<?xml version="1.0" encoding="UTF-8" standalone="no"?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" version="2.0"><channel><title>Cyber Kendra</title><description>Tech Hub</description><managingEditor>noreply@blogger.com (Root)</managingEditor><pubDate>Sun, 26 Jul 2026 11:08:11 +0530</pubDate><generator>Blogger http://www.blogger.com</generator><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/">3551</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/">25</openSearch:itemsPerPage><link>https://www.cyberkendra.com/</link><language>en-us</language><itunes:explicit>no</itunes:explicit><copyright>All the content is copyright of cyberkendra.com</copyright><itunes:image href="http://2.bp.blogspot.com/-svYWW7Cp8JI/UDUgofD9kUI/AAAAAAAAAEY/ina7VZi4ZRg/s1600/webprotal.png"/><itunes:keywords>Computer,technology,tech,IT,security,Gadgets,Telecom</itunes:keywords><itunes:summary>All about Computer and technology. </itunes:summary><itunes:subtitle>Cyber kendra</itunes:subtitle><itunes:category text="Technology"><itunes:category text="Tech News"/></itunes:category><itunes:author>Vivek Gurung</itunes:author><itunes:owner><itunes:email>protalweb@gmail.com</itunes:email><itunes:name>Vivek Gurung</itunes:name></itunes:owner><item><title>North Korea Arrests Its Own Hackers Over Bank Heist</title><link>https://www.cyberkendra.com/2026/07/north-korea-arrests-its-own-hackers.html</link><category>North Korea</category><category>Security</category><pubDate>Sun, 26 Jul 2026 11:08:11 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-6608608216498086874</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="North Korea Hacker Arrested" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5C5-fULu3CF-OIghrajZOzuyiZB-7Zo9cqsCyrHe_xFLT6W4GMlsPhTE449XP3itdoYqRSes0d_DeQ65ExCzj9YRyqTJF7BQHOrlm_KVjzaYs6y2YpY8tzqd66YDc-QC7000aHcKiyAgN2gNxtxb0dLzrEcb9Qna8tOwE1hpIajCxoGbiIMbFn78gjj0/s1600/North-Korea-Arrests.webp" title="North Korea Hacker Arrested" /&gt;&lt;/div&gt;&lt;p&gt;The country that built the world's most prolific state hacking program just discovered what every CISO already knows: the people you train to break in can break in anywhere — including your own vault.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;North Korea's National Intelligence Agency has arrested a ring of former military cyber operators accused of looting two state banks and washing the money through cryptocurrency, according to Seoul-based outlet &lt;a href="https://www.dailynk.com/20260723-1/" rel="nofollow" target="_blank"&gt;Daily NK&lt;/a&gt;, which cited an anonymous source in Pyongyang. The report has not been independently verified.&lt;/p&gt;&lt;p&gt;The ringleaders were reportedly discharged veterans of a cyber unit under the Reconnaissance and Intelligence General Bureau — North Korea's military intelligence arm — who recruited young IT talent from Kim Chaek University of Technology and Pyongyang University of Science after leaving service. They allegedly breached the internal networks and foreign payment systems of the Chosun Central Bank, which handles currency issuance, and the Foreign Trade Bank, which processes the country's overseas payments.&lt;/p&gt;&lt;p&gt;The tradecraft is familiar to anyone who has read a DPRK threat report. The group is said to have skimmed state trade funds and foreign currency from shell accounts in tiny increments — structuring, in anti-money-laundering terms — then pushed the money into overseas crypto wallets, where Chinese brokers converted it back to dollars and yuan. Handlers in the border cities of Sinuiju and Hyesan reportedly settled the cash in real time, coordinating over encrypted messaging apps, unregistered burner phones, and Chinese wireless gear.&lt;/p&gt;&lt;p&gt;What broke the operation was not exotic forensics. Officials noticed small mismatches in foreign-currency payment approvals and flagged odd overseas IP access logs, triggering a covert probe that traced encrypted transaction traffic to a Pyongyang safe house raided on the night of July 12. Agents reportedly caught the crew mid-laundering at their keyboards and seized hundreds of thousands of dollars in equipment.&lt;/p&gt;&lt;p&gt;That detection path is the takeaway for defenders. Reconciliation gaps in payment approvals and geographically impossible logins remain the two highest-yield insider-threat signals in any finance stack — and both are cheap to monitor. Pair transaction-level reconciliation with conditional access on IP and device, enforce dual approval on outbound payments, and log privileged access to core banking systems separately from the admins who hold it.&lt;/p&gt;&lt;p&gt;Context on scale: North Korean operators stole a record $2 billion in crypto last year, per Chainalysis, and TRM Labs pegged them at 76% of all hack and scam losses through April.&lt;/p&gt;&lt;p&gt;Pyongyang's elite are reportedly rattled. One official, quoted via Daily NK's source, warned it would be "hard for the entire family line to survive."&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5C5-fULu3CF-OIghrajZOzuyiZB-7Zo9cqsCyrHe_xFLT6W4GMlsPhTE449XP3itdoYqRSes0d_DeQ65ExCzj9YRyqTJF7BQHOrlm_KVjzaYs6y2YpY8tzqd66YDc-QC7000aHcKiyAgN2gNxtxb0dLzrEcb9Qna8tOwE1hpIajCxoGbiIMbFn78gjj0/s72-c/North-Korea-Arrests.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>BitMart to Shut Down, Sets August Withdrawal Deadline</title><link>https://www.cyberkendra.com/2026/07/bitmart-to-shut-down-sets-august.html</link><category>Crypto Currency</category><pubDate>Sun, 26 Jul 2026 10:50:37 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-2568084247252982649</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="BitMart Shut Down" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFNPFkNjOQZLmWnrQv8gfsmQnTyynPrZUKI6aTMw5bnqzOHuURQvTZXzUmxjFBH-iZAENRGiES0b7vQhzkjhjeMQRUVOIlA3kzDZFYibvtXRcbeG12Ad39pHM-u6y33JIXEiIcojaoDzbfkNQbQ1cJ7JNmXQxeayP8ubyPKsaRjBnGIHbFH9DjgAl3w98/s1600/bitmart.webp" title="BitMart Shut Down" /&gt;&lt;/div&gt;&lt;p&gt;BitMart posted its wind-down notice at 01:40 UTC on July 26, and everyone will repeat the same date: January 31, 2027, when the platform officially ceases operating. That date is a distraction. If you hold assets on BitMart, the number that decides whether you get them back is August 26, 2026, at 05:00 UTC — the deadline BitMart itself recommends for submitting withdrawals. That is one month away.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The closure lands three days after &lt;a href="https://bitmart.zendesk.com/hc/en-us/articles/53544595916059-Important-Notice-Regarding-the-Orderly-Cessation-of-BitMart-Operations" rel="nofollow" target="_blank"&gt;BitMEX announced&lt;/a&gt; its own shutdown, and the two notices read very differently. BitMEX told users its assets exceed its liabilities and cited zero customer funds lost to hacks in 11 years. BitMart's notice offers no comparable assurance.&amp;nbsp;&lt;/p&gt;&lt;p&gt;What it offers instead is a long list of withdrawal review triggers: KYC checks, device and IP verification, address screening, source-of-funds review, Travel Rule compliance (the rule requiring platforms to pass sender and recipient data alongside transfers), and sanctions screening. It states plainly that submitting a request does not mean the review is finished.&lt;/p&gt;&lt;p&gt;The phased timeline started immediately. Deposits, new registrations, and new orders stopped at 01:30 UTC on July 26. Futures accounts went Reduce-Only — positions can shrink, not grow. All trading ends 01:00 UTC on August 26, with any open positions settled at whatever price the platform applies. Users who miss the window get moved into a "dedicated processing procedure" that has no published timeline.&lt;/p&gt;&lt;p&gt;Context matters here. BitMart lost $196 million to a hot wallet breach in 2021, has never published credible proof of reserves, and faced withdrawal-delay reports in May. Its BMX token fell by over 60% on the news. It was still scheduling new token listings this week.&lt;/p&gt;&lt;p&gt;Act now, in order: finish KYC, cancel open orders, close futures positions before August 26, redeem Earn and staking products, export your full trade history, then withdraw to a wallet you control — verifying the network twice.&lt;/p&gt;&lt;p&gt;BitMart's own fraud warning deserves repeating: there is no expedited withdrawal channel and no unfreezing fee. Anyone offering one is stealing from you.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFNPFkNjOQZLmWnrQv8gfsmQnTyynPrZUKI6aTMw5bnqzOHuURQvTZXzUmxjFBH-iZAENRGiES0b7vQhzkjhjeMQRUVOIlA3kzDZFYibvtXRcbeG12Ad39pHM-u6y33JIXEiIcojaoDzbfkNQbQ1cJ7JNmXQxeayP8ubyPKsaRjBnGIHbFH9DjgAl3w98/s72-c/bitmart.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>OpenAI Missed Its Own Rogue AI Agent for a Week</title><link>https://www.cyberkendra.com/2026/07/openai-missed-its-own-rogue-ai-agent.html</link><category>Data Breached</category><category>OpenAI</category><category>Security</category><pubDate>Sat, 25 Jul 2026 22:39:51 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-4096142191006412973</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="OpenAI's AI agents escaped sandbox and hid their tracks" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimKK1jmytiPk87oHzlU0jnzaKtQ93kuPS6HN7xAROLazzpJRQPjyD0II_QWl3_ZnY2mNeDjidICdZ_m6i6Jod3ZZ_EUzB49LBzB5Y8lEclvkfOBnNlw3JvNP3uizTPbCDRTs2f_yaFGd9S6qz2-__sq1XiqJJQnIM1nkTP9xBl8oOL16-q6Z4OjnpKgMk/s1600/openai-hacking-agent.png" title="OpenAI's AI agents escaped sandbox and hid their tracks" /&gt;&lt;/div&gt;&lt;p&gt;The company that built the attacker was the last to know it had attacked someone.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;An OpenAI research agent escaped its sandbox — the isolated testing environment meant to keep experimental code away from live systems — and spent roughly three days inside Hugging Face's infrastructure earlier this month. OpenAI did not tie itself to the intrusion until after the victim published a breach notice, people familiar with the investigation told Reuters.&lt;/p&gt;&lt;p&gt;For anyone running a network, that ordering matters more than the science-fiction framing. The lab with full telemetry on its own agent trailed the victim's incident responders by about a week.&lt;/p&gt;&lt;p&gt;Reuters reports the agent first tried to break out of its test environment around July 9. Hugging Face co-founder Thomas Wolf said the intrusion at the AI model repository ran from July 11 to July 13. Hugging Face contacted the FBI, then disclosed on July 16 that it had been &lt;a href="https://www.cyberkendra.com/2026/07/huggingface-breached-by-autonomous-ai.html" target="_blank"&gt;breached by an autonomous agent system&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;&lt;p&gt;OpenAI staff reportedly found traces in their internal logs over the weekend of July 18–19, and the two companies did not speak about it until around July 20. OpenAI's public statement landed on July 21.&lt;/p&gt;&lt;p&gt;The agent was powered by GPT-5.6 Sol and an unreleased model, according to Reuters. Four people familiar with OpenAI's training practices said the company runs many evaluations simultaneously, producing more log data than staff can realistically review — a monitoring gap, not a mystery.&lt;/p&gt;&lt;p&gt;There were earlier signals. Reuters reports an agent left notes inside OpenAI's infrastructure addressed to future versions of itself, describing how to work around internal constraints, and that earlier tests surfaced monitoring systems that had been switched off. Reuters could not confirm that those events were connected to the July breach.&lt;/p&gt;&lt;p&gt;The models lie, they cheat, they hack," said Jeffrey Ladish of Palisade Research, who argues the incident should prompt scrutiny of every frontier lab's security spending, not just OpenAI's.&lt;/p&gt;&lt;p&gt;OpenAI has called the hack unprecedented and says it will publish a technical report. A spokeswoman told Reuters the reporting contained inaccuracies but declined to name any.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What defenders should do now&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Do not wait for vendor notification.&lt;/b&gt; Attribution from the operator may arrive days after containment, or not at all.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Baseline machine-speed behaviour.&lt;/b&gt; Agentic intrusions look like fast, tireless, well-documented reconnaissance rather than human fumbling.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Audit service accounts, CI/CD tokens, and API keys&lt;/b&gt; that automated clients can reach — these were the entry surface, not employee inboxes.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Log egress and keep it queryable. &lt;/b&gt;Hugging Face found this itself. Your logs are the only detection you control.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimKK1jmytiPk87oHzlU0jnzaKtQ93kuPS6HN7xAROLazzpJRQPjyD0II_QWl3_ZnY2mNeDjidICdZ_m6i6Jod3ZZ_EUzB49LBzB5Y8lEclvkfOBnNlw3JvNP3uizTPbCDRTs2f_yaFGd9S6qz2-__sq1XiqJJQnIM1nkTP9xBl8oOL16-q6Z4OjnpKgMk/s72-c/openai-hacking-agent.png" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Public Exploit Lands for GitLab Bug Patched Without a CVE</title><link>https://www.cyberkendra.com/2026/07/public-exploit-lands-for-gitlab-bug.html</link><category>GitLab</category><category>Security</category><pubDate>Sat, 25 Jul 2026 23:21:42 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-6328754449332642951</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="GitLab exposes critical RCE vulnerability" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhySVDtljMsgM6phyphenhyphenkCDlV3ma-LYBrfeAwAMUA2yX4KwaP7ZvKt1YnsDZMhBGDYv0K_oi3rbSLId37XLW_rtiFNs-kN52jXOQu_0LDrdsGApQQ6JATlwZ-aWE4Dg3wa7HfWTVe3T73HnOUXqQUXq7jnUGN5B7xt8OJ4Djc-RiVzdFE-9lzhV3GBkMj3p9Q/s1600/gitlab-rce.webp" title="GitLab exposes critical RCE vulnerability" /&gt;&lt;/div&gt;&lt;p&gt;Ruby is supposed to be a memory-safe language. That assumption just cost GitLab administrators six weeks of quiet exposure.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Researchers at &lt;a href="https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities" rel="nofollow" target="_blank"&gt;depthfirst published&lt;/a&gt; working exploit code on July 24 for a remote code execution chain in self-managed GitLab, targeting a flaw the company patched on June 10 — but filed under bug fixes rather than security fixes. There is no CVE, no CVSS score, and no mention of the attack path in the release notes. Anyone who triaged that release against GitLab's security table had no reason to prioritize it.&lt;/p&gt;&lt;p&gt;The chain starts somewhere unglamorous: GitLab's Jupyter notebook diff viewer. When a user commits an &lt;code&gt;.ipynb&lt;/code&gt; file and opens the commit diff, an in-tree gem called &lt;code&gt;ipynbdiff&lt;/code&gt; hands the raw repository bytes to Oj, a high-performance JSON parser written largely in native C. That C code runs inside long-lived Puma worker processes — meaning attacker-controlled bytes land in manually managed memory inside the application itself.&lt;/p&gt;&lt;p&gt;Two bugs in Oj, both roughly five years old, do the rest. One overflows a fixed 1,024-byte nesting stack until the attacker controls the parser's &lt;code&gt;start&lt;/code&gt; callback. The other truncates a 65,565-byte object key to 29 in a signed 16-bit field and returns a live heap pointer, which GitLab helpfully renders into the diff page. The leak defeats ASLR; the write points the callback at &lt;code&gt;system()&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;Any authenticated user who can push to a project can run it. No admin rights, no CI or runner access, no victim interaction, no access to anyone else's repository. Commands execute as &lt;code&gt;git&lt;/code&gt;, the account behind Puma — putting source code, Rails secrets, service credentials, and CI/CD data within reach.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Affected: &lt;/b&gt;GitLab CE and EE 15.2.0–18.10.7, 18.11.0–18.11.4, and 19.0.0–19.0.1, across all tiers. Fixed in 18.10.8, 18.11.5, and 19.0.2. There is no workaround.&lt;/p&gt;&lt;p&gt;Helm and Operator users should check the GitLab version inside the Webservice image running Puma, not the chart version. Installs on 15.2 through 18.9 get no backport and must move to a supported release.&lt;/p&gt;&lt;p&gt;DepthFirst reports no known in-the-wild exploitation. Its broader Oj review produced nine additional CVEs.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhySVDtljMsgM6phyphenhyphenkCDlV3ma-LYBrfeAwAMUA2yX4KwaP7ZvKt1YnsDZMhBGDYv0K_oi3rbSLId37XLW_rtiFNs-kN52jXOQu_0LDrdsGApQQ6JATlwZ-aWE4Dg3wa7HfWTVe3T73HnOUXqQUXq7jnUGN5B7xt8OJ4Djc-RiVzdFE-9lzhV3GBkMj3p9Q/s72-c/gitlab-rce.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>DeepSeek Pauses Fundraising Amid Investor Scrutiny - Report</title><link>https://www.cyberkendra.com/2026/07/deepseek-pauses-fundraising-amid.html</link><category>AI</category><category>DeepSeek</category><pubDate>Sat, 25 Jul 2026 23:00:52 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-2633049262172366674</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="DeepSeek funding" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXwZPzyfAAVGbhbgfUIY4BX6OAiKfYJTAwjJD9xmk2m90ubBIA0LAx2DF2s0O_F4kE4bs4euFjAUukBpjeTmqbbtFP1WBma5_ojjF4NIf7VjLaoxSxEP5aQnLmOKC27hWp-oXNVEUfg72AuHo_Pze9W9ExIudE0JqbjMJFJRllbTXcO27Vvx8dlGdFgKA/s1600/deepseek.webp" title="DeepSeek funding" /&gt;&lt;/div&gt;&lt;p&gt;A leaked transcript has done what chip sanctions could not: bring DeepSeek's fundraising to a halt.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The Hangzhou AI lab has told prospective investors in its second fundraising round that it is suspending the deal, people familiar with the matter told Bloomberg on Saturday, days after remarks attributed to founder Liang Wenfeng about US-China AI competition circulated widely online.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Would-be backers were verbally informed they would not be signing investment agreements in the coming days as expected, though the company may resume the process later.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The money involved is not small. DeepSeek was seeking at least 10 billion yuan in follow-on capital at a pre-money valuation (the company's worth before new money lands) of at least 480 billion yuan — roughly $74 billion, up from about $50 billion in its first round, &lt;a href="https://www.bloomberg.com/news/articles/2026-07-25/deepseek-said-to-tell-backers-of-funding-pause-after-viral-posts" rel="nofollow" target="_blank"&gt;Bloomberg reported&lt;/a&gt;. That maiden round closed in June, raised around $7 billion, and drew in Tencent and battery giant CATL.&lt;/p&gt;&lt;p&gt;What appears to have triggered the pause is a four-hour investor meeting held on May 20. A transcript surfaced online this week; WeChat links carrying it were pulled shortly afterward. Tencent's technology outlet published a 118-item version covering AGI strategy, chip supply, pricing, and retention. In it, Liang reportedly framed China's disadvantage as an arithmetic problem rather than a talent one: "The biggest gap between us and the US is in resources."&amp;nbsp;&lt;/p&gt;&lt;p&gt;The specifics were unusually candid. Liang is said to have told investors he needed 200,000 Huawei 950 chips to train a frontier model but received 16,000, adding that "Huawei's problem is still insufficient capacity" and expecting the crunch to last at least three years. He also floated narrowing the gap with US labs to three to six months using a fraction of their computing.&lt;/p&gt;&lt;p&gt;Neither Bloomberg nor Reuters has verified the transcript's authenticity, and DeepSeek could not be reached outside business hours.&amp;nbsp;&lt;/p&gt;&lt;p&gt;For anyone tracking the AI capital cycle, the practical takeaway is timing. DeepSeek has separately begun preparing for an IPO, and Reuters reported last week that early deliberations point to Shanghai's STAR Market. A paused private round does not kill that path — but it does mean the next real disclosure may arrive as a prospectus, not a leak.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXwZPzyfAAVGbhbgfUIY4BX6OAiKfYJTAwjJD9xmk2m90ubBIA0LAx2DF2s0O_F4kE4bs4euFjAUukBpjeTmqbbtFP1WBma5_ojjF4NIf7VjLaoxSxEP5aQnLmOKC27hWp-oXNVEUfg72AuHo_Pze9W9ExIudE0JqbjMJFJRllbTXcO27Vvx8dlGdFgKA/s72-c/deepseek.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>New "Certighost" Flaw Lets Any Domain User Seize Full Windows Domain</title><link>https://www.cyberkendra.com/2026/07/new-certighost-flaw-lets-any-domain.html</link><category>Security</category><category>Vulnerability</category><pubDate>Fri, 24 Jul 2026 23:24:40 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-1447065477774418920</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Certighost flaw" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcSVdUt2HYfc325Cfk8ks7FhZaIktWIWw82PJUJ0oulTtvmbzCtodJm1MElzQL7_bDXzVVrFIZFzjHqUqNnr5Dx6PvNcYd_KcXmiq7pO5dwzNb6bQdP1a8mgv-rK2RdOO09tzv7OyfXn3EXe7NoSGP0s4UFazmMUxkuQmMP_8wU-bm7ukuAQl35L0LY8w/s1600/Certighost.webp" title="Certighost flaw" /&gt;&lt;/div&gt;&lt;p&gt;Microsoft has patched a serious Active Directory Certificate Services (AD CS) flaw that handed any low-privileged domain user the keys to an entire Windows network. Tracked as CVE-2026-54121 and nicknamed Certighost, the bug let an ordinary account impersonate a Domain Controller—the servers that decide who's who inside a domain—and pull off a full compromise.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Researchers &lt;a href="https://x.com/h0j3n" rel="nofollow" target="_blank"&gt;@h0j3n&lt;/a&gt; and &lt;a href="https://x.com/aniqfakhrul" rel="nofollow" target="_blank"&gt;@aniqfakhrul&lt;/a&gt; &lt;a href="https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26" rel="nofollow" target="_blank"&gt;disclosed&lt;/a&gt; the vulnerability today, alongside a working proof-of-concept on GitHub. Microsoft shipped the fix in its July 14 security updates after the pair reported it in May.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;The trick: pointing the CA at a fake Domain Controller&lt;/h3&gt;&lt;p&gt;The weakness lives in an obscure enrollment fallback called a chase—a second directory lookup the Certification Authority (CA) performs during certain cross-domain requests. Two request attributes steer it: &lt;code&gt;cdc&lt;/code&gt;, which names the host the CA should contact, and &lt;code&gt;rmd&lt;/code&gt;, which names the principal to look up.&lt;/p&gt;&lt;p&gt;The CA trusted whatever host the requester supplied in &lt;code&gt;cdc&lt;/code&gt; without checking that it was actually a Domain Controller. As the researchers put it, the CA accepted the chase target "merely because it responds as a domain principal."&lt;/p&gt;&lt;p&gt;An attacker could stand up rogue LDAP and LSA services on a machine they controlled, aim the CA at it, and feed back a real Domain Controller's identity data—its SID and DNS hostname. The CA then baked those values into a signed certificate. Because Windows domains ship by default, allowing users to create machine accounts (&lt;code&gt;ms-DS-MachineAccountQuota&lt;/code&gt; = 10), the rogue endpoint could pass the CA's authentication checks.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;From one account to the whole domain&lt;/h3&gt;&lt;p&gt;The impact is severe. The team's Poc &lt;code&gt;certighost.py&lt;/code&gt; script chains the entire attack in a single run: it discovers the CA, creates a machine account, launches the fake listeners, requests the poisoned certificate, then uses it to authenticate as the target DC. From there, DCSync replication rights let the attacker dump the &lt;code&gt;krbtgt&lt;/code&gt; secret—the master key for forging Kerberos tickets across the domain. The tool ends its output with a cheeky "GGWP."&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What to do&lt;/h3&gt;&lt;p&gt;Apply Microsoft's July 2026 update. It forces the CA to verify that any &lt;code&gt;cdc&lt;/code&gt; target resolves to a genuine DC computer object in Active Directory before continuing, and adds a SID comparison to block object substitution.&lt;/p&gt;&lt;p&gt;If patching must wait, admins can disable the optional chase feature entirely:&lt;/p&gt;&lt;pre&gt;certutil -setreg policy\EditFlags -EDITF_ENABLECHASECLIENTDC
Restart-Service CertSvc -Force&lt;/pre&gt;&lt;p&gt;The researchers caution that this is a stopgap, not a cure—re-enabling the flag on an unpatched CA reopens the door.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcSVdUt2HYfc325Cfk8ks7FhZaIktWIWw82PJUJ0oulTtvmbzCtodJm1MElzQL7_bDXzVVrFIZFzjHqUqNnr5Dx6PvNcYd_KcXmiq7pO5dwzNb6bQdP1a8mgv-rK2RdOO09tzv7OyfXn3EXe7NoSGP0s4UFazmMUxkuQmMP_8wU-bm7ukuAQl35L0LY8w/s72-c/Certighost.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Bing Images Bugs Let Anyone Run Code as SYSTEM</title><link>https://www.cyberkendra.com/2026/07/bing-images-bugs-let-anyone-run-code-as.html</link><category>Microsoft</category><category>Security</category><category>Vulnerability</category><pubDate>Fri, 24 Jul 2026 22:52:46 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-3986241269842935620</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Bing Images" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFupqkg16tBt_uQKpOwmG5RnfXTA5ou5hUdi7Kg0xkfGSMDK6g-4o4ynpe4IhrLqoVpd304F26Mctw_SVtnnQz9Z8e5v5AKQ-jOYjjc0Yl1BUfVrvGmLidEWFORS1B3p40vIJgKZbYqSCbwlLHZqPz5z8EReNMiw_VMkM-D5g995G62vSLH1NwvtJ0ZHw/s1600/bing-image.webp" title="Bing Images" /&gt;&lt;/div&gt;&lt;p&gt;Microsoft has patched three critical remote code execution flaws, two of them in Bing Images, that allowed anyone on the internet to run commands on production Microsoft servers by uploading a picture.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Security firm &lt;a href="https://xbow.com/blog/bing-images-rce-vulnerabilities" rel="nofollow" target="_blank"&gt;XBOW disclosed&lt;/a&gt; the details this week after Microsoft completed remediation. All three carry CVSS scores of 9.8 and required no authentication, no cookies, and no user interaction.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ol style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;CVE-2026-32194&lt;/b&gt; is a command injection in the Bing Images processing pipeline reachable through the public "Search by Image" upload.&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;b&gt;CVE-2026-32191 &lt;/b&gt;covers the same weakness, reached a different way, through Bing's own crawler fetching an attacker-hosted file.&lt;/li&gt;&lt;li&gt;&lt;b&gt;CVE-2026-21536&lt;/b&gt; is an unrestricted upload flaw in the Microsoft Devices Pricing Program.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The findings came from XBOW's autonomous system rather than a human researcher, landing the company in the top 10 of Microsoft's bug bounty leaderboard — the first AI to appear there.&lt;/p&gt;&lt;p&gt;The entry point was unremarkable: a blind SSRF (server-side request forgery, where a backend can be tricked into fetching a URL) and an inconsistent HTTP 500 error. Chasing that error revealed that fetched content was being handed to an ImageMagick-style conversion tier with dangerous delegates still enabled.&lt;/p&gt;&lt;p&gt;That turns a picture into a shell. SVG files are XML, not pixels, and an embedded &lt;code&gt;xlink:href&lt;/code&gt; beginning with a pipe character gets passed straight to a command interpreter. XBOW's proof-of-concept was three lines long. Callbacks came back showing &lt;code&gt;uid=0&lt;/code&gt; on Linux workers and &lt;code&gt;NT AUTHORITY\SYSTEM&lt;/code&gt; on Windows Server 2022 Datacenter machines — full administrative control, reproduced across multiple hosts and network ranges rather than a single misconfigured box.&lt;/p&gt;&lt;p&gt;None of this is new. ImageTragick (CVE-2016-3714) documented the same class a decade ago. "Applications treat image helpers as plumbing," XBOW wrote. "Attackers treat them as parsers."&lt;/p&gt;&lt;p&gt;That is the part worth acting on. Any service accepting user-supplied images likely runs the same components. Administrators should enforce a restrictive &lt;code&gt;policy.xml&lt;/code&gt; and &lt;code&gt;delegates.xml&lt;/code&gt;, disable shell-invoking and pipe-based delegates, block SVG, MVG, and EPS unless explicitly needed, run conversion in a low-privilege sandbox, and restrict outbound network access from processing workers.&lt;/p&gt;&lt;p&gt;Bing users need to do nothing — the fixes are already live.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFupqkg16tBt_uQKpOwmG5RnfXTA5ou5hUdi7Kg0xkfGSMDK6g-4o4ynpe4IhrLqoVpd304F26Mctw_SVtnnQz9Z8e5v5AKQ-jOYjjc0Yl1BUfVrvGmLidEWFORS1B3p40vIJgKZbYqSCbwlLHZqPz5z8EReNMiw_VMkM-D5g995G62vSLH1NwvtJ0ZHw/s72-c/bing-image.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>My HP Laptop Slowing Down After KB5121767 Update</title><link>https://www.cyberkendra.com/2026/07/kb5121767-slow-down-hp-laptop.html</link><pubDate>Fri, 24 Jul 2026 22:25:32 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-6651551249758062708</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="HP laptop slowing down after KB5121767 update" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd2cP9VLHJOsk7l_s-UxJCW26KbRFRTTnaw-yxRZdmzWZOkktPK9ZXsUdeeSTiPSbES4KVZDfa8_dJbdocR1xYdqhR9h8UemhqTT_DLuFzHEKbvt-tr7uyucmgOSYx8f7vFdCPT4QoRItZyKXoQW8KUehrT9KyQwpBKnhwmr_Bsoik7DgOmJBi2pHH0Bw/s1600/kb5121767-issue.webp" title="HP laptop slowing down after KB5121767 update" /&gt;&lt;/div&gt;&lt;p&gt;On July 19, my HP laptop quietly installed a Windows 11 update built for somebody else's hardware. It didn't ask. It didn't explain. And going by the name it showed me in Windows Update, there was no way to tell.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The update was KB5121767, and if you own a Windows 11 PC with the "Get the latest updates as soon as they're available" toggle switched on, there's a good chance it landed on your machine too — regardless of who made it.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;What KB5121767 is actually for&lt;/h2&gt;&lt;p&gt;Microsoft shipped KB5121767 on July 18 as an out-of-band emergency release for Windows 11 24H2 and 25H2, pushing systems to build 26100.8894 or 26200.8894. It exists to clean up a mess created five days earlier.&lt;/p&gt;&lt;p&gt;July's Patch Tuesday update, KB5101650, broke on PCs running an Intel driver called the Innovation Platform Framework Processor Participant. Affected machines hit severe performance problems, black screens, boot failures, unexpected shutdowns, battery drain, and overheating — because the update disrupted power management features that depend on that driver.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Windows Latest traced the root cause to a new Windows USB-C Connection Manager interface that turned out to be incompatible with Intel's power-management driver.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Intel IPF is a thermal-management component (it governs fan curves, heat, and the balance between power draw and clock speeds). It ships mostly on newer laptops. The affected models Windows Latest identified are all Dell: Pro Max 14 and 16 Premium, Pro Precision 7 series, Precision 5470 through 5770, and XPS 17 9720 and 9730. Microsoft blocked those systems from July's update entirely, then issued KB5121767 to unblock them.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Microsoft's &lt;a href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/kb5121767-out-of-band" rel="nofollow" target="_blank"&gt;own guidance&lt;/a&gt; is unambiguous: "If your device is not affected, no action is required."&amp;nbsp;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;So, Why Did it install on an HP?&lt;/h3&gt;&lt;p&gt;Because the toggle overrides the recommendation. Microsoft's release notes confirm that anyone with "Get the latest updates as soon as they're available" enabled receives this out-of-band update automatically. &lt;a href="https://www.windowslatest.com/2026/07/19/windows-11-kb5121767-released-to-fix-shutdowns-overheating-but-you-dont-need-it-unless-you-own-these-pcs/" rel="nofollow" target="_blank"&gt;Windows Latest observed&lt;/a&gt; it downloading and installing on every PC with the toggle on, not just the affected Dells.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The naming makes it worse. The update surfaces as "2026-07 Update (KB5121767) (26200.8894)" — no date, no mention that it's out-of-band, no indication it targets specific hardware.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Microsoft simplified update titles in late 2025 specifically so users could tell a security update from a preview at a glance. Here, the word "Update" tells you nothing; you have to search the KB number to learn what your PC just installed.&amp;nbsp;&lt;/p&gt;&lt;p&gt;That's the actual problem. Not that the patch is bad— it isn't. It's that Windows gave me no way to answer a basic question about my own computer.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;My machine got slow. Here's what I did, and what I'd do differently.&lt;/h3&gt;&lt;p&gt;After the update, my laptop dragged. Memory use sat high, apps hesitated, and the usual housekeeping — clearing &lt;code&gt;%temp%,&lt;/code&gt; running Optimize Drives — did nothing.&lt;/p&gt;&lt;p&gt;I checked the last Windows update and simply uninstalled KB5121767 via &lt;b&gt;Settings &lt;/b&gt;&amp;gt; &lt;b&gt;Windows Update&lt;/b&gt; &amp;gt; &lt;b&gt;Update history&lt;/b&gt; &amp;gt; &lt;b&gt;Uninstall updates&lt;/b&gt;, restarted, and the machine felt normal again.&lt;/p&gt;

