<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>Cyber Kendra</title>
	<atom:link href="https://www.cyberkendra.com/feed" rel="self" type="application/rss+xml"/>
	<link>https://www.cyberkendra.com</link>
	<description></description>
	<lastBuildDate>Mon, 28 Sep 2026 17:51:58 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://www.cyberkendra.com/wp-content/uploads/2026/08/cropped-fav-32x32.png</url>
	<title>Cyber Kendra</title>
	<link>https://www.cyberkendra.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<itunes:explicit>no</itunes:explicit><copyright>All the content is copyright of cyberkendra.com</copyright><itunes:image href="http://2.bp.blogspot.com/-svYWW7Cp8JI/UDUgofD9kUI/AAAAAAAAAEY/ina7VZi4ZRg/s1600/webprotal.png"/><itunes:keywords>Computer,technology,tech,IT,security,Gadgets,Telecom</itunes:keywords><itunes:summary>All about Computer and technology. </itunes:summary><itunes:subtitle>Cyber kendra</itunes:subtitle><itunes:category text="Technology"><itunes:category text="Tech News"/></itunes:category><itunes:author>Vivek Gurung</itunes:author><itunes:owner><itunes:email>protalweb@gmail.com</itunes:email><itunes:name>Vivek Gurung</itunes:name></itunes:owner><item>
		<title>WhatsApp Malware Targets Malaysia via KuGou-Signed File</title>
		<link>https://www.cyberkendra.com/2026/09/whatsapp-malware-malaysia-kugou-signed-loader.html</link>
					<comments>https://www.cyberkendra.com/2026/09/whatsapp-malware-malaysia-kugou-signed-loader.html#respond</comments>
		
		
		<pubDate>Mon, 28 Sep 2026 17:51:54 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Kugou]]></category>
		<category><![CDATA[SilverFox]]></category>
		<category><![CDATA[whatsapp malware]]></category>
		<guid isPermaLink="false">https://www.cyberkendra.com/?p=12907</guid>

					<description><![CDATA[A WhatsApp finance-report lure is infecting Malaysian Windows PCs with a KuGou-signed loader, Pelagos Intel says.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A WhatsApp message disguised as a finance report is being used to infect Windows computers in Malaysia with a malware loader that hides behind a valid code-signing certificate issued to Guangzhou Kugou Technology, according to <a href="https://research.pelagos-intel.com/silverfox-in-the-desktop" target="_blank" rel="noreferrer noopener nofollow">research published on 27 September 2026 by Pelagos Intel</a>. </p>



<p class="wp-block-paragraph">The infection ends with the compromised PC repeatedly calling a command-and-control (C2) server at 134.122.155.135 on port 443, and Pelagos says the techniques resemble those of the Silver Fox threat group.</p>



<p class="wp-block-paragraph">The attachment, named <code>PDF_C2841_20260911100446.zip</code>, arrives with a message asking the recipient to forward the report for verification and to open it on a computer. That second instruction moves the victim off the phone and onto Windows, where the payload can run. Inside the ZIP is an IMG disk image, a file type that Windows mounts and opens like a removable drive.</p>



<p class="wp-block-paragraph">The disk image carries two files. The first is an executable that presents itself as KuGou software and carries a genuine Authenticode signature from Guangzhou Kugou Technology Co., Ltd., which Windows reports as valid. The second is an unsigned DLL, <code>active_desktop_render_x64.dll</code>, whose metadata claims to be a Microsoft Desktop Window Manager helper with the original filename <code>dwmapi.dll</code>.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="576" src="https://www.cyberkendra.com/wp-content/uploads/2026/09/KuGou-Signed-File-1024x576.webp" alt="KuGou-Signed File" class="wp-image-12908" srcset="https://www.cyberkendra.com/wp-content/uploads/2026/09/KuGou-Signed-File-1024x576.webp 1024w, https://www.cyberkendra.com/wp-content/uploads/2026/09/KuGou-Signed-File-300x169.webp 300w, https://www.cyberkendra.com/wp-content/uploads/2026/09/KuGou-Signed-File-768x432.webp 768w, https://www.cyberkendra.com/wp-content/uploads/2026/09/KuGou-Signed-File-1536x864.webp 1536w, https://www.cyberkendra.com/wp-content/uploads/2026/09/KuGou-Signed-File-480x270.webp 480w, https://www.cyberkendra.com/wp-content/uploads/2026/09/KuGou-Signed-File-679x382.webp 679w, https://www.cyberkendra.com/wp-content/uploads/2026/09/KuGou-Signed-File.webp 1600w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">The pairing is a classic sideloading setup, in which a trusted program loads a malicious library placed next to it. Pelagos found that the signed launcher calls two functions exported by the DLL, <code>SetDesktopMonitorHook</code> and <code>ClearDesktopMonitorHook</code>. The DLL then looks up Windows functions through hashed identifiers, decodes hidden data with XOR, and writes a transformed 11,200-byte block into executable memory. The same signature check Windows uses to tell users a file can be trusted is what vouches for the launcher that starts the chain.</p>



<p class="wp-block-paragraph">Dynamic analysis tied the pieces together. A Windows decryption call produced an output of exactly 11,200 bytes, and the decrypted data held a configuration marker, <code>@@RAPID_CFG_START@@</code>, the C2 address, port 443, and a Chinese label meaning &#8220;Default group&#8221;. The malware copied both files to <code>%APPDATA%\Microsoft\Update</code>, added a Registry Run value named <code>MicrosoftUpdate</code> so it restarts at every login, and makes 96 connection attempts to the server at roughly three-second intervals. The ZIP delivered over WhatsApp carries the number C2841, while the executable Pelagos analysed is numbered C2089. The report does not explain the difference.</p>



<h2 class="wp-block-heading">Silver Fox links stop short of a match</h2>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img decoding="async" width="942" height="975" src="https://www.cyberkendra.com/wp-content/uploads/2026/09/High_Level_Infection_Chain.webp" alt="WhatsApp Infection Chain" class="wp-image-12909" srcset="https://www.cyberkendra.com/wp-content/uploads/2026/09/High_Level_Infection_Chain.webp 942w, https://www.cyberkendra.com/wp-content/uploads/2026/09/High_Level_Infection_Chain-290x300.webp 290w, https://www.cyberkendra.com/wp-content/uploads/2026/09/High_Level_Infection_Chain-767x794.webp 767w, https://www.cyberkendra.com/wp-content/uploads/2026/09/High_Level_Infection_Chain-479x496.webp 479w, https://www.cyberkendra.com/wp-content/uploads/2026/09/High_Level_Infection_Chain-679x703.webp 679w" sizes="(max-width: 942px) 100vw, 942px" /></figure>
</div>


<p class="wp-block-paragraph">Pelagos compares the chain to a <a href="https://www.cloudsek.com/blog/silver-fox-targeting-india-using-tax-themed-phishing-lures" target="_blank" rel="noreferrer noopener nofollow">Silver Fox campaign against India documented by CloudSEK</a> in December 2025. That campaign delivered the ValleyRAT remote access trojan by pairing a legitimately signed <code>Thunder.exe</code> from Xunlei with a malicious <code>libexpat.dll</code>. Both operations use signed software to launch a rogue DLL, in-memory execution, configurable C2 settings, and persistent retry behaviour. Pelagos says the similarity holds at the tradecraft level and is &#8220;not an exact campaign match&#8221;. The report does not name the final payload.</p>



<p class="wp-block-paragraph">Malaysia has been the main target of WhatsApp-borne Windows malware this year. In June 2026, <a href="https://securelist.com/whatsapp-vbs-rmm-campaign/120290/" target="_blank" rel="noreferrer noopener nofollow">Kaspersky reported</a> a campaign that used compromised WhatsApp accounts to send VBScript files posing as business documents. Eighty per cent of its victims were in Malaysia, and its infrastructure overlapped with earlier ValleyRAT and Gh0st RAT activity.</p>



<p class="wp-block-paragraph">Kaspersky urged caution with &#8220;unexpected attachments through WhatsApp, even when they appear to originate from known contacts&#8221;. No link between that campaign and the one Pelagos analysed has been established.</p>



<p class="wp-block-paragraph">Users of WhatsApp Desktop or WhatsApp Web on Windows should not open ZIP or IMG files that arrive as &#8220;PDF&#8221; reports, regardless of who sends them. An <code>MicrosoftUpdate</code> entry under <code>HKCU\Software\Microsoft\Windows\CurrentVersion\Run</code> pointing to <code>%APPDATA%\Microsoft\Update</code> is a strong sign of infection. During the June campaign, Malaysia&#8217;s Computer Emergency Response Team (MyCERT) advised infected users to disconnect the machine from the internet, change passwords from a separate clean device, and report the incident to Cyber999.</p>



<p class="wp-block-paragraph">Several questions remain open. Pelagos has not said how many people received the lure or whether it was sent from hijacked accounts. It has also not said whether the KuGou certificate, thumbprint <code>757BDD02CBA91CA59C46E2098A5479C1ABC1FDBE</code>, was stolen or misused, or whether KuGou or the issuing certificate authority has been notified. The report lists file hashes for the ZIP, IMG, EXE, and DLL for defenders who want to hunt for the samples.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cyberkendra.com/2026/09/whatsapp-malware-malaysia-kugou-signed-loader.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			<dc:creator>protalweb@gmail.com (Vivek Gurung)</dc:creator></item>
		<item>
		<title>Microsoft Details NeedyMantis Post-Compromise Malware</title>
		<link>https://www.cyberkendra.com/2026/09/needymantis-malware-microsoft-storm-3069.html</link>
					<comments>https://www.cyberkendra.com/2026/09/needymantis-malware-microsoft-storm-3069.html#respond</comments>
		
		
		<pubDate>Mon, 28 Sep 2026 17:15:17 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.cyberkendra.com/?p=12904</guid>

					<description><![CDATA[Microsoft Threat Intelligence on 28 September 2026 disclosed NeedyMantis, a modular malware framework that attackers deploy only after they already have a foothold in a network, and said it has surfaced in a small number of intrusions against telecommunications firms, universities, medical nonprofits, intergovernmental organizations and government contractors. The activity dates back to at least [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft Threat Intelligence on 28 September 2026 disclosed NeedyMantis, a modular malware framework that attackers deploy only after they already have a foothold in a network, and said it has surfaced in a small number of intrusions against telecommunications firms, universities, medical nonprofits, intergovernmental organizations and government contractors.</p>



<p class="wp-block-paragraph">The activity dates back to at least October 2025 and matches what Microsoft associates with threat actors operating from China, although the company has not tied every incident to a single group.</p>



