News

Google Pixel phones pwned in zero-click attacks

The Register - 1 hour 7 min ago
Both Google and Uncle Sam warned that attackers have exploited a zero-day improper authorization bug in Pixel phones' cellular modems that can bypass permission checks and escalate privileges with no user interaction required. The hole has since been closed, provided that you update. Google disclosed the high-severity vulnerability, tracked as CVE-2026-58704, on Tuesday - and, at the time, warned the security hole “may be under limited, targeted exploitation.” In other words: miscreants found and exploited this bug before Google fixed the issue. The Register reached out to Google for more details about the scope of exploitation, and how attackers are exploiting the flaw and what they can achieve. We have very limited details about the vulnerability itself, other than that it exists in Pixel phones' modems, is being exploited in the wild, and can be exploited in zero-click attacks, meaning no user interaction is required. We do know, however, that these types of zero-click attacks are frequently used by commercial spyware makers to surveil targeted individuals. On Wednesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added the CVE to its Known Exploited Vulnerabilities Catalog and gave federal agencies just three days - until September 19 - to patch the flaw. “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” according to the cyber-defense agency. Earlier this month, CISA added two Google Chromium vulnerabilities, CVE-2026-85046 and CVE-2026-87491, to its KEV catalog. CVE-2026-85046 is a type confusion flaw in Chromium’s V8 JavaScript engine that allows remote attackers to execute code inside the sandbox via a crafted HTML page. It affects all Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera. The second flaw, an out-of-bounds write vulnerability tracked as CVE-2026-87491, also exists in the V8 engine, allows for remote code execution, and affects all Chromium-based browsers. Security researchers at Proofpoint last week told The Register that at least four espionage groups, most with suspected links to China, chained three bugs together, including CVE-2026-85046, to break into organizations' networks in the US and Southeast Asia. ®
Categories: News

Spain gets its first taste of AI-aided cyber attack

The Register - 7 hours 7 min ago
Spain’s data protection agency (AEPD) has reported the country’s first-ever personal data breach caused by the actions of an autonomous AI agent. Francisco Pérez Bes, president and deputy of the AEPD, said in a Monday blog post that an individual deployed an AI agent that used a “known large language model (LLM)” to carry out the attack on an organization. The agent scanned “generic files” before accessing the organization’s system, then ran vulnerability scans to find flaws that would give it read/write access to files containing personal data and invoices. Pérez Bes did not name the LLM used to support the attack, but said whoever was behind it used the agent to “successfully chain together different phases of the attack.” This demonstrates that AI-supported attacks are no longer theoretical, he added, and called on organizations to embrace defense tools that are capable of keeping pace with the speed at which agentic attacks can be executed. “Human supervision remains essential, but it must be supported by detection, containment, and response mechanisms capable of operating quickly enough,” said Pérez Bes (machine-translated). “The arrival of AI agents in the offensive arena should prompt an immediate review of security and data protection models. “Data protection officers, managers, and delegates must prepare for a scenario in which the speed of attacks will increase, but in which the same fundamentals will continue to be crucial: Understanding the processing activities, minimizing data, limiting access, correcting vulnerabilities, controlling suppliers, and being prepared to respond.” The Register asked AEPD for more information. Spain’s first AI agent attack comes as the AEPD recently recorded its busiest year for data protection complaints. According to its most recent annual report, covering 2025, the agency received 30,931 complaints – the most in its history – representing a 64 percent increase compared to the year before. And although Spain is only now getting its first taste of a security mishap caused by a naughty agent, cases involving the foremost US AI houses are already heavily documented. OpenAI’s claim in July that its agents escaped a sandbox and started attacking Hugging Face kickstarted something of a battle between it and rival Anthropic over whose agents could take the most liberties with their security. Both companies have reported several instances of their agents going rogue, escaping "secure" environments and going walkies across the internet to attack unwitting organizations. OpenAI has been circumspect about the true scale of its rogue agents’ damage, as third-party reporting showed more websites than it was letting on were taken over. Similarly, Anthropic has said that its AI agents had, in four cases now, accessed third-party systems in attacks that, if carried out by a human, could see them convicted under computer laws. ®
Categories: News

Ministry of Justice apologizes after court staff accessed Southport victims' files

The Register - 8 hours 21 min ago
The Ministry of Justice (MoJ) has apologized after court staff accessed documents relating to victims and survivors of the 2024 Southport murders without authorization. For a limited number of people, the material accessed included sensitive personal data assessed as likely to pose a high risk to their rights and freedoms. There is no evidence that the information was shared with third parties. "We are appalled that this happened and recognise the distress it will have caused victims, survivors, and their families," an MoJ spokesperson said. "We apologise to those affected – unauthorized access to court files is completely unacceptable. "This is now being investigated urgently, and the prime minister has asked the Lord Chancellor to oversee this. "All wrongdoing will be met with extremely firm action." The Register asked the MoJ how many staff accessed the files, whether they remained employed, and what their reasons may have been. It did not address those questions. Those affected include members of victims' and survivors' families, all of whom are being contacted directly. The MoJ did not disclose how many people were involved. HM Prison and Probation Service and HM Courts and Tribunals Service are investigating the matter. The Information Commissioner's Office has also been informed. The MoJ breach is the latest in a series of incidents involving inappropriate access to sensitive records connected to the attack. Separately, North West Ambulance Service investigated potentially inappropriate access by some of its staff to records of patients in the Southport attacks. And nearly 50 staff were found to have inappropriately accessed the medical records of some victims treated at Aintree University Hospital, near the place of Axel Rudakubana's attacks. Rudakubana, who was 17 at the time and has since been admitted to a psychiatric hospital, attacked a Taylor Swift-themed dance class in Southport, England, on July 29, 2024, killing three children and injuring eight other children and two adults. False claims about the attack online prompted violent, racially charged riots across the UK. Police made 1,511 arrests in the weeks that followed and brought 960 charges. Rudakubana was sentenced to life imprisonment with a minimum term of 52 years. ®
Categories: News

Mythos has made 2026 patching hell. It might make 2027 a breeze

The Register - 13 hours 9 min ago
When Microsoft delivered over 970 patches last week, many saw a nightmare for beleaguered security staff. Gartner research vice president Craig Lawson thinks infosec workers might soon see sunlit uplands as their workloads ease. Lawson outlined that scenario at Gartner’s IT Symposium in Australia today and explained it by theorising that the increased volume of vulnerability discoveries made possible by Anthropic’s Mythos and other bug-hunting AI might be getting close to finding most of the flaws in established codebases. “We've never had a situation where massive codebases have been audited to that level before,” he told The Register, and offered the recent series of CVEs found in OpenBSD – which has historically been an unusually secure and stable OS – as evidence that AI bug-hunters are cleaning up. “Think about how much technical debt has been retired in products just in the last six months,” he said. Lawson pointed to the fact security vendors, who in theory know what it takes to create secure products, are also using AI to find flaws in their wares. Those discoveries, he suggested, again indicate AI is taking out potential avenues for zero-day attacks. The high number of CVEs reported in 2026 is a positive signal. Lawson thinks Mythos and its ilk may also create an invisible signal as vendors use the AI to detect more bugs in their future releases. He therefore thinks that 2027 might see CVE numbers fall as vendors finish cleaning up old codebases, and because they use AI to more thoroughly test their next releases. “2027 could be the first year we see a net drop, maybe not in aggregate vulnerabilities, but definitely in severity of flaws,” he told The Register. He thinks AI will also make defenders happy by giving them better tools. Today, he said, a red-teaming exercise is an infrequent and costly event that usually involves hiring an external provider. AI bug-hunters could mean organizations can effectively run a red team every day. And if a red team exercise produces tickets that need solving, he thinks AI will help analysts to identify fixes more quickly. “What if I could spend three minutes going to Gemini and saying ‘Write syntax for an F5 IRule’ that becomes a virtual patch? Everyone can do threat intelligence, enrichment, some of those harder tasks.” When infosec staff make those fixes, Lawson wants organizations to celebrate the impact of their work. Today, Lawson said, security operations centers measure staff by the number of tickets they process and close. He thinks a better approach is to celebrate the fact that cyber-defenders kept a hospital open or stopped a ransomware raid. ®
Categories: News