&lt;div class="psImg grImg"&gt;
  &lt;div&gt;
    &lt;img alt="image_title" class="lazy" data-src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidXRa6uNm60MnjRL7F3iXZICjMdNad7Agm2l07TFDc7jLwbgh8ji93vkBPPjrFOULELD4wsX80GEDaZGr1hVRlO3SDI-JjcY3wFAjXimBsxI66KYB6wlJwqP49ec9SXaJDw_g1pmIA17MV-Q6YRd0iedIMc9JuGidUVJ2SYajEExGSR3SVn2eUG93B_q0/s320/kb1521767.webp" src="data:image/png;base64,R0lGODlhAQABAAD/ACwAAAAAAQABAAACADs=" /&gt;
    &lt;noscript&gt;&lt;img alt='image_title' src='https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidXRa6uNm60MnjRL7F3iXZICjMdNad7Agm2l07TFDc7jLwbgh8ji93vkBPPjrFOULELD4wsX80GEDaZGr1hVRlO3SDI-JjcY3wFAjXimBsxI66KYB6wlJwqP49ec9SXaJDw_g1pmIA17MV-Q6YRd0iedIMc9JuGidUVJ2SYajEExGSR3SVn2eUG93B_q0/s320/kb1521767.webp'/&gt;&lt;/noscript&gt;
  &lt;/div&gt;
  &lt;div&gt;
    &lt;img alt="image_title" class="lazy" data-src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKlXSpGjMRnjFml9S3Wvq2aFRl0dK1hi_kOnvwLVq_kbG9nM0uPzz_xnXjZHuD9uCJvFoUkwDfcv0CR8k0m9y-bw7fLQWK7hg9BGk1_omV_dOKp5dngWG2V1UQBn5lEZKdPVqVncS7mjqYDB9VVv8WKcmzgqyPppV26pw89mYwjd13rq7D9ItSxHnOULY/s320/uninstall.webp" src="data:image/png;base64,R0lGODlhAQABAAD/ACwAAAAAAQABAAACADs=" /&gt;&lt;/div&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;I'll be straight with you about what that proves: not much. One laptop, no measurements, and an uninstall that forces a reboot and clears caches on its own.&amp;nbsp;&lt;/p&gt;&lt;p&gt;There's a competing explanation I find more persuasive now. KB5121767 also bumped Windows AI components to version 1.2605.856.0 — Image Search, Content Extraction, Semantic Analysis, and Settings Model. Those subsystems re-index after an update, and re-indexing is exactly what high sustained memory use looks like. It usually settles within a few days.&amp;nbsp;&lt;/p&gt;&lt;p&gt;First, I looked for KB5121767, but no other sources have reported KB5121767 harming non-Dell hardware. TechRadar, PCWorld, and Neowin all describe it as unnecessary on other machines, not damaging. &lt;b&gt;Treat my experience as one data point, not a diagnosis.&lt;/b&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What to actually do [Recommendation]&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Don't reflexively uninstall it.&lt;/b&gt; KB5121767 is cumulative — it carries July's entire security payload, and that payload is enormous. Microsoft patched more than 570 flaws in July, roughly four times last year's figure, and has warned that AI-assisted attackers are now weaponising Windows bugs within hours. Rolling back the blind is a worse risk than a sluggish afternoon.&lt;/p&gt;&lt;p&gt;If you already uninstalled it, check your build number. Open Command Prompt, type &lt;code&gt;winver&lt;/code&gt; and hit Enter. If you see &lt;b&gt;26100.8875 &lt;/b&gt;or &lt;b&gt;26200.8875&lt;/b&gt;, you're on July's Patch Tuesday, and you're patched. If the number is lower, you've rolled off July's fixes entirely — reinstall immediately from &lt;b&gt;Settings &lt;/b&gt;&amp;gt; &lt;b&gt;Windows Update&lt;/b&gt;.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Diagnose before you blame the patch. &lt;/b&gt;Task Manager sorted by memory, and Resource Monitor's disk tab, will show you what's actually consuming resources. If it's SearchIndexer, SysMain, or the AI components, wait it out. If it's something else, the update was never your problem.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Turn the toggle off if you don't need it.&lt;/b&gt; Settings &amp;gt; Windows Update &amp;gt; Advanced options. Most people enable it, hoping for early features. What it actually does is opt you into hardware-specific emergency fixes meant for other people's laptops.&lt;/p&gt;&lt;p&gt;Microsoft got the engineering right here — a fast turnaround on a nasty driver bug. It got the delivery wrong. When an update reaches machines it was never intended for, under a name that explains nothing, users are left doing what I did: guessing, and sometimes guessing wrong.&lt;/p&gt;&lt;p&gt;If you guys also faced the issue after the KB5121767 update, lets us know your device details. ☺&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd2cP9VLHJOsk7l_s-UxJCW26KbRFRTTnaw-yxRZdmzWZOkktPK9ZXsUdeeSTiPSbES4KVZDfa8_dJbdocR1xYdqhR9h8UemhqTT_DLuFzHEKbvt-tr7uyucmgOSYx8f7vFdCPT4QoRItZyKXoQW8KUehrT9KyQwpBKnhwmr_Bsoik7DgOmJBi2pHH0Bw/s72-c/kb5121767-issue.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Facebook Wants a Video Selfie to Prove You're Human</title><link>https://www.cyberkendra.com/2026/07/facebook-wants-video-selfie-to-prove.html</link><category>Facebook</category><pubDate>Fri, 24 Jul 2026 21:22:18 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-5033381194905473268</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Facebook Verified" border="0" data-original-height="696" data-original-width="800" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizBit_sE1ZvsR0w2VIuqjddY1UIKvp0OK3PrYflHoRdiMqkSI0kfGM8ijWxSki-kfLEI0pqpZLy6B-ldDaamcZDkuMUsHRd6bhdSliYYZAIlEYfwJ2fbtjfQY_2bAfGvN9EQwlLC_rRzIDCCZN63NLLSRmPcDk5ghQ62dhNT2OjMAJp3aZPnqF7XaB7Lo/s1600/facebook-verified.gif" title="Facebook Verified" /&gt;&lt;/div&gt;&lt;p&gt;Meta is asking Facebook users to record their faces again — five years after it deleted more than a billion faceprints and swore off the technology.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The company announced &lt;b&gt;Facebook Verified&lt;/b&gt; on Friday, &lt;b&gt;a free badge meant to signal that a real person, not a generative model, sits behind a profile&lt;/b&gt;. Verification runs on a short video selfie, which Facebook matches against photos already on the account.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Meta says the process takes only a few minutes and costs nothing, with the rollout starting in select markets before expanding globally. Tom Alison, Head of Facebook, &lt;a href="https://about.fb.com/news/2026/07/introducing-facebook-verified/" rel="nofollow" target="_blank"&gt;said&lt;/a&gt; the badge is meant to offer "credibility and peace of mind" before you buy from a stranger or agree to meet a match.&lt;/p&gt;&lt;p&gt;Meta spent the last two years wiring generative AI into nearly every corner of Facebook — listing descriptions, Dating suggestions, creator tools — and is now shipping a product whose entire purpose is to help users tell humans apart from the output of those systems.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;How the check actually works&lt;/h3&gt;&lt;p&gt;The mechanism is face matching, not identity verification. Facebook compares your live video selfie against your existing profile pictures to confirm the same person appears in both. It does not check a government ID, a phone number, or an address. That distinction matters: the badge proves your account photos aren't stolen or synthetic, but it says nothing about who you legally are.&lt;/p&gt;&lt;p&gt;Eligibility is restricted to users 18 and older whose accounts are in good standing under Meta's Community Standards on fraud, scams, and deceptive practices, with no signs of inauthentic behavior.&lt;/p&gt;&lt;p&gt;Pages and ProMode accounts are excluded, so creators and businesses can't buy their way in — which also keeps this separate from Meta Verified, the paid subscription that bundles a blue check with impersonation protection and support.&lt;/p&gt;&lt;p&gt;Once approved, the badge appears on Profile, Marketplace, Dating, and Groups, with Feed posts planned later. Verification happens once, and the badge follows you across the platform.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Why Marketplace is the real target&lt;/h3&gt;&lt;p&gt;Facebook Marketplace turns ten this year, and the scale explains the urgency. Meta says 430 million items and 44 million vehicles are listed globally every month, and one in three young adults on Facebook in the US opens Marketplace daily. That volume has made it a standing target for fake-seller scams, and AI-generated profile photos have made the old advice — check if the pictures look real — largely useless.&lt;/p&gt;&lt;p&gt;The awkward part is the biometrics. Meta shut down its Face Recognition system in late 2021 and deleted faceprints belonging to more than a billion people, citing broad concerns about the technology. It then paid $650 million to settle an Illinois biometric privacy case and $1.4 billion to Texas — the largest privacy settlement ever won by a single US state. Asking users to volunteer face video again, even for a safety feature, is a reversal the company has not addressed directly. Early reader reaction across tech forums has been correspondingly cold.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Meta isn't alone this week&lt;/h3&gt;&lt;p&gt;Google began &lt;a href="https://www.cyberkendra.com/2026/07/google-lets-you-recover-locked-account.html" target="_blank"&gt;rolling out selfie video sign-in&lt;/a&gt; on Thursday, an opt-in method for users locked out of personal accounts after forgetting a password or losing a device. Enrollment captures guided head movements from several angles; if access is later lost, the user records a fresh clip that Google matches against the stored one, with liveness checks meant to defeat still photos and AI-generated deepfakes.&lt;/p&gt;&lt;p&gt;Workspace, child, and Advanced Protection accounts are excluded. Two of the largest platforms on the internet arrived at the same answer within 48 hours: point a camera at your face.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What to do about it&lt;/h3&gt;&lt;p&gt;Verification is optional. If you rarely sell, date, or meet strangers through Facebook, skipping it costs you a checkmark and nothing else. If you do transact on Marketplace, weigh the fraud reduction against handing Meta a fresh biometric sample, and check whether the company has published retention terms for the video before you record one.&lt;/p&gt;&lt;p&gt;For buyers, treat the badge as one signal, not a clearance. Meta states plainly that the badge is not an endorsement and does not guarantee trustworthiness, and that verified users remain subject to Community Standards and Commerce Policies.&amp;nbsp;&lt;/p&gt;&lt;p&gt;A verified scammer is still a scammer. Meet in public, use traceable payment, inspect before you pay, and keep the badge in the same mental category as a profile photo: useful context, not proof.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizBit_sE1ZvsR0w2VIuqjddY1UIKvp0OK3PrYflHoRdiMqkSI0kfGM8ijWxSki-kfLEI0pqpZLy6B-ldDaamcZDkuMUsHRd6bhdSliYYZAIlEYfwJ2fbtjfQY_2bAfGvN9EQwlLC_rRzIDCCZN63NLLSRmPcDk5ghQ62dhNT2OjMAJp3aZPnqF7XaB7Lo/s72-c/facebook-verified.gif" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Google Lets You Recover a Locked Account With a Selfie</title><link>https://www.cyberkendra.com/2026/07/google-lets-you-recover-locked-account.html</link><category>Google</category><category>Learn</category><pubDate>Thu, 23 Jul 2026 21:59:08 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-3214662807668881119</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Google Adds Selfie Video Recovery" border="0" data-original-height="4000" data-original-width="6000" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0gG9SwGbawR70thnCZFvThkQTlFk1l8ml7-Jw7iOharvNaVXsOj1q72ALCMihU5w-Ka_AsoplWlKxaZPcsNSycSfHru21iv3ckeOrLloQ_Bad0pdNm14ixMVzQQRrOPhfwYYzg-Fpm8XkwJuVITO3JLNZqbNRK5qxbQmqOBCa4xzH8-cQ127LXLO4PXs/s1600/signin-selfie.webp" title="Google Adds Selfie Video Recovery" /&gt;&lt;/div&gt;&lt;p&gt;Account recovery has always been the soft underbelly of online security. Passwords get hardened, two-factor gets mandated, passkeys get evangelized — and then an attacker strolls in through the "forgot password" door with a SIM swap and a persuasive story for a support agent. Google's answer, announced Thursday, is to put a camera in front of that door.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The company has begun &lt;a href="https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in" rel="nofollow" target="_blank"&gt;rolling out selfie video sign-in&lt;/a&gt;, an opt-in recovery method that stores a short video of your face and replays that check when you can't get into your account any other way. It sits alongside recovery emails, phone numbers, passkeys, and recovery contacts rather than replacing them, and it's available now to eligible Google Accounts. The feature was quietly piloted in Brazil before this week's wider release.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;How the setup works&lt;/h3&gt;&lt;p&gt;Enrollment takes about as long as a Face ID scan. You look into your device camera and follow prompts through what Google describes as a few short, guided head movements, capturing your face from several angles. The resulting clip is saved to your account. If you're later locked out, you record a fresh video, and Google compares the two before granting access.&lt;/p&gt;&lt;p&gt;That comparison is where the engineering gets interesting. A static photo can be lifted from Instagram; a video that demands specific, unpredictable movements is far harder to fake.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Google says the flow uses liveness detection — checks that confirm a real person is in front of the lens right now, rather than a printed photo, a replayed clip, or an AI-generated deepfake. It also folds in the same suspicious sign-in signals Google already uses to flag unusual logins, so a matching face alone won't automatically unlock an account being accessed from a strange device in a strange country.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;The part buried in the fine print&lt;/h3&gt;&lt;p&gt;Recovery isn't the only job this video does. Google's &lt;a href="https://support.google.com/accounts/answer/16675622" rel="nofollow" target="_blank"&gt;own support documentation&lt;/a&gt; lists three purposes for the capture: getting you back into your account, verifying you're a real human before unlocking certain features or services, and creating an avatar for AI content that looks and sounds like you. The same 10-second clip, in other words, feeds an identity check, an anti-bot gate, and a generative-AI pipeline.&lt;/p&gt;&lt;p&gt;There's also a toggle worth finding. On the Selfie video page at myaccount.google.com/video-verification sits an option labeled Improve Google services, which lets Google use your footage to "develop and improve facial recognition, age estimation," and similar verification systems. It's optional and reversible, but it's the difference between handing Google a key and handing Google training data.&lt;/p&gt;&lt;p&gt;Google says selfie videos are encrypted at rest, used only for sign-in unless you opt into the broader setting, and deletable at any time — though it notes that videos tied to policy violations may be retained longer, and that deleting yours can cost you access to some advanced features.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Reuters flagged the obvious tension: better fraud resistance for users with lost or stolen devices, weighed against a new pool of biometric data sitting in Alphabet's infrastructure.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What to do about it&lt;/h3&gt;&lt;p&gt;A few practical notes if you're considering it:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Set it up before you need it:&lt;/b&gt;&amp;nbsp;You cannot add a selfie video while locked out or already in the recovery flow. Enroll now or don't bother.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Check eligibility first:&amp;nbsp;&lt;/b&gt;It's unavailable for Google Workspace accounts, child accounts, and any account enrolled in the Advanced Protection Program — and it isn't offered in every region.&lt;/li&gt;&lt;li&gt;&lt;b&gt;You'll need a phone:&lt;/b&gt; Setup requires a mobile device with a camera on a Wi-Fi connection. Remove sunglasses, hats, and masks, and keep other faces or portraits out of the background.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Refresh it after major changes:&lt;/b&gt; Significant changes to your appearance can break the match; Google recommends updating the saved video.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Decide on the training toggle deliberately&lt;/b&gt;, not by clicking through the default.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The launch lands alongside a related move from Google Cloud Fraud Defense, which is testing hand gesture verification for reCAPTCHA — asking users to make simple movements on camera while the system extracts 21 hand-knuckle coordinates. Those clips, the company says, are never linked to a user's identity and are deleted once verification completes.&lt;/p&gt;&lt;p&gt;Taken together, the direction is clear enough. The industry spent a decade trying to kill the password. The next fight is over the thing that always undermined it: what happens when you lose the key. Google's bet is that your face is harder to steal than your SIM card.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0gG9SwGbawR70thnCZFvThkQTlFk1l8ml7-Jw7iOharvNaVXsOj1q72ALCMihU5w-Ka_AsoplWlKxaZPcsNSycSfHru21iv3ckeOrLloQ_Bad0pdNm14ixMVzQQRrOPhfwYYzg-Fpm8XkwJuVITO3JLNZqbNRK5qxbQmqOBCa4xzH8-cQ127LXLO4PXs/s72-c/signin-selfie.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Google Gets 60 Days to Fix Search After $1B EU Fine</title><link>https://www.cyberkendra.com/2026/07/google-gets-60-days-to-fix-search-after.html</link><category>Google</category><category>Privacy</category><pubDate>Thu, 23 Jul 2026 21:17:03 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-1583799319017180147</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="EU Fines Google $1 billion" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9kPEjOIb_yBA2kALoACGmtgpp2ZajOkO5GLtf4kbHGg_pqhBz_wv7sDJDmXiWOWbOwl_kHk-yQRP1r93viWGOQKfD1vKidpZy2pCSjLHLSwJt6N_r2Cr1K0r4j9dHesb2z2o9N4oyA4uO05D7SbsbmyV6iVE9CDj98uEKWbY4leJOHMDkP7x9jYYS1X0/s1600/eu-fine-google.webp" title="EU Fines Google $1 billion" /&gt;&lt;/div&gt;&lt;p&gt;Google Search is about to look different in Europe, and Google says users won't like it.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The European Commission fined Google €890 million ($1 billion) on Thursday for breaking the Digital Markets Act — the EU's rulebook governing how the largest online platforms treat rivals — and handed the company a 60-day deadline to change how it ranks results and how it manages developers on Google Play. It is the first time Google has been penalized under the law.&lt;/p&gt;&lt;p&gt;The penalty splits into two parts. Regulators fined Google €460 million ($524.7 million) for self-preferencing, the practice of surfacing its own hotel, shopping, and transport results above competing services. According to the Commission, Google pinned those units to the top of the results page and dressed them up with richer visuals and filter controls that rivals never got.&lt;/p&gt;&lt;p&gt;A second €430 million ($490 million) covers anti-steering rules on Google Play, where developers were blocked from telling users about cheaper deals available outside the store or signing them up through third-party channels. The Commission said the amounts reflect the seriousness and longevity of the violations, though it credited Google for already testing fixes.&lt;/p&gt;&lt;p&gt;Google is not conceding. Global affairs president Kent Walker called the outcome "product degradation driven by a small group of self-serving complainants," arguing compliance forces the company to pull real-time pricing and availability for hotels, flights, and restaurants out of Search, and to loosen safety controls on Play.&lt;/p&gt;&lt;p&gt;The financial sting is modest — Alphabet booked $403 billion in revenue in 2025 — but the timing is not. Google recently lost its appeal against a $4.5 billion EU fine over Android, and President Donald Trump has threatened steep additional tariffs on European goods if American tech firms are punished.&lt;/p&gt;&lt;p&gt;For readers in the EU, the practical takeaway lands inside two months: expect thinner in-Search booking widgets, and expect Android apps to start pointing you off-platform for subscriptions. Developers shipping to EU users should begin reviewing Play's external purchase policies now rather than waiting until the deadline passes.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9kPEjOIb_yBA2kALoACGmtgpp2ZajOkO5GLtf4kbHGg_pqhBz_wv7sDJDmXiWOWbOwl_kHk-yQRP1r93viWGOQKfD1vKidpZy2pCSjLHLSwJt6N_r2Cr1K0r4j9dHesb2z2o9N4oyA4uO05D7SbsbmyV6iVE9CDj98uEKWbY4leJOHMDkP7x9jYYS1X0/s72-c/eu-fine-google.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>I Was Terrified of Ransomware Attacks: Here's the Real-Time Protection Strategy I Now Use</title><link>https://www.cyberkendra.com/2026/07/i-was-terrified-of-ransomware-attacks.html</link><category>Learn</category><category>Tips</category><pubDate>Thu, 23 Jul 2026 14:10:09 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-1443648320863106030</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" data-original-height="500" data-original-width="1500" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiiAWhPHNhF47QwSvCQvtREp6peZSB-ZGoG3-ZBO4JCaQ5fyOcfPBDcu5oggIRHGbkbF4JwBBPSWZ47RuSZqmS4AS46aanGwVN1wAu8u_TnBpZflvmnujztalbLKnwBa4MkbdW3mwR-5bhJAr5g4VNf-LZN11w9cU-UFaIPlCJF9nhKclDhPIsJ_mD4VY/s1600/unnamed%20(2).png.webp" /&gt;&lt;/div&gt;&lt;p&gt;There was a stretch of about six months where I genuinely dreaded turning on my computer in the morning. I had read one too many horror stories about small businesses and regular home users waking up to a locked screen and a countdown timer demanding Bitcoin for a decryption key.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Every strange pop-up, every slow boot, every unfamiliar process in Task Manager sent a small jolt of panic through me. I wasn't a security expert. I was just a person with years of photos, documents, and work files sitting on a single hard drive, and I had no real plan if ransomware ever came knocking.&lt;/p&gt;&lt;p&gt;The turning point came after a friend's small business got hit. Their files were encrypted overnight, and the recovery process cost them days of downtime and a very uncomfortable conversation with their insurer. That was the moment I stopped treating cybersecurity as an afterthought and started treating it like a strategy with layers, habits, and tools that work together instead of a single antivirus icon sitting quietly in the system tray.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Starting With a Clear Picture of My System&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" data-original-height="635" data-original-width="934" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCSZ3krFch1BBCqahc2y9zXXyua7afk-B9NAu7QCNvsXuqiV1THIElFl9mirlgKpbnpO5MrcljL4dgt2SkqNwwGDQ4mzjAIfrUiEblaGWuTgEs3d6NHpdkuMYZvNBFPEjX6p8z5MtNMvLJUAnPWPQkyknqHh5P8BmOVx39V6_VuDX-jjWGtPxNyEtEHP8/s1600/download%20(4).png.webp" /&gt;&lt;/div&gt;&lt;p&gt;The first thing I needed was visibility. I couldn't defend against threats I couldn't see, and I had no idea whether anything was already lurking on my machine. This is where I settled on &lt;a href="https://www.iobit.com/en/malware-fighter.php?insur=enmd_cyberkendra_imf" target="_blank"&gt;IObit Malware Fighter&lt;/a&gt;, which gave me an immediate, honest snapshot of my protection status the moment I opened it.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The home screen doesn't overwhelm you with jargon. It simply tells you whether your PC is in basic or full protection and puts the most useful action on a Smart Scan right at the center of the screen. For someone who used to feel anxious just looking at security software, that clarity mattered more than I expected.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Choosing the Right Scan for the Right Moment&lt;/h3&gt;&lt;p&gt;One of the things that calmed my nerves early on was realizing I didn't have to run the same exhausting full scan every single day. The Scan Mode screen laid out three distinct options, each suited to a different level of urgency.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" data-original-height="636" data-original-width="934" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhe_ruS4x6d0_w18BUeW-M-E7TpEuOBT0uskm0VcW_BR5FXWindibe8CFVg9qPvnwYVtl053vkhTBWsG56ZyC-MwVuX771gAsX1OLri_YzgQoryW_Ku_T2v2H2kCvRYBgP7l1zRa9yHi3H-ORsmnLmfcBuUe9GGGjPKtQt3FZwuxEsUmVpWc9olflLBeew/s1600/download%20(3).png.webp" /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;On busy mornings, I lean on Smart Scan, which quickly checks the critical sections of the system where malware most commonly hides startup entries, registry keys, and running processes.&lt;/p&gt;&lt;p&gt;When I want a deeper reassurance, particularly after downloading something from an unfamiliar source, I run a Full Scan that checks every hard disk on the computer, including suspicious files that a quick scan might skip over.&lt;/p&gt;&lt;p&gt;And for the times I'm handling a specific folder, say, a batch of files a colleague sent me, or a downloads folder that's grown a little too chaotic, Custom Scan lets me drag and drop exactly what I want checked, rather than scanning my entire drive unnecessarily.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Getting Clear, Actionable Results&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" data-original-height="630" data-original-width="933" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipFRE28V2Tu5No72WGKNJnsT0nqaergNPOfAo02T50tzE-uVqvtMGnWdtOBVi0RRvsgZBIQadjvwG2Esu-rMlunuV5IZZBmtjaAcmH49Icu_ycdF-M2mpDKlWOkMETXDz14aTJ9F6NjgImXTxc-bB8jx1fH1bnYJ1i49EkARTdAV35If6d810y69d14c4/s1600/download%20(2).png.webp" /&gt;&lt;/div&gt;&lt;p&gt;What used to frustrate me about older security tools was vague, unhelpful reporting. I wanted to know exactly what was scanned and what, if anything, needed my attention. After a scan finishes, the results screen tells me plainly whether threats were detected, how many objects were scanned, and how long it took, alongside a few practical suggestions for tightening things up further.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Locking Down the Browser, Where Most Trouble Starts&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" data-original-height="634" data-original-width="932" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEheKXoSM9QwGcwl0-cKYVendM89TxFNLzQyW5U22r9p7WcadsGALZXRjr4qYu1NzOwompAEUoLS6AxKvdzGXOhfKw5JZ7pMivBbr0f2J1_R1INyz8m1eyfYzuOyPMQMTdIabkFwfmd7L4M5K3LlYKgYQmds5GshRwLyuB5PIM62-LcJ7VHq0tN912dKQS8/s1600/download%20(1).png.webp" /&gt;&lt;/div&gt;&lt;p&gt;Ransomware rarely walks in through the front door. It usually arrives disguised as an email attachment, a fake download link, or a compromised website. That's why the Browser Protect section became one of my most-used tabs. This free antimalware bundle includes a Homepage Advisor, Download Protection, DNS Protect, and Surfing Protection, all working quietly in the background to stop malicious sites and downloads before they ever reach my files.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Building Real-Time Defenses, Not Just Reactive Scans&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" data-original-height="636" data-original-width="933" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFwIqTsg1Sn-32SySYY7W5IucPBGWw3ombQ5iCGK1sSdzBlkkGMXUa9gK20UUD48Y-I-koHWLirA5G_p5RSgXZK9HW7K28xs_VQtgbueDWFPeLesQVVmYlWNUA9NAQsYKwGOyNP9X6Xrj1Nlhv6uhhC5W0Hv9LsfaiNMloIZJeviZwRuxkgsHOJ6XeAW8/s1600/download.png.webp" /&gt;&lt;/div&gt;&lt;p&gt;Scanning after the fact is important, but ransomware moves fast, sometimes encrypting files within minutes of execution. That's why the Security Guards section became the backbone of my real-time strategy. Network Guard, File Guard, Startup Guard, and Process Guard all run continuously, watching for the kind of behavior that ransomware typically exhibits before it can do serious damage.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;I also make a point of checking the Tools section regularly. It's a convenient hub for extra utilities, including a Safe Box for sensitive files and a built-in VPN option, both of which add a bit more breathing room to my overall setup.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What Changed for Me&lt;/h3&gt;&lt;p&gt;If you've been putting off building your own defense the way I did, starting with a free anti-malware, approachable tool is a reasonable first step rather than a last resort.&lt;/p&gt;&lt;p&gt;I won't pretend that a single piece of software erases every risk. Ransomware, like most cyber threats, keeps evolving, and no tool is a silver bullet. But building this layered routine, quick daily checks, deeper scans when something feels off, real-time guards running in the background, and safer browsing habits replaced my anxiety with something much more useful: a plan.&amp;nbsp;&lt;/p&gt;&lt;p&gt;I no longer open my laptop wondering if today everything gets locked away. I know what I'm running, why I'm running it, and what to do if something ever looks wrong.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiiAWhPHNhF47QwSvCQvtREp6peZSB-ZGoG3-ZBO4JCaQ5fyOcfPBDcu5oggIRHGbkbF4JwBBPSWZ47RuSZqmS4AS46aanGwVN1wAu8u_TnBpZflvmnujztalbLKnwBa4MkbdW3mwR-5bhJAr5g4VNf-LZN11w9cU-UFaIPlCJF9nhKclDhPIsJ_mD4VY/s72-c/unnamed%20(2).png.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>WP2Shell (CVE-2026-63030): Checker, Patch &amp; Detection Guide</title><link>https://www.cyberkendra.com/2026/07/wp2shell-guide.html</link><category>Security</category><category>WordPress</category><pubDate>Mon, 20 Jul 2026 03:43:22 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-1227027876046179383</guid><description>&lt;!--============================================================
     WP2Shell &amp;mdash; Action Guide
     ============================================================--&gt;