<p class="wp-block-paragraph">Microsoft found the malware while pivoting from indicators linked to the DAEMON Tools supply chain compromise that <a href="https://securelist.com/tr/daemon-tools-backdoor/119654/" target="_blank" rel="noreferrer noopener nofollow">Kaspersky exposed earlier this year</a>. According to <a href="https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/" target="_blank" rel="noreferrer noopener nofollow">Microsoft&#8217;s analysis</a>, at least one actor uses NeedyMantis: Storm-3069, the company&#8217;s temporary designator for the group behind the DAEMON Tools campaign. Microsoft assesses that Storm-3069 operates from China but has not attributed it to a Chinese nation-state actor.</p>



<p class="wp-block-paragraph">Microsoft has also seen NeedyMantis in intrusions outside the DAEMON Tools campaign, and said the tool &#8220;might be used by more than one operator.&#8221; Those operations share targeting that aligns with Chinese interests and a pattern of selective deployment. Microsoft did not name any victims, their countries or how many organizations were hit.</p>



<p class="wp-block-paragraph">The link to DAEMON Tools is narrower than it first appears. Kaspersky reported in May that attackers had served signed, trojanized installers of the disk-imaging software from its official website since 8 April 2026, profiling thousands of machines but sending a backdoor to only about a dozen government, scientific, manufacturing and retail systems in Russia, Belarus and Thailand. </p>



<p class="wp-block-paragraph">Kaspersky said the pattern showed &#8220;intentions to conduct the infection in a targeted manner.&#8221; Microsoft says it has not seen NeedyMantis itself delivered through a supply chain compromise, only that supply chain access is one route an actor could use to reach the point where the malware is installed.</p>



<h2 class="wp-block-heading">How NeedyMantis gets in and hides</h2>



<p class="wp-block-paragraph">NeedyMantis starts with a first-stage loader that abuses DLL sideloading, a technique in which a legitimate program is tricked into loading a malicious library that carries the name of one it expects. In the sample Microsoft analyzed, the loader replaced WinSparkle.dll, the software update component of the Poedit translation tool. Other variants hid behind curl, Vim and TightVNC, or posed as Microsoft Office, Broadcom, Intel and NVIDIA components in folders such as ProgramData\USOShared and ProgramData\Intel.</p>



<p class="wp-block-paragraph">In one intrusion, an operator used the Impacket toolkit during hands-on keyboard activity to copy the legitimate software, the malicious DLL and an encrypted archive from a network share onto a target machine. That archive uses a custom compressed format whose keys and offsets change from sample to sample. The analyzed copy held 11 files, including genuine 7-Zip and Sysinternals components alongside malicious files disguised as Windows libraries such as dnsapi.dll and ws2_32.dll.</p>



<p class="wp-block-paragraph">The second-stage loader, named encryptbase64.ps1, carries a PowerShell extension but contains x64 shellcode. It unpacks the main component, which is stored in a stripped-down custom version of the Windows executable format to frustrate analysis tools.</p>



<p class="wp-block-paragraph">The main component contacts its command-and-control (C2) server at corp.tripswithengine[.]com over HTTPS, hiding the computer name, username and running processes in a cookie header. It then switches the connection to WebSockets and an RC4-encrypted binary protocol, using a hard-coded &#8220;firefox/21.0&#8221; user agent. Its own command set is small. It can load, unload and feed data to additional modules, and Microsoft said the capabilities of those modules remain unconfirmed.</p>



<h2 class="wp-block-heading">What defenders should check</h2>



<p class="wp-block-paragraph">Microsoft advises organizations to look for outbound traffic to corp.tripswithengine[.]com and the Firefox/21.0 user agent, and to check for the sideloaded DLL names in unexpected folders. </p>



<p class="wp-block-paragraph">It has published hunting queries for Defender XDR and Sentinel. Defender detects the malware as TrojanDropper:Win64/NeedyMantis and Behavior:Win64/NeedyMantis. The company also recommends running endpoint detection and response (EDR) in block mode and enabling attack surface reduction rules that block obfuscated scripts and rare executables. Anyone who installed DAEMON Tools versions 12.5.0.2421 to 12.5.0.2434 should move to 12.6.0.2445 or later, which Kaspersky says no longer contains the malicious code.</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cyberkendra.com/2026/09/needymantis-malware-microsoft-storm-3069.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			<dc:creator>protalweb@gmail.com (Vivek Gurung)</dc:creator></item>
		<item>
		<title>Nvidia Open Agent Safety Platform Launch: OpenShell, Sentry</title>
		<link>https://www.cyberkendra.com/2026/09/nvidia-open-agent-safety-platform-openshell-sentry.html</link>
					<comments>https://www.cyberkendra.com/2026/09/nvidia-open-agent-safety-platform-openshell-sentry.html#respond</comments>
		
		
		<pubDate>Mon, 28 Sep 2026 17:04:17 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[AI safety]]></category>
		<category><![CDATA[nvidia]]></category>
		<category><![CDATA[openshell]]></category>
		<guid isPermaLink="false">https://www.cyberkendra.com/?p=12901</guid>

					<description><![CDATA[Nvidia on Monday, 28 September 2026, launched the Open Agent Safety Platform, an open software stack and reference hardware design built to stop AI agents from acting outside the limits set by the people running them. The platform combines OpenShell, Nvidia&#8217;s open-source agent sandbox, which is now generally available to everyone, with Sentry, a new [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Nvidia on Monday, 28 September 2026, launched the Open Agent Safety Platform, an open software stack and reference hardware design built to stop AI agents from acting outside the limits set by the people running them. The platform combines OpenShell, Nvidia&#8217;s open-source agent sandbox, which is now generally available to everyone, with Sentry, a new hardware-backed watchdog that Nvidia says can quarantine an agent trying to cross its boundaries within milliseconds, according to <a href="https://nvidianews.nvidia.com/news/open-agent-safety-platform" target="_blank" rel="noreferrer noopener nofollow">Nvidia&#8217;s announcement</a>.</p>



<p class="wp-block-paragraph">The launch follows a summer in which AI agents from OpenAI and Anthropic broke out of test environments and reached real companies and government systems, including an Australian Medicare statistics portal and several US federal websites. Nvidia says more than 100 organisations, among them Anthropic, Microsoft, CrowdStrike, Cisco, Palantir and SpaceXAI, are working with the platform&#8217;s technologies.</p>



<h2 class="wp-block-heading">How OpenShell and Sentry work</h2>



<p class="wp-block-paragraph">OpenShell, first announced at Nvidia&#8217;s GTC conference in March, runs each AI agent inside a sandbox with kernel-level isolation, meaning the agent&#8217;s activity is contained at the core of the operating system rather than inside the app. Operators decide which files, networks, tools, processes and credentials an agent may touch. OpenShell checks that policy before the agent starts and enforces it while the agent works, Nvidia explained in a <a href="https://developer.nvidia.com/blog/nvidia-open-agent-safety-platform-a-reference-for-continuous-in-silicon-agent-monitoring/" target="_blank" rel="noreferrer noopener nofollow">technical blog post</a>. The code is on <a href="https://github.com/NVIDIA/OpenShell" target="_blank" rel="noreferrer noopener nofollow">GitHub</a> under the Apache 2.0 licence.</p>



<p class="wp-block-paragraph">Sentry is a second, independent layer. It runs on Nvidia&#8217;s BlueField-4 data processing unit (DPU), a programmable chip that sits on a server&#8217;s only path to the AI model. That position keeps Sentry isolated from the host machine and out of the agent&#8217;s reach. Built on Nvidia&#8217;s DOCA software, Sentry inspects what agents send to and receive from the model, verifies each agent&#8217;s identity and records tamper-resistant telemetry. Nvidia says this lets it catch &#8220;drift,&#8221; its term for an agent wandering away from its assigned task.</p>



<p class="wp-block-paragraph">For customers already running Nvidia Vera systems with BlueField-4, Nvidia says turning on these protections takes only a software update. The company has not published pricing for Sentry deployments.</p>



<p class="wp-block-paragraph">The design rests on one argument. Nvidia&#8217;s engineers wrote that an agent stuck on a hard, long-running task cannot be trusted to fully police itself, so the controls have to sit outside it. Justin Boitano, Nvidia&#8217;s vice president of enterprise computing, told WIRED that agents are &#8220;very creative at finding ways to achieve the goals that they&#8217;re given.&#8221; He said Nvidia is working with Arm and Intel on a version of Sentry for x86 chips, but gave no release date.</p>



<p class="wp-block-paragraph">&#8220;AI&#8217;s extraordinary potential for society will only be realized if we solve AI safety,&#8221; Nvidia chief executive Jensen Huang said in the announcement. Huang has previously called fears of an existential AI threat overblown, CNN reported, and he is now selling hardware built around the premise that agents cannot be left to govern themselves.</p>



<h2 class="wp-block-heading">Who is signing on</h2>



<p class="wp-block-paragraph">Anthropic said its Claude Managed Agents now integrate with OpenShell and BlueField, and chief commercial officer Paul Smith described Nvidia&#8217;s platform as an added layer of governance on top of Anthropic&#8217;s own controls. SpaceXAI is using the platform for its Cursor coding agents and Grok models. Salesforce has wired OpenShell into Slack so teams can approve or reject an agent&#8217;s request for more permissions, and SAP is embedding it in its Joule Studio runtime. Red Hat, Canonical and SUSE are building it into their operating systems.</p>



<p class="wp-block-paragraph">HP said it will build AI infrastructure components with the platform&#8217;s technologies. Interim chief executive Bruce Broussard said security &#8220;has to be built in from the start.&#8221; CrowdStrike&#8217;s Bartley Richardson wrote in a <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-nvidia-extend-security-across-ai-stack/" target="_blank" rel="noreferrer noopener nofollow">company blog post</a> that an agent &#8220;shouldn&#8217;t be responsible for enforcing its own security boundaries.&#8221; Cloudflare said in a post on X that it splits the job with OpenShell: Nvidia&#8217;s runtime controls what an agent can do on its host, while Cloudflare&#8217;s Zero Trust policies control what the agent can reach, including the internet, private applications, MCP servers and models.</p>



<p class="wp-block-paragraph">One name is absent from the partner list. OpenAI is not on it, even though both companies told WIRED it is part of the OpenShell effort. Neither explained the omission. WIRED also noted it is unclear how many listed partners have actually deployed OpenShell rather than simply endorsing it.</p>