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

The Register - Tue, 15/09/2026 - 22:38
Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino's history. While this CVE count is hardly notable compared to some vendors - hello, Microsoft’s record-breaking 974 bugs disclosed earlier this month - it does set a company record for Apple. It also reflects the new reality of AI-driven bug hunting, as models become exponentially better and faster at finding security vulnerabilities. However, the flip side of the AI coin we were promised - that models would also excel at writing patches and automatically fixing software and systems - yeah, that hasn't happened yet. The silver lining for everyone updating their Apple products right now (including this humble vulture): none of the vulnerabilities are listed as being under active exploitation. Of course, that may change very quickly as attackers are, at this very moment, looking to exploit the newly disclosed bugs, too. And we promise you that they are using AI. Apple’s latest mobile and operating system versions, iOS 27 and macOS 27 Golden Gate, released on Monday, also address a record 122 and 204 security vulnerabilities, respectively, across phone, iPad, and computer operating systems. Of these hundreds of CVEs, however, there are only ten (by our count) that AI is directly credited with finding. iOS 27 fixes 122 flaws Just two of the iPhone and iPad CVEs fixed with iOS 27 credit a coding agent or AI assistant with finding them. These include CVE-2026-65410, a vuln that exists in iPhone and iPad AVE video encoders, that can cause unexpected system termination. Apple credited AI-bug-finding firm Calif, along with Claude and Anthropic Research, with finding and reporting this security flaw. Then there's CVE-2026-65409, a type-confusion issue in iOS’ Foundation framework that can be abused to cause a denial of service, also found by Calif - specifically human researcher Bruce Dang - in collaboration with Claude and Anthropic Research. Some of the more interesting and serious iOS bugs fixed with the newest update aren’t listed as found by AI. These include CVE-2026-43689, a privilege-escalation flaw that could allow an app to gain root access. Apple credited Nosebeard Labs’ Andreas Jaegersberger and Ro Achterberg with reporting this bug. Additionally, CVE-2026-65406, a logic-issue flaw due to improper validation in Background Assets, could be abused to access sensitive user data. Background Assets is an Apple framework that lets you download large files and content in the background before a user opens the app for the first time. Baidu Security researcher Ye Zhang spotted this one. macOS 27 patches 204 vulns Meanwhile, the new macOS 27 update that addresses 204 vulns also fixes both the AI hunted bugs: CVE-2026-65410 and CVE-2026-65409. Plus, it credits AI helpers with discovering eight others, including one especially nasty flaw that could lead to remote code execution through the CUPS printer interface. Let’s start with that one. CVE-2026-43692 is a validation issue in CUPS that can be exploited by a remote user to either terminate the app or execute malicious code. Aaron Grattafiori and the Nvidia AI Red Team receive credit for disclosing this flaw. CVE-2026-64790 in CUPS can be exploited to gain elevated privileges. Grattafiori and the Nvidia AI Red Team again get credit for the win. CVE-2026-43791, a validation issue in StorageKit, can be abused to read files. Grattafiori, the Nvidia AI Red Team, Meridian Miftari, and Amy from amys.website disclosed this flaw to Apple. CVE-2026-43690 is a race-condition bug in the Server Message Block (SMB) network communication protocol. A local user can exploit the flaw to read kernel memory. Calif’s Bruce Dang, with Claude and Anthropic Research, found this one. CVE-2026-43719 is another SMB use-after-free bug, discovered by Calif’s Dang and Jakob Pammer, Claude, and Anthropic. “Mounting a maliciously crafted SMB network share may lead to system termination,” Apple warned. CVE-2026-65376 is yet another SMB issue - this one an out-of-bounds-read flaw reported by Dang, Claude, Anthropic, and 재영 정. CVE-2026-65374 is a memory-corruption issue in the WebDAV protocol that can lead to code execution. Dang, Claude, Anthropic, and He Wei (ギカク) receive credit for finding this bug. CVE-2026-65375, also in WebDAV, can cause unexpected system termination. Apple credited Dang, Claude, Anthropic, and Devcore Research Team’s YingMuo. CVE-2026-43677 is an out-of-bounds write issue in WebDAV with a slew of researchers receiving credit for finding it. In addition to the usual trio (Dang, Claude, and Anthropic), bubu, Omar Cerrito, HE WEI(ギカク), Roman Zabicki, Richard Zana, Chris Bailey - Short Circuit, Aswin Kumar Gokulakannan, and Surya Narayan Kushwaha are on the list.®
Categories: News

Low-quality casino sites conceal highly dangerous threat actors

The Register - Tue, 15/09/2026 - 20:38
If your employees are visiting Chinese-language gambling or adult sites, they may not just be wasting time and money, but potentially encountering serious malware hidden behind domains that look like mostly harmless entertainment at first glance. A report from Infoblox urges the security community to pay closer attention to these websites, because some double as command-and-control (C2) infrastructure for espionage and malware distribution. Zach Edwards, staff threat researcher at Infoblox, suggests security researchers and the media have ignored these sites because the story is complicated and confusing. Infoblox says it tracks about 1.7 million Chinese-language casino websites that facilitate illegal gambling. These support North Korean money laundering and tax avoidance, among other dubious activities. And these casino sites can be difficult to distinguish from one another. They tend to use variations of common templates in terms of design and function. Many operate like a legal casino would, just relying on the advantage of house odds to profit. While these sites provide illegal gambling and adult entertainment for online visitors from China and Asia, some rely on US cloud providers for computing infrastructure. "Major US hosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host infrastructure associated with these domains," the Infoblox report explains. "One likely explanation is account theft at those providers, a practice documented previously as 'infrastructure laundering.'" That refers to hosting companies like Funnull that have reportedly rented IP addresses from Amazon Web Services and Microsoft and made those resources available to clients carrying out illegal activities. According to a July 2026 report from the UN Office on Drugs and Crime (UNODC), disparate crime syndicates increasingly use common infrastructure for cybercrime, while online scams resulted in estimated losses of between $88.3 billion and $114.1 billion in 2025 across East Asia, Southeast Asia, Australia, and New Zealand. A subset of casino sites offer scam gambling, or "scambling." Visitors place bets but can't get their money out if they win. And then there's a subset of sites used by China-aligned threat groups. "China-aligned APT groups have been running the PeckBirdy framework since 2023, hiding their malware C2 domains inside low-quality Chinese-language casino websites," Infoblox said. PeckBirdy, as noted by Trend Micro researchers in January, is a script-based framework that attackers can load through compromised websites. In one campaign, attackers injected scripts into gambling sites that loaded PeckBirdy and displayed fake software update pages designed to entice victims to download malware. The problem is that each of these three types of sites, though they change frequently, looks similar. Infoblox notes that just over 3 percent of its enterprise customers resolved at least one PeckBirdy C2 domain. "The most important thing for defenders to do is stop ignoring casino domains," Infoblox argues. "An alert on a Chinese-language casino or adult domain that gets closed as an employee browsing violation is precisely the outcome the PeckBirdy operators are counting on. The decoy works because the dismissal is reasonable – these domains genuinely are, most of the time, exactly what they appear to be." Security analysts who review suspicious network contacts are advised to check whether these casino domains include malicious payloads before closing the review ticket. ®
Categories: News