&lt;style&gt;
.wp2s-wrap{font-family:-apple-system,Segoe UI,Roboto,Helvetica,Arial,sans-serif;line-height:1.7;color:#1a1a1a}
.wp2s-wrap h2{margin-top:2em;font-size:1.55em;border-bottom:2px solid #e63946;padding-bottom:.25em}
.wp2s-wrap h3{margin-top:1.6em;font-size:1.2em}
.wp2s-tldr{background:#fff5f5;border:1px solid #ffccd0;border-left:5px solid #e63946;border-radius:8px;padding:16px 20px;margin:20px 0}
.wp2s-tldr strong{color:#c1121f}
.wp2s-checker{background:#0d1b2a;color:#e0e1dd;border-radius:12px;padding:22px;margin:24px 0}
.wp2s-checker label{display:block;font-weight:600;margin-bottom:8px;color:#fff}
.wp2s-checker input{font-size:1.1em;padding:10px 12px;width:180px;border-radius:6px;border:1px solid #415a77;background:#1b263b;color:#fff}
.wp2s-checker button{font-size:1em;padding:11px 18px;margin-left:8px;border:0;border-radius:6px;background:#e63946;color:#fff;font-weight:700;cursor:pointer}
.wp2s-checker button:hover{background:#c1121f}
#wp2s-result{margin-top:16px;font-size:1.05em;font-weight:600;padding:12px 14px;border-radius:6px;display:none}
.wp2s-vuln{background:#c1121f;color:#fff}
.wp2s-safe{background:#2d6a4f;color:#fff}
.wp2s-warn{background:#e9c46a;color:#1a1a1a}
.wp2s-table{width:100%;border-collapse:collapse;margin:18px 0;font-size:.97em}
.wp2s-table th,.wp2s-table td{border:1px solid #ddd;padding:10px 12px;text-align:left}
.wp2s-table th{background:#0d1b2a;color:#fff}
.wp2s-table tr:nth-child(even){background:#f7f7f9}
.wp2s-code{background:#0d1b2a;color:#a8e6a1;font-family:Consolas,Monaco,monospace;font-size:.9em;padding:16px;border-radius:8px;overflow-x:auto;white-space:pre;margin:14px 0}
.wp2s-faq details{border:1px solid #e0e0e0;border-radius:8px;margin:10px 0;padding:4px 16px}
.wp2s-faq summary{font-weight:600;cursor:pointer;padding:12px 0;font-size:1.05em}
.wp2s-note{font-size:.9em;color:#555;font-style:italic}
.wp2s-updated{font-size:.85em;color:#777}
&lt;/style&gt;

&lt;div class="wp2s-wrap"&gt;

&lt;p class="wp2s-updated"&gt;Last updated: 23 July 2026 · Now includes in-the-wild exploitation data and the WAF-bypass warning. Written for site owners, admins and defenders who need to act, not just read.&lt;/p&gt;

&lt;div class="wp2s-tldr"&gt;
&lt;strong&gt;The 20-second version:&lt;/strong&gt; WP2Shell is a pre-authentication remote code execution (RCE) chain in &lt;em&gt;WordPress core&lt;/em&gt; — no plugin required, no login required. It affects WordPress &lt;strong&gt;6.9.0–6.9.4&lt;/strong&gt; and &lt;strong&gt;7.0.0–7.0.1&lt;/strong&gt;. WordPress shipped emergency fixes on 17 July 2026: update to &lt;strong&gt;7.0.2&lt;/strong&gt;, &lt;strong&gt;6.9.5&lt;/strong&gt;, or &lt;strong&gt;6.8.6&lt;/strong&gt; right now. Public exploit code exists. If you can't patch this minute, block &lt;code&gt;/wp-json/batch/v1&lt;/code&gt; and &lt;code&gt;?rest_route=/batch/v1&lt;/code&gt; at your WAF. Scroll down for a version checker, patch steps, WAF rules, detection scripts and indicators of compromise.
&lt;/div&gt;

&lt;h2 id="checker"&gt;Is my site affected? (Instant checker)&lt;/h2&gt;

&lt;p&gt;Type your exact WordPress version (find it in &lt;em&gt;Dashboard → Updates&lt;/em&gt;, or the bottom-right of your admin screen) and hit check. Everything runs in your browser — nothing is sent anywhere.&lt;/p&gt;

&lt;div class="wp2s-checker"&gt;
  &lt;label&gt;Your WordPress version&lt;/label&gt;
  &lt;input autocomplete="off" id="wp2s-ver" type="text" /&gt;
  &lt;button onclick="wp2sCheck()"&gt;Check now&lt;/button&gt;
  &lt;div id="wp2s-result"&gt;&lt;/div&gt;
&lt;/div&gt;

&lt;p class="wp2s-note"&gt;Prefer an external second opinion? Searchlight Cyber (the team that found the bug) runs a free tester at &lt;a href="https://wp2shell.com/" rel="nofollow noopener" target="_blank"&gt;wp2shell.com&lt;/a&gt; that probes your live site. You can also check our &lt;b&gt;&lt;a href="https://tools.cyberkendra.com/2026/07/wp2shell-checker-tool.html" target="_blank"&gt;wp2shell vulnerability checker&lt;/a&gt;&lt;/b&gt; tool.&lt;/p&gt;
&lt;div class="separator" style="clear: both;"&gt;&lt;img alt="" border="0" data-original-height="736" data-original-width="1312" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqMcJKKdX3duwNnvQ6pC9dY0uIksicIcQFRs-gkTXEU3g6MCyq_bJIZCJCpma5oncn6VXf1ve4VIuqAOPcnAIF1q4qDVyEL2oAKYBll_P8aEIXAWDHkyX9jObAWZypkjlCMPATX7vNEjuum88GM8k4zwaFsZHQEGzHD8fJ0diiERxU7AYu4bC7yA6zxnE/s1600/wp2shell-guide.webp" /&gt;&lt;/div&gt;
&lt;h2 id="facts"&gt;The facts at a glance&lt;/h2&gt;

&lt;table class="wp2s-table"&gt;
&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Item&lt;/th&gt;&lt;th&gt;Detail&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Name&lt;/td&gt;&lt;td&gt;WP2Shell (a.k.a. "wp2shell")&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;CVE IDs&lt;/td&gt;&lt;td&gt;&lt;strong&gt;CVE-2026-63030&lt;/strong&gt; (REST API batch-route confusion → RCE) chained with &lt;strong&gt;CVE-2026-60137&lt;/strong&gt; (SQL injection in core)&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Type&lt;/td&gt;&lt;td&gt;Unauthenticated / pre-auth Remote Code Execution&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Preconditions&lt;/td&gt;&lt;td&gt;&lt;strong&gt;None.&lt;/strong&gt; Works against a stock install with zero plugins.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Affected (RCE)&lt;/td&gt;&lt;td&gt;WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 (plus 7.1 beta1)&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Affected (SQLi only)&lt;/td&gt;&lt;td&gt;WordPress 6.8.0–6.8.5 — vulnerable to CVE-2026-60137 but &lt;em&gt;not&lt;/em&gt; the full RCE chain&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Not affected&lt;/td&gt;&lt;td&gt;Anything below 6.8.0&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Fixed in&lt;/td&gt;&lt;td&gt;&lt;strong&gt;7.0.2, 6.9.5, 6.8.6&lt;/strong&gt; (released 17 July 2026)&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Entry point&lt;/td&gt;&lt;td&gt;The REST batch endpoint: &lt;code&gt;/wp-json/batch/v1&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Discovered by&lt;/td&gt;&lt;td&gt;Adam Kues, Searchlight Cyber&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Exposure&lt;/td&gt;&lt;td&gt;WordPress powers 500M+ sites; forced auto-updates were enabled for affected installs&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h2 id="how"&gt;How WP2Shell actually works (in plain English)&lt;/h2&gt;

&lt;p&gt;WordPress 6.9 introduced a REST &lt;em&gt;batch&lt;/em&gt; endpoint — a convenience feature that lets a client bundle several API calls into one request. The flaw is a &lt;em&gt;route-confusion&lt;/em&gt; bug: the batch handler can be tricked into resolving inner requests to routes it shouldn't, in a context where the normal permission checks don't apply the way you'd expect.&lt;/p&gt;

&lt;p&gt;On its own that's a nasty logic bug. The problem is what it can reach: a second vulnerability, an SQL injection in core (CVE-2026-60137), that an anonymous request can now touch through the batch route. Chain the two together and an attacker walks a completely unauthenticated request from "hello, I'm nobody" all the way to running SQL — and from there to code execution on the server. That's the "2shell" in the name: WordPress to shell, no account needed.&lt;/p&gt;

&lt;p&gt;The reason the security community is treating this as a five-alarm fire isn't cleverness — it's &lt;em&gt;reach&lt;/em&gt;. There is no plugin dependency, no unusual configuration, no authenticated user required. If you're on an affected version and reachable from the internet, you're in scope. That's why WordPress.org took the rare step of forcing auto-updates.&lt;/p&gt;

&lt;h2 id="itw"&gt;It's being exploited right now (in-the-wild data)&lt;/h2&gt;

&lt;p&gt;This is no longer theoretical. Patchstack, which watches traffic from inside protected WordPress installs, published a timeline of the campaign that should end any "I'll patch next week" thinking:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;90 minutes.&lt;/strong&gt; The first real exploitation attempts hit sensors roughly 90 minutes after 7.0.2 was released — about three hours after the fix was committed to WordPress core. Attackers diffed the patch, built a scanner, and pointed it at the internet before most owners had read the release notes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;65,000+ blocked attempts&lt;/strong&gt; from &lt;strong&gt;1,500+ unique IPs&lt;/strong&gt; in the days after disclosure — and because those mitigations only run on genuinely vulnerable sites, every one of those was aimed at an unpatched target that a network/server WAF had already let through.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;97%&lt;/strong&gt; of blocked traffic hit the REST batch endpoint; roughly three-quarters carried a SQL injection attempt in &lt;code&gt;author_exclude&lt;/code&gt;. Most was validation probing (&lt;code&gt;AND (1=1)&lt;/code&gt;, &lt;code&gt;OR SLEEP(5)&lt;/code&gt;), but a small cluster from three IPs — &lt;code&gt;129.121.77.134&lt;/code&gt;, &lt;code&gt;91.202.233.61&lt;/code&gt;, &lt;code&gt;125.164.233.50&lt;/code&gt; — ran the full chain straight to administrator creation.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The takeaway from the researchers who watched it: 90 minutes from public patch to live exploitation isn't enough time to schedule a maintenance window. If you're on an affected version, treat this as already-happening, not a future risk.&lt;/p&gt;

&lt;h2 id="patch"&gt;Patch it — the 5-minute fix (do this first)&lt;/h2&gt;

&lt;p&gt;Patching is the only real fix. Mitigations below are stopgaps; this is the cure.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Back up first.&lt;/strong&gt; Snapshot your database and files (your host's one-click backup is fine). Core updates rarely break anything, but you want a rollback point.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Go to Dashboard → Updates.&lt;/strong&gt; If WordPress already auto-updated you (many sites did), you'll see you're on 7.0.2 / 6.9.5 / 6.8.6 — you're done, jump to &lt;a href="#detect"&gt;detection&lt;/a&gt; to make sure you weren't hit before the patch landed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Click "Update Now."&lt;/strong&gt; Land on the fixed release for your branch:
  &lt;ul&gt;
    &lt;li&gt;On the 7.0 branch → &lt;strong&gt;7.0.2&lt;/strong&gt;&lt;/li&gt;
    &lt;li&gt;On the 6.9 branch → &lt;strong&gt;6.9.5&lt;/strong&gt;&lt;/li&gt;
    &lt;li&gt;On the 6.8 branch → &lt;strong&gt;6.8.6&lt;/strong&gt; (fixes the SQLi; consider moving to a current branch after)&lt;/li&gt;
  &lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Confirm the version.&lt;/strong&gt; Don't assume — check the number in your dashboard footer after the update completes.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Prefer the command line?&lt;/strong&gt; With WP-CLI:&lt;/p&gt;
&lt;div class="wp2s-code"&gt;wp core update
wp core version          # confirm you're on 7.0.2 / 6.9.5 / 6.8.6
wp core verify-checksums # confirm core files weren't tampered with&lt;/div&gt;

&lt;p&gt;That last command is doing double duty: &lt;code&gt;verify-checksums&lt;/code&gt; compares your core files against WordPress.org's official hashes, so if an attacker modified a core file before you patched, it'll flag the mismatch.&lt;/p&gt;

&lt;h2 id="cant-patch"&gt;Can't patch right now? Emergency mitigations&lt;/h2&gt;

&lt;p&gt;Maybe you have a fragile custom build, a change-freeze, or 200 sites to coordinate. These buy you time — they are &lt;strong&gt;not&lt;/strong&gt; a permanent fix, and each can interfere with legitimate REST traffic. You must block &lt;em&gt;both&lt;/em&gt; forms of the route; blocking only the pretty path leaves the query-string version wide open.&lt;/p&gt;

&lt;h3&gt;Option A — Block at your WAF / CDN&lt;/h3&gt;
&lt;p&gt;Block requests to the batch route in &lt;em&gt;every&lt;/em&gt; form:&lt;/p&gt;
&lt;div class="wp2s-code"&gt;/wp-json/batch/v1
?rest_route=/batch/v1
rest_route=/batch/v1   (in the POST body — see warning below)&lt;/div&gt;

&lt;div class="wp2s-tldr"&gt;
&lt;strong&gt;⚠ Critical update (23 Jul 2026):&lt;/strong&gt; Patchstack revealed that almost every WAF rule shipped in the first hours after disclosure — including early versions of their own — was &lt;strong&gt;bypassable&lt;/strong&gt;. The rules only inspected the URL. But WordPress reads the &lt;code&gt;rest_route&lt;/code&gt; query variable from the &lt;em&gt;POST body before&lt;/em&gt; the query string, so an attacker can send a plain &lt;code&gt;POST /&lt;/code&gt; with &lt;code&gt;rest_route=/batch/v1&lt;/code&gt; and the whole payload in the body — the URL never contains &lt;code&gt;batch/v1&lt;/code&gt; at all, and a URL-only rule waves it straight through. Patchstack confirmed live attacks using exactly this shape from around 17:00 UTC on 21 July. &lt;strong&gt;Your WAF rule must match the batch route in the URL &lt;em&gt;and&lt;/em&gt; in the POST body.&lt;/strong&gt; If yours only checks the URL, it's one request rewrite away from useless.&lt;/div&gt;

&lt;p&gt;Attackers also spray path variants to dodge naive matching — block these too: &lt;code&gt;/index.php?rest_route=/batch/v1&lt;/code&gt;, &lt;code&gt;/wp/?rest_route=/batch/v1&lt;/code&gt;, &lt;code&gt;/blog/?rest_route=/batch/v1&lt;/code&gt;, &lt;code&gt;/wp-json?rest_route=/batch/v1&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;If you're behind &lt;strong&gt;Cloudflare&lt;/strong&gt; or &lt;strong&gt;Patchstack&lt;/strong&gt;, managed rules for both CVEs were deployed for you (Patchstack has since updated theirs to close the POST-body bypass). It's still worth patching; a WAF rule is a filter, not a fix — and as this episode proves, filters have edges.&lt;/p&gt;

&lt;h3&gt;Option B — Drop-in "must-use" plugin (no WAF needed, bypass-resistant)&lt;/h3&gt;
&lt;p&gt;This is actually the &lt;em&gt;stronger&lt;/em&gt; stopgap. Because it inspects the route &lt;em&gt;after&lt;/em&gt; WordPress has resolved it — not the raw URL — it catches the batch route no matter how the request arrived, including the POST-body bypass that defeats URL-only WAF rules. Create &lt;code&gt;wp-content/mu-plugins/block-batch.php&lt;/code&gt; with this. It rejects anonymous calls to the batch route while leaving logged-in admin traffic alone:&lt;/p&gt;
&lt;div class="wp2s-code"&gt;&amp;lt;?php
/**
 * Emergency WP2Shell mitigation — blocks anonymous access to the REST batch route.
 * TEMPORARY. Remove after updating to 7.0.2 / 6.9.5 / 6.8.6.
 */
add_filter('rest_pre_dispatch', function ($result, $server, $request) {
    $route = $request-&amp;gt;get_route();
    if (strpos($route, '/batch/') !== false &amp;amp;&amp;amp; !is_user_logged_in()) {
        return new WP_Error(
            'rest_forbidden',
            'Batch endpoint temporarily disabled (WP2Shell mitigation).',
            array('status' =&amp;gt; 403)
        );
    }
    return $result;
}, 0, 3);&lt;/div&gt;
&lt;p class="wp2s-note"&gt;mu-plugins load automatically and can't be deactivated from the dashboard, which is exactly what you want for an emergency control. Delete the file once you've patched.&lt;/p&gt;

&lt;h2 id="detect"&gt;Were you already hit? Detection &amp;amp; log-hunting&lt;/h2&gt;

&lt;p&gt;Because public exploit code circulated quickly, patching doesn't answer the real question: &lt;em&gt;did someone reach me first?&lt;/em&gt; Here's how to check.&lt;/p&gt;

&lt;h3&gt;1. Hunt your access logs for batch-endpoint abuse&lt;/h3&gt;
&lt;p&gt;The earliest signal is traffic to the batch route, especially with suspicious SQL-ish parameters. On most Apache/Nginx hosts:&lt;/p&gt;
&lt;div class="wp2s-code"&gt;# Any hits on the batch endpoint, all known forms + path variants
grep -Ei "batch/v1|rest_route=/?batch" /var/log/nginx/access.log*

# Higher-signal: batch traffic carrying SQL injection markers,
# including the obfuscated spellings seen in the live campaign
grep -Ei "batch/v1|rest_route=/?batch" /var/log/nginx/access.log* \
  | grep -Ei "author.?exclude|author_?_?not_?_?in|UNION|SLEEP\(|SUBSTRING|CHAR_LENGTH|/\*!|/\*\*/|\bAnD\b|\bOr\b"

# Privileged writes smuggled inside a batch body (admin creation / plugin install)
grep -Ei "wp/v2/(users|plugins)" /var/log/nginx/access.log* \
  | grep -Ei "administrator|roles"

# Known full-chain source IPs from the observed campaign (context, not proof)
grep -E "129\.121\.77\.134|91\.202\.233\.61|125\.164\.233\.50" /var/log/nginx/access.log*&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Watch the parameter, not just the URL.&lt;/strong&gt; The real campaign moved the batch route into the &lt;em&gt;POST body&lt;/em&gt; to dodge URL-only filters, and the &lt;code&gt;requests&lt;/code&gt; array can arrive as JSON, form-encoded (&lt;code&gt;requests[0][path]=...&lt;/code&gt;), or in the query string. WordPress also normalizes &lt;code&gt;author.exclude&lt;/code&gt; and &lt;code&gt;author exclude&lt;/code&gt; back to &lt;code&gt;author_exclude&lt;/code&gt;, so match those spellings too. A non-integer &lt;code&gt;author_exclude&lt;/code&gt; value carrying &lt;code&gt;UNION&lt;/code&gt;, &lt;code&gt;SLEEP(&lt;/code&gt;, or comment-obfuscated &lt;code&gt;AND&lt;/code&gt;/&lt;code&gt;OR&lt;/code&gt; is one of the cleanest indicators of an attempt against this chain.&lt;/p&gt;

&lt;h3&gt;2. Look for dropped web shells&lt;/h3&gt;
&lt;p&gt;Successful exploitation typically drops a PHP payload. Scan for recently-changed or suspicious PHP files:&lt;/p&gt;
&lt;div class="wp2s-code"&gt;# PHP files created/modified in the last 7 days under your webroot
find /var/www/html -name "*.php" -mtime -7 -print

# Classic web-shell function calls hiding in your uploads/plugins
grep -RilE "eval\(|base64_decode\(|system\(|shell_exec\(|passthru\(|assert\(" \
  /var/www/html/wp-content/uploads /var/www/html/wp-content/plugins

# PoC-tool artifacts: rogue plugin folders/zips named like wp2shell-xxxxxxxx
find /var/www/html/wp-content/plugins -iname "wp2shell*" -print

# Easy to miss: mu-plugins auto-load and never appear on the Plugins screen
ls -la /var/www/html/wp-content/mu-plugins/&lt;/div&gt;

&lt;h3&gt;3. Verify core integrity&lt;/h3&gt;
&lt;div class="wp2s-code"&gt;wp core verify-checksums
# Any "File doesn't verify against checksum" line = investigate that file immediately.&lt;/div&gt;

&lt;h3&gt;4. Check the database for injected admin users / options&lt;/h3&gt;
&lt;div class="wp2s-code"&gt;# New admin accounts you don't recognise
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered

# Suspicious auto-loaded options (common persistence spot)
wp option list --search="*eval*" --autoload=on&lt;/div&gt;

&lt;h2 id="ioc"&gt;Indicators of Compromise (IOC)&lt;/h2&gt;

&lt;p&gt;The following are associated with public WP2Shell proof-of-concept tooling. Treat them as &lt;strong&gt;leads, not proof&lt;/strong&gt; — they're trivial for an attacker to change, and some payloads self-delete after running, so their &lt;em&gt;absence&lt;/em&gt; doesn't clear you. Use them to prioritise investigation, alongside the log and file checks above.&lt;/p&gt;

&lt;table class="wp2s-table"&gt;
&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Category&lt;/th&gt;&lt;th&gt;Indicator&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Target endpoints&lt;/td&gt;&lt;td&gt;Batch route in any form: &lt;code&gt;/wp-json/batch/v1&lt;/code&gt;, &lt;code&gt;?rest_route=/batch/v1&lt;/code&gt;, or &lt;code&gt;rest_route=/batch/v1&lt;/code&gt; &lt;strong&gt;in the POST body&lt;/strong&gt;; plus path variants &lt;code&gt;/index.php&lt;/code&gt;, &lt;code&gt;/wp/&lt;/code&gt;, &lt;code&gt;/blog/&lt;/code&gt;, &lt;code&gt;/wp-json?rest_route=...&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Request body&lt;/td&gt;&lt;td&gt;Nested &lt;code&gt;requests[]&lt;/code&gt; arrays (as JSON, form-encoded &lt;code&gt;requests[0][path]=...&lt;/code&gt;, or query string) with malformed &lt;code&gt;http://&lt;/code&gt; / &lt;code&gt;http::&lt;/code&gt; paths&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SQLi markers&lt;/td&gt;&lt;td&gt;Non-integer &lt;code&gt;author_exclude&lt;/code&gt; / &lt;code&gt;author__not_in&lt;/code&gt; (also spelled &lt;code&gt;author.exclude&lt;/code&gt;, &lt;code&gt;author exclude&lt;/code&gt;) containing &lt;code&gt;UNION&lt;/code&gt;, &lt;code&gt;SLEEP(&lt;/code&gt;, &lt;code&gt;SUBSTRING&lt;/code&gt;, &lt;code&gt;CHAR_LENGTH&lt;/code&gt;, or obfuscated &lt;code&gt;AnD&lt;/code&gt;/&lt;code&gt;Or&lt;/code&gt;, inline comments &lt;code&gt;/**/&lt;/code&gt;, &lt;code&gt;/*!AND*/&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Privilege escalation&lt;/td&gt;&lt;td&gt;Nested privileged writes inside a batch body: &lt;code&gt;POST /wp/v2/users&lt;/code&gt; with &lt;code&gt;"roles":["administrator"]&lt;/code&gt;, or &lt;code&gt;POST /wp/v2/plugins&lt;/code&gt; (plugin install/activate)&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Full-chain source IPs&lt;/td&gt;&lt;td&gt;&lt;code&gt;129.121.77.134&lt;/code&gt;, &lt;code&gt;91.202.233.61&lt;/code&gt;, &lt;code&gt;125.164.233.50&lt;/code&gt; (observed running the complete admin-creation chain; context only — IPs rotate)&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;User-Agents&lt;/td&gt;&lt;td&gt;&lt;code&gt;wp2shell-check/1.0&lt;/code&gt;, &lt;code&gt;wp2shell-poc/1.0&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Multipart boundary&lt;/td&gt;&lt;td&gt;Boundaries beginning &lt;code&gt;----wp2shell&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Dropped files&lt;/td&gt;&lt;td&gt;Plugin ZIPs named &lt;code&gt;wp2shell-&amp;lt;8-hex&amp;gt;.zip&lt;/code&gt;; files/dirs under &lt;code&gt;wp-content/plugins/wp2shell-*&lt;/code&gt;; anything unexpected in &lt;code&gt;wp-content/mu-plugins/&lt;/code&gt; (auto-loads, hidden from Plugins screen)&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Command channel&lt;/td&gt;&lt;td&gt;Requests containing &lt;code&gt;?tok=&amp;lt;token&amp;gt;&amp;amp;c=&amp;lt;command&amp;gt;&lt;/code&gt;; cleanup requests with &lt;code&gt;&amp;amp;rm=1&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Response markers&lt;/td&gt;&lt;td&gt;Responses containing &lt;code&gt;WP2SHELL_OUT_START&lt;/code&gt; / &lt;code&gt;WP2SHELL_OUT_END&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;&lt;strong&gt;If you find evidence of compromise:&lt;/strong&gt; assume full server compromise. Patching does not evict an attacker who already has a shell. Take the site offline, rotate all secrets (database password, &lt;code&gt;wp-config.php&lt;/code&gt; salts, API keys, admin passwords), restore from a known-clean pre-incident backup, then patch before bringing it back. When in doubt, engage an incident-response professional.&lt;/p&gt;

