❌

Reading view

Atlassian warns of critical file access flaw in its datacenter products

Atlassian has told its users to patch its datacenter products, pronto, to prevent attackers accessing their files. The Australian collaborationware company on Monday sent users an email that opens with the words “Action required” and points to a security bulletin that explains CVE-2026-21589. The 9.3-rated arbitrary file access vulnerability is present in the datacenter versions of its Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye products. Atlassian says the vulnerability “allows an unauthenticated attacker to access specific files within the web application root directory in affected versions.” That’s scary because Atlassian warns “In some configurations, there may be sensitive files present that increase your risk.” There’s also some good news in that attackers must know the exact filename and path to exploit the vulnerability, and the mess doesn’t allow anyone to see the contents of a directory. Another piece of good news is that Atlassian has updated its products – so users only need to find a change window in which to upgrade to a safe version of their software. Atlassian advised those who can’t patch ASAP to remove their instances from the internet, if possible. “Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action,” the company warned. Its advisory also includes mitigations and advice on how to determine if your instances need the fix. Users who made the move from datacenter products to the Atlassian cloud have nothing to do, as Atlassian fixed the flaws in its own SaaS. That state of affairs rather vindicates Atlassian’s 2020 decision to stop developing its low-end server products and require users to shift into its cloud, and last year’s sequel in which it decided to discontinue its datacenter software, too. Atlassian admitted it hasn’t made that migration easy, because it somehow released a lift and shift tool that was worse than an earlier version. In March 2026, Atlassian axed ten percent of staff. The company’s share price was on a year-long slide at the time, as pundits suggested it might fall victim to the SaaSPocalypse, a theory that AI would replace business software. The price of Atlassian scrip has tripled since then, suggesting investors are more confident the company’s plan to use AI to power workflows represents a moat LLMs cannot cross. ®

  •  

Security researcher claims they found KVM guest-host escape flaw

Linux KVM, the hypervisor favoured by hyperscale clouds, apparently has a full VM escape bug. That nasty news came from security researcher Paulos Yibelo, who on X shared a screenshot of a bug bounty award he won for discovering what he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!” The bug bounty Yibelo participated in is run by Vercel, a company that provides MicroVMs as sandboxes for AI agents to work inside. The company’s Sandbox uses Firecracker MicroVMs, a technology created by AWS, which relies on Linux KVM – the kernel level hypervisor in Linux. Vercel CEO Guillermo Rauch named KVM as the hypervisor identified by Yibelo. “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization,” he wrote. And that’s all the info that has made it into the public view at this time. The Register can find no chat on relevant mailing lists. We have asked Rauch and Yibelo for additional details. Hopefully, we don’t hear from either of them for days or weeks, for two reasons. One is that guest-host escapes are the nightmare virtualization scenario because they mean whoever runs a guest VM could take over an entire server, and perhaps gain the ability to control other guests. The other is that KVM is astoundingly prevalent: AWS and Google both use it to power their public clouds. Enterprise virtualization players Nutanix, HPE, and Proxmox also rely on KVM. And of course KVM is also in Firecracker, which is open source and could therefore be running in all sorts of places. Whatever Yibelo discovered therefore very much needs a responsible disclosure process, because if hints about the flaw emerge it could allow attackers to do a lot of damage. Once a fix is found, the next question is whether implementing it will require disruption or downtime. It’s possible to hot-patch KVM, and to migrate live VMs from vulnerable hosts to machines running a patched version of Linux. Hopefully those techniques will work. This might be the second nasty bug discovered in KVM this year, after the so-called Januscape flaw. Beyond the potential risks this bug created, observers have suggested the potential seriousness of the flaw means Yibelo’s reward should exceed the $50,000 available under Vercel’s bug bounty program. ®

  •  

Citrix NetScaler security snafus get even worse amid more 0-day reports

The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found - and has already exploited - yet another Citrix bug before it had a patch. This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. It only affects NetScaler ADC and Gateway appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication. Late Friday, amid exploitation reports, Citrix confirmed that it was investigating a “newly observed issue related to SAML authentication in customer-managed NetScaler deployments.” By Saturday night, the vendor released a security advisory for NetScaler ADC and NetScaler Gateway with patches, urging vulnerable customers to “install the relevant updated versions as soon as possible.” Citrix also posted a blog about the vulnerability, confirming that it has observed targeted attacks on unmitigated NetScaler deployments that can lead to denial of service. Citrix did not answer our questions about CVE-2026-88779 - including how many instances have been affected and what attackers are doing after exploiting the bug - but urged customers to "quickly apply" the fix to NetScaler instances. "We were recently alerted to a new issue that affects service availability for some NetScaler deployments," a Citrix spokesperson told The Register. "After we were alerted to this issue we immediately developed and published a mitigation while concurrently developing, testing and deploying a fix." On Sunday, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed CVE-2026-88779 was under active exploitation and ordered federal agencies to patch the bug by Wednesday. While the new vulnerability is not technically related to the earlier eight CVEs finally disclosed by Citrix on September 27 - weeks after miscreants began abusing two of these security holes (CVE-2026-88772 and CVE-2026-88771) - watchTowr researchers told us they suspect it has been used to purposefully crash machines, making exploitation of CVE-2026-88771 faster. “This vulnerability is incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline,” watchTowr’s head of threat intelligence, Jake Knott, told The Register. “Exploitation is already occurring in the wild, and disrupting an authentication gateway can prevent legitimate users from accessing the services behind it.” WatchTowr reproduced the vulnerability on Friday, and Citrix credited the attack-surface management company along with Bishop Fox with helping it address the issue. “Citrix provides an indicator-of-compromise script that teams can run to check exposed appliances for signs of compromise, though a clean result is not definitive proof,” Knott said. “Security teams should prioritize appliances configured as a Gateway or AAA virtual server with SAML authentication enabled, and affected organizations should apply the fixed build or Citrix’s interim mitigation if an immediate upgrade is not possible.”®

