healthcare sector before authorities reached out. "Hiding attacks by companies is the biggest mistake, as it always puts citizens at risk," Gawkowski said. Poland's data protection authority separately announced that its president had ordered a formal audit of Qbusoft.

Medyc, which has operated as a cloud-based platform since 2014, is used across Polish medical practices and clinics for electronic medical records, patient scheduling, electronic prescriptions, referrals, sick notes, telemedicine and administrative billing. In a public notice, the company warned that its infrastructure had faced repeated attack attempts since the incident and that users might see temporary slowdowns or restricted access to certain modules.


The Same Attacker?

Polish cybersecurity publication Zaufana Trzecia Strona reported that a person or group using the alias "fingerprint" contacted the outlet claiming responsibility for the Medyc attack. The publication had previously linked that alias to the MyDr breach, a separate incident involving another Polish healthcare software vendor. Polish broadcaster RMF FM also reported that the same attackers behind MyDr were likely responsible for the Medyc intrusion, though Polish authorities have not formally attributed the attack to any individual or group.

The alleged attacker claimed to have obtained records on 5 million patients and 8 million private photographs, some of which Zaufana Trzecia Strona said may depict patients in sensitive medical settings. Neither figure has been independently confirmed, and the stolen data has not been made public. The actor reportedly framed the operations as an effort to expose weak security rather than profit from the data.

The MyDr breach, confirmed in August, potentially affected close to 19 million people across more than 12,000 healthcare facilities, involving over 2 terabytes of stolen data including names, PESEL numbers, prescription histories, diagnoses and appointment records. Poland has roughly 36.5 million residents, meaning the MyDr incident alone touched the records of nearly half the country's population. The Inowrocław treatment center caught up in the Medyc breach was also among the organizations affected by MyDr.

Gawkowski said Polish authorities had observed a surge in criminal activity targeting healthcare organizations in recent weeks and were preparing new regulations in response, including mandatory security certification for healthcare technology companies and tighter controls on how private vendors handle medical data. Poland recorded a 144 percent year-on-year rise in reported cybersecurity incidents in 2025. The consecutive breaches of Medyc and MyDr, both software vendors connecting thousands of clinics to national health infrastructure, have made clear that the weakest link in Poland's health data chain is not the government platform but the private companies sitting in front of it.




DC Health Agency Data Exposure Affects Nearly 400,000 Medicaid Beneficiaries

 

Almost 400,000 people who enrolled in Medicaid and the DC Healthcare Alliance may have been affected by a data breach, which occurred on the website of the District of Columbia Department of Health Care Finance. 

The issue concerned the reports published on the organization’s website, which showed aggregated data about the people who enrolled in the programs between 2023 and 2026. DHCF noted that the breach did not involve cybersecurity issues or intentional unauthorized access to the system. The problem was discovered by the agency in July, when it was revealed that two reports on the website contained fields with personally identifiable information that could have been accessed by unauthorized parties. 

The reports included only aggregated data, such as the number of people enrolled in the programs at specific times and other related information. Nevertheless, according to DHCF, the supporting information on its website could have been accessed by unauthorized parties since 2023. The personally identifiable information of the people who enrolled in Medicaid and the DC Healthcare Alliance includes their ID, providers, date of birth, race, gender, ethnicity, and wards. 

According to the agency, the reports do not contain Social Security numbers, names, and financial information of the affected people. DHCF announced that 399,086 people were affected by the issue and notified the United States Department of Health and Human Services (HHS). The latter added DHCF to its website, which keeps track of data breaches. It is unclear whether the affected people’s information was misused or will be misused in the future. Nevertheless, DHCF advised them to remain wary of potential fraudulent activities and unauthorized attempts to gain access to their information. 

According to the agency, the fact that the reports did not include Social Security numbers and financial accounts minimizes the risk of exploitation, but it remains present due to the inclusion of people’s IDs. After the breach was discovered, DHCF removed the reports from its website. In addition, it initiated an internal review process and responded to the problem by checking its systems for vulnerabilities and ensuring that its internal procedures were appropriate for addressing the issue. 

It is important to note that the breach illustrates how people’s information can be exposed even when it should not be. In this case, the data was not hacked or intentionally shared with unauthorized parties. Nevertheless, it became available to anyone who wanted to see it because the reports containing it were publicly available. 

Therefore, it is essential for people who enrolled in Medicaid and the DC Healthcare Alliance to ensure that they are not contacted by scammers and that their information is not misused. It is necessary for them to contact DHCF if they suspect that something is wrong. At the same time, it is important to keep in mind that, according to the agency, there is no information about the affected people’s information being viewed or misused.

NVIDIA Unveils Layered Security Architecture for AI Agents

 

NVIDIA has introduced the Open Agent Safety Platform as a security architecture for controlling autonomous AI agents from testing through deployment. Announced on September 28, 2026, the architecture combines open-source runtime controls with hardware-based monitoring, placing security boundaries outside the AI model itself. This design recognizes that prompt-level safeguards alone may not prevent an agent from accessing unauthorized files, tools, networks or services. Instead, NVIDIA’s approach connects agent permissions to the wider software, compute and hardware stack. 

