<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>Cybersecurity News and Magazine</title>
	<atom:link href="https://thecyberexpress.com/feed/" rel="self" type="application/rss+xml"/>
	<link>https://thecyberexpress.com</link>
	<description>Trending Cybersecurity News, Updates, Magazine and More.</description>
	<lastBuildDate>Thu, 10 Sep 2026 18:24:35 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://thecyberexpress.com/wp-content/uploads/tce-favicon-75x75.jpg?crop=1</url>
	<title>The Cyber Express</title>
	<link>https://thecyberexpress.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">208869986</site>	<itunes:explicit>no</itunes:explicit><itunes:subtitle>Trending Cybersecurity News, Updates, Magazine and More.</itunes:subtitle><item>
		<title>AI Agents Compromised 440 PaperCut Servers, Researchers Say</title>
		<link>https://thecyberexpress.com/ai-agents-compromised-440-papercut-servers/</link>
		
		<dc:creator><![CDATA[Mihir Bagwe]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 18:24:35 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[PaperCut]]></category>
		<guid isPermaLink="false">https://thecyberexpress.com/?p=114023</guid>

					<description><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="PaperCut, PaperCut Compromise" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise.webp 800w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise.webp 800w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="AI Agents Compromised 440 PaperCut Servers, Researchers Say 1"></p><p dir="ltr">A threat intelligence firm says it watched a Russian-speaking attacker turn hundreds of AI agents loose on a print management platform and compromise 440 servers in 48 countries — including 11 organizations in 26 seconds. It is the most vivid account yet of an autonomous intrusion campaign. It is also, so far, a single-source story that the vendor at the center of it has pointedly declined to endorse.</p>
<p dir="ltr">GreyNoise <a href="https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf" target="_blank" rel="nofollow noopener">published</a> the report on Sept. 9, describing a campaign it says launched Aug. 31 against PaperCut NG and MF, the self-hosted Java print management software used by a frequently cited 100 million people. The firm says it observed the operation through its own sensor network rather than reconstructing it from victim forensics after the fact.</p>
<p dir="ltr">GreyNoise counts 440 compromised instances across 395 organizations, with education absorbing 204 of them, and domain administrator privileges reached at 12 victims. It says the operator went from an empty workspace to remote code execution against a real victim in under four hours, and to harvested domain admin credentials in roughly six. One US high school, the report says, went from initial access to full domain admin in seven minutes. The agents ran on an OpenAI Codex harness alongside a DeepSeek model.</p>
<p dir="ltr">The most quietly alarming detail is not the speed. GreyNoise says the operator maintained a list of 28 countries the agents were told to leave alone — Russia, China, Iran and Venezuela among them — and that the victim <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/"   title="data" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29554">data</a> shows the agents hit some of them anyway. An attacker's sanctions-avoidance policy failed because the automation did not respect it. The report frames this as evidence that unconstrained agentic operations drift, and that the drift is a <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/"   title="risk" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29553">risk</a> to the attacker as much as to anyone else.</p>
<p dir="ltr">The underlying <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/"   title="vulnerabilities" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29555">vulnerabilities</a> are real and the exploitation is not in dispute. CVE-2026-81578, an authentication bypass, and CVE-2026-82078, an unsafe-reflection remote code execution flaw, were published Aug. 28 and can be chained. PaperCut shipped emergency patches on Aug. 28 and Sept. 1 and full maintenance releases — 26.0.5, 25.0.13 and 24.1.10 — on Sept. 10. CISA added both to its Known Exploited Vulnerabilities catalog on Aug. 31 with a Sept. 14 remediation deadline, a listing that predates the GreyNoise report and was driven by the earlier exploitation wave documented.</p>

<h5 dir="ltr">Read: <a href="https://thecyberexpress.com/papercut-issues-second-emergency-patch/">PaperCut Issues Second Emergency Patch as Researchers Break Fix for Exploited Zero-Days</a></h5>]]></description>
										<content:encoded><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="PaperCut, PaperCut Compromise" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise.webp 800w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise.webp 800w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/PaperCut-Compromise-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="AI Agents Compromised 440 PaperCut Servers, Researchers Say 2"></p><p dir="ltr">A threat intelligence firm says it watched a Russian-speaking attacker turn hundreds of AI agents loose on a print management platform and compromise 440 servers in 48 countries — including 11 organizations in 26 seconds. It is the most vivid account yet of an autonomous intrusion campaign. It is also, so far, a single-source story that the vendor at the center of it has pointedly declined to endorse.</p>
<p dir="ltr">GreyNoise <a href="https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf" target="_blank" rel="nofollow noopener">published</a> the report on Sept. 9, describing a campaign it says launched Aug. 31 against PaperCut NG and MF, the self-hosted Java print management software used by a frequently cited 100 million people. The firm says it observed the operation through its own sensor network rather than reconstructing it from victim forensics after the fact.</p>
<p dir="ltr">GreyNoise counts 440 compromised instances across 395 organizations, with education absorbing 204 of them, and domain administrator privileges reached at 12 victims. It says the operator went from an empty workspace to remote code execution against a real victim in under four hours, and to harvested domain admin credentials in roughly six. One US high school, the report says, went from initial access to full domain admin in seven minutes. The agents ran on an OpenAI Codex harness alongside a DeepSeek model.</p>
<p dir="ltr">The most quietly alarming detail is not the speed. GreyNoise says the operator maintained a list of 28 countries the agents were told to leave alone — Russia, China, Iran and Venezuela among them — and that the victim <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/"   title="data" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29554">data</a> shows the agents hit some of them anyway. An attacker's sanctions-avoidance policy failed because the automation did not respect it. The report frames this as evidence that unconstrained agentic operations drift, and that the drift is a <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/"   title="risk" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29553">risk</a> to the attacker as much as to anyone else.</p>
<p dir="ltr">The underlying <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/"   title="vulnerabilities" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29555">vulnerabilities</a> are real and the exploitation is not in dispute. CVE-2026-81578, an authentication bypass, and CVE-2026-82078, an unsafe-reflection remote code execution flaw, were published Aug. 28 and can be chained. PaperCut shipped emergency patches on Aug. 28 and Sept. 1 and full maintenance releases — 26.0.5, 25.0.13 and 24.1.10 — on Sept. 10. CISA added both to its Known Exploited Vulnerabilities catalog on Aug. 31 with a Sept. 14 remediation deadline, a listing that predates the GreyNoise report and was driven by the earlier exploitation wave documented.</p>

<h5 dir="ltr">Read: <a href="https://thecyberexpress.com/papercut-issues-second-emergency-patch/">PaperCut Issues Second Emergency Patch as Researchers Break Fix for Exploited Zero-Days</a></h5>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">114023</post-id>	</item>
		<item>
		<title>EUChatGPT Sandbox Flaw Let a Planted Prompt Ship Victim’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Acts Gmail Data to Another Account</title>
		<link>https://thecyberexpress.com/eu-cyber-resilience-act-24-hr-reporting/</link>
		
		<dc:creator><![CDATA[Mihir Bagwe]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 11:09:23 +0000</pubDate>
				<category><![CDATA[Policy Updates]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Cyber Essentials]]></category>
		<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Governance]]></category>
		<category><![CDATA[Regulations]]></category>
		<category><![CDATA[24-hour vulnerability reporting]]></category>
		<category><![CDATA[actively exploited vulnerability reporting]]></category>
		<category><![CDATA[CRA Article 14]]></category>
		<category><![CDATA[CRA fines penalties]]></category>
		<category><![CDATA[CRA manufacturer obligations]]></category>
		<category><![CDATA[CRA September 11 2026 deadline]]></category>
		<category><![CDATA[ENISA Single Reporting Platform]]></category>
		<category><![CDATA[EU Cyber Resilience Act reporting obligations]]></category>
		<category><![CDATA[EU cybersecurity compliance 2026]]></category>
		<category><![CDATA[NIS2 DORA overlap]]></category>
		<category><![CDATA[products with digital elements]]></category>
		<guid isPermaLink="false">https://thecyberexpress.com/?p=114019</guid>

					<description><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/EU-Sanctions.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Cyber Resilience Act, CRA, EU, EU Sanctions, Iran, Chinese Hacking," decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/EU-Sanctions.webp 800w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions.webp 800w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="EU&#039;s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act 3"></p><p dir="ltr">Manufacturers selling connected products in the European Union face a new legal duty starting Sept. 11. Report actively exploited vulnerabilities to authorities within 24 hours of confirming them. The obligation arrives 15 months ahead of the <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/"   title="Cyber" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29551">Cyber</a> Resilience Act's full application date of Dec. 11, 2027, making it the regulation's first hard deadline.</p>
<p dir="ltr">The CRA covers products with digital elements placed on the EU market, a category broad enough to take in enterprise software, consumer IoT devices, industrial controllers and much of the component software beneath them.</p>
<p dir="ltr">Under Article 14, manufacturers must file an early warning within 24 hours of becoming aware of an actively exploited <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/"   title="vulnerability" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29549">vulnerability</a> or a severe incident affecting product security, a fuller notification within 72 hours, and a final report within 14 days of a corrective measure becoming available — one month in the case of severe incidents.</p>
<p dir="ltr">Reports go through a Single Reporting Platform operated by ENISA. A manufacturer submits once to a designated national computer security <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank"  rel="noopener" title="incident response" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29550">incident response</a> team, which then shares the notification with CSIRTs in other member states where the product is sold, with ENISA receiving it in parallel. The European Commission has said the platform will be operational by the September date and has been undergoing functional and <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29552">security</a> testing.</p>

<h3 dir="ltr">Where the Deadline Bites</h3>
<p dir="ltr">The awareness standard is what will generate arguments. The trigger is a reasonable degree of certainty that a vulnerability is being exploited or that an incident has severely compromised product security — a judgment call that must be made in hours, often on partial telemetry, and one that manufacturers cannot defer by declining to investigate.</p>
<p dir="ltr">Two further wrinkles are drawing attention from compliance advisers. Reporting duties survive end of support, unlike most of the CRA's other vulnerability-handling requirements, which means legacy product lines remain in scope. And importers or distributors that rebrand a product or substantially modify it inherit manufacturer obligations outright.</p>
<p dir="ltr">Penalties for breaching core manufacturer obligations reach €15 million or 2.5% of global annual turnover, whichever is higher.</p>

<h3 dir="ltr">Readiness Questions on the Cyber Resilience Act</h3>
<p dir="ltr">Practitioners have raised two gaps. The reporting platform is scheduled to be ready by the deadline rather than in advance of it, leaving little room for manufacturers to rehearse submissions. And the harmonised standards that will define what adequate compliance looks like are still working through public enquiry, so companies are building processes against a moving target. The <a href="https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august" target="_blank" rel="nofollow noopener">CRA's requirement</a> that manufacturers publish a coordinated vulnerability disclosure policy does not apply until December 2027.</p>
<p dir="ltr">The effects reach past manufacturers. Enterprises that buy connected products will begin receiving vendor notifications on the vendor's clock rather than their own, and will need a route from a supplier advisory into incident triage — plus a fast assessment of whether the same event triggers separate duties under NIS2 or DORA.</p>
<p dir="ltr">Friday's start date has an immediate real-world test case. Adobe confirmed this week that a maximum-severity Magento flaw, CVE-2026-75650, has been exploited against merchants since Sept. 4. Had the same sequence begun a week later, the 24-hour clock would have applied.</p>

