{
    "generated_at": "2026-10-02T21:57:24+00:00",
    "count": 30,
    "articles": [
        {
            "id": 4418,
            "title": "Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus",
            "url": "https://therecord.media/judge-dismisses-spyware-case-brought-by-salvadoran-journalists",
            "author": null,
            "summary": "The plaintiffs, who all worked for the independent and Salvadoran news outlet El Faro, failed to convince the court that their case had jurisdiction in California, according to the judge’s order.",
            "published_at": "2026-10-02 20:30:00",
            "discovered_at": "2026-10-02 20:45:04",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4416,
            "title": "CVE-2026-104019 - OS command injection in the Studio Space startup script in Amazon SageMaker Distribution",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-125-aws/",
            "author": "aws@amazon.com",
            "summary": "Bulletin ID: 2026-125-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/02/2026 13:00 PM PDT Description: Amazon SageMaker Unified Studio is an AWS service that unifies data, analytics, and AI development. It lets you find and access your organization's data and act on it with integrated, purpose-built tools. We identified CVE-2026-104019, an issue with the startup of SageMaker Spaces in SageMaker Unified Studio. The startup script in a SageMaker Space performs a network validation against all the available SageMaker connections in a project. Under certain conditions, improper sanitization of connection details during this validation could allow arbitrary code to be executed in the Space of another project member. In projects with the Trusted Identity Propagation feature enabled, this issue could result in a user with project contributor permissions (or higher) gaining access to another member's temporary execution role credentials and calling downstream trusted identity propagation-enabled AWS services on their behalf. We implemented a fix to all supported SageMaker Distribution versions to sanitize connection details during the startup validation process. The fix is deployed globally and will apply to all Spaces automatically on the next startup. Impacted versions: - 2.8.x - 2.13.x: all versions affected, no fix (end of support) - 2.14.x: < 2.14.12, fixed in 2.14.12 - 3.3.x - 3.8.x: all versions affected, no fix (end of support) - 3.9.x: < 3.9.12, fixed in 3.9.12 - 4.0.x: < 4.0.11, fixed in 4.0.11 - 4.1.x: < 4.1.11, fixed in 4.1.11 - 4.2.x: < 4.2.8, fixed in 4.2.8 - 4.3.x: < 4.3.5, fixed in 4.3.5 - 4.4.x: < 4.4.3, fixed in 4.4.3 - 4.5.x: not affected - < 2.8.0 and < 3.3.0: not affected Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.",
            "published_at": "2026-10-02 20:25:48",
            "discovered_at": "2026-10-02 20:40:05",
            "updated_at": null,
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-104019"
            ]
        },
        {
            "id": 4417,
            "title": "RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail",
            "url": "https://www.darkreading.com/cybersecurity-operations/remotethreat-bets-security-teams-need-to-test-what-happens-after-defenses-fail",
            "author": "Arielle Waldman",
            "summary": "The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.",
            "published_at": "2026-10-02 20:18:37",
            "discovered_at": "2026-10-02 20:45:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4415,
            "title": "Bipartisan backlash to ALPRs grows as two high-profile bills are introduced",
            "url": "https://therecord.media/alpr-legislation-hawley-sanders-merkley-aoc",
            "author": null,
            "summary": "Republican Sen. Josh Hawley has new legislation on limiting automated license plate readers (ALPRs), while Democratic Sens. Bernie Sanders and Jeff Merkley, with Rep. Alexandria Ocasio-Cortez, have teed up a broader bill.",
            "published_at": "2026-10-02 19:30:00",
            "discovered_at": "2026-10-02 19:45:07",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4414,
            "title": "CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-124-aws/",
            "author": "aws@amazon.com",
            "summary": "Bulletin ID: 2026-124-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/02/2026 12:00 PM PDT Description: Loom is an AWS Labs open-source AI agent orchestration platform. We have identified and addressed three issues in Loom for AWS, described below. We recommend upgrading to the latest version (1.7.0) and ensuring any forked or derivative code is patched to incorporate the new fixes. - CVE-2026-103956 ‐ Authentication bypass in Loom for AWS (CWE-306, CWE-1188) An issue in the authentication dependency in Loom for AWS versions",