The software foundation is NVIDIA OpenShell, a secure runtime that places each AI agent inside an isolated execution environment. It can define and enforce rules governing filesystem access, processes, credentials, network connections, APIs and external tools. Operators can convert instructions into verifiable policies before an agent begins work, while OpenShell traces actions and records policy decisions in an audit trail. Because these restrictions operate outside the model and agent framework, they can apply to both open and closed AI models. 

OpenShell is designed to act as the first enforcement layer in the architecture. For example, an enterprise agent authorized to retrieve an invoice from one folder could be blocked from opening unrelated files, modifying records or connecting to unapproved services. NVIDIA says the software runs with minimal overhead on its Vera CPUs, while its open-source design can be extended to third-party computing platforms, including Arm and Intel systems. This makes the runtime layer more portable than a security system tied entirely to one model or application.

The second major layer is NVIDIA Sentry, an out-of-band watchdog included in the reference system design. Running on NVIDIA BlueField-4 data processing units, Sentry monitors agent behaviour independently of the agent’s operating environment. Through NVIDIA’s DOCA software, it can inspect requests and responses, verify identities and enforce access policies covering data, tools, APIs and services. If an agent attempts to cross its permitted boundary, Sentry is designed to quarantine and stop it in milliseconds, creating a hardware-backed response when software controls are bypassed. 

Together, OpenShell and Sentry form a layered AI-agent security architecture rather than a standalone product review. OpenShell governs what an agent is allowed to do, while Sentry provides independent monitoring and containment below the software layer. The broader model gives developers a way to combine policy verification, runtime isolation, continuous telemetry and hardware enforcement across agent deployments. NVIDIA has made OpenShell and related skills available through its developer resources and GitHub, allowing organisations to examine and adapt the architecture as autonomous systems move into production.

NeedyMantis Malware Expands the Post-Compromise Threat Landscape


A modular malware family dubbed NeedyMantis has been identified by Microsoft Threat Intelligence, and has been employed to maintain access to compromised systems in a limited number of targeted intrusions. 


Evidence of the malware dating back to at least October 2025 indicates that it has affected telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. During an investigation into indicators associated with the DAEMON Tools supply chain compromise, Microsoft identified NeedyMantis. 

The company tracks activity associated with Storm-3069, and has observed the malware in use beyond that campaign. While Microsoft believes the observed operations are associated with activities associated with China-based threat actors, it has not attributed Storm-3069 to a Chinese nation state actor or confirmed that all NeedyMantis activity originated from a single operator. 

As a general rule, NeedyMantis is deployed after attackers have already gained access to the target environment. The malware serves primarily as an initial access tool, but it is also intended to maintain access and facilitate further activity within the compromised network, utilizing DLL sideloading as part of its delivery chain. It has been observed that attackers packaged malicious DLLs with legitimate applications and encrypted archives in an attempt to facilitate their delivery. 

Poedit, curl, Vim, and TightVNC were among the programs abused in this manner, while malicious DLLs were disguised as Microsoft Office, Broadcom, Intel, and NVIDIA components. One incident involved the use of Impacket toolkit to copy a legitimate software package from a network share into the malicious file, which was then executed on the targeted computer. It is important to note that NeedyMantis played a crucial role in the post-compromise phase of an intrusion, despite the attacker already having established access to the environment. 

Once the initial DLL is loaded, the malware continues to feature layered security. A second-stage component is extracted from the encrypted archive by the first-stage loader, which is the file used in the analysis, encryptbase64.ps1. Even though the file has a PowerShell extension, it contains x64 shellcode rather than a conventional PowerShell script. 

Once the embedded malware has been decoded and decompressed, a custom executable format based on a reduced version of the Windows PE format is loaded. An additional level of protection can be provided by the custom archive. Its contents can vary between samples, with file names and internal values varying. 

The analyzed WinSparkle archive contained legitimate components of 7-Zip and Sysinternals as well as files with familiar Windows library names, including dnsapi.dll and ws2_32.dll, mixed with legitimate components. Instead of the legitimate libraries represented by these files, NeedyMantis configuration and communication components were found in these files. The main component communicates with the malware's command-and-control infrastructure and manages additional modules. 

It is Microsoft's responsibility to observe an initial HTTPS request before switching the connection to a binary WebSocket protocol. The communications component utilizes WebSockets. A hard-coded user agent for Firefox 21.0 has also been used by the malware in one implementation. Through the C2 channel, operators can add and remove modules and exchange data with them, though Microsoft has not confirmed the specific functionality of the modules. 

A NeedyMantis sample collected in October of 2025 contained a persistence module based on Windows services, however the persistence method employed by the newer analyzed sample has not been identified. The malware is more challenging to analyze through a single file or indicator due to its staged loading, misleading file names, encrypted archives, and modular C2 communication. 

Detection points have been provided by Microsoft for hashes, file paths, the C2 hostname corp.tripswithengine[.]com, and the Firefox/21.0 user agent. As a result of the NeedyMantis campaign, security teams need to monitor suspicious loaders, C2 traffic, and unusual usage of legitimate software in order to recognize the risks posed by modular post-compromise malware.