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

The Register - Tue, 15/09/2026 - 19:01
Iranian state cyber actors are targeting individuals using social messaging apps to deploy surveillance and data-stealing malware on their Windows machines, three Western governments warned. In all observed cases, Chosen Brick has infected Windows systems exclusively. Iran has used it since at least 2025 to take over individuals’ devices, stealing their contacts, emails, and social media messages, which allows the spies to track people’s movements, the FBI, UK National Cyber Security Centre, and the Netherlands’ General Intelligence and Security Service (AIVD) said on Tuesday. “Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists,” the security advisory said. “In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.” These attacks typically begin with WhatsApp and Telegram messages, purportedly coming from individuals and organizations that the victim knows and trusts. The Iranian spies do a significant amount of research to prepare for these social engineering campaigns. By the time they send the initial message via a social media app, they have “extensive” knowledge of the targeted individual, their contacts, and relevant industry organizations to make the phony messages more believable, according to the agencies. After building rapport with the mark, the attackers convince them to download and open a file that appears to be a legitimate application. Specifically: Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass are among the legitimate applications the malicious files have been made to resemble, the government agencies said. Upon opening the file, the malware executes without the victim’s knowledge, and will survive a reboot of the target device. Chosen Brick also adds exclusions to Microsoft Defender antivirus in an attempt to evade detection, and then connects to Telegram for command-and-control (C2) communications using a victim-specific Telegram bot. While the malware hasn’t yet been observed to automate lateral movement across the network, this is “technically possible,” the advisory noted. It does, however, download additional malware and set up persistence for new payloads on infected devices, using the same registry key that Chosen Brick uses to establish its own persistence on a Windows device: HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Other features include enumerating running processes and system information, capturing screen and audio content, stealing emails, along with Telegram and WhatsApp data from web browsers, and wiping the computer system. “Organizations that are concerned Chosen Brick has been executed should contact their IT providers, either internal or external, to investigate,” the US, UK, and the Netherlands warned. “As this actor targets personal devices, not just corporate devices, organizations are recommended to circulate this with their staff that are likely to be targeted and support them in checking their personal devices too.” The Western agencies’ latest Iran alert follows a series of water and energy cyberattacks that researchers and media reports have linked to Iran, although the US and UK governments have stopped short of formally attributing them, as the military conflict between Iran and the US approaches its seventh month. In August, America’s lead cybersecurity agency, CISA, disclosed that the July cyberattacks that disrupted American water utilities across 12 states targeted more than 100 internet-exposed water systems. CISA did not, however, attribute the campaign to Iran or anyone else. Around the same time, a suspected Iran-linked cyberattack also shut down a small UK power plant. Also in August, five US agencies warned that attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities. “This is not a theoretical risk – it is an active threat,” the feds warned. ®
Categories: News

Cisco email security boxes can be rooted by... an email

The Register - Tue, 15/09/2026 - 17:01
Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix. The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root. Which is not exactly what you want from the box tasked with keeping nasty emails out. Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant hasn't said who is behind the attacks, how long they have been going on, or how many organizations have been compromised. Cisco uncovered the bug while resolving a Technical Assistance Center support case. Signs suggest at least some Cisco cloud customers were caught up in the attacks. Cisco said it investigated devices belonging to its Secure Email Cloud service and directly contacted customers whose appliances showed indicators of possible compromise. It is now carrying out remediation and recovery work and says all of its Secure Email Cloud devices have been upgraded to AsyncOS 16.5.0-780. Admins running their own appliances have a little more work to do. Cisco recommends checking logs for signs of suspicious activity, but warns that finding nothing doesn't necessarily mean the system is clean. Once attackers have root access, Cisco says they could tamper with the logs and cover their tracks. Admins are also being told to check network and firewall logs for anything unusual, rather than relying on the gateway itself for answers. For virtual appliances suspected of being compromised, Cisco's recovery advice is fairly drastic: preserve the forensic evidence, deploy a fresh VM running fixed software, rebuild the configuration, and rotate credentials and cryptographic material. Cisco has fixed the bug in AsyncOS releases 15.5.5-014, 16.0.4-302 and 16.5.0-780, with customers strongly encouraged to move to the latter. There's still a decent-sized target pool out there. The Shadowserver Foundation was tracking more than 400 Cisco Secure Email Gateway appliances exposed to the internet as of Monday The flaw has also landed in CISA's Known Exploited Vulnerabilities catalog, with US federal civilian agencies ordered to remediate it by September 17. CVE-2026-76461 comes less than a year after attackers exploited another critical AsyncOS flaw, CVE-2025-20393, to break into Cisco Secure Email Gateway appliances and install persistence mechanisms. That bug eventually scored a perfect 10. For anyone still running an affected gateway, the message is fairly simple: the box designed to inspect hostile email can itself be pwned by one; attackers are already doing it, and there is no workaround to hide behind. ®
Categories: News