            "published_at": "2026-10-02 19:21:29",
            "discovered_at": "2026-10-02 19:25:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "AI Security",
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-103956",
                "CVE-2026-103957",
                "CVE-2026-103958"
            ]
        },
        {
            "id": 138,
            "title": "Cisco IOS XE Software Security Hardening Release: August 2026",
            "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ?vs_f=Cisco%20Security%20Advisory%26vs_cat%3DSecurity%20Intelligence%26vs_type%3DRSS%26vs_p%3DCisco%20IOS%20XE%20Software%20Security%20Hardening%20Release%3A%20August%202026%26vs_k%3D1",
            "author": null,
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID). Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ Security Impact Rating: Critical CVE: CVE-2026-20267,CVE-2026-20268,CVE-2026-20269,CVE-2026-20270,CVE-2026-20271,CVE-2026-20272,CVE-2026-20273",
            "published_at": "2026-10-02 19:21:28",
            "discovered_at": "2026-08-15 14:33:28",
            "updated_at": "2026-10-02 19:45:02",
            "priority_score": 30,
            "source": "Cisco Security Advisories",
            "source_group": "Vendor Research",
            "categories": [
                "Apple",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-20267",
                "CVE-2026-20268",
                "CVE-2026-20269",
                "CVE-2026-20270",
                "CVE-2026-20271",
                "CVE-2026-20272",
                "CVE-2026-20273"
            ]
        },
        {
            "id": 4413,
            "title": "Frontline Education breach exposes school district employee data",
            "url": "https://www.bleepingcomputer.com/news/security/frontline-education-data-breach-impacts-school-district-employees/",
            "author": "Lawrence Abrams",
            "summary": "Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]",
            "published_at": "2026-10-02 19:01:40",
            "discovered_at": "2026-10-02 19:15:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Data Breaches",
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 4412,
            "title": "Warlock ransomware breach SharePoint in water, telecom operator attacks",
            "url": "https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/",
            "author": "Ionut Ilascu",
            "summary": "The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]",
            "published_at": "2026-10-02 18:33:01",
            "discovered_at": "2026-10-02 18:35:02",
            "updated_at": null,
            "priority_score": 15,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Microsoft",
                "Ransomware"
            ],
            "cves": []
        },
        {
            "id": 4409,
            "title": "GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers",
            "url": "https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw",
            "published_at": "2026-10-02 17:33:31",
            "discovered_at": "2026-10-02 17:45:03",
            "updated_at": null,
            "priority_score": 10,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4410,
            "title": "Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign",
            "url": "https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster",
            "published_at": "2026-10-02 17:33:16",
            "discovered_at": "2026-10-02 17:45:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "APT / Nation-State",
                "Malware",
                "Threat Actors"
            ],
            "cves": []
        },
        {
            "id": 4411,
            "title": "Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes",
            "url": "https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an",
            "published_at": "2026-10-02 17:02:12",
            "discovered_at": "2026-10-02 17:45:03",
            "updated_at": null,
            "priority_score": 5,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-63688"
            ]
        },
        {
            "id": 4408,
            "title": "Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response",
            "url": "https://www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response",
            "author": "Robert Lemos",
            "summary": "One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.",
            "published_at": "2026-10-02 16:56:30",
            "discovered_at": "2026-10-02 17:15:03",
            "updated_at": null,
            "priority_score": 25,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 4407,
