Search/kde
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
kmplayer
Connections
72 relationships
OpenMandriva Linux says contributor tried to sabotage the project
The OpenMandriva Linux project announced that it was the target of an attempted act of internal sabotage after a dispute among contributors. The attempted destructive action extended from wiping GitHub repositories to pushing an empty package that could have damaged users' systems. OpenMandriva is an independent, community-run Linux distribution, forked from Mandriva Linux in 2012 and maintained by the OpenMandriva Association. The distro stands out for building most of its components with the LLVM/Clang toolchain instead of GCC, which is commonly used by most Linux distributions. According to a post on the project's forum from long-time OpenMandriva developer and maintainer AngryPenguin, the sabotage attempt occurred after a contributor's abusive behavior "towards certain users and members of the distribution," which caused some of them to leave the project. Following these events, Davide Beatrici, the leading developer of the instant messaging app Mumble and a friend of the attacker, decided to delete part of a repository the OpenMandriva team had been working on for almost a decade. AngryPenguin stated that Beatrici had administrative privileges because he previously helped migrate and mirror project repositories to his private OneDev instance. Apart from the data wipe, Beatrici also published an empty package in the Cooker repository that obsoleted the packages for the Gnome and Cosmic desktop environments. The OpenMandriva team says it is currently restoring the deleted repositories and packages and is conducting a full system audit to determine any other unauthorized changes. BleepingComputer has contacted Beatrici directly, as well as through the Mumble team, requesting his side of the story, but we have not heard back as of publishing. However, Beatrici rejected the sabotage claims in a statement for The Lunduke Journal, saying that his goal was never to harm the OpenMandriva community or the distribution’s users. "Let me state right away that this was by no means a 'sabotage.’ I'm not the kind of person to do something like that," Beatrici stated. "The objective was not to harm the distribution I cared for and contributed to for the past 3 years. I carefully deleted all Cosmic and GNOME repositories from GitHub, the corresponding packages on Cooker (development branch) and pushed a package obsoleting them." As Beatrici says, this action was triggered by a few members of the project who did not agree with OpenMandriva's focus on KDE and LXQt. "The same members, who notably don't care about security nor a clean Git commit history, decided to delete the ".onedev-buildspec.yml" file from several repositories without asking/informing me or anyone else first," the developer said. AngryPenguin stated on behalf of the OpenMandriva team that although Beatrici’s actions constitute a criminal offense, they have decided not to pursue legal action against the former contributor. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 9, 2026extracted
KDE Plasma: PoC pubblico per lo sfruttamento di una vulnerabilità
KDE Plasma: PoC pubblico per lo sfruttamento di una vulnerabilità Alert AL04/260703/CSIRT-ITA Sintesi Disponibile un Proof of Concept (PoC) per una vulnerabilità, presente in KDE Plasma, ambiente desktop (interfaccia) open source per sistemi operativi basati su Linux. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato di eludere i meccanismi di sicurezza ed eseguire codice arbitrario sui sistemi interessati. Tipologia Security Feature Bypass Arbitrary Code Execution Descrizione e potenziali impatti È stato recentemente reso pubblico un Proof of Concept (PoC) per una vulnerabilità di tipo Arbitrary Code Execution con score CVSS v3.1 stimabile pari a 8.2. Tale vulnerabilità è dovuta a una gestione non adeguata dei parametri forniti in input dall'utente relativi all’identificativo dell’applicazione (app_id) e alla riga di comando /proc/[PID]/cmdline, che viene letta in modo non convalidato durante l’attivazione dell’azione. Utilizzando l’azione “apri nuova finestra” per una applicazione, combinando il PID ottenuto dalla console di debug di KWin con le informazioni sui control group e sulla rootfs ricavate dal procfs, risulterebbe possibile eludere i meccanismi ci controllo della sandbox ed eseguire comandi sul sistema sottostante. Prodotti e/o versioni affette KDE Plasma Versione 6.7 e precedenti Azioni di mitigazione In assenza del rilascio delle correttive di sicurezza, si raccomanda di valutare l'implementazione delle seguenti azioni preventive, al fine di ridurre la superficie di attacco disabilitare i menu contestuali dei widget di Plasma mediante, la creazione o la modifica del file di configurazione globale delle restrizioni. Tale configurazione limita l'accesso all'azione "apri nuova finestra " quando questa è esposta tramite il menu contestuale della taskbar ma, tuttavia, non elimina la vulnerabilità, che interessa la logica di gestione dell'azione "apri nuova finestra" in libtaskmanager e che potrebbe rimanere raggiungibile attraverso altri meccanismi di attivazione.