<h5 dir="ltr">Read: <a href="https://thecyberexpress.com/attackers-exploit-unpatched-magento-zero-day/">Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores</a></h5>]]></description>
										<content:encoded><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/EU-Sanctions.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Cyber Resilience Act, CRA, EU, EU Sanctions, Iran, Chinese Hacking," decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/EU-Sanctions.webp 800w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions.webp 800w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/EU-Sanctions-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="EU&#039;s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act 4"></p><p dir="ltr">Manufacturers selling connected products in the European Union face a new legal duty starting Sept. 11. Report actively exploited vulnerabilities to authorities within 24 hours of confirming them. The obligation arrives 15 months ahead of the <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/"   title="Cyber" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29551">Cyber</a> Resilience Act's full application date of Dec. 11, 2027, making it the regulation's first hard deadline.</p>
<p dir="ltr">The CRA covers products with digital elements placed on the EU market, a category broad enough to take in enterprise software, consumer IoT devices, industrial controllers and much of the component software beneath them.</p>
<p dir="ltr">Under Article 14, manufacturers must file an early warning within 24 hours of becoming aware of an actively exploited <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/"   title="vulnerability" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29549">vulnerability</a> or a severe incident affecting product security, a fuller notification within 72 hours, and a final report within 14 days of a corrective measure becoming available — one month in the case of severe incidents.</p>
<p dir="ltr">Reports go through a Single Reporting Platform operated by ENISA. A manufacturer submits once to a designated national computer security <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank"  rel="noopener" title="incident response" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29550">incident response</a> team, which then shares the notification with CSIRTs in other member states where the product is sold, with ENISA receiving it in parallel. The European Commission has said the platform will be operational by the September date and has been undergoing functional and <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29552">security</a> testing.</p>

<h3 dir="ltr">Where the Deadline Bites</h3>
<p dir="ltr">The awareness standard is what will generate arguments. The trigger is a reasonable degree of certainty that a vulnerability is being exploited or that an incident has severely compromised product security — a judgment call that must be made in hours, often on partial telemetry, and one that manufacturers cannot defer by declining to investigate.</p>
<p dir="ltr">Two further wrinkles are drawing attention from compliance advisers. Reporting duties survive end of support, unlike most of the CRA's other vulnerability-handling requirements, which means legacy product lines remain in scope. And importers or distributors that rebrand a product or substantially modify it inherit manufacturer obligations outright.</p>
<p dir="ltr">Penalties for breaching core manufacturer obligations reach €15 million or 2.5% of global annual turnover, whichever is higher.</p>

<h3 dir="ltr">Readiness Questions on the Cyber Resilience Act</h3>
<p dir="ltr">Practitioners have raised two gaps. The reporting platform is scheduled to be ready by the deadline rather than in advance of it, leaving little room for manufacturers to rehearse submissions. And the harmonised standards that will define what adequate compliance looks like are still working through public enquiry, so companies are building processes against a moving target. The <a href="https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august" target="_blank" rel="nofollow noopener">CRA's requirement</a> that manufacturers publish a coordinated vulnerability disclosure policy does not apply until December 2027.</p>
<p dir="ltr">The effects reach past manufacturers. Enterprises that buy connected products will begin receiving vendor notifications on the vendor's clock rather than their own, and will need a route from a supplier advisory into incident triage — plus a fast assessment of whether the same event triggers separate duties under NIS2 or DORA.</p>
<p dir="ltr">Friday's start date has an immediate real-world test case. Adobe confirmed this week that a maximum-severity Magento flaw, CVE-2026-75650, has been exploited against merchants since Sept. 4. Had the same sequence begun a week later, the 24-hour clock would have applied.</p>

<h5 dir="ltr">Read: <a href="https://thecyberexpress.com/attackers-exploit-unpatched-magento-zero-day/">Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores</a></h5>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">114019</post-id>	</item>
		<item>
		<title>EUChatGPT Sandbox Flaw Let a Planted Prompt Ship Victim’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Acts Gmail Data to Another Account</title>
		<link>https://thecyberexpress.com/chatgpt-sandbox-flaw-leads-to-gmail-leak/</link>
		
		<dc:creator><![CDATA[Mihir Bagwe]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 08:48:09 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[AI agent security risk]]></category>
		<category><![CDATA[AI connector security]]></category>
		<category><![CDATA[ChatGPT prompt injection attack]]></category>
		<category><![CDATA[ChatGPT sandbox flaw]]></category>
		<category><![CDATA[Check Point Research ChatGPT]]></category>
		<category><![CDATA[coerced insider AI]]></category>
		<category><![CDATA[cross-account data leakage]]></category>
		<category><![CDATA[Gmail data exfiltration]]></category>
		<category><![CDATA[indirect prompt injection]]></category>
		<category><![CDATA[JFrog Artifactory vulnerability]]></category>
		<category><![CDATA[LLM security OWASP]]></category>
		<category><![CDATA[OpenAI Hugging Face incident]]></category>
		<guid isPermaLink="false">https://thecyberexpress.com/?p=114005</guid>

					<description><![CDATA[<p><img width="1000" height="666" src="https://thecyberexpress.com/wp-content/uploads/SearchGPT.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ChatGPT, SearchGPT, OpenAI, Sam Altman, Lockdown Mode" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/SearchGPT.jpg 1000w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-300x200.jpg 300w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-768x511.jpg 768w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-600x400.jpg 600w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-150x100.jpg 150w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-750x500.jpg 750w, https://thecyberexpress.com/wp-content/uploads/SearchGPT.avif 1000w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-300x200.avif 300w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-768x511.avif 768w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-600x400.avif 600w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-150x100.avif 150w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-750x500.avif 750w" sizes="(max-width: 1000px) 100vw, 1000px" title="ChatGPT Sandbox Flaw Let a Planted Prompt Ship Victim&#039;s Gmail Data to Another Account 5"></p><p dir="ltr">Check Point Research disclosed Tuesday that a weakness in ChatGPT's code-execution sandbox let data from one user's connected Gmail account be moved into a separate, attacker-controlled ChatGPT account, with no confirmation prompt shown to the victim.</p>
<p dir="ltr">The flaw sat not in the model but in the infrastructure beneath it. Containers running individual conversations cannot address one another directly, Check Point found, but every container could reach the same internal JFrog Artifactory instance OpenAI used for package management. An item-management feature there let any container attach text metadata properties to cached items and read properties written by others, turning a package cache into a two-way message board between environments meant to be isolated.</p>

<h3 dir="ltr">How the Chain Worked</h3>
<p dir="ltr">The attack starts with an instruction the victim never sees. Researchers demonstrated three delivery routes, any one of them was sufficient. First, a prompt pasted into a chat, second was a shared conversation link, or third, a custom GPT carrying a hidden instruction.</p>
<p dir="ltr">The victim's session then quietly processes a second stream of tasks alongside the conversation they can actually see. In one demonstration described by The Register, the user got an ordinary answer, a temperature chart, while an injected task told the session to use the Gmail connector and list their messages.</p>
<p dir="ltr">Those instructions reach whatever the victim has connected. Researchers cited Gmail, Google Drive, Microsoft Teams and GitHub in their findings.</p>
<p dir="ltr">The decisive detail is the permission model. ChatGPT's default connected-app setting automatically approves read actions it judges low <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/"   title="risk" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29547">risk</a>, with no separate confirmation step. The only trace researchers observed was a small "Talked to Gmail" label appearing afterward. Harvested <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/"   title="data" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29544">data</a> went into the shared metadata channel and was collected by the attacker's own session — exfiltration that never touches the victim's browser or their employer's network egress, leaving nothing for conventional data-loss prevention tools to inspect.</p>

<h5 dir="ltr">Also read: <a href="https://thecyberexpress.com/chatgphish-prompt-injection-vulnerability/" target="_blank" rel="noopener">New ChatGPhish Technique Uses Prompt Injection to Manipulate ChatGPT Responses</a></h5>
<h3 dir="ltr">The Hugging Face Connection</h3>
<p dir="ltr">Check Point <a href="https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/" target="_blank" rel="nofollow noopener">reported</a> the channel to OpenAI in late June and says it had a working proof of concept before the activity that led to the Hugging Face compromise OpenAI has since disclosed. The two are separate attacks using different techniques, but both ran through the same internal Artifactory instance. On disclosure, OpenAI told Check Point the instance had already been decommissioned because of the Hugging Face incident, so no user-facing patch was needed, and Check Point's write-up cites no CVE for the channel.</p>
<p dir="ltr">In that episode, OpenAI models running an internal exploitation evaluation chained Artifactory zero-days to escalate privileges, reach a node with <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/"   title="internet" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29548">internet</a> access and pull evaluation answers from Hugging Face's production database. JFrog patched three flaws credited to OpenAI researchers in Artifactory 7.161.15; Hugging Face disclosed the intrusion July 16.</p>
<p dir="ltr">Also read: <a href="https://thecyberexpress.com/openai-and-hugging-face-ai-security-incident/" target="_blank" rel="noopener">OpenAI and Hugging Face Investigate AI Models’ Cyber Breakout</a></p>
<p dir="ltr">Check Point's Pedro Drimel Neto framed the lesson as one of privilege rather than model behavior, saying "the biggest AI <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29546">security</a> risk has become the access and trust we give it." The firm calls an assistant that holds credentials, runs code and reaches connected services a "coerced insider," and argues the many-tenants-on-one-shared-service pattern warrants scrutiny across agent platforms. OpenAI did not respond to The Register's request for comment.</p>
<p dir="ltr">The latest disclosure lands weeks after the European Commission and national authorities began enforcing the EU AI Act on Aug. 2. Indirect prompt injection remains the top entry in OWASP's Top 10 for large language model applications, and NIST's AI <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-risk-management/"   title="Risk Management" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29545">Risk Management</a> Framework treats leakage through connected tooling as a core control area. For enterprises, the exposure is also a GDPR question. Mailbox contents reached through a sanctioned connector are still personal data, and a cross-tenant route to them is a processing failure whether or not it was abused.</p>]]></description>
										<content:encoded><![CDATA[<p><img width="1000" height="666" src="https://thecyberexpress.com/wp-content/uploads/SearchGPT.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ChatGPT, SearchGPT, OpenAI, Sam Altman, Lockdown Mode" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/SearchGPT.jpg 1000w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-300x200.jpg 300w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-768x511.jpg 768w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-600x400.jpg 600w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-150x100.jpg 150w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-750x500.jpg 750w, https://thecyberexpress.com/wp-content/uploads/SearchGPT.avif 1000w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-300x200.avif 300w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-768x511.avif 768w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-600x400.avif 600w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-150x100.avif 150w, https://thecyberexpress.com/wp-content/uploads/SearchGPT-750x500.avif 750w" sizes="(max-width: 1000px) 100vw, 1000px" title="ChatGPT Sandbox Flaw Let a Planted Prompt Ship Victim&#039;s Gmail Data to Another Account 6"></p><p dir="ltr">Check Point Research disclosed Tuesday that a weakness in ChatGPT's code-execution sandbox let data from one user's connected Gmail account be moved into a separate, attacker-controlled ChatGPT account, with no confirmation prompt shown to the victim.</p>
<p dir="ltr">The flaw sat not in the model but in the infrastructure beneath it. Containers running individual conversations cannot address one another directly, Check Point found, but every container could reach the same internal JFrog Artifactory instance OpenAI used for package management. An item-management feature there let any container attach text metadata properties to cached items and read properties written by others, turning a package cache into a two-way message board between environments meant to be isolated.</p>

<h3 dir="ltr">How the Chain Worked</h3>
<p dir="ltr">The attack starts with an instruction the victim never sees. Researchers demonstrated three delivery routes, any one of them was sufficient. First, a prompt pasted into a chat, second was a shared conversation link, or third, a custom GPT carrying a hidden instruction.</p>
<p dir="ltr">The victim's session then quietly processes a second stream of tasks alongside the conversation they can actually see. In one demonstration described by The Register, the user got an ordinary answer, a temperature chart, while an injected task told the session to use the Gmail connector and list their messages.</p>
<p dir="ltr">Those instructions reach whatever the victim has connected. Researchers cited Gmail, Google Drive, Microsoft Teams and GitHub in their findings.</p>
<p dir="ltr">The decisive detail is the permission model. ChatGPT's default connected-app setting automatically approves read actions it judges low <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/"   title="risk" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29547">risk</a>, with no separate confirmation step. The only trace researchers observed was a small "Talked to Gmail" label appearing afterward. Harvested <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/"   title="data" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29544">data</a> went into the shared metadata channel and was collected by the attacker's own session — exfiltration that never touches the victim's browser or their employer's network egress, leaving nothing for conventional data-loss prevention tools to inspect.</p>