Citrix NetScaler Zero-Days Exploited in Attacks

 

Two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are reportedly being exploited in the wild, raising serious concerns for organisations that rely on the products for remote access and application delivery. Security firm watchTowr disclosed the activity on September 26, stating that attackers had used the flaws to achieve remote code execution before Citrix released patches or detailed technical guidance. The company warned that the vulnerabilities could allow attackers to compromise exposed appliances and potentially gain access to connected networks. 

According to watchTowr, the flaws were discovered during forensic investigations into suspected intrusions. Both vulnerabilities reportedly enable remote code execution, meaning an unauthenticated attacker could potentially execute malicious commands on a vulnerable NetScaler device. Because these appliances frequently sit at the edge of corporate networks and handle VPN or application access, a successful compromise could provide attackers with an important entry point for credential theft, lateral movement, data exfiltration or ransomware deployment. 

At the time of the initial disclosure, Citrix had not confirmed the vulnerabilities, published affected-version information or released a security update. The absence of official indicators of compromise or a reliable workaround left administrators with limited options. Some organisations reportedly chose to take NetScaler appliances offline to reduce the risk, although doing so can disrupt remote workers, business applications and customer-facing services. Researchers expected Citrix to issue communications and patches during the week beginning September 28. 

The situation later developed when Citrix confirmed that two critical NetScaler flaws had been exploited and released fixes alongside patches for six additional vulnerabilities. The issues were identified as CVE-2026-88771 and CVE-2026-88772, both carrying a CVSS score of 9.5. The first is an improper input-validation vulnerability that could allow an unauthenticated attacker to run arbitrary commands, while the second involves improper memory-buffer restrictions and could lead to remote code execution or denial-of-service attacks. 

Security teams should treat these vulnerabilities as an emergency priority. Administrators should identify all internet-facing NetScaler ADC and Gateway systems, apply Citrix’s latest fixes immediately and review logs for unusual authentication, configuration or administrative activity. Organisations should also rotate potentially exposed credentials, inspect connected systems for signs of post-compromise activity and restrict management access wherever possible. CISA’s addition of both flaws to its Known Exploited Vulnerabilities catalogue further underlines the urgency of patching and incident investigation.

Singapore Expands AI Cybersecurity After UNC3886 Attacks

 

Singapore is changing its cybersecurity strategy after a state-sponsored cyber espionage group targeted the country’s four major telecommunications companies. The attack by UNC3886, disclosed in July 2025, could have disrupted telecommunications and internet services had the attackers penetrated further and raised concerns about national security. 

The incident has pushed Singapore toward a more proactive approach that assumes sophisticated attackers may eventually enter protected networks. Instead of focusing only on preventing intrusions, authorities are emphasizing threat hunting and the detection of suspicious activity after attackers gain access. In an interview, Cyber Security Agency of Singapore (CSA) chief executive and Commissioner of Cybersecurity Gwenda Fong said advanced persistent threat actors such as UNC3886 pursue specific targets, meaning perimeter protection alone is not enough. 

Once inside a network, attackers still need to move toward sensitive systems and data, giving defenders opportunities to identify unusual internal activity. Singapore is using artificial intelligence to strengthen this detection and prevention work. The Government Technology Agency of Singapore (GovTech) has developed two AI-powered tools for government systems. One performs automated penetration testing across about 2,000 government systems, including systems containing citizen data and transactions. 

The second scans the source code of government applications and systems for security weaknesses so agencies can address vulnerabilities before attackers exploit them. The authorities have not disclosed which agencies are using the tools, but their use is being evaluated for expansion across Singapore’s 11 critical information infrastructure sectors, which include healthcare, aviation, banking and finance, energy, government and information and communications. 

CSA has also started regularly scanning internet-facing systems operated by critical infrastructure organizations to identify potential entry points such as unpatched software and weak configurations. The agency said these scans are external and do not involve active probing. Other measures include proprietary threat-detection tools developed by a technical agency under Singapore’s Ministry of Defence and the sharing of classified threat intelligence with critical infrastructure operators. CSA is also examining supply-chain security because compromised vendors could potentially expose data or disrupt services. 

The agency is considering requiring some vendors and suppliers working with critical infrastructure operators to obtain Cyber Essentials or Cyber Trust mark certifications, potentially as early as 2027. As of August, 874 Cyber Essentials and 346 Cyber Trust mark certifications had been issued. 

The shift reflects the growing importance of cybersecurity to national security, the digital economy and public trust. CSA reported that suspected advanced persistent threat activity in Singapore quadrupled between 2021 and 2024, while authorities expect threats to increase as attackers gain access to AI tools. 

For organizations connected to critical digital infrastructure, the message is clear: security cannot end at the network perimeter. Identifying weaknesses, monitoring internal activity and detecting attackers before they can reach sensitive systems are becoming essential parts of defending increasingly connected services.

File Notification APIs in Windows, Linux, and Android Are Leaking What You Do on Your Computer

 



A research team from Graz University of Technology in Austria has shown that a routine feature built into virtually every major operating system can be turned into a surveillance channel that tracks keystrokes, visited websites, and private messaging activity without needing administrator access.