<h2 class="wp-block-heading">The breaches behind the launch</h2>



<p class="wp-block-paragraph">Anthropic said on 30 July that it had reviewed 141,006 cybersecurity evaluation runs and found three incidents, the earliest in April, in which Claude models escaped test environments and compromised real organisations. According to <a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals" target="_blank" rel="noreferrer noopener nofollow">Anthropic&#8217;s report</a>, a misunderstanding with its evaluation partner left the environment connected to the internet. The models believed they were in a capture-the-flag exercise and used weak passwords and unauthenticated endpoints to get in.</p>



<p class="wp-block-paragraph"><a href="https://www.cyberkendra.com/2026/07/openai-missed-its-own-rogue-ai-agent.html" target="_blank" rel="noreferrer noopener">Cyber Kendra reported in July</a> that OpenAI agents broke into Hugging Face between 11 and 13 July, that Hugging Face disclosed the breach on 16 July, and that OpenAI staff only found traces in their own logs days later. OpenAI&#8217;s <a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/" target="_blank" rel="noreferrer noopener nofollow">incident report</a> says the agents executed code on dozens of Hugging Face servers, gained root access on one and harvested credentials. AI evaluation nonprofit METR estimated that about 700 agents collaborated in the attack, <a href="https://www.darkreading.com/cyberattacks-data-breaches/hundreds-openai-agents-invaded-hugging-face-servers" target="_blank" rel="noreferrer noopener nofollow">Dark Reading reported</a>.</p>



<p class="wp-block-paragraph">The first known case involving a government system came from Australia. As <a href="https://www.cyberkendra.com/2026/09/openai-agent-medicare-portal-breach-australia.html" target="_blank" rel="noreferrer noopener">Cyber Kendra reported</a>, Prime Minister Anthony Albanese said on 23 September that an OpenAI agent had accessed Services Australia&#8217;s Medicare Statistics Reporting Service portal on 18 June and viewed both public and non-public files. </p>



<p class="wp-block-paragraph">He said no personal Medicare records appear to have been touched. OpenAI did not tell the government until 10 September, and then only by email to a public inbox, the <a href="https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078" target="_blank" rel="noreferrer noopener nofollow">ABC reported</a>. Cyber Kendra&#8217;s analysis of the dataset released by AI lab Transluce found 4,844 scan records tied to the Australian Institute of Health and Welfare, nearly all logged between 17 and 21 June. Australia has since opened a task force investigation.</p>



<p class="wp-block-paragraph">On 25 September, OpenAI confirmed its agents had used developer keys found online to reach Census Bureau data and had reposted public Securities and Exchange Commission (SEC) information on another website. Separately, Transluce flagged a failed attempt by OpenAI-linked agents to hack a Department of Education civil rights site, <a href="https://www.nextgov.com/cybersecurity/2026/09/openai-says-its-advanced-models-may-have-gone-after-government-websites/416250/" target="_blank" rel="noreferrer noopener nofollow">Nextgov reported</a>. OpenAI said it found no access to nonpublic SEC data, and the Education Department said its reviews found no impact on its systems. The disclosures follow a <a href="https://www.cyberkendra.com/2026/09/openai-model-misalignment-reporting-framework.html" target="_blank" rel="noreferrer noopener nofollow">misalignment-reporting framework OpenAI launched on 16 September</a>, which included cases of models using an exposed API key without authorisation and uploading task files to public hosting sites.</p>



<p class="wp-block-paragraph">The same day, OpenAI disclosed that on 20 September, an agent had escaped a supposedly internet-free training environment by tunnelling queries through its DNS resolver, the service that turns web addresses into server locations, to reach a public chatbot. OpenAI&#8217;s monitoring flagged the activity within 15 minutes, but the automatic shutdown failed, and staff stopped the run manually about two and a half hours later. OpenAI has paused training, evaluation and tool-using inference on its most capable models, <a href="https://fortune.com/2026/09/26/openai-ai-agents-secure-sandbox-escape-training-pause-second-time-hugging-face-hack/" target="_blank" rel="noreferrer noopener nofollow">Fortune reported</a>. That is its second pause in under three months.</p>



<p class="wp-block-paragraph">Security researcher Niels Provos, speaking generally about agent-containment tools, told WIRED that such tools help &#8220;dispel the myth that agents can&#8217;t be controlled.&#8221;</p>



<p class="wp-block-paragraph">Ordinary ChatGPT and Claude users do not need to do anything; the platform is aimed at labs and enterprises running agents on their own infrastructure. Several questions remain open. Nvidia has not said when the x86 version of Sentry will ship. Its millisecond-quarantine claim has not been tested independently. And no one has said whether Sentry would have caught a network-layer escape like OpenAI&#8217;s DNS tunnel, or why the lab at the centre of most of these incidents is missing from the launch.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cyberkendra.com/2026/09/nvidia-open-agent-safety-platform-openshell-sentry.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			<dc:creator>protalweb@gmail.com (Vivek Gurung)</dc:creator></item>
		<item>
		<title>Citrix Patches Two Exploited NetScaler RCE Zero-Days</title>
		<link>https://www.cyberkendra.com/2026/09/cve-2026-88771-netscaler-zero-days-exploited.html</link>
					<comments>https://www.cyberkendra.com/2026/09/cve-2026-88771-netscaler-zero-days-exploited.html#respond</comments>
		
		
		<pubDate>Sun, 27 Sep 2026 16:49:59 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.cyberkendra.com/?p=12894</guid>

					<description><![CDATA[Citrix on Sunday released patches for two critical NetScaler ADC and NetScaler Gateway vulnerabilities that attackers exploited as zero-days, one of which allows unauthenticated command execution on appliances running the default configuration. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, each carry a CVSS v4 score of 9.5. They are among eight vulnerabilities addressed in security [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Citrix on Sunday released patches for <a href="https://www.cyberkendra.com/2026/09/netscaler-shutdown-warning-unverified-rce-flaws.html" target="_blank" data-type="link" data-id="https://www.cyberkendra.com/2026/09/netscaler-shutdown-warning-unverified-rce-flaws.html" rel="noreferrer noopener nofollow">two critical NetScaler ADC and NetScaler Gateway vulnerabilities that attackers exploited as zero-days</a>, one of which allows unauthenticated command execution on appliances running the default configuration.</strong></p>



<p class="wp-block-paragraph">The flaws, tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-88771" target="_blank" rel="nofollow noopener noreferrer">CVE-2026-88771</a> and <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-88772" target="_blank" rel="nofollow noopener noreferrer">CVE-2026-88772</a>, each carry a CVSS v4 score of 9.5. They are among eight vulnerabilities addressed in security bulletin <a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096" target="_blank" rel="nofollow noopener noreferrer">CTX697096</a>.</p>



<p class="wp-block-paragraph">&#8220;Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,&#8221; Citrix said. The company did not say who was behind the attacks, how many organisations were hit, or when exploitation began.</p>



<p class="wp-block-paragraph">The Dutch National Cyber Security Centre (NCSC-NL) issued an <a href="https://advisories.ncsc.nl/2026/ncsc-2026-0394.html" target="_blank" rel="nofollow noopener noreferrer">advisory</a> on Sunday evening with a high priority rating, urging organisations to apply the updates urgently. The agency said Secure Private Access Hybrid deployments that use NetScaler instances are also vulnerable. The flaws affect customer-managed appliances, and Cloud Software Group updates Citrix-managed cloud services itself.</p>



<p class="wp-block-paragraph">The fixes are in NetScaler ADC and NetScaler Gateway 14.1-73.37 and 13.1-64.23, NetScaler ADC 14.1-73.37 FIPS, and 13.1.37.279 for the 13.1-FIPS and 13.1-NDcPP editions. Appliances updated in August for the exploited authentication bypass CVE-2026-19490 remain vulnerable, because those builds, 14.1-73.32 and 13.1-63.21, predate the new fixes.</p>



<p class="wp-block-paragraph">CVE-2026-88771 is an improper input validation flaw that lets a remote, unauthenticated attacker execute arbitrary commands on the appliance. According to Citrix, every NetScaler ADC and NetScaler Gateway deployment is affected, including those left at their default configuration, and no additional features need to be enabled.</p>



<p class="wp-block-paragraph">CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service. It can only be exploited when DTLS, the UDP-based version of the TLS encryption protocol, is enabled, and NetScaler turns DTLS on by default for VPN virtual servers.</p>



<p class="wp-block-paragraph">The patches follow a weekend in which organisations <a href="https://www.cyberkendra.com/2026/09/netscaler-shutdown-warning-unverified-rce-flaws.html" target="_blank" rel="nofollow noopener noreferrer">took NetScaler appliances offline</a> after IT suppliers and CERT teams relayed shutdown advice attributed to NCSC-NL. On Saturday, security firm watchTowr said two unpatched NetScaler RCE flaws had been exploited in the wild and were discovered during forensic investigations.</p>



<p class="wp-block-paragraph">The new zero-days follow two other NetScaler flaws that were exploited this year. CISA added <a href="https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog" target="_blank" rel="nofollow noopener noreferrer">CVE-2026-8452</a> to its Known Exploited Vulnerabilities catalog in August and <a href="https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog" target="_blank" rel="nofollow noopener noreferrer">CVE-2026-19490</a> on September 9. As of publication, the agency had not listed either of the new flaws.</p>



<h2 class="wp-block-heading">Which NetScaler deployments are affected?</h2>



<p class="wp-block-paragraph">Citrix said that every NetScaler ADC and NetScaler Gateway deployment is affected by at least one of the eight flaws and recommends upgrading immediately. The remaining six vulnerabilities depend on which features and virtual servers are configured.</p>



<p class="wp-block-paragraph">For CVE-2026-88772, a VPN virtual server configured with <code>-dtls OFF</code> is not exposed. A VPN virtual server without that setting has DTLS enabled by default, as does any DTLS-type virtual server.</p>



<p class="wp-block-paragraph">CVE-2026-88773, an HTTP request smuggling flaw that Citrix found internally, is rated critical with a CVSS score of 9.3. It affects appliances with load balancing, content switching, VPN or authentication virtual servers of type HTTP or SSL. CVE-2026-88774 (CVSS 7.0) lets URLs that are not normalised slip past web application firewall and security rules; NCSC-NL said it applies only where HTTP URL-based policy expressions are configured, and Citrix said it has been fixed since the 14.1-72 builds.</p>



<p class="wp-block-paragraph">Three more memory overflows, each rated at 8.8, can cause erratic behaviour or denial-of-service. CVE-2026-88775 affects appliances configured as a Gateway or AAA virtual server. CVE-2026-88776 affects load-balancing virtual servers of the Oracle type. CVE-2026-88777 affects load balancing, content switching and CGNAT (LSN/NAT64) deployments that use non-HTTP Layer 7 features such as FTP, RTSP, DNS64 or NAT64.</p>



