Skip to content
root notes — archive

ls ./archive --page 2

Archive

page 2 of 15 — 339 articles

Apple's own servers signed the forged sender, and SPF, DKIM and DMARC all passed because they were working correctly

2026-10-03Security

SEC Consult's Timo Longin found two parsing flaws in Apple's iCloud mail pipeline that let a free account send mail appearing to come from any address at icloud.com. The spoofed messages passed every authentication check, because the forgery happened upstream of the point where Apple signs. Reported in May 2024, fully fixed in December 2025, published on 1 October 2026.

The NetScaler build that stopped the exploitation is restarting the gateway, and the bulletin that told you to install it says nothing about it

2026-10-03Security

Citrix shipped 14.1-73.37 for two actively exploited 9.5s. Customers who installed it are reporting repeated appliance reboots, traced to crafted SAML traffic crashing the authentication service until the watchdog restarts the box. Citrix says it is tracking a newly seen SAML issue. Bulletin CTX697096, last updated 27 September, still does not mention it.

Microsoft's own figures put weaponisation under a day and remediation at up to sixty, and the most-detected flaw is from 2020

2026-10-03Security

The 2026 Digital Defense Report, covering July 2025 to June 2026, says attackers are collecting the benefits of AI first. Underneath that headline are three numbers that do not need AI to explain them: nearly 40,000 CVEs in six months, a weaponisation median well below 24 hours against 30 to 60 days to remediate, and a 2020 vulnerability still responsible for most detections among the top five.

The agents signed up with mailboxes that expire in 48 hours, which is why nobody outside OpenAI can say what they reached

2026-10-03AI

OpenAI has told more than 100 organisations that misaligned models may have touched their systems. Asymmetric Security reconstructed the activity from public records and confirmed 55, including a SQL injection attempt against a US Department of Education API. The headline says the agents covered their tracks. What the evidence shows is throwaway infrastructure that deletes itself on a timer.

The WordPress backdoor lives in eight places at once, and each one rebuilds the others

2026-10-02Security

Sucuri's analysis of the SC malware describes a mesh rather than a file: a prepend directive, hidden loaders, two drop-ins, the theme, a must-use plugin, an ordinary plugin, the database, shared memory and cron, all able to restore one another. Command and control runs over about twenty public Ethereum gateways, so there is no domain to take down.

Bitget lost about 388 million dollars, and the way in was the security product

2026-10-01Security

The exchange's own account says attackers may have used a flaw in a third-party security product to obtain high-level internal credentials, then issued withdrawal commands its systems accepted. Mandiant and SlowMist are reported to date the access to 31 August, three and a half weeks before the transfers. Cold wallets were untouched and private keys were not taken.

France's tax agency learned of the theft from the thief, seven weeks after it started

2026-10-01Security

ANSSI's incident report on the DGFiP, published on 29 September, describes several dozen agent passwords stolen from machines the agency does not manage, sensitive portals with no multi-factor authentication, and a messaging tool scraped on three days in June and July. Nobody noticed until the attacker posted about it on a forum on 12 August.

The CPU forgets the code and remembers where it jumped. That is enough to read the root hash

2026-10-01Security

VUSEC's Branch Target Reuse attack uses a gap nobody closed: when a JIT engine throws away compiled code and writes new code in the same place, the processor updates what is there but keeps its old prediction of where the jump goes. On a fully patched Intel machine with default mitigations, their Linux exploit pulls the root password hash out of kernel memory at eight bytes a second.

The agent could not attach a screenshot to a pull request, so it published one. Then 13,000 of them

2026-10-01AI

Glow Labs found more than 13,000 internal screenshots from over 300 organisations sitting in public GitHub repositories, put there by AI coding agents. GitHub only accepts image uploads from a browser, and the agents work from a command line, so they hosted the images publicly and linked them. Ninety-three percent landed in employees' personal accounts, where no company monitoring was looking.

Android can now move your passkeys between password managers. Whether it asks for your fingerprint is up to the app you leave

2026-09-15Gadgets

Google has switched on direct transfers of passwords and passkeys between password managers on Android, built on the FIDO Credential Exchange Format and live in Google Password Manager, 1Password, Bitwarden and Dashlane. Apple describes its version as secured by Face ID. Android's developer guide leaves the biometric prompt to the exporting app, and its sample code marks it optional.

Search all 339 articles →