Visualização normal

Ontem — 7 de Setembro de 2026Stream principal
  • ✇Cybersecurity News
  • PHP Web Server Rootkit Targets F5 BIG-IP Devices Do Son
    A Linux PHP web server rootkit targets BIG-IP systems. Learn how this PHP web server rootkit injects in-memory shells into Apache processes. Related Posts: StreamRat Banking Trojan Targets Spanish Android Users Silver Fox Fake Software Installers Disable Windows Defender The Gentlemen Ransomware Deploys in Under 24 Hours The post PHP Web Server Rootkit Targets F5 BIG-IP Devices appeared first on Daily CyberSecurity.
     
Antes de ontemStream principal
  • ✇Security Affairs
  • Meta to Pay Up to $18B Over Teen Social Media Use Pierluigi Paganini
    Meta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety. Meta will pay up to $18 billion over the next decade and impose real usage limits on teenagers using Facebook and Instagram, settling claims that the company deliberately designed its platforms to addict children. The deal ended a federal trial mid-stream, right as Instagram head Adam Mosseri had begun testifying and Mark Zuckerberg was expected to take the s
     

Meta to Pay Up to $18B Over Teen Social Media Use

27 de Agosto de 2026, 05:15

Meta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety.

Meta will pay up to $18 billion over the next decade and impose real usage limits on teenagers using Facebook and Instagram, settling claims that the company deliberately designed its platforms to addict children. The deal ended a federal trial mid-stream, right as Instagram head Adam Mosseri had begun testifying and Mark Zuckerberg was expected to take the stand next.

The timing made sense given the huge potential penalties. Four states, California, Colorado, Kentucky, and New Jersey, were seeking up to $200 billion in damages. Before the trial, Meta said they could demand as much as $1.4 trillion. Against those figures, the $18 billion settlement looks relatively small, although it still equals about three to four months of Meta’s profits.

The most important part of the deal is what Meta agreed to change. Teenagers will be limited to two hours a day on Facebook and Instagram. Meta will also block access between midnight and 6 a.m. unless a parent gives permission, and it will turn off most push notifications during school hours.

“The focus of this case was to protect our kids,” Colorado Attorney General Phil Weiser said in a statement reported by Reuters. “The relief we are getting in this settlement is very meaningful and well beyond what any court has ordered or is likely to order.””

What the settlement leaves unchanged matters too. Meta does not have to stop using personalized recommendations or targeted ads for teenagers. It also does not have to remove specific types of content that researchers have linked to negative effects, such as posts that can make users feel worse about their bodies. A two-hour limit is still a meaningful restriction, but Meta can continue trying to maximize engagement during those two hours.

The deal also creates an interesting financial incentive. Of the roughly $16.7 billion going to 47 states, Washington D.C., Puerto Rico and other territories, about $12.7 billion is guaranteed. The remaining $5 billion depends on whether Snapchat, TikTok and YouTube introduce similar protections for teenagers. This gives Meta a financial reason to push its competitors to adopt the same rules, which is why the company reportedly plans to use newspaper ads to encourage TikTok and YouTube to follow suit.

Separately, Wednesday’s settlement also resolved lingering state privacy claims tied to the Cambridge Analytica scandal, with Meta agreeing to pay $459 million on top of everything else. That’s an old wound getting stitched up alongside a much newer one, in the same afternoon.

Not every state joined the settlement. New Mexico stayed out after winning a $567 million public nuisance ruling against Meta earlier this month, on top of a separate $375 million jury verdict. Attorney General Raul Torrez said the settlement didn’t include some changes his case had pushed for, including stronger protection against adults targeting children and a ban on sexualized AI chatbot interactions with minors. Still, he called the deal a step forward.

Florida rejected the settlement altogether. Attorney General James Uthmeier said the payouts amount to “peanuts” compared with the harm caused and said Florida would take Meta to trial instead.

Legal experts already see the settlement as a possible model for future cases. Northwestern law professor James Speta said Meta and other tech companies faced growing pressure to change anyway, from Congress, state lawmakers and the public. That makes the settlement more than a single case: it could set a standard that courts and regulators use when judging other platforms.

Thousands of similar lawsuits from individuals, school districts and municipalities are still moving through courts across the U.S. If those cases follow the same pattern, we haven’t seen the last of these headlines.

“Today, we are announcing an agreement with a bipartisan group of 52 attorneys general across US states, territories, and the District of Columbia, building on our longstanding efforts to empower parents and support teens.” reads the statement published by Meta.

“Over the years, we have consistently partnered with parents and experts — listening, learning, and building. That’s why we launched Teen Accounts in 2024, to bring automatic protections to teens, and more control for parents.”

The agreement aims to push YouTube, TikTok and other platforms to adopt similar protections for teenagers.

“While this is an important step, the fact is that teens move fluidly between dozens of apps a day. All platforms should empower parents and support teens by putting the same measures in place, because we know that when teens are restricted on one app, they simply move to another.” concludes Meta. “For meaningful progress to happen, we urge TikTok and YouTube to join us and state attorneys general in adopting this new standard, to ensure teens use social media in a healthy and responsible way.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Facebook)

US Navy tells sailors and their families: scrub your social media, enemies are watching

27 de Agosto de 2026, 06:46
The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be using them to determine who they are, where they live, and when they may not be at home. Read more in my article on the Hot for Security blog.
  • ✇Security Affairs
  • TikTok Settles U.S. Child Privacy Case for $400 Million Pierluigi Paganini
    TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy. “Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities (TikTok) resolving litigation concerning compliance with the Children’s Online Privacy Protection Act and its implementing
     

TikTok Settles U.S. Child Privacy Case for $400 Million

24 de Agosto de 2026, 04:23

TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13.

The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy.

“Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities (TikTok) resolving litigation concerning compliance with the Children’s Online Privacy Protection Act and its implementing regulations (COPPA).” reads the press release published by DoJ. “Under the settlement, TikTok will pay $300 million immediately and an additional $100 million upon entry of an order vacating a prior consent decree entered against TikTok’s predecessor, Musical.ly. The settlement represents one of the largest recoveries ever obtained in a COPPA case.”

TikTok will pay $300 million immediately and another $100 million after a court order removes an earlier consent decree involving Musical.ly. The 2024 case, brought by the DoJ and FTC, accused TikTok of knowingly allowing children under 13 to create accounts and illegally collecting data from children using Kids Mode.

Since the Justice Department filed its lawsuit against TikTok in 2024, the company has made major changes to its ownership, management, compliance, and privacy practices. It has also introduced stronger safeguards for younger users, improved age controls, and expanded parental oversight.