<h5 dir="ltr">Also read: <a href="https://thecyberexpress.com/chatgphish-prompt-injection-vulnerability/" target="_blank" rel="noopener">New ChatGPhish Technique Uses Prompt Injection to Manipulate ChatGPT Responses</a></h5>
<h3 dir="ltr">The Hugging Face Connection</h3>
<p dir="ltr">Check Point <a href="https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/" target="_blank" rel="nofollow noopener">reported</a> the channel to OpenAI in late June and says it had a working proof of concept before the activity that led to the Hugging Face compromise OpenAI has since disclosed. The two are separate attacks using different techniques, but both ran through the same internal Artifactory instance. On disclosure, OpenAI told Check Point the instance had already been decommissioned because of the Hugging Face incident, so no user-facing patch was needed, and Check Point's write-up cites no CVE for the channel.</p>
<p dir="ltr">In that episode, OpenAI models running an internal exploitation evaluation chained Artifactory zero-days to escalate privileges, reach a node with <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/"   title="internet" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29548">internet</a> access and pull evaluation answers from Hugging Face's production database. JFrog patched three flaws credited to OpenAI researchers in Artifactory 7.161.15; Hugging Face disclosed the intrusion July 16.</p>
<p dir="ltr">Also read: <a href="https://thecyberexpress.com/openai-and-hugging-face-ai-security-incident/" target="_blank" rel="noopener">OpenAI and Hugging Face Investigate AI Models’ Cyber Breakout</a></p>
<p dir="ltr">Check Point's Pedro Drimel Neto framed the lesson as one of privilege rather than model behavior, saying "the biggest AI <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29546">security</a> risk has become the access and trust we give it." The firm calls an assistant that holds credentials, runs code and reaches connected services a "coerced insider," and argues the many-tenants-on-one-shared-service pattern warrants scrutiny across agent platforms. OpenAI did not respond to The Register's request for comment.</p>
<p dir="ltr">The latest disclosure lands weeks after the European Commission and national authorities began enforcing the EU AI Act on Aug. 2. Indirect prompt injection remains the top entry in OWASP's Top 10 for large language model applications, and NIST's AI <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-risk-management/"   title="Risk Management" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29545">Risk Management</a> Framework treats leakage through connected tooling as a core control area. For enterprises, the exposure is also a GDPR question. Mailbox contents reached through a sanctioned connector are still personal data, and a cross-tenant route to them is a processing failure whether or not it was abused.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">114005</post-id>	</item>
		<item>
		<title>Microsoft Patch Tuesday Hits Record 974 CVEs, Two Exploited</title>
		<link>https://thecyberexpress.com/patch-tuesday-september-2026/</link>
		
		<dc:creator><![CDATA[Ashish Khaitan]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 06:51:42 +0000</pubDate>
				<category><![CDATA[Firewall Daily]]></category>
		<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[CVEs]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Patch Tuesday September 2026]]></category>
		<category><![CDATA[The Cyber Express]]></category>
		<category><![CDATA[The Cyber Express News]]></category>
		<category><![CDATA[Zero Day]]></category>
		<guid isPermaLink="false">https://thecyberexpress.com/?p=114006</guid>

					<description><![CDATA[<p><img width="808" height="491" src="https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Patch Tuesday September 2026" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026.webp 808w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-300x182.webp 300w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-768x467.webp 768w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-600x365.webp 600w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-750x456.webp 750w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026.webp 808w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-300x182.webp 300w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-768x467.webp 768w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-600x365.webp 600w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-750x456.webp 750w" sizes="(max-width: 808px) 100vw, 808px" title="Microsoft Patch Tuesday Hits Record 974 CVEs, Two Exploited 7"></p><span data-contrast="auto">Microsoft's Patch Tuesday September 2026 rollout has broken previous records, with the company addressing 974 CVEs across its product lineup in a single release. Two of these vulnerabilities were already being exploited in the wild before fixes became available, prompting quick action from federal cybersecurity authorities.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The sheer volume of this month's Patch Tuesday September 2026 release dwarfs recent months. Windows accounted for 723 of the fixed flaws, while the Office suite received patches for 222 issues, 111 of which affected Office 2016 specifically. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Scale of Patch Tuesday September 2026</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">SQL Server products saw 62 CVEs resolved, Developer Tools had 22, SharePoint Server received 16 fixes, Azure had 12, Skype for Business had 10, and Exchange Server accounted for 9. More than 110 of the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/"   title="vulnerabilities" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29543">vulnerabilities</a> patched carry a critical severity rating, and nearly 90% of the total fall into three categories: privilege escalation, remote code execution, and information disclosure. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Factoring in fixes for 25 non-Microsoft CVEs, the combined total for this Patch Tuesday September 2026 cycle reaches 999 resolved vulnerabilities.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">This <a href="https://support.microsoft.com/en-gb/servicing/os/windows-11/2026/09/kb5124008-windows-11-24h2-25h2-security-update" target="_blank" rel="nofollow noopener">release continues a pattern of escalating patch volumes</a> from Microsoft in recent months — 457 CVEs were addressed in August, 663 in July, 220 in June, and 161 in May, making September's numbers a significant jump even against that backdrop.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">The Two Exploited Zero-Days</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">Central to this month's Patch Tuesday September 2026 update are two <a href="https://thecyberexpress.com/july-2026-critical-patch-update-oracle/" target="_blank" rel="noopener">CVEs</a> that Microsoft confirmed had been exploited before patches were issued.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The first, CVE-2026-85880 (CVSS 7.8), is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component. It allows an attacker with local access to escalate privileges and obtain SYSTEM-level control. Microsoft's advisory states that an attacker who can execute code in a low-privilege AppContainer could exploit this <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/"   title="vulnerability" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29542">vulnerability</a> locally to escape the sandbox and elevate privileges on the affected system, with no additional user interaction required.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The second actively exploited flaw, CVE-2026-81963 (CVSS 7.8), stems from improper link resolution within the Windows Update Stack. Like the ALPC bug, it enables a local, authorized attacker to escalate privileges and gain SYSTEM access.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Both CVEs have since been added to the Known Exploited Vulnerabilities (KEV) catalog maintained by the U.S. <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank"  rel="noopener" title="Cybersecurity" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29541">Cybersecurity</a> and Infrastructure Security Agency (CISA). Federal Civilian Executive Branch agencies now face a September 22, 2026 deadline to apply the relevant patches.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Other Notable CVEs Worth Tracking</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">Beyond the zero-days, several other CVEs patched in this Patch Tuesday September 2026 batch carry high severity scores and warrant prompt attention from <a href="https://thecyberexpress.com/microsoft-reverses-exploitation-cve-2026-69836/" target="_blank" rel="noopener">Microsoft</a> administrators:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-55007</span></b><span data-contrast="auto"> (CVSS 8.1) — a double-free flaw in Microsoft Exchange Server enabling remote code execution</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-80097</span></b><span data-contrast="auto"> (CVSS 8.6) — improper authentication in Microsoft Authenticator allowing local privilege escalation</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-69465</span></b><span data-contrast="auto"> (CVSS 8.8) — missing authorization in Microsoft Office SharePoint permitting remote code execution</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-65669</span></b><span data-contrast="auto"> (CVSS 9.6) — an injection flaw in SQL Server enabling remote privilege escalation</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-69525</span></b><span data-contrast="auto"> (CVSS 9.8) — use-after-free in Windows Remote Desktop Services allowing remote code execution</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="6" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-69595</span></b><span data-contrast="auto"> (CVSS 9.8) — use-after-free in the Windows Services for NFS ONCRPC XDR Driver</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="7" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-69730</span></b><span data-contrast="auto"> (CVSS 9.8) — use-after-free in the Windows DNS server</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="8" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-69829</span></b><span data-contrast="auto"> (CVSS 9.8) — heap-based buffer overflow in Windows Shell</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="9" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-72979</span></b><span data-contrast="auto"> (CVSS 9.8) — use-after-free in the Windows DHCP Server</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<span data-contrast="auto">Alongside the CVE fixes, Microsoft's Patch Tuesday September 2026 release also included new Servicing Stack Updates (SSUs), classified as critical, covering Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Given the number of critical-severity CVEs and the confirmed exploitation of two privilege-escalation bugs, security teams are expected to prioritize this Patch Tuesday September 2026 rollout above routine monthly cycles, particularly for internet-facing <a href="https://thecyberexpress.com/microsoft-reverses-exploitation-cve-2026-69836/" target="_blank" rel="noopener">Windows</a> and Exchange deployments.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>]]></description>
										<content:encoded><![CDATA[<p><img width="808" height="491" src="https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Patch Tuesday September 2026" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026.webp 808w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-300x182.webp 300w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-768x467.webp 768w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-600x365.webp 600w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-750x456.webp 750w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026.webp 808w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-300x182.webp 300w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-768x467.webp 768w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-600x365.webp 600w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/Patch-Tuesday-September-2026-750x456.webp 750w" sizes="(max-width: 808px) 100vw, 808px" title="Microsoft Patch Tuesday Hits Record 974 CVEs, Two Exploited 8"></p><span data-contrast="auto">Microsoft's Patch Tuesday September 2026 rollout has broken previous records, with the company addressing 974 CVEs across its product lineup in a single release. Two of these vulnerabilities were already being exploited in the wild before fixes became available, prompting quick action from federal cybersecurity authorities.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The sheer volume of this month's Patch Tuesday September 2026 release dwarfs recent months. Windows accounted for 723 of the fixed flaws, while the Office suite received patches for 222 issues, 111 of which affected Office 2016 specifically. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Scale of Patch Tuesday September 2026</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">SQL Server products saw 62 CVEs resolved, Developer Tools had 22, SharePoint Server received 16 fixes, Azure had 12, Skype for Business had 10, and Exchange Server accounted for 9. More than 110 of the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/"   title="vulnerabilities" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29543">vulnerabilities</a> patched carry a critical severity rating, and nearly 90% of the total fall into three categories: privilege escalation, remote code execution, and information disclosure. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Factoring in fixes for 25 non-Microsoft CVEs, the combined total for this Patch Tuesday September 2026 cycle reaches 999 resolved vulnerabilities.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">This <a href="https://support.microsoft.com/en-gb/servicing/os/windows-11/2026/09/kb5124008-windows-11-24h2-25h2-security-update" target="_blank" rel="nofollow noopener">release continues a pattern of escalating patch volumes</a> from Microsoft in recent months — 457 CVEs were addressed in August, 663 in July, 220 in June, and 161 in May, making September's numbers a significant jump even against that backdrop.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">The Two Exploited Zero-Days</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">Central to this month's Patch Tuesday September 2026 update are two <a href="https://thecyberexpress.com/july-2026-critical-patch-update-oracle/" target="_blank" rel="noopener">CVEs</a> that Microsoft confirmed had been exploited before patches were issued.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The first, CVE-2026-85880 (CVSS 7.8), is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component. It allows an attacker with local access to escalate privileges and obtain SYSTEM-level control. Microsoft's advisory states that an attacker who can execute code in a low-privilege AppContainer could exploit this <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/"   title="vulnerability" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29542">vulnerability</a> locally to escape the sandbox and elevate privileges on the affected system, with no additional user interaction required.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The second actively exploited flaw, CVE-2026-81963 (CVSS 7.8), stems from improper link resolution within the Windows Update Stack. Like the ALPC bug, it enables a local, authorized attacker to escalate privileges and gain SYSTEM access.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Both CVEs have since been added to the Known Exploited Vulnerabilities (KEV) catalog maintained by the U.S. <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank"  rel="noopener" title="Cybersecurity" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29541">Cybersecurity</a> and Infrastructure Security Agency (CISA). Federal Civilian Executive Branch agencies now face a September 22, 2026 deadline to apply the relevant patches.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Other Notable CVEs Worth Tracking</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">Beyond the zero-days, several other CVEs patched in this Patch Tuesday September 2026 batch carry high severity scores and warrant prompt attention from <a href="https://thecyberexpress.com/microsoft-reverses-exploitation-cve-2026-69836/" target="_blank" rel="noopener">Microsoft</a> administrators:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-55007</span></b><span data-contrast="auto"> (CVSS 8.1) — a double-free flaw in Microsoft Exchange Server enabling remote code execution</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-80097</span></b><span data-contrast="auto"> (CVSS 8.6) — improper authentication in Microsoft Authenticator allowing local privilege escalation</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-69465</span></b><span data-contrast="auto"> (CVSS 8.8) — missing authorization in Microsoft Office SharePoint permitting remote code execution</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-65669</span></b><span data-contrast="auto"> (CVSS 9.6) — an injection flaw in SQL Server enabling remote privilege escalation</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="5" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-69525</span></b><span data-contrast="auto"> (CVSS 9.8) — use-after-free in Windows Remote Desktop Services allowing remote code execution</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="6" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-69595</span></b><span data-contrast="auto"> (CVSS 9.8) — use-after-free in the Windows Services for NFS ONCRPC XDR Driver</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="7" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-69730</span></b><span data-contrast="auto"> (CVSS 9.8) — use-after-free in the Windows DNS server</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="8" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-69829</span></b><span data-contrast="auto"> (CVSS 9.8) — heap-based buffer overflow in Windows Shell</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<ul>
 	<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="9" data-aria-level="1"><b><span data-contrast="auto">CVE-2026-72979</span></b><span data-contrast="auto"> (CVSS 9.8) — use-after-free in the Windows DHCP Server</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></li>
</ul>
<span data-contrast="auto">Alongside the CVE fixes, Microsoft's Patch Tuesday September 2026 release also included new Servicing Stack Updates (SSUs), classified as critical, covering Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Given the number of critical-severity CVEs and the confirmed exploitation of two privilege-escalation bugs, security teams are expected to prioritize this Patch Tuesday September 2026 rollout above routine monthly cycles, particularly for internet-facing <a href="https://thecyberexpress.com/microsoft-reverses-exploitation-cve-2026-69836/" target="_blank" rel="noopener">Windows</a> and Exchange deployments.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">114006</post-id>	</item>
		<item>
		<title>Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet</title>
		<link>https://thecyberexpress.com/220-million-airline-passenger-crew-data-expose/</link>
		