            "title": "CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-120-aws/",
            "author": "aws@amazon.com",
            "summary": "Bulletin ID: 2026-120-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 08:30 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVolume creation privileges can inject additional mount options through the mounttargetipmap volumeAttribute. Appending comma-separated values to a value inside that JSON map causes the mount utility to parse them as separate mount options. Impacted versions: >= v3.1.0 AND",
            "published_at": "2026-10-02 16:38:11",
            "discovered_at": "2026-10-02 16:50:03",
            "updated_at": null,
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-103505"
            ]
        },
        {
            "id": 4405,
            "title": "SWIFT Banking & Government Middleware Enables RCE",
            "url": "https://www.darkreading.com/cybersecurity-operations/swift-banking-govt-middleware-rce",
            "author": "Nate Nelson",
            "summary": "Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.",
            "published_at": "2026-10-02 16:27:54",
            "discovered_at": "2026-10-02 16:30:12",
            "updated_at": null,
            "priority_score": 15,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 4406,
            "title": "GitLab warns of critical RCE vulnerability in AI Gateway service",
            "url": "https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/",
            "author": "Sergiu Gatlan",
            "summary": "GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]",
            "published_at": "2026-10-02 16:20:05",
            "discovered_at": "2026-10-02 16:35:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 4404,
            "title": "Is Your Organization Ready for 2027's AI Accountability Era?",
            "url": "https://www.darkreading.com/cybersecurity-operations/is-your-organization-ready-for-2027-s-ai-accountability-era-",
            "author": "Arielle Waldman",
            "summary": "Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.",
            "published_at": "2026-10-02 16:01:22",
            "discovered_at": "2026-10-02 16:15:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "AI Security"
            ],
            "cves": []
        },
        {
            "id": 4403,
            "title": "Is It Fair to Blame 'Rogue' AI for Security Failures?",
            "url": "https://www.darkreading.com/insider-threats/blame-rogue-ai-security-failures",
            "author": "Alexander Culafi",
            "summary": "\"Rogue AI\" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.",
            "published_at": "2026-10-02 15:51:33",
            "discovered_at": "2026-10-02 16:00:05",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "AI Security",
                "Microsoft"
            ],
            "cves": []
        },
        {
            "id": 4402,
            "title": "US sanctions Tren de Aragua gang members in ATM hacks crackdown",
            "url": "https://www.bleepingcomputer.com/news/security/us-sanctions-tren-de-aragua-members-in-atm-jackpotting-crackdown/",
            "author": "Sergiu Gatlan",
            "summary": "The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]",
            "published_at": "2026-10-02 15:20:53",
            "discovered_at": "2026-10-02 15:25:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4391,
            "title": "Cyber Brief 26-10 - September 2026",
            "url": "https://cert.europa.eu/publications/threat-intelligence/cb26-10/",
            "author": null,
            "summary": "Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.",
            "published_at": "2026-10-02 15:00:00",
            "discovered_at": "2026-10-02 13:15:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "CERT-EU Threat Intelligence",
            "source_group": "Government",
            "categories": [],
            "cves": []
        },
        {
            "id": 4400,
            "title": "In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats",
            "url": "https://www.securityweek.com/in-other-news-15k-icloud-spoofing-bugs-ai-policy-experts-phished-adblocker-spies-on-ai-chats/",
            "author": "SecurityWeek News",
            "summary": "Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats appeared first on SecurityWeek.",
            "published_at": "2026-10-02 14:30:00",
            "discovered_at": "2026-10-02 14:30:06",
            "updated_at": null,
            "priority_score": 0,
            "source": "Security Week",
            "source_group": "Security Journalism",
            "categories": [
                "Cloud Security",
                "Microsoft",
                "Mobile Security",