The DOJ said these measures have advanced the goals of its case and strengthened protections for millions of U.S. families. The settlement reflects a focus on practical results, securing a significant recovery while recognizing TikTok’s compliance improvements. The case was filed in California and handled by the DOJ’s Civil Division following a referral from the FTC.

“This settlement is a major victory for American children and parents,” said Associate Attorney General Stanley E. Woodward Jr. “The Department’s priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations. This resolution secures a substantial recovery while reinforcing the protections that families expect and deserve.”

TikTok has faced regulatory scrutiny over children’s privacy before. In September 2023, Ireland’s Data Protection Commission fined the company €345 million for breaching the GDPR through its handling of children’s personal data.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, privacy)

  • ✇Cybersecurity News
  • Researchers Rebuild Leaked Tiangou Secure Gateway, Find Great Firewall Ties Do Son
    Researchers rebuilt the leaked Tiangou Secure Gateway censorship system from 100,000+ leaked files and found DNS-handling quirks matching the Great Firewall. Related Posts: SafePal Data Breach Exposes Order Information of 39,798 Customers OpenAI AI Agents Collude to Breach Internal Systems WebKit Flaw Triggers iCloud Private Relay IP Leak The post Researchers Rebuild Leaked Tiangou Secure Gateway, Find Great Firewall Ties appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks Pierluigi Paganini
    Trump authorizes vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks. President Trump signed a national security memorandum on August 13 establishing a formal program that allows vetted private US cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations under government direction and oversight. The program, managed by the National Coordination Center, covers both intelligence c
     

US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks

14 de Agosto de 2026, 04:14

Trump authorizes vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks.

President Trump signed a national security memorandum on August 13 establishing a formal program that allows vetted private US cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations under government direction and oversight. The program, managed by the National Coordination Center, covers both intelligence collection, described as Cyber Surveillance Operations, and active disruption of criminal infrastructure, described as Cyber Effects Operations. It’s the formal implementation of what the White House’s Cyber Strategy for America promised in March: unleashing the private sector as an offensive cyber instrument.

“The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States. Yet, American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace. Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.” states the memorandum.

“By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”

The program targets what the memo defines as Cyber-Enabled Transnational Criminal Organizations, any foreign group conducting cyber-enabled crime against US interests, explicitly excluding entities that are institutional parts of foreign governments or wholly operated under foreign government direction. That carve-out matters: this program is aimed at criminal networks, not nation-state adversaries. The line between the two is often blurry in practice, but the memo establishes the presumption that a group is not government-directed unless clear intelligence says otherwise.

““Cyber Effects Operation” means activity conducted in or through the interdependent network of information technology infrastructure that includes the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, and embedded processors and controllers that results in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon.” continues the memorandum.

Program executive directors from the Department of Justice and the Department of Homeland Security must co-approve every operation in writing before any action is taken. Operations that could produce those Critical Outcomes require additional authorization beyond the program executive directors, an explicit acknowledgment that some cyber actions cross into territory governed by the laws of armed conflict.

Companies wanting to participate must clear rigorous vetting, demonstrate technical capability, submit to annual evaluations, and maintain a bond or escrow of at least $1 million that is forfeited if they violate their contract terms. The operational procedures are to be finalized within 60 days, and the Justice Department will review any operation that touches a US person or raises domestic constitutional questions. The legal question hovering over the whole program is whether the CFAA exemption for lawfully authorized government investigative activities extends to private companies acting under government contracts, a question no US court has yet answered. Jenner & Block lawyers noted the exemption likely applies when companies operate under direct government direction, but wouldn’t cover independent offensive operations without that oversight. That’s precisely why the memo makes government control explicit at every step: every operation needs written approval before action, every unintended contact with a US person or system must trigger an immediate stop and notification, and the Justice Department stays in the loop throughout.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Transnational Criminal Networks)

  • ✇Security Affairs
  • Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Pierluigi Paganini
    China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe. China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing national security law and cybersecurity law as the basis for the review, and offers essentially nothing beyond that. “To
     

Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions

8 de Agosto de 2026, 10:41

China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe.

China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing national security law and cybersecurity law as the basis for the review, and offers essentially nothing beyond that.

“To ensure the safe and stable operation of critical information infrastructure, prevent cybersecurity risks and vulnerabilities, and safeguard national security, in accordance with the National Security Law of the People’s Republic of China and the Cybersecurity Law of the People’s Republic of China, the Cybersecurity Review Office, following the Cybersecurity Review Measures, has conducted a cybersecurity review of Palo Alto Networks’ products sold in China.” the regulator says.

That’s the entire public justification. No specific vulnerability named, no incident referenced, no timeline for when findings might land. Palo Alto Networks told The Register it maintains high standards across its global operations and that, for now, there’s no impact on its ability to serve customers or deliver products in the region.

The situation resembles China’s 2023 security review of Micron, which was announced without warning. Weeks later, Beijing deemed Micron’s products a security risk for critical infrastructure, effectively restricting sales, but provided little explanation. Micron eventually withdrew its data center and server products from China, losing billions in annual revenue while local chipmakers gained new opportunities.

Micron’s story offers one genuinely reassuring data point for Palo Alto, if it’s any comfort: getting banned from a major market didn’t permanently damage the company. The AI boom drove memory prices high enough afterward that the China restriction barely shows up in Micron’s financials today. Getting frozen out of a market stings a lot less when the rest of the world is buying everything you can produce anyway.

China has already been pushing companies away from foreign cybersecurity products: in January, authorities reportedly told Chinese firms to stop using security software from a list of U.S. and Israeli vendors that included Palo Alto Networks, Fortinet, Check Point, CrowdStrike and others, encouraging the replacement of those products with domestic alternatives. Chinese vendors such as Huawei and H3C have increasingly positioned their own firewalls and security platforms as alternatives to foreign products, while other domestic companies are expanding across the cybersecurity market. H3C, for example, openly promotes its security products as replacements for overseas technologies.

That makes the Palo Alto review more than a simple technical investigation. It fits a broader strategy in which cybersecurity and national security are increasingly intertwined with China’s push for technological self-reliance.

For Palo Alto, the immediate financial impact is difficult to measure because the company does not separately report China revenue, but restrictions could still create an opening for domestic competitors while adding another layer of uncertainty for Western technology companies operating in the country.