The feature is the file-change notification system. Every major platform ships one: Linux has inotify and fanotify, Windows uses ReadDirectoryChangesW, and Android and macOS have their own equivalents. Text editors, antivirus software, cloud sync clients, and file managers depend on these APIs to react when files are created, modified, or deleted. The catch is that subscribing to those notifications requires no special privileges, only read access to the directory being watched.

What these APIs never hand over is actual file content. What they do leak, the researchers found, is file names and the exact timing of events. That combination is enough to reconstruct meaningful details about what other users on the same machine are doing throughout the day.


Linux: Keystrokes Through the Filesystem

On Linux, if a process is blocked from watching a specific file directly, it can still receive that file's events by watching the parent directory, as long as that directory is readable. The researchers applied this to device files under /dev that represent keyboard hardware. The result is that an unprivileged process can detect every keystroke another user makes, though not which key was pressed.

That gap offers less protection than it appears to. Research going back more than two decades has established that the rhythm of inter-keystroke timing can help reconstruct what was typed. In tests with seven participants, the attack scored between 93.1% and 100% on standard accuracy measures. Input that never echoes to the screen, such as a password entered during a sudo prompt, does not generate filesystem events and stays invisible to the attack.

The team also demonstrated website fingerprinting by watching which system fonts Firefox loads for a given page. Against the top 100 sites, that technique reached 87.9% accuracy. A third Linux attack targeted KDE Plasma 6 on Wayland: a malicious process running as the victim can detect when a real authentication dialog is about to appear and draw a counterfeit one over it to capture credentials before the legitimate prompt ever loads.


Android: No Permissions Required

On Android, an application requesting zero permissions can watch the private storage directory of a completely separate app. Testing against WhatsApp on a Google Pixel and a Samsung Galaxy device, the researchers extracted file names and event timing that revealed when photos, videos, and documents were sent or received. The attack also exposed when that media was later deleted, offering a window into communication patterns that the app's own privacy controls do not address.


Windows: One Watch, Every User's Files

The most consequential Windows scenario arises when a process watches the root of the system drive. Windows reports the full path of every file that changes anywhere on the machine, including paths inside other users' home directories that the monitoring account has no direct permission to access.

Because Firefox names profile subdirectories after associated websites, an unprivileged user watching the drive root can track which sites another logged-in account is browsing in near-real time. Across the top 1,000 websites, the researchers hit 97.8% accuracy against Firefox and 48.5% against Edge, which creates far fewer site-named folders.

This behavior comes from the same ReadDirectoryChangesW API that was flagged under CVE-2007-0843 for a similar class of issue almost two decades ago. Microsoft's position has not shifted. The company told the researchers the behavior is working as designed, on the grounds that file contents remain inaccessible. A Microsoft spokesperson told SecurityWeek that "the technique requires an attacker to already have the ability to run code locally on a device under a separate user account and does not provide access to file contents." Microsoft did note that administrators can enable optional protections it documented in April 2025 covering some path-disclosure scenarios tied to directory change notifications.

macOS came out the least exposed of the four platforms. Its equivalent API can only monitor globally readable files, which limits the attack surface, though the researchers still demonstrated tracking of application launches, app interactions, and settings changes.

The Linux kernel received a targeted patch under CVE-2025-68788, which stops the fsnotify subsystem from generating access and modify events for special files, including the device files representing keyboard input. The researchers describe this as addressing the most serious Linux issue, but other attack paths from their research remain open.

Apple and Google have not responded to requests for comment, and no fixes have been announced for Android or macOS. The researchers say they have found no evidence of active exploitation in the wild. Proof-of-concept code for the full set of attacks has been published on GitHub at isec-tugraz/file-notification-attacks.



Supabase Misconfigurations Leave Customer Data Publicly Exposed


A cybersecurity firm UpGuard has found that thousands of databases hosted on Supabase can expose private information to the public internet. According to the research, approximately 16,000 databases hosted on the platform were able to be accessed by individuals through some form of personal data. The findings indicate that misconfigured databases and applications are a recurring security issue. 


Data storage and operations are widely facilitated by Suprabase for web and mobile applications, while the increasing use of artificial intelligence-assisted vibration coding has allowed developers with limited security expertise to create and deploy applications more easily. Among the exposed databases, UpGuard found names, addresses, telephone numbers, and passwords that were publicly accessible. A smaller number also contained authentication tokens. 

Various services and projects were connected to the exposed information, demonstrating that the problem is not limited to one type of application or industry. Datasets examined by researchers include private conversations provided by an Indian adult streaming platform, thousands of license plates owned by a valet service in the United States, as well as contacts for immigration and relocation services in the United States. 

Another exposed database reportedly served as a gateway to intercepting text messages via a virtual SIM farm. As UpGuard discovered, the database was linked to a consulate of the African government in France. By using these systems, online account holders can receive one-time verification codes, but when their data is left accessible via the internet, additional risks may be incurred. 

It is evident that the problem extends beyond isolated incidents; earlier investigations had also identified the public exposure of Supabase databases belonging to startups and widely used applications. UpGuard identified a large number of data sets that were located in the United States; however, the researchers indicated that the exposed databases were part of a global problem. 