<p class="wp-block-paragraph">CVE-2026-88778 (CVSS 8.8) allows TCP initial sequence number prediction on appliances with TCP-based virtual servers where Enhanced ISN Generation is disabled. Running <code>show ns tcpparam | grep "Enhanced ISN Generation"</code> shows the setting, and fixing this flaw requires a configuration change in addition to the update.</p>



<h2 class="wp-block-heading">What should admins check before upgrading?</h2>



<p class="wp-block-paragraph">NCSC-NL advises saving relevant logs and a memory dump before installing the update, so that forensic evidence of any earlier exploitation is preserved for investigation.</p>



<p class="wp-block-paragraph">The Security Advisory feature in NetScaler Console may wrongly flag appliances on 13.1-64.23 as vulnerable. Citrix said an automatic advisory update will correct this, and no Console or appliance upgrade is needed.</p>



<p class="wp-block-paragraph">The new builds also stop accepting unsigned SAML assertions. Any configuration that sets <code>samlRejectUnsignedAssertion</code> to OFF is converted to the secure default during the upgrade, so identity providers must issue signed assertions.</p>



<p class="wp-block-paragraph">Organisations that powered their NetScalers down over the weekend can now apply the update before bringing the appliances back online.</p>



<h2 class="wp-block-heading">How can admins check NetScaler for compromise?</h2>



<p class="wp-block-paragraph">Citrix is making generic indicators of compromise available through the Security Advisory page in NetScaler Console, both in the cloud service and on-premises, starting with Console 14.1-73.36 and later with Cloud Connect. The scan requires the telemetry channel to be enabled and appears only once Citrix releases the detection logic. Customers who do not use Console can ask Citrix Support for the indicators or for help running the scan.</p>



<p class="wp-block-paragraph">Citrix cautioned that the indicators do not cover every technique attackers use and may fail to identify actual compromises, and it advised hiring experienced forensic investigators. The company also recommends NetScaler Console&#8217;s File Integrity Monitoring and forwarding NetScaler logs to an external SIEM.</p>



<p class="wp-block-paragraph">Updating does not remove an attacker who is already inside an appliance. Because both zero-days were exploited before fixes existed, NCSC-NL advises treating any system exposed before the update as possibly compromised, noting that the patch prevents new exploitation but does not rule out earlier abuse.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cyberkendra.com/2026/09/cve-2026-88771-netscaler-zero-days-exploited.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			<dc:creator>protalweb@gmail.com (Vivek Gurung)</dc:creator></item>
		<item>
		<title>Unpatched NetScaler Zero-Days Exploited, watchTowr Says</title>
		<link>https://www.cyberkendra.com/2026/09/netscaler-shutdown-warning-unverified-rce-flaws.html</link>
					<comments>https://www.cyberkendra.com/2026/09/netscaler-shutdown-warning-unverified-rce-flaws.html#respond</comments>
		
		
		<pubDate>Sat, 26 Sep 2026 17:43:08 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[ZeroDay Bug]]></category>
		<category><![CDATA[Citrix NetScaler]]></category>
		<category><![CDATA[zeroday]]></category>
		<guid isPermaLink="false">https://www.cyberkendra.com/?p=12874</guid>

					<description><![CDATA[Two unpatched remote code execution vulnerabilities in Citrix NetScaler have been exploited in the wild as zero-days, security firm watchTowr said on Saturday, as organisations take appliances offline ahead of patches Citrix is expected to release early next week. Update: Citrix has released patches for the two exploited zero-days, now tracked as CVE-2026-88771 and CVE-2026-88772. [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong><strong><strong>Two unpatched remote code execution vulnerabilities in Citrix NetScaler have been exploited in the wild as zero-days, security firm watchTowr said on Saturday, as organisations take appliances offline ahead of patches Citrix is expected to release early next week.</strong></strong></strong></p>



<p class="wp-block-paragraph"><strong>Update:</strong> Citrix has released patches for the two exploited zero-days, now tracked as CVE-2026-88771 and CVE-2026-88772. <a href="https://www.cyberkendra.com/2026/09/cve-2026-88771-netscaler-zero-days-exploited.html">Read our full coverage of the Citrix NetScaler patches</a>.</p>



<p class="wp-block-paragraph">In a <a href="https://x.com/watchtowrcyber/status/2103972792043479307" target="_blank" data-type="link" data-id="https://x.com/watchtowrcyber/status/2103972792043479307" rel="noreferrer noopener nofollow">follow-up post on X</a>, watchTowr said the exploitation was discovered during forensic investigations, and that Citrix&#8217;s communications and patches are expected early next week. The two flaws match the number that administrators had been warned about earlier in the day. The company asked that further questions go to Citrix, noting that it is not the vendor&#8217;s product security team.</p>



<p class="wp-block-paragraph">Earlier in the day, watchTowr said in a <a href="https://x.com/watchtowrcyber/status/2103891689857228803" target="_blank" rel="noreferrer noopener nofollow">post on X</a> that it was reacting to reports that several unpatched NetScaler RCE vulnerabilities are circulating in the wild, and that details remain scarce. The company said it had notified customers of its exposure management platform about their NetScaler exposure. Its alert describes the issue as an unconfirmed zero-day affecting NetScaler ADC and NetScaler Gateway.</p>



<p class="wp-block-paragraph">watchTowr has not named any CVE IDs, affected builds or configurations, or said which organisations were targeted. It said it had verified the reports with authoritative sources, in reply to a security researcher who asked on X how the intelligence could be credible with so few details public.</p>



<p class="wp-block-paragraph">The shutdowns first surfaced in a <a href="https://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/" data-type="link" data-id="https://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/" target="_blank" rel="noopener">Reddit thread on r/Citrix</a> titled &#8220;Netscaler leak?&#8221;, which had more than 75 upvotes and 50 comments by Saturday evening. The thread&#8217;s author, a user named FastFredNL, said their IT supplier&#8217;s security team called and advised an immediate shutdown but gave no details.</p>



<p class="wp-block-paragraph">FastFredNL said the supplier normally advises customers to update quickly or change a setting as a temporary mitigation. This time the supplier said, &#8220;this is a big one and there&#8217;s no fix yet, shut it down.&#8221;</p>



<p class="wp-block-paragraph">According to FastFredNL, the two flaws allow remote code execution with little effort and have not yet been assigned CVE IDs or severity scores. More information and possibly a software update are expected after the weekend, the user added.</p>



<h2 class="wp-block-heading">Who is telling admins to shut NetScaler down?</h2>



<p class="wp-block-paragraph">FastFredNL said the supplier gets its information directly from NCSC-NL. The user&#8217;s understanding is that the agency reported the flaws to Citrix and then advised organisations to power down rather than wait for a fix. Cyber Kendra has not confirmed that account.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img decoding="async" width="1024" height="849" src="https://www.cyberkendra.com/wp-content/uploads/2026/09/HTJtS5bXoAAtBvB-1024x849.webp" alt="Citrix NetScaler Reddit Thread" class="wp-image-12878" style="aspect-ratio:1.2061467091910698;width:592px;height:auto" srcset="https://www.cyberkendra.com/wp-content/uploads/2026/09/HTJtS5bXoAAtBvB-1024x849.webp 1024w, https://www.cyberkendra.com/wp-content/uploads/2026/09/HTJtS5bXoAAtBvB-300x249.webp 300w, https://www.cyberkendra.com/wp-content/uploads/2026/09/HTJtS5bXoAAtBvB-768x637.webp 768w, https://www.cyberkendra.com/wp-content/uploads/2026/09/HTJtS5bXoAAtBvB-480x398.webp 480w, https://www.cyberkendra.com/wp-content/uploads/2026/09/HTJtS5bXoAAtBvB-680x564.webp 680w, https://www.cyberkendra.com/wp-content/uploads/2026/09/HTJtS5bXoAAtBvB.webp 1320w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>
</div>


<p class="wp-block-paragraph">Another administrator in the thread said their organisation shut its NetScalers down based on an NCSC notification. The notice arrived through the organisation&#8217;s CERT team rather than the NCSC website, and management made the decision. A third said their appliances were offline while they waited for word from their CSIRT, the NCSC or Citrix.</p>



<p class="wp-block-paragraph">Other administrators received nothing. One found no notice on the NCSC site and no email from the agency, and said an earlier comment mentioning the notice had been deleted without explanation. Another said their Citrix technical account manager had heard nothing.</p>



<p class="wp-block-paragraph">FastFredNL rejected suggestions that the warning concerns <strong>CVE-2026-19490</strong>, a critical authentication bypass that Citrix <a href="https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html" target="_blank" rel="nofollow noopener noreferrer">patched on August 19</a> and that has been <a href="https://www.securityweek.com/critical-netscaler-vulnerability-exploited-in-attacks/" target="_blank" rel="nofollow noopener noreferrer">exploited since September 3</a>. If it did, the user said, the supplier would have named it.</p>



<p class="wp-block-paragraph">watchTowr made the same point. Replying to a post that tied the shutdowns to CVE-2026-19490, the company said the new issue is a different vulnerability and warned against confusing the two.</p>



<h2 class="wp-block-heading">Has Citrix or the NCSC confirmed new NetScaler flaws?</h2>



<p class="wp-block-paragraph">Not as of publication. The most recent NetScaler bulletin Cyber Kendra found is CTX696939, which covers CVE-2026-19489 and CVE-2026-19490. NCSC-NL&#8217;s newest public advisory, <a href="https://advisories.ncsc.nl/2026/ncsc-2026-0318.html" target="_blank" rel="nofollow noopener noreferrer">NCSC-2026-0318</a>, covers the same two flaws, and the agency raised its rating to high.</p>



<p class="wp-block-paragraph">With no advisory published, it is unknown which NetScaler configurations or builds are affected, or whether appliances on the latest fixed builds, 14.1-73.32 and 13.1-63.21, are exposed.</p>



<p class="wp-block-paragraph">The NetScaler reports came the same weekend that Kiteworks asked customers to shut down its file-sharing servers over a possible imminent attack. Kiteworks&#8217; CISO cited <a href="https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/" target="_blank" rel="nofollow noopener noreferrer">intelligence from law enforcement</a>, while the company&#8217;s <a href="https://www.kiteworks.com/company/press-releases/kiteworks-precautionary-shutdown-advisory/" target="_blank" rel="nofollow noopener noreferrer">press release</a> refers to federal intelligence authorities and a nine-hour window. Several Reddit users asked whether the two warnings are connected. Nothing published so far links them.</p>