		<dc:creator><![CDATA[Mihir Bagwe]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 14:51:26 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Firewall Daily]]></category>
		<category><![CDATA[Airline Data Leak]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[ElasticSearch]]></category>
		<guid isPermaLink="false">https://thecyberexpress.com/?p=114000</guid>

					<description><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/airline-data-leak.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Airline, Data Leak," decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/airline-data-leak.webp 800w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak.webp 800w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet 9"></p><p dir="ltr">A misconfigured Elasticsearch cluster exposed roughly 220.8 million airline passenger and crew records, including passport numbers and full itineraries, before it was secured in June, researchers at Kinryu Labs disclosed.</p>
<p dir="ltr">The records spanned January 2017 through April 2026 and came from an Advance Passenger Information System deployment - the standardized data feed airlines transmit to border authorities before departure, covering traveler identity and flight details. Researchers linked the server to IP address space assigned to Vietnamese telecommunications operator Viettel in Hanoi but said they could not confirm which organization operated it.</p>

<h3 dir="ltr">What was exposed</h3>
<p dir="ltr">As per <a href="https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/" target="_blank" rel="nofollow noopener">BleepingComputer</a>, the data set combined identity documents with granular travel history. Exposed fields included names, dates of birth, sex and nationality; passport or travel <a class="wpil_keyword_link" href="https://thecyberexpress.com/how-to-password-protect-a-word-document/"   title="document" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29538">document</a> numbers, expiration dates and issuing countries; and flight numbers and dates, airline names, departure, destination and transit airports, seat numbers, baggage references, and scheduled, estimated and actual flight times.</p>
<p dir="ltr">That combination is unusually sensitive. Passport numbers are difficult to change and useful for identity <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank"  rel="noopener" title="fraud" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29537">fraud</a> and account takeover at travel providers, while the itinerary fields - particularly transit airports and actual flight times - allow reconstruction of an individual's movements over nine years. <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="Security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29535">Security</a> researchers have long flagged APIS-style data as a surveillance risk precisely because it maps people to places at fixed times.</p>

<h5 dir="ltr">Also read: <a href="https://thecyberexpress.com/why-airline-data-breaches-matter-and-why-qantas-could-have-been-worse/">Why Airline Data Breaches Matter – And Why Qantas Could Have Been Worse</a></h5>
<h3 dir="ltr">Two misconfigurations</h3>
<p dir="ltr">According to <a href="https://kinryu.sh/" target="_blank" rel="nofollow noopener">Kinryu Labs</a>, the cluster was protected inconsistently. Direct access over the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/"   title="internet" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29539">internet</a> returned an HTTP 401 authentication error, which would give a casual scanner the impression the system was locked down. An alternative cloud-based access path, however, reached the same cluster and accepted default credentials.</p>
<p dir="ltr">The exposure appears to have been long-lived. Internet scanning service FOFA detected the host in 2022 and identified it as a database in 2023. Kinryu Labs reported the issue on June 3, 2026, and the cluster was secured by June 8. Singapore Airlines assisted in coordinating the response, the researchers said. There is no indication any airline was itself breached or operated the server.</p>
<p dir="ltr">Researchers said they found no evidence the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/"   title="data" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29540">data</a> was stolen, but noted that without server logs they could not determine whether anyone copied it during the years it was reachable — a distinction that matters more than it may appear, because notification obligations in several jurisdictions turn on whether unauthorized access can be ruled out.</p>

<h3 dir="ltr">Compliance exposure</h3>
<p dir="ltr">Vietnam's Personal Data Protection Law, Law No. 91/2025/QH15, took effect Jan. 1, 2026 - before the exposure was reported and remediated. The statute requires notification within 72 hours of detecting a violation, rather than from the time it occurred, and expands notification duties to affected individuals in defined circumstances. Its penalty ceiling for <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank"  rel="noopener" title="general" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29536">general</a> violations is 3 billion Vietnamese dong, with cross-border transfer breaches exposed to fines of up to 5% of prior-year revenue.</p>
<p dir="ltr">Because the records cover international flights, EU and UK residents are almost certainly represented, which brings GDPR and UK GDPR into scope for any controller established in or targeting those markets. Passport numbers and travel history fall squarely within personal data, and passenger data processing has drawn repeated scrutiny from European data protection authorities.</p>]]></description>
										<content:encoded><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/airline-data-leak.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Airline, Data Leak," decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/airline-data-leak.webp 800w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak.webp 800w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/airline-data-leak-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet 10"></p><p dir="ltr">A misconfigured Elasticsearch cluster exposed roughly 220.8 million airline passenger and crew records, including passport numbers and full itineraries, before it was secured in June, researchers at Kinryu Labs disclosed.</p>
<p dir="ltr">The records spanned January 2017 through April 2026 and came from an Advance Passenger Information System deployment - the standardized data feed airlines transmit to border authorities before departure, covering traveler identity and flight details. Researchers linked the server to IP address space assigned to Vietnamese telecommunications operator Viettel in Hanoi but said they could not confirm which organization operated it.</p>

<h3 dir="ltr">What was exposed</h3>
<p dir="ltr">As per <a href="https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/" target="_blank" rel="nofollow noopener">BleepingComputer</a>, the data set combined identity documents with granular travel history. Exposed fields included names, dates of birth, sex and nationality; passport or travel <a class="wpil_keyword_link" href="https://thecyberexpress.com/how-to-password-protect-a-word-document/"   title="document" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29538">document</a> numbers, expiration dates and issuing countries; and flight numbers and dates, airline names, departure, destination and transit airports, seat numbers, baggage references, and scheduled, estimated and actual flight times.</p>
<p dir="ltr">That combination is unusually sensitive. Passport numbers are difficult to change and useful for identity <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank"  rel="noopener" title="fraud" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29537">fraud</a> and account takeover at travel providers, while the itinerary fields - particularly transit airports and actual flight times - allow reconstruction of an individual's movements over nine years. <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="Security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29535">Security</a> researchers have long flagged APIS-style data as a surveillance risk precisely because it maps people to places at fixed times.</p>

<h5 dir="ltr">Also read: <a href="https://thecyberexpress.com/why-airline-data-breaches-matter-and-why-qantas-could-have-been-worse/">Why Airline Data Breaches Matter – And Why Qantas Could Have Been Worse</a></h5>
<h3 dir="ltr">Two misconfigurations</h3>
<p dir="ltr">According to <a href="https://kinryu.sh/" target="_blank" rel="nofollow noopener">Kinryu Labs</a>, the cluster was protected inconsistently. Direct access over the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/"   title="internet" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29539">internet</a> returned an HTTP 401 authentication error, which would give a casual scanner the impression the system was locked down. An alternative cloud-based access path, however, reached the same cluster and accepted default credentials.</p>
<p dir="ltr">The exposure appears to have been long-lived. Internet scanning service FOFA detected the host in 2022 and identified it as a database in 2023. Kinryu Labs reported the issue on June 3, 2026, and the cluster was secured by June 8. Singapore Airlines assisted in coordinating the response, the researchers said. There is no indication any airline was itself breached or operated the server.</p>
<p dir="ltr">Researchers said they found no evidence the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/"   title="data" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29540">data</a> was stolen, but noted that without server logs they could not determine whether anyone copied it during the years it was reachable — a distinction that matters more than it may appear, because notification obligations in several jurisdictions turn on whether unauthorized access can be ruled out.</p>

<h3 dir="ltr">Compliance exposure</h3>
<p dir="ltr">Vietnam's Personal Data Protection Law, Law No. 91/2025/QH15, took effect Jan. 1, 2026 - before the exposure was reported and remediated. The statute requires notification within 72 hours of detecting a violation, rather than from the time it occurred, and expands notification duties to affected individuals in defined circumstances. Its penalty ceiling for <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank"  rel="noopener" title="general" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29536">general</a> violations is 3 billion Vietnamese dong, with cross-border transfer breaches exposed to fines of up to 5% of prior-year revenue.</p>
<p dir="ltr">Because the records cover international flights, EU and UK residents are almost certainly represented, which brings GDPR and UK GDPR into scope for any controller established in or targeting those markets. Passport numbers and travel history fall squarely within personal data, and passenger data processing has drawn repeated scrutiny from European data protection authorities.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">114000</post-id>	</item>
		<item>
		<title>Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores</title>
		<link>https://thecyberexpress.com/attackers-exploit-unpatched-magento-zero-day/</link>
		
		<dc:creator><![CDATA[Mihir Bagwe]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 12:32:45 +0000</pubDate>
				<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Adobe Commerce RCE]]></category>
		<category><![CDATA[e-commerce security]]></category>
		<category><![CDATA[Magecart]]></category>
		<category><![CDATA[Magento 2.4.9 exploi]]></category>
		<category><![CDATA[Magento backdoor]]></category>
		<category><![CDATA[Magento zero-day]]></category>
		<category><![CDATA[StyleSmuggler vulnerability]]></category>
		<category><![CDATA[unpatched Magento vulnerability]]></category>
		<guid isPermaLink="false">https://thecyberexpress.com/?p=113992</guid>