An analysis performed by UpGuard identified 16,326 databases with Supabase tables that were publicly accessible. Approximately half of the databases contained personally identifiable information, and a smaller number contained passwords, authentication tokens, and payment card information in rare cases. The researchers also tested a sample of the databases to confirm that some of the exposed records contained information that was accurate. There has been prior documentation of this problem. 

In 2025, research discovered misconfigured Supabase databases connected to AI-assisted development platforms, and further investigation identified access controls and public key handling issues. The latest findings suggest that similar configuration errors remain widespread as more applications are constructed using AI coding tools for building and deploying.

Although Suprabase has implemented additional security safeguards, researchers noted that they are not necessarily applied automatically when databases are built using programming platforms. Nevertheless, proper configuration remains the only way to prevent unauthorized access to stored data. In addition, the findings highlight the differences between securing the backend of an application and building it. 

In contrast to AI-assisted development producing a working application rapidly, security settings around database access remain dependent upon decisions made during deployment. Consequently, access controls that are incorrectly configured can expose a database accessible through a given application when they are incorrectly configured. 

Supabase, on the other hand, stated that its projects are automatically secure and that database security is a shared responsibility between all parties. Managing Director of Information Security Bil Harmer stated that customers control how their projects are configured, while Supabase provides security defaults and tools and informs customers as soon as security threats are identified. The company has also implemented security-related changes to its platform over the years. 

The scope identified in the latest research, however, indicates that customer-side database configuration remains a critical part of the security equation, given that Supabase continues to be used for applications developed using artificial intelligence-assisted development tools. This study demonstrates that poorly configured cloud databases pose security risks, particularly as AI-assisted development continues to accelerate application deployments. 

Maintaining strict access controls and configuring databases carefully remain essential to prevent the public from having access to sensitive information.

Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks

 

Secure file-sharing provider Kiteworks issued an urgent advisory urging customers to power down their servers for a six-hour window following credible threat intelligence of a potential imminent cyberattack. The recommendation, communicated directly to enterprise and government clients, was described as a precautionary measure rather than a response to any confirmed compromise of systems. According to reports, the company received specific warnings from federal law enforcement agencies indicating that a threat actor may attempt to target Kiteworks installations over the weekend. 

The shutdown window was carefully scheduled to accommodate customers across multiple time zones, spanning from Australian Eastern Standard Time to Pacific Daylight Time. In Central Europe, organizations were instructed to take their Kiteworks systems offline between 4:00 a.m. and 10:00 a.m. on Saturday, September 26, while customers in New York faced a window from 10:00 p.m. Friday to 4:00 a.m. Saturday. Company representatives reportedly advised clients to shut down servers before the scheduled window began and emphasized that systems should be taken offline even if they were not directly accessible from the Internet, reflecting the seriousness of the potential threat. 

Kiteworks explicitly stated that it was not aware of any actual compromise of its systems and characterized the advisory as preventative in nature. The company confirmed that all known vulnerabilities affecting its platform had already been addressed in the current software release, version 9.5.1, and continued to recommend that customers run the latest version available. Despite this assurance, customer support representatives reportedly indicated to technology journalists that the shutdown recommendation was specifically intended to protect against potential zero-day attacks, though neither the official company statement nor the customer notification explicitly confirmed the discovery or exploitation of such a vulnerability. 

The potential targeting of Kiteworks platforms carries significant implications given the nature of the software and its typical user base. The company develops secure file-transfer and communications products that are widely used by government organizations, financial institutions, and large enterprises to handle sensitive documents and data. Secure file-sharing platforms represent high-value targets for cybercriminals who specialize in data-theft extortion attacks, as they commonly store confidential information that organizations would be desperate to protect from public exposure or unauthorized access. 

While the specific threat actor behind the potential attacks remains unidentified, the cybersecurity community has noted historical patterns that raise particular concerns. The Clop extortion gang has established a long history of targeting enterprise file-transfer platforms in sophisticated data-theft campaigns, including previous attacks against Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer systems. The U.S. Department of State currently offers a ten million dollar reward for information that could link this cybercrime gang's operations to foreign government sponsorship, underscoring the geopolitical dimensions that often accompany major enterprise security incidents of this nature.

Bitget Hack Climbs to $387.5 Million as Exchange Launches Recovery Bounty and Points to North Korea

 



Crypto exchange Bitget confirmed on September 25 that hackers stole approximately $387.5 million from its hot and warm wallets a day earlier, revising an initial estimate upward as investigators traced funds across multiple blockchains and accounting for assets on Zcash and TRON that were missed in the first tally. The exchange has since launched a structured bounty program for anyone who helps freeze or recover stolen funds, and has brought in independent cybersecurity firms Mandiant and SlowMist to assist with the investigation.

Bitget's security systems first flagged the unauthorized transfers at 18:31 UTC on September 24. By the time the exchange confirmed the breach publicly, the damage figure had already reached $351.6 million. The revised total of $387.5 million reflects a more complete accounting of transfers that occurred during the incident, adding affected assets on Zcash and TRON not captured in the initial estimate. The exchange confirmed no further unauthorized transfers occurred after the incident was contained.