acn.gov.itJul 3, 2026extracted
Kali Linux 2026.2 released with 9 new tools, NetHunter updates
Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. The Kali Linux distro is designed for cybersecurity professionals and ethical hackers and comes with tools for security audits, penetration testing, and network research. Kali Linux is available as an installable operating system or as a live environment, and supports a wide range of hardware, including Raspberry Pi devices and Android phones via Kali NetHunter. In the 2026.2 release, in addition to new tools and improvements to the NetHunter penetration testing platform for Android devices, the Kali Team has also added updated helper scripts, desktop environments updates, and VM boot tweaks. New tools added to Kali Linux 2026.2 In this release, the Kali Team has updated numerous packages, added new libraries, and upgraded the Kali kernel to 6.19 (with the 7.0 kernel available in kali-experimental). It has also added 9 new tools to the network repositories, including: arsenal-ng - Go-based command library equipped with 200+ cybersecurity cheat-sheets hydra-gtk - [Re-added] Very fast network logon cracker - GTK+ based GUI legba - Multiprotocol credentials bruteforcer / password sprayer and enumerator oletools - Analyze MS OLE2 files and MS Office documents penelope - Powerful shell handler shell-gpt - Command-line productivity tool powered by AI large language models tailscale - Secure connectivity platform tookie-osint - OSINT information gathering tool for finding social media accounts uro - Declutter URLs for crawling/pentesting The Kali Team has also updated the services helper scripts, making it easier to manage services, check if they're running, track service status, list default credentials, and get info on how to access running services. Starting with this release, Kali Linux pre-built VM images no longer include graphics firmware, and installer images can detect when installation occurs in a virtual machine to ensure graphics firmware is not installed. "As a result, the initrd is down to 60 MB for VM users, and the boot time is cut by ~3x (tested for QEMU VM on a Linux host, your mileage may vary). That's a massive improvement in boot time," the Kali Team said. For baremetal users: nothing changed, so you still get a 200 MB initrd with all graphics firmware pre-installed. If you'd like to optimize, it's on you to uninstall the firmware that you don't need." The Kali desktop environments have also been updated, with the distro now shipping with GNOME 50 and KDE Plasma 6.6. Kali NetHunter Updates Besides the new tools, Kali Linux 2026.2 also introduces a long list of NetHunter updates, including but not limited to: Magisk standalone kernel flashing support, new kernels with qcacld3 injection support, kernels for more versions and phones, and bare metal support on more phones via NetHunter Pro. "The Kali NetHunter app launches instantly now, various bugs have been fixed with the custom commands and chroot manager. A new EvilTwin (Wi-Fi Fake AP) tab has been added with password verification captive portal, which brought along a really needed iptables fix. So now after using Wifipumpkin3 or EvilTwin, Android Hotspot will work properly," the Kali Team added. "The Magisk standalone kernel flashing support is now here - you can simply open any newly built kernel installer zip in the Magisk app that was built using the kali-nethunter-installer." How to get Kali Linux 2026.2 To start using Kali Linux 2026.2, you can upgrade your existing installation, select a platform, or directly download ISO images for new installs and live distributions. Kali users who want to update from a previous version can use the following commands to upgrade to the latest version. echo "deb http://http.kali.org/kali kali-rolling main contrib non-free non-free-firmware" | sudo tee /etc/apt/sources.list sudo apt update && sudo apt -y full-upgrade cp -vrbi /etc/skel/. ~/ [ -f /var/run/reboot-required ] && sudo reboot -f If you're using Kali on Windows Subsystem for Linux, you should consider upgrading to WSL 2 for better support of graphical apps. To check your WSL version, run wsl -l -v in a Windows command prompt. After upgrading, you can check whether the process was successful using the following command: grep VERSION /etc/os-release. You can view the complete changelog for the Kali Linux 2026.2 release on Kali's website. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 30, 2026extracted
Kali Linux 2026.2 trims VM boot times, refreshes its desktops