There is also a wider geopolitical dimension. Beijing has repeatedly framed foreign technology as a potential national-security risk, while Washington and its allies have taken similar measures against Chinese and Russian vendors, including Huawei, ZTE and Kaspersky. The United States, for example, banned Kaspersky’s cybersecurity and antivirus products over national-security concerns, arguing that the software created risks because of its ties to Russia. The Palo Alto case therefore sits within a much larger cycle of reciprocal distrust, in which cybersecurity products are increasingly treated not only as commercial technologies but also as potential strategic assets.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, China)

  • ✇Security Affairs
  • Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case Pierluigi Paganini
    Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M. Meta ‘s child-safety legal bill just got another half-billion dollars heavier. A New Mexico state judge ruled that company’s platforms constitute a “public nuisance,” the BBC reports, ordering $567 million into a fund meant to address harm the company caused to children. Combined with an earlier $375 million penalty from the same case, Meta now owes New Mexico $942 million
     

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case

7 de Agosto de 2026, 08:42

Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M.

Meta ‘s child-safety legal bill just got another half-billion dollars heavier. A New Mexico state judge ruled that company’s platforms constitute a “public nuisance,” the BBC reports, ordering $567 million into a fund meant to address harm the company caused to children. Combined with an earlier $375 million penalty from the same case, Meta now owes New Mexico $942 million total.

“Judge Bryan Biedscheid said the social media giant is a “public nuisance” akin to air pollution and that it must put the money in a fund aimed at reducing future harms.Thursday’s ruling is in addition to $375m in fines Meta was already ordered to pay in the case, for a total of $942m.” BBC reports. “Judge Biedscheid compared Meta to a factory, with advertising and content as its product and “the psychological harm and sexual exploitation of children to be the pollution that must be abated”.”

Judge Bryan Biedscheid didn’t hold back on the framing. He compared Meta to a factory, with advertising and content as its output and the psychological harm and sexual exploitation of children as the pollution that output produces. It’s the kind of comparison a judge doesn’t reach for lightly, and according to CNN, it’s the first time any social media company has been legally labeled a public nuisance.

“The court found that “just as noxious pollution produced by the factory can harm the common public right to reasonably clean air, the harmful effects of Meta’s platforms on children do not stay contained by its platforms and, instead, migrate to the internet as a whole and, perhaps most concerning, to the real world and create a common, societal burden on and harm to the affected children and their families and schools, as well as hospitals and law enforcement.”” CNN reports.

The case traces back to a 2023 lawsuit from state attorneys general, and it unfolded in two phases. A March jury verdict already found Meta had repeatedly violated New Mexico’s Unfair Practices Act, largely because its recommendation algorithms steered young users toward harmful content and predatory contacts. This second phase, decided by the judge alone rather than a jury, existed specifically to answer one question: did that harm rise to the level of a public nuisance affecting the broader community.

According to CNBC’s reporting, Biedscheid’s written ruling didn’t pull punches on causation either.

“Expert testimony supports a causal link between social media and the youth mental health crisis in New Mexico,” the ruling states, closing off Meta’s usual argument that any correlation is just correlation.

Most of the money has a specific destination. $420 million goes toward direct treatment, funding clinical and behavioral health programs for young people already affected. The remainder covers prevention training for teachers and healthcare workers, plus broader awareness efforts, all running over roughly the next five years, according to PBS.

Cash isn’t the only thing Meta has to hand over. The judge ordered a list of concrete platform changes: no recommending accounts of users under 18 to adults, no adults messaging minors, a ban on sending or receiving nudity for underage accounts, and elimination of “like” counts for teen users. Push notifications get blocked overnight and during school hours on weekdays, and total monthly usage for minors gets capped at 90 hours across Instagram and Facebook combined, roughly three hours a day.

Meta’s response was predictable and brief. A company spokesperson said Meta disagrees with the ruling and will appeal, adding that the company has worked hard to keep people safe and remains confident in its record protecting teens online.

“We disagree with the ruling and will appeal.” a company spokesman told BBC. “We work hard to keep people safe on our platforms and have been transparent about the challenges of identifying and removing bad actors and harmful content,” he added.

“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

That’s the same basic line the company used after the March verdict, and it’s likely to stay the company line through however many appeals this takes.

New Mexico is far from the only front in this fight. Nearly three dozen state attorneys general are pursuing a separate case against Meta over child privacy violations, with another major trial starting next week in California, and Meta already lost a Los Angeles case earlier this year that found it could be held liable for building deliberately addictive platforms. Add in the EU’s ongoing preliminary findings against Meta over underage users on Instagram and Facebook, and the pattern stops looking like isolated lawsuits and starts looking like a coordinated reckoning across multiple jurisdictions at once.

Former Twitter executive Bruce Daisley put the number in context on BBC Radio 4, calling it “a drop in the ocean” against Meta’s finances; the company posted $61 billion in quarterly revenue this year, up 28% from the year before. The fine is real money by any normal measure. Whether it’s real money by Meta’s measure is a different question entirely, and it’s the one regulators worldwide are now racing to answer with policy rather than just penalties.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Meta)

  • ✇Firewall Daily – The Cyber Express
  • Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign Ashish Khaitan
    Microsoft Threat Intelligence has uncovered CaptiveCrunch, a cyber espionage campaign linked to Storm-2945, a subgroup of Midnight Blizzard, the Russian state-linked threat actor associated with Russia's Foreign Intelligence Service (SVR).   Active since early May 2026, the operation targets business travelers by exploiting hospitality Wi-Fi networks and captive portals in hotels, conference centers, and similar venues. The campaign combines adversary-in-the-middle attacks, phishing, malware
     

Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign

CaptiveCrunch

Microsoft Threat Intelligence has uncovered CaptiveCrunch, a cyber espionage campaign linked to Storm-2945, a subgroup of Midnight Blizzard, the Russian state-linked threat actor associated with Russia's Foreign Intelligence Service (SVR).   Active since early May 2026, the operation targets business travelers by exploiting hospitality Wi-Fi networks and captive portals in hotels, conference centers, and similar venues. The campaign combines adversary-in-the-middle attacks, phishing, malware deployment, and AI-assisted development to steal credentials and infiltrate enterprise environments. 

Storm-2945 Uses Hospitality Networks to Target Travelers 

According to Microsoft, Storm-2945 manipulates DNS and HTTP traffic on public Wi-Fi networks using captive portals. By intercepting users before they reach legitimate websites, attackers redirect victims to malicious infrastructure that hosts fake Microsoft sign-in pages or malware downloads. This approach allows the Midnight Blizzard campaign to compromise users without requiring them to intentionally visit suspicious websites. Microsoft believes the attackers may have gained access to shared captive portal infrastructure used across multiple hospitality providers, expanding the scale of the CaptiveCrunch operation beyond isolated venues.