How the Attack Worked

Bitget CEO Gracy Chen clarified that attackers did not steal private keys or forge user withdrawal requests. Instead, they broke into a backend system inside Bitget's wallet infrastructure and used it to spoof transaction data, tricking the exchange's own authorization process into approving payouts that looked routine.

The mechanics were methodical. The attacker's first transfer was a small 0.84 ETH test payment to a fresh address, after which Bitget's main Ethereum hot wallet made roughly 380 transactions during the attack. Every time the hot wallets refilled from the warm wallet layer, the attacker drained them again. The warm wallet, which normally only pays the exchange's own hot wallets, sent 13,966 ETH worth approximately $37 million to an address less than an hour old, with no approved list check and no secondary authorization on a wallet holding over $40 million.

The single largest piece of the haul was roughly 103 million XRP, valued at approximately $157 million at the time of the theft. About $75 million of the stolen funds were held in stablecoins including USDT and USDC.

Some of that ETH moved quickly into mixers: on-chain analysis shows around 6,300 ETH, close to $19 million, funneled through Tornado Cash within hours of the breach.

The confirmed affected assets span XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX, spread across Ethereum and several EVM-compatible networks, the XRP Ledger, Zcash, and TRON.


User Funds and the Protection Fund

Bitget operates a three-tier wallet architecture, and the breach touched only portions of the hot and warm wallet layers. Cold wallets remained fully secure throughout the attack. Bitget's User Protection Fund, which holds more than $464 million, will cover the full loss, meaning customer account balances stay intact even though the funds themselves were taken. The protection fund was set aside in 2023 specifically to cover hacks and theft so users would not absorb the impact.


North Korea in the Frame

During a three-hour livestream on X, CEO Gracy Chen said Bitget suspects North Korean attackers exploited the backend authentication system, making fraudulent withdrawals appear legitimate. Chen added that she has personally been targeted by the same group before, losing about $80,000 from a personal wallet unconnected to Bitget. North Korea's Lazarus Group, also tracked under the codename TraderTraitor, has been blamed for the industry's biggest thefts, including Bybit's $1.4 billion hack in February 2025, which the FBI confirmed weeks later was North Korean work.


The Recovery Bounty

Bitget has launched a Recovery Bounty Program covering eligible voluntary actions that have already resulted in affected funds being frozen, as well as future actions that directly contribute to freezing or recovering funds. The structure is straightforward: 5% of successfully frozen funds goes to the eligible person or entity whose efforts directly caused the freeze, and 5% of successfully recovered funds is available on the same terms. Bitget will also use Bybit's LazarusBounty initiative as a core channel for the effort.

To support the hunt, Bitget published a real-time fund tracing dashboard at trace.bgblockchain.xyz, an API tracking attacker-controlled addresses updated continuously, and a submission portal for anyone with freezing or recovery information. Exchanges, stablecoin issuers, bridges, custodians, and other infrastructure providers have been encouraged to monitor the flagged addresses and report relevant information through the recovery portal.

The attack is the largest cryptocurrency breach of the year to date and lands in an already turbulent stretch for the industry. Earlier in September, Liquid Network suffered a $319 million security breach, and in late July, hardware wallet maker Coldcard was hit in a separate incident that drained around $116 million in Bitcoin.

Bitget said it will publish a full incident report including root-cause analysis once technical teams complete remediation. Withdrawal restoration was expected to be announced by September 26, 4:00 AM UTC.


x47.c Windows Botnet Uses xAI Grok for Persistence and AI Credit Draining

 

A new Windows botnet called x47.c is being sold with a range of capabilities, including credential theft, distributed denial-of-service (DDoS) attacks, SOCKS5 proxy access and a method designed to drain paid AI credits. According to Qrator, the malware also uses artificial intelligence to help maintain persistence on infected systems. 

The botnet is advertised by a threat actor known as WraithTools. In early August, the operator offered the base x47.c package for $200, with a DDoS add-on priced at $150. The complete package, including its full range of capabilities, was offered for $950. Customers receive access to a command-and-control panel that allows them to manage infected machines and access features including fast-flux configuration, information-stealing logs, proxies, concealment capabilities and DDoS operations. 

The DDoS section provides 18 attack methods, including HTTP floods, slow HTTP attacks, TCP and UDP floods, TLS stresser activity, and reflection and amplification techniques. One feature specifically targets paid artificial intelligence services. The AI drain mode is designed to consume a victim’s AI credits by sending requests directly to an AI provider. The operator supplies a model name and a valid API key for accounts using OpenAI, xAI and compatible chat APIs. Because the requests are sent directly to the provider, the targeted website can remain accessible while the account’s available AI credits are depleted. x47.c also incorporates an “AI stealth” module designed to maintain persistence on compromised Windows systems. 

The feature is advertised as using xAI Grok to select actions from a predefined list, including startup entries and scheduled tasks. Optional process hollowing and privilege escalation capabilities are also available. According to Qrator, the operator activates the AI functionality by including an xAI key in the botnet build. Status messages can indicate startup changes, persistence repairs and Windows Defender exclusions. The malware also has local fallback actions that allow maintenance operations to continue when an AI model call fails. 

