Skip to content
root notes — archive

ls ./archive --page 5

Archive

page 5 of 15 — 339 articles

440,000 blocked attempts is a WAF metric, not a compromise count

2026-09-08Security

Wordfence blocked more than 250,000 attempts against Super Forms and more than 190,000 against Elementor Pro. Both flaws are unauthenticated file upload, both are patched, and the Super Forms campaign has been running since 14 July. What nobody has published is how many sites actually fell.

One researcher dropped three exploits. Only Gen Digital has shipped a fix

2026-09-08Security

PrettyPrague, FalconFlank and GreenSection target Avast's sandbox, CrowdStrike Falcon's macro remediation and NVIDIA's display driver. Gen Digital has patched. CrowdStrike's advice is to turn the affected protection off. NVIDIA is still investigating. And the FalconFlank claim this site called single-source last week now has independent confirmation.

Adobe has patched StyleSmuggler. The first confirmed victim was fully patched too

2026-09-08Security

CVE-2026-75650 is rated CVSS 10.0 and Adobe shipped the fix on 8 September, four days into active exploitation. Applying it is only half the remediation — the encryption keys have to be rotated as well. And the first confirmed victim was already running the August patches, which is why patching is not the same as being clear.

PEEP forges Chromium's own integrity values. It also needs you to be compromised first

2026-09-08Security

SOCRadar documented a post-exploitation toolkit that installs itself into Chrome and Edge profiles as an extension called Smart Bookmarks, forges the signatures Chromium uses to detect exactly that, and reaches the operating system through native messaging. It cannot get onto a machine by itself, which is the part the headlines drop.

The payloads sit on a blockchain testnet, which is free

2026-09-08Security

Netskope found over 5,400 compromised WordPress and PrestaShop sites pulling their next stage from smart contracts on the BNB Smart Chain testnet. EtherHiding is not new. Putting it on the testnet is, because the testnet costs nothing, behaves like the real chain, and has no abuse desk to write to.

The rogue ScreenConnect clients infect the hosts that connect to them

2026-09-08Security

Huntress found ScreenConnect clients that write a four-stage VBScript chain onto machines as they connect, profile each host, and then request a different payload depending on how much RAM it has and which EDR is installed. There is no code execution vulnerability to patch — it abuses file transfer, and ConnectWise says the fix is to turn the permission off.

The Telerik exploit chain needs the hardening step Telerik recommends

2026-09-07Security

TantoSec released a working exploit on 7 September for a padding-oracle chain in Telerik's RadAsyncUpload control that ends in unauthenticated code execution. Its precondition is an explicit, non-default encryption key — the setting administrators were told to configure. Roughly 127,000 requests and an hour in a lab.

N-able's two documents disagreed about exploitation. CISA has settled it

2026-09-07Security

CVE-2026-86218 is a CVSS 10.0 pre-authentication RCE in N-central, patched in the fourth hotfix in five weeks. For two days the vendor's release notes and its incident notice said opposite things about whether it was being exploited. CISA added it to the KEV catalogue on 8 September with a three-day federal deadline.

On Daybreak Blue the control is who you are. On a $20 plan it is whether the model says no

2026-09-07AI

Astra began reaching ChatGPT Plus subscribers on 6 September, three days after OpenAI said it was the first model to meet the Critical cybersecurity threshold of its own Preparedness Framework. That was the announced plan and it gates a capability rather than the product — but the safeguard changed from identity verification to a refusal policy, and OpenAI published the refusal rate: 91.5%.

The deletion was contractual, confirmed in writing, and did not happen

2026-09-07Security

Trezor says it repeatedly asked its logistics provider to delete customer data and repeatedly received written confirmation that it had been. On 5 September it disclosed that 67,000 US customers' names, phone numbers and home addresses from 2019 to 2021 were in a breach at that provider — matched, in every case, to the purchase of a hardware wallet.

A Chrome V8 zero-day paid $1,000. The lowest published tier is $7,000

2026-09-07Security

CVE-2026-85046 is a V8 type confusion, rated 8.8, exploited in the wild, and the sixth actively exploited Chrome zero-day of 2026. It was reported on 4 August and awarded $1,000 — an amount that does not appear anywhere on Chrome's published memory-corruption reward schedule. Several explanations fit. Google has offered none.

The print server held the LDAP bind credentials. That is what they came for

2026-09-07Security

Arctic Wolf has published what attackers do after exploiting the two PaperCut zero-days against schools and universities: create an account, dump the SAM hives, and grep the PaperCut config for the strings password, secret, ldap, bind and token. The print server is domain-joined and nobody's threat model has it on the list.

REPLICATION was never a read-only privilege. For twelve years it was a shell

2026-09-07Security

CVE-2026-6471 lets any account holding PostgreSQL's REPLICATION attribute load an arbitrary library as a logical decoding plugin and run code as the postgres user. It has been there since logical decoding shipped in 9.4 in 2014, and REPLICATION is the privilege every CDC pipeline in your estate already has.

A court seals a record by order. The order did not travel with the backup copy

2026-09-06Security

West Publishing says an intruder sat in Thomson Reuters' cloud from 1 March to 29 June, and that confidential, redacted or sealed court information may have been affected. Thomson Reuters' reassurance is that C-Track had no operational disruption and is safe to keep using — which answers a question nobody asked.

The backdoor was compiled into HAProxy. That is not an HAProxy vulnerability

2026-09-06Security

Rapid7 found a Linux implant built into the HAProxy binaries of two South Korean organisations, intercepting traffic and erasing its own requests from the proxy's own logs. Every headline calls it an HAProxy backdoor. Installing it requires already owning the host, which makes patching HAProxy the one response that changes nothing.

Three tools are called God's Eye. Only one of them publishes what it cannot see

2026-09-05Security

An MIT-licensed OSINT globe with 17.7k stars refuses to add person tracking and warns its own data may be wrong. A facial recognition product with the same name claims to unmask faces, detect sex changes and score attractiveness as trafficking risk, and publishes no accuracy figure at all. The name is identical. The honesty is not.

Search all 339 articles →