                "Phishing"
            ],
            "cves": []
        },
        {
            "id": 4401,
            "title": "AI Agents Attempt SQL Injection While Searching Government Data",
            "url": "https://securityaffairs.com/200234/ai/ai-agents-attempt-sql-injection-while-searching-government-data.html",
            "author": "Pierluigi Paganini",
            "summary": "AI agents probing US and Canadian government sites made SQL injection attempts while seeking data, but investigators found no evidence of compromise. Autonomous AI agents, working on what looks like ordinary data retrieval tasks, ended up throwing basic hacking attempts at a U.S. Department of Education site and Library and Archives Canada. Nobody told them […]",
            "published_at": "2026-10-02 14:19:28",
            "discovered_at": "2026-10-02 15:10:05",
            "updated_at": null,
            "priority_score": 0,
            "source": "Security Affairs",
            "source_group": "Other",
            "categories": [
                "AI Security"
            ],
            "cves": []
        },
        {
            "id": 4398,
            "title": "Mississippi mayor says ransomware incident led city to shut down systems",
            "url": "https://therecord.media/vicksburg-mississippi-government-ransomware-attack",
            "author": null,
            "summary": "Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating.",
            "published_at": "2026-10-02 14:06:00",
            "discovered_at": "2026-10-02 14:20:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [
                "Law Enforcement",
                "Ransomware"
            ],
            "cves": []
        },
        {
            "id": 4399,
            "title": "'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries",
            "url": "https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks",
            "author": null,
            "summary": "The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.",
            "published_at": "2026-10-02 14:05:00",
            "discovered_at": "2026-10-02 14:20:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [
                "Microsoft",
                "Ransomware"
            ],
            "cves": []
        },
        {
            "id": 4397,
            "title": "The EDR blind spot: 3 ways browser attacks evade endpoint telemetry",
            "url": "https://www.bleepingcomputer.com/news/security/the-edr-blind-spot-3-ways-browser-attacks-evade-endpoint-telemetry/",
            "author": "Sponsored by NordLayer Browser",
            "summary": "Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. [...]",
            "published_at": "2026-10-02 14:00:10",
            "discovered_at": "2026-10-02 14:15:02",
            "updated_at": "2026-10-02 14:30:08",
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4396,
            "title": "Vulnerability Backlogs Are an Ownership Problem",
            "url": "https://www.darkreading.com/cybersecurity-operations/vulnerability-backlogs-ownership-problem",
            "author": "Nishant Sharma",
            "summary": "Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.",
            "published_at": "2026-10-02 14:00:00",
            "discovered_at": "2026-10-02 14:05:01",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 4395,
            "title": "macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor",
            "url": "https://www.securityweek.com/macos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor/",
            "author": "Kevin Townsend",
            "summary": "The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek.",
            "published_at": "2026-10-02 13:15:00",
            "discovered_at": "2026-10-02 13:30:08",
            "updated_at": null,
            "priority_score": 0,
            "source": "Security Week",
            "source_group": "Security Journalism",
            "categories": [
                "Apple",
                "Malware"
            ],
            "cves": []
        },
        {
            "id": 4393,
            "title": "Follow the thread: a new dashboard to investigate account abuse",
            "url": "https://blog.cloudflare.com/account-abuse-protection-dashboard/",
            "author": "Nicole Justus",
            "summary": "Fraudsters are increasingly using AI to bypass stateless security checks. Cloudflare's new Account Abuse Protection dashboard uses stateful analysis and edge-generated Hashed User IDs to help teams investigate and block account abuse.",
            "published_at": "2026-10-02 13:00:00",
            "discovered_at": "2026-10-02 13:30:06",
            "updated_at": null,
            "priority_score": 0,
            "source": "Cloudflare Security",