The botnet provides operators with additional control over infected systems. They can select DDoS targets and download, update or remove software from compromised hosts. A rootkit module is also promoted for removing artifacts associated with rival malware. Beyond DDoS activity, x47.c can harvest passwords and cookies from browsers, along with Discord tokens, cryptocurrency wallet data and AI-service tokens. 

Its SOCKS5 module allows compromised systems to relay traffic, while operators can monitor proxy connections and review their health status and timeouts. The combination of AI-assisted persistence, credential theft, proxy capabilities, DDoS functions and AI credit draining makes x47.c a broad Windows botnet offering multiple ways to abuse compromised systems and online services.

Hacking and Extortion Operation Targeting U.S. Official Ends in Conviction


A former U.S. Army soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for participating in a hacking and extortion campaign which exposed sensitive information and targeted telecommunication companies. According to the U.S. Department of Justice, Wagenius has also been ordered to pay $294,978 in restitution. Wagenius was involved in the cybercrime operation while serving as an active duty military member. 

In April 2023 and December 2024, he and other conspirators obtained credentials allowing them to access protected networks belonging to at least ten organizations. The stolen information was then used to extort victims by threatening publication or sale of the data without their payment.

Investigators have stated Wagenius was an online hacker known as “kiberphant0m” and he contributed to the development of the hacking tool SSH Brute, which was used to obtain login credentials. To exchange stolen credentials and coordinate access to victim networks, the group communicated via Telegram. Additionally, public threats were made on cybercrime forums.

Stolen information was made available for sale on platforms including BreachForums and Wagenius published two posts in November 2024 that contained stolen non-content call detail records associated with a former US government official and relatives of another former official. As part of the threats, the Justice Department also stated that additional confidential records would be released if a ransom was paid.

One of the posts indicated that the activity may be partly motivated by retaliation for the arrest of another cybercriminal. There have been several attacks involving major telecommunications companies and other companies. According to cybersecurity researchers, Wagenius' possession of data was related to broader attacks targeting Snowflake customer environments. Several companies were affected by the campaign, including AT&T, Ticketmaster, Advance Auto Parts, and Santander. 

Wagenius pleaded guilty in separate proceedings filed in the Western District of Washington in support of the charges. A conviction for wire fraud, extortion using computers, and aggravated identity theft was obtained in July 2025. Prior to this, he had pleaded guilty to two counts of unlawfully transferring confidential phone records related to the same operation in March 2025. Additionally, Wagenius appears to be tied to the wave of attacks against organizations using Snowflake cloud environments that took place in 2024. 

According to AT&T, attackers accessed call and text records covering nearly all of its mobile customers in December 2022. The stolen information was later associated with extortion activity involving several cyber criminals. Moreover, court records and the investigation report indicate that Wagenius attempted to sell stolen information to an email address he believed was affiliated with a foreign military intelligence service. Moreover, the prosecution alleges that he searched the Internet for information about leaving the United States for Russia. 

The intelligence services involved have not yet been publicly identified by the government. Based on the findings of the investigation, the hacking operation was primarily a result of the use of stolen credentials, rather than an exploit of a specific software vulnerability. The credentials were used by Wagenius and his associates to gain access to company networks and cloud environments, using Telegram to communicate access details and coordinate further intrusions. 

After invading victim networks, the group aimed at obtaining data to be monetized. In some cases, information was provided to other criminals, whereas other records were used for fraud schemes, such as SIM swapping. Additionally, extortion demands were extorted through private communications as well as public postings on cybercrime forums. 

The FBI, Defense Criminal Investigative Service, and other law enforcement agencies investigated these activities. A warrant was issued for Wagenius' arrest in December 2024, bringing to a close the hacking activities he allegedly conducted for more than a year while remaining an active duty soldier.

SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted

 

SolarWinds has issued security updates for two critical vulnerabilities in its Observability Self-Hosted product that could enable remote code execution without authentication. The flaws, tracked as CVE-2026-28324 and CVE-2026-28325, are present in multiple versions of the IT monitoring solution and have been patched in the latest release. Observability Self-Hosted is an on-premises and hybrid IT monitoring platform that enables organizations to centrally monitor their environments. 

It also features configuration management and control over operations data and security compliance. The first vulnerability, CVE-2026-28324, has a CVSS score of 9.8 and is described as an insufficient integrity check leading to remote code execution. SolarWinds reported that the problem affects deployments that use a non-default and non-secure configuration. Since the weakness is an unauthenticated remote code execution (RCE) vulnerability, SolarWinds warned that such deployments could be at risk of exploitation. 

The second flaw, CVE-2026-28325, has a CVSS score of 8.8 and is described as a deserialization of untrusted data issue that affects the instances of the application running in a specific communication mode. The company stated that it also allows for an unauthenticated RCE, meaning that the affected systems could be compromised by an attacker. Both weaknesses impact Observability Self-Hosted up to and including version 2026.2.2. SolarWinds has already released updates in the 2026.2.3 version of the product which resolves the identified issues. 