Kali Linux 2026.2 trims VM boot times, refreshes its desktops Penetration testers who run Kali Linux inside virtual machines boot their systems faster after the 2026.2 release. The change comes from a decision about graphics firmware, the code that drives NVIDIA, AMD, and Intel GPUs. That firmware has grown large enough to slow the early stages of startup, and few virtual machines need it. Kali images traditionally shipped with a broad set of firmware so hardware worked out of the box. Graphics firmware alone now reaches almost 300 MB. Parts of it load very early in startup, which placed them in the initrd, the small system the kernel reads at boot. A heavier initrd slows startup and can crowd a small /boot partition. The Kali initrd had climbed to around 200 MB. Pre-built VM images now omit graphics firmware, and the installer detects a virtual machine and skips that firmware during setup. The initrd for VM users drops to 60 MB, and boot time on a QEMU virtual machine running on a Linux host falls to roughly a third. Baremetal installs keep all the graphics firmware. New desktop versions Every other Kali release brings a major desktop update, and this cycle covers GNOME and KDE Plasma. GNOME moves to version 50. Its file manager gained optimizations that speed thumbnail and icon loading, improve responsiveness, and lower memory use. The desktop adds accessibility features through a new preferences window, screen reader tweaks, and automatic language switching. The Document Viewer app supports annotations, so users can add notes and highlights to documents. KDE Plasma reaches version 6.6 with a focus on usability and accessibility. A new on-screen keyboard improves the experience on touch devices. The Spectacle screenshot utility can recognize and extract text from screenshots, putting OCR on the desktop. Plasma also adds color-vision options, Zoom and Magnifier improvements, Slow Keys support on Wayland, and the standardized Reduced Motion setting. More consistent service helper scripts Many Kali tools depend on a background service, and their helper scripts now behave the same way across packages. A script can start or stop the service, check whether it already runs, show its status, display any default credentials, and point to a web UI by opening the URL in the browser. Kali packages that include a service use a tool-start and tool-stop naming pattern for their commands. A new APT sources format Kali retires the long-standing /etc/apt/sources.list file in favor of /etc/apt/sources.list.d/kali.sources. The new file uses the deb822 style, which spreads the repository definition across labeled fields such as Types, URIs, Suites, and Components. Fresh installs receive the new format. Existing systems continue with the old file, which works the same way, and a future APT version will warn when the old file is in use and recommend the new one. Debian and its derivatives are making the same shift, and Kali follows that course. Reboots for polkit and xrdp Two package updates call for a system reboot. The polkitd update requires one, and GUI applications started as root will fail with cryptic errors until the reboot happens. The hint appears in the upgrade logs, buried among other output. Users who need to restore root application access afterward can enable the polkit-agent-helper socket. The xrdp and xorgxrdp packages move to the v0.10 series, and xrdp users need a reboot after the upgrade. People who run Kali in Hyper-V with Enhanced Session Mode count as xrdp users. Some report that xrdp stops working after the upgrade, and toggling Hyper-V Enhanced Session Mode off and on through kali-tweaks can restore it. Kernel 6.19, with 7.0 available Kali ships with the 6.19 kernel this release. Recent vulnerability disclosures, among them Copy Fail and Dirty Frag, supported moving to the newest kernel. The 7.0 kernel showed incompatibility with the NVIDIA DKMS drivers in Debian. The team chose 6.19 to keep NVIDIA users working and placed the 7.0 kernel in kali-experimental for anyone who wants it. Nine new tools and NetHunter work The release adds nine tools to the network repositories. They include arsenal-ng, a Go command library carrying a couple hundred cybersecurity cheat-sheets; legba, a multiprotocol credentials bruteforcer; oletools for analyzing MS Office documents; shell-gpt, a command-line tool powered by large language models; and tailscale for secure connectivity. The hydra-gtk GUI returns as well. On mobile, the NetHunter app launches instantly and gains an EvilTwin Wi-Fi fake access point tab. The release begins a wave of Qcacld-3.0 injection support, bringing packet injection to devices such as the OnePlus 7, POCO X3 Pro, and Xiaomi Mi A3. Kali also welcomed its first mirror in Africa, hosted in South Africa. Must read: 25 open-source cybersecurity tools that don’t care about your budget GitHub CISO on security strategy and collaborating with the open-source community Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comJun 30, 2026extracted