            "source_group": "Vendor Research",
            "categories": [
                "Cybercrime"
            ],
            "cves": []
        },
        {
            "id": 4394,
            "title": "Protected Quick Tunnels: simple accountless authentication for your next dev project",
            "url": "https://blog.cloudflare.com/protected-quick-tunnels/",
            "author": "Nikita Cano",
            "summary": "Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.",
            "published_at": "2026-10-02 13:00:00",
            "discovered_at": "2026-10-02 13:30:06",
            "updated_at": null,
            "priority_score": 0,
            "source": "Cloudflare Security",
            "source_group": "Vendor Research",
            "categories": [],
            "cves": []
        },
        {
            "id": 4392,
            "title": "SMTP is the key: BPFDoor and AVERAT hitting the network edge",
            "url": "https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge",
            "author": "Rapid7 Intelligence",
            "summary": "OverviewRapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT, deployed against Taiwanese appliances. Additionally, we provide source code details of the Rapid7 BPFDoor controller introduced in our April 2026 blog, Stealthy BPFDoor Variants are a Needle That Looks Like Hay.The chain uses two binaries. A dropper writes a shell script to the appliance's storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image.The dropper derives its encryption key from the string ShareTech and lives in the appliance's own add-on package directory. The BPFDoor variants seen against South Korean systems impersonate the PID file of SpamSniper, a Korean anti-spam product, and rotate through ten Linux daemon names. Across the samples, each component adopts names and conventions designed to look unremarkable in the environment it targets.The common thread is regionalized disguise: each sample is aware of the vendor’s software running on the targeted systems and implements process spoofing accordingly. Passive BPF implants avoid conventional port scans; while outbound beacons hide inside ordinary DNS, TCP, and traffic, the threat-actor(s) are leveraging SMTP to stay under the radar. Telecommunications and network-edge operators are most affected, including embedded devices such as CCTV and DVR systems that can sit close to the network core. Readers will learn how each component works, what binds the six AVERAT builds to one another, and which behaviors and indicators to hunt for.Technical analysis Rapid7 BPFDoor controllerFigure 1: Overview of BPFDoor HTTP-tunneled trigger flow through edge proxy⠀Following our introduction of the Rapid7 BPFDoor controller, published in March, this section examines new features from the reconstructed source code.Earlier BPFDoor variants relied on raw \"magic bytes\" (like 0x7255 or 0x5293) sitting in the TCP or UDP headers. Once security vendors wrote static network signatures (Suricata/Snort) to detect these Layer 4 anomalies, the operators began targeting the edge proxies. By wrapping the magic packet in standard HTTPS POST requests and relying on SSL offloading common in telecom environments, the trigger can be delivered to the BPFDoor-infected node in a way that may evade conventional deep packet inspection.Because proxies alter HTTP headers (adding X-Forwarded-For and changing User-Agent lengths), the malware can no longer rely on static byte offsets to find its payload. To solve this, the new controller sends fake, benign-looking web requests (e.g., POST /admin/login.aspx?id=99990) that are mathematically padded. This guarantees that the string \"9999\" lands at exactly offset 26 of the TCP payload consistently.The backdoor uses this \"9999\" as a reference point, dynamically scans for the \\r\\n\\r\\n terminator, and extracts the hex-encoded command payload from the HTTP body.The dogetlogin function contains the hardcoded paths blending in with legitimate requests:Figure 2: Hardcoded web login paths used by the dogetlogin function⠀When running, the controller spoofs the identity of /usr/sbin/abrtd via set_proc_name and PR_SET_NAME. The #ifndef SOLARIS compiles safely across different operating systems, applying the abrtd disguise only where the Linux-specific prctl function is supported.Figure 3: Process name spoofing logic applying the abrtd disguise on non-Solaris systems⠀The table below lists the Rapid7 controller flags, with new features identified relative to the TrendAI analysis marked accordingly.SwitchVariable/ActionDescription-hdestipSpecifies the target host (the infected machine's IP address) to control.-ddportSets the destination port on the infected host to send the trigger packet to.