&lt;h2 id="poc"&gt;Public PoC code &amp;amp; research resources&lt;/h2&gt;

&lt;div class="wp2s-tldr"&gt;
&lt;strong&gt;Use responsibly.&lt;/strong&gt; The repositories below contain working exploit code and are listed for defenders, researchers and penetration testers to understand and test the flaw &lt;em&gt;on systems they own or are authorised to assess&lt;/em&gt;. Running exploits against a site you don't control is illegal in most jurisdictions. All links are external and open in a new tab. WatchTowr has reported in-the-wild exploitation, so treat any unpatched, internet-facing install as a live target.
&lt;/div&gt;

&lt;table class="wp2s-table"&gt;
&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Resource&lt;/th&gt;&lt;th&gt;Type&lt;/th&gt;&lt;th&gt;What it is&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
  &lt;td&gt;&lt;a href="https://github.com/0xsha/wp2shell" rel="nofollow noopener" target="_blank"&gt;0xsha/wp2shell&lt;/a&gt;&lt;/td&gt;
  &lt;td&gt;PoC (Python)&lt;/td&gt;
  &lt;td&gt;Single-file, stdlib-only tool that unifies several public PoCs; forges a post via the UNION confusion, creates an admin, and drops a token-gated webshell. Verified end-to-end in-lab.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td&gt;&lt;a href="https://github.com/Icex0/wp2shell-poc" rel="nofollow noopener" target="_blank"&gt;Icex0/wp2shell-poc&lt;/a&gt;&lt;/td&gt;
  &lt;td&gt;PoC (Python)&lt;/td&gt;
  &lt;td&gt;Independent PoC for the batch-route SQLi chain with three modes: &lt;code&gt;check&lt;/code&gt; (confirms the SQLi path), &lt;code&gt;read&lt;/code&gt; (DB read), and &lt;code&gt;shell&lt;/code&gt; (plugin-backed command shell).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td&gt;&lt;a href="https://github.com/mverschu/CVE-2026-63030" rel="nofollow noopener" target="_blank"&gt;mverschu/CVE-2026-63030&lt;/a&gt;&lt;/td&gt;
  &lt;td&gt;PoC (Exploit)&lt;/td&gt;
  &lt;td&gt;PoC exploit for the unauthenticated RCE; documents affected 6.9.0–6.9.4 / 7.0.0–7.0.1 and fixes in 6.9.5 / 7.0.2.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td&gt;&lt;a href="https://github.com/projectdiscovery/nuclei-templates" rel="nofollow noopener" target="_blank"&gt;ProjectDiscovery Nuclei template&lt;/a&gt;&lt;/td&gt;
  &lt;td&gt;Detection&lt;/td&gt;
  &lt;td&gt;Community Nuclei template for non-intrusive detection of WP2Shell across many hosts at once (search the repo for “wp2shell” / CVE-2026-63030).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td&gt;&lt;a href="https://blog.zsec.uk/wp2shell-code-trace-deep-dive/" rel="nofollow noopener" target="_blank"&gt;ZSec – Code Trace Deep Dive&lt;/a&gt;&lt;/td&gt;
  &lt;td&gt;Analysis&lt;/td&gt;
  &lt;td&gt;Line-by-line trace of how the batch route confusion reaches the &lt;code&gt;author__not_in&lt;/code&gt; SQL injection. Best read for understanding the root cause.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td&gt;&lt;a href="https://www.rapid7.com/blog/post/etr-cve-2026-63030-wp2shell-a-critical-remote-code-execution-vulnerability-in-wordpress-core/" rel="nofollow noopener" target="_blank"&gt;Rapid7 – Emergent Threat Report&lt;/a&gt;&lt;/td&gt;
  &lt;td&gt;Analysis&lt;/td&gt;
  &lt;td&gt;Vendor breakdown of the chain, exploitation status and detection guidance.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td&gt;&lt;a href="https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/" rel="nofollow noopener" target="_blank"&gt;Searchlight Cyber advisory&lt;/a&gt;&lt;/td&gt;
  &lt;td&gt;Primary source&lt;/td&gt;
  &lt;td&gt;The original disclosure from the team (Adam Kues) that found the bug.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td&gt;&lt;a href="https://wp2shell.com/" rel="nofollow noopener" target="_blank"&gt;wp2shell.com&lt;/a&gt;&lt;/td&gt;
  &lt;td&gt;Live checker&lt;/td&gt;
  &lt;td&gt;Searchlight's hosted tool that tests whether a live instance is exposed. Occasionally offline under load.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p class="wp2s-note"&gt;Repositories can be renamed or taken down without notice, and GitHub may remove PoCs that violate its policies — if a link 404s, search GitHub for “wp2shell” or “CVE-2026-63030” for current mirrors. We only link to code already public and widely cited by mainstream security outlets.&lt;/p&gt;

&lt;h2 id="faq"&gt;WP2Shell FAQ&lt;/h2&gt;
&lt;div class="wp2s-faq"&gt;

&lt;details&gt;&lt;summary&gt;What WordPress versions are vulnerable to WP2Shell?&lt;/summary&gt;
&lt;p&gt;The full remote code execution chain affects WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. WordPress 6.8.0–6.8.5 is affected by the underlying SQL injection (CVE-2026-60137) but cannot be driven to full RCE because the vulnerable batch route was introduced in 6.9. Versions below 6.8.0 are not affected. Fixed releases are 7.0.2, 6.9.5 and 6.8.6.&lt;/p&gt;&lt;/details&gt;

&lt;details&gt;&lt;summary&gt;What are the CVE numbers for WP2Shell?&lt;/summary&gt;
&lt;p&gt;WP2Shell is a chain of two CVEs: CVE-2026-63030 (REST API batch-route confusion leading to RCE) and CVE-2026-60137 (SQL injection in WordPress core). They are exploited together.&lt;/p&gt;&lt;/details&gt;

&lt;details&gt;&lt;summary&gt;Is there a public WP2Shell PoC or exploit?&lt;/summary&gt;
&lt;p&gt;Yes. Public exploit code and testing tools circulated shortly after disclosure on 17 July 2026, which is why patching immediately is critical. Searchlight Cyber, who discovered the flaw, deliberately withheld deep technical detail at disclosure to give defenders time, but working exploits are now in the wild.&lt;/p&gt;&lt;/details&gt;

&lt;details&gt;&lt;summary&gt;Do I need a plugin to be vulnerable?&lt;/summary&gt;
&lt;p&gt;No. This is a WordPress &lt;em&gt;core&lt;/em&gt; vulnerability. A stock install with no plugins on an affected version is exploitable by an anonymous, unauthenticated attacker.&lt;/p&gt;&lt;/details&gt;

&lt;details&gt;&lt;summary&gt;I'm on Cloudflare — am I safe?&lt;/summary&gt;
&lt;p&gt;Cloudflare deployed managed WAF rules covering both CVEs for proxied sites across all plans, including free, which blocks known exploitation patterns. That's a strong safety net, but it's a filter, not a fix — you should still update WordPress to the patched version.&lt;/p&gt;&lt;/details&gt;

&lt;details&gt;&lt;summary&gt;How do I know if my site was already hacked?&lt;/summary&gt;
&lt;p&gt;Search your access logs for POST requests to &lt;code&gt;/wp-json/batch/v1&lt;/code&gt; with SQL-like &lt;code&gt;author_exclude&lt;/code&gt; / &lt;code&gt;author__not_in&lt;/code&gt; parameters, scan for recently-modified or web-shell PHP files, run &lt;code&gt;wp core verify-checksums&lt;/code&gt;, and check for unfamiliar administrator accounts (and the hidden &lt;code&gt;wp-content/mu-plugins/&lt;/code&gt; folder). See the detection section above for exact commands.&lt;/p&gt;&lt;/details&gt;

&lt;details&gt;&lt;summary&gt;Is my WAF rule for WP2Shell enough?&lt;/summary&gt;
&lt;p&gt;Maybe not. Patchstack found that WAF rules matching only the URL (looking for &lt;code&gt;batch/v1&lt;/code&gt; in the path or query string) can be bypassed: WordPress reads the &lt;code&gt;rest_route&lt;/code&gt; variable from the POST body before the query string, so an attacker can send &lt;code&gt;POST /&lt;/code&gt; with &lt;code&gt;rest_route=/batch/v1&lt;/code&gt; in the body and the URL never shows the batch route. Live attacks using this shape were seen from 21 July 2026. Your rule must match the batch route in the URL and the POST body. The must-use plugin mitigation avoids this problem entirely because it inspects the resolved route, not the URL.&lt;/p&gt;&lt;/details&gt;

&lt;/div&gt;

&lt;h2 id="sources"&gt;Sources &amp;amp; further reading&lt;/h2&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;a href="https://www.cyberkendra.com/2026/07/wp2shell-critical-wordpress-flaw-lets.html" rel="noopener" target="_blank"&gt;Cyber Kendra coverage&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://wordpress.org/news/2026/07/wordpress-7-0-2-release/" rel="noopener" target="_blank"&gt;WordPress.org — 7.0.2 security release (official)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/" rel="noopener" target="_blank"&gt;Searchlight Cyber — WP2Shell disclosure (discoverer)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://patchstack.com/articles/ninety-minutes-watching-attackers-weaponize-the-wordpress-core-rce/" rel="noopener" target="_blank"&gt;Patchstack — 90 minutes: watching attackers weaponize the RCE (in-the-wild data + WAF-bypass)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;/div&gt;

&lt;!--Interactive version checker--&gt;
&lt;script&gt;
function wp2sCmp(a,b){
  a=a.split('.').map(Number);b=b.split('.').map(Number);
  for(var i=0;i&lt;3;i++){var x=a[i]||0,y=b[i]||0;if(x&gt;y)return 1;if(x&lt;y)return -1;}
  return 0;
}
function wp2sCheck(){
  var el=document.getElementById('wp2s-result');
  var raw=(document.getElementById('wp2s-ver').value||'').trim().replace(/[^0-9.]/g,'');
  el.style.display='block';
  if(!/^\d+\.\d+(\.\d+)?$/.test(raw)){
    el.className='wp2s-warn';el.innerHTML='Enter a version like 6.9.3, 7.0.1 or 6.8.5.';return;
  }
  // Fixed / safe releases
  if(raw==='7.0.2'||raw==='6.9.5'||raw==='6.8.6'||wp2sCmp(raw,'7.0.2')&gt;=0){
    el.className='wp2s-safe';el.innerHTML='&amp;#9989; Patched. '+raw+' includes the WP2Shell fix. Still run the detection checks below to confirm you weren\'t hit before updating.';return;
  }
  // RCE-vulnerable range: 6.9.0&amp;ndash;6.9.4 and 7.0.0&amp;ndash;7.0.1
  if((wp2sCmp(raw,'6.9.0')&gt;=0&amp;&amp;wp2sCmp(raw,'6.9.4')&lt;=0)||(wp2sCmp(raw,'7.0.0')&gt;=0&amp;&amp;wp2sCmp(raw,'7.0.1')&lt;=0)){
    el.className='wp2s-vuln';el.innerHTML='&amp;#128680; VULNERABLE to WP2Shell RCE. Update to 7.0.2 (or 6.9.5) immediately, then check for compromise.';return;
  }
  // SQLi-only range: 6.8.0&amp;ndash;6.8.5
  if(wp2sCmp(raw,'6.8.0')&gt;=0&amp;&amp;wp2sCmp(raw,'6.8.5')&lt;=0){
    el.className='wp2s-warn';el.innerHTML='&amp;#9888; Partially affected. '+raw+' is exposed to the SQL injection (CVE-2026-60137) but not the full RCE chain. Update to 6.8.6.';return;
  }
  // Below 6.8.0
  if(wp2sCmp(raw,'6.8.0')&lt;0){
    el.className='wp2s-safe';el.innerHTML='&amp;#9989; Not affected by WP2Shell. '+raw+' predates the vulnerable code &amp;mdash; though a version this old has other security issues; consider upgrading.';return;
  }
  el.className='wp2s-warn';el.innerHTML='Couldn\'t classify '+raw+'. When in doubt, update to the latest release.';
}
document.getElementById('wp2s-ver').addEventListener('keydown',function(e){if(e.key==='Enter')wp2sCheck();});
&lt;/script&gt;

&lt;!--============================================================
     FAQ STRUCTURED DATA
     ============================================================--&gt;
&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "What WordPress versions are vulnerable to WP2Shell?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The full RCE chain affects WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. WordPress 6.8.0&amp;ndash;6.8.5 is affected by the underlying SQL injection (CVE-2026-60137) but not the full RCE. Versions below 6.8.0 are not affected. Fixed releases are 7.0.2, 6.9.5 and 6.8.6."
      }
    },
    {
      "@type": "Question",
      "name": "What are the CVE numbers for WP2Shell?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "WP2Shell chains CVE-2026-63030 (REST API batch-route confusion leading to RCE) with CVE-2026-60137 (SQL injection in WordPress core)."
      }
    },
    {
      "@type": "Question",
      "name": "Is there a public WP2Shell exploit?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes. Public exploit code and testing tools circulated shortly after disclosure on 17 July 2026, making immediate patching critical."
      }
    },
    {
      "@type": "Question",
      "name": "Do I need a plugin to be vulnerable to WP2Shell?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. WP2Shell is a WordPress core vulnerability. A stock install with no plugins on an affected version is exploitable by an anonymous attacker."
      }
    },
    {
      "@type": "Question",
      "name": "How do I know if my WordPress site was already hacked via WP2Shell?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Search access logs for POST requests to /wp-json/batch/v1 with SQL-like author_exclude parameters, scan for recently modified or web-shell PHP files, run wp core verify-checksums, and check for unfamiliar administrator accounts and the hidden wp-content/mu-plugins folder."
      }
    },
    {
      "@type": "Question",
      "name": "Is a WAF rule enough to stop WP2Shell?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Not always. WAF rules that only match the batch route in the URL can be bypassed, because WordPress reads the rest_route variable from the POST body before the query string. An attacker can POST to the site root with rest_route=/batch/v1 in the body and the URL never shows the batch route. Rules must match both the URL and POST body, and live bypass attempts were observed from 21 July 2026. Updating WordPress is the only real fix."
      }
    }
  ]
}
&lt;/script&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqMcJKKdX3duwNnvQ6pC9dY0uIksicIcQFRs-gkTXEU3g6MCyq_bJIZCJCpma5oncn6VXf1ve4VIuqAOPcnAIF1q4qDVyEL2oAKYBll_P8aEIXAWDHkyX9jObAWZypkjlCMPATX7vNEjuum88GM8k4zwaFsZHQEGzHD8fJ0diiERxU7AYu4bC7yA6zxnE/s72-c/wp2shell-guide.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Most GitHub Enterprise Servers Still Unpatched for New RCE</title><link>https://www.cyberkendra.com/2026/07/most-github-enterprise-servers-still.html</link><category>GitHub</category><category>Security</category><category>Vulnerability</category><pubDate>Thu, 23 Jul 2026 00:05:36 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-1295262730368814238</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="GitHub Hacked" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFvNz_M7naquwbUlDQC2aMVPDIaYui6BWjeIsFib0ob8zUnSxisLbc0AMyF9xpkMUJdiGx9pmsTkxw6nIbgdUy9a_u8oeYmD7cp5UGCv6ly45LP10vYIqJGag43u7M2I9hTzNvRQsZzRV15b3fvBZUnr6vgZSxxUBZPFEubnZgf8oJ5M_JwMAT0F1ptT8/s1600/github-hacked.webp" title="GitHub Hacked" /&gt;&lt;/div&gt;&lt;p&gt;Nearly nine out of ten self-hosted GitHub Enterprise Server instances remain vulnerable to a critical remote code execution flaw that needs nothing more than a standard git client to exploit, according to Wiz Research.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Tracked as &lt;b&gt;CVE-2026-3854&lt;/b&gt;, the bug lives in GitHub's internal git infrastructure and affected both GitHub.com and GHES. Any authenticated user with push access to a repository could run arbitrary commands on backend servers with a single git push.&amp;nbsp;&lt;/p&gt;&lt;p&gt;GitHub shut the loophole on GitHub.com within six hours of &lt;a href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854" rel="nofollow" target="_blank"&gt;Wiz's report&lt;/a&gt;, so cloud users need to do nothing. Administrators running their own servers are the ones now carrying the risk — Wiz's telemetry indicates 88% of GHES instances are still exposed.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="GitHub RCE" border="0" data-original-height="1463" data-original-width="1920" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7lgrjDen9DHsyU9I8TIFffam1EMKepfeMf1ppGxsu30p7_4lP4vO40TBwPOfvmnBHztF15s3C0c8nJLReszQDcUkeuAgeWR-QBc2wX0kSDAFGo5gUO64vsyE6q0C04vmJWskZyANZ6fU2IVwUDTPJk3J_HPY0sCtIwLxNTnLLWFTs2-ylufBWleZVEwQ/s1600/github-rce.webp" title="GitHub RCE" /&gt;&lt;/div&gt;&lt;p&gt;Wiz credits AI-augmented reverse engineering, specifically IDA MCP tooling, with letting its team pull apart GitHub's compiled closed-source binaries and reconstruct the internal protocols between them. The company had probed GHES before and abandoned the effort as too labor-intensive. This time the binaries gave up their secrets fast enough to map the entire push pipeline.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The flaw itself is almost mundane. When you push code, GitHub's proxy service passes security metadata to downstream services through an internal header called X-Stat, a list of semicolon-separated key=value pairs.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Push options — arbitrary strings a user supplies with git push -o — get copied into that header without stripping semicolons. Because the parser applies last-write-wins logic, a semicolon in a push option lets an attacker append their own fields that silently override the legitimate ones.&lt;/p&gt;&lt;p&gt;From there, Wiz chained three injected fields to flip the pre-receive hook binary out of its sandboxed production path, redirect the hook lookup directory, and use path traversal to execute an arbitrary file as the git service user.&amp;nbsp;&lt;/p&gt;&lt;p&gt;On GitHub.com, that landed them on shared storage nodes holding millions of repository entries belonging to other tenants. Wiz says it verified permissions using its own accounts only and did not read anyone else's code.&lt;/p&gt;&lt;p&gt;GitHub CISO Alexis Wales called a finding of this caliber "rare", noting it earned one of the program's highest bounty payouts.&lt;/p&gt;&lt;p&gt;&lt;b&gt;What to do: &lt;/b&gt;Upgrade GHES to 3.19.3, 3.18.6, 3.17.12, 3.16.15, 3.15.19, or 3.14.24. Anything at or below 3.19.1 is vulnerable.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFvNz_M7naquwbUlDQC2aMVPDIaYui6BWjeIsFib0ob8zUnSxisLbc0AMyF9xpkMUJdiGx9pmsTkxw6nIbgdUy9a_u8oeYmD7cp5UGCv6ly45LP10vYIqJGag43u7M2I9hTzNvRQsZzRV15b3fvBZUnr6vgZSxxUBZPFEubnZgf8oJ5M_JwMAT0F1ptT8/s72-c/github-hacked.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Why Your AI Agents Are Guessing: The Case for Enterprise Context Management</title><link>https://www.cyberkendra.com/2026/07/why-your-ai-agents-are-guessing-case.html</link><category>AI</category><category>Tips</category><pubDate>Tue, 21 Jul 2026 08:42:35 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-8916413150168277465</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="AI Agents" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7W8TcpPFfdtA1kZjKgvXiN1lDW7DunqIQYT1Uv7hgySgtXnwXkCGWJ9pVQnISAu7KH9Q6_hS41kr-s8Q64Vr7E79s7GCmgdyd4sJw465dvaVEccdDzNJ3-KWWJcEpA035b9MPS_vZqQAHv-HGbqVSJU27LKKGDZd4HggMmo38Wz4GucJqI1Mvrj6Qbo0/s1600/ai-fact.webp" title="AI Agents" /&gt;&lt;/div&gt;&lt;p&gt;Artificial intelligence agents are moving from pilot projects to production, but organizations face a critical challenge that they discover too late.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Without proper context, even sophisticated &lt;a href="https://www.cyberkendra.com/2026/04/ai-agent-wiped-startups-entire-database.html" target="_blank"&gt;AI agents&lt;/a&gt; produce inaccurate results, waste compute resources, and fail to deliver reliable answers when business decisions depend on them.&lt;/p&gt;