<p class="wp-block-paragraph">The Dutch agency has advised a Citrix shutdown before. In January 2020, NCSC-NL <a href="https://www.bleepingcomputer.com/news/security/dutch-govt-suggests-turning-off-citrix-adc-devices-mitigations-may-fail/" target="_blank" rel="nofollow noopener noreferrer">told organisations to consider switching off</a> Citrix ADC and Gateway during attacks on CVE-2019-19781, after concluding that Citrix&#8217;s interim mitigations did not work reliably. Two government ministers <a href="https://www.security.nl/posting/640694/Ministers+gaven+toestemming+voor+advies+Citrix+uit+te+schakelen" target="_blank" rel="nofollow noopener noreferrer">approved that advice</a>, which, unlike the current warning, was issued publicly.</p>



<p class="wp-block-paragraph">In July 2025, NCSC-NL sent confidential alerts to organisations it believed had been hit through CVE-2025-6543, weeks before confirming that the flaw had been <a href="https://www.helpnetsecurity.com/2025/08/12/citrix-netscaler-exploitation-zero-day-cve-2025-6543/" target="_blank" rel="nofollow noopener noreferrer">exploited as a zero-day</a> against critical Dutch organisations. More recently, Citrix first described CVE-2026-8452 as a denial-of-service bug, until <a href="https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/" target="_blank" rel="nofollow noopener noreferrer">watchTowr showed</a> that it allows root-level code execution.</p>



<h2 class="wp-block-heading">What should NetScaler admins do before Monday?</h2>



<p class="wp-block-paragraph">Users in the thread suggested stopgaps for teams that cannot go offline: blocking internet access and allowing only a temporary list of employee addresses, or disabling DTLS and watching the crash dumps folder. </p>



<p class="note wr"><strong>Note:</strong> None of this guidance comes from Citrix, and its effect on the unpublished flaws is unknown. Restricting inbound access to trusted IP ranges matches the interim advice <a href="https://cert.europa.eu/publications/security-advisories/2023-075/" target="_blank" rel="nofollow noopener noreferrer">Mandiant gave during earlier NetScaler attacks</a>.</p>



<p class="wp-block-paragraph">Because the flaws were exploited before any patch existed, shutting down or patching an appliance will not remove an attacker who is already inside it. In 2025, NCSC-NL warned that intruders could keep access after patches were applied, and it published compromise-check scripts for NetScaler images and core dumps.</p>



<h2 class="wp-block-heading">Updates</h2>



<p class="wp-block-paragraph"><strong>2026-09-27:</strong> Citrix published bulletin CTX697096, confirming exploitation of CVE-2026-88771 and CVE-2026-88772 and releasing fixes in 14.1-73.37 and 13.1-64.23. <a href="https://www.cyberkendra.com/2026/09/cve-2026-88771-netscaler-zero-days-exploited.html">Full details here</a>.</p>



<p class="wp-block-paragraph"><strong>2026-09-27:</strong> watchTowr says the two NetScaler flaws are unpatched zero-days exploited in the wild, discovered during forensic investigations, with Citrix communications and patches expected early next week. Headline and story updated.</p>



<p class="wp-block-paragraph"><strong>2026-09-27:</strong> Added watchTowr&#8217;s statements that it has verified the reports with authoritative sources and that the issue is not CVE-2026-19490. Citrix and NCSC-NL have still not published an advisory.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cyberkendra.com/2026/09/netscaler-shutdown-warning-unverified-rce-flaws.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			<dc:creator>protalweb@gmail.com (Vivek Gurung)</dc:creator></item>
		<item>
		<title>DMARC Compliance Requirements: Everything Businesses Need To Know</title>
		<link>https://www.cyberkendra.com/2026/09/dmarc-compliance-requirements-everything-businesses-need-to-know.html</link>
					<comments>https://www.cyberkendra.com/2026/09/dmarc-compliance-requirements-everything-businesses-need-to-know.html#respond</comments>
		
		
		<pubDate>Sat, 26 Sep 2026 17:31:00 +0000</pubDate>
				<category><![CDATA[Domains]]></category>
		<category><![CDATA[Tips]]></category>
		<guid isPermaLink="false">https://www.cyberkendra.com/?p=12880</guid>

					<description><![CDATA[Email remains one of the most important communication channels for businesses, but it is also a common target for spoofing, phishing, and impersonation attacks. DMARC compliance helps organizations strengthen email authentication by working with SPF and DKIM to verify legitimate senders and define how receiving mail servers should handle unauthorized messages.&#160; From publishing accurate DNS [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Email remains one of the most important communication channels for businesses, but it is also a common target for spoofing, phishing, and impersonation attacks. DMARC compliance helps organizations strengthen email authentication by working with SPF and DKIM to verify legitimate senders and define how receiving mail servers should handle unauthorized messages.&nbsp;</p>



<p class="wp-block-paragraph">From publishing accurate DNS records and maintaining <strong>identifier alignment to monitoring</strong> DMARC reports and gradually enforcing stronger policies, businesses need a structured approach to achieve effective protection. This guide explains the key DMARC compliance requirements, implementation steps, common challenges, and ongoing management practices businesses should know to protect their domains and improve email security.</p>



<h2 class="wp-block-heading">What DMARC Compliance Means and Why It Matters for Businesses</h2>



<p class="wp-block-paragraph">DMARC compliance represents an organization’s ability to properly implement and maintain Domain-based Message Authentication, Reporting, and Conformance (DMARC) controls to validate outbound emails, protect against spoofing, and secure their <a href="https://www.activecampaign.com/blog/domain-reputation" target="_blank" rel="noreferrer noopener nofollow">domain reputation</a>. At its core, DMARC compliance ensures that every email sent under a company’s domain <strong>passes key authentication protocols</strong>—namely SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail)—and aligns with the DMARC policy published in the DNS records.</p>



<p class="wp-block-paragraph">Attaining DMARC compliance is vital for businesses looking to protect sensitive information, maintain brand trust, and shield themselves from email-based attacks such as phishing, impersonation attacks, and business email compromise. <em>As digital communications become increasingly targeted by threat actors, DMARC authentication and enforcement have become mandatory for organizations aiming for robust email security and domain authentication.</em></p>



<p class="wp-block-paragraph">Moreover, regulatory and industry frameworks, influenced by standards formalized in RFC 7489 by the IETF DMARC Working Group, are increasingly encouraging or requiring businesses to achieve DMARC compliance. This broad push not only mitigates risks of email scams but also enables better reporting, faster detection of misconfigurations, and <strong>ongoing protection against spoofing</strong> activities.</p>



<h2 class="wp-block-heading">Core DMARC Requirements: SPF, DKIM, DNS Records, and Policy Alignment</h2>



<p class="wp-block-paragraph">Achieving and maintaining DMARC compliance entails more than simply publishing a DMARC record. The following technical components form the foundation of genuine DMARC readiness:</p>



<h3 class="wp-block-heading">SPF—Sender Policy Framework</h3>



<p class="wp-block-paragraph">SPF specifies which mail servers are authorized to send email for your domain. The domain owner must publish an accurate SPF record as a TXT record in their DNS. This record lists the IP addresses and servers permitted to send mail. Email servers use this information for sender verification, bolstering defenses against <strong>phishing and spoofing</strong>.</p>



<h3 class="wp-block-heading">DKIM—DomainKeys Identified Mail</h3>



<p class="wp-block-paragraph"><em>DKIM applies a cryptographic signature to outgoing email headers, allowing receiving email servers to validate that the content has not been altered in transit and that the message is genuinely from the claimed domain.</em> DKIM signature alignment—ensuring that the “From” domain matches (or is aligned) with the DKIM domain—is a key DMARC requirement.</p>



<h3 class="wp-block-heading">Publishing a DMARC Record</h3>



<p class="wp-block-paragraph">A valid DMARC record, published as a <a href="https://www.cloudflare.com/learning/dns/dns-records/dns-txt-record/" target="_blank" rel="noreferrer noopener nofollow">DNS TXT record</a>, specifies the DMARC policy, reporting endpoints, and <strong>compliance preferences</strong> for receiving mail servers. A DMARC record typically contains DMARC tags such as p, *rua*, *ruf*, *adkim*, *aspf*, *pct*, *ri*, and others. For example, the p tag sets the DMARC policy (*p=none*, *p=quarantine*, or *p=reject*), while *rua* and *ruf* define where DMARC aggregate reports and forensic reports should be sent.</p>



<p class="wp-block-paragraph">Adhering to correct DMARC syntax and DMARC standards as outlined in RFC 7489 is critical for policy distribution and effective message validation.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img decoding="async" width="700" height="382" src="https://www.cyberkendra.com/wp-content/uploads/2026/09/image-5.webp" alt="" class="wp-image-12881" style="aspect-ratio:1.8352941176470587;width:774px;height:auto" srcset="https://www.cyberkendra.com/wp-content/uploads/2026/09/image-5.webp 700w, https://www.cyberkendra.com/wp-content/uploads/2026/09/image-5-300x164.webp 300w, https://www.cyberkendra.com/wp-content/uploads/2026/09/image-5-478x261.webp 478w, https://www.cyberkendra.com/wp-content/uploads/2026/09/image-5-680x371.webp 680w" sizes="(max-width: 700px) 100vw, 700px" /></figure>
</div>


<h3 class="wp-block-heading">Policy and Identifier Alignment</h3>



<p class="wp-block-paragraph">DMARC requires “identifier alignment,” meaning the domain identifiers used by SPF and DKIM must match (or align with) the domain in the “From” field. This domain alignment is mandatory per DMARC standards and is checked each time an email undergoes DMARC validation.</p>



<h3 class="wp-block-heading">Subdomain Policy</h3>



<p class="wp-block-paragraph">Enterprises with multiple subdomains should use the sp tag within the DMARC record to define how subdomains are handled. This subdomain policy ensures that even subdomain-based emails are covered by <strong>DMARC authentication and enforcement</strong>.</p>



<h2 class="wp-block-heading">How to Implement DMARC: From Monitoring Mode to Enforcement</h2>



<p class="wp-block-paragraph">Implementing DMARC can be divided into three fundamental phases: monitoring, analysis, and full enforcement.</p>