-llhostSets the remote IP address that the infected machine will connect back to (Reverse Shell).-slportSets the destination port to listen for incoming connections on the attacker's machine.-mself = 1Sets the attacker's local IP address as the remote host, automatically setting up the local listener (overwrites -l).-bbportInstructs the controller to bind to a specified TCP port locally (Bind Shell mode).-nnopass = 1Sends the packet without prompting for a password (sends an empty/hashed password). Often used just to check if the backdoor is alive.-iraw = 2ICMP mode. Embeds the magic packet into an ICMP Echo Request.-uraw = 3UDP mode. Sends the magic packet via a UDP datagram.-wraw = 1TCP mode. Sends the magic packet via a raw TCP SYN packet.-fmagic_flagAllows the operator to manually define a custom magic byte sequence (integer value).-omagic_flag = 0x5571Quick-sets the magic bytes/flag to 0x5571.-Hhdestip[NEW] Specifies a secondary \"hidden\" IP address to embed inside the newly added hip field used to relay the magic packet. -ggethost[NEW] Activates the HTTPS POST tunneling mode (dogetlogin).-Ddir[NEW] Customizes the URI directory path to blend into specific web server logs when using the -g (HTTPS POST) mode.-vdebug = 1[NEW] Enables verbose/debug mode, which is particularly useful for printing out the crafted HTTP requests and responses.-ttmout[NEW] Sets a custom timeout value.-cbreak;[DEPRECATED] Parses the flag but takes no actionsTable 1: Rapid7 BPFDoor Controller Flags and DescriptionsA new BPFDoor variant tied to the South Korean clusterThe BPFDoor variants create a raw PF_PACKET socket, attaching a classic BPF filter matching Rapid7 Variant F and using magic bytes 0x6693 (UDP), 0x4274 (TCP) and 0x7820 (ICMP). On a match, the implant extracts the source address and connects back to the sender if the password is gZbpx0, opens a bind shell if the password is sT21xf, and otherwise defaults to a UDP knock.Strings are hidden with a rotating substitution alphabet. Decoding reveals a direct product-spoofing artifact and a set of service-name disguises. The SpamSniper /var/run/spamsniper.pid mutex, together with the sample provenance, ties this build to the South Korean cluster.List of spoofed processes:[watchdogd] /usr/sbin/chronyd /usr/lib/polkit-1/polkitd --no-debug /usr/sbin/rsyslogd -n [scsi_tmf_6] /usr/sbin/crond -n /usr/sbin/NetworkManager --no-daemon /usr/bin/python -Es /usr/sbin/tuned -l -p [charger_manager] [kaluad_sync]⠀SpamSniper is antispam software used mainly in South Korea, so this masquerade is consistent with targeting a Korean mail or telecom environment. The variants a37ea9897221d4495b538de72b74f2aa1d2ff09b7b6dcedd395aee58931adbf3 and 7e667ba5f9df912e02275d3cfe3809d16f822fe776f4035c84b118ebd925b1b5 share the same filter, packet parser, callback, and command paths.The data plane variantThe BPFDoor sample (a6f3b7f932761fb1fd5e74123f2482e36c65dd13e769af2ce08c65da195bfa7a) attaches a SOCK_RAW 16-BPF instructions parsing IP/TCP offsets and gates on a 14-byte payload (2B 76 C0 63 83 E9 5F E1 EE 69 3F 32 CD 94, unique per sample).Figure 4: BPF filtering for abc00922 TCP magic bytes⠀It spoofs its process name to ora_ppmond, mimicking the naming convention of Oracle-backed telecom subscriber and provisioning platforms (HSS, OSS/BSS), a disguise that only reads as legitimate on hosts actually running that class of infrastructure. Once triggered, it opens a stock Tiny Shell session and dispatches single-byte 'S'/'U'/'D' commands — interactive shell, upload, download — the same switch-case and iptables NAT-redirect staging/teardown logic found byte-for-byte in a second sample 4435fcd6862921092614dbeaa880e4192352984686ebcd98f0ba13ee8e226ef9 (the latter spoofing /sniper/snipe/bin/dtnpd and /sniper/bin/ofgmd). These samples show B",
            "published_at": "2026-10-02 13:00:00",
            "discovered_at": "2026-10-02 13:30:05",
            "updated_at": null,
            "priority_score": 0,
            "source": "Rapid7",
            "source_group": "Vendor Research",
            "categories": [
                "Linux",
                "Malware",
                "Network Security"
            ],
            "cves": []
        },
        {
            "id": 4390,
            "title": "Malicious Linux Implants Mimic Asian Mail Security Products",
            "url": "https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security",
            "author": "Nate Nelson",
            "summary": "A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it's hard to tell they're not.",
            "published_at": "2026-10-02 13:00:00",
            "discovered_at": "2026-10-02 13:05:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "Linux",
                "Malware"
            ],
            "cves": []
        }
    ]
}