Who's governing your AI? A trust framework for enterprise agents and models

The Register - Tue, 15/09/2026 - 16:00
Experienced IT leaders know that shadow IT is a persistent problem, but rapidly evolving AI and the proliferation of agents mean the potential threat - and cost - is greater than ever. AI agents are non-deterministic, autonomous, and adaptable. They excel at solving tasks in creative ways, often to the surprise of their creators. We've seen agents write blogs that criticize project maintainers that refused their pull requests. Another one hacked a McKinsey chatbot to gain read/write access without asking for permission. And agents are getting smarter all the time. As an industry veteran, DigiCert's senior vice president of product Brian Trzupek sees an old pattern. "When the promise of the technology is so good, people are willing to throw security out the window, and they just want to get to that promise real fast." CISOs should be worried about allowing these agents into their infrastructure without strict controls, but it's happening anyway. IBM's 2026 Cost of a Data Breach report found that more organizations lacked governance to manage AI or detect shadow AI, at 68 percent compared to 63 percent last year. The number requiring IT approval to deploy AI had fallen to 38 percent from 45 percent. DigiCert is trying to solve this problem with its own approach to AI governance called AI Trust. The framework, outlined in this white paper, builds on what the company is good at: public key infrastructure, DNS, and attestation. The AI governance questions CISOs should ask AI Trust uses these tools to help organizations answer five AI governance questions: · What agents your employees are using · What regulated data is flowing to them · Whose credentials they hold · Whether a compromised agent can be stopped immediately · Whether an incident can be reconstructed with a tamper-evident trail Almost every enterprise fails at the first hurdle, warns Trzupek. Developers build agents or buy them from vendors and deploy them internally without asking. Users might also spawn agents from inside tools like Claude Desktop or OpenAI Codex that will then create sub-agents. "Those sub-agents don't assume the same rights and responsibilities and authorization as the parent agent," he says. "So they try to delegate tasks that can be wholly controlled." How to manage AI agent identity Most companies haven't developed the tools to keep track of all these different agent types yet. The first step is to identify them. This is where many organizations make their first mistake by bolting agents onto the human identity and access management (IAM) stack they already have. The idea is that if you give an agent a service account and a long-lived API key you can treat them like a super-fast employee. That's impractical. "IAM was built for a human sitting at a keyboard who can tap 'approve' on their phone," Trzupek says. "An agent can't do that. So you fall back to a static API key that never expires and has way more scope than it needs, and now you've undone everything zero trust was supposed to give you. It's the exact credential we've spent a decade telling people to get rid of." Industry bodies have started converging on a different answer. IDC now recommends treating agent identity as a workload identity problem rather than an extension of human IAM, aligning with the IETF's Workload Identity Management and Security Extensions (WIMSE) and NIST's Cybersecurity Framework version 2.0. They can then frame agents as governed workloads requiring runtime attestation and short-lived credentials . This idea also pushes teams toward the Service Profile Identity (SPIFFE) and its SPIFFE Registration Endpoint (SPIRE). This is an open workload identity standard already deployed inside many hyperscaler-hosted Kubernetes estates, and they're part of DigiCert's AI strategy. DNS is a governance tool for agentic AI Inventory and identity might get you visibility, but you still need somewhere to enforce policy. DigiCert has strong opinions about where, tied to its history managing DNS integrity. No matter whether an agent is resolving an API endpoint or connecting to an MCP server, it has to query DNS first. So why not make that a core verification point? DigiCert proposes a solution that looks a lot like the DMARC standard used for email. An organization would publish an agent policy record in DNS that declares several things: · Its authorized agent identities · The certificate authority that issued their credentials · The scopes they're allowed to act within A gateway can then query that record to verify whether an inbound agent is legit, and terminate the session if the check fails . And if an agent contacts an unauthorized domain mid-execution, DNS can block the query and the MCP gateway kills the session. IDC likes this idea but warns that scale is an issue. As the number of agents grows, DNS records might not keep up, and stale records might become a loophole. Overly permissive scope declarations are also still a potential problem. "The scale problem is real, but it's the same problem DNS has solved a hundred times before," Trzupek responds. "You automate the lifecycle, you tie the record to the certificate issuance, and when the cert expires the record goes with it." And operators writing wildcard scopes because they're in a hurry is a discipline problem, not an architecture problem, he adds. Inside DigiCert's AI Passport Agents built in-house live alongside third-party agents like Microsoft Copilot, Salesforce Agentforce and ServiceNow, and the control planes for the two categories are different. DigiCert's answer is a single SPIRE server anchored to a DigiCert CA for identity, with policy enforced centrally in an Open Policy Agent engine, and a unified kill switch that operates across both categories. The AI Agent Passport is the artifact that ties the identity to the authorization. It's a cryptographically protected record of approved systems and permitted operations. Each 'passport' also contains things like data sensitivity classifications and expiration state, along with an accountable human owner. Trzupek says the field that generates the most pushback in the design is policy itself, because customers typically have a complex web of policies already in GCP or AWS. "Trying to replace those or displace them is a fool's errand," he says. So the passport can hold pointers to those engines rather than replacing them. How to manage model integrity Governing agents is only half of the challenge. The models themselves are strategic assets, and they're subject to integrity and provenance controls too. That means encryption and cryptographic signing of model artifacts, Open Container Initiative-compliant packaging with tools like the Sigstore code signing initiative, and a cryptographically verifiable Model bill of materials describing weights, datasets and dependencies . It also means governing models at runtime, not just securing the supply chain. DigiCert's AI Trust framework advocates trusted hardware execution to help solve that problem. A model running inside a trusted execution environment on Intel TDX or AMD SEV-SNP stays encrypted in memory, isolated from the host OS. DigiCert operates a confidential computing attestation service that follows the IETF Remote ATtestation Procedures (RATS) architecture. The execution environment is the attester and DigiCert is the verifier. Downstream systems are the relying parties. This approach moves attestation from a neutral third party rather than the cloud operator running the workload, which serves regulated buyers. Hyperscalers shouldn't attest to their own integrity. Those regulated buyers face some heavy governance conversations. In healthcare, the question is whether the AI model cleared through an FDA 510(k) pathway is the exact algorithm running in clinical deployment. Cryptographic attestation lets these companies prove model integrity before every inference. That addresses the FDA's 2023 cybersecurity guidance on software integrity verification and SBOM enforcement. But while some regulated verticals have specific needs, AI governance is a cross-sector problem. Any organization storing customer data an agent can access or exfiltrate needs these controls. Why build in AI governance now This is agentic AI's moment, so companies are at a pivot point, and they've been here before. Many of them spent the last 25 years following a cybersecurity antipattern: move fast to grab an opportunity with a significant new technology development, and call in the security team later to clean up the loose ends. It hasn't gone well. With many organizations at the beginning of their agentic AI journey, they now have an opportunity to break that habit and do things right from the beginning using verifiable controls. As frontier model prices climb and AI crops up as a noticeable cost on enterprise budgets, this will become an increasingly visible choice, concludes Trzupek. Companies will hold people more accountable for their use of agentic technology. Wouldn't it be nice to have the controls in place and be ahead of the game for once? Sponsored by DigiCert
Categories: News

Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler

The Register - Tue, 15/09/2026 - 14:32
A Swiss court has sentenced a 52-year-old Ukrainian ransomware developer to 12 years and nine months in prison for his role in attacks on companies including Stadler Rail. Zurich District Court found that the man developed LockerGoga, MegaCortex, and Nefilim, but was not the mastermind behind the operations. He also received a ten-year ban from Switzerland. The judgment is not final and can be appealed. He had been held in pretrial detention since October 2021 and consistently denied knowing that his software was being used for criminal purposes. He said the source code found at his home in Basel-Landschaft came from his consulting work for an unidentified IT security client. The court rejected that explanation because extortion messages were also found among his data, SWI reported. The ransomware developer was also found guilty of playing a key role in high-profile ransomware attacks, including the one that hit Stadler Rail in 2020 [PDF]. Not to be confused with the more recent attack on the rolling stock manufacturer – that one was claimed by Everest – the earlier breach occurred in May 2020. At the time, Stadler Rail did not use the word "ransomware," but said the attack involved malware, that it "most likely led to a data leak," and that "the offenders tried to extort a large amount of money," threatening to leak the files if the ransom was not paid. As it did following this year's incident, Stadler refused to pay. The 2020 Nefilim ransom demand was reportedly $6 million. The court also found that he played a key role in attacks on HVAC company Meier Tobler and software company Crealogix. In September 2022, Zurich prosecutors reported that a suspect had been arrested in Basel-Landschaft in October 2021 on suspicion of money laundering and data corruption. The statement accused the perpetrators of involvement in attacks on more than 1,800 individuals and institutions across 71 countries, causing estimated losses of several hundred million Swiss francs. The same law enforcement action in 2021 led to the identification of other alleged members of the three ransomware operations, none of whom were named. Volodymyr Tymoshchuk was formally indicted in the US last year and was described by prosecutors as the mastermind of all three ransomware crews. Unlike many others, Tymoshchuk has not yet been arrested, but is on the FBI's most wanted list, with an $11 million bounty placed on the information that could lead to his arrest or conviction, or that of other key leaders. He was allegedly responsible for attacks on at least 250 companies, including the infamous Norsk Hydro attack in 2019. ®
Categories: News