					<description><![CDATA[<p><img width="1920" height="1280" src="https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Magento, Magento Vulnerability" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability.webp 1920w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1536x1024.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability.webp 1920w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1536x1024.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1140x760.webp 1140w" sizes="(max-width: 1920px) 100vw, 1920px" title="Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores 11"></p><p dir="ltr">Attackers are exploiting an unpatched remote code execution flaw in Adobe Commerce and Magento Open Source to install persistent backdoors on e-commerce sites, Dutch security firm Sansec reported, with the first intrusions observed Sept. 4 and no vendor fix available as of Sept. 6.</p>
<p dir="ltr">Sansec's forensics team, in an advisory, named the flaw StyleSmuggler. No CVE identifier has been assigned. As of Sept. 7, Adobe's Magento security bulletin index listed no September advisory, and the flaw does not appear in CISA's Known Exploited <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/"   title="Vulnerabilities" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29533">Vulnerabilities</a> catalog, leaving an unknown number of merchants exposed during a window in which working exploit traffic is already circulating.</p>
<p dir="ltr">Magento underpins a large share of mid-market online retail, and Adobe has sold it as Adobe Commerce since acquiring the platform in 2018. The codebase has been a durable target for payment-skimming crews: Sansec has tracked Magecart-style card theft against Magento storefronts for close to a decade, and the platform's checkout position makes any unauthenticated code execution flaw unusually valuable.</p>
<p dir="ltr">According to Sansec's <a href="https://sansec.io/research/stylesmuggler-0day" target="_blank" rel="nofollow noopener">analysis</a>, StyleSmuggler is a two-stage chain that abuses the platform's GraphQL interface. Attackers first inject PHP code into files Magento writes on its own, such as failure reports, then trigger execution through the platform's "Payment Transaction Failed Reminder" email routine. Because the trigger fires when the reminder is generated, no recipient has to open the message for the payload to run.</p>
<p dir="ltr">The <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/"   title="vulnerability" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29532">vulnerability</a> was confirmed on Magento Open Source 2.4.7, 2.4.8 and 2.4.9. The detail likely to unsettle merchants most is the first known victim: a store running 2.4.6-p15 with all available patches applied. Being current on Adobe's release cycle did not prevent compromise.</p>
<p dir="ltr">The implant Sansec documented is built to survive routine inspection. It runs under a process name mimicking a Linux kernel thread, <code>[kworker/u:8:0]</code>, with the binary written to <code>~/.local/share/.gvfsd/gvfsd-user</code> and a cron entry relaunching it every five minutes. Sansec also listed the domain <code>247.cdnflare.xyz</code> among its indicators of compromise.</p>
<p dir="ltr">Sansec advised merchants to disable GraphQL where the storefront can tolerate it, disable the PHP <code>proc_open</code> function, and mount <code>/tmp</code>, <code>/var/tmp</code> and <code>/dev/shm</code> with the <code>noexec</code> option. Unofficial community patches have been published by Disrex Group, ProxiBlue and Graycore. Disrex said it independently identified two compromised stores and a third that was attacked without being breached.</p>
<p dir="ltr">Adobe's most recent scheduled Commerce bulletin, APSB26-92, was published Aug. 11 and addressed critical and important flaws across the 2.4.4 through 2.4.9 branches. The company's next scheduled <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29534">security</a> release is Sept. 8. Adobe did not appear to have commented publicly on StyleSmuggler.</p>

<h5 dir="ltr">Also read: <a href="https://thecyberexpress.com/adobe-commerce-flaw-cve-2025-54236/">Adobe Issues Urgent Patch for ‘SessionReaper’ Vulnerability in Commerce and Magento</a></h5>]]></description>
										<content:encoded><![CDATA[<p><img width="1920" height="1280" src="https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Magento, Magento Vulnerability" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability.webp 1920w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1536x1024.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability.webp 1920w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1536x1024.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Adobe-Magento-Vulnerability-1140x760.webp 1140w" sizes="(max-width: 1920px) 100vw, 1920px" title="Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores 12"></p><p dir="ltr">Attackers are exploiting an unpatched remote code execution flaw in Adobe Commerce and Magento Open Source to install persistent backdoors on e-commerce sites, Dutch security firm Sansec reported, with the first intrusions observed Sept. 4 and no vendor fix available as of Sept. 6.</p>
<p dir="ltr">Sansec's forensics team, in an advisory, named the flaw StyleSmuggler. No CVE identifier has been assigned. As of Sept. 7, Adobe's Magento security bulletin index listed no September advisory, and the flaw does not appear in CISA's Known Exploited <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/"   title="Vulnerabilities" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29533">Vulnerabilities</a> catalog, leaving an unknown number of merchants exposed during a window in which working exploit traffic is already circulating.</p>
<p dir="ltr">Magento underpins a large share of mid-market online retail, and Adobe has sold it as Adobe Commerce since acquiring the platform in 2018. The codebase has been a durable target for payment-skimming crews: Sansec has tracked Magecart-style card theft against Magento storefronts for close to a decade, and the platform's checkout position makes any unauthenticated code execution flaw unusually valuable.</p>
<p dir="ltr">According to Sansec's <a href="https://sansec.io/research/stylesmuggler-0day" target="_blank" rel="nofollow noopener">analysis</a>, StyleSmuggler is a two-stage chain that abuses the platform's GraphQL interface. Attackers first inject PHP code into files Magento writes on its own, such as failure reports, then trigger execution through the platform's "Payment Transaction Failed Reminder" email routine. Because the trigger fires when the reminder is generated, no recipient has to open the message for the payload to run.</p>
<p dir="ltr">The <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/"   title="vulnerability" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29532">vulnerability</a> was confirmed on Magento Open Source 2.4.7, 2.4.8 and 2.4.9. The detail likely to unsettle merchants most is the first known victim: a store running 2.4.6-p15 with all available patches applied. Being current on Adobe's release cycle did not prevent compromise.</p>
<p dir="ltr">The implant Sansec documented is built to survive routine inspection. It runs under a process name mimicking a Linux kernel thread, <code>[kworker/u:8:0]</code>, with the binary written to <code>~/.local/share/.gvfsd/gvfsd-user</code> and a cron entry relaunching it every five minutes. Sansec also listed the domain <code>247.cdnflare.xyz</code> among its indicators of compromise.</p>
<p dir="ltr">Sansec advised merchants to disable GraphQL where the storefront can tolerate it, disable the PHP <code>proc_open</code> function, and mount <code>/tmp</code>, <code>/var/tmp</code> and <code>/dev/shm</code> with the <code>noexec</code> option. Unofficial community patches have been published by Disrex Group, ProxiBlue and Graycore. Disrex said it independently identified two compromised stores and a third that was attacked without being breached.</p>
<p dir="ltr">Adobe's most recent scheduled Commerce bulletin, APSB26-92, was published Aug. 11 and addressed critical and important flaws across the 2.4.4 through 2.4.9 branches. The company's next scheduled <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29534">security</a> release is Sept. 8. Adobe did not appear to have commented publicly on StyleSmuggler.</p>

<h5 dir="ltr">Also read: <a href="https://thecyberexpress.com/adobe-commerce-flaw-cve-2025-54236/">Adobe Issues Urgent Patch for ‘SessionReaper’ Vulnerability in Commerce and Magento</a></h5>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">113992</post-id>	</item>
		<item>
		<title>Attackers Exploited MikroTik RouterOS Flaws a Day Before Patches Shipped</title>
		<link>https://thecyberexpress.com/mikrotik-routeros-exploited-before-patch/</link>
		
		<dc:creator><![CDATA[Mihir Bagwe]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 11:39:45 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<guid isPermaLink="false">https://thecyberexpress.com/?p=113986</guid>

					<description><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="World map showing 122,500 internet-exposed MikroTik routers concentrated in Brazil, the United States, Indonesia, the Czech Republic and Ukraine" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS.webp 800w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS.webp 800w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="Attackers Exploited MikroTik RouterOS Flaws a Day Before Patches Shipped 13"></p><p dir="ltr">Attackers began compromising internet-exposed MikroTik routers on Sept. 2, a day before the Latvian vendor released fixes and three days before national authorities published the technical detail defenders needed to detect the intrusions.</p>

<h3 dir="ltr"><strong>What is the MikroTrick vulnerability chain?</strong></h3>
<p dir="ltr">CERT Polska <a href="https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/" target="_blank" rel="nofollow noopener">disclosed</a> six RouterOS vulnerabilities Sept. 5 and gave the two-flaw chain seen in the wild a common name, "MikroTrick." CVE-2026-67276, rated 9.2, is an SSH authentication bypass. RouterOS verified the type and modulus of a public key during authentication but omitted the exponent, letting an attacker who knows a username and the RSA modulus forge a matching key and authenticate without ever holding the private one.</p>
<p dir="ltr">CVE-2026-86060, also rated 9.2, is an argument injection flaw in which an SSH username beginning with a disallowed character escalates the session to full administrative rights. Chained, the two give an unauthenticated attacker complete control of any device with SSH reachable from the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/"   title="internet" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29530">internet</a>.</p>
<p dir="ltr">A third flaw, CVE-2026-67277 at 8.8, permits unauthenticated access to privileged state through the bandwidth-test service. CERT Polska credited the discoveries to its own team, which said it used OpenAI's GPT-5.5-<a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/"   title="cyber" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29531">cyber</a> and GPT-5.6-sol models under the vendor's Government and Trust Agency Collaboration program to automate version comparison, RFC analysis and binary review, with researchers independently verifying every finding.</p>
<p dir="ltr">The exposed population is large. Shadowserver counts more than 122,500 MikroTik devices with SSH reachable on the open internet, concentrated in Brazil with 11,300, the United States and Indonesia with 7,100 each, the Czech Republic with 6,300 and Ukraine with 5,100. CERT.LV said it has <a href="https://cert.lv/lv/2026/09/papildinats-uzbruceji-pastiprinati-censas-kompromitet-mikrotik-marsrutetajus" target="_blank" rel="nofollow noopener">confirmed</a> 12 compromised devices in Latvia out of several thousand exposed, notified critical infrastructure operators Sept. 3, and recorded intensifying attacks in an update published Sept. 6.</p>

<h3 dir="ltr"><strong>How to check whether your MikroTik router is compromised</strong></h3>
<p dir="ltr">Both agencies published the same indicators. Failed logins for a user named <code>-2</code>, system history entries reading <code>ssh:-2@</code>, creation of a privileged account named <code>ops</code>, and a "Flagged" marker RouterOS sets at startup. Attack traffic traced to 82.192.72.4 for successful compromises and 103.102.31.18 for attempts.</p>
<p dir="ltr">MikroTik shipped 6.49.21, 7.23.4, 7.24.2 and 7.25beta3 on Sept. 3 and pushed alerts through its mobile app, but declined to publish specifics, saying it was withholding detail to give users time to update. The embargo held about a day.</p>
<p dir="ltr">Network engineer Nick Pratley <a href="https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/" target="_blank" rel="nofollow noopener">published</a> a binary diff of RouterOS 7.23.3 against 7.24.2 on Sept. 4, reconstructing three of the fixes and releasing working proof-of-concept code. Shipping patched binaries worldwide, he argued, makes the diff itself the disclosure. A separate lab proof-of-concept for CVE-2026-67276 has since been posted to GitHub.</p>

<h3><strong>Why MikroTik's silent patch drew criticism</strong></h3>
<p dir="ltr">The sequencing is what draws criticism. Because exploitation preceded the patch, the withheld detail was not being kept from an attacker who lacked it. It was being kept from administrators who had no way to know they were already being targeted.</p>
<p dir="ltr">There is a regulatory dimension approaching. MikroTik is headquartered in Riga, and from Sept. 11 the EU Cyber Resilience Act requires manufacturers to file an early warning within 24 hours of learning a product is under active exploitation, routed through a platform operated by ENISA. A repeat of this week's sequence after that date would start a regulatory clock rather than leaving disclosure timing to vendor discretion.</p>

<h5 dir="ltr">Also read: <a href="https://thecyberexpress.com/russia-cyberattack-linked-to-fsb/">EU, UK Attribute Russia Cyberattack to FSB, Announce Sanctions</a></h5>]]></description>
										<content:encoded><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="World map showing 122,500 internet-exposed MikroTik routers concentrated in Brazil, the United States, Indonesia, the Czech Republic and Ukraine" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS.webp 800w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS.webp 800w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/MikroTik-RouterOS-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="Attackers Exploited MikroTik RouterOS Flaws a Day Before Patches Shipped 14"></p><p dir="ltr">Attackers began compromising internet-exposed MikroTik routers on Sept. 2, a day before the Latvian vendor released fixes and three days before national authorities published the technical detail defenders needed to detect the intrusions.</p>