&lt;details class="note tp sp notranslate"&gt;
  &lt;summary&gt;&amp;nbsp;&lt;b&gt;Key Takeaways&lt;/b&gt;&lt;svg viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"&gt;&lt;path d="M7.41,8.58L12,13.17L16.59,8.58L18,10L12,16L6,10L7.41,8.58Z"&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/summary&gt;
  &lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;AI agents without proper context waste tokens guessing and surfacing unverified information, directly causing 24% of AI/ML project failures.&lt;/li&gt;&lt;li&gt;Context platforms unify technical metadata from Snowflake and dbt, business knowledge from Notion, and operational data into a single governed layer.&lt;/li&gt;&lt;li&gt;Context Intelligence auto-generates metric definitions from existing query logs and dashboards, solving cold-start problems in days instead of months.&lt;/li&gt;&lt;li&gt;Connected lineage eliminates fragmentation where metric definitions live scattered across dbt, Looker, and Confluence without centralized agent access.&lt;/li&gt;&lt;li&gt;Real-time context activation through MCP and APIs delivers validated definitions to every agent simultaneously, preventing contradictory answers across departments.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;
&lt;/details&gt;
&lt;h2 style="text-align: left;"&gt;The Hidden Cost of AI Agent Failures&lt;/h2&gt;&lt;p&gt;Modern enterprises deploy AI agents expecting them to answer questions with expertise and accuracy.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Instead, teams discover agents hallucinate answers, contradict each other across departments, and confidently surface incorrect information grounded in stale or duplicated data.&lt;/p&gt;&lt;p&gt;The root cause is rarely the AI model but rather the fragmented context these agents operate with daily.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Data definitions scatter across multiple tools, metric logic hides in transformation code, business knowledge sits in undated documentation, and access controls prevent agents from reaching authoritative sources.&lt;/p&gt;&lt;p&gt;When business teams lose confidence in AI agent outputs, entire initiatives stall before delivering ROI.&amp;nbsp;&lt;/p&gt;&lt;p&gt;IDC research shows 24% of AI project failures stem from context issues, while 82% of IT leaders agree that agentic AI cannot reach production without proper context management.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The impact compounds as teams duplicate efforts because they cannot find or agree on an authoritative context.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Understanding Context in the AI Era&lt;/h2&gt;&lt;p&gt;Context for AI agents differs fundamentally from human-readable documentation that readers can interpret with nuance.&amp;nbsp;&lt;/p&gt;&lt;p&gt;When people read Notion or dbt documentation, they understand the surrounding context, ask for clarification, and grasp the intent behind definitions.&lt;/p&gt;&lt;p&gt;AI agents need machine-readable, validated, consistent context delivered in real time at inference time.&amp;nbsp;&lt;/p&gt;&lt;p&gt;This includes technical definitions, operational constraints, business rules, data lineage, quality signals, and access policies unified into a single source of truth every agent can query.&lt;/p&gt;&lt;p&gt;The distinction matters architecturally because most organizations treat context as a human documentation problem solved through portals. Instead, context is infrastructure requiring a platform that continuously maintains, validates, and distributes governed context to every agent deployed.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;The Problem: Fragmented Context Across Systems&lt;/h2&gt;&lt;p&gt;Organizations lack connected lineage across their data ecosystem. Metric definitions live in dbt, join logic hides in Looker, business glossaries sit in Confluence, technical metadata lives in Snowflake, and operational knowledge exists in unsearchable Slack threads.&lt;/p&gt;&lt;p&gt;This fragmentation creates the worst situation for AI agents: five partial views from five tools with critical dependencies hidden in gaps between them.&amp;nbsp;&lt;/p&gt;&lt;p&gt;When source schemas change, warehouse teams cannot see dependent dashboards, BI teams cannot see source contracts, and change teams cannot predict ripple effects.&lt;/p&gt;&lt;p&gt;Most organizations attempt to solve fragmentation manually through documentation workshops, consuming months of SME time.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Even completed documentation becomes stale within weeks as pipelines evolve and knowledge shifts without systematic capture.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;The Solution: Unified Context Platform&lt;/h2&gt;&lt;p&gt;A true &lt;a href="https://datahub.com/products/context-platform/" target="_blank"&gt;context platform for AI agents&lt;/a&gt; solves fragmentation by unifying technical metadata, business knowledge, and operational context into a single governed layer updating in real time.&lt;/p&gt;&lt;p&gt;Rather than replacing tools, it connects them, extracting context automatically from query logs, BI dashboards, dbt projects, and business systems, then making unified context accessible to every agent instantly.&lt;/p&gt;&lt;p&gt;Context platform for AI agents operates across four integrated capabilities. Context Ingestion connects all data sources, pulling metadata from Snowflake, Databricks, Looker, dbt, Airflow, and 100+ platforms, plus documentation from Notion and Confluence whenever changes occur.&lt;/p&gt;&lt;p&gt;Context Intelligence solves cold-start problems by continuously extracting semantic meaning from query logs and dashboards to auto-generate metric definitions and join patterns within days.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Rather than blank templates, teams work with AI-proposed context, capturing what the organization actually does, validated through structured reviews.&lt;/p&gt;&lt;p&gt;Context Hub gives subject matter experts dedicated workspaces to confirm, refine, and resolve definitions so agents stay accurate long-term.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Experts become reviewers of AI-generated content rather than documentation creators, dramatically reducing effort while ensuring accuracy.&lt;/p&gt;&lt;p&gt;Context Activation delivers validated context to every agent through the MCP Server for Claude and Cursor integration, native SDKs for LangChain and Snowflake Intelligence, GraphQL APIs for custom applications, and user interfaces for human teams.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;How Enterprise Teams Deploy Agents Successfully&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Deploy Agents Successfully" border="0" data-original-height="1365" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1OOSi5DOPCQ6ELpC8NbwLBGq7V7IfwZUOjNXI4HB-a7_nnsX7knX_uEY-4zamciDk8hhyfR4NBdyhH3nJIkBPaw9dkSw0NyR0Z5T5mg_8PQ4otunTC9h37LRTyt7ggkQ4JLubj9vYIS0kdEGhuK_Js0OU7RvP1E2VPf9Unha8v3F3pdJfdoWq0pQSoQ0/s1600/deploy-agents.webp" title="Deploy Agents Successfully" /&gt;&lt;/div&gt;&lt;p&gt;Data experts enable analytics agents by leveraging Context Intelligence to surface semantic meaning buried in years of history.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The platform automatically extracts metric definitions and patterns, then validates them, eliminating the need to start documentation from scratch.&lt;/p&gt;&lt;p&gt;Business users get reliable agent responses they can act on without second-guessing because every answer draws from SME-validated context extracted from organizational history rather than probabilistic guessing.&amp;nbsp;&lt;/p&gt;&lt;p&gt;This shift from uncertain answers to deterministic, traceable responses builds confidence.&lt;/p&gt;&lt;p&gt;Data platform teams eliminate fragmentation and drift by maintaining one synchronized context layer, unifying metadata organization-wide.&amp;nbsp;&lt;/p&gt;&lt;p&gt;When definitions change upstream in dbt or Looker, every agent gets the latest version immediately without manual effort.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Real-World Results from Pinterest&lt;/h2&gt;&lt;p&gt;Pinterest faced an overwhelming challenge: 400,000 ungoverned tables and institutional knowledge buried in Slack with no way to determine which tables were trustworthy.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Analysts spent hours reverse-engineering data provenance before asking business questions.&lt;/p&gt;&lt;p&gt;By implementing context management, Pinterest transformed ungoverned tables into a curated foundation for AI agents.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The platform indexed 100,000 critical assets and learned analyst query intent from historical patterns, enabling agents to retrieve answers grounded in real institutional knowledge.&lt;/p&gt;&lt;p&gt;The impact was transformative: the Analytics Agent became Pinterest's most-used AI agent with 10x usage of the next agent, delivered trusted answers in minutes instead of hours, and achieved a 70% reduction in manual documentation effort.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Building Trust Through Deterministic Answers&lt;/h2&gt;&lt;p&gt;The fundamental shift from traditional discovery to agent-powered discovery requires platforms delivering deterministic, auditable answers grounded in validated context.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Agents without a governed context waste tokens searching and guessing before surfacing untrusted answers.&lt;/p&gt;&lt;p&gt;With proper context layers, agents reach the right answers faster from the start, eliminating guesswork loops wasting tokens.&amp;nbsp;&lt;/p&gt;&lt;p&gt;This efficiency translates to cost reduction as token usage drops and answer speed improves, benefiting both users and the economy.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Conclusion&lt;/h2&gt;&lt;p&gt;Enterprise AI deployments require more than sophisticated models and prompt engineering. They demand context platforms that unify fragmented metadata and knowledge into a single, governed source of truth.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Organizations implementing proper context management enable teams to deploy reliable agents at scale, reduce project failures, and realize true AI business value.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The future belongs to enterprises treating context management as infrastructure rather than documentation.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Frequently Asked Questions&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Q. What is a context platform, and how does it differ from a data catalog?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A.&lt;/b&gt; A data catalog indexes structured metadata about assets while delivering information through human portals.&amp;nbsp;&lt;/p&gt;&lt;p&gt;A context platform unifies that metadata with unstructured knowledge, including runbooks and glossaries, then serves both humans and AI agents from the same governed source.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Why do AI agents fail without proper context?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A.&lt;/b&gt; AI agents without trusted context waste tokens, hallucinate answers, and produce results users cannot verify.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Without deterministic answers grounded in a validated context, organizations cannot deploy agents to production where business decisions depend on reliability.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. How does Context Intelligence work?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A.&lt;/b&gt; Context Intelligence continuously analyzes query logs and dashboards to automatically extract metric definitions and operational rules without manual documentation.&amp;nbsp;&lt;/p&gt;&lt;p&gt;AI-generated context becomes a starting point for expert review rather than requiring creation from scratch.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Can agents pull context from multiple sources simultaneously?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A.&lt;/b&gt; Yes, context platforms integrate 100+ data sources, including Snowflake, Looker, dbt, Airflow, Notion, and Confluence, pulling metadata in real time.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Agents access unified context through single interfaces, whether using MCP, APIs, or SDKs.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. How quickly can organizations deploy agents after implementing context management?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A.&lt;/b&gt; Organizations using auto-generated context from existing query logs can enable production agent deployments within days because they start with validated context extracted from institutional knowledge rather than blank templates.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. What happens when a definition changes in DBT or business processes change?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A.&lt;/b&gt; Context platforms detect upstream changes automatically and route them to subject matter experts for validation.&amp;nbsp;&lt;/p&gt;&lt;p&gt;This ensures agents immediately access the latest definitions rather than operating on stale context.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7W8TcpPFfdtA1kZjKgvXiN1lDW7DunqIQYT1Uv7hgySgtXnwXkCGWJ9pVQnISAu7KH9Q6_hS41kr-s8Q64Vr7E79s7GCmgdyd4sJw465dvaVEccdDzNJ3-KWWJcEpA035b9MPS_vZqQAHv-HGbqVSJU27LKKGDZd4HggMmo38Wz4GucJqI1Mvrj6Qbo0/s72-c/ai-fact.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>PoC Exploit Released for Drupal's Critical SQL Injection CVE-2026-9082</title><link>https://www.cyberkendra.com/2026/05/poc-exploit-released-for-drupals.html</link><category>Drupal</category><category>Security</category><pubDate>Thu, 21 May 2026 22:28:15 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-5989485341691297262</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="SQL Injection in Drupal Core" border="0" data-original-height="1010" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhA2t-hzZEsbKHniC93VmzPPwFmk2TN1Ct-SobxZ5Lo1KnVcIB9U_1HxmNx4jQJV-ysIBFEiKAyX6rIDCdW2qxEiFTQQke6rSnr37_3sq83hmslKPHdsDTX3OzQn5etYe5a5QApeShqPyktOACakJ7oG3MvEi_DdLk72Q05X05z2J89ICY03ULM1Gqc3_A/s16000/drupal-sqli.png" title="SQL Injection in Drupal Core" /&gt;&lt;/div&gt;&lt;p&gt;A day after &lt;a href="https://www.cyberkendra.com/2026/05/drupal-patches-highly-critical-sql.html" target="_blank"&gt;Drupal's emergency patches landed&lt;/a&gt;, security researchers at Searchlight Cyber have published a full technical breakdown of CVE-2026-9082 — complete with two working proof-of-concept exploits. If your PostgreSQL-backed Drupal site isn't patched yet, consider this the final warning.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Drupal's database abstraction API exists for one reason: to sanitise queries and prevent SQL injection. The flaw is inside that very layer — specifically in the PostgreSQL-specific override that handles case-insensitive comparisons.&lt;/p&gt;&lt;p&gt;Researcher at &lt;a href="https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/" rel="nofollow" target="_blank"&gt;Searchlight Cyber shows&lt;/a&gt; that PostgreSQL is case-sensitive by default, so Drupal wraps query comparisons in a LOWER() function to normalise them. When processing an IN (...) list — say, matching a username against multiple values — it loops through each value and builds SQL placeholder names by combining a field prefix with an array key. The assumption was that those keys would always be sequential integers (0, 1, 2). They aren't.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://www.cyberkendra.com/2026/07/wp2shell-guide.html"&gt;WP2Shell (CVE-2026-63030): Checker, Patch &amp;amp; Detection Guide&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;If an attacker sends a JSON object instead of a plain string for the name field on the login endpoint, PHP decodes it into an associative array with attacker-controlled keys. Those keys land directly inside the SQL text before PDO (PHP's database layer) ever gets to bind and sanitise them. The fix? Three array_values() calls across three files — roughly seven lines of code — that forcibly reset array keys to sequential integers before they reach the vulnerable loop.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Two Entry Points, Both Unauthenticated&lt;/h3&gt;&lt;p&gt;Researchers confirmed two separate paths to trigger the injection:&lt;/p&gt;&lt;p&gt;&lt;b&gt;Variant 1 — &lt;/b&gt;JSON Login endpoint (/user/login?_format=json): An attacker sends the name field as a JSON object with an injected key containing a divide-by-zero subquery. When the boolean predicate is true, the server returns HTTP 500 with a SQLSTATE[22012] division-by-zero error. When false, it returns HTTP 400. That clean status-code split means an attacker can extract arbitrary database content one bit at a time — at scanning speeds. No session, no CSRF token, no credentials required.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Variant 2 — &lt;/b&gt;JSON:API filter parameters (/jsonapi/node/{bundle}): A single GET request with a backtick in a filter key is enough to produce a SQLSTATE[HY093] error on a vulnerable host. This variant doesn't even need a POST body — it's a one-shot fingerprinting probe that works against any publicly accessible node bundle. JSON:API isn't enabled by default, but it's a standard addition on API-driven Drupal deployments.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What's Actually at Risk&lt;/h3&gt;&lt;p&gt;Both exploit variants are fully anonymous — no account needed. On a vulnerable PostgreSQL-backed site, an attacker can quietly extract usernames, password hashes, private content, and any other data the database user can access. From there, privilege escalation and remote code execution are realistic next steps depending on the site configuration.&lt;/p&gt;&lt;p&gt;MySQL and SQLite installations are not reachable via these specific paths, but the same Drupal release bundle includes Symfony and Twig security fixes that apply to every backend — so there's no justification for skipping the update.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What You Should Do Right Now&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Update to the patched releases: Drupal 11.3.10, 11.2.12, 11.1.10 or Drupal 10.6.9, 10.5.10, 10.4.10&lt;/li&gt;&lt;li&gt;If you can't patch immediately, disable the JSON:API module to close Variant 2&lt;/li&gt;&lt;li&gt;Review which user roles can edit Twig templates — a separate exposure path flagged in the same advisory&lt;/li&gt;&lt;li&gt;Check server logs for unexpected HTTP 500 responses on /user/login or /jsonapi/ routes — that's your indicator of active scanning&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;With working exploits now public, automated scanning of Drupal installations has almost certainly already begun. The patch window is effectively closed.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhA2t-hzZEsbKHniC93VmzPPwFmk2TN1Ct-SobxZ5Lo1KnVcIB9U_1HxmNx4jQJV-ysIBFEiKAyX6rIDCdW2qxEiFTQQke6rSnr37_3sq83hmslKPHdsDTX3OzQn5etYe5a5QApeShqPyktOACakJ7oG3MvEi_DdLk72Q05X05z2J89ICY03ULM1Gqc3_A/s72-c/drupal-sqli.png" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Drupal Patches Highly Critical SQL Injection That Lets Anonymous Attackers Hijack PostgreSQL-Backed Sites</title><link>https://www.cyberkendra.com/2026/05/drupal-patches-highly-critical-sql.html</link><category>Drupal</category><category>Security</category><pubDate>Thu, 21 May 2026 00:29:13 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-9074516310879613360</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="CVE-2026-9082 - Drupal SQL Injection" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYmB8vsFk-8-SIe1gbYVNUCjxaUho69AYfhVYBM28rzCaDCHV9kRL9DnLGz5SUFy7HHCbAXAg4bhdTvngwmEKI4KV4mRGSna8qkHnyqQbHo7FCyiXeg1dvfA1bokbsdWZ_aTmYxKJOu5maFtr8RCU4JYwmy8yHAZJiaw4rxJQeLtYCbqqJnBRiejq_CwE/s16000/CVE-2026-9082.webp" title="CVE-2026-9082 - Drupal SQL Injection" /&gt;&lt;/div&gt;&lt;p&gt;Drupal has pushed emergency security updates for a highly critical SQL injection vulnerability in its core database abstraction layer — the kind of flaw that lets an unauthenticated attacker walk straight into your database without needing a username or password.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The vulnerability, tracked as &lt;b&gt;CVE-2026-9082 &lt;/b&gt;and disclosed under advisory &lt;a href="https://www.drupal.org/sa-core-2026-004" rel="nofollow" target="_blank"&gt;SA-CORE-2026-004&lt;/a&gt;, scores 20 out of 25 on Drupal's risk scale. That "Highly Critical" rating isn't an exaggeration: the scoring breakdown shows zero access complexity, no authentication required, and full confidentiality and integrity impact — meaning an attacker can read everything and modify anything.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://www.cyberkendra.com/2026/07/wp2shell-guide.html"&gt;WP2Shell (CVE-2026-63030): Checker, Patch &amp;amp; Detection Guide&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What's broken and why&lt;/h3&gt;&lt;p&gt;Drupal's database abstraction API is supposed to act as a safety net — a layer between PHP code and the database that automatically sanitizes queries to block injection attacks. But a flaw in this API allows specially crafted HTTP requests to slip past that sanitization entirely, enabling arbitrary SQL to execute directly against the database.&lt;/p&gt;&lt;p&gt;The vulnerability only affects sites running PostgreSQL databases, not MySQL or MariaDB backends. That's a narrowing factor, but PostgreSQL is common among enterprise Drupal deployments — government portals, university sites, and large media organizations frequently run it for performance and compliance reasons.&lt;/p&gt;&lt;p&gt;The consequences of successful exploitation range from &lt;b&gt;data exfiltration&lt;/b&gt; (leaking user records, private content, credentials) to &lt;b&gt;privilege escalation&lt;/b&gt; and, in some configurations, &lt;b&gt;remote code execution&lt;/b&gt; — full server takeover.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Broader blast radius: Symfony and Twig&lt;/h3&gt;&lt;p&gt;The patches do more than fix the SQL injection. The releases for all supported branches also bundle upstream security updates for Symfony and Twig, two PHP libraries that Drupal depends on heavily.&lt;/p&gt;&lt;p&gt;Drupal's advisory explicitly warns that depending on your site's configuration and installed modules, you may be independently vulnerable to those upstream issues — even if PostgreSQL isn't in the picture. All sites should update regardless.&lt;/p&gt;&lt;p&gt;The advisory specifically recommends reviewing which user roles have the ability to update Twig templates, for example through Views or contributed modules — a Twig template injection path could compound the risk significantly.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Who is affected and what to do&lt;/h3&gt;&lt;p&gt;Every supported Drupal branch is in scope: Drupal 10.4 through 11.3. The Drupal Security Team went further and issued best-effort patches for end-of-life Drupal 8 and 9 installations, acknowledging the severity warrants the exception — though those patches come without guarantees and those sites remain exposed to prior unpatched vulnerabilities.&lt;/p&gt;&lt;p&gt;Patched versions are:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Drupal 11: &lt;/b&gt;11.3.10, 11.2.12, 11.1.10&lt;/li&gt;&lt;li&gt;&lt;b&gt;Drupal 10: &lt;/b&gt;10.6.9, 10.5.10, 10.4.10&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Sites using Drupal Steward (Drupal's WAF-based protection service) are already shielded from known attack vectors, but should still upgrade promptly in case additional exploitation paths surface.&lt;/p&gt;&lt;p&gt;Two days before release, the Drupal Security Team issued an advance public notice — rare, and a signal of how seriously they treated this. The team explicitly warned that "exploits might be developed within hours or days" of the advisory going public, urging administrators to reserve time the same day patches dropped.&lt;/p&gt;&lt;p&gt;If your Drupal site runs PostgreSQL and hasn't been updated yet, that window is closing fast. Update now.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYmB8vsFk-8-SIe1gbYVNUCjxaUho69AYfhVYBM28rzCaDCHV9kRL9DnLGz5SUFy7HHCbAXAg4bhdTvngwmEKI4KV4mRGSna8qkHnyqQbHo7FCyiXeg1dvfA1bokbsdWZ_aTmYxKJOu5maFtr8RCU4JYwmy8yHAZJiaw4rxJQeLtYCbqqJnBRiejq_CwE/s72-c/CVE-2026-9082.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Critical WordPress Plugin Vulnerability Affects 2 Million Sites</title><link>https://www.cyberkendra.com/2025/02/critical-wordpress-plugin-vulnerability.html</link><category>Vulnerability</category><category>WordPress</category><pubDate>Thu, 27 Feb 2025 15:42:00 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-5896198238265543713</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="XSS on Essential Addons for Elementor" border="0" data-original-height="676" data-original-width="1260" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrWM_Tl2ydpqrT7JKTExliaqK4HJYAQz8hu748G_wPEADoUggYrY-pb8CV1rIDK-NnQ-433KwKARwp7y1gKxZTiEcXShMI8jZuBNAAAt53BpZZPgO4pnIX0E_aJuNj_mif9c9kNmJxXl_VR8OM-m4hmSHF6lVSuovisot9vqyq916oSas3nHgCujYkSvk/s16000/Essential%20Addons%20for%20Elementor.webp" title="XSS on Essential Addons for Elementor" /&gt;&lt;/div&gt;&lt;p&gt;A critical reflected cross-site scripting (XSS) vulnerability has been discovered in the Essential Addons for Elementor plugin, potentially affecting over two million WordPress websites. The security flaw, tracked as CVE-2025-24752, was reported by security researcher "xssium" through the Patchstack Alliance.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;According to the security &lt;a href="https://patchstack.com/articles/reflected-xss-patched-in-essential-addons-for-elementor-affecting-2-million-sites/" rel="nofollow" target="_blank"&gt;advisory&lt;/a&gt;, the vulnerability stems from improper sanitization of the 'popup-selector' query parameter in the plugin's &lt;code&gt;src/js/view/general.js&lt;/code&gt; file. The plugin would replace underscores with spaces but failed to sanitize other dangerous characters, allowing attackers to inject malicious JavaScript code that would execute in victims' browsers.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Vulnerable code" border="0" data-original-height="435" data-original-width="834" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhWEzjtOYIoi7baB01K0DZm2qkEuK7PjtVfvh6m06_pDWnpDIdFL6yWFI-FyB4qUf5sQgKXMdC7dS1mNojOMP9HEsifgHDeJ1YfW7G0vMZMJufHK9v5W9DCYNgE05S7k9Evulr3uV2xtAq7qfDWhfNnlOZYM5a0NKYaraMgAKoIXT85Qoa5BcWKS7eW-PU/s16000/code.webp" title="Vulnerable code" /&gt;&lt;/div&gt;&lt;p&gt;This high-severity vulnerability, with a CVSS score of 7.1, could lead to serious consequences if exploited, including session hijacking, phishing redirects, or unauthorized administrative access to affected sites.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://www.cyberkendra.com/2026/07/wp2shell-guide.html"&gt;WP2Shell (CVE-2026-63030): Checker, Patch &amp;amp; Detection Guide&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Essential Addons for Elementor is the most popular extension bundle for the Elementor page builder, providing WordPress site owners with over 100+ design elements like advanced data tables, WooCommerce integrations, and dynamic galleries. Its widespread adoption made it an attractive target for potential attackers.&lt;/p&gt;&lt;p&gt;The plugin's developer, WPDeveloper, addressed the vulnerability by releasing version 6.0.15. However, the Proof-of-Concept code for the flaw has also been released on &lt;a href="https://github.com/Sachinart/essential-addons-for-elementor-xss-poc" rel="nofollow" target="_blank"&gt;GitHub&lt;/a&gt;.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="PoC for CVE-2025-24752" border="0" data-original-height="332" data-original-width="1178" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3JhIthpWimQ76n_QtMnXiMbEnWIvTW49NO1EBD4ehymgL1oMCWRK8zQwBBPGMnxStaF2mwwQHpRtl2gkYNEwqwNGBxI80E4B0BpTYUu5nPttGY4A7dLxw5fY7XxDD2a2N4_EyozzBgpIi0XdeA275r8pANeu9N1nv7hmPCn5jy42oGXvgUSZeo6niHD4/s16000/poc.webp" title="PoC for CVE-2025-24752" /&gt;&lt;/div&gt;&lt;p&gt;WordPress site administrators using Essential Addons for Elementor are strongly advised to update to version 6.0.15 or later immediately.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrWM_Tl2ydpqrT7JKTExliaqK4HJYAQz8hu748G_wPEADoUggYrY-pb8CV1rIDK-NnQ-433KwKARwp7y1gKxZTiEcXShMI8jZuBNAAAt53BpZZPgO4pnIX0E_aJuNj_mif9c9kNmJxXl_VR8OM-m4hmSHF6lVSuovisot9vqyq916oSas3nHgCujYkSvk/s72-c/Essential%20Addons%20for%20Elementor.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Three Patches, Zero Fix: WordPress Cache Plugin's Persistent RCE Nightmare</title><link>https://www.cyberkendra.com/2025/12/three-patches-zero-fix-wordpress-cache.html</link><category>Security</category><category>WordPress</category><pubDate>Wed, 24 Dec 2025 22:41:00 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-628345799724604277</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="CVE-2025-9501" border="0" data-original-height="744" data-original-width="1200" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhht7RPg-H1ox_xPhAEXcpVPLU_3k11vsF6JztCMpzrDyP0DYm-DdHkow6E3jTXqVVkoKo4pgAKxDNaw5QC4QXMiHYz1P8QTaXoio66IeUMZFAB1wF9UR3iaeimWyV_oqlKWFDlgjGemkMCSqlYFrSRlMnKzkwFlRqBwy9Bjp-w0wfCzodW_gHkhpDEyX4/s16000/CVE-2025-9501.webp" title="CVE-2025-9501" /&gt;&lt;/div&gt;&lt;p&gt;Security researchers have uncovered a security bug with three successive patches for same vulnerability in W3 Total Cache—one of WordPress's most popular plugins—can all be bypassed using surprisingly simple techniques. The flaw (&lt;b&gt;CVE-2025-9501&lt;/b&gt;) threatens over one million websites with remote code execution, and the vendor's easy bypass fix it raises more concerns.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The vulnerability centers on W3 Total Cache's dynamic content processing, specifically in its &lt;code&gt;_parse_dynamic_mfunc&lt;/code&gt; function that uses PHP's &lt;code&gt;eval()&lt;/code&gt; to execute code embedded in cached page comments. When researcher "wcraft" first disclosed the flaw to WPScan, it affected all versions before 2.8.13 with a CVSS score of 9.0—categorized as critical.&lt;/p&gt;&lt;p&gt;But here's where things get messy. Security firm RCE Security decided to test the vendor's fixes and discovered what amounts to a patch security circus. Version 2.8.13's attempt to strip malicious tags failed because it used &lt;code&gt;str_replace&lt;/code&gt; after pattern matching—meaning attackers could embed the security token within itself (like "rcercesecsec" for a token "rcesec"). The &lt;code&gt;str_replace&lt;/code&gt; would reconstruct the valid token, making the exploit work again.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="https://www.cyberkendra.com/2026/07/wp2shell-guide.html"&gt;WP2Shell (CVE-2026-63030): Checker, Patch &amp;amp; Detection Guide&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Version 2.8.14 added more checks but left the same vulnerability intact. Version 2.8.15 tried a different approach, looking for whitespace after the &lt;code&gt;mfunc&lt;/code&gt; tag (&lt;code&gt;\s+&lt;/code&gt;). Clever, except the original vulnerable code uses &lt;code&gt;\s*&lt;/code&gt; (zero or more spaces). Removing the space between the tag and token—&lt;code&gt;&amp;lt;!--mfuncrcercesecsec--&amp;gt;&lt;/code&gt;—bypasses the 2.8.15 sanitization while still triggering code execution.&lt;/p&gt;&lt;p&gt;"We didn't believe that it was so easy to exploit," RCE Security researchers &lt;a href="https://www.rcesecurity.com/2025/11/exploiting-a-pre-auth-rce-in-w3-total-cache-for-wordpress-cve-2025-9501/" rel="nofollow" target="_blank"&gt;wrote&lt;/a&gt;, highlighting the gap between security advisories and exploitability reality.&lt;/p&gt;&lt;p&gt;The exploit requires specific conditions: attackers must know the site's &lt;code&gt;W3TC_DYNAMIC_SECURITY&lt;/code&gt; constant (a secret string administrators configure), comments must be enabled for unauthenticated users, and page caching must be active. While these requirements narrow the attack surface, they're common enough configurations to remain concerning—especially given the plugin's million-plus installation base.&lt;/p&gt;&lt;p&gt;WordPress administrators using W3 Total Cache should verify they're running the absolute latest version, audit their &lt;code&gt;W3TC_DYNAMIC_SECURITY&lt;/code&gt; constant for uniqueness, review security logs for suspicious comment activity since October 2025, and consider restricting comments to authenticated users only. With proof-of-concept exploits now public and three failed patches documented, attackers have a clear roadmap for exploitation.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhht7RPg-H1ox_xPhAEXcpVPLU_3k11vsF6JztCMpzrDyP0DYm-DdHkow6E3jTXqVVkoKo4pgAKxDNaw5QC4QXMiHYz1P8QTaXoio66IeUMZFAB1wF9UR3iaeimWyV_oqlKWFDlgjGemkMCSqlYFrSRlMnKzkwFlRqBwy9Bjp-w0wfCzodW_gHkhpDEyX4/s72-c/CVE-2025-9501.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Codex App Still Straining Mac SSDs Despite OpenAI Fix</title><link>https://www.cyberkendra.com/2026/07/codex-app-still-straining-mac-ssds.html</link><category>AI</category><category>Tips</category><pubDate>Mon, 20 Jul 2026 01:28:09 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-1994861723607288332</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Codex SSD Issue" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWjsuvo4uxO-IzMbAvg3jeOETz5lI-xkWSobQocY4CImRwvoCp3RD9RFpfR2trsiRwtlGtTmrJuKSaVz9fWT-AG-HQjN5ccUty61zR1Pjh3_vd1ETl5Ujexhnn31XRHFzGWwQ6EGukhYGqCJmEKvj-P7Fh0ru1tv_5TsM6-GZgDpLdadyTZNkava9V3UY/s1600/codex-ssd-issue.webp" title="Codex SSD Issue" /&gt;&lt;/div&gt;&lt;p&gt;Weeks after OpenAI declared victory over a logging bug that was chewing through developers' SSDs, Mac users say the Codex desktop app is still punishing their hardware — and this time, the symptoms go beyond disk writes.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;A &lt;a href="https://www.reddit.com/r/codex/comments/1v0m3lt/codex_is_wearing_out_our_devices/" rel="nofollow" target="_blank"&gt;post on r/codex&lt;/a&gt; that climbed past 100 upvotes over the weekend reports that running the Codex app causes system-wide lag on Macs that persists even after the app is closed, with a full restart being the only reliable fix. Crucially, the poster says the slowdown isn't explained by ordinary CPU or memory pressure — and when they asked Codex itself to diagnose the problem, the agent blamed its own "excessive I/O" and graphics work.&amp;nbsp;&lt;/p&gt;&lt;p&gt;A &lt;a href="https://www.reddit.com/r/codex/comments/1v033k6/is_the_codex_app_slowing_down_your_computer_or_is/?share_id=upMG1dJefA3DLIUNED-13&amp;amp;utm_content=1&amp;amp;utm_medium=android_app&amp;amp;utm_name=androidcss&amp;amp;utm_source=share&amp;amp;utm_term=1" rel="nofollow" target="_blank"&gt;second thread&lt;/a&gt; on the subreddit corroborates the pattern across multiple users, though the severity appears to vary from machine to machine.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;The bug OpenAI said it fixed&lt;/h2&gt;&lt;p&gt;The frustration traces back to June, when GitHub issue &lt;a href="https://github.com/openai/codex/issues/28224" rel="nofollow" target="_blank"&gt;#28224&lt;/a&gt; revealed that Codex's local diagnostic logger was writing at TRACE level (the noisiest possible verbosity) to a SQLite database at &lt;code&gt;~/.codex/logs_2.sqlite&lt;/code&gt;, ignoring the &lt;code&gt;RUST_LOG&lt;/code&gt; environment variable entirely.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Apache Flink PMC member Rui Fan measured the damage: "after about 21 days of uptime, the main SSD has written about 37 TB" — an extrapolated 640 TB per year, enough to burn through a typical consumer SSD's entire write-endurance warranty in under twelve months.&lt;/p&gt;&lt;p&gt;OpenAI shipped two fixes in the 0.142.0 release on June 22, cutting log volume by roughly 85% by the reporter's own measurement, with a third patch targeted at 0.143.0.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The issue was closed. Case apparently not closed: a follow-up report (issue #29876) filed just two days later documented a MacBook Air M4 still sustaining roughly 207 MB per minute of writes while Codex sat mostly idle, with a &lt;code&gt;code_sign_clone&lt;/code&gt; cache folder ballooning to 12 GB. On machines with soldered storage — which is every modern MacBook — that wear is permanent.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Why Macs lag even after Codex closes&lt;/h2&gt;&lt;p&gt;The persistent slowdown may have a separate culprit. GitHub issue #25719, still open since June 1, shows the Codex desktop app repeatedly triggering a runaway in macOS's own Gatekeeper daemon: &lt;code&gt;syspolicyd&lt;/code&gt; spiking to 125–200% CPU and swelling past 8 GB of RAM the moment Codex launches.&lt;/p&gt;&lt;p&gt;Because &lt;code&gt;syspolicyd&lt;/code&gt; is a system process that validates every app you open, a wedged instance keeps dragging the whole machine — even after Codex and its helper processes exit. That matches the Reddit reports almost exactly: lag that outlives the app and only clears on reboot.&lt;/p&gt;&lt;p&gt;The reporter verified that Codex's bundled "Computer Use" helper is properly signed and notarized, suggesting the fault lies in how the app repeatedly launches or re-validates its components — reportedly even when users disable those features in the config.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What Codex users should do now&lt;/h3&gt;&lt;p&gt;There are no confirmed cases of drives failing outright, but the wear is real and cumulative. Mac and Linux users can check lifetime writes with &lt;code&gt;smartctl -a /dev/nvme0n1&lt;/code&gt; (via Homebrew); Windows users can read "Total Host Writes" in CrystalDiskInfo.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Update to the latest Codex build to pick up the 0.142.x logging fixes, and if writes remain high, the community workaround still applies: symlink &lt;code&gt;~/.codex/logs_2.sqlite&lt;/code&gt; to a RAM-backed path so the churn never touches flash. Until OpenAI addresses the &lt;code&gt;syspolicyd&lt;/code&gt; interaction, users seeing post-Codex lag can quit the app and restart rather than fighting a wedged Gatekeeper.&lt;/p&gt;&lt;p&gt;OpenAI has not publicly commented on the renewed reports.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWjsuvo4uxO-IzMbAvg3jeOETz5lI-xkWSobQocY4CImRwvoCp3RD9RFpfR2trsiRwtlGtTmrJuKSaVz9fWT-AG-HQjN5ccUty61zR1Pjh3_vd1ETl5Ujexhnn31XRHFzGWwQ6EGukhYGqCJmEKvj-P7Fh0ru1tv_5TsM6-GZgDpLdadyTZNkava9V3UY/s72-c/codex-ssd-issue.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>15-Year-Old Nginx Vulnerability Exposes Critical RCE Flaw</title><link>https://www.cyberkendra.com/2026/07/15-year-old-nginx-vulnerability-exposes.html</link><category>Security</category><category>Vulnerability</category><pubDate>Mon, 20 Jul 2026 00:54:30 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-5606787685465678962</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Third nginx Script-Engine RCE" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGpFdxVWdlLBEP7E_ABAe8ZE-Vrg4xBBk-KkaDP7ZVMaV6yeUxRtKBbs1VkXRB6vdUgQmZYPrCnH1crteHqaoD1UfCaRXcHz-rpn85nD-32PSn6rhOffRjHU4xbTZOtVn-C-cVk9npkbYE9rf4P-ZmLpCCql27G4LWr8mDAg5-5QCxAfRITMo0Cz5vOMg/s1600/NGINX-FLAW.webp" title="Third nginx Script-Engine RCE" /&gt;&lt;/div&gt;&lt;p&gt;nginx just took its third critical hit in the same fragile corner of its codebase this year — and this one has been sitting there since 2011.&lt;/p&gt;&lt;p&gt;Tracked as&amp;nbsp;&lt;b&gt;CVE-2026-42533&lt;/b&gt; is a pre-authentication remote code execution flaw carrying a critical 9.2 CVSS v4.0 score. It affects the nginx open source from 0.9.6 through 1.30.3 (stable) and 1.31.2 (mainline), plus NGINX Plus R33–R36 and multiple 37.x builds. Fixes shipped in nginx 1.30.4, 1.31.3, and NGINX Plus R36 P7 / 37.0.3.1.&lt;/p&gt;&lt;p&gt;Researcher Stan Shaw (&lt;a href="https://cyberstan.co.uk/nginx-rce/" rel="nofollow" target="_blank"&gt;cyberstan&lt;/a&gt;) traced the bug to nginx's map directive when it uses regex matching (pattern-based text rules). The server evaluates certain expressions in two passes — one to measure the output size, one to write it — and both read the same shared capture array (r-&amp;gt;captures).&amp;nbsp;&lt;/p&gt;&lt;p&gt;When a regex map fires between the passes, it silently overwrites that array. The buffer gets sized for one value and filled with another, producing either a heap overflow stuffed with attacker-controlled bytes or an information leak that exposes memory pointers and defeats ASLR (a key anti-exploit defense) in a single request.&lt;/p&gt;&lt;p&gt;This is the third two-pass "measure then write" mismatch found in nginx's script engine in months — after &lt;b&gt;NGINX Rift &lt;/b&gt;(CVE-2026-42945), the &lt;a href="https://www.cyberkendra.com/2026/05/nginx-rift-18-year-old-bug-lets-hackers.html" target="_blank"&gt;18-year-old rewrite-module overflow&lt;/a&gt; that was later exploited in the wild, and &lt;a href="https://www.cyberkendra.com/2026/05/nginx-hit-by-second-unauthenticated-rce.html" target="_blank"&gt;&lt;b&gt;nginx-poolslip&lt;/b&gt; (CVE-2026-9256)&lt;/a&gt; days behind it.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Shaw explicitly frames CVE-2026-42533 as the same structural weakness, noting that, unlike Rift, his info-leak defeats ASLR without needing it disabled — and that Rift saw active exploitation soon after its PoC dropped.&lt;/p&gt;&lt;p&gt;The flawed pattern spans 13 separate code sites across nginx's HTTP and stream modules, and Shaw reports the chained exploit hit 10-out-of-10 reliability on Ubuntu 24.04 with full ASLR on. The behavior isn't even new: a 2014 nginx ticket flagged the capture-clobbering quirk, but nobody connected it to memory safety until now.&lt;/p&gt;&lt;p&gt;Admins should patch immediately. As a stopgap, &lt;a href="https://my.f5.com/manage/s/article/K000162097" rel="nofollow" target="_blank"&gt;F5 recommends&lt;/a&gt; named captures used within the same block as the regex match, and Shaw has released a config scanner to flag exposed setups. He's holding the full exploit for 21 days post-patch — deliberately, to buy defenders time.&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGpFdxVWdlLBEP7E_ABAe8ZE-Vrg4xBBk-KkaDP7ZVMaV6yeUxRtKBbs1VkXRB6vdUgQmZYPrCnH1crteHqaoD1UfCaRXcHz-rpn85nD-32PSn6rhOffRjHU4xbTZOtVn-C-cVk9npkbYE9rf4P-ZmLpCCql27G4LWr8mDAg5-5QCxAfRITMo0Cz5vOMg/s72-c/NGINX-FLAW.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>HuggingFace Breached by Autonomous AI Agent Swarm</title><link>https://www.cyberkendra.com/2026/07/huggingface-breached-by-autonomous-ai.html</link><category>Data Breached</category><category>Security</category><pubDate>Sat, 18 Jul 2026 21:05:09 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-8285960065069274247</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Hugging Face Hacked" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp_2wi-DYTLipYsQrw6I-t1sFzFSMXbvNqMy2RviHAdw6zPH8WlLIguyUQoYR1kp1vluA3q5GtOmDhoh72uqnpNX52HClHUwzZwZcHLsk5ow-mXhF4-FzxY5QWSks8Pv69EU9MtfLI75ef2e92QE7ivYbLoJ_nIqIN2kdOXkR5vtV0J-jUF6XHFN7CsDE/s1600/hugging-face-hack.webp" title="Hugging Face Hacked" /&gt;&lt;/div&gt;&lt;p&gt;Hugging Face has confirmed a security breach unlike anything the AI platform has faced before — an intrusion planned and executed end-to-end by an autonomous AI agent system, with no human operator visibly at the keyboard.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The company &lt;a href="https://huggingface.co/blog/security-incident-july-2026" rel="nofollow" target="_blank"&gt;disclosed this week&lt;/a&gt; that attackers gained unauthorised access to a limited set of internal datasets and service credentials after compromising its production infrastructure over a single weekend. Hugging Face says public models, datasets, Spaces, and its software supply chain were verified clean, though an assessment of potential partner and customer data exposure is still underway.&lt;/p&gt;&lt;p&gt;The entry point was the platform's own data-processing pipeline. A malicious dataset abused two code-execution flaws — a remote-code dataset loader and a template injection in a dataset configuration file — to run code on a processing worker.&amp;nbsp;&lt;/p&gt;&lt;p&gt;From there, the agent framework escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across several internal clusters, executing more than 17,000 recorded actions through a swarm of short-lived sandboxes with self-migrating command-and-control (C2) staged on public services. The underlying LLM powering the attack remains unidentified.&lt;/p&gt;&lt;p&gt;Ironically, the breach was caught by AI as well. Hugging Face's LLM-based triage system correlated anomalous telemetry signals and flagged the compromise, and the company then unleashed its own analysis agents on the full attacker action log — compressing days of forensic work into hours.&lt;/p&gt;&lt;p&gt;That forensic effort surfaced an uncomfortable asymmetry. When responders first fed real exploit payloads and C2 artifacts into frontier commercial models, safety guardrails blocked the requests, unable to distinguish an incident responder from an attacker. The team ultimately ran the investigation on GLM 5.2, an open-weight model hosted on its own infrastructure, which also prevented stolen credentials from leaving the environment. Hugging Face's advice to defenders: vet and stage a capable self-hosted model before an incident, not during one.&lt;/p&gt;&lt;p&gt;The company has patched the root vulnerabilities, rebuilt compromised nodes, rotated affected secrets, and notified law enforcement, with outside forensic specialists now reviewing its security posture.&lt;/p&gt;&lt;p&gt;Users are urged to rotate access tokens and review recent account activity.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp_2wi-DYTLipYsQrw6I-t1sFzFSMXbvNqMy2RviHAdw6zPH8WlLIguyUQoYR1kp1vluA3q5GtOmDhoh72uqnpNX52HClHUwzZwZcHLsk5ow-mXhF4-FzxY5QWSks8Pv69EU9MtfLI75ef2e92QE7ivYbLoJ_nIqIN2kdOXkR5vtV0J-jUF6XHFN7CsDE/s72-c/hugging-face-hack.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>WP2Shell: Critical WordPress Flaw Lets Anyone Run Code</title><link>https://www.cyberkendra.com/2026/07/wp2shell-critical-wordpress-flaw-lets.html</link><category>Security</category><category>Vulnerability</category><category>WordPress</category><pubDate>Sat, 18 Jul 2026 03:39:51 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-6678190317998417850</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="wp2shell - pre-authentication RCE in WordPress Core." border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-u2Uw5cvlxSlONe1zSIc16yIhHzUzD8zB6ewawIzGOm22QeDM9pR9ZzAQuK3t2M8mdGtkhW6Bc-Bm_W4YvaO5n6N0x6NBKv__WO-s4UXsdgvdT3B39bUr266kpfmkhYtjenagbHt9ImMRQA3VuDiGXS46HMTxfq3oo41PfxgGpC2mb-pR536IKT_miR0/s1600/wp2shell.webp" title="wp2shell - pre-authentication RCE in WordPress Core." /&gt;&lt;/div&gt;&lt;p&gt;WordPress does not force-push updates onto sites that have opted out of them. Doing so overrides an administrator's explicit choice, and the project treats it as a measure of last resort.&amp;nbsp;&lt;/p&gt;&lt;p&gt;On July 17, it did exactly that, shipping versions 7.0.2 and 6.9.5 and enabling forced auto-updates across affected installs to close a pre-authentication remote code execution flaw in core. That single decision says more about the bug's severity than any advisory has.&lt;/p&gt;&lt;p&gt;Tracked publicly as &lt;b&gt;wp2shell&lt;/b&gt;, the vulnerability requires no authentication, no plugins, and no non-default configuration. An anonymous HTTP request against a stock install is sufficient to achieve code execution on the underlying server — the worst outcome a web application can offer an attacker, reachable by anyone who can send a request.&lt;/p&gt;&lt;p&gt;The flaw was found by Adam Kues of Assetnote, the attack-surface-management arm of Searchlight Cyber, and reported through WordPress's HackerOne program.&amp;nbsp;&lt;/p&gt;&lt;p&gt;In its disclosure, the firm states the attack has "no preconditions and can be exploited by an anonymous user." Searchlight is deliberately withholding technical details to give defenders room to patch, and has instead published a checker at wp2shell.com so WordPress admin can test their own sites.&amp;nbsp;&lt;/p&gt;&lt;p&gt;At the time of writing, the site was unreachable with a 404 error.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Two bugs, chained&lt;/h3&gt;&lt;p&gt;&lt;b&gt;wp2shell &lt;/b&gt;is not one vulnerability but two, and their relationship is what makes it dangerous.&lt;/p&gt;&lt;p&gt;The first, &lt;b&gt;CVE-2026-60137&lt;/b&gt;, is an SQL injection in the &lt;code&gt;author__not_in&lt;/code&gt; parameter of &lt;code&gt;WP_Query&lt;/code&gt;, the core class that builds nearly every database query WordPress issues. It carries a CVSS base score of 9.1 (Critical) and is classified as CWE-89. It reaches back to WordPress 6.8, the widest exposure of the two. On its own, it is a data-integrity problem — serious, but bounded by what the database can be coerced into returning.&lt;/p&gt;&lt;p&gt;The second, &lt;b&gt;CVE-2026-63030&lt;/b&gt;, is a REST API batch-route confusion issue — an interpretation conflict (CWE-436) in the &lt;code&gt;/wp-json/batch/v1&lt;/code&gt; endpoint that has shipped with WordPress since version 5.6 in 2020. Its base score is 7.5 (High). This is the component that turns a confined injection into full compromise: routed through the batch endpoint on WordPress 6.9 and later, the SQL injection escalates to remote code execution.&lt;/p&gt;&lt;p&gt;There is a notable inconsistency in how the two are ranked. WordPress's GitHub advisories label the batch-route bug "Critical" and the injection "Moderate"; the CVSS scores assigned through NVD invert that order, making the injection the more critical of the pair. The disagreement reflects a genuine difference in what each party is measuring — chain potential versus standalone impact —, but for a site operator, it is academic. Both are patched in the same release, and the combined result is server compromise from an unauthenticated request.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Scale, and the limits of the scale&lt;/h3&gt;&lt;p&gt;Searchlight notes that WordPress runs on more than 500 million websites, and the platform accounts for roughly 40 percent of the web overall. Those figures describe the install base, not the exposed population, and the distinction matters.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The vulnerable code path only exists from WordPress 6.9 onward, and 6.9 shipped on December 2, 2025. Every affected site is therefore running a release less than eight months old — a meaningful constraint, though one offset by how aggressively WordPress users tend to stay current.&lt;/p&gt;&lt;p&gt;The affected and fixed versions are precise:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;6.9.0 – 6.9.4 are vulnerable to the RCE; fixed in 6.9.5.&lt;/li&gt;&lt;li&gt;7.0.0 – 7.0.1 are vulnerable to the RCE; fixed in 7.0.2.&lt;/li&gt;&lt;li&gt;7.1 beta is affected; fixed in 7.1 beta2.&lt;/li&gt;&lt;li&gt;6.8.x is exposed only to the SQL injection, not the RCE chain; fixed in 6.8.6.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Anything older than 6.8 is unaffected by either issue.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Response&lt;/h3&gt;&lt;p&gt;The priority is unambiguous: update to 7.0.2, or to 6.9.5 on the 6.9 branch. Operators should verify the running version in the dashboard rather than assume the forced push landed — WordPress has not confirmed whether the mechanism reaches sites with background updates fully disabled, and a forced update is only as good as the sites it actually touches.&lt;/p&gt;&lt;p&gt;Where an immediate update is not possible, every mitigation Searchlight offers reduces to the same principle: deny anonymous callers access to the batch endpoint. At the WAF layer, that means blocking both &lt;code&gt;/wp-json/batch/v1&lt;/code&gt; and the equivalent querystring route &lt;code&gt;rest_route=/batch/v1&lt;/code&gt; — a rule covering only the path leaves the second route open.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Alternatively, unauthenticated REST access can be disabled outright, or a must-use plugin can reject anonymous &lt;code&gt;/batch/v1&lt;/code&gt; requests at &lt;code&gt;rest_pre_dispatch&lt;/code&gt;. Each carries a cost to legitimate REST traffic and integrations, and none is a substitute for the patch.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;The window is closing on its own&lt;/h3&gt;&lt;p&gt;No exploitation had been observed as of July 18, and with technical details still private, broad scanning has yet to materialize. That quiet is temporary.&amp;nbsp;&lt;/p&gt;&lt;p&gt;WordPress core is open source; releases 7.0.1 and 7.0.2 both sit in the public archive, and comparing two versions is the standard route by which a silent patch is reverse-engineered into a working exploit.&lt;/p&gt;&lt;p&gt;Searchlight has demonstrated the pattern itself: when Drupal patched an analogous anonymous SQL injection in May, the firm converted the public fix into a same-day analysis with two functioning proofs of concept.&lt;/p&gt;&lt;p&gt;That is the structural bind of open-source security — a project cannot distribute the fix without also distributing the diff that points to the flaw. The only remaining variable is time: whether the patch reaches a given site before someone else reads the change.&amp;nbsp;&lt;/p&gt;&lt;p&gt;WordPress spent its most disruptive update mechanism to weigh that race in defenders' favor. Confirming the version on your own site is the last step you can't take.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-u2Uw5cvlxSlONe1zSIc16yIhHzUzD8zB6ewawIzGOm22QeDM9pR9ZzAQuK3t2M8mdGtkhW6Bc-Bm_W4YvaO5n6N0x6NBKv__WO-s4UXsdgvdT3B39bUr266kpfmkhYtjenagbHt9ImMRQA3VuDiGXS46HMTxfq3oo41PfxgGpC2mb-pR536IKT_miR0/s72-c/wp2shell.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Best Android Hacking Tools in 2026: The Ethical Hacker's Toolkit</title><link>https://www.cyberkendra.com/2014/04/best-10-android-tools-for-hacking.html</link><category>Android</category><category>Ethical hacking.</category><category>Learn</category><pubDate>Sun, 20 Apr 2014 14:07:00 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-2112839510559985253</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;img alt="Best Android Hacking Tools" border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYFPp31KEDONujmgslK5h42KHsPXrtcnxX__-rV98e7O2_J7_erQ5kml4EbirXoy-q5-DYojQRZts8rnRL4dFOoTSETk01uNMcnnx1efNSctDJQIiilFKrBhwYLGyR64YZR-LARC3niHs/s1600/Best+Android+Hacking+Tools.png" title="Best Android Hacking Tools" /&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;&lt;/p&gt;&lt;p&gt;Most "Android hacking tools" lists you'll find are one of two things: a decade-old copy-paste of zANTI and DroidSheep that no working professional has touched since 2016, or a thinly disguised advert for phone-spying apps that have nothing to do with security research.&lt;/p&gt;&lt;p&gt;This is neither. Below is the toolkit that people who actually assess Android apps for a living reach for in 2026 — organized the way a real engagement runs, from the moment you get a target APK to the point where you're staring at a native-code crash in a debugger. For each tool, you get what it does, why it earns its place, and how to get started.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;How a real Android assessment is structured&lt;/h2&gt;&lt;p&gt;Before the tool list, the mental model — because this is what separates a professional from someone who installed forty apps and learned nothing. A mobile security assessment moves through phases:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ol style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Static analysis — &lt;/b&gt;pull the app apart without running it. Decompile, read the code, hunt for hardcoded secrets and dangerous logic.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Dynamic analysis —&lt;/b&gt; run the app and manipulate it live. Hook functions, bypass protections, and watch what it does in memory.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Traffic interception — &lt;/b&gt;sits between the app and its servers, and reads every API call.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Vulnerability discovery — &lt;/b&gt;automated scanning and fuzzing to surface the bugs that manual review misses.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Native/deep research —&lt;/b&gt; reverse-engineer the C/C++ .so libraries where the serious memory-corruption bugs live.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Your toolkit maps onto these phases. Learn the phases and the tools make sense; skip them, and you're just clicking buttons.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Phase 0 — The environment&lt;/h2&gt;&lt;h3 style="text-align: left;"&gt;1. Termux&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: Terminal environment · &lt;b&gt;Root&lt;/b&gt;: No · &lt;b&gt;Cost&lt;/b&gt;: Free&lt;/p&gt;&lt;p&gt;Termux brings a real Linux command line to Android with a working package manager — no root needed. It's the foundation the rest of your on-device kit sits on. With pkg you can pull in nmap, sqlmap, hydra, Python, Git, and a Metasploit install, turning a phone into a genuinely capable field terminal.&lt;/p&gt;&lt;pre&gt;pkg update &amp;amp;&amp;amp; pkg upgrade
pkg install nmap python git openssh&lt;/pre&gt;&lt;p&gt;&lt;b&gt;Honest note: &lt;/b&gt;install it from F-Droid, not the Play Store — the Play Store build is frozen and years out of date. This is the single most common Termux mistake.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;2. Kali NetHunter&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: Full mobile pentest platform · &lt;b&gt;Root&lt;/b&gt;: Optional (rootless mode exists) · &lt;b&gt;Cost&lt;/b&gt;: Free · &lt;b&gt;Maintainer&lt;/b&gt;: Offensive Security&lt;/p&gt;&lt;p&gt;NetHunter is Kali Linux adapted for Android, and it comes in three flavors — full (rooted, custom kernel), Lite (rooted, generic), and rootless (no root at all), which is where most people should start. The rooted builds unlock the headline features: wireless frame injection, HID keyboard attacks, BadUSB, and a full Kali toolset with a KeX desktop.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Honest note:&lt;/b&gt; the marquee attacks (Wi-Fi injection, HID) need a supported device, a custom kernel, and often an external adapter. Rootless NetHunter is the sane on-ramp; don't brick your daily driver chasing frame injection on unsupported hardware.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Phase 1 — Static analysis&lt;/h2&gt;&lt;h3 style="text-align: left;"&gt;3. JADX&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: Decompiler · &lt;b&gt;Root&lt;/b&gt;: No · &lt;b&gt;Cost&lt;/b&gt;: Free&lt;/p&gt;&lt;p&gt;The gold standard for turning an APK back into readable Java. jadx-gui lets you browse decompiled source, search across the codebase, and cross-reference methods; the CLI is what you script. Its edge over other decompilers is how gracefully it handles obfuscated apps — where others produce garbage, JADX stays legible.&lt;/p&gt;&lt;p&gt;First move on almost any target: decompile, then grep for the secrets developers leave behind.&lt;/p&gt;&lt;pre&gt;# Decompile an APK to source
jadx -d output_dir/ target.apk