The latest AI doomsayer is China’s intelligence boss

The Register - Tue, 15/09/2026 - 05:56
China’s minister for State Security has decided AI might be bad for the nation’s ruling Communist Party. Party secretary and minister Chen Yixin’s views appeared in China Cyberspace Magazine, the flagship publication of China’s Cyberspace Administration (and which readers may recall once carried a piece by Elon Musk). In Chen’s view, “the field of AI has become the main battleground for global technological competition and a new arena for strategic rivalry among major powers.” His article also recites familiar grievances about US sanctions and the possibility AI could be weaponized to detect and exploit software vulnerabilities and then to attack important infrastructure, or to steal industrial and state secrets. OpenClaw and similar products also worry the minister, who thinks such software has “structural problems such as remote control of device management permissions and leakage of sensitive user information.” China may also have a PEBCAK* problem because Chen thinks “Some domestic users lack sufficient security awareness, using foreign AI products to process sensitive information and export data overseas, resulting in large-scale data leaks from within the country.” The minister is also worried about how AI challenges China’s Communist Party. “The application of artificial intelligence brings a large number of uncertainties to social governance and public order,” he observed. “The ‘black box’ of algorithms and the ‘poisoning’ of data may amplify existing social biases. The abuse of personal information during data use may trigger a crisis of user trust. The automatic decision-making of the system creates problems in attribution of responsibility.” He’s also worried that “rapid development of artificial intelligence has broken through the traditional technology governance framework, causing existing legal norms, ethical principles and governance mechanisms to frequently lag behind in practice, making it difficult to form an effective institutional constraint and supervision system.” Chen’s suggested response is for China to adhere to the words of President Xi Jinping and modernize China’s national security system and capabilities, so they are ready for AI. The minister says China must “ensure the independent control of key core technologies, firmly grasp technological sovereignty, and achieve a virtuous cycle and synergistic progress between innovation empowerment and security governance.” That stance rather suggests Nvidia isn't going to get back into China anytime soon, and AMD can probably write off its prospects of selling many GPUs there too. Chen also wants “special laws and regulations targeting the research, development, application, and supervision of artificial intelligence technology,” plus improvements to standards and laws “covering the entire chain of technology research and development, application implementation, risk prevention and control, and accountability, focusing on prominent issues such as algorithm security, data protection, ethical norms, and privacy rights.” The day after Chen’s article appeared, the Cyberspace Administration of China published version 3.0 of the nation’s AI Safety Governance Framework. That document calls for China to “actively employ risk-controllable institutional mechanisms such as regulatory sandboxes to make room for error and correction in the development of new technologies and new applications.” China also plans to “make every effort to ensure AI safety” and to “take timely measures to address any risks that infringe upon the legitimate rights and interests of individuals, harm public interests, threaten national security, and endanger human survival and development.” That’s quite the contrast compared to the position taken by US president Donald Trump, who on Monday labeled concerns about AI safety a “hoax” and suggested “The only control or ‘guardrails’ that AI needs is a STRONG AND SMART (High IQ!) PRESIDENT, and the U.S.A. has that, in spades!” ® * Problem Exists Between Chair And Keyboard
Categories: News

HBO Max Reddit account compromised to serve ClickFix attacks

The Register - Mon, 14/09/2026 - 23:43
Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author — this is the verified HBO Max account — and advertised a macOS app for HBO Max. The streaming service does not offer a native client for the Mac. Anyone who clicked on the malicious ad would then be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button. Clicking the button produced instructions telling the user to copy and paste a command into Terminal on macOS. The Reddit security sleuth described that as “the classic infostealer/clickfix paste this command to download,” noting that they tested all of this in a sandboxed environment, and didn’t actually run the executable on their machine. “My guess is that the Reddit account is compromised,” they concluded. Three days later, Reddit paused the infostealer-dropping ads, and an admin said the social media platform’s safety and security teams were investigating what happened. HBO Max’s parent company Warner Bros. Discovery didn’t immediately respond to The Register’s inquiries about the account takeover - including who hijacked the streaming service’s Reddit account and how they did it. Maybe someone who didn’t like the House of the Dragon season 3 finale? We will update this story if and when we hear back. Researchers at Hudson Rock and ADAMnetworks analyzed the ads, and in a couple of reports said the HBO Max account hijacking was part of a “massive 48-hour malvertising blitz” that pushed 108 distinct ads using multiple software lures. They named the campaign PasteSwitch, and said it serves up targeted malware aimed at victims’ operating system - either macOS or Windows. The payloads include infostealers, malware loaders, cryptocurrency clippers, and fake cryptocurrency wallet applications. The cryptocurrency clippers - PasteSwitch delivers either AnimateClipper or ZigClipper - also provide blockchain-based command-and-control fallbacks for the attackers. They use Binance Smart Chain (BSC) contracts to dynamically fetch whatever C2 domain the crooks are using at any given time. “Between March and July 2026, researchers observed 36 mainnet changes executed by the same attacker controller address,” Hudson Rock said. “Because the C2 domain is hosted directly on the blockchain, the infrastructure demonstrates dynamic resilience, allowing the threat actors to easily rotate burned domains.” In addition to HBO Max, the attackers used developer-tool, disk-cleaner, and AI-themed lures, including fake OpenAI Codex ads, which crims have previously used to push Mac malware. Of the 108 ads, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). “The campaign proves once again why trusted distribution channels are becoming prime targets for infostealer delivery,” Hudson Rock co-founder and CTO Alon Gal said in a LinkedIn post. It also shows that miscreants continue to make heavy use of ClickFix attacks, so there’s little sign this social engineering method is going away anytime soon.®
Categories: News

New hardware device can RAM into encrypted memory, expose your data

The Register - Mon, 14/09/2026 - 19:31
Computer security researchers have identified a design flaw in modern encryption hardware that allows access to protected memory in notionally confidential computing environments. But the attacker would need physical access to the victim system. Boffins affiliated with KU Leuven, ETH Zurich, Durham University, and Google have found that scalable memory encryption hardware fails to check whether the data in memory is fresh. As a result, they've been able to devise a small hardware interposer, dubbed DDRop, that when wired to an appropriate circuit board, interferes with DDR5 write operations. Unable to tell that memory isn't fresh, a protected VM becomes vulnerable to a replay attack that uses stale, attacker-selected data. They describe their work in a paper titled, "DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes." Their attack requires physical access and so it is relevant mainly in scenarios where confidential computing guarantees have been made to tenants by cloud service providers. "DDRop uses a custom-built 'interposer': a small, custom-designed circuit board, costing under $200, that sits between the processor and a memory module," explained Jo Van Bulck, a professor in the DistriNet lab at KU Leuven, Belgium, in an email to The Register. "It corrupts commands on the high-speed DDR5 memory bus to silently drop writes to encrypted memory. The protected VM keeps computing on old data that still decrypts perfectly. We are releasing the complete interposer design as open-source hardware." The attack breaks the integrity of Intel TDX, Scalable SGX, and AMD SEV-SNP, used in trusted execution environments (TEEs). Van Bulck and colleagues Jesse De Meulemeester, Stefan Gloor, Patrick Jattke, Daniel Moghimi, David Oswald, Martin Thompson, Kaveh Razavi, and Ingrid Verbauwhede developed a proof-of-concept attack on a current Intel TDX server. "By injecting maliciously crafted secure page-table entries, we can force any protected VM into debug mode and read out its private memory in plaintext," said Van Bulck. "Furthermore, writing to critical TDX metadata structures enables forged attestation reports, so that a backdoored VM appears trusted to the remote user." Both attacks, said Van Bulck, succeed deterministically in under two minutes without crashing the machine. Several of these researchers developed a similar attack on DDR4. But Van Bulck said this is the first active interposer attack on DDR5. "DDR5’s redesigned command bus prevents the address-aliasing tricks used by Battering RAM, and until now, only considerably weaker passive attacks had been demonstrated on DDR5: TEE.fail monitors the data bus using bulky, second-hand logic analyzers that are easier to detect and require slowing the memory bus to its lowest speed to observe ciphertext patterns, which can be masked in software," he explained. DDRop differs in that it alters DDR5 bus traffic at full speed. According to Van Bulck, it's the first attack to subvert TDX's trusted management interface without exploiting a software bug. It also reduces the cost of prior interposition attacks that took an estimated $170,000 in lab equipment to perform. There's no easy fix for Intel's and AMD's current scalable memory-encryption designs, said Van Bulck, and no simple software or hardware patch that can address the root cause. "Scalable memory encryption deliberately trades cryptographic freshness (e.g., available in early Intel SGX offerings supporting only 128/256 MB of protected memory) for the ability to protect large amounts of memory in cloud systems," he said. Noting that Intel's Simon Johnson recently discussed memory-interposer attacks at an industry conference, Van Bulck said that planned mitigations like "cache line versioning" still appear to be vulnerable to DDRop. In a security bulletin released on Monday, Intel acknowledged the DDRop disclosure and said the attack is out of scope for its cloud computing threat model. The company said it is "evaluating additional architectural hardening options and detection mechanisms as part of ongoing platform security improvements…" AMD also said the attack is out of scope and no mitigation is planned. ®
Categories: News