<h3 class="wp-block-heading">Step 1: Start in Monitoring (p=none) Mode</h3>



<p class="wp-block-paragraph">Initially, DMARC is best deployed with a policy of *p=none*. This allows businesses to collect DMARC aggregate reports and forensic reports—using the *rua* and *ruf* DMARC tags—without affecting the delivery of emails. During this phase, IT teams can use DMARC lookup or DMARC check tool solutions like EasyDMARC, MXToolbox, or the tools referenced on dmarc.org to analyze authentication outcomes and <strong>identify potential misconfigurations</strong> in SPF or DKIM.</p>



<h3 class="wp-block-heading">Step 2: Analyze Reports and Adjust Configurations</h3>



<p class="wp-block-paragraph">Aggregate reporting (via XML reports sent to the *rua* email) enables organizations to spot authentication failure trends and verify domain alignment. Forensic reporting (*ruf*) provides detailed information about individual message disposition and aids in identifying spoofing or phishing attempts.</p>



<p class="wp-block-paragraph">Using DMARC record checker and record testing tools, businesses can troubleshoot DMARC syntax errors, SPF misconfigurations, or DKIM alignment gaps. Domain authentication settings must be continually refined to <strong>ensure consistent compliance</strong>.</p>



<h3 class="wp-block-heading">Step 3: Gradually Enforce Stronger Policies (p=quarantine / p=reject)</h3>



<p class="wp-block-paragraph">Once confidence in the configuration is established, organizations should incrementally tighten their DMARC policy to *p=quarantine* (emails that fail DMARC are sent to spam) or full *p=reject* (emails are rejected outright). The process may involve:</p>



<ul class="wp-block-list">
<li>Adjusting the *pct* tag to gradually increase enforcement coverage.</li>



<li>Updating the reporting interval (*ri* tag) to align with reporting protocol requirements and internal review cycles.</li>



<li>Ensuring that all legitimate senders are authorized and any third-party vendors are included in the <strong>SPF and DKIM records</strong>.</li>
</ul>



<p class="wp-block-paragraph"><em>DMARC enforcement at *p=reject* delivers the strongest protection against spoofing and is considered the compliance benchmark by security experts, regulators, and consortia like the IETF DMARC Working Group.</em></p>



<h2 class="wp-block-heading">Common DMARC Compliance Challenges and How to Avoid Them</h2>



<p class="wp-block-paragraph">Despite clear protocols, businesses often face hurdles while aiming for DMARC validation and compliance. Being cognizant of these pitfalls is crucial for a <strong>successful DMARC deployment</strong>.</p>



<h3 class="wp-block-heading">Incomplete or Inaccurate DNS Records</h3>



<p class="wp-block-paragraph">Misconfigured SPF, DKIM, or DMARC records are a common source of authentication failure. Errors in txt record formatting, outdated mail server details, or missing DMARC tags can undermine the entire email authentication ecosystem.</p>



<h3 class="wp-block-heading">Inadequate Identifier Alignment</h3>



<p class="wp-block-paragraph">Poor coordination between the <strong>sender policy framework and DKIM</strong> can result in a lack of domain alignment, leading to emails failing DMARC checks even when authentication passes. Close monitoring using a DMARC check tool allows for regular verification and ensures identifier alignment.</p>



<h3 class="wp-block-heading">Insufficient Reporting and Response Plan</h3>



<p class="wp-block-paragraph">Overlooking DMARC aggregate and forensic reports can leave organizations unaware of fraudulent activities or compliance gaps. A robust compliance action plan should prioritize reviewing XML reports, investigating forensic reporting, and responding to message validation issues quickly.</p>



<h4 class="wp-block-heading">Third-Party Senders and Policy Distribution</h4>



<p class="wp-block-paragraph">Many businesses rely on third-party platforms. Failure to coordinate policy distribution and ensure third-party authorization in SPF/DKIM records jeopardizes DMARC authentication across the <strong>full email ecosystem</strong>.</p>



<h3 class="wp-block-heading">Subdomain Oversight</h3>



<p class="wp-block-paragraph">Not specifying a subdomain policy (sp tag) leaves subdomain emails vulnerable to impersonation attacks and reduces overall brand protection.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img decoding="async" width="700" height="382" src="https://www.cyberkendra.com/wp-content/uploads/2026/09/image-7.webp" alt="" class="wp-image-12883" style="aspect-ratio:1.8352941176470587;width:780px;height:auto" srcset="https://www.cyberkendra.com/wp-content/uploads/2026/09/image-7.webp 700w, https://www.cyberkendra.com/wp-content/uploads/2026/09/image-7-300x164.webp 300w, https://www.cyberkendra.com/wp-content/uploads/2026/09/image-7-478x261.webp 478w, https://www.cyberkendra.com/wp-content/uploads/2026/09/image-7-680x371.webp 680w" sizes="(max-width: 700px) 100vw, 700px" /></figure>
</div>


<h2 class="wp-block-heading">Ongoing DMARC Management: Reporting, Audits, and Maintaining Compliance</h2>



<p class="wp-block-paragraph">DMARC compliance is not a one-off project, but an ongoing commitment demanding continuous oversight.</p>



<h3 class="wp-block-heading">Regular DMARC Record Audits</h3>



<p class="wp-block-paragraph">Routine DMARC lookup and validation—using a DMARC record checker—ensures no <strong>new misconfigurations creep</strong> in. As the sender or organizational structure changes, DNS records and txt record settings must be kept up-to-date and fully aligned with evolving dmarc policy targets.</p>



<h3 class="wp-block-heading">Continuous Report Monitoring</h3>



<p class="wp-block-paragraph">Frequent review of dmarc aggregate reports and forensic reports is essential for proactive email security posture management. <em>Monitoring the reporting interval and message disposition outcomes helps organizations identify new risks, track compliance progress, and refine their DMARC enforcement strategy.</em></p>



<h3 class="wp-block-heading">Staying Informed on Standards</h3>



<p class="wp-block-paragraph">Staying current with updates to DMARC standards (such as RFC 9989, RFC 9990, and RFC 9991), and <strong>referencing leading resources</strong> on EasyDMARC, dmarc.org, and Wikipedia ensures that the organization’s dmarc compliance actions are in line with global best practices.</p>



<h3 class="wp-block-heading">Internal Policy Enforcement and Brand Protection</h3>



<p class="wp-block-paragraph">Comprehensive DMARC deployment enforces effective sender verification, grants protection against spoofing, and assures customers and partners of the organization’s commitment to email security and brand protection. Ongoing training, regular audits, and automated record testing tools should form the backbone of a sustainable <a href="https://dmarcreport.com/blog/what-is-dmarc-compliance-and-how-can-you-achieve-it/" target="_blank" rel="noreferrer noopener">dmarc compliance</a> action plan for every business.</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cyberkendra.com/2026/09/dmarc-compliance-requirements-everything-businesses-need-to-know.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			<dc:creator>protalweb@gmail.com (Vivek Gurung)</dc:creator></item>
		<item>
		<title>Bitget Confirms $351.6M Hot Wallet Hack, Pauses Withdrawals</title>
		<link>https://www.cyberkendra.com/2026/09/bitget-confirms-351-6m-hot-wallet-hack-pauses-withdrawals.html</link>
					<comments>https://www.cyberkendra.com/2026/09/bitget-confirms-351-6m-hot-wallet-hack-pauses-withdrawals.html#respond</comments>
		
		
		<pubDate>Fri, 25 Sep 2026 02:33:20 +0000</pubDate>
				<category><![CDATA[Crypto Currency]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bitget]]></category>
		<category><![CDATA[crypto heist]]></category>
		<category><![CDATA[eth]]></category>
		<guid isPermaLink="false">https://www.cyberkendra.com/?p=12869</guid>

					<description><![CDATA[Bitget has confirmed that attackers drained about $351.6 million from its hot and warm wallets on September 24, 2026, the largest crypto theft of the year so far. CEO Gracy Chen said on X that the exchange detected the unauthorized transfers at 18:31 UTC (12:01 a.m. IST on September 25), paused withdrawals for all users, [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Bitget has confirmed that attackers drained about $351.6 million from its hot and warm wallets on September 24, 2026, the largest crypto theft of the year so far. CEO Gracy Chen <a href="https://x.com/GracyBitget/status/2103235655879074084" target="_blank" rel="noreferrer noopener nofollow">said on X</a> that the exchange detected the unauthorized transfers at 18:31 UTC (12:01 a.m. IST on September 25), paused withdrawals for all users, and will cover the full loss from its User Protection Fund, which she said holds more than $464 million.</p>



<p class="wp-block-paragraph">A day later, Bitget gave its first account of how the break-in worked. On September 25, Chen said the attackers breached a core backend system behind Bitget&#8217;s wallet service. They used it to generate forged transfer requests and ran those requests through the exchange&#8217;s own approval-and-signing process, <a href="https://en.bloomingbit.io/feed/news/121028" target="_blank" rel="noreferrer noopener nofollow">according to Bloomingbit</a> and <a href="https://www.techflowpost.com/en-US/newsletter/137721" target="_blank" rel="noreferrer noopener nofollow">TechFlow</a>. </p>



<p class="wp-block-paragraph">She said Bitget has ruled out a private key leak, meaning the attackers did not steal the keys. Instead they got the system that holds those keys to sign transfers it should have rejected. How they first got into that backend is still under review.</p>



<p class="wp-block-paragraph">Chen said the losses have been fully tallied and there is no further risk of funds leaving the platform. In a live Q&amp;A covered by <a href="https://cointelegraph.com/news/bitget-calls-security-withdrawal-claims-unverified-amid-178m-breach-reports" target="_blank" rel="noreferrer noopener nofollow">Cointelegraph</a>, she listed the affected assets as ETH, XRP, USDT, USDC, AVAX, BNB and USDT0 on Arbitrum. The affected networks were Ethereum, the XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum. She said withdrawals could reopen within hours or days. Deposits and trading were never halted.</p>



<p class="wp-block-paragraph">Bitget&#8217;s figure is roughly double what outside researchers first spotted. Pseudonymous analyst DCF GOD, <a href="https://x.com/bubblemaps/status/2103229553850380794" target="_blank" rel="noreferrer noopener nofollow">Bubblemaps</a> and Arkham analyst Emmett Gallic flagged $174 million to $183 million moving from Bitget-labeled wallets to a freshly created address. Chen said those early estimates only captured the Ethereum side of the attack.</p>