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. "This attack avoids the most common npm execution paths through lifecycle scripts, perhaps in an attempt to remain 'compatible' with npm v12's security hardenings," JFrog said in a technical analysis. "The package hides execution inside a VS Code task, configured to run automatically when the project folder is opened in VS Code. From there, the malware retrieves encrypted JavaScript from blockchain transaction data, connects to attacker-controlled infrastructure, launches a socket.io backdoor, and eventually deploys a Python infostealer. The names of the identified npm packages are listed below - html-to-gutenberg fetch-page-assets (which lists html-to-gutenberg as a dependency) The two packages were uploaded to npm on May 25, 2026, and are no longer available for download from the registry. The starting point of the attack is a hidden Microsoft Visual Studio Code (VS Code) task named "eslint-check" that's configured with the "runOn: 'folderOpen'" option to trigger the execution of arbitrary code when the folder is opened as a workspace folder in an IDE like VS Code or Cursor. "They do not recursively execute every nested .vscode/tasks.json; in this case, the trigger fires when the malicious package directory itself is opened as the workspace and marked as trusted, or that the developer explicitly allowed automatic tasks," JFrog said. "The command also disguises the payload as a font file - public/fonts/fa-solid-400.woff2, even though the file just contains JavaScript code." It's worth noting that the abuse of a VS Code auto-run task, coupled with the disguise of JavaScript malware as font files, has been attributed to North Korea. The OpenSourceMalware team, which is tracking the activity under the moniker Fake Font, has described it as a variant of Contagious Interview, a long-running campaign targeting software developers and technical personnel through fraudulent job interview processes. "This 'Fake Font' campaign delivers a multi-stage loader that ultimately deploys the InvisibleFerret Python backdoor, designed to steal cryptocurrency wallets, browser credentials, and establish persistent access," security researcher Paul McCarty noted back in January. "This is the third sub-campaign of the Contagious Interview' campaign that has been ongoing since 2023." The bogus font file uses blockchain infrastructure as a dead drop resolver, relying on TronGrid and Aptos as a fallback mechanism to fetch a next-stage JavaScript payload in a manner that's resilient to takedown efforts. The JavaScript stage repeats the same dead drop retrieval pattern to configure a command-and-control (C2) server that enables file uploads and Python malware delivery. This includes setting up a Socket.io backdoor that grants the operator remote control over the infected host through features like shell execution, clipboard harvesting, file system operations, file upload, process management, and arbitrary JavaScript execution. In parallel, the infection chain launches a Python loader component that's responsible for retrieving the Python infostealer from the C2 server and installing the necessary dependencies. The artifact is a wide-ranging credential, browser, wallet, and developer artifact stealer that can siphon data stored in Chromium-based and Mozilla Firefox browsers, password managers, authenticators, and cryptocurrency wallets. It's also equipped to harvest developer-oriented information like Git credentials, GitHub CLI hosts.yml, GitHub Desktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keychain, and cloud storage metadata for Dropbox, Google Drive, Microsoft OneDrive, Apple iCloud, Box, Mega, and pCloud. In the final stage, the collected data is packaged into compressed ZIP archives and uploaded to the C2 server, and to a Telegram bot if a bot token is provided by the attacker during runtime. The campaign has also targeted the Go ecosystem, with Nextron Systems discovering a set of 16 Go packages containing the same malware. The list is as follows - github.com/lambda-platform/lambda github.com/reauheau/goaubio github.com/glacialspring/go-winsparkle github.com/bm-197/chill github.com/naol7/dist-task-scheduler github.com/anatoli-derese/a2sv-excercise github.com/amantsehay/a2sv-go-course github.com/dexbotsdev/uniswap-v2-v3-arbitrage github.com/lambda-platform/ebarimt-rest-api github.com/lambda-platform/dan github.com/zainirfan13/graphql-client github.com/hngi/team-fierce-backend-golang github.com/glacialspring/static github.com/rickt/slack-weather-bot github.com/Barsu5489/commerce github.com/Setsu548/Logistic "Most appear to be legitimate packages whose latest released version included the malware alongside the original package contents, using the same structure and fake font file," JFrog added. Users who have installed the packages are advised to remove them with