Credential Theft and Malware Deployment 

A key objective of CaptiveCrunch is stealing Microsoft Entra ID credentials. Researchers observed Storm-2945 using counterfeit Microsoft login pages and device code phishing to gain unauthorized access to Microsoft 365 accounts. Once authentication succeeds, the attackers register compromised devices and collect cloud data, making corporate travelers especially attractive targets.  The campaign also distributes malware disguised as browser or operating system updates through convincing "ClickFix" prompts that encourage users to run scripts or install software. Similar tactics have targeted Android users by prompting them to download malicious APK files. The primary payload is CornFlake, a Windows remote access trojan written in Go that installs itself as a persistent "Cloud Sync Service." It maintains persistence through Windows services, registry keys, and scheduled tasks while enabling attackers to log keystrokes, capture screenshots, monitor clipboard activity, record webcam and microphone data, steal browser credentials, exfiltrate files, monitor USB devices, and execute remote commands through PowerShell or Windows Command Prompt. Communications with command-and-control servers are encrypted to evade analysis.

AI-Assisted Malware and Centralized Control

Supporting CornFlake is ChocoShell, a PowerShell-based infostealer that operates entirely in memory to avoid detection. It extracts browser passwords, Microsoft 365 Single Sign-On tokens, Azure Active Directory authentication tokens, Wi-Fi credentials, and session cookies while bypassing AMSI, User Account Control, and virtual analysis environments. Microsoft researchers noted that ChocoShell's source code contains detailed developer comments, suggesting significant AI-assisted development.  The attackers manage infected systems through FruitStone, a web-based command-and-control platform that allows operators to deploy malware, execute remote commands, collect stolen credentials, review screenshots and keystrokes, configure campaigns, and organize compromised devices by geography and operational status. 

Microsoft's Defensive Guidance

Microsoft assesses with high confidence that Storm-2945 operates as part of Midnight Blizzard because of overlaps in tooling, phishing techniques, victim selection, and cloud exploitation methods. The Russian state-linked threat actor has previously targeted governments, diplomatic organizations, NGOs, IT providers, and other strategic sectors.  To reduce exposure to CaptiveCrunch, Microsoft recommends treating public Wi-Fi as untrusted, enforcing phishing-resistant multi-factor authentication or passkeys, restricting OAuth permissions, monitoring device registrations, and applying Conditional Access policies.   Organizations should also educate employees about ClickFix-style social engineering and avoid installing software, certificates, or updates delivered through captive portals. Business travelers are encouraged to use trusted VPNs, mobile hotspots, or enterprise-managed travel routers whenever possible. 
  • ✇Security Affairs
  • Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access Pierluigi Paganini
    Qilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks. Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate networks. CVE-2026-0257 is a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways. Palo Alto Networks addressed the vulnerability on May 13. Two weeks later, cybersecuri
     

Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access

21 de Julho de 2026, 13:08

Qilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks.

Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate networks.

CVE-2026-0257 is a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways.

Palo Alto Networks addressed the vulnerability on May 13. Two weeks later, cybersecurity firm Rapid7 confirmed active exploitation across multiple customer environments. In early June, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability affects the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS, allowing attackers to bypass authentication and establish unauthorized VPN connections. The vulnerabilities do not affect Panorama or Cloud NGFW deployments.

“Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.” reads the advisory.

Arctic Wolf warns that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate networks. The flaw allows attackers to bypass authentication and establish unauthorized VPN sessions on unpatched devices. Palo Alto Networks released patches on May 13 and confirmed exploitation attempts against systems that had not applied updates or mitigations.

Arctic Wolf Labs has observed several attacks in which threat actors exploited CVE-2026-0257 to gain initial access and deploy Qilin ransomware across entire Windows domains. Investigators found evidence that multiple Qilin affiliates are actively abusing the flaw to compromise organizations, making unpatched PAN-OS GlobalProtect devices a high-priority target for ransomware operations.

“Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances.” reads the report published by Arctic Wolf. “Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella.”

Arctic Wolf found that attacks exploiting CVE-2026-0257 followed a common initial pattern but diverged after compromise. Threat actors consistently used the same entry point, ransomware staging paths, PsExec execution, and registry persistence. However, some attacks quickly encrypted entire environments without stealing data, while others involved extensive reconnaissance, deployment of remote-access tools such as AnyDesk, Ngrok, and LogMeIn, large-scale credential theft, and data exfiltration to cloud services before ransomware execution, reflecting the varied tactics of Qilin RaaS affiliates.

After exploiting CVE-2026-0257, the attackers established VPN sessions from Kali Linux systems, then quickly secured persistent access using registry Run keys, scheduled tasks, and remote administration tools such as AnyDesk, Ngrok, LogMeIn, and MeshAgent. They harvested credentials by dumping LSASS memory and extracting the Active Directory database (NTDS), enabling lateral movement with PsExec, RDP, and compromised administrator accounts.

The operators scanned networks with SoftPerfect Network Scanner and NetExec, cleared Windows event logs, and in some cases disabled Microsoft Defender before deploying ransomware. Several intrusions also involved data theft using Rclone, ProtonDrive, FileZilla, and MEGA cloud storage, while others focused solely on rapid encryption.

The ransomware payload, typically named win.exe, was staged in C:\PerfLogs, executed with password-protected parameters, and encrypted files using unique extensions assigned to each campaign.

“The variability in post-exploitation tradecraft, from encryption-only operations to full double-extortion, shows that perimeter compromise is the critical point for defenders. After exploitation succeeds, the impact depends on the affiliate’s goals and timeline, but domain compromise and ransomware deployment are consistent.” concludes the report. “Arctic Wolf Labs assesses with moderate confidence that intrusions leveraging CVE-2026-0257 and leading to Qilin ransomware deployment are likely ongoing. This assessment is based on the extensive scanning activity observed and the RaaS model’s tendency to distribute successful exploits among multiple affiliates.”

Qilin ransomware operation has been active since 2022, it has become one of the most active RaaS groups in 2025, claiming over 40 victims monthly and peaking at 100 in June.

The group enables affiliates to deploy customized ransomware payloads against targeted organizations. Qilin uses double-extortion tactics, encrypting data while threatening to leak it via Tor-based portals. The group has targeted multiple sectors worldwide, including healthcare, manufacturing, and finance, leveraging phishing and known vulnerabilities.

In October 2025, Resecurity’s researchers detailed how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.

In early October, DragonForceLockBit, and Qilin formed a ransomware alliance to boost attack effectiveness, marking a major shift in the cyber threat landscape. Ransomware groups DragonForce, LockBit, and Qilin formed a strategic alliance to enhance their attack capabilities, signaling an evolving cyber threat landscape. The alliance aims at sharing tools and infrastructure to enhance attack effectiveness. 