  •  

SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click

I was going through the SelectorsHub code, id:ndgimibanhlabgdgjcpbbndiehljcpfh the XPath extension with about 400k users, and noticed it pulls ads from its own server and opens them in a background tab. You don't click anything.

Every couple of days the side panel pops up a "community link" and says "100% Safe, No Spam, No Malware." Five seconds later the tab opens by itself. The URL isn't in the extension. Their server picks it, and while I was analysing the extension the links changed three times with no extension update.

On install and update it skips the popup and just opens whatever the server sends.

The store page says they collect no data. The code still pings them daily, and the extension reads all your cookies to find one of its own instead of just fetching its own cookie value.

Another weird finding: there's a hidden Fix Selector button that sends the selector to shubads[.]testcasehub.net. VirusTotal - Domain - shubads.testcasehub.net
That host now redirects to a gambling site, blomehairdryers[.]com.

Nothing gets run today because the reply is HTML, but that's the server the eval path trusts.

Looks like adware, not password theft. I wouldn't leave it on a work browser, especially since this is a tool used by devs and tech people browsing protected endpoints in a company.

Write-up: https://malext.io/reports/RedirectorsHub/

submitted by /u/Huge-Skirt-6990
[link] [comments]
  •  

FBI confirms 'multiple' arrests related to ShinyHunters hack

The FBI and law enforcement partners have arrested “multiple” suspects as part of an investigation into a September hack allegedly involving data-theft-and-extortion group ShinyHunters, the bureau told The Register. “The bureau continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice,” an FBI spokesperson told us in an email on Monday. The FBI declined to comment on the specific arrests, including that of Saif al-Din Khader, a suspected ShinyHunters member who has reportedly been detained in Jordan, according to Reuters. Khader, who goes by the alias Rey, was reportedly brought into custody on September 29, and is said to be cooperating with the FBI to identify other members of the group. ShinyHunters did not respond to The Register’s inquiries about the arrest and Khader’s alleged involvement with the criminal group. Rey confirmed his real identity - Khader - to security journalist Brian Krebs last year. Krebs described Khader as the “technical operator and public face” of Scattered LAPSUS$ Hunters. “Rey got picked up finally,” said security sleuth Kevin Beaumont following news of the arrest. According to Beaumont, Rey was “one of the kids who got into JLR.” The Jaguar Land Rover (JLR) breach, which occurred in late August 2025, affected the company's IT systems and halted manufacturing operations. Dealer systems also went down, and suppliers faced canceled or delayed orders. In addition to crippling the carmaker’s business operations for months, the digital thieves stole personal payroll data belonging to thousands of JLR employees. The cyberattack, one of the most costly in UK history, was attributed to Scattered LAPSUS$ Hunters. Khader’s detention came two weeks after the Dutch National Police arrested a 24-year-old whom the FBI described as “one of the alleged leaders of ShinyHunters.” While Dutch cops have not named the suspect, Krebs and other reports say he is Pepijn van der Stap, who was convicted in 2023 for hacking and extorting numerous organizations and was on supervised release after three years in prison. Van der Stap also worked as a software engineer at the Amsterdam-based cybersecurity startup Hadrian and volunteered as a security researcher at the Dutch Institute for Vulnerability Disclosure (DIVD). In a video message following the arrest, Brett Leatherman, assistant director of the FBI's Cyber Division, had some advice for the “remaining members” of the data theft and extortion gang. “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left,” Leatherman said last week. “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.” At the time, the FBI declined to answer The Register’s questions about the video message, including whether it had seized any of the cybercrime group’s infrastructure, and whether any of ShinyHunters’ members had taken Leatherman up on his offer to “reach out first.” In late September, ShinyHunters hacked the FBIJobs.gov portal and claimed it stole sensitive personal details about current, former, and prospective FBI employees. A spokesperson told The Register that unlike most of its digital break-ins, this one was “NOT financially motivated … We want the FBI to correct or retract their statements they made, which included substantial false allegations.” Later, in an exclusive interview, the spokesperson told us the attention-grabbing hack was “fundamentally a public relations and marketing initiative for our business.” ®