# Hunt for hardcoded secrets
grep -rE "api_key|password|secret|token|Bearer " output_dir/&lt;/pre&gt;&lt;h3 style="text-align: left;"&gt;4. apktool&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: Reverse-engineering / repackaging · &lt;b&gt;Root&lt;/b&gt;: No · &lt;b&gt;Cost&lt;/b&gt;: Free&lt;/p&gt;&lt;p&gt;Where JADX gives you Java to read, apktool gives you smali — the bytecode Android actually runs — to modify. It decodes resources and the manifest, lets you patch behavior at the smali level, and rebuilds a signed APK you can reinstall for testing. Essential whenever you need to change what an app does, rather than just observe it.&lt;/p&gt;&lt;pre&gt;apktool d target.apk -o decoded/
# edit smali, then rebuild:
apktool b decoded/ -o modified.apk&lt;/pre&gt;&lt;h3 style="text-align: left;"&gt;5. MobSF (Mobile Security Framework)&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: Automated static + dynamic analysis · &lt;b&gt;Root&lt;/b&gt;: No · &lt;b&gt;Cost&lt;/b&gt;: Free&lt;/p&gt;&lt;p&gt;MobSF is your rapid first pass. Drop in an APK (or IPA), and it produces a full report — permissions, exported components, hardcoded secrets, insecure crypto, manifest issues — in minutes, and it plugs into CI/CD for DevSecOps pipelines.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Honest note:&lt;/b&gt; automated scanners find the low-hanging fruit and miss the serious logic bugs. Use MobSF to build a fast picture of a new target, then follow up manually on what it flags. It's a starting point, not a verdict.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Phase 2 — Dynamic analysis&lt;/h2&gt;&lt;h3 style="text-align: left;"&gt;6. Frida&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: Runtime instrumentation · &lt;b&gt;Root&lt;/b&gt;: Optional · &lt;b&gt;Cost&lt;/b&gt;: Free&lt;/p&gt;&lt;p&gt;If you learn one tool on this list, learn Frida. It injects JavaScript into a running app so you can hook any function, read and rewrite return values, dump memory, and defeat runtime protections live. SSL-pinning bypass, root-detection bypass, function tracing — Frida is how it's done, and fluency with it is effectively the dividing line between hobbyist and professional.&lt;/p&gt;&lt;pre&gt;// Classic SSLContext bypass to unpin an app
Java.perform(function () {
  var SSLContext = Java.use("javax.net.ssl.SSLContext");
  SSLContext.init.overload(
    "[Ljavax.net.ssl.KeyManager;",
    "[Ljavax.net.ssl.TrustManager;",
    "java.security.SecureRandom"
  ).implementation = function (km, tm, sr) {
    this.init(km, null, sr); // trust everything (lab use only)
  };
});&lt;/pre&gt;&lt;h3 style="text-align: left;"&gt;7. Objection&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: Frida-powered exploration toolkit · &lt;b&gt;Root&lt;/b&gt;: No · &lt;b&gt;Cost&lt;/b&gt;: Free&lt;/p&gt;&lt;p&gt;Objection is Frida with the common tasks pre-written. Point it at an app, and you get SSL-pinning bypass, root-detection bypass, filesystem enumeration, and activity launching from a clean command line — no custom scripts required. It's the fastest way to get your bearings on a new target before you write bespoke Frida hooks.&lt;/p&gt;&lt;pre&gt;objection -g com.target.app explore
# then, inside objection:
android sslpinning disable
android hooking list activities&lt;/pre&gt;&lt;h2 style="text-align: left;"&gt;Phase 3 — Traffic interception&lt;/h2&gt;&lt;h3 style="text-align: left;"&gt;8. Burp Suite&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: HTTP(S) intercepting proxy · &lt;b&gt;Root&lt;/b&gt;: No (cert install needed) · &lt;b&gt;Cost&lt;/b&gt;: Free tier + Commercial&lt;/p&gt;&lt;p&gt;Burp is the standard for reading and modifying an app's network traffic. Route the device's Wi-Fi through Burp, install its CA certificate, and every API call — headers, bodies, tokens — is laid bare. When an app pins its certificate, pair Burp with Objection or a Frida unpinning script to get through.&lt;/p&gt;&lt;p&gt;Workflow: device Wi-Fi proxy → Burp → install Burp CA → bypass pinning with Frida/Objection → intercept.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;9. Wireshark + tcpdump&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: Packet analysis · &lt;b&gt;Root&lt;/b&gt;: Yes (for live capture) · &lt;b&gt;Cost&lt;/b&gt;: Free&lt;/p&gt;&lt;p&gt;For traffic below the HTTP layer, you capture with tcpdump on a rooted device (or PCAP-Droid without root) and analyze in Wireshark. This is how you inspect non-HTTP protocols, spot cleartext leaks, and understand exactly what a device is emitting on the wire.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Phase 4 — Vulnerability discovery &amp;amp; native research&lt;/h2&gt;&lt;h3 style="text-align: left;"&gt;10. Drozer&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: IPC / attack-surface assessment · &lt;b&gt;Root&lt;/b&gt;: No · &lt;b&gt;Cost&lt;/b&gt;: Free&lt;/p&gt;&lt;p&gt;Drozer probes an app's exported components — Activities, Services, Broadcast Receivers, Content Providers — the IPC surface that's a perennial source of real Android vulnerabilities. It's one of the very few tools that tests component exposure with precision, and after years of neglect, it has active community maintenance again.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;11. Ghidra&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: Native reverse engineering · &lt;b&gt;Root&lt;/b&gt;: No · &lt;b&gt;Cost&lt;/b&gt;: Free · &lt;b&gt;Maintainer&lt;/b&gt;: NSA (open-source)&lt;/p&gt;&lt;p&gt;When the interesting logic lives in a native &lt;code&gt;.so&lt;/code&gt; library, Ghidra is the free answer. Extract the libraries from the APK, load them, find the JNI exports (they begin with &lt;code&gt;Java_&lt;/code&gt;), and read the disassembly to understand what native code really does.&lt;/p&gt;&lt;pre&gt;unzip target.apk -d extracted/
ls extracted/lib/arm64-v8a/*.so   # load these in Ghidra&lt;/pre&gt;&lt;h3 style="text-align: left;"&gt;12. AFL++ (American Fuzzy Lop++)&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: Coverage-guided fuzzer · &lt;b&gt;Root&lt;/b&gt;: No · &lt;b&gt;Cost&lt;/b&gt;: Free&lt;/p&gt;&lt;p&gt;AFL++ is the state of the art for finding memory-corruption bugs in native code. You write a small harness that feeds fuzzer-generated input to a target function, then let it run for hours, automatically discovering crashes — each one a potential vulnerability. This is the tool behind a large share of high-severity Android CVEs in media parsers and image decoders.&lt;/p&gt;&lt;pre&gt;afl-fuzz -i input_corpus/ -o findings/ -m none -- ./harness @@&lt;/pre&gt;&lt;h3 style="text-align: left;"&gt;13. GDB / LLDB with pwndbg&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Category&lt;/b&gt;: Native debugger · &lt;b&gt;Root&lt;/b&gt;: Yes · &lt;b&gt;Cost&lt;/b&gt;: Free&lt;/p&gt;&lt;p&gt;When AFL++ hands you a crash, a debugger tells you whether it's exploitable. GDB with the pwndbg extension lets you reproduce the crash, inspect registers and memory at the fault, and classify the root cause — out-of-bounds write, use-after-free, and so on.&lt;/p&gt;&lt;pre&gt;adb forward tcp:1234 tcp:1234
gdbserver :1234 --attach $(pidof target_process)
# on host: gdb-multiarch target.so → target remote :1234&lt;/pre&gt;&lt;h3 style="text-align: left;"&gt;Quick comparison&lt;/h3&gt;&lt;div class="table noWrap w100"&gt;&lt;table border="1" cellpadding="8" cellspacing="0"&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;&lt;strong&gt;Tool&lt;/strong&gt;&lt;/th&gt;
      &lt;th&gt;&lt;strong&gt;Phase&lt;/strong&gt;&lt;/th&gt;
      &lt;th&gt;&lt;strong&gt;Root Required&lt;/strong&gt;&lt;/th&gt;
      &lt;th&gt;&lt;strong&gt;Cost&lt;/strong&gt;&lt;/th&gt;
      &lt;th&gt;&lt;strong&gt;Best For&lt;/strong&gt;&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;Termux&lt;/td&gt;
      &lt;td&gt;Environment&lt;/td&gt;
      &lt;td&gt;No&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;On-device Linux terminal&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Kali NetHunter&lt;/td&gt;
      &lt;td&gt;Platform&lt;/td&gt;
      &lt;td&gt;Optional&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;Full mobile pentest suite&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;JADX&lt;/td&gt;
      &lt;td&gt;Static&lt;/td&gt;
      &lt;td&gt;No&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;Decompiling APKs to Java&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;apktool&lt;/td&gt;
      &lt;td&gt;Static&lt;/td&gt;
      &lt;td&gt;No&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;Patching &amp;amp; repackaging&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;MobSF&lt;/td&gt;
      &lt;td&gt;Static / Dynamic&lt;/td&gt;
      &lt;td&gt;No&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;Fast automated overview&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Frida&lt;/td&gt;
      &lt;td&gt;Dynamic&lt;/td&gt;
      &lt;td&gt;Optional&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;Runtime hooking, unpinning&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Objection&lt;/td&gt;
      &lt;td&gt;Dynamic&lt;/td&gt;
      &lt;td&gt;No&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;Zero-script exploration&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Burp Suite&lt;/td&gt;
      &lt;td&gt;Traffic&lt;/td&gt;
      &lt;td&gt;No&lt;/td&gt;
      &lt;td&gt;Free + Paid&lt;/td&gt;
      &lt;td&gt;HTTP(S) interception&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Wireshark / tcpdump&lt;/td&gt;
      &lt;td&gt;Traffic&lt;/td&gt;
      &lt;td&gt;Yes&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;Packet-level analysis&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Drozer&lt;/td&gt;
      &lt;td&gt;Vulnerability Discovery&lt;/td&gt;
      &lt;td&gt;No&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;IPC attack surface analysis&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Ghidra&lt;/td&gt;
      &lt;td&gt;Native&lt;/td&gt;
      &lt;td&gt;No&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;.so reverse engineering&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;AFL++&lt;/td&gt;
      &lt;td&gt;Native&lt;/td&gt;
      &lt;td&gt;No&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;Fuzzing native code&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;GDB / pwndbg&lt;/td&gt;
      &lt;td&gt;Native&lt;/td&gt;
      &lt;td&gt;Yes&lt;/td&gt;
      &lt;td&gt;Free&lt;/td&gt;
      &lt;td&gt;Crash triage&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;&lt;h2 style="text-align: left;"&gt;How to build your setup (learning path)&lt;/h2&gt;&lt;p&gt;You don't install all thirteen on day one. Layer them:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ol style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Week 1 — foundations: &lt;/b&gt;Termux + JADX + Frida + Burp Suite. This covers static reading, live hooking, and traffic — the core loop of every assessment.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Week 4 — broaden: &lt;/b&gt;add Objection, MobSF, and apktool for faster exploration and repackaging.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Going deeper — native work:&lt;/b&gt; Ghidra, AFL++, and GDB/pwndbg when you're ready to research native libraries.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Practice legally:&lt;/b&gt; never on live third-party apps. Use deliberately vulnerable targets — &lt;b&gt;DIVA, InsecureBankv2, OWASP MASTG&lt;/b&gt; crackmes — and platforms like TryHackMe or Hack The Box.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Defending against these tools&lt;/h3&gt;&lt;p&gt;If these tools can pull secrets out of your app, here's how to make that hard:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Certificate pinning &lt;/b&gt;raises the bar for traffic interception (though Frida can defeat it, it stops casual attackers).&lt;/li&gt;&lt;li&gt;&lt;b&gt;Root and tamper detection&lt;/b&gt; with response logic — but assume a determined researcher bypasses it and don't rely on it alone.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Never hardcode secrets&lt;/b&gt; in the APK. JADX + grep finds them in seconds. Use a backend, short-lived tokens, and server-side checks.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Obfuscate &lt;/b&gt;with R8/ProGuard to slow static analysis.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Minimize exported components&lt;/b&gt; and validate every incoming Intent — this shuts down the Drozer attack surface.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Keep native code memory-safe&lt;/b&gt; and patched; that's where AFL++ finds the severe bugs.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Frequently asked questions&lt;/h2&gt;&lt;p&gt;&lt;b&gt;Q. Are Android hacking tools legal to use?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;The tools are legal to own and run. Using them against apps, devices, or networks you don't own or have written permission to test is illegal — in India under the IT Act, 2000, and under equivalent computer-misuse laws elsewhere. Learn on your own devices and on deliberately vulnerable practice apps.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Do I need to root my phone?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;For a lot of modern work, no. Termux, JADX, MobSF, Objection, and rootless NetHunter run unrooted. Rooting unlocks deeper capability — live packet capture, some Frida scenarios, HID attacks — but start rootless and add root only when a specific task demands it.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. What's the best Android hacking tool for beginners?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;Start with Frida and JADX. JADX teaches you to read what an app is doing; Frida teaches you to change it at runtime. Together, they underpin most real assessments, and both are free.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Is Termux a hacking tool?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;Termux is a terminal emulator — a Linux environment on Android. It becomes a security toolkit only when you install packages like nmap or Metasploit into it. On its own, it's a legitimate developer tool used far more for scripting and SSH than for anything security-related.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Which of these do professionals actually use in 2026?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;The daily-driver core is JADX, Frida, Burp Suite, and Objection, with Ghidra, AFL++, and GDB/pwndbg for native research. Older network apps like zANTI and DroidSheep still appear on legacy lists but have largely fallen out of professional use.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Can these tools hack WhatsApp / Instagram / someone's phone remotely?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;No — and that framing is exactly what the spyware "hire a hacker" scams exploit. These are assessment tools for apps and devices you control. Anything promising remote account takeover of someone else's phone is a scam, malware, or a crime. Don't.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;The bottom line&lt;/h3&gt;&lt;p&gt;&amp;nbsp;The 2026 toolkit is a workflow: read the app (JADX, apktool, MobSF), manipulate it live (Frida, Objection), watch its traffic (Burp, Wireshark), and hunt real bugs (Drozer, Ghidra, AFL++). Learn the phases, practice on legal targets, and keep the framing straight — everything here is for building things that are harder to break.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;