<p class="wp-block-paragraph">The on-chain trail shows an attacker in a hurry. A 0.84 ETH test transfer left a wallet labeled &#8220;Bitget 6&#8221; at 18:31:11 UTC, <a href="https://www.forbes.com/sites/boazsobrado/2026/09/24/bitget-hack-of-3516-million-triggers-a-withdrawal-freeze/" target="_blank" rel="noreferrer noopener nofollow">Forbes reported</a>. It was followed by about $34.75 million in USDT, $19.67 million in USDT0, $12.85 million in USDC and 3,000 XAUT, Tether&#8217;s gold-backed token. Tether and Circle can freeze their tokens, so the attacker quickly swapped them into ether, which no issuer can freeze. DCF GOD <a href="https://x.com/dcfgod/status/2103212139007873136" target="_blank" rel="noreferrer noopener nofollow">noted</a> the buyer was &#8220;paying up to +5% over spot&#8221; on Arbitrum. TechFlow later put the attacker&#8217;s holdings at roughly 68,500 ETH.</p>



<p class="wp-block-paragraph">The same data complicates Bitget&#8217;s account of its response. Chen said emergency protocols kicked in immediately. But Forbes traced a final 223 ETH outflow at 21:23 UTC. That was nearly three hours after detection and seven minutes before Chen&#8217;s public notice went up.</p>



<p class="wp-block-paragraph">Several of Bitget&#8217;s reassurances also rest on its own word for now. Some early on-chain reports described cold reserves among the drained wallets. Bitget says its offline cold storage was untouched, and that claim has not been independently verified. The protection fund launched in 2022 with a $300 million commitment and averaged $382 million in August, according to the company&#8217;s own reports <a href="https://www.thestreet.com/crypto/markets/bitget-ceo-confirms-351-6m-hack-withdrawals-paused" target="_blank" rel="noreferrer noopener nofollow">cited by TheStreet</a>. Outside auditors have not confirmed what the fund currently holds. Bitget&#8217;s token, BGB, fell as much as 5% as news spread.</p>



<p class="wp-block-paragraph">Security specialists say this kind of breach rarely involves breaking cryptography. Ido Sofer, CEO of key management firm Sodot, described the pattern behind the Bybit theft and similar cases this way: &#8220;Those are off-chain hacks that led to on-chain loss of funds.&#8221; His examples included stolen developer credentials, deployment keys and API keys.</p>



<p class="wp-block-paragraph">Chen, for her part, struck a defiant tone: &#8220;We will not run from this.&#8221;</p>



<h2 class="wp-block-heading">What Bitget users should do</h2>



<p class="wp-block-paragraph">Bitget exchange customers don&#8217;t need to take action. The company says balances are accurate and withdrawals will resume after its security review. Users of Bitget Wallet, the company&#8217;s separate self-custody app, got different advice. </p>



<p class="wp-block-paragraph">In a post on X, the Bitget Wallet account urged all users to temporarily revoke approvals granted to its smart contracts while it investigates. Approvals are standing permissions that let a contract move tokens from your wallet. The post did not say whether any wallet contracts were compromised. In the app, approvals can be reviewed and revoked under Wallet > More > Approvals.</p>



<p class="wp-block-paragraph">Within hours of the theft, spoofed tokens named &#8220;ETH,&#8221; &#8220;USDC&#8221; and &#8220;USDT&#8221; began sending transfers from lookalike addresses that differ from the attacker&#8217;s only in the middle characters, Forbes reported. Addresses copied from a block explorer right now may be fakes. Treat any &#8220;recovery&#8221; or &#8220;verification&#8221; prompt tied to the incident as phishing.</p>



<p class="wp-block-paragraph">The Bitget breach is the largest exchange loss since <a href="https://www.cyberkendra.com/2025/02/bybit-suffers-largest-crypto-hack-in.html" data-type="post" data-id="8605" target="_blank" rel="noreferrer noopener">Bybit lost $1.4 billion</a> in February 2025. It also tops the roughly $319 million drained from <a href="https://www.cyberkendra.com/2026/08/core-lightning-vulnerabilities-prompt.html" data-type="post" data-id="8885" target="_blank" rel="noreferrer noopener">Blockstream&#8217;s Liquid Network</a> Liquid Network, which TRM Labs had called 2026&#8217;s biggest hack until now.</p>



<p class="wp-block-paragraph">Bitget has not attributed the attack, and no investigator has publicly tied it to a specific group. Chen said a full incident report with root-cause analysis and corrective actions would follow within 24 hours of her first notice.</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cyberkendra.com/2026/09/bitget-confirms-351-6m-hot-wallet-hack-pauses-withdrawals.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			<dc:creator>protalweb@gmail.com (Vivek Gurung)</dc:creator></item>
		<item>
		<title>Cloudflare Containers Flaw Exposed Cross-Tenant Disk Data</title>
		<link>https://www.cyberkendra.com/2026/09/cloudflare-containers-cross-tenant-disk-data-flaw.html</link>
					<comments>https://www.cyberkendra.com/2026/09/cloudflare-containers-cross-tenant-disk-data-flaw.html#respond</comments>
		
		
		<pubDate>Thu, 24 Sep 2026 17:49:59 +0000</pubDate>
				<category><![CDATA[CloudFlare]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[cloudflare]]></category>
		<category><![CDATA[sandbox bypass]]></category>
		<guid isPermaLink="false">https://www.cyberkendra.com/?p=12866</guid>

					<description><![CDATA[Cloudflare has patched a flaw in its Containers platform that let any customer on a paid Workers plan read leftover data from containers that other customers had previously run on the same server. The flaw was reported by Accomplish security researcher Oren Yomtov, which also affected Cloudflare Sandboxes. According to Cloudflare&#8217;s disclosure, the company has [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Cloudflare has patched a flaw in its Containers platform that let any customer on a paid Workers plan read leftover data from containers that other customers had previously run on the same server. </p>



<p class="wp-block-paragraph">The flaw was reported by Accomplish security researcher Oren Yomtov, which also affected Cloudflare Sandboxes.</p>



<p class="wp-block-paragraph">According to <a href="https://blog.cloudflare.com/containers-cross-tenant-vulnerability/" target="_blank" rel="noreferrer noopener nofollow">Cloudflare&#8217;s disclosure</a>, the company has &#8220;no evidence that customer data has been compromised.&#8221; Customers don&#8217;t need to take any action.</p>



<p class="wp-block-paragraph">The problem traced back to a single configuration flag. Cloudflare Containers carves each container&#8217;s disk out of a shared storage pool using Linux&#8217;s dm-thin thin provisioning. Those pools were set to <code>skip_block_zeroing</code>, so storage freed by one customer&#8217;s deleted container went to the next customer without being wiped.</p>



<p class="wp-block-paragraph">Yomtov&#8217;s proof of concept wrote tiny 4 KiB chunks into empty regions of a fresh container&#8217;s disk. Each write pulled in a recycled 64 KiB block but overwrote only a sliver of it. The other 60 KiB, along with whatever the previous tenant had stored there, stayed readable from the raw disk.</p>



<p class="wp-block-paragraph">The researchers found residual data on 20 of the 22 servers they landed on, spread across four continents. According to the joint write-up, they recovered directory structures, database pages, and complete SQLite databases. </p>



<p class="wp-block-paragraph">In its <a href="https://accomplish.ai/blog/escaping-the-cloudflare-sandbox/" target="_blank" rel="noreferrer noopener nofollow">own post</a>, Accomplish goes further, saying the exposed files included Chromium browser profiles, <code>.env</code> files, and credential files. Accomplish also says Cloudflare&#8217;s Browser Run service was affected.</p>



<p class="wp-block-paragraph">An attacker couldn&#8217;t pick a victim or read a disk that was still in use, and leftover data wasn&#8217;t guaranteed to be there at all. Cloudflare says the researchers&#8217; scripts only counted and format-checked what they found. It adds that the researchers submitted no customer content and have since deleted everything they recovered.</p>



<p class="wp-block-paragraph">Cloudflare confirmed the issue about three hours after the report and shipped a fix that removed the flag the same evening. Turning the flag off only protected new allocations, though. Old data still sat in running container disks and cached image snapshots, so Cloudflare had to drain hosts, restart every virtual machine, and wipe its image caches. That cleanup didn&#8217;t finish until September 19, 15 days after the report was issued.</p>



<p class="wp-block-paragraph">It built detection signatures from the attack&#8217;s telltale pattern of small writes followed by oversized reads and ran them against its retained disk-I/O logs. The only matches came from the researchers and Cloudflare&#8217;s own engineers. The company didn&#8217;t say how far back those logs go or how long the flag had been enabled in production. Yomtov received a bug bounty, but the amount wasn&#8217;t disclosed.</p>



<p class="wp-block-paragraph">The Cloudflare bug is the sixth sandbox escape Accomplish has published since July. The earlier ones hit <a href="https://accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/" target="_blank" rel="noreferrer noopener nofollow">Claude Cowork (SharedRoot)</a>, Claude Code, Cursor CLI, Docker&#8217;s hypervisor, and OpenAI&#8217;s Codex sandbox. The firm&#8217;s takeaway is that isolation &#8220;can fail in many ways.&#8221;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cyberkendra.com/2026/09/cloudflare-containers-cross-tenant-disk-data-flaw.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			<dc:creator>protalweb@gmail.com (Vivek Gurung)</dc:creator></item>
		<item>
		<title>OpenAI Agent Breached Australia’s Medicare Stats Portal</title>
		<link>https://www.cyberkendra.com/2026/09/openai-agent-medicare-portal-breach-australia.html</link>
					<comments>https://www.cyberkendra.com/2026/09/openai-agent-medicare-portal-breach-australia.html#respond</comments>
		
		
		<pubDate>Thu, 24 Sep 2026 06:04:47 +0000</pubDate>
				<category><![CDATA[OpenAI]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Hacked]]></category>
		<category><![CDATA[AI Threats]]></category>
		<category><![CDATA[Medical]]></category>
		<guid isPermaLink="false">https://www.cyberkendra.com/?p=12861</guid>

					<description><![CDATA[An OpenAI AI agent gained unauthorised access to Services Australia&#8217;s Medicare Statistics Reporting Service portal on 18 June 2026 and viewed both public and non-public files, Prime Minister Anthony Albanese said on 23 September. OpenAI did not tell the government until 10 September, nearly three months later, and did so through an email to Services [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">An OpenAI AI agent gained unauthorised access to Services Australia&#8217;s Medicare Statistics Reporting Service portal on 18 June 2026 and viewed both public and non-public files, Prime Minister Anthony Albanese said on 23 September. OpenAI did not tell the government until 10 September, nearly three months later, and did so through an email to Services Australia&#8217;s public inbox, <a href="https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078" target="_blank" rel="noreferrer noopener nofollow">the ABC reported</a>.</p>