OpenAI's malicious bot swarm attacked RubyGems

The Register - Mon, 14/09/2026 - 19:03
OpenAI agents appear to have flooded RubyGems with malicious packages, adding to a near-daily deluge of rogue AI models engaging in potentially unlawful activity while their human creators face growing questions over responsibility for their agents’ bad behavior. A swarm of agents began uploading malware to the Ruby package registry on May 5, and flooded RubyGems with more than 2,000 malicious packages between May 11 and May 12, ultimately forcing maintainers to disable new user registration for four days. “We believe these were authored by internal OpenAI agents,” researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said on Friday. An OpenAI spokesperson confirmed that the model maker is investigating the incident. “Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information," the spokesperson said. "We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.” This same trio of researchers earlier this month said that they found evidence that OpenAI’s swarm hijacked a German wiki months before the AI agents attacked Hugging Face. As they did during the German wiki incident, the agents involved in the RubyGems abuse self-identified as being from OpenAI. Hundreds of the gems included “oai” in their name, and 15 set “oai” as their author. At least one other used “openaixyz65947@gmail.com” as the email address for contact. Also according to the researchers, more than 100 of the malicious packages followed the same exploitation path, submitting a malicious package to the public library and triggering a documentation request to force RubyDoc.info to build the package. OpenAI’s agents then used the build script to run code on RubyDoc.info, scrape targeted websites, and steal data from the documentation server by publishing another gem to the public Ruby language package registry, the researchers said. “Additionally, once the AIs got arbitrary RCE on the build environment, they would sometimes use the build environment to attempt to steal other users’ API keys (though we are unsure if they succeeded or not),” they wrote. The agentic swarm also found and attempted to exploit a zero-day CDN caching bug on May 12 that wasn’t discovered by maintainers until July. The vulnerability would have allowed the AIs to steal users’ API keys. At least six of the malicious packages, including one named slnleaker5, used this security hole, the researchers said. Most of the agentic activity happened in May. After the RubyGems team added security measures such as requiring verified emails for new signups, OpenAI’s agents resumed their efforts on June 18 and published 83 gems over three hours. While the researchers note that they don’t know whether the swarm used a shared message board to communicate, as agents did during the Hugging Face intrusions, they “suspect” the bots were coordinating and likely had some way to exchange information. The researchers also said that it’s “unclear” if or when OpenAI learned that its agents were using RubyGems to scrape publicly available data. “It seems that either their monitors failed to catch it or they did not disclose it,” the trio wrote. This seems to be the case with other recent agentic hacks traced back to OpenAI’s models going rogue during training exercises. To be fair, Anthropic’s bots have also gained unauthorized access to third-party systems over the past few months without being caught at the time by their human supervisors. In light of the increasingly apocalyptic warnings around AI - or perhaps in a self-serving attempt at regulatory capture - several of the industry’s biggest bosses over the weekend backed a collective slowdown of AI training and development, after Anthropic CEO Dario Amodei warned that future agents could become “capable of taking over the entire internet with a persistent botnet.” Meanwhile, President Trump said on Truth Social, "the only control or 'guardrails' that AI needs is a strong and smart (high IQ!) president," and claimed his administration has stopped "AI 'people' from doing bad, or potentially bad, 'things.'"® Editor's note: This story was amended post-publication with comment from OpenAI.
Categories: News

Perfect-10 GitLab bug under attack days after patch lands

The Register - Mon, 14/09/2026 - 15:30
CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files from vulnerable servers after the code shack released fixes on September 10. The US Cybersecurity and Infrastructure Security Agency has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog. The vulnerability is a path traversal bug in the repository commits API affecting GitLab Community Edition and Enterprise Edition. GitLab rates it a perfect 10.0, the maximum score on the CVSS v3.1 severity scale. Under certain conditions, an attacker doesn't need to log in before abusing the flaw to read arbitrary files from the GitLab server. GitLab blamed the problem on improper path confinement combined with missing authentication enforcement in the affected API. That's not an especially comforting combination on a platform that can be stuffed with source code, configuration files, and credentials. GitLab shipped fixes on September 10 in versions 19.3.2, 19.2.6 and 19.1.8, and urged operators of affected self-managed installations to upgrade immediately. The bug affects versions from 18.7 before 19.1.8, the 19.2 branch before 19.2.6, and 19.3 before 19.3.2. GitLab.com is already patched, while GitLab Dedicated customers don't need to take action. Security outfit watchTowr said over the weekend that it was observing probes for CVE-2026-85706 in the wild. The firm warned that widespread exploitation was likely to follow quickly. According to watchTowr, exploiting the flaw can be as simple as sending a single HTTP request, potentially allowing an attacker to get at local files, configuration data, credentials and other secrets. The firm advised organizations running internet-facing self-hosted GitLab instances to patch them or pull them from public access. Admins investigating potential exploitation attempts should check logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ containing file.path parameters, watchTowr said. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA said. "While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities." For exposed, unpatched installations, that upgrade belongs on today's to-do list. ®
Categories: News

UK.gov begins killing off passwords for 23 million users

The Register - Mon, 14/09/2026 - 10:16
The UK government is giving more than 23 million people the chance to ditch passwords for passkeys – and could save itself a tidy sum on authentication texts in the process. Passkeys are being rolled out more widely across GOV.UK One Login following a trial involving more than 300,000 users, allowing people to sign in using a fingerprint, Face ID, or device PIN instead of entering a password and waiting for a two-factor authentication (2FA) code. The government says nearly one in ten daily One Login sign-ins are already being made using passkeys, which it claims are up to eight times faster than logging in with a username, password and 2FA code. There is also a less glamorous incentive for Whitehall: text messages cost money. The switch is already saving taxpayers nearly £600 a day in SMS costs, according to the government. Passkeys are designed to resist phishing. Rather than relying on a password that can be stolen, reused, or handed over to a convincing fake login page, a passkey uses cryptographic credentials tied to the website or app for which it was created. The biometric data or PIN used to unlock it remains on the user's device and isn't seen or stored by GOV.UK One Login. "Cyber criminals often look for the easiest route to access important accounts, which means login details remain a common target," said Jonathon Ellison, director for national resilience at the UK's National Cyber Security Centre (NCSC). "But passkeys offer a highly phishing-resistant alternative to passwords, frustrating attackers and saving the public time." The NCSC is encouraging users to switch, although passwords aren't disappearing just yet. Passkeys remain optional, and anyone who would rather continue signing in the old-fashioned way can do so. GOV.UK One Login is intended to provide a single account for accessing government services rather than requiring users to navigate a collection of separate sign-in systems. It is already used for services including checking State Pension details, managing tax services, and accessing childcare support. Digital Government Minister Stephanie Peacock said the rollout was intended to make government services both easier to access and harder for fraudsters to exploit. "Nobody enjoys hunting for a forgotten password or waiting for a text message code just to check their tax return or renew a document," she said. Whether Britain's 23 million One Login users share Whitehall's enthusiasm for replacing passwords is unclear. But with passkeys already accounting for almost 10 percent of daily logins – and every authentication text adding to the government's phone bill – there are at least a couple of reasons to keep nudging them in that direction. ®
Categories: News