At the end of March, Qilin Ransomware group allegedly breached the chemical manufacturing giant Dow Inc. 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

  • ✇Security Affairs
  • Bad Epoll Flaw Gives Attackers Root Access on Linux and Android Pierluigi Paganini
    Bad Epoll (CVE-2026-46242) lets local attackers gain root on Linux and Android. The flaw was missed by AI but found by a security researcher. A newly disclosed Linux kernel vulnerability, named Bad Epoll (CVE-2026-46242), allows a local attacker with no special privileges to gain full root access on affected Linux systems and Android devices. Security updates are already available, and users are urged to install them as soon as possible. The flaw affects the Linux kernel’s epoll subsystem
     

Bad Epoll Flaw Gives Attackers Root Access on Linux and Android

6 de Julho de 2026, 05:24

Bad Epoll (CVE-2026-46242) lets local attackers gain root on Linux and Android. The flaw was missed by AI but found by a security researcher.

A newly disclosed Linux kernel vulnerability, named Bad Epoll (CVE-2026-46242), allows a local attacker with no special privileges to gain full root access on affected Linux systems and Android devices. Security updates are already available, and users are urged to install them as soon as possible.

The flaw affects the Linux kernel’s epoll subsystem, a core feature used by servers, browsers, and countless applications to efficiently manage multiple network connections and file events. Because epoll is fundamental to Linux, there is no practical workaround other than patching vulnerable systems.

Bad Epoll is a classic use-after-free vulnerability, which occurs when a program continues to use a piece of memory after it has already been released (“freed”).

Two kernel threads attempt to release the same internal object simultaneously. One frees the memory while the other continues using it, creating a brief opportunity to corrupt kernel memory and escalate privileges to root.

Bad Epoll

“Two of epoll’s close paths run at the same time and collide. One frees an object while the other is still writing into it, and that is the use-after-free (UAF).” continues the advisory. “The race window, and how the exploit drives it. The exploit uses four epoll objects grouped into two pairs. One pair triggers the race, while the other becomes the victim. From there, the exploit turns the 8-byte UAF write into a UAF on a file object, and uses a cross-cache attack to fully control the file’s contents. Turning the bug into an arbitrary kernel memory read through /proc/self/fdinfo. With that control, the exploit gains an arbitrary read of kernel memory through /proc/self/fdinfo. Finally, it hijacks control flow and executes a ROP chain to gain a root shell.”

Although exploiting the flaw requires hitting a timing window only six CPU instructions wide, researcher Jaeyoung Chung developed a reliable proof-of-concept that reportedly succeeds in about 99% of attempts on tested systems. According to the researcher, the exploit can even be launched from Chrome’s renderer sandbox, making it particularly dangerous, and could also impact Android devices.

“Bad Epoll (CVE-2026-46242) is a race-condition use-after-free in the Linux kernel’s epoll subsystem. This bug lets an unprivileged process become root, not only on Linux desktops and servers but also on Android devices.” reads an advisory published by Chung.

One of the most interesting aspects of the vulnerability is its connection to AI-assisted vulnerability research. Bad Epoll originates from the same section of kernel code where Anthropic’s Mythos model previously identified another privilege escalation flaw, tracked as CVE-2026-43074. The AI detected the first bug, but missed this closely related vulnerability, which was later discovered manually.

“A single commit in 2023 introduced two separate race conditions into the epoll code, only about 2,500 lines in all. Both turned out to be critical bugs that can lead to privilege escalation.

The first was found by Anthropic’s Mythos and reported as CVE-2026-43074. That result is impressive on its own, because kernel race bugs are known to be hard to find. It showed a frontier AI model’s ability to find race bugs. An independent researcher later submitted a 1-day exploit for it to kernelCTF.” continunes the advisory. “The other race is Bad Epoll, which Mythos missed.”

Chung believes the miss is understandable. The race condition is extremely difficult to reason about because the vulnerable execution path exists for only a tiny fraction of a second. In addition, once the first flaw was patched, Bad Epoll no longer generated obvious warnings through KASAN, Linux’s memory error detection system, making it even harder to spot.

The good news is that there is currently no evidence that Bad Epoll has been exploited in the wild. The only public exploit is the proof-of-concept released through Google’s kernelCTF program. An Android exploit is reportedly still under development.

Bad Epoll

The flaw affects Linux kernels based on version 6.4 and later, unless they already include the upstream fix. Older long-term support kernels based on Linux 6.1, including some Android devices such as the Pixel 8, are not vulnerable because the problematic code was introduced after those versions branched.

Bad Epoll joins a growing list of high-profile Linux privilege escalation vulnerabilities recently disclosed, including Copy Fail, Dirty Frag, Fragnesia, and DirtyClone. While many of these newer vulnerabilities are deterministic and relatively easy to exploit, Bad Epoll belongs to the older class of race-condition bugs, which are significantly harder to discover, exploit, and patch.

The case also highlights both the promise and the current limitations of AI in vulnerability research. Models such as Mythos have already demonstrated they can identify complex kernel flaws and even uncover long-standing vulnerabilities in projects like FreeBSD.

At the same time, Bad Epoll shows that highly subtle race conditions can still escape even state-of-the-art AI systems. For now, human expertise remains essential, particularly when vulnerabilities depend on tiny timing windows and complex concurrent execution paths.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Bad Epoll)

  • ✇Firewall Daily – The Cyber Express
  • Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S. Samiksha Jain
    An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group. Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago a
     

Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S.

Scattered Spider

An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group.

Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago after being extradited from Finland.

According to the U.S. Department of Justice, Stokes was arrested by Finnish authorities in April following an Interpol Red Notice and was transferred to the United States last week. A criminal complaint filed in the Northern District of Illinois accuses him of participating in cyberattacks carried out as part of the Scattered Spider group.

Scattered Spider Linked to More Than 100 Network Intrusions

According to the complaint, Scattered Spider, also known as Octo Tempest, UNC3944, and 0ktapus, has been associated with more than 100 network intrusions. Authorities allege the group's activities have resulted in over $100 million in ransom payments and millions of dollars in additional damages suffered by victims.

Investigators said the group targeted companies across the United States by obtaining access to employee accounts through fraudulent methods.

Once inside corporate networks, the attackers allegedly encrypted data or exfiltrated sensitive information to remote servers before demanding cryptocurrency payments to restore access or prevent the public release of stolen data.

Complaint Details Alleged Luxury Retailer Cyberattack

The criminal complaint describes an alleged cyber intrusion that occurred in May 2025 involving a luxury jewelry retailer.