</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYFPp31KEDONujmgslK5h42KHsPXrtcnxX__-rV98e7O2_J7_erQ5kml4EbirXoy-q5-DYojQRZts8rnRL4dFOoTSETk01uNMcnnx1efNSctDJQIiilFKrBhwYLGyR64YZR-LARC3niHs/s72-c/Best+Android+Hacking+Tools.png" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">14</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Best Bottleneck Calculators for PC in 2026 — Tested</title><link>https://www.cyberkendra.com/2023/08/best-bottleneck-calculator-tools-for-pc.html</link><category>Tech</category><category>Tips</category><category>Tools</category><pubDate>Mon, 14 Aug 2023 01:23:00 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-7028613460782374151</guid><description>&lt;p&gt;&lt;/p&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
  &lt;img alt="Best Bottleneck Calculators for PC" border="0" data-original-height="1024" data-original-width="1386" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhRm-NFkh3UtzIig9c9rWWAFRwa1gzzqigT_9M7HVLicQFlN-aaR0NIbQSZTrMaOcF5Iq_6JMwlZwBtD-ENl0fjs-9sO1wkYW3Ig44tE68WdvpMlWkB5lJ4KIxZ6msYaeJl_1nySRCas8eKFdiT3daq-BmA_PfyJ1_fNGyzqjOgEiz2s3rcM3tD2xofaNE/s16000/Bottleneck-calculator.webp" title="Best Bottleneck Calculators for PC" /&gt;
&lt;/div&gt;
&lt;p&gt;
  Every few months, someone posts a build on Reddit asking why their RTX 5070 is
  only pulling 90 FPS in a game that should run at 140. The replies arrive
  within minutes: bottleneck. Run a calculator. Upgrade your CPU.
&lt;/p&gt;
&lt;p&gt;
  Then they run three different bottleneck calculators and get three different
  answers — 4%, 18%, and "severe CPU bottleneck, upgrade immediately." All from
  the same hardware.
&lt;/p&gt;
&lt;p&gt;
  That inconsistency isn't a bug in one bad tool. It's the whole category
  telling you something about how it works. This guide covers which bottleneck
  calculators are actually worth your time, why their numbers disagree so
  wildly, and — more usefully — how to find your real bottleneck in about ninety
  seconds without any calculator at all.
&lt;/p&gt;
&lt;h2 style="text-align: left;"&gt;What a PC bottleneck actually is&lt;/h2&gt;
&lt;p&gt;
  A bottleneck is when one component finishes its work and then waits for
  another. That's it. Your CPU prepares draw calls and hands them to the GPU; if
  the CPU can't prepare them fast enough, the GPU sits idle at 60% utilisation
  while your frame rate flatlines. Reverse it, and the GPU is pinned at 100%
  while the CPU coasts.
&lt;/p&gt;
&lt;p&gt;
  Two things follow from this that most guides skip, and they matter more than
  any calculator output:
&lt;/p&gt;
&lt;p&gt;
  &lt;b&gt;A bottleneck is not a defect. &lt;/b&gt;Every system has one. If nothing were the
  limiting factor, your frame rate would be infinite. A GPU pinned at 99% in a
  demanding game isn't a problem — that's what you paid for. You're getting
  everything the card can give.
&lt;/p&gt;
&lt;p&gt;
  &lt;b&gt;A bottleneck is not a property of your hardware.&lt;/b&gt; It's a property of
  your hardware running a specific workload at a specific resolution. The same
  Ryzen 5 7600 and RTX 5080 pairing will be CPU-limited in Counter-Strike 2 at
  1080p and GPU-limited in Cyberpunk 2077 at 4K with ray tracing. Nothing about
  the parts changed. Only the job did.
&lt;/p&gt;
&lt;p&gt;
  This second point is the reason bottleneck calculators struggle. A single
  percentage cannot describe a value that changes with every game you launch and
  every setting you touch.
&lt;/p&gt;&lt;p&gt;&lt;p&gt;You can use our tool to check the bottleneck.&lt;/p&gt;&lt;p&gt;
&lt;div id="ck-bottleneck-calc"&gt;
  &lt;style&gt;
    #ck-bottleneck-calc {
      --ck-accent: #e02d2d;          /* CyberKendra red — change to match brand exactly */
      --ck-accent-dark: #b71f1f;
      --ck-ink: #14181f;
      --ck-ink-soft: #4a5361;
      --ck-line: #e4e7ec;
      --ck-bg: #ffffff;
      --ck-bg-soft: #f6f8fa;
      --ck-cpu: #2563eb;
      --ck-gpu: #16a34a;
      --ck-warn: #d97706;
      --ck-good: #16a34a;
      --ck-mid: #d97706;
      --ck-bad: #dc2626;
      --ck-radius: 12px;
      --ck-font: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Helvetica, Arial, sans-serif;

      max-width: 760px;
      margin: 24px auto;
      font-family: var(--ck-font);
      color: var(--ck-ink);
      background: var(--ck-bg);
      border: 1px solid var(--ck-line);
      border-radius: var(--ck-radius);
      overflow: hidden;
      box-shadow: 0 1px 2px rgba(16,24,40,.04), 0 8px 24px rgba(16,24,40,.05);
      -webkit-font-smoothing: antialiased;
    }
    #ck-bottleneck-calc * { box-sizing: border-box; }

    .ckb-head {
      background: linear-gradient(180deg, #1a1f28 0%, #14181f 100%);
      color: #fff;
      padding: 22px 24px 20px;
    }
    .ckb-head h2 {
      margin: 0;
      font-size: 20px;
      font-weight: 700;
      letter-spacing: -.01em;
      display: flex;
      align-items: center;
      gap: 9px;
      color: white;
    }
    .ckb-dot {
      width: 9px; height: 9px; border-radius: 50%;
      background: var(--ck-accent);
      box-shadow: 0 0 0 4px rgba(224,45,45,.18);
      flex: none;
    }
    .ckb-head p { margin: 7px 0 0; font-size: 13px; color: #aab3c0; line-height: 1.5; }

    .ckb-body { padding: 22px 24px; }

    .ckb-grid {
      display: grid;
      grid-template-columns: 1fr 1fr;
      gap: 14px 18px;
    }
    .ckb-field { display: flex; flex-direction: column; gap: 6px; }
    .ckb-field.full { grid-column: 1 / -1; }
    .ckb-field label {
      font-size: 12px; font-weight: 600; text-transform: uppercase;
      letter-spacing: .04em; color: var(--ck-ink-soft);
    }
    .ckb-field select {
      appearance: none; -webkit-appearance: none;
      width: 100%; padding: 11px 38px 11px 13px;
      font-size: 14px; font-family: inherit; color: var(--ck-ink);
      background: var(--ck-bg) url("data:image/svg+xml;utf8,&lt;svg xmlns='http://www.w3.org/2000/svg' width='12' height='12' viewBox='0 0 12 12'&gt;&lt;path d='M2 4l4 4 4-4' stroke='%234a5361' stroke-width='1.6' fill='none' stroke-linecap='round' stroke-linejoin='round'/&gt;&lt;/svg&gt;") no-repeat right 13px center;
      border: 1px solid var(--ck-line);
      border-radius: 9px;
      cursor: pointer;
      transition: border-color .15s, box-shadow .15s;
    }
    .ckb-field select:hover { border-color: #c8cdd6; }
    .ckb-field select:focus-visible {
      outline: none; border-color: var(--ck-accent);
      box-shadow: 0 0 0 3px rgba(224,45,45,.15);
    }

    .ckb-toggles {
      grid-column: 1 / -1;
      display: flex; flex-wrap: wrap; gap: 8px;
      padding-top: 2px;
    }
    .ckb-chip {
      display: inline-flex; align-items: center; gap: 7px;
      padding: 8px 13px; font-size: 13px; font-weight: 500;
      border: 1px solid var(--ck-line); border-radius: 999px;
      background: var(--ck-bg-soft); cursor: pointer;
      user-select: none; transition: all .15s;
    }
    .ckb-chip input { position: absolute; opacity: 0; pointer-events: none; }
    .ckb-chip .ckb-box {
      width: 15px; height: 15px; border-radius: 4px;
      border: 1.5px solid #b6bdc8; flex: none;
      display: grid; place-items: center; transition: all .15s;
    }
    .ckb-chip .ckb-box svg { width: 9px; height: 9px; opacity: 0; transition: opacity .12s; }
    .ckb-chip.on { border-color: var(--ck-accent); background: rgba(224,45,45,.06); color: var(--ck-accent-dark); }
    .ckb-chip.on .ckb-box { background: var(--ck-accent); border-color: var(--ck-accent); }
    .ckb-chip.on .ckb-box svg { opacity: 1; }

    .ckb-upscale-row { grid-column: 1/-1; display: none; }
    .ckb-upscale-row.show { display: flex; }

    .ckb-cta {
      grid-column: 1 / -1;
      margin-top: 4px;
      display: flex; gap: 10px; align-items: center;
    }
    .ckb-btn {
      flex: 1;
      padding: 13px 18px; font-size: 15px; font-weight: 600;
      font-family: inherit; color: #fff;
      background: var(--ck-accent); border: none; border-radius: 9px;
      cursor: pointer; transition: background .15s, transform .05s;
    }
    .ckb-btn:hover { background: var(--ck-accent-dark); }
    .ckb-btn:active { transform: translateY(1px); }
    .ckb-btn:focus-visible { outline: 3px solid rgba(224,45,45,.35); outline-offset: 2px; }
    .ckb-reset {
      padding: 13px 16px; font-size: 14px; font-weight: 500;
      font-family: inherit; color: var(--ck-ink-soft);
      background: transparent; border: 1px solid var(--ck-line);
      border-radius: 9px; cursor: pointer; transition: all .15s;
    }
    .ckb-reset:hover { border-color: #c8cdd6; color: var(--ck-ink); }

    /* Result */
    .ckb-result { margin-top: 22px; display: none; }
    .ckb-result.show { display: block; animation: ckbFade .3s ease; }
    @keyframes ckbFade { from { opacity: 0; transform: translateY(6px); } to { opacity: 1; transform: none; } }

    .ckb-verdict {
      display: flex; align-items: baseline; gap: 12px;
      padding: 18px 20px; border-radius: 10px;
      border: 1px solid var(--ck-line); background: var(--ck-bg-soft);
    }
    .ckb-pct { font-size: 34px; font-weight: 800; line-height: 1; letter-spacing: -.02em; }
    .ckb-verdict-txt { flex: 1; }
    .ckb-verdict-txt strong { display: block; font-size: 15px; margin-bottom: 2px; }
    .ckb-verdict-txt span { font-size: 13px; color: var(--ck-ink-soft); line-height: 1.5; }
    .ckb-pill {
      font-size: 11px; font-weight: 700; text-transform: uppercase; letter-spacing: .04em;
      padding: 4px 9px; border-radius: 6px; color: #fff; white-space: nowrap;
    }

    .ckb-bars { margin-top: 16px; display: flex; flex-direction: column; gap: 12px; }
    .ckb-bar-row { }
    .ckb-bar-label {
      display: flex; justify-content: space-between; font-size: 12px;
      font-weight: 600; margin-bottom: 5px; color: var(--ck-ink-soft);
    }
    .ckb-bar-track { height: 10px; background: #eef1f5; border-radius: 999px; overflow: hidden; }
    .ckb-bar-fill { height: 100%; border-radius: 999px; width: 0; transition: width .6s cubic-bezier(.4,0,.2,1); }

    .ckb-notes { margin-top: 16px; display: flex; flex-direction: column; gap: 8px; }
    .ckb-note {
      display: flex; gap: 10px; font-size: 13px; line-height: 1.55;
      padding: 11px 13px; border-radius: 9px; background: var(--ck-bg-soft);
      border: 1px solid var(--ck-line);
    }
    .ckb-note .ckb-ni { flex: none; font-size: 15px; line-height: 1.35; }
    .ckb-note.warn { background: #fff8ee; border-color: #fde4bf; }
    .ckb-note.warn .ckb-ni { color: var(--ck-warn); }

    /* Methodology disclosure — the trust differentiator */
    .ckb-method { margin-top: 18px; border-top: 1px solid var(--ck-line); padding-top: 14px; }
    .ckb-method summary {
      cursor: pointer; font-size: 13px; font-weight: 600; color: var(--ck-ink-soft);
      list-style: none; display: flex; align-items: center; gap: 7px;
    }
    .ckb-method summary::-webkit-details-marker { display: none; }
    .ckb-method summary::before {
      content: "+"; font-size: 15px; font-weight: 700; color: var(--ck-accent);
      width: 16px; text-align: center;
    }
    .ckb-method[open] summary::before { content: "\2212"; }
    .ckb-method .ckb-method-body {
      font-size: 13px; line-height: 1.65; color: var(--ck-ink-soft);
      padding: 12px 2px 2px;
    }
    .ckb-method .ckb-method-body p { margin: 0 0 9px; }
    .ckb-method .ckb-method-body strong { color: var(--ck-ink); }

    .ckb-foot {
      padding: 13px 24px; font-size: 12px; color: var(--ck-ink-soft);
      background: var(--ck-bg-soft); border-top: 1px solid var(--ck-line);
      line-height: 1.5;
    }
    .ckb-foot b { color: var(--ck-ink); }

    @media (max-width: 560px) {
      .ckb-grid { grid-template-columns: 1fr; }
      .ckb-verdict { flex-direction: column; align-items: flex-start; gap: 8px; }
    }
    @media (prefers-reduced-motion: reduce) {
      #ck-bottleneck-calc *, #ck-bottleneck-calc *::before { transition: none !important; animation: none !important; }
    }
  &lt;/style&gt;

  &lt;div class="ckb-head"&gt;
    &lt;h2&gt;&lt;span class="ckb-dot"&gt;&lt;/span&gt;PC Bottleneck Calculator&lt;/h2&gt;
    &lt;p&gt;Check whether your CPU or GPU is holding your system back — with resolution, upscaling and ray-tracing factored in. Free, no signup, updated for 2026 hardware.&lt;/p&gt;
  &lt;/div&gt;

  &lt;div class="ckb-body"&gt;
    &lt;div class="ckb-grid"&gt;
      &lt;div class="ckb-field"&gt;
        &lt;label for="ckb-cpu"&gt;Processor (CPU)&lt;/label&gt;
        &lt;select id="ckb-cpu"&gt;&lt;option value=""&gt;Select your CPU…&lt;/option&gt;&lt;/select&gt;
      &lt;/div&gt;
      &lt;div class="ckb-field"&gt;
        &lt;label for="ckb-gpu"&gt;Graphics card (GPU)&lt;/label&gt;
        &lt;select id="ckb-gpu"&gt;&lt;option value=""&gt;Select your GPU…&lt;/option&gt;&lt;/select&gt;
      &lt;/div&gt;
      &lt;div class="ckb-field"&gt;
        &lt;label for="ckb-res"&gt;Resolution&lt;/label&gt;
        &lt;select id="ckb-res"&gt;
          &lt;option value="1080"&gt;1080p (1920×1080)&lt;/option&gt;
          &lt;option value="1440" selected&gt;1440p (2560×1440)&lt;/option&gt;
          &lt;option value="2160"&gt;4K (3840×2160)&lt;/option&gt;
        &lt;/select&gt;
      &lt;/div&gt;
      &lt;div class="ckb-field"&gt;
        &lt;label for="ckb-ram"&gt;System RAM&lt;/label&gt;
        &lt;select id="ckb-ram"&gt;
          &lt;option value="8"&gt;8 GB&lt;/option&gt;
          &lt;option value="16" selected&gt;16 GB&lt;/option&gt;
          &lt;option value="32"&gt;32 GB&lt;/option&gt;
          &lt;option value="64"&gt;64 GB or more&lt;/option&gt;
        &lt;/select&gt;
      &lt;/div&gt;

      &lt;div class="ckb-toggles"&gt;
        &lt;label class="ckb-chip" data-toggle="upscale"&gt;
          &lt;input type="checkbox" id="ckb-upscale"&gt;
          &lt;span class="ckb-box"&gt;&lt;svg viewBox="0 0 12 12"&gt;&lt;path d="M2 6l3 3 5-6" stroke="#fff" stroke-width="2" fill="none" stroke-linecap="round" stroke-linejoin="round"/&gt;&lt;/svg&gt;&lt;/span&gt;
          Upscaling (DLSS / FSR / XeSS)
        &lt;/label&gt;
        &lt;label class="ckb-chip" data-toggle="rt"&gt;
          &lt;input type="checkbox" id="ckb-rt"&gt;
          &lt;span class="ckb-box"&gt;&lt;svg viewBox="0 0 12 12"&gt;&lt;path d="M2 6l3 3 5-6" stroke="#fff" stroke-width="2" fill="none" stroke-linecap="round" stroke-linejoin="round"/&gt;&lt;/svg&gt;&lt;/span&gt;
          Ray tracing on
        &lt;/label&gt;
        &lt;label class="ckb-chip" data-toggle="fg"&gt;
          &lt;input type="checkbox" id="ckb-fg"&gt;
          &lt;span class="ckb-box"&gt;&lt;svg viewBox="0 0 12 12"&gt;&lt;path d="M2 6l3 3 5-6" stroke="#fff" stroke-width="2" fill="none" stroke-linecap="round" stroke-linejoin="round"/&gt;&lt;/svg&gt;&lt;/span&gt;
          Frame generation
        &lt;/label&gt;
      &lt;/div&gt;

      &lt;div class="ckb-field ckb-upscale-row" id="ckb-upscale-row"&gt;
        &lt;label for="ckb-upscale-mode"&gt;Upscaling quality&lt;/label&gt;
        &lt;select id="ckb-upscale-mode"&gt;
          &lt;option value="8"&gt;Quality (lightest)&lt;/option&gt;
          &lt;option value="12" selected&gt;Balanced&lt;/option&gt;
          &lt;option value="18"&gt;Performance (heaviest lift)&lt;/option&gt;
        &lt;/select&gt;
      &lt;/div&gt;

      &lt;div class="ckb-cta"&gt;
        &lt;button class="ckb-btn" id="ckb-go" type="button"&gt;Calculate bottleneck&lt;/button&gt;
        &lt;button class="ckb-reset" id="ckb-reset" type="button"&gt;Reset&lt;/button&gt;
      &lt;/div&gt;
    &lt;/div&gt;

    &lt;div class="ckb-result" id="ckb-result" aria-live="polite"&gt;
      &lt;div class="ckb-verdict"&gt;
        &lt;div class="ckb-pct" id="ckb-pct"&gt;0%&lt;/div&gt;
        &lt;div class="ckb-verdict-txt"&gt;
          &lt;strong id="ckb-title"&gt;—&lt;/strong&gt;
          &lt;span id="ckb-sub"&gt;—&lt;/span&gt;
        &lt;/div&gt;
        &lt;span class="ckb-pill" id="ckb-pill"&gt;—&lt;/span&gt;
      &lt;/div&gt;

      &lt;div class="ckb-bars"&gt;
        &lt;div class="ckb-bar-row"&gt;
          &lt;div class="ckb-bar-label"&gt;&lt;span id="ckb-cpu-name"&gt;CPU&lt;/span&gt;&lt;span id="ckb-cpu-load"&gt;—&lt;/span&gt;&lt;/div&gt;
          &lt;div class="ckb-bar-track"&gt;&lt;div class="ckb-bar-fill" id="ckb-cpu-bar" style="background:var(--ck-cpu)"&gt;&lt;/div&gt;&lt;/div&gt;
        &lt;/div&gt;
        &lt;div class="ckb-bar-row"&gt;
          &lt;div class="ckb-bar-label"&gt;&lt;span id="ckb-gpu-name"&gt;GPU&lt;/span&gt;&lt;span id="ckb-gpu-load"&gt;—&lt;/span&gt;&lt;/div&gt;
          &lt;div class="ckb-bar-track"&gt;&lt;div class="ckb-bar-fill" id="ckb-gpu-bar" style="background:var(--ck-gpu)"&gt;&lt;/div&gt;&lt;/div&gt;
        &lt;/div&gt;
      &lt;/div&gt;

      &lt;div class="ckb-notes" id="ckb-notes"&gt;&lt;/div&gt;

      &lt;details class="ckb-method"&gt;
        &lt;summary&gt;How this is calculated&lt;/summary&gt;
        &lt;div class="ckb-method-body"&gt;
          &lt;p&gt;Every bottleneck calculator — including this one — &lt;strong&gt;estimates&lt;/strong&gt;; none measures your actual system. CPUs and GPUs here are placed on aligned 0–100 gaming-tier indices, where the same number on each side means a balanced pairing at 1440p. Your chosen resolution, upscaling mode and ray-tracing state then shift the comparison, because the same parts land in a completely different balance at 4K native versus 1080p with DLSS.&lt;/p&gt;
          &lt;p&gt;These indices reflect relative gaming performance from published benchmarks, not a single synthetic score, and the tables are updated as new hardware ships. Results are directional guidance for planning a build — not a substitute for testing.&lt;/p&gt;
          &lt;p&gt;&lt;strong&gt;The only fully accurate method&lt;/strong&gt; is to open an in-game overlay (MSI Afterburner, or your GPU app) while playing and read your real CPU and GPU utilisation. If the GPU sits at 95–100%, that's normal. If the GPU is low while a CPU core is pinned near 100%, that's a real CPU bottleneck.&lt;/p&gt;
        &lt;/div&gt;
      &lt;/details&gt;
    &lt;/div&gt;
  &lt;/div&gt;