Security through obscurity is dead, and AI delivered the fatal blow

The Register - Sun, 13/09/2026 - 12:21
The term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency. Now it’s obsolete. Don’t believe us? Here’s proof. Software vendors and independent researchers alike are now using AI agents to find bugs – some very obscure and decades old – across products and open source code, leading to record-breaking numbers of security disclosures and patches, and a massive backlog for project maintainers. “You see open source platforms that have been visible to the tech community for a decade, these libraries that are run in 80 percent of web servers out there, people have stress-tested those for 10 years, and the community believed that they were really secure,” Brett Leatherman, assistant director of the FBI's Cyber Division, told The Register. “The latest models were able to break those and say, ‘yeah, there’s significant vulnerabilities in here.’” Whether or not security through obscurity is dead “isn't even an opinion question,” Trend Micro’s Zero Day Initiative chief bug hunter Dustin Childs told The Register, the day after Microsoft’s record-breaking Patch Tuesday addressed 974 CVEs. “When you look at all of the components patched by Adobe and Microsoft yesterday, you see components no one has talked about in years,” Childs said. “Telnet client – is this even still used in any secure environment? Windows RNDIS – the USB-networking protocol Microsoft has been trying to deprecate for years. NFS Portmapper – 1980s Unix tech. And Link Layer Topology Discovery – the Vista-era network-map protocol nobody's thought about since Vista – just to name a few.” Meanwhile, attackers are also using AI to reverse-engineer fixes and find exploits within hours. In one recent case, at least four espionage crews, most suspected of links to China, slammed shut the “patch-gap” window for open source Chromium, using an exploit kit developed shortly after the maintainers released an upstream patch – but before the downstream stable release was pushed to users. What this means for OT security During interviews at Black Hat in August, both former US National Cyber Director Chris Inglis and John Hultquist, chief analyst at Google Threat Intelligence Group, told us that they worry about what this means for critical operational technologies and industrial control systems (ICS). These are the systems that ensure the lights turn on when people flip a switch, gas flows out of pumps, and safe drinking water pours from faucets – all critical services that people use daily, and assume will continue working reliably. The OT systems themselves often use obscure protocols and proprietary hardware and software, which historically made them black boxes, even to IT specialists and hackers. AI upended this assumption. It means that criminals don't need to be OT experts to carry out destructive cyberattacks on critical networks and facilities. They just have to ask an agent to learn everything about these systems and do the dirty work for them. A couple of weeks after Black Hat, five US agencies said that attackers used AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities. “This is not a theoretical risk – it is an active threat,” the feds warned. AI “is excellent at technical troubleshooting, at knowing obscure systems and helping you make your way through it, and this makes me very concerned about industrial control systems,” Hultquist told The Register in an interview last week. “They've been largely secured because the expertise was in a handful of people's heads, and that's not going to last forever,” he said. AI can be a useful guide for attackers studying not just the application layer, but also the operating system, and even down into the firmware, Hultquist added. “That's going to have implications for a lot of different areas of security, but definitely for industrial control systems.” However, while this undoubtedly means more work for sysadmins and defenders, burying this outdated idea of security through obscurity isn’t necessarily a bad thing. 'Never a winning strategy' “I've always been of the mind that security through obscurity was never a winning strategy,” Katie Moussouris, founder and CEO of bug bounty consultancy Luta Security and the fairy godmother of bug bounties, told The Register. “But that's because I've been a hacker for so long. The argument always fails in the face of someone who decides to turn their gaze towards your organization. If there is something to find, they will find it.” Plus, she added, AI makes hacking a whole lot easier. “People might not have familiarity with the particular tech stack that you're running, but that is no longer a barrier because AI has ingested everything, and an AI is going to help them enumerate weak spots, even if they themselves are not familiar with the particular tech stack that they are pointing an AI towards,” Moussouris said. However, finding bugs and other weaknesses has never been the big security problem, she added. “It’s triaging and prioritization and actually getting things fixed.” This, Moussouris said, has also been her biggest issue with the way that organizations implement bug bounty programs. “AI is shining that bright light on the wrong end of the security picture, and unfortunately, AI hasn't caught up on the defensive side,” Moussouris said. “We're not there with AI automated patching, remediation – anything of the sort.” A couple of recent studies back this up, both finding that AI-generated patches fail more than half of the time. 1Password’s research team took six CVEs disclosed since March, and produced 6,080 patches using two frontier models: OpenAI's ChatGPT-5.5 and Anthropic's Opus 4.8. “The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0 percent,” wrote Director of Security Research Keith Hoodlet, adding that even patches that did fix the flaw also mucked up the application’s behavior 20 percent of the time. This included things like changing “allow list” logic to “deny list” logic. “Conversely, LLM-generated patches did not resolve the vulnerability, added a new vulnerability, or both, an average 53.9% of the time,” Hoodlet said. Another study by app security shop Veracode found that, across more than 100 models and 80 coding tasks, the average security pass rate for AI-generated code was just 56 percent. “If people are telling you that you need to accelerate on the fixing side, and the defense side – that’s just not cutting it,” Moussouris said. “Orgs that are looking at this as we're going to throw more resources at finding and fixing bugs, and they're not investing in taking a look at their process failures that led to so many bugs – those organizations are going to die on the treadmill,” she added. “They will literally have a heart attack and die. Like there's no VO2 max that will make you fast enough to deal with all those bugs, and giving up is not the answer.” The answer, she says, is taking a more dynamic approach, assessing where your organization can find patterns that lead to a process improvement instead of patching vuln after vuln. “A lot of organizations don't even know how to measure their progress, so they are counting bugs and speed of fixing, which is one way to measure. We had this many criticals, and then we fixed them super fast, and we had this many high, this many medium,” Moussouris said. The number of flaws fixed is important, but it doesn’t show the entire picture, she added. This involves looking at types of vulnerabilities, too. “Like: We've got a lot of injection flaws. That's something we could solve with better, safer templates earlier in our CI/CD pipeline. This is something that we can prevent at scale, as opposed to fixing these like really easy to find and fix vulnerabilities really really fast.” ®
Categories: News

More JFrog Artifactory bugs under attack, and all 3 have patches

The Register - Fri, 11/09/2026 - 18:43
JFrog Artifactory instances continue to get hit hard. Multiple attackers are exploiting three JFrog Artifactory bugs to gain administrative control over vulnerable instances - in some cases, just days after the vendor published a patch - and then using this illicit access to install malicious plugins and backdoors. The three vulnerabilities are: CVE-2026-42018 is a high-severity, improper authentication flaw that can return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled. An attacker can use this token to authenticate to the repository manager and then access sensitive resources. JFrog patched this vulnerability on August 12. CVE-2026-42016 is a high-severity privilege-escalation bug. Artifactory doesn’t properly validate the token’s scope, and this can allow an attacker with low-privileged access to elevate privileges and perform actions that they should not be allowed to do. JFrog fixed this one on July 27. CVE-2026-82329 is a critical authentication-bypass vulnerability that allows unauthenticated attackers with network access to obtain administrative privileges. JFrog published a patch for it on August 28. Earlier this month, security researchers told The Register that miscreants began battering internet-exposed systems vulnerable to CVE-2026-82329 just four days after JFrog disclosed the bug. In addition to creating new administrative credentials, watchTowr’s honeypot network caught miscreants “enumerating users, groups, credential sets and federated access topologies,” said Yordan Ganchev, principal threat intelligence specialist at watchTowr. The one thing everyone agrees upon is that attackers didn’t start exploiting any of these CVEs until after JFrog issued fixes. In a Thursday report, Wiz security researchers “confirmed in-the-wild exploitation of all three vulnerabilities across multiple environments,” and noted that “patching velocity has been slow.” JFrog has not responded to any of The Register’s inquiries about attacks against any of the three CVEs. 'Patching velocity has been slow' Six weeks after JFrog disclosed CVE-2026-42016, 59 percent of organizations remain vulnerable, and 62 percent remain vulnerable to CVE-2026-42018 after four weeks. Organizations have been quicker to remediate the critical bug, CVE-2026-82329, although 49 percent remain vulnerable two weeks after its publication, according to Wiz. Beginning August 15 and running through September 8, Wiz spotted “multiple” attackers chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances to gain admin access. Many of these intruders then dropped a custom Rust backdoor to establish command-and-control (C2) capabilities. While the post-exploitation activity varies, Wiz reports observing attackers doing all types of mischief with their administrative access to compromised Artifactory instances, including establishing persistent admin accounts, installing Groovy plugins to achieve remote code execution on the server, executing shell commands run through the plugin to perform reconnaissance and scan for sensitive files, deliver second-stage payloads, and upload web shells. Then, between September 1 and 8, Wiz saw “several” attackers exploiting CVE-2026-82329. These intrusions were not a “unified attack chain by a single threat actor,” but spanned multiple illicit behaviors including exfiltration of configuration details, establishing persistent admin accounts, token minting for long-lived credentials, stealing keys, attaching their own SSH keys to created users in some cases, and enumerating users, repositories, and tokens. If you haven't already, patch vulnerable instances Wiz advises - and we strongly concur - upgrading to a fixed Artifactory version as soon as possible. “Given that exploitation may be possible remotely without authentication under the default configuration, organizations should prioritize internet-accessible Artifactory instances and restrict network access to trusted users and systems where possible,” the researchers added. “Organizations should also review Artifactory authentication and administrative activity for unexpected privileged access.” These latest exploits follow a rough few months for JFrog's package management system, which has been under fire from both human and AI attackers. OpenAI and JFrog revealed that OpenAI’s models broke out of their cages to hack Hugging Face by exploiting an Artifactory zero-day in July, and at Black Hat, the model provider said agents used Artifactory to build message boards and help each other access the open internet. ®
Categories: News