<p class="wp-block-paragraph">Albanese, speaking in New York during the UN General Assembly, said he raised both the delay and the way the notification was sent with OpenAI CEO Sam Altman. The agent had been researching public medical spending when it got past the portal&#8217;s protections and &#8220;didn&#8217;t accept &#8216;no&#8217; for an answer,&#8221; Albanese said. The government says there is no evidence that personal Medicare records were accessed, and no sign of a broader compromise of the Services Australia network.</p>



<p class="wp-block-paragraph">OpenAI said the activity surfaced during a wider review of misaligned model behaviour, meaning cases where models act against their developers&#8217; intent. The review found several Australian government websites that its models queried while answering questions about Australia in an internal evaluation. The company said its models &#8220;took actions we did not intend&#8221; and that the material accessed was aggregate health statistics and internal file names. OpenAI says it is giving technical details to the affected agencies.</p>



<p class="wp-block-paragraph">Services Australia reported the incident to the Australian Signals Directorate&#8217;s (ASD) Australian Cyber Security Centre on 15 September. Three more sites may have been involved: the Australian Institute of Health and Welfare (AIHW), the NSW Bureau of Crime Statistics and Research (BOCSAR) and the Victorian Department of Health. Albanese said access to those three has not been confirmed. A taskforce led by the Department of the Prime Minister and Cabinet will review the incident with ASD and the AI Safety Institute.</p>



<p class="wp-block-paragraph">Defence Minister Richard Marles said the data was of low sensitivity and sat on a site with lighter security than systems holding national security information. &#8220;This was really kept behind a fence that the AI agent effectively climbed over,&#8221; Marles told ABC Radio National, <a href="https://www.sbs.com.au/news/article/openai-agent-hacked-medicare-albanese-reveals/qas79d9ta" target="_blank" rel="noreferrer noopener nofollow">SBS reported</a>.</p>



<h2 class="wp-block-heading">What Public Scan Records Show</h2>



<p class="wp-block-paragraph">AI research lab <a href="https://transluce.org/agent-activity" target="_blank" rel="noreferrer noopener nofollow">Transluce reported</a> this week that AI agents used urlquery.net as a remote browser to get around access blocks. The public service loads any submitted link in a sandboxed browser and publishes the result. Transluce says agents tried to hack public data providers on three occasions, including an Australian government website, and it directly links the AIHW activity to the agent swarm OpenAI has confirmed as its own. The lab describes those attempts as minor, involving a small number of probe payloads with no evidence of exploitation. It notes the agents were working on ordinary data-retrieval tasks, not security tests.</p>



<p class="wp-block-paragraph">Cyber Kendra&#8217;s analysis of Transluce&#8217;s released <a href="https://transluce.org/data/urlquery-agent-activity-2026-09-23.zip" target="_blank" data-type="link" data-id="https://transluce.org/data/urlquery-agent-activity-2026-09-23.zip" rel="noreferrer noopener nofollow">dataset</a> (version 5, dated 23 September 2026) puts numbers on that episode. Of the 4,844 urlquery.net reports the dataset ties to AIHW, all but one were logged between 17 and 21 June 2026 (UTC), a window that brackets the 18 June Medicare breach. Activity rose from 29 reports on 17 June to 766 on 18 June and peaked at 1,775 on 20 June. Transluce rates 373 of them &#8220;significant&#8221; because they carried task-specific code that fetched data or submitted forms automatically.</p>



<p class="wp-block-paragraph">OpenAI has not explained why notifying Australia took three months, named the model involved, or said whether it reached the other three sites. Medicare card holders do not need to take any action as of 24 September 2026, and the government has described the taskforce review as urgent.</p>



<p class="wp-block-paragraph">One AIHW report, logged at 06:46 UTC on 20 June, is flagged as a reflected-script probe: a test of whether a site will echo injected code back to a browser. The dataset notes that the flag does not mean any data was recovered. Two custom-code requests against NSW BOCSAR appear on 19 June. The dataset has no entries for Services Australia or the Medicare portal, and Transluce labels its entries as candidate evidence rather than confirmed attribution.</p>



<p class="wp-block-paragraph">Separately, <a href="https://www.abc.net.au/news/2026-09-24/openai-agents-plotted-to-access-data-amid-medicare-hack/107189504" target="_blank" rel="noreferrer noopener nofollow">the ABC found archived posts</a> on DseWiki, a German coding site that OpenAI previously confirmed its agents used to communicate. In those posts, more than a dozen agents mentioned AIHW over 300 times while hunting for government spending data on skin medicines across Victorian council areas. After Cloudflare&#8217;s bot protection blocked them, the agents traded workarounds including proxies, screenshot services and guessed file names. The DseWiki logs make no mention of Medicare or Services Australia, and neither OpenAI nor the government has said whether the two episodes are connected.</p>



<p class="wp-block-paragraph">The Medicare disclosure follows the July incident in which <a href="https://www.cyberkendra.com/2026/07/huggingface-breached-by-autonomous-ai.html" target="_blank" data-type="post" data-id="11605" rel="noreferrer noopener">OpenAI models running an internal cybersecurity evaluation escaped their sandbox and broke into Hugging Face&#8217;s production</a> infrastructure. In that case, OpenAI took about ten days to confirm to Hugging Face that its models were responsible. Transluce says the urlquery.net records show agent activity going back to at least 6 March 2026.</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cyberkendra.com/2026/09/openai-agent-medicare-portal-breach-australia.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			<dc:creator>protalweb@gmail.com (Vivek Gurung)</dc:creator><enclosure length="4570708" type="application/zip" url="https://transluce.org/data/urlquery-agent-activity-2026-09-23.zip"/><itunes:explicit>no</itunes:explicit><itunes:subtitle>An OpenAI AI agent gained unauthorised access to Services Australia&amp;#8217;s Medicare Statistics Reporting Service portal on 18 June 2026 and viewed both public and non-public files, Prime Minister Anthony Albanese said on 23 September. OpenAI did not tell the government until 10 September, nearly three months later, and did so through an email to Services [&amp;#8230;]</itunes:subtitle><itunes:author>Vivek Gurung</itunes:author><itunes:summary>An OpenAI AI agent gained unauthorised access to Services Australia&amp;#8217;s Medicare Statistics Reporting Service portal on 18 June 2026 and viewed both public and non-public files, Prime Minister Anthony Albanese said on 23 September. OpenAI did not tell the government until 10 September, nearly three months later, and did so through an email to Services [&amp;#8230;]</itunes:summary><itunes:keywords>Computer,technology,tech,IT,security,Gadgets,Telecom</itunes:keywords></item>
		<item>
		<title>ShinyHunters Claims FBI Hack, Theft of Employee Data</title>
		<link>https://www.cyberkendra.com/2026/09/shinyhunters-claims-fbi-hack-theft-of-employee-data.html</link>
					<comments>https://www.cyberkendra.com/2026/09/shinyhunters-claims-fbi-hack-theft-of-employee-data.html#respond</comments>
		
		
		<pubDate>Wed, 23 Sep 2026 17:50:31 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[peoplesoft]]></category>
		<category><![CDATA[shiny hunters]]></category>
		<category><![CDATA[zeroday]]></category>
		<guid isPermaLink="false">https://www.cyberkendra.com/?p=12848</guid>

					<description><![CDATA[ShinyHunters claims it hacked the FBI via a PeopleSoft zero-day and stole data on agents and applicants. The FBI is investigating.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>The ShinyHunters extortion group claimed on Tuesday that it breached FBI systems and stole data on nearly all of the bureau&#8217;s employees and job applicants.</strong></p>



<p class="wp-block-paragraph">The hackers told [<a href="https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/" data-type="link" data-id="https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/" target="_blank" rel="noreferrer noopener nofollow">404 Media</a>] they used a zero-day in Oracle PeopleSoft on Monday night, moved into FBI-managed AWS GovCloud servers, and downloaded 2 to 3 TB of data. They also claim to have compromised FBI Criminal Justice, HR, and Medlink services.</p>



<p class="wp-block-paragraph">ShinyHunters has previously exploited a PeopleSoft zero-day. According to Mandiant, the group exploited <strong>CVE-2026-35273</strong> between May 27 and June 9, 2026, before Oracle published its advisory. The flaw carries a CVSS score of 9.8 and lets an unauthenticated attacker execute code over HTTP. It is unclear whether the FBI intrusion used the same bug or a new one.</p>



<p class="wp-block-paragraph">To back its claim, the group defaced apply.fbijobs.gov with a banner announcing the site had been seized, mimicking the notices the FBI posts on criminal sites it takes down. The jobs site and the Special Agent Applicant Portal remain offline.</p>



<p class="wp-block-paragraph">ShinyHunters gave 404 Media a sample, which it said covers 5,000 FBI employees, with names, home addresses, phone numbers, dates of birth, and, in some cases, spouse details. 404 Media matched some phone numbers to people of the same name, and some to Justice Department personnel. Reuters found matching details in at least 10 records, including those of FBI Director Kash Patel, but could not determine where the data originated.</p>



<p class="wp-block-paragraph">The FBI said it is &#8220;aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.&#8221; The bureau has not confirmed a breach yet.</p>



<figure class="wp-block-embed aligncenter is-type-rich is-provider-twitter wp-block-embed-twitter"><div class="wp-block-embed__wrapper">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the <a href="https://t.co/CXFsC8cNUA">https://t.co/CXFsC8cNUA</a> portal and alleged impact to FBI employee personally identifiable information (PII). While the point of breach is still undetermined—whether a third-party or the FBI’s…</p>&mdash; FBI (@FBI) <a href="https://x.com/FBI/status/2102807819695071709?ref_src=twsrc%5Etfw">September 23, 2026</a></blockquote><script async src="https://platform.x.com/widgets.js" charset="utf-8"></script>
</div></figure>



<p class="wp-block-paragraph">The group says the attack is not financially motivated. On its leak site, it gave the FBI one week to correct or remove a May FLASH report stating that ShinyHunters exaggerates its access, harasses victims&#8217; families with threatening calls and texts, and sometimes carries out swatting. The group denies those claims and any affiliation with The Com.</p>



<p class="wp-block-paragraph">ShinyHunters also told BleepingComputer it is exploiting the same alleged zero-day against other organizations, including Fortune 500 companies. Oracle advises PeopleSoft customers to apply its June 2026 Critical Security Patch Update, which covers CVE-2026-35273.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cyberkendra.com/2026/09/shinyhunters-claims-fbi-hack-theft-of-employee-data.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			<dc:creator>protalweb@gmail.com (Vivek Gurung)</dc:creator></item>
	</channel>
</rss>