Federal prosecutors allege that Stokes and other co-conspirators breached the retailer's computer systems, exfiltrated company data, and demanded approximately $8 million in cryptocurrency as ransom. According to court documents, the retailer's security team successfully removed the threat actors from its network before any ransom payment was made.

Although the company did not pay the ransom, authorities said it still incurred losses of at least $2 million due to business disruption, investigation costs, and mitigation efforts following the incident.

Operation Riptide Targets Cybercrime Networks

The extradition and criminal charges were announced by the Department of Justice, the U.S. Attorney's Office for the Northern District of Illinois, and the FBI. The investigation also involved the FBI's Copenhagen Law Enforcement Attaché Office, the FBI Las Vegas Field Office, the Justice Department's Office of International Affairs, and Finland's National Bureau of Investigation.

Officials said the case forms part of Operation Riptide, an ongoing FBI campaign focused on disrupting cybercriminal actors, infrastructure, financial networks, and fraud schemes targeting Americans.

According to the FBI, Americans reported more than $20 billion in cybercrime losses last year, representing a 26% increase compared with the previous year.

Authorities Cite International Cooperation

Assistant Attorney General A. Tysen Duva said the charges stem from years of investigative work by the Justice Department, the U.S. Attorney's Office, and the FBI, adding that authorities would continue working together to pursue cybercriminals operating across international borders.

U.S. Attorney Andrew S. Boutros said the alleged attacks caused significant disruption to businesses across the United States and emphasized the government's commitment to prosecuting individuals involved in cyber intrusions.

FBI Special Agent-in-Charge Douglas S. DePodesta also highlighted the role of international law enforcement partnerships in identifying alleged members of the hacking group and pursuing cross-border cybercrime investigations.

Recent Guidance on Scattered Spider Threat

The arrest follows recent law enforcement efforts targeting the Scattered Spider threat group. In July 2025, the FBI and CISA released updated guidance describing the group's latest attack techniques, including the use of DragonForce ransomware to encrypt VMware ESXi servers.

The advisory urged organizations to maintain isolated offline backups, implement phishing-resistant multifactor authentication (MFA), and apply application controls to manage software execution.

Separately, in November 2025, two alleged Scattered Spider members appeared before Southwark Crown Court in the United Kingdom and pleaded not guilty to charges related to the August 2024 cyberattack on Transport for London (TfL).

The Department of Justice emphasized that the complaint against Stokes contains allegations only. As with all criminal cases, he is presumed innocent unless and until proven guilty in court.

Denmark Ordered to Pay $12M Over Huawei Equipment Removal

25 de Junho de 2026, 13:00

A Danish court ordered the state to compensate TDC NET after the removal of Huawei fiber-network equipment, raising questions about telecom security costs.

The post Denmark Ordered to Pay $12M Over Huawei Equipment Removal appeared first on TechRepublic.

TfL Hackers Plead Guilty After Breach Exposed Customer Data and Cost £29 Million

Transport for London cyberattack

Two alleged members of the cybercrime collective Scattered Spider have pleaded guilty to their roles in the Transport for London cyberattack, an incident that disrupted services, exposed customer data, and resulted in approximately £29 million in losses and recovery costs for London's transport authority. The guilty pleas were entered by Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, on the opening day of proceedings at Woolwich Crown Court. The pair had been due to stand trial on June 22 but changed their pleas to guilty.

Transport for London Cyberattack Led to Major Disruption

According to the National Crime Agency (NCA) and City of London Police, TfL's network was infiltrated between August 31 and September 3, 2024. The breach forced all 28,000 employees to attend TfL offices for password resets and caused significant operational disruption across the organization. The TfL cyberattack also resulted in unauthorized access to data held within TfL's Oyster refunds system. The incident affected the authority's customer refund process, delaying reimbursements for some customers. In addition, the application system for Oyster photocards used by children and young people was temporarily shut down. Authorities said the attack caused substantial financial damage, with TfL reporting losses and recovery costs totaling approximately £29 million.

Investigation Linked Attackers to Scattered Spider

Jubair and Flowers were arrested at their homes on September 16, 2024, following a joint investigation conducted by the NCA and City of London Police. Investigators identified both individuals as members of Scattered Spider, a cybercriminal collective that has been linked to a number of high-profile intrusions. During searches of Flowers' residence, officers recovered laptops, desktop computers, hard drives, and USB storage devices. Evidence recovered from one Acer laptop included a screenshot showing connectivity to TfL infrastructure. [caption id="attachment_112868" align="aligncenter" width="600"]Transport for London cyberattack Source: NCA[/caption] Authorities also found evidence indicating Flowers had accessed an online marketplace that sold breached credentials. Investigators further discovered videos recorded by Flowers that allegedly showed Jubair accessing TfL systems during the attack. The investigation revealed that the two communicated through Telegram and collaborated using an online workspace platform that allowed multiple participants to work remotely on shared systems.

Additional Allegations Involving US Healthcare Networks

The investigation extended beyond the Transport for London cyberattack. When Flowers was first arrested on September 6, 2024, NCA officers identified evidence suggesting unauthorized activity targeting the networks of SSM Health Care Corporation and Sutter Health in the United States. Court records show Flowers pleaded guilty to charges related to a conspiracy to conduct unauthorized acts against SSM Health Care Corporation's computer systems with intent to impair operations. He also admitted attempting unauthorized acts against Sutter Health's systems with the same intent. Jubair additionally faced a charge for failing to disclose PINs or passwords associated with devices seized during the investigation. Authorities noted that Flowers breached bail conditions on two occasions in March and May 2025.

Law Enforcement Highlights Impact of Cybercrime

Paul Foster, Deputy Director and head of the NCA's National Cyber Crime Unit, described the case as a lengthy and highly complex investigation. He said the attack demonstrated that cybercrime has significant real-world consequences, affecting public services and causing millions of pounds in losses to critical national infrastructure. Foster also highlighted the growing threat posed by cybercriminal groups operating from the UK and other English-speaking countries, citing Scattered Spider as a notable example. Deputy Commissioner Nik Adams of the City of London Police said the cyberattack had a significant impact on essential public services and daily operations. He emphasized that individuals responsible for targeting critical organizations and causing financial harm would be pursued through coordinated law enforcement efforts. The investigation received support from the West Midlands Regional Organised Crime Unit and British Transport Police. Jubair and Flowers are scheduled to be sentenced at Woolwich Crown Court on July 16.