<h3 dir="ltr"><strong>What is the MikroTrick vulnerability chain?</strong></h3>
<p dir="ltr">CERT Polska <a href="https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/" target="_blank" rel="nofollow noopener">disclosed</a> six RouterOS vulnerabilities Sept. 5 and gave the two-flaw chain seen in the wild a common name, "MikroTrick." CVE-2026-67276, rated 9.2, is an SSH authentication bypass. RouterOS verified the type and modulus of a public key during authentication but omitted the exponent, letting an attacker who knows a username and the RSA modulus forge a matching key and authenticate without ever holding the private one.</p>
<p dir="ltr">CVE-2026-86060, also rated 9.2, is an argument injection flaw in which an SSH username beginning with a disallowed character escalates the session to full administrative rights. Chained, the two give an unauthenticated attacker complete control of any device with SSH reachable from the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/"   title="internet" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29530">internet</a>.</p>
<p dir="ltr">A third flaw, CVE-2026-67277 at 8.8, permits unauthenticated access to privileged state through the bandwidth-test service. CERT Polska credited the discoveries to its own team, which said it used OpenAI's GPT-5.5-<a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/"   title="cyber" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29531">cyber</a> and GPT-5.6-sol models under the vendor's Government and Trust Agency Collaboration program to automate version comparison, RFC analysis and binary review, with researchers independently verifying every finding.</p>
<p dir="ltr">The exposed population is large. Shadowserver counts more than 122,500 MikroTik devices with SSH reachable on the open internet, concentrated in Brazil with 11,300, the United States and Indonesia with 7,100 each, the Czech Republic with 6,300 and Ukraine with 5,100. CERT.LV said it has <a href="https://cert.lv/lv/2026/09/papildinats-uzbruceji-pastiprinati-censas-kompromitet-mikrotik-marsrutetajus" target="_blank" rel="nofollow noopener">confirmed</a> 12 compromised devices in Latvia out of several thousand exposed, notified critical infrastructure operators Sept. 3, and recorded intensifying attacks in an update published Sept. 6.</p>

<h3 dir="ltr"><strong>How to check whether your MikroTik router is compromised</strong></h3>
<p dir="ltr">Both agencies published the same indicators. Failed logins for a user named <code>-2</code>, system history entries reading <code>ssh:-2@</code>, creation of a privileged account named <code>ops</code>, and a "Flagged" marker RouterOS sets at startup. Attack traffic traced to 82.192.72.4 for successful compromises and 103.102.31.18 for attempts.</p>
<p dir="ltr">MikroTik shipped 6.49.21, 7.23.4, 7.24.2 and 7.25beta3 on Sept. 3 and pushed alerts through its mobile app, but declined to publish specifics, saying it was withholding detail to give users time to update. The embargo held about a day.</p>
<p dir="ltr">Network engineer Nick Pratley <a href="https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/" target="_blank" rel="nofollow noopener">published</a> a binary diff of RouterOS 7.23.3 against 7.24.2 on Sept. 4, reconstructing three of the fixes and releasing working proof-of-concept code. Shipping patched binaries worldwide, he argued, makes the diff itself the disclosure. A separate lab proof-of-concept for CVE-2026-67276 has since been posted to GitHub.</p>

<h3><strong>Why MikroTik's silent patch drew criticism</strong></h3>
<p dir="ltr">The sequencing is what draws criticism. Because exploitation preceded the patch, the withheld detail was not being kept from an attacker who lacked it. It was being kept from administrators who had no way to know they were already being targeted.</p>
<p dir="ltr">There is a regulatory dimension approaching. MikroTik is headquartered in Riga, and from Sept. 11 the EU Cyber Resilience Act requires manufacturers to file an early warning within 24 hours of learning a product is under active exploitation, routed through a platform operated by ENISA. A repeat of this week's sequence after that date would start a regulatory clock rather than leaving disclosure timing to vendor discretion.</p>

<h5 dir="ltr">Also read: <a href="https://thecyberexpress.com/russia-cyberattack-linked-to-fsb/">EU, UK Attribute Russia Cyberattack to FSB, Announce Sanctions</a></h5>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">113986</post-id>	</item>
		<item>
		<title>Liquid Network Hackers Demand Bug Fix Before Returning $320M BTC</title>
		<link>https://thecyberexpress.com/liquid-network-security-incident/</link>
		
		<dc:creator><![CDATA[Ashish Khaitan]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 08:28:11 +0000</pubDate>
				<category><![CDATA[Firewall Daily]]></category>
		<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Liquid Network security incident]]></category>
		<category><![CDATA[The Cyber Express]]></category>
		<category><![CDATA[The Cyber Express News]]></category>
		<category><![CDATA[Thorn]]></category>
		<category><![CDATA[White hat hackers]]></category>
		<guid isPermaLink="false">https://thecyberexpress.com/?p=113978</guid>

					<description><![CDATA[<p><img width="824" height="496" src="https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Liquid Network security incident" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident.webp 824w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-300x181.webp 300w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-768x462.webp 768w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-600x361.webp 600w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-150x90.webp 150w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-750x451.webp 750w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident.webp 824w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-300x181.webp 300w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-768x462.webp 768w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-600x361.webp 600w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-150x90.webp 150w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-750x451.webp 750w" sizes="(max-width: 824px) 100vw, 824px" title="Liquid Network Hackers Demand Bug Fix Before Returning $320M BTC 15"></p><span data-contrast="auto">The Liquid Network security incident has taken an unusual turn after the unidentified actors behind the theft of nearly 4,000 BTC offered to return “most” of the funds — but only after the vulnerability that enabled the exploit is fixed across the network.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The purported white-hat hackers communicated their condition through an ongoing exchange with Blockstream, according to <a href="https://x.com/intangiblecoins/status/2096808321332158474" target="_blank" rel="nofollow noopener">Galaxy Research head Alex Thorn</a>. The incident involved roughly $320 million worth of BTC and has raised questions over whether the attackers are genuine security researchers or simply exploiting the language and behavior associated with white-hat <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-hacking/"   title="hacking" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29526">hacking</a>.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The episode began on Sunday, when approximately 4,000 BTC was withdrawn from the Liquid Federation wallet. The amount represented about 95% of the Bitcoin that had been pegged into the Liquid sidechain.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Following the withdrawals, Liquid disabled its bridge nodes and paused the network. The stolen funds were subsequently consolidated into a Bitcoin address containing a message that read: “we are whitehats. contact us on chain.”</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Liquid, however, has continued to describe the individuals involved as purported white-hat hackers, reflecting the uncertainty surrounding their identity and intentions.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Liquid Network Security Incident Sparks On-Chain Conversation</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">The <a href="https://u.today/liquid-hackers-to-return-most-of-4000-btc-after-bug-fix" target="_blank" rel="nofollow noopener">unusual communication</a> between the attackers and Blockstream has taken place through Bitcoin OP_RETURN messages and PGP-encrypted text.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Thorn reconstructed the exchange and reported that Blockstream attempted to contact the actors at Bitcoin block 965,822. The company sent 1,000 satoshis along with an OP_RETURN message intended to alert its <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29528">security</a> team and establish a communication channel.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">A later transaction included encrypted material addressed to the holder of the relevant key, along with a PGP signature. According to Thorn, the signature could be verified against Blockstream’s published public key, providing an indication that the communication was connected to the company.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The purported <a href="https://thecyberexpress.com/maltese-government-legal-hacking-framework/" target="_blank" rel="noopener">white-hat hackers</a> subsequently responded at block 965,869. They moved their own balance and sent 1,000 satoshis to the federation’s peg wallet. Alongside the transaction, they asked whether returning “most” of the withdrawn BTC to the federation address would be acceptable.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">That proposal came with a significant condition: the <a href="https://thecyberexpress.com/cve-2026-77846-ashsqlite-vulnerability/" target="_blank" rel="noopener">vulnerability</a> responsible for the Liquid Network security incident would have to be fixed first.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">“Please fix the bug first,” the hackers told Blockstream.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">White-Hat Hackers Leave Questions Over Returned BTC</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">The use of the word “most” has introduced another layer of uncertainty. The message does not specify how much BTC the actors would ultimately return, leaving open the possibility that they could retain a portion of the nearly 4,000 BTC taken from the federation wallet.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">There is also no guarantee that the promised return will actually occur. Until the funds move back to the federation-controlled address, almost all of the Bitcoin remains under the control of the unidentified actors.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The incident initially prompted skepticism from <a href="https://u.today/liquid-hackers-to-return-most-of-4000-btc-after-bug-fix" target="_blank" rel="nofollow noopener">Ledger Chief Technology Officer Charles Guillemet</a>, who argued that conventional white-hat hackers generally do not drain hundreds of millions of dollars from a bridge.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Guillemet compared the situation with major cryptocurrency exploits such as Ronin and Euler, where attackers were responsible for substantial losses. His initial assessment suggested that the scale and method of the Liquid incident were inconsistent with the typical behavior expected from legitimate security researchers.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">His position later softened after the hackers attempted to communicate with Blockstream.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">BTC Remains Under Hackers’ Control</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">Guillemet noted that criminal groups do not typically make efforts to establish direct communication with their victims after carrying out an <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank"  rel="noopener" title="exploit" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29527">exploit</a>. The willingness of the actors to communicate therefore created some hope that the funds could eventually be recovered.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">“There’s hope,” Guillemet wrote.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">He also argued that the <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/"   title="vulnerability" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29525">vulnerability</a> could potentially be researched using powerful AI systems to identify the underlying flaw without relying on proper disclosure procedures.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">For now, however, the outcome of the Liquid <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-network-security/"   title="Network security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29529">Network security</a> incident remains unresolved. The hackers have indicated that they are prepared to return “most” of the BTC, but only once the underlying bug has been fixed across the network.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The development leaves Blockstream and Liquid facing two immediate challenges: addressing the vulnerability that allowed the exploit and determining whether the unidentified actors will honor their commitment.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Until those steps are completed, the nearly 4,000 BTC involved in the incident remains largely outside the federation’s control. The on-chain messages provide a rare window into negotiations between an exploited <a href="https://thecyberexpress.com/west-african-organized-crime-groups-crackdown/" target="_blank" rel="noopener">crypto network</a> and the people claiming responsibility, but they do not yet establish whether the purported white-hat hackers will ultimately return the funds.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>]]></description>
										<content:encoded><![CDATA[<p><img width="824" height="496" src="https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Liquid Network security incident" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident.webp 824w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-300x181.webp 300w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-768x462.webp 768w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-600x361.webp 600w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-150x90.webp 150w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-750x451.webp 750w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident.webp 824w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-300x181.webp 300w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-768x462.webp 768w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-600x361.webp 600w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-150x90.webp 150w, https://thecyberexpress.com/wp-content/uploads/Liquid-Network-security-incident-750x451.webp 750w" sizes="(max-width: 824px) 100vw, 824px" title="Liquid Network Hackers Demand Bug Fix Before Returning $320M BTC 16"></p><span data-contrast="auto">The Liquid Network security incident has taken an unusual turn after the unidentified actors behind the theft of nearly 4,000 BTC offered to return “most” of the funds — but only after the vulnerability that enabled the exploit is fixed across the network.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The purported white-hat hackers communicated their condition through an ongoing exchange with Blockstream, according to <a href="https://x.com/intangiblecoins/status/2096808321332158474" target="_blank" rel="nofollow noopener">Galaxy Research head Alex Thorn</a>. The incident involved roughly $320 million worth of BTC and has raised questions over whether the attackers are genuine security researchers or simply exploiting the language and behavior associated with white-hat <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-hacking/"   title="hacking" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29526">hacking</a>.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The episode began on Sunday, when approximately 4,000 BTC was withdrawn from the Liquid Federation wallet. The amount represented about 95% of the Bitcoin that had been pegged into the Liquid sidechain.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Following the withdrawals, Liquid disabled its bridge nodes and paused the network. The stolen funds were subsequently consolidated into a Bitcoin address containing a message that read: “we are whitehats. contact us on chain.”</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Liquid, however, has continued to describe the individuals involved as purported white-hat hackers, reflecting the uncertainty surrounding their identity and intentions.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Liquid Network Security Incident Sparks On-Chain Conversation</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">The <a href="https://u.today/liquid-hackers-to-return-most-of-4000-btc-after-bug-fix" target="_blank" rel="nofollow noopener">unusual communication</a> between the attackers and Blockstream has taken place through Bitcoin OP_RETURN messages and PGP-encrypted text.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Thorn reconstructed the exchange and reported that Blockstream attempted to contact the actors at Bitcoin block 965,822. The company sent 1,000 satoshis along with an OP_RETURN message intended to alert its <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29528">security</a> team and establish a communication channel.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">A later transaction included encrypted material addressed to the holder of the relevant key, along with a PGP signature. According to Thorn, the signature could be verified against Blockstream’s published public key, providing an indication that the communication was connected to the company.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The purported <a href="https://thecyberexpress.com/maltese-government-legal-hacking-framework/" target="_blank" rel="noopener">white-hat hackers</a> subsequently responded at block 965,869. They moved their own balance and sent 1,000 satoshis to the federation’s peg wallet. Alongside the transaction, they asked whether returning “most” of the withdrawn BTC to the federation address would be acceptable.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">That proposal came with a significant condition: the <a href="https://thecyberexpress.com/cve-2026-77846-ashsqlite-vulnerability/" target="_blank" rel="noopener">vulnerability</a> responsible for the Liquid Network security incident would have to be fixed first.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">“Please fix the bug first,” the hackers told Blockstream.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">White-Hat Hackers Leave Questions Over Returned BTC</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">The use of the word “most” has introduced another layer of uncertainty. The message does not specify how much BTC the actors would ultimately return, leaving open the possibility that they could retain a portion of the nearly 4,000 BTC taken from the federation wallet.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">There is also no guarantee that the promised return will actually occur. Until the funds move back to the federation-controlled address, almost all of the Bitcoin remains under the control of the unidentified actors.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The incident initially prompted skepticism from <a href="https://u.today/liquid-hackers-to-return-most-of-4000-btc-after-bug-fix" target="_blank" rel="nofollow noopener">Ledger Chief Technology Officer Charles Guillemet</a>, who argued that conventional white-hat hackers generally do not drain hundreds of millions of dollars from a bridge.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Guillemet compared the situation with major cryptocurrency exploits such as Ronin and Euler, where attackers were responsible for substantial losses. His initial assessment suggested that the scale and method of the Liquid incident were inconsistent with the typical behavior expected from legitimate security researchers.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">His position later softened after the hackers attempted to communicate with Blockstream.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">BTC Remains Under Hackers’ Control</span></b><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h3>
<span data-contrast="auto">Guillemet noted that criminal groups do not typically make efforts to establish direct communication with their victims after carrying out an <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank"  rel="noopener" title="exploit" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29527">exploit</a>. The willingness of the actors to communicate therefore created some hope that the funds could eventually be recovered.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">“There’s hope,” Guillemet wrote.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">He also argued that the <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/"   title="vulnerability" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29525">vulnerability</a> could potentially be researched using powerful AI systems to identify the underlying flaw without relying on proper disclosure procedures.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">For now, however, the outcome of the Liquid <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-network-security/"   title="Network security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29529">Network security</a> incident remains unresolved. The hackers have indicated that they are prepared to return “most” of the BTC, but only once the underlying bug has been fixed across the network.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The development leaves Blockstream and Liquid facing two immediate challenges: addressing the vulnerability that allowed the exploit and determining whether the unidentified actors will honor their commitment.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Until those steps are completed, the nearly 4,000 BTC involved in the incident remains largely outside the federation’s control. The on-chain messages provide a rare window into negotiations between an exploited <a href="https://thecyberexpress.com/west-african-organized-crime-groups-crackdown/" target="_blank" rel="noopener">crypto network</a> and the people claiming responsibility, but they do not yet establish whether the purported white-hat hackers will ultimately return the funds.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">113978</post-id>	</item>
		<item>
		<title>Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ</title>
		<link>https://thecyberexpress.com/mathspace-data-breach/</link>
		