  •  

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a

  •  

Debian's latest kernel security update has 1,313 reasons to patch

The age of LLM-assisted security vulnerability discovery is really starting to bite. Debian's latest Linux kernel security update comes with a formidable reading list of 1,313 CVE identifiers. The DSA-6528-1 Linux security advisory, published on September 29, covers kernel package version 6.12.111-1 for Debian 13, codenamed Trixie. Debian 13.7 was released on September 12, before upstream kernel 6.12.111 arrived nine days later. The Debian security tracker links to descriptions of the individual issues. We have not examined every entry. If we had, this article would not appear until after Debian 13.8 (which is likely to appear later in October), or possibly at some point in 2027. Several checked at random also affect older kernel versions, so the list should not be read as a tally of bugs introduced in 6.12.111. The Linux kernel project became a CVE Numbering Authority (CNA) in February 2024. Back in February this year, kernel maintainer Greg Kroah-Hartman described the Linux CVE assignment process in some detail. He said kernel development averages around nine changes an hour, with a feed of known bug fixes averaging about 30 changes a day providing the basis for the CNA team's review. The kernel team's policy is to assign CVEs automatically after fixes have reached a stable kernel tree. It takes a deliberately cautious approach because the security implications of a bug may not be apparent when it is fixed. A CVE identifier alone therefore says little about severity or exploitability. We strongly suspect that this number of CVEs is due to LLM bots doing the bug hunting, and quite possibly doing the bug fixing as well. Linux is not an anti-AI project, and neither is Debian. AI-assisted bug hunting is already swamping the Linux security mailing list, as The Register reported in May. Kroah-Hartman released kernel 6.12.112 on October 3. Its detailed changelog runs to more than 27,000 lines. With both the rates of change and the sizes of the changes getting so large, it is hard to deny that LLM bot assistance must be very useful to the hard-pressed maintainers. Whether coding bots constitute a net benefit to the projects, to software, or to humanity as a whole remains at best an open question. ®

  •  

Legacy sign-on service comes back to bite school software provider Bromcom

UK education software provider Bromcom has notified customers of a personal data breach affecting its single sign-on (SSO) technology. In a September 24 EduGeek post, an account named Bromcom_Alastair said an unauthorized third party had accessed and retrieved email addresses and limited information associated with affected SSO registrations. The incident involved legacy SSO registration functionality in Bromcom's Communication Server environment. The company confirmed in an FAQ it found no evidence that its school Management Information System (MIS), used to manage student data, attendance, behaviour, and administration, was compromised. Bromcom said it was working with external forensic specialists to determine the nature and scope of the data involved. The company identified the incident on September 6 after reports of SSO access problems and has since withdrawn the legacy functionality from production. The service held email addresses associated with SSO registrations, the provider used, such as Microsoft or Google, registration and last sign-in dates where recorded, and internal user and registration reference numbers. Bromcom said the affected component did not hold account passwords or authentication tokens. The legacy SSO registration functionality had remained in production after being superseded because "it was still being called by an internal system," the supplier said. The incident did not enable access to Microsoft or Google accounts, whose authentication services are separate from the affected component said Bromcom. The Register has asked Bromcom to comment further. Bromcom provides information management software used in schools and the wider education sector in the UK. It offers tools for budgeting, timetabling, HR, and benchmarking. Bromcom's software is used by more than 5,000 schools and 390 multi-academy trusts (organizations that run multiple schools). Recent customer wins include Newport City Council, the Ministry of Defence, Warwickshire County Council, and the Northern Ireland Education Authority. ®

  •  

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others

  •  

The Credential Layer Is Expanding Faster Than Security Teams Can See It

Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and what they

  •  

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report

  •  

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge

  •  

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

  •  

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to

  •  

Weekly Update 524: Live From Copenhagen

Weekly Update 524: Live From Copenhagen

I'm in Denmark! Well, just, I'm now at Copenhagen airport ready to begin the long trek home, with the final event at GOTO now done and going just perfectly. This week, there are two ShinyHunters arrests in the news: Pepijn in the Netherlands and then Saif in Jordon. It's an inevitable outcome, of course, and as I say this week, it was also the most likely one. Time will tell how many more join their ranks, but the seriousness of the crimes, the length of time they were perpetrated over, and the motivations behind them will certainly see substantial custodial sentences.

In other news, this week I'm properly introducing a new sponsor for the blog: Origin. One of our next AI frontiers is understanding what agents have actually done (and we've all seen news of where they're been a bit too, well, "creative" in executing their tasks), and Origin's solution gives you visiblity into just that. Check them out, and a big thanks to them for their ongoing support.

Weekly Update 524: Live From Copenhagen
Weekly Update 524: Live From Copenhagen
Weekly Update 524: Live From Copenhagen
Weekly Update 524: Live From Copenhagen
  •  

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, and cooperating with the U.S. Federal Bureau of Investigation (FBI)

  •  
❌