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

The Register - Fri, 11/09/2026 - 13:15
A Ukrainian lawyer who wound up coding malware for the Conti ransomware gang has been sentenced to four years in a US prison. Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty in June to conspiracy to commit wire fraud over his role in Conti, the Russia-linked ransomware operation associated with more than 1,000 victims and at least $150 million in ransom payments. Lytvynenko took an unusual route into the ransomware business. The Ukrainian national, who later lived in Cork, Ireland, trained as a lawyer before joining Conti as an intruder and developer. According to his plea agreement [PDF], Lytvynenko operated under the handle "henry" and joined a team run by another Conti conspirator known as "silver" or "buza." He was recruited to help with coding and directed to work on a malware loader – software designed to get other malicious code running on a victim's machine. Prosecutors said his Google account showed he had also been doing some homework. Investigators found books and videos about malware and hacking alongside Conti malware, ransom notes, and stolen victim data. Prosecutors said he also used Google and ZoomInfo to research potential targets. Lytvynenko wasn't confined to writing code, according to the filing. Evidence from his online accounts showed that he possessed data stolen from eight US victims and four overseas, with the eight American victims reporting more than $1.5 million in losses. Court documents identify several Bitcoin transfers tied to his Conti work, including 0.4 BTC worth $25,042 that prosecutors traced back to one of his victims. He has been ordered to forfeit the same amount. Conti disbanded in 2022 after its internal chats and source code were leaked following the gang's public support for Russia's invasion of Ukraine. Lytvynenko apparently didn't take that as his cue to find another line of work. When Gardaí turned up at his County Cork home in July 2023, they said they found his laptop open, Cobalt Strike running and a Rocket.Chat session connected over Tor. Prosecutors said evidence recovered from the machine showed that his involvement in ransomware activity had continued after Conti disbanded. Lytvynenko was extradited from Ireland to the US in October 2025. The Justice Department says Conti attacked organizations across 47 US states, the District of Columbia, Puerto Rico, and 31 foreign countries between 2020 and 2022. By January 2022, the FBI estimated that victim payouts associated with Conti exceeded $150 million. Lytvynenko will now have four years to contemplate a career change. ®
Categories: News

EU's Cyber Resilience Act starts the 24-hour vulnerability clock

The Register - Fri, 11/09/2026 - 12:34
Manufacturers selling products with digital elements in the EU must now report actively exploited vulnerabilities to cybersecurity authorities under the Cyber Resilience Act's mandatory reporting rules. The reporting duties set out in Article 14 of the CRA became applicable today. Subject to the regulation's exemptions, they apply to manufacturers of products with digital elements made available in the EU, regardless of where those manufacturers are based. Manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability, followed by a more detailed notification within 72 hours. The same deadlines apply to severe incidents affecting the security of products with digital elements. The only difference in timing is related to the final report. Manufacturers must provide a final report on an actively exploited vulnerability within 14 days of making a corrective or mitigating measure available. For serious incidents, the final report is due one month after the first report. Darren Anstee, CTO for security at Netscout, said the reporting deadlines introduce much-needed urgency in working toward global cyber resilience. "The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt," he said. "Better, more rapid sharing of information helps organisations put defences and mitigating controls in place when they know there is heightened risk." EU and non-EU manufacturers must file these reports through ENISA's Single Reporting Platform (SRP). Notifications are addressed to the coordinating computer security incident response team (CSIRT) determined under the CRA. For an EU manufacturer, this is generally the CSIRT for the member state where it has its main establishment; separate rules determine the coordinator for manufacturers based outside the bloc. Manufacturers must also inform affected users, where appropriate, about actively exploited vulnerabilities or severe incidents. The CRA states that users must be informed of available corrections or mitigations without undue delay. Generally, failures under the CRA are punishable by varying tiers of fines, the most serious of which can reach €15 million ($17.4 million) or 2.5 percent of the offender's annual turnover, whichever is higher. The reporting duties that took effect today are classified as core responsibilities under the act, meaning failures to comply with them could lead to the maximum fines being issued. They are the latest step in the EU's plan to drip-feed tighter security regulations on companies operating in the bloc. Most remaining CRA provisions become applicable on December 11, 2027, at which time manufacturers will also be required to embed security by design and default. That means no default passwords and security updates are no longer optional. Products covered by the CRA will also have to undergo the applicable conformity assessment before being placed on the EU market and bearing a CE mark. More than a deadline The CRA's new rules are not just intended to accelerate manufacturers' responses to security flaws. They are also intended to give businesses a better understanding of their software supply chains. With the reporting clock starting as soon as manufacturers become aware of an issue, they cannot afford to begin mapping an affected product only after a vulnerability or incident emerges. They need a comprehensive view of the affected product and any related products that may share the flaw if they are to meet the deadlines. Furthermore, those requirements demand that manufacturers maintain this understanding throughout each product's lifecycle. Creating a software bill of materials (SBOM) when a product is launched is one thing. The SBOM becomes a mandatory requirement when most of the CRA's remaining provisions become applicable next year. Maintaining that security snapshot over time, however, is intended to help reduce the number and impact of serious cyberattacks across the EU. "What all this means for manufacturers is that secure development, effective vulnerability handling, and traceability across the software supply chain should be elevated to the top of their priority list," said Eran Kinsbruner, veep of product marketing at Checkmarx. "Modern applications are assembled from a complex ecosystem of components, with combinations of proprietary code, open-source packages, third-party components and, increasingly, AI models and services all interconnected," he added. "Organizations need to understand these components, their dependencies and the risks they introduce." Given enough time, the CRA looks set to improve cyber resilience across the board. However, lawyers warn that manufacturers, particularly those outside heavily regulated sectors, must now contend with a growing body of overlapping rules. "The CRA is arriving as organizations are already grappling with a growing body of Digital Decade legislation, including NIS2, DORA, the Data Act, and the AI Act," said Heidi Waem, data, privacy and cybersecurity partner at DLA Piper. "We're seeing the compliance challenge for many businesses evolving beyond understanding single regulations in isolation, but determining how multiple frameworks interact, where requirements overlap and how compliance programmes can be coordinated across them." John Magee, partner and global co-chair of data, privacy, and cybersecurity at the same law firm, added: "Even now we're seeing the breadth of the regulation's reach catching organizations off guard. "Many still associate the CRA primarily with consumer IoT devices, when in reality it applies to a much broader pool of products with digital elements. For compliance teams already very busy managing multiple Digital Decade initiatives, there is a risk that this first wave of CRA obligations has arrived sooner, and with a wider impact, than they had expected." ®
Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News