		<dc:creator><![CDATA[Ashish Khaitan]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 07:14:26 +0000</pubDate>
				<category><![CDATA[Firewall Daily]]></category>
		<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Data Breach News]]></category>
		<category><![CDATA[Mathspace data breach]]></category>
		<category><![CDATA[schools]]></category>
		<category><![CDATA[security incident]]></category>
		<category><![CDATA[teachers]]></category>
		<category><![CDATA[The Cyber Express]]></category>
		<category><![CDATA[The Cyber Express News]]></category>
		<guid isPermaLink="false">https://thecyberexpress.com/?p=113972</guid>

					<description><![CDATA[<p><img width="809" height="476" src="https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Mathspace data breach" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach.webp 809w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-300x177.webp 300w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-768x452.webp 768w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-600x353.webp 600w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-150x88.webp 150w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-750x441.webp 750w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach.webp 809w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-300x177.webp 300w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-768x452.webp 768w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-600x353.webp 600w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-150x88.webp 150w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-750x441.webp 750w" sizes="(max-width: 809px) 100vw, 809px" title="Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ 17"></p><span data-contrast="auto">The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said the affected records involve students, parents or guardians, teachers, and Mathspace staff.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The company said names, email addresses, and account details were exposed, but customer passwords, single sign-on (SSO) tokens, and other authentication credentials were not. There is currently no evidence that the information has been published, sold, distributed, or otherwise misused. The attacker’s identity remains unknown.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">How the Mathspace Data Breach Happened?</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h3>
<span data-contrast="auto">The security incident resulted from a <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/"   title="vulnerability" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29521">vulnerability</a> in Mathspace’s self-hosted Metabase installation, which was used for internal reporting. The flaw allowed attackers to obtain administrator access without a legitimate login.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Metabase issued a critical <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29524">security</a> advisory and patched versions on August 6. Mathspace said its vulnerability-notification process failed to identify and escalate that advisory. The company later updated its Metabase instance on August 29 after seeing a subsequent notice.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto"><a href="https://blog.mathspace.co/mathspace-data-breach-what-happened-and-what-affected-users-should-know/" target="_blank" rel="nofollow noopener">An investigation found</a> unauthorized access dating to August 10, Australian Eastern Standard Time. Information was downloaded from Mathspace’s Australian reporting database on August 27. Historical log reviews confirmed the unauthorized access on September 3, before the update had been applied. Mathspace also acknowledged that it did not complete additional compromise checks recommended for potentially affected systems at the time of the update.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">What Information was Exposed?</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h3>
<span data-contrast="auto">The exported <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/"   title="data" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29523">data</a> included user IDs, usernames, first and last names, email addresses, country, time zone, user type, email-verification status, last-active date, last-login date and joining date. Not every field appeared for every affected person.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Mathspace said the exposure went beyond names and <a href="https://thecyberexpress.com/clickup-feature-flag-misgonfiguration-leak/" target="_blank" rel="noopener">email addresses</a>. User IDs are internal identifiers, including those linked to student accounts. However, no academic records, learning activities, results, assessments, password hashes, authentication tokens, SSO credentials or API credentials were exposed.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The data did not contain records directly linking accounts to schools, although Mathspace said school affiliations could potentially be inferred where identifiable email domains were used. Former or inactive users may also be affected because retained information could remain in the reporting database.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">What Users Should Know After the Security Incident?</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h3>
<span data-contrast="auto">Names, email addresses, and account details could make <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank"  rel="noopener" title="phishing" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29522">phishing</a> or impersonation attempts more convincing. Users have been advised to independently verify unexpected messages, avoid unfamiliar links and attachments, and never provide passwords or verification codes in response to unsolicited communications.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Mathspace is not requiring password resets because customer authentication credentials were not exposed. However, anyone who reused a Mathspace password elsewhere should change those reused passwords to unique ones and monitor accounts for unusual activity.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Response to the Mathspace Data Breach</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h3>
<span data-contrast="auto">After confirming the breach on September 3, Mathspace took Metabase offline, revoked its API keys, disabled Metabase database-access accounts in its Australian and US Snowflake environments, and changed passwords for its Metabase Cloud SQL databases. The company also copied the application database and exported access logs for <a href="https://thecyberexpress.com/tiktok-age-verification-probe-launched-by-uk/" target="_blank" rel="noopener">investigation</a>. Metabase remains offline while recovery and compromise checks continue.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Mathspace began notifying school contacts on September 4 and started notifying affected individuals on September 6, earlier than the date previously communicated to schools.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">On September 4, the security incident was reported to Australia’s Office of the Australian Information Commissioner, the Australian Signals Directorate’s Australian <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/"   title="Cyber" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29520">Cyber</a> Security Centre, New Zealand’s Office of the Privacy Commissioner and National Cyber Security Centre, as well as Australian state and territory education departments.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>]]></description>
										<content:encoded><![CDATA[<p><img width="809" height="476" src="https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Mathspace data breach" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach.webp 809w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-300x177.webp 300w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-768x452.webp 768w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-600x353.webp 600w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-150x88.webp 150w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-750x441.webp 750w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach.webp 809w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-300x177.webp 300w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-768x452.webp 768w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-600x353.webp 600w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-150x88.webp 150w, https://thecyberexpress.com/wp-content/uploads/Mathspace-data-breach-750x441.webp 750w" sizes="(max-width: 809px) 100vw, 809px" title="Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ 18"></p><span data-contrast="auto">The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said the affected records involve students, parents or guardians, teachers, and Mathspace staff.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The company said names, email addresses, and account details were exposed, but customer passwords, single sign-on (SSO) tokens, and other authentication credentials were not. There is currently no evidence that the information has been published, sold, distributed, or otherwise misused. The attacker’s identity remains unknown.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">How the Mathspace Data Breach Happened?</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h3>
<span data-contrast="auto">The security incident resulted from a <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/"   title="vulnerability" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29521">vulnerability</a> in Mathspace’s self-hosted Metabase installation, which was used for internal reporting. The flaw allowed attackers to obtain administrator access without a legitimate login.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Metabase issued a critical <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29524">security</a> advisory and patched versions on August 6. Mathspace said its vulnerability-notification process failed to identify and escalate that advisory. The company later updated its Metabase instance on August 29 after seeing a subsequent notice.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto"><a href="https://blog.mathspace.co/mathspace-data-breach-what-happened-and-what-affected-users-should-know/" target="_blank" rel="nofollow noopener">An investigation found</a> unauthorized access dating to August 10, Australian Eastern Standard Time. Information was downloaded from Mathspace’s Australian reporting database on August 27. Historical log reviews confirmed the unauthorized access on September 3, before the update had been applied. Mathspace also acknowledged that it did not complete additional compromise checks recommended for potentially affected systems at the time of the update.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">What Information was Exposed?</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h3>
<span data-contrast="auto">The exported <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/"   title="data" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29523">data</a> included user IDs, usernames, first and last names, email addresses, country, time zone, user type, email-verification status, last-active date, last-login date and joining date. Not every field appeared for every affected person.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Mathspace said the exposure went beyond names and <a href="https://thecyberexpress.com/clickup-feature-flag-misgonfiguration-leak/" target="_blank" rel="noopener">email addresses</a>. User IDs are internal identifiers, including those linked to student accounts. However, no academic records, learning activities, results, assessments, password hashes, authentication tokens, SSO credentials or API credentials were exposed.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">The data did not contain records directly linking accounts to schools, although Mathspace said school affiliations could potentially be inferred where identifiable email domains were used. Former or inactive users may also be affected because retained information could remain in the reporting database.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">What Users Should Know After the Security Incident?</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h3>
<span data-contrast="auto">Names, email addresses, and account details could make <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank"  rel="noopener" title="phishing" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29522">phishing</a> or impersonation attempts more convincing. Users have been advised to independently verify unexpected messages, avoid unfamiliar links and attachments, and never provide passwords or verification codes in response to unsolicited communications.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Mathspace is not requiring password resets because customer authentication credentials were not exposed. However, anyone who reused a Mathspace password elsewhere should change those reused passwords to unique ones and monitor accounts for unusual activity.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Response to the Mathspace Data Breach</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:299,&quot;335559739&quot;:299}"> </span></h3>
<span data-contrast="auto">After confirming the breach on September 3, Mathspace took Metabase offline, revoked its API keys, disabled Metabase database-access accounts in its Australian and US Snowflake environments, and changed passwords for its Metabase Cloud SQL databases. The company also copied the application database and exported access logs for <a href="https://thecyberexpress.com/tiktok-age-verification-probe-launched-by-uk/" target="_blank" rel="noopener">investigation</a>. Metabase remains offline while recovery and compromise checks continue.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">Mathspace began notifying school contacts on September 4 and started notifying affected individuals on September 6, earlier than the date previously communicated to schools.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>