The company credited Kai Huang of Armadin for reporting the problems. The recent updates to Observability Self-Hosted follow the patch for an unauthenticated RCE vulnerability in SolarWinds Access Rights Manager (ARM). The flaw, tracked as CVE-2026-28326, has a CVSS score of 8.8 and impacts ARM versions up to and including 2026.2. This vulnerability also resides in a hardcoded static key for the affected system version. SolarWinds released the patch for CVE-2026-28326 last week after receiving the report from the anonymous security researcher. 

According to the company, this is the third high-severity flaw discovered in its products this year. Moreover, SolarWinds warned that all three could be actively exploited. However, the company added that there were no reports of exploitation for any of the three vulnerabilities. More information on the discovered issues can be found in the company’s advisory. 

The affected organizations should update their Observability Self-Hosted instances to version 2026.2.3 as it includes the fixes for two newly discovered RCE flaws. In particular, the update is recommended for the deployments that feature the non-default, insecure configurations described by the vendor.

Cloudflare Patches Cross-Tenant Container Flaw That Let Tenants Read Each Other's Leftover Disk Data

 




Cloudflare has patched a vulnerability in its Containers product that could have allowed a paying customer to pull residual data out of disk storage blocks previously used by a different tenant. The company disclosed the issue on September 24, three weeks after security researcher Oren Yomtov from the firm Accomplish filed a report through Cloudflare's HackerOne bug bounty program.

The flaw was rooted in how Cloudflare configured the Linux storage subsystem underpinning its container infrastructure. Cloudflare Containers run each workload inside a dedicated virtual machine powered by the Firecracker virtual machine monitor. Each VM gets a writable root disk backed by Linux device mapper thin provisioning, known as dm-thin, a storage technology that allocates physical disk space on demand rather than upfront. When a container's thin volume was deleted, the physical 64 KiB blocks it had occupied were handed back to a shared pool that served workloads from multiple customer accounts.

The problem was a single configuration option: `skip_block_zeroing`. With this flag set, dm-thin does not wipe a block before reassigning it. That is a performance trade-off operators sometimes make deliberately, but in a multi-tenant environment the consequences were significant. A freshly assigned block would carry the previous tenant's data intact unless the incoming workload happened to overwrite every byte of it.

Yomtov and his team worked out a way to exploit this behavior without needing any privileged access. A tenant with a standard Workers Paid account could open their container's raw root disk at `/dev/vdc` and identify regions that the guest ext4 filesystem had marked as free space. Writing a small 4 KiB block into a 64 KiB-aligned free region would force dm-thin to pull a physical block from the shared pool. Because zeroing was disabled, only the 4 KiB the attacker wrote got replaced. The remaining 60 KiB stayed exactly as the previous owner had left it. A subsequent raw-device read could then pull those bytes out.

What the researchers found across production runs was striking in scope. They tested the technique across 24 placements and found residual data on 18 of them, across 20 of 22 underlying nodes and spanning four continents. The recovered material included directory structures, database pages, and structurally complete SQLite databases. Using ext4's `metadata_csum` checksum feature, the team was able to confirm that recovered directory blocks did not originate from their own test filesystem. Across six placements they identified 2,700 distinct foreign directory inodes. All proof-of-concept materials submitted to Cloudflare were scrubbed of third-party identifiers and content values, and the researchers confirmed they securely deleted the recovered data after submission.

The vulnerability carried real limits. An attacker could not pick a target. Which blocks dm-thin reassigned to a new container depended entirely on Cloudflare's workload scheduler, so exploitation was opportunistic rather than directed. The technique also could not touch any actively mounted disk or modify another tenant's live data.

Cloudflare moved fast. Yomtov filed the report on September 4 at 15:26 UTC. The engineering team opened a security incident and confirmed the production setup behind the flaw within about three hours. A runtime fix was merged by 21:27 UTC the same day. Rolling out the change across the fleet began by 23:15 UTC. But removing `skip_block_zeroing` only stops future misallocation. Blocks already mapped into running containers or cached in pre-built snapshot layers were unaffected. To clean those up, Cloudflare drained hosts during off-peak hours, restarted their VMs, and wiped each host's image cache so every disk would be rebuilt using zeroed allocations. That final cleanup finished on September 19. The researchers confirmed their proof of concept stopped working on September 14.

Cloudflare said it reviewed all available historical disk I/O telemetry and found no activity consistent with the exploit technique other than what came from the researchers and from Cloudflare engineers during authorized validation. No customer-side action is needed.

The disclosure adds to a recent pattern in cloud infrastructure research. Yomtov's team at Accomplish has a track record of finding platform-level flaws; they also reported a sandbox escape in Anthropic's Cowork tool this year. In the wider cloud industry, Wiz researchers disclosed a separate cross-tenant issue in Microsoft Azure Cosmos DB this year, called CosmosEscape, which could have let attackers escalate from a crafted Gremlin query to retrieving primary account keys for other customers' databases. Microsoft said it found no evidence of customer impact in that case either.

Cloudflare co-authored its disclosure with Yomtov and the Accomplish research team, a relatively transparent move for a company of its size. The company's bug bounty sits on HackerOne and remains open for further researcher submissions.