New Pink Extortion Group Targets Microsoft 365 Cloud Data Via Vishing Scams

Cybersecurity researchers are warning businesses about Pink Extortion Group, a threat actor that uses voice phishing to bypass multi-factor authentication and steal files from cloud environments.
  • ✇Firewall Daily – The Cyber Express
  • PAN-OS Flaw CVE-2026-0300 Exposes Firewalls to Remote Code Execution Ashish Khaitan
    A newly disclosed cybersecurity issue, tracked as CVE-2026-0300, has drawn urgent attention due to its critical severity and active exploitation. The flaw affects PAN-OS, the operating system used in Palo Alto Networks firewalls, and has been categorized as a buffer overflow vulnerability with serious implications for enterprise security environments.  The CVE-2026-0300 PAN-OS vulnerability was officially published on May 6, 2026, and updated the same day after being discovered in real-world
     

PAN-OS Flaw CVE-2026-0300 Exposes Firewalls to Remote Code Execution

Buffer Overflow Vulnerability

A newly disclosed cybersecurity issue, tracked as CVE-2026-0300, has drawn urgent attention due to its critical severity and active exploitation. The flaw affects PAN-OS, the operating system used in Palo Alto Networks firewalls, and has been categorized as a buffer overflow vulnerability with serious implications for enterprise security environments.  The CVE-2026-0300 PAN-OS vulnerability was officially published on May 6, 2026, and updated the same day after being discovered in real-world production environments. It carries a CVSS score of 9.3, placing it firmly in the “critical” category. The issue stems from a buffer overflow vulnerability in the User-ID Authentication Portal, also known as the Captive Portal service, within PAN-OS.  This flaw allows an unauthenticated attacker to execute arbitrary code with root privileges by sending specially crafted network packets. Because the attack requires no authentication, no user interaction, and can be carried out over the network with low complexity, the exposure risk is considered extremely high. 

Technical Details of the Buffer Overflow Vulnerability in PAN-OS 

The root cause of CVE-2026-0300 PAN-OS is classified under CWE-787: Out-of-bounds Write, a common but dangerous type of buffer overflow vulnerability. Attackers can exploit this flaw to overwrite memory and potentially take full control of affected systems.  The vulnerability impacts PA-Series and VM-Series firewalls when the User-ID™ Authentication Portal is enabled. Importantly, Prisma Access, Cloud NGFW, and Panorama appliances are not affected.  Security data associated with the vulnerability highlights the following: 
  • Attack Vector: Network  
  • Attack Complexity: Low  
  • Privileges Required: None  
  • User Interaction: None  
  • Confidentiality, Integrity, Availability Impact: High  
Additionally, the vulnerability is automatable and has already reached the “ATTACKED” stage in exploit maturity, indicating that real-world attacks have been observed. 

Active Exploitation and Risk Factors 

Evidence shows limited exploitation of CVE-2026-0300 PAN-OS, particularly targeting systems where the User-ID Authentication Portal is exposed to untrusted networks or the public internet. Environments that allow external access to this portal face the highest level of risk. The severity is further highlighted by the CVSS vector:  CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H  This translates to a scenario where attackers can remotely compromise systems without needing credentials or user involvement, leveraging the buffer overflow vulnerability to gain root-level access. 

Affected and Unaffected Versions 

Multiple versions of PAN-OS are impacted by CVE-2026-0300, including: 
  • PAN-OS 12.1 versions prior to 12.1.4-h5 and 12.1.7  
  • PAN-OS 11.2 versions prior to 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, and 11.2.12  
  • PAN-OS 11.1 versions prior to 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, and 11.1.15  
  • PAN-OS 10.2 versions prior to 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, and 10.2.18-h6  
Patches are scheduled with estimated availability dates ranging from May 13 to May 28, 2026. Cloud NGFW and Prisma Access deployments remain unaffected. 

Mitigation and Workarounds 

While patches are being rolled out, organizations are advised to take immediate steps to reduce exposure to the buffer overflow vulnerability in PAN-OS.  Recommended mitigations include: 
  • Restricting access to the User-ID Authentication Portal to trusted internal IP addresses only  
  • Preventing any exposure of the portal to the public internet  
  • Disabling the User-ID Authentication Portal entirely if it is not required  
The risk associated with CVE-2026-0300 PAN-OS drops significantly when these best practices are implemented. Systems that already follow strict network segmentation and access control policies are at a much lower risk. 
  • ✇Krebs on Security
  • Anti-DDoS Firm Heaped Attacks on Brazilian ISPs BrianKrebs
    A Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has been enabling a botnet responsible for an extended campaign of massive DDoS attacks against other network operators in Brazil, KrebsOnSecurity has learned. The firm’s chief executive says the malicious activity resulted from a security breach and was likely the work of a competitor trying to tarnish his company’s public image. An Archer AX21 router from TP-Link. Image: tp-link.com.
     

Anti-DDoS Firm Heaped Attacks on Brazilian ISPs

30 de Abril de 2026, 11:04

A Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has been enabling a botnet responsible for an extended campaign of massive DDoS attacks against other network operators in Brazil, KrebsOnSecurity has learned. The firm’s chief executive says the malicious activity resulted from a security breach and was likely the work of a competitor trying to tarnish his company’s public image.

An Archer AX21 router from TP-Link. Image: tp-link.com.

For the past several years, security experts have tracked a series of massive DDoS attacks originating from Brazil and solely targeting Brazilian ISPs. Until recently, it was less than clear who or what was behind these digital sieges. That changed earlier this month when a trusted source who asked to remain anonymous shared a curious file archive that was exposed in an open directory online.

The exposed archive contained several Portuguese-language malicious programs written in Python. It also included the private SSH authentication keys belonging to the CEO of Huge Networks, a Brazilian ISP that primarily offers DDoS protection to other Brazilian network operators.

Founded in Miami, Fla. in 2014, Huge Networks’s operations are centered in Brazil. The company originated from protecting game servers against DDoS attacks and evolved into an ISP-focused DDoS mitigation provider. It does not appear in any public abuse complaints and is not associated with any known DDoS-for-hire services.

Nevertheless, the exposed archive shows that a Brazil-based threat actor maintained root access to Huge Networks infrastructure and built a powerful DDoS botnet by routinely mass-scanning the Internet for insecure Internet routers and unmanaged domain name system (DNS) servers on the Web that could be enlisted in attacks.

DNS is what allows Internet users to reach websites by typing familiar domain names instead of the associated IP addresses. Ideally, DNS servers only provide answers to machines within a trusted domain. But so-called “DNS reflection” attacks rely on DNS servers that are (mis)configured to accept queries from anywhere on the Web. Attackers can send spoofed DNS queries to these servers so that the request appears to come from the target’s network. That way, when the DNS servers respond, they reply to the spoofed (targeted) address.