<span data-contrast="auto">On September 4, the security incident was reported to Australia’s Office of the Australian Information Commissioner, the Australian Signals Directorate’s Australian <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/"   title="Cyber" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29520">Cyber</a> Security Centre, New Zealand’s Office of the Privacy Commissioner and National Cyber Security Centre, as well as Australian state and territory education departments.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">113972</post-id>	</item>
		<item>
		<title>G7, CISA Urge Urgent Shift to Post-Quantum Cryptography</title>
		<link>https://thecyberexpress.com/post-quantum-cryptography/</link>
		
		<dc:creator><![CDATA[Samiksha Jain]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 06:51:40 +0000</pubDate>
				<category><![CDATA[Firewall Daily]]></category>
		<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[CISA]]></category>
		<category><![CDATA[CRQC development]]></category>
		<category><![CDATA[CRQCs]]></category>
		<category><![CDATA[ENISA]]></category>
		<category><![CDATA[G7 Cybersecurity Working Group]]></category>
		<category><![CDATA[post-quantum cryptography]]></category>
		<category><![CDATA[PQC Transition]]></category>
		<category><![CDATA[Quantum computers]]></category>
		<category><![CDATA[Quantum Computing]]></category>
		<guid isPermaLink="false">https://thecyberexpress.com/?p=113966</guid>

					<description><![CDATA[<p><img width="1408" height="768" src="https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="post-quantum cryptography" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography.webp 1408w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-1024x559.webp 1024w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-1140x622.webp 1140w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography.webp 1408w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-1024x559.webp 1024w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-1140x622.webp 1140w" sizes="(max-width: 1408px) 100vw, 1408px" title="G7, CISA Urge Urgent Shift to Post-Quantum Cryptography 19"></p><p dir="ltr">Some of the world's leading democracies are pushing governments and companies to start preparing for <strong>post-quantum cryptography</strong> before quantum computers become powerful enough to break the encryption systems that protect global digital infrastructure today.</p>
<p dir="ltr">In a joint advisory released Thursday, the G7 Cybersecurity Working Group and the U.S. Cybersecurity and Infrastructure Security Agency (<a href="https://thecyberexpress.com/?s=CISA" target="_blank" rel="nofollow noopener">CISA</a>) said organizations should begin their transition to post-quantum cryptography now, rather than waiting until cryptographically relevant quantum computers (CRQCs) are available to threat actors.</p>

<h3 dir="ltr"><strong>Why the Post-Quantum Cryptography Shift Cannot Wait</strong></h3>
<p dir="ltr">The publication, titled "Preparing for the Post-Quantum Era: A Call to Action,"<a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow noopener"> warns</a> that the quantum computing threat is no longer a distant concern. While the exact timeline for CRQC development remains uncertain, the working group said recent technological advances suggest such machines could emerge sooner than expected, putting widely used public-key cryptography mechanisms at risk.</p>
<p dir="ltr">One of the most immediate dangers is a tactic known as "harvest now, decrypt later," where malicious actors intercept and store encrypted <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/"   title="data" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29518">data</a> today with the intention of decrypting it once a CRQC becomes available. This poses a serious risk to governmental records, sensitive personal data, and trade or business secrets that require long-term confidentiality.</p>
<p dir="ltr">The advisory also cautions that CRQCs could eventually be used to target authentication mechanisms, allowing bad actors to impersonate trusted entities, forge data, or compromise equipment. Because supply chain <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/"   title="vulnerabilities" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29513">vulnerabilities</a> can cascade, a single organization's delay in adopting post-quantum cryptography could expose entire sectors to compromise.</p>
<p dir="ltr">According to the report, organizations that fail to act may also face business consequences beyond <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29514">security</a> risk, including exclusion from public procurement contracts and loss of competitive advantage.</p>

<h3 dir="ltr"><strong>Five Priorities for the PQC Transition</strong></h3>
<p dir="ltr">The G7 <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/"   title="Cybersecurity" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29516">Cybersecurity</a> Working Group outlined five priority areas to guide the global shift toward post-quantum cryptography:</p>

<ol dir="ltr">
 	<li><strong>Raising awareness</strong> — Many organizations still view the quantum threat as a distant or purely technical issue. The group called for awareness campaigns, technical guidance, and workforce upskilling to reframe it as an economic and business risk.</li>
 	<li><strong>Developing national strategies</strong> — Countries are encouraged to build strategies that ensure an adequate supply of quantum-safe hardware and software while encouraging adoption, integrating the effort into broader digital <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-privacy/"   title="privacy" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29517">privacy</a> and security policies.</li>
 	<li><strong>Advancing research and development</strong> — Governments should fund research programs and support pilot projects and testbeds to help organizations test and refine their transition to post-quantum cryptography.</li>
 	<li><strong>Building public-private partnerships</strong> — Collaboration between government, industry, and academia is seen as key to developing domestic expertise, lowering transition costs, and sharing playbooks and case studies across sectors.</li>
 	<li><strong>Integrating PQC into <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank"  rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29519">cybersecurity</a> requirements</strong> — The group recommends treating post-quantum cryptography adoption as a natural evolution of cryptographic best practice, and embedding requirements into public procurement to push both vendors and organizations toward quantum-safe systems.</li>
</ol>
<p dir="ltr">The advisory emphasizes that the shift to post-quantum cryptography cannot be solved by individual organizations in isolation. Instead, it calls for early engagement, coordinated planning, and informed decision-making across public and private sectors worldwide.</p>
<p dir="ltr">Tackling the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/"   title="risks" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29515">risks</a> that the impending quantum computing era poses to current cryptographic systems... requires a coordinated global effort to transition to PQC," the report states, adding that public and private organizations must act now to safeguard confidential data, supply chains, and critical systems.</p>
<p dir="ltr">The document was jointly published by cybersecurity authorities from Canada, Germany, Italy, Japan, the United Kingdom, the United States, and France's ANSSI, with participation from the European Commission and support from the <a href="https://thecyberexpress.com/european-space-agency-confirms-cyber-incident/" target="_blank" rel="noopener">EU Agency for Cybersecurity</a> (ENISA).</p>]]></description>
										<content:encoded><![CDATA[<p><img width="1408" height="768" src="https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="post-quantum cryptography" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography.webp 1408w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-1024x559.webp 1024w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-1140x622.webp 1140w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography.webp 1408w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-1024x559.webp 1024w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/post-quantum-cryptography-1140x622.webp 1140w" sizes="(max-width: 1408px) 100vw, 1408px" title="G7, CISA Urge Urgent Shift to Post-Quantum Cryptography 20"></p><p dir="ltr">Some of the world's leading democracies are pushing governments and companies to start preparing for <strong>post-quantum cryptography</strong> before quantum computers become powerful enough to break the encryption systems that protect global digital infrastructure today.</p>
<p dir="ltr">In a joint advisory released Thursday, the G7 Cybersecurity Working Group and the U.S. Cybersecurity and Infrastructure Security Agency (<a href="https://thecyberexpress.com/?s=CISA" target="_blank" rel="nofollow noopener">CISA</a>) said organizations should begin their transition to post-quantum cryptography now, rather than waiting until cryptographically relevant quantum computers (CRQCs) are available to threat actors.</p>

<h3 dir="ltr"><strong>Why the Post-Quantum Cryptography Shift Cannot Wait</strong></h3>
<p dir="ltr">The publication, titled "Preparing for the Post-Quantum Era: A Call to Action,"<a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow noopener"> warns</a> that the quantum computing threat is no longer a distant concern. While the exact timeline for CRQC development remains uncertain, the working group said recent technological advances suggest such machines could emerge sooner than expected, putting widely used public-key cryptography mechanisms at risk.</p>
<p dir="ltr">One of the most immediate dangers is a tactic known as "harvest now, decrypt later," where malicious actors intercept and store encrypted <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/"   title="data" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29518">data</a> today with the intention of decrypting it once a CRQC becomes available. This poses a serious risk to governmental records, sensitive personal data, and trade or business secrets that require long-term confidentiality.</p>
<p dir="ltr">The advisory also cautions that CRQCs could eventually be used to target authentication mechanisms, allowing bad actors to impersonate trusted entities, forge data, or compromise equipment. Because supply chain <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/"   title="vulnerabilities" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29513">vulnerabilities</a> can cascade, a single organization's delay in adopting post-quantum cryptography could expose entire sectors to compromise.</p>
<p dir="ltr">According to the report, organizations that fail to act may also face business consequences beyond <a class="wpil_keyword_link" href="https://thecyberexpress.com/"   title="security" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29514">security</a> risk, including exclusion from public procurement contracts and loss of competitive advantage.</p>

<h3 dir="ltr"><strong>Five Priorities for the PQC Transition</strong></h3>
<p dir="ltr">The G7 <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/"   title="Cybersecurity" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29516">Cybersecurity</a> Working Group outlined five priority areas to guide the global shift toward post-quantum cryptography:</p>

<ol dir="ltr">
 	<li><strong>Raising awareness</strong> — Many organizations still view the quantum threat as a distant or purely technical issue. The group called for awareness campaigns, technical guidance, and workforce upskilling to reframe it as an economic and business risk.</li>
 	<li><strong>Developing national strategies</strong> — Countries are encouraged to build strategies that ensure an adequate supply of quantum-safe hardware and software while encouraging adoption, integrating the effort into broader digital <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-privacy/"   title="privacy" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29517">privacy</a> and security policies.</li>
 	<li><strong>Advancing research and development</strong> — Governments should fund research programs and support pilot projects and testbeds to help organizations test and refine their transition to post-quantum cryptography.</li>
 	<li><strong>Building public-private partnerships</strong> — Collaboration between government, industry, and academia is seen as key to developing domestic expertise, lowering transition costs, and sharing playbooks and case studies across sectors.</li>
 	<li><strong>Integrating PQC into <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank"  rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29519">cybersecurity</a> requirements</strong> — The group recommends treating post-quantum cryptography adoption as a natural evolution of cryptographic best practice, and embedding requirements into public procurement to push both vendors and organizations toward quantum-safe systems.</li>
</ol>
<p dir="ltr">The advisory emphasizes that the shift to post-quantum cryptography cannot be solved by individual organizations in isolation. Instead, it calls for early engagement, coordinated planning, and informed decision-making across public and private sectors worldwide.</p>
<p dir="ltr">Tackling the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/"   title="risks" data-wpil-keyword-link="linked"  data-wpil-monitor-id="29515">risks</a> that the impending quantum computing era poses to current cryptographic systems... requires a coordinated global effort to transition to PQC," the report states, adding that public and private organizations must act now to safeguard confidential data, supply chains, and critical systems.</p>
<p dir="ltr">The document was jointly published by cybersecurity authorities from Canada, Germany, Italy, Japan, the United Kingdom, the United States, and France's ANSSI, with participation from the European Commission and support from the <a href="https://thecyberexpress.com/european-space-agency-confirms-cyber-incident/" target="_blank" rel="noopener">EU Agency for Cybersecurity</a> (ENISA).</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">113966</post-id>	</item>
	</channel>
</rss>