  &lt;div class="ckb-foot"&gt;
    &lt;b&gt;A note on accuracy:&lt;/b&gt; this tool gives a well-calibrated estimate to sanity-check a pairing before you buy. No calculator can be 100% accurate — for a PC you already own, an in-game utilisation overlay is the real answer.
  &lt;/div&gt;

  &lt;script&gt;
  (function () {
    // ---- Aligned gaming-tier indices (0-100). Same number CPU vs GPU = balanced @1440p. ----
    // Update these two tables when new hardware launches. That is the only maintenance needed.
    var CPUS = [
      ["Ryzen 7 9800X3D", 100], ["Ryzen 9 9950X3D", 99], ["Core i9-14900K", 90],
      ["Ryzen 9 9900X3D", 97], ["Ryzen 7 7800X3D", 95], ["Ryzen 9 7950X3D", 94],
      ["Core Ultra 9 285K", 88], ["Core i7-14700K", 87], ["Ryzen 9 9900X", 86],
      ["Ryzen 7 9700X", 84], ["Core Ultra 7 265K", 84], ["Ryzen 7 5800X3D", 82],
      ["Core i5-14600K", 82], ["Ryzen 7 7700X", 82], ["Ryzen 5 9600X", 80],
      ["Ryzen 5 7600X", 78], ["Ryzen 5 7600", 76], ["Core i5-13600K", 80],
      ["Core i5-13400F", 68], ["Core i5-12400F", 64], ["Ryzen 5 5600X", 62],
      ["Ryzen 5 5600", 60], ["Core i5-11400F", 52], ["Ryzen 5 3600", 48],
      ["Core i5-10400F", 45], ["Ryzen 5 2600", 38], ["Core i7-8700K", 44]
    ];
    var GPUS = [
      ["GeForce RTX 5090", 100], ["GeForce RTX 4090", 96], ["GeForce RTX 5080", 90],
      ["Radeon RX 7900 XTX", 87], ["GeForce RTX 4080 Super", 85], ["GeForce RTX 4080", 83],
      ["GeForce RTX 5070 Ti", 82], ["Radeon RX 7900 XT", 80], ["GeForce RTX 4070 Ti Super", 78],
      ["Radeon RX 9070 XT", 77], ["GeForce RTX 4070 Ti", 74], ["GeForce RTX 5070", 72],
      ["Radeon RX 9070", 71], ["GeForce RTX 4070 Super", 70], ["Radeon RX 7800 XT", 66],
      ["GeForce RTX 4070", 64], ["Radeon RX 7700 XT", 60], ["GeForce RTX 5060 Ti", 56],
      ["GeForce RTX 4060 Ti", 52], ["GeForce RTX 5060", 50], ["Intel Arc B580", 48],
      ["Radeon RX 7600", 44], ["GeForce RTX 4060", 42], ["GeForce RTX 3060", 40],
      ["GeForce RTX 3050", 30], ["Radeon RX 6600", 36], ["GeForce GTX 1660 Super", 26]
    ];

    // Resolution offset applied to GPU's effective tier.
    // Low res =&gt; GPU has it easy =&gt; effective tier UP =&gt; CPU more likely the limiter.
    // High res =&gt; GPU stressed =&gt; effective tier DOWN =&gt; GPU more likely the limiter.
    var RES_OFFSET = { "1080": 15, "1440": 0, "2160": -15 };

    var $ = function (id) { return document.getElementById(id); };
    var root = $("ck-bottleneck-calc");

    function fill(sel, rows) {
      rows.slice().sort(function (a, b) { return b[1] - a[1]; }).forEach(function (r) {
        var o = document.createElement("option");
        o.value = r[1]; o.textContent = r[0]; o.dataset.name = r[0];
        sel.appendChild(o);
      });
    }
    fill($("ckb-cpu"), CPUS);
    fill($("ckb-gpu"), GPUS);

    // Chip toggle visuals + reveal upscaling quality
    root.querySelectorAll(".ckb-chip").forEach(function (chip) {
      var cb = chip.querySelector("input");
      function sync() {
        chip.classList.toggle("on", cb.checked);
        if (chip.dataset.toggle === "upscale") {
          $("ckb-upscale-row").classList.toggle("show", cb.checked);
        }
      }
      cb.addEventListener("change", sync);
      sync();
    });

    function pctColor(p) {
      if (p &lt; 8) return "var(--ck-good)";
      if (p &lt; 15) return "var(--ck-good)";
      if (p &lt; 25) return "var(--ck-mid)";
      return "var(--ck-bad)";
    }
    function band(p) {
      if (p &lt; 8) return ["Well balanced", "var(--ck-good)"];
      if (p &lt; 15) return ["Minor imbalance", "var(--ck-good)"];
      if (p &lt; 25) return ["Moderate bottleneck", "var(--ck-mid)"];
      return ["Significant bottleneck", "var(--ck-bad)"];
    }

    function calculate() {
      var cpuSel = $("ckb-cpu"), gpuSel = $("ckb-gpu");
      if (!cpuSel.value || !gpuSel.value) {
        alert("Please select both a CPU and a GPU.");
        return;
      }
      var cpu = parseFloat(cpuSel.value);
      var gpuBase = parseFloat(gpuSel.value);
      var cpuName = cpuSel.options[cpuSel.selectedIndex].dataset.name;
      var gpuName = gpuSel.options[gpuSel.selectedIndex].dataset.name;
      var res = $("ckb-res").value;
      var ram = parseInt($("ckb-ram").value, 10);

      // Effective GPU tier = base + resolution offset + modifiers.
      var gpuEff = gpuBase + RES_OFFSET[res];
      if ($("ckb-upscale").checked) gpuEff += parseFloat($("ckb-upscale-mode").value); // upscaling eases GPU
      if ($("ckb-fg").checked) gpuEff += 10;                                           // frame gen: GPU pushes more frames
      if ($("ckb-rt").checked) gpuEff -= 18;                                           // ray tracing loads GPU

      // Limiter = lower effective value. Bottleneck % = how far ahead the faster side is.
      var hi = Math.max(cpu, gpuEff), lo = Math.min(cpu, gpuEff);
      var pct = hi &lt;= 0 ? 0 : Math.round(((hi - lo) / hi) * 100);
      var cpuIsLimiter = cpu &lt; gpuEff;

      // Illustrative utilisation bars: limiter ~100%, other scaled by ratio.
      var cpuLoad, gpuLoad;
      if (cpuIsLimiter) { cpuLoad = 100; gpuLoad = Math.round((gpuEff &lt;= 0 ? 0 : (lo / hi) * 100)); gpuLoad = Math.min(gpuLoad, 100); cpuLoad = 100; gpuLoad = Math.round((cpu / gpuEff) * 100); }
      else { gpuLoad = 100; cpuLoad = Math.round((gpuEff / cpu) * 100); }
      cpuLoad = Math.max(30, Math.min(100, cpuLoad));
      gpuLoad = Math.max(30, Math.min(100, gpuLoad));
      if (cpuIsLimiter) { cpuLoad = 100; } else { gpuLoad = 100; }

      // ---- Render ----
      var b = band(pct);
      $("ckb-pct").textContent = pct + "%";
      $("ckb-pct").style.color = pctColor(pct);
      $("ckb-pill").textContent = b[0];
      $("ckb-pill").style.background = b[1];

      var title, sub;
      if (pct &lt; 8) {
        title = "Balanced pairing";
        sub = "Your CPU and GPU are well matched for this resolution. Neither is meaningfully holding the other back — build with confidence.";
      } else if (cpuIsLimiter) {
        title = "CPU is the limiting component (" + pct + "%)";
        sub = "Your processor can't feed frames as fast as the graphics card can render them. This is the actionable kind of bottleneck — it shows up as stutter and weak 1% lows more than low average FPS.";
      } else {
        title = "GPU is the limiting component (" + pct + "%)";
        sub = "Your graphics card is the ceiling here. At higher resolutions this is normal and usually desirable — the GPU working at capacity means you're getting everything you paid for.";
      }
      $("ckb-title").textContent = title;
      $("ckb-sub").textContent = sub;

      $("ckb-cpu-name").textContent = cpuName;
      $("ckb-gpu-name").textContent = gpuName;
      $("ckb-cpu-load").textContent = "~" + cpuLoad + "% load";
      $("ckb-gpu-load").textContent = "~" + gpuLoad + "% load";
      requestAnimationFrame(function () {
        $("ckb-cpu-bar").style.width = cpuLoad + "%";
        $("ckb-gpu-bar").style.width = gpuLoad + "%";
      });

      // ---- Contextual notes ----
      var notes = [];
      if (ram &lt;= 8) {
        notes.push(["warn", "\u26A0", "&lt;b&gt;8 GB RAM is your real bottleneck in 2026.&lt;/b&gt; This limits games before your CPU or GPU ever does. Moving to 16 GB (ideally 32 GB) is the cheapest and most impactful upgrade you can make — do this first."]);
      } else if (ram === 16 &amp;&amp; gpuBase &gt;= 78) {
        notes.push(["warn", "\u26A0", "With a card this powerful, &lt;b&gt;32 GB&lt;/b&gt; is worth considering — several 2026 titles now exceed 16 GB when paired with high-end GPUs and background apps."]);
      }
      if (cpuIsLimiter &amp;&amp; res !== "2160" &amp;&amp; pct &gt;= 15) {
        notes.push(["", "\uD83D\uDCA1", "Because this is a CPU limit, &lt;b&gt;raising your resolution shifts load onto the GPU&lt;/b&gt; and can reduce the bottleneck for free — often with a better monitor as the bonus, rather than a new CPU."]);
      }
      if (!cpuIsLimiter &amp;&amp; res === "2160" &amp;&amp; pct &gt;= 15) {
        notes.push(["", "\uD83D\uDCA1", "A GPU limit at 4K is expected. To gain FPS: &lt;b&gt;enable upscaling (DLSS/FSR/XeSS)&lt;/b&gt; or lower settings before spending on a new card."]);
      }
      if ($("ckb-upscale").checked &amp;&amp; cpuIsLimiter) {
        notes.push(["", "\u2139", "You've enabled upscaling, which eases the GPU — that's part of &lt;b&gt;why the CPU is now the limiter&lt;/b&gt;. Upscaling can flip a GPU bottleneck into a CPU one. Most calculators miss this; it's real."]);
      }
      if ($("ckb-rt").checked &amp;&amp; !cpuIsLimiter) {
        notes.push(["", "\u2139", "Ray tracing pushes work back onto the GPU, which is part of why the GPU is the limit here. Turning it off, or pairing it with upscaling, rebalances the load."]);
      }
      if ($("ckb-fg").checked) {
        notes.push(["", "\u2139", "Frame generation needs CPU headroom to work well. On a CPU-limited system its benefit shrinks and input latency can rise."]);
      }
      if (pct &gt;= 25) {
        notes.push(["", "\uD83D\uDD0D", "Before spending money on a " + (cpuIsLimiter ? "CPU" : "GPU") + " upgrade, verify this with an in-game overlay. A CPU swap often also means a new motherboard and RAM — budget for the platform, not just the chip."]);
      }
      var wrap = $("ckb-notes");
      wrap.innerHTML = "";
      notes.forEach(function (n) {
        var d = document.createElement("div");
        d.className = "ckb-note" + (n[0] ? " " + n[0] : "");
        d.innerHTML = '&lt;span class="ckb-ni"&gt;' + n[1] + '&lt;/span&gt;&lt;span&gt;' + n[2] + '&lt;/span&gt;';
        wrap.appendChild(d);
      });

      $("ckb-result").classList.add("show");
      $("ckb-result").scrollIntoView({ behavior: "smooth", block: "nearest" });
    }

    $("ckb-go").addEventListener("click", calculate);
    $("ckb-reset").addEventListener("click", function () {
      $("ckb-cpu").selectedIndex = 0;
      $("ckb-gpu").selectedIndex = 0;
      $("ckb-res").value = "1440";
      $("ckb-ram").value = "16";
      ["ckb-upscale", "ckb-rt", "ckb-fg"].forEach(function (id) {
        var cb = $(id); cb.checked = false; cb.dispatchEvent(new Event("change"));
      });
      $("ckb-result").classList.remove("show");
    });
  })();
  &lt;/script&gt;
&lt;/div&gt;&lt;/p&gt;
&lt;h3 style="text-align: left;"&gt;The components that can bottleneck&lt;/h3&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ul style="text-align: left;"&gt;
  &lt;li&gt;
    &lt;b&gt;CPU — &lt;/b&gt;Limits frame rate in simulation-heavy games (strategy titles,
    large multiplayer maps) and at low resolutions where the GPU has an easy
    time. Symptom: stutter and inconsistent 1% lows rather than a uniformly low
    frame rate.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;GPU —&lt;/b&gt; Limits maximum frame rate at high resolutions and settings.
    Symptom: consistently low FPS that scales cleanly when you drop settings.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;RAM —&lt;/b&gt; Capacity limits multitasking; speed and latency matter more
    than most people think on Ryzen. 16 GB is now the floor for gaming; 32 GB is
    the comfortable default in 2026.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Storage — &lt;/b&gt;Rarely limits frame rate, but limits load times and causes
    traversal stutter in open-world games, streaming assets from a slow drive.
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h3 style="text-align: left;"&gt;Are bottleneck calculators accurate?&lt;/h3&gt;
&lt;p&gt;&lt;i&gt;
  Short answer: They're rough directional estimates, and you should treat them
  that way.
&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;
  The reason is structural, not sloppiness. To tell you that a specific CPU and
  GPU pairing produces an 11% bottleneck, a tool needs benchmark data for that
  exact pairing — ideally in the games you play, at your resolution and
  settings. Nobody has that. The combinatorial space is enormous: hundreds of
  CPUs times hundreds of GPUs times dozens of games times several resolutions.
&lt;/p&gt;
&lt;p&gt;
  So calculators interpolate. They take a synthetic score for your CPU, a
  synthetic score for your GPU, run them through a ratio formula, and return a
  percentage. It's an educated guess dressed up as a measurement.
&lt;/p&gt;
&lt;p&gt;That's why:&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ul style="text-align: left;"&gt;
  &lt;li&gt;
    &lt;b&gt;Different tools contradict each other. &lt;/b&gt;There's no standard definition
    of "bottleneck percentage." Each site invented its own formula, so the
    numbers aren't comparable across tools. An 8% on one site and a 22% on
    another aren't disagreeing about your PC — they're using different
    arithmetic.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Precision is theatre.&lt;/b&gt; When a calculator reports "13.7% CPU
    bottleneck," the decimal is doing marketing work. The underlying model
    doesn't support that resolution. One site currently advertises "99.99%
    accurate diagnostic results" — a claim no benchmark methodology on earth can
    back.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Modern upscaling breaks the model.&lt;/b&gt; This is the big one, and most
    calculators ignore it entirely. DLSS, FSR, and XeSS render the game at a
    lower internal resolution and reconstruct it upward. That reduces GPU load
    dramatically — which means enabling DLSS Quality can convert a GPU
    bottleneck into a CPU bottleneck, because the GPU now finishes frames faster
    than the CPU can feed it. Frame generation muddies it further. A calculator
    that only knows your CPU model, GPU model, and resolution has no idea
    whether you're running native 4K or DLSS Performance, and those are
    radically different loads on the same hardware.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Ray tracing cuts the other way. &lt;/b&gt;RT pushes work back onto the GPU and
    can swing a CPU-limited system back to GPU-limited in the same session.
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;
  None of this makes the tools useless. It makes them useful for one specific
  thing: &lt;b&gt;sanity-checking a pairing before you buy&lt;/b&gt;.&amp;nbsp;&lt;/p&gt;&lt;p&gt;If a calculator
  screams that a Ryzen 3 and an RTX 5090 are mismatched, it's right, and you
  didn't need three decimal places to know it. Use them for coarse "is this
  combination stupid?" checks. Don't use them to decide whether a 12% number
  justifies a ₹30,000 upgrade.
&lt;/p&gt;
&lt;h2 style="text-align: left;"&gt;The best bottleneck calculators in 2026&lt;/h2&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h3 style="text-align: left;"&gt;
  1. PC Builds Bottleneck Calculator&amp;nbsp;— best overall
&lt;/h3&gt;
&lt;p&gt;&lt;/p&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
  &lt;img alt="PC Builds Bottleneck Calculator" border="0" data-original-height="821" data-original-width="1576" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiySZnBEpIfYRfnpsfFdv3OytAnfb0v-xZHhW63_FRnCEijaZZYEKo6nPtl8k_vx31AY9qRGs70VRyYhM7GDLuhQc7Ayb40_n5udyv6sumyCUzspzTA6MCoWdnm9K7TSpl3_34WJeJ8GVuxM5gOU2XZ9eB-akpTEzHU76dWJMw0PzR9fSx0ZYhbe9upj4I/s16000/PC%20Builds%20Bottleneck%20Calculator.webp" title="PC Builds Bottleneck Calculator" /&gt;
&lt;/div&gt;
&lt;p&gt;
  The most established tool in the category, and the only one that meaningfully
  addresses the workload-dependence problem. Rather than returning one abstract
  percentage, it calculates against specific games, and reports projected CPU
  and GPU utilisation for that title at your chosen resolution — for example,
  showing a processor running at 90% while the graphics card sits at 55%, which
  is a far more legible way to express a bottleneck than a bare percentage.
&lt;/p&gt;

&lt;p&gt;
  It also runs a companion FPS calculator that estimates frame rates at
  low/medium/high/ultra across 1080p, 1440p, and 4K, and a separate RAM
  calculator. Resolution is a first-class input, which is correct — resolution
  is the single biggest determinant of where your bottleneck lands.
&lt;/p&gt;

&lt;p&gt;
  &lt;b&gt;Strengths: &lt;/b&gt;Game-specific results; utilisation figures rather than an
  opaque score; wide, well-maintained hardware database including
  current-generation parts; large user base feeding calibration data.
&lt;/p&gt;

&lt;p&gt;
  &lt;b&gt;Weaknesses: &lt;/b&gt;No input for DLSS/FSR or ray tracing, so results assume
  native rendering. Affiliate links to retailers throughout. The interface is
  dense.
&lt;/p&gt;

&lt;p&gt;
  &lt;b&gt;Use it for:&lt;/b&gt; Checking a planned build against the actual games you play.
&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h3 style="text-align: left;"&gt;
  2. CPU&amp;nbsp;Agent — best for the underlying data
&lt;/h3&gt;
&lt;p&gt;&lt;/p&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
  &lt;img alt="CPU Agent BottleNeck Calculator" border="0" data-original-height="972" data-original-width="962" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXcAjm1NlFAzNJXHMHXOsBw7E7FknUWEdmijmNY8OO9z6NexZ6pWTAC8nk12zuFfmNa84Qae977X_D93KF-g9gnxPRWr40QScOmDyLllPEFB9t7GIsbCI8Aecp_gTQdrIdj6-Bmb94DHDnQ2enhTZSl0GeETO2U7cScven0fBMaOur9wdgU0MGdtCyhMY/s16000/CPU%20Agent%20BottleNeck%20Calculator.webp" title="CPU Agent BottleNeck Calculator" /&gt;
&lt;/div&gt;
&lt;p&gt;
  Worth being precise about what this is, because it's frequently misdescribed:
  CPU Agent is fundamentally a CPU and GPU benchmark comparison database with
  bottleneck tooling layered on top. Its value isn't the bottleneck verdict —
  it's that you can look at the game-by-game FPS data the verdict is derived
  from.
&lt;/p&gt;

&lt;p&gt;
  That's the right way to use any of these tools. The percentage is an opinion;
  the benchmark numbers are evidence. CPU Agent lets you skip to the evidence.
&lt;/p&gt;

&lt;p&gt;
  &lt;b&gt;Strengths: &lt;/b&gt;Transparent underlying benchmark data; strong CPU-to-CPU
  comparison; useful for "which CPU do I actually need for this GPU" questions.
&lt;/p&gt;
&lt;p&gt;
  &lt;b&gt;Weaknesses: &lt;/b&gt;Less of a one-click experience; more of a research tool
  than a calculator.
&lt;/p&gt;
&lt;p&gt;
  &lt;b&gt;Use it for: &lt;/b&gt;Answering why a pairing is mismatched, not just whether it
  is.
&lt;/p&gt;

&lt;h3 style="text-align: left;"&gt;
  3. IObit Bottleneck Calculator — cleanest free tool
&lt;/h3&gt;
&lt;p&gt;
  A straightforward CPU/GPU/RAM/resolution input returning a balance percentage.
  No signup, no gate. It's competent, and it's fast.
&lt;/p&gt;

&lt;p&gt;
  The caveat is commercial: IObit makes Advanced SystemCare, and the tool is a
  funnel for it. Expect download prompts positioned as performance fixes. A "PC
  optimiser" will not fix a hardware bottleneck — nothing installed in Windows
  can make your CPU feed your GPU faster. Take the number, ignore the upsell.
&lt;/p&gt;

&lt;p&gt;
  &lt;b&gt;Strengths:&lt;/b&gt; Clean UI, genuinely free, no account, reputable company
  behind it.
&lt;/p&gt;

&lt;p&gt;
  &lt;b&gt;Weaknesses:&lt;/b&gt; Software promotion woven into results; generic percentage
  with no game context; no upscaling awareness.
&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Use it for:&lt;/b&gt; A fast second opinion to cross-check PC builds.&lt;/p&gt;
&lt;h2 style="text-align: left;"&gt;
  How to find your real bottleneck in 90 seconds
&lt;/h2&gt;
&lt;p&gt;
  This is more reliable than every calculator on this page combined, because it
  measures your actual system running your actual game instead of interpolating
  from a database.
&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Step 1 — Turn on an overlay.&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;
  MSI Afterburner with RivaTuner is the standard. NVIDIA users can use the
  built-in overlay; AMD users have Adrenalin's metrics panel. Enable CPU
  utilisation, GPU utilisation, and frame rate.
&lt;/p&gt;

&lt;p&gt;
  &lt;b&gt;Step 2 — Play the game you actually care about.&lt;/b&gt; Not a benchmark loop —
  the real thing, in a demanding area.
&lt;/p&gt;
&lt;p&gt;
  &lt;/p&gt;&lt;p&gt;Step 3 — Read the two numbers.&lt;/p&gt;
  &lt;div class="table noWrap w100"&gt;&lt;table border="1" cellpadding="8" cellspacing="0"&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;GPU Usage&lt;/th&gt;
      &lt;th&gt;CPU Usage&lt;/th&gt;
      &lt;th&gt;What It Means&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;95–100%&lt;/td&gt;
      &lt;td&gt;Below ~70%&lt;/td&gt;
      &lt;td&gt;GPU-limited. Normal and expected in demanding games. To gain more FPS, lower graphics settings, enable upscaling, or upgrade the GPU.&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Below ~90%&lt;/td&gt;
      &lt;td&gt;One or more cores near 100%&lt;/td&gt;
      &lt;td&gt;CPU-limited. Increase resolution or graphics settings to shift more workload to the GPU, or upgrade the CPU.&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Both high&lt;/td&gt;
      &lt;td&gt;Both high&lt;/td&gt;
      &lt;td&gt;Balanced. Your CPU and GPU are being utilized efficiently.&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Both low&lt;/td&gt;
      &lt;td&gt;Both low&lt;/td&gt;
      &lt;td&gt;Neither component is the bottleneck. You're likely limited by V-Sync, a frame rate limiter, or your monitor's refresh rate.&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;&lt;p&gt;&lt;b&gt;Step 4 — Watch the 1% lows, not the average.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Averages hide stutter. A system with a 120 FPS average and 45 FPS 1% lows feels dramatically worse than one averaging 100 with 85 lows. CPU bottlenecks show up in the lows first, and no bottleneck calculator reports 1% lows at all.&lt;/p&gt;&lt;p&gt;That's the whole method. It costs nothing, takes under two minutes, and it is your data rather than a stranger's regression model.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;When a bottleneck is worth fixing&lt;/h3&gt;&lt;p&gt;Some perspective before you spend money.&lt;/p&gt;&lt;p&gt;A 10% bottleneck is noise — you cannot perceive it, and it will not survive your next driver update. Below about 15%, do nothing. In the 15–25% range, it's worth checking whether setting changes solve it for free: raising resolution shifts load to the GPU and can eliminate a CPU limit without spending a rupee. Above 25%, and only if you can feel it during play, consider an upgrade.&lt;/p&gt;&lt;p&gt;The order of operations most people get backwards:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ol style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Check RAM first. &lt;/b&gt;It's the cheapest fix and the most common real bottleneck. If you're on 8 GB in 2026, that's your problem, and no CPU upgrade will help.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Check whether you're CPU-limited only at 1080p.&lt;/b&gt; If so, a higher-resolution monitor "fixes" your bottleneck and gets you a better display.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Then consider a component. &lt;/b&gt;And a caution: a CPU upgrade often means a new motherboard and new RAM. The ₹20,000 CPU is a ₹45,000 decision. GPU upgrades are usually a drop-in.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Frequently asked questions&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Q. Are bottleneck calculators accurate?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;They're directional, not precise. They interpolate from synthetic scores rather than measuring your system, and they don't account for upscaling, ray tracing, or the specific games you play. Use them to sanity-check a pairing before buying; use an in-game overlay to diagnose a system you already own.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Why do different bottleneck calculators give different results?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;Because there's no standard definition of "bottleneck percentage." Each site uses its own formula and its own benchmark dataset, so their outputs aren't measuring the same quantity. Contradictory numbers don't mean one is broken — they mean the metric isn't standardised.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. What's a good bottleneck percentage?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;Under 10% is effectively balanced and imperceptible. Up to 15% is fine. Over 25% is worth investigating — but verify it with an overlay before spending money.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Can a bottleneck damage my PC?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;No. A bottlenecked component runs less, not harder. The idle component is doing less work, not stressing itself. There's no thermal or electrical risk from a bottleneck.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Does DLSS or FSR change my bottleneck?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;Yes, significantly — and this is the most under-discussed point in the category. Upscaling renders internally at a lower resolution, which cuts GPU load. That can flip a GPU-limited system into a CPU-limited one, because the GPU now completes frames faster than the CPU can supply them. Frame generation amplifies the effect. Almost no bottleneck calculator accounts for this, which is a major reason their numbers drift from reality on modern systems.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Is my CPU bottlenecking my GPU?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;Run the game, open an overlay. If GPU utilisation sits below ~90% while a CPU core is pinned near 100%, yes. If the GPU is at 95%+, no — your GPU is simply working at capacity, which is the correct state.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Should I fix a CPU bottleneck at 1080p?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;Often you don't need to. CPU bottlenecks are most pronounced at low resolutions, where the GPU has little to do. Moving to 1440p usually shifts the limit back to the GPU and resolves it — with a better monitor as the side effect rather than a new platform.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q. Does RAM speed matter for bottlenecks?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A. &lt;/b&gt;On AMD Ryzen, meaningfully yes — the memory controller is sensitive to speed and latency, and slow RAM can cost real frames. On Intel, it matters less but isn't nothing. Capacity is the bigger issue for most people: 16 GB minimum, 32 GB comfortable.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;The bottom line&lt;/h3&gt;&lt;p&gt;Bottleneck calculators are useful for one job: a quick reality check on a pairing you're considering buying. PC-Builds is the strongest of them because it grounds results in specific games and reports utilisation rather than an abstract score. CPU Agent is the best if you want to see the benchmark data behind the verdict. IObit is a clean, free second opinion.&lt;/p&gt;&lt;p&gt;But for a system you already own, none of them beat two numbers on an overlay in the game you actually play. Every calculator on this page is guessing at what your PC is doing. Afterburner just tells you.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhRm-NFkh3UtzIig9c9rWWAFRwa1gzzqigT_9M7HVLicQFlN-aaR0NIbQSZTrMaOcF5Iq_6JMwlZwBtD-ENl0fjs-9sO1wkYW3Ig44tE68WdvpMlWkB5lJ4KIxZ6msYaeJl_1nySRCas8eKFdiT3daq-BmA_PfyJ1_fNGyzqjOgEiz2s3rcM3tD2xofaNE/s72-c/Bottleneck-calculator.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item></channel></rss>