By taking advantage of an extension to the DNS protocol that enables large DNS messages, botmasters can dramatically boost the size and impact of a reflection attack — crafting DNS queries so that the responses are much bigger than the requests. For example, an attacker could compose a DNS request of less than 100 bytes, prompting a response that is 60-70 times as large. This amplification effect is especially pronounced when the perpetrators can query many DNS servers with these spoofed requests from tens of thousands of compromised devices simultaneously.

A DNS amplification attack, illustrated. It shows an attacker on the left, sending malicious commands to a number of bots to the immediate right, which then make spoofed DNS queries with the source address as the target's IP address.

A DNS amplification and reflection attack, illustrated. Image: veracara.digicert.com.

The exposed file archive includes a command-line history showing exactly how this attacker built and maintained a powerful botnet by scouring the Internet for TP-Link Archer AX21 routers. Specifically, the botnet seeks out TP-Link devices that remain vulnerable to CVE-2023-1389, an unauthenticated command injection vulnerability that was patched back in April 2023.

Malicious domains in the exposed Python attack scripts included DNS lookups for hikylover[.]st, and c.loyaltyservices[.]lol, both domains that have been flagged in the past year as control servers for an Internet of Things (IoT) botnet powered by a Mirai malware variant.

The leaked archive shows the botmaster coordinated their scanning from a Digital Ocean server that has been flagged for abusive activity hundreds of times in the past year. The Python scripts invoke multiple Internet addresses assigned to Huge Networks that were used to identify targets and execute DDoS campaigns. The attacks were strictly limited to Brazilian IP address ranges, and the scripts show that each selected IP address prefix was attacked for 10-60 seconds with four parallel processes per host before the botnet moved on to the next target.

The archive also shows these malicious Python scripts relied on private SSH keys belonging to Huge Networks’s CEO, Erick Nascimento. Reached for comment about the files, Mr. Nascimento said he did not write the attack programs and that he didn’t realize the extent of the DDoS campaigns until contacted by KrebsOnSecurity.

“We received and notified many Tier 1 upstreams regarding very very large DDoS attacks against small ISPs,” Nascimento said. “We didn’t dig deep enough at the time, and what you sent makes that clear.”

Nascimento said the unauthorized activity is likely related to a digital intrusion first detected in January 2026 that compromised two of the company’s development servers, as well as his personal SSH keys. But he said there’s no evidence those keys were used after January.

“We notified the team in writing the same day, wiped the boxes, and rotated keys,” Nascimento said, sharing a screenshot of a January 11 notification from Digital Ocean. “All documented internally.”

Mr. Nascimento said Huge Networks has since engaged a third-party network forensics firm to investigate further.

“Our working assessment so far is that this all started with a single internal compromise — one pivot point that gave the attacker downstream access to some resources, including a legacy personal droplet of mine,” he wrote.

“The compromise happened through a bastion/jump server that several people had access to,” Nascimento continued. “Digital Ocean flagged the droplet on January 11 — compromised due to a leaked SSH key, in their wording — I was traveling at the time and addressed it on return. That droplet was deprecated and destroyed, and it was never part of Huge Networks infrastructure.”

The malicious software that powers the botnet of TP-Link devices used in the DDoS attacks on Brazilian ISPs is based on Mirai, a malware strain that made its public debut in September 2016 by launching a then record-smashing DDoS attack that kept this website offline for four days. In January 2017, KrebsOnSecurity identified the Mirai authors as the co-owners of a DDoS mitigation firm that was using the botnet to attack gaming servers and scare up new clients.

In May 2025, KrebsOnSecurity was hit by another Mirai-based DDoS that Google called the largest attack it had ever mitigated. That report implicated a 20-something Brazilian man who was running a DDoS mitigation company as well as several DDoS-for-hire services that have since been seized by the FBI.

Nascimento flatly denied being involved in DDoS attacks against Brazilian operators to generate business for his company’s services.

“We don’t run DDoS attacks against Brazilian operators to sell protection,” Nascimento wrote in response to questions. “Our sales model is mostly inbound and through channel integrator, distributors, partners — not active prospecting based on market incidents. The targets in the scripts you received are small regional providers, the vast majority of which are neither in our customer base nor in our commercial pipeline — a fact verifiable through public sources like QRator.”

Nascimento maintains he has “strong evidence stored on the blockchain” that this was all done by a competitor. As for who that competitor might be, the CEO wouldn’t say.

“I would love to share this with you, but it could not be published as it would lose the surprise factor against my dishonest competitor,” he explained. “Coincidentally or not, your contact happened a week before an important event – ​​one that this competitor has NEVER participated in (and it’s a traditional event in the sector). And this year, they will be participating. Strange, isn’t it?”

Strange indeed.

  • ✇Security Boulevard
  • Unauthorized Users Reportedly Gain Access to Anthropic’s Mythos AI Model Jeffrey Burt
    A group of unauthorized users reportedly has gained access to Anthropic’s controversial Claude Mythos Preview AI frontier model despite the AI vendor’s efforts to keep it out of public hands by limiting the organizations that can use it. Bloomberg reported that the unnamed group had tried multiple ways to gain access to the AI model.. The post Unauthorized Users Reportedly Gain Access to Anthropic’s Mythos AI Model appeared first on Security Boulevard.
     
  • ✇Arstechnica
  • Researchers disclose vulnerabilities in IP KVMs from four manufacturers Dan Goodin
    Researchers are warning about the risks posed by a low-cost device that can give insiders and hackers unusually broad powers in compromising networks. The devices, which typically sell for $30 to $100, are known as IP KVMs. Administrators often use them to remotely access machines on networks. The devices, not much bigger than a deck of cards, allow the machines to be accessed at the BIOS/UEFI level, the firmware that runs before the loading of the operating system. This provides power and conve
     

Researchers disclose vulnerabilities in IP KVMs from four manufacturers

17 de Março de 2026, 14:07

Researchers are warning about the risks posed by a low-cost device that can give insiders and hackers unusually broad powers in compromising networks.

The devices, which typically sell for $30 to $100, are known as IP KVMs. Administrators often use them to remotely access machines on networks. The devices, not much bigger than a deck of cards, allow the machines to be accessed at the BIOS/UEFI level, the firmware that runs before the loading of the operating system.

This provides power and convenience to admins, but in the wrong hands, the capabilities can often torpedo what might otherwise be a secure network. Risks are posed when the devices—which are exposed to the Internet—are deployed with weak security configurations or surreptitiously connected to by insiders. Firmware vulnerabilities also leave them open to remote takeover.

Read full article

Comments

© Getty Images

❌
❌