immediate effect, search developer machines for hidden VS Code folder-open tasks, and rotate credentials, tokens, cloud credentials, API keys, browser-stored credentials, and wallet credentials. "The payloads show that the attacker was interested in both immediate theft and interactive access," the cybersecurity company concluded. "The socket.io-based backdoor provides command execution and file collection, while the Python stage performs wide credential and wallet harvesting across browsers, OS credential stores, developer tooling, and cryptocurrency applications." Update When reached for comment, JFrog security researcher Guy Korolevski affirmed the similarities between the latest activity and Fake Font, adding it's "probably an evolution of the previous campaign." While the earlier iteration targeted GitHub users, the new campaign focuses on malicious packages in both npm and Go, the latter of which are hosted on GitHub. "The delivery system changed and shifted to public blockchain infrastructure as a dead drop mechanism, and the lure is malicious packages in both npm and Go," Korolevski noted. (The story was updated after publication to include a response from JFrog.)
thehackernews.comJun 29, 2026extracted
FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances
A vulnerability in the FFmpeg media processing framework allows attackers to crash applications and execute arbitrary code remotely, JFrog warns. FFmpeg is used in most media-processing applications across every platform, including desktop video players, Linux file managers, self-hosted media servers, and cloud transcoding pipelines. Tracked as CVE-2026-8461 (CVSS score of 8.8), the security defect is described as a heap out-of-bounds write within FFmpeg’s libavcodec library, in the MagicYUV decoder. The flaw exists in the MagicYUV decoder’s slice handling and is “caused by an inconsistency between how the frame allocator and the decoder compute chroma plane heights,” JFrog explains. Dubbed PixelSmash, it can be exploited to crash any application that uses FFmpeg. Code execution can be achieved by targeting FFmpeg’s AVBuffer struct, a refcounted buffer management object allocated immediately after each plane’s pixel data. To gain code execution, an attacker needs to target FFmpeg’s AVBuffer struct, a refcounted buffer management object allocated immediately after each plane’s pixel data. According to JFrog, by placing a NUL-terminated shell command at a specific out-of-bounds offset, an attacker can obtain shell execution before the FFmpeg process crashes on subsequent heap corruption. PixelSmash can be exploited for remote code execution (RCE) via crafted media files delivered to any application that uses FFmpeg’s libavcodec for video decoding. On desktop, the vulnerability is triggered when the user opens the malicious file in a video player, or when they browse to a folder containing it, if the file manager’s thumbnail generator uses the vulnerable library. Code execution on a server is achieved when the media file is uploaded to a media server, chat platform, or cloud transcoding service, which automatically processes it. The bug can also be exploited on NAS appliances, media appliances, and smart TVs that generate video thumbnails or previews. “No authentication, special privileges, or prior access to the target system is required beyond the ability to deliver a media file – the default attack surface for any media-processing application,” JFrog explains. The exploit payload can be delivered as a 50 KB AVI, MKV, or MOV file. It can be used in zero-click attacks over torrents if the victim has their torrent client set to download media files directly into a monitored media library folder. As soon as the torrent finishes, the automated library scanning executes the payload. On the self-hosted cloud storage platform Nextcloud, which uses an independent FFmpeg build, the vulnerability can be triggered via the optional Movie preview provider, which invokes the system FFmpeg binary to generate thumbnails. “The attacker requires no interaction beyond ensuring the file is visible in a folder listing; the server-side processing handles the rest, making this a near-zero-click vector,” JFrog notes. The cybersecurity firm confirmed successful exploitation of the bug against Kodi, mpv, ffmpegthumbnailer (used by GNOME, KDE, XFCE), Jellyfin, Emby, Nextcloud, Immich, PhotoPrism, and OBS Studio. It also demonstrated successful RCE against Jellyfin. FFmpeg version 8.1.2 contains fixes for PixelSmash. Users are advised to update as soon as possible. Related: Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data Related: Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data Related: New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones Related: Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure
securityweek.comJun 23, 2026extracted
FFmpeg fixes PixelSmash flaw in widely used video decoder
A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. The vulnerability is tracked as CVE-2026-8461 and is a heap out-of-bounds write in the MagicYUV decoder. It received a high-severity score of 8.8 and can be leveraged via a malicious video file in AVI, MKV, or MOV format. Any application that uses libavcodec, FFmpeg’s core library for video decoding and encoding, is considered vulnerable. However, exploitation for remote code execution (RCE) is possible if the Address Space Layout Randomization (ASLR) defense is disabled or by chaining another vulnerability to defeat the protection. Root cause and impact Researchers at software supply-chain security company JFrog say that PixelSmash stems from the way MagicYUV processes slices, independent regions of a video frame that can be decoded separately from the rest of the image. "The vulnerability is a one-row heap buffer overflow in the MagicYUV decoder’s slice handling, caused by an inconsistency between how the frame allocator and the decoder compute chroma plane heights," JFrog explains. PixelSmash can be triggered when the user opens AVI, MKV, or MOV video files, browses a directory containing the file (via thumbnail generation), or runs any automated media ingestion workflow. JFrog found that multiple popular media applications, such as Kodi, OBS Studio, PhotoPrism, and GNOME/KDE/XFCE’s thumbnail generators, use FFmpeg with the MagicYUV decoder enabled, making them vulnerable to PixelSmash attacks. Slack, Discord, Telegram, and WhatsApp may also be susceptible to PixelSmash attacks, as they use FFmpeg to generate server-side video previews, but they were not tested. JFrog lead researcher Yuval Moravchick demonstrated that PixelSmash can be used for remote code execution on Jellyfin and Nextcloud (with Movie preview enabled) instances. “To demonstrate the real-world impact, we achieved full remote code execution against a Jellyfin 10.11.9 media server - the second-most popular self-hosted media server (after Plex) - through its normal media library scan pipeline,” JFrog says. “Attack path: a download of a crafted MagicYUV AVI into the media library -> Jellyfin automatically triggers ffprobe for metadata extraction -> the OOB write fires -> AVBuffer.free is hijacked to system() -> arbitrary command executes as the jellyfin service user.” However, Moravchick noted that the RCE exploit requires ASLR (Address Space Layout Randomization) to be disabled, and that CVE-2026-8461 alone does not bypass this memory protection. In theory, a separate information-disclosure bug in FFmpeg's FlashSV decoder could be chained with PixelSmash to bypass ASLR. Another attack scenario is via torrent downloads and requires no user interaction. The researchers say that an attacker could seed a malicious video that targets Jellyfin users who point the download to the application's media library folder. "Jellyfin’s real-time file system monitor detects the new file and automatically triggers an ffprobe metadata scan. The exploit fires during the scan - AVBuffer.free is hijacked to system(), and the attacker’s reverse shell command executes as the jellyfin service user" Even when RCE is prevented or impossible, the CVE-2026-8461 vulnerability should be sufficient to reliably achieve a denial-of-service (DoS) condition on vulnerable targets. The researchers found that Plex, the massively popular media server, uses a custom FFmpeg build in which decoders are disabled and a minimal allowlist is in effect, effectively mitigating the PixelSmash risk. Apart from FFmpeg releasing version 8.1.2, which fixes the flaw, Jellyfin also updated its bundled FFmpeg version, and PhotoPrism is working to add a file format blocklist to prevent potential exploitation. The Nextcloud team received the report via HackerOne, but declined to address the flaw because it exists outside of Nextcloud. JFrog discovered PixelSmash (CVE-2026-8461) and reported it to the FFmpeg security team on May 13. The developer addressed the issue in version 8.1.2, released on June 17. The researchers warn that PixelSmash has a huge attack surface because the MagicYUV decoder is present in hundreds of projects that "trust FFmpeg to handle untrusted input safely," turning the vulnerability into a supply-chain problem. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 22, 2026extracted
Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecast
Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecast Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory Agent Memory Guard is an open-source runtime defense layer that sits between an agent and its memory store, screening every read and write through a pipeline of detectors and a YAML policy. The project is the OWASP reference implementation for ASI06, Memory Poisoning, one entry in the OWASP Top 10 for Agentic Applications. Data discovery gaps that catch enterprises off guard In this interview with Help Net Security, Avani Desai, CEO at Schellman, talks about the gap between what organizations think they know about their data and what discovery scans turn up. She shares stories of shadow data in abandoned cloud storage, post-merger surprises where duplicated datasets slowed integration, and why synthetic data is overmarketed while confidential computing stays underappreciated. Zero trust physical security needs trust decisions at the edge In this interview with Help Net Security, Chuck Davis, VP, Global Information Security at Hikvision, explains how zero trust applies to physical security systems like cameras and door controllers. He breaks down how to make trust decisions at the edge without recreating old perimeter assumptions, why these devices should be treated as IT assets, and what the Mirai botnet taught the industry. A small Slovenian team handles 6,000 cyber incidents a year Online fraud complaints, ransomware cases, and phishing tips reach Slovenia’s national cyber response center in steady volume, and a team of around a dozen analysts sorts through them. Gorazd Božič, who manages SI-CERT at the public agency ARNES, described that work in an interview conducted in person at the Span Cyber Security Arena conference. He put the original proposal for a Slovenian CERT to ARNES leadership in 1994, and the center now records about 6,000 incidents a year, up from roughly 300 ten to fifteen years earlier. Only 11% of production agents pass the AI agent security bar Enterprise teams are running AI agents that write code, drive browsers, answer customer calls, manage cloud infrastructure, and query data warehouses with standing credentials. A new independent assessment of 100 production agents finds that nearly all of them carry the conditions for a single hostile document to take them over. Spotless compliance evidence can still hide a broken control In this interview with Help Net Security, Marc Rubbinaccio, Head of Cybersecurity and Compliance at Secureframe, explains where security teams go wrong when preparing for CMMC and FedRAMP 20x. The conversation covers how organizations check the 110 requirements but miss the 320 assessment objectives beneath them, why spotless SOC 2 evidence can hide a broken control, and how continuous monitoring is changing compliance work. OAuth marketplace apps keep access after publishers vanish Installing an app from the Google Workspace Marketplace or GitHub Marketplace can grant a third party access to company email, files, calendars, code repositories, CI workflows, organization settings, and secrets. Marketplace presence gives these apps the appearance of approval. The OAuth grants behind them often reach into business systems beyond the listed function. Thieves can pull off keyless car theft in under a minute and here’s how to stop them A keyless car can be stolen in under a minute. Two people, a pair of cheap radio amplifiers, and a fob sitting on a hallway table inside the house. That is enough. No broken glass. No alarm. No sound. The vulnerability runs across the global market. Germany’s largest auto club, ADAC, runs ongoing tests of keyless models against relay attacks. AgentGG: Open-source agentic SAST scanner Static analysis tools have spent years matching source code against known-bad patterns and handing engineers long lists of candidate issues to triage by hand. AgentGG approaches the same job with AI agents that read the code, follow imports, walk the call graph, and confirm a finding before they report it. The project is an open-source agentic SAST scanner released under the Apache 2.0 license. Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) Authentication bypass vulnerabilities (CVE-2026-0257) in Palo Alto Networks’ firewalls that the company disclosed on May 13 have been targeted in “limited exploit attempts”. The good news, though, is that the company hasn’t observed any indication of successful lateral movement from the devices. How NIST fumbled management of the National Vulnerability Database A US federal watchdog has outlined how the National Institute of Standards and Technology (NIST) failed to effectively manage the growing backlog of unprocessed cybersecurity vulnerabilities in the National Vulnerability Database (NVD). Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild, the Centre for Cybersecurity Belgium (CCB) warned last Friday. CVE-2026-41089 is a stack-based buffer overflow vulnerability in Windows Netlogon, the service and protocol that handles authentication and security within a Windows domain environment. Google fixes actively exploited Android vulnerability (CVE-2025-48595) Google has announced the June 2026 Android security updates, which fix a bucketload of vulnerabilities, including a high-severity vulnerability (CVE-2025-48595) in the Android Framework that “may be under limited, targeted exploitation.” Autonomous AI-driven worm can reason its way through corporate networks Researchers at the University of Toronto, the Vector Institute, and the University of Cambridge have built and tested a proof-of-concept AI-driven worm that does not operate on a fixed list of exploits. Instead, it analyzes each target it encounters, reasons about how to attack it, and creates a strategy on the fly, all with the help of a small, free large language model (LLM) running directly on machines it has already compromised. Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245) A 0-day privilege escalation vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager that has yet to be patched by Cisco is being leveraged by attackers. June 2026 Patch Tuesday forecast: Where are the CVEs? Forecast from last month was only partly right. After the Anthropic Mythos announcements and the deluge of newly discovered vulnerabilities from vendors like Mozilla, Microsoft’s updates were standard fare, 65 CVEs reported in Windows 11 and 58 in Windows 10. The modern-day business can learn a lot about risk from this year’s mega events Every year brings its share of global events, but 2026 is proving to be a banner year for mega-scale entertainment. The year got off to a roaring start with the Winter Olympics, and now anticipation is building for the fast-approaching FIFA World Cup. But amid the buzz, have you ever paused to consider the staggering level of risk inherent to such large-scale events? Or how impressive it is that organizers are able to manage that risk so successfully? From critical to controlled: Cutting vulnerabilities in a live manufacturing environment A vulnerability scanner flags a critical CVSS 10 vulnerability on an industrial asset. The report lands in the boss’ inbox and now he wants to know why we’re sitting on a critical vulnerability. In a normal IT environment, you patch it then close the ticket and call it a day. If, however, you’re in OT or dealing with ICS in a live manufacturing facility, it’s rarely that simple. Why you need BAS and autonomous pentesting together A new autonomous penetration testing tool delivers impressive results at first—finding critical issues, uncovering undocumented attack paths, and exposing forgotten accounts. But by the fourth or fifth run, the discoveries dry up. The tool keeps reporting the same stale issues, and the dashboard becomes another source of noise. What seemed like continuous validation quietly turns into a repeat of the same well-worn attack paths. Governing shadow AI without killing innovation In this Help Net Security video, Alan Snyder, CEO at NowSecure, talks about governing shadow AI without stopping innovation. He frames the problem as two opposing forces. Companies need to adopt AI fast because attackers and competitors will outpace them otherwise, but they also need to do it safely. What CISOs need to do about post-quantum migration in the next 24 months In this Help Net Security video, Garfield Jones, SVP Global Strategy and Research, QuSecure, lays out what CISOs should do over the next 24 months. A recent Google paper moved the expected arrival of a cryptographically relevant quantum computer from 2035 to 2029, leaving organizations about two and a half years to prepare. AI agent governance gets harder when agents outnumber your people In this Help Net Security video, Amit Gautam, CTO at Abluva, explains the security risks that autonomous AI agents bring into enterprise environments. EU organizations buckle under rising compliance pressure Cybersecurity governance in the EU is shifting under expanding frameworks such as NIS2 and DORA, while AI raises new questions for security teams. What the future brings is hard to predict, and organizations must find a way to cope. Antonija Vojnović, Governance, Risk and Compliance Department Manager at Span, spoke with Help Net Security at the Span Cyber Security Arena conference about how these regulatory frameworks are shaping compliance priorities and day-to-day decision-making. DNS-AID lets AI agents find and verify each other through DNS AI agents run across many platforms, and each one needs a way to locate and confirm the identity of the others it works with. The Linux Foundation’s DNS-AID project gives them that capability through the Domain Name System, the same address lookup system that has directed internet traffic for decades. The project lets AI agents and Model Context Protocol (MCP) servers use DNS as a global, vendor-neutral directory for publishing, discovering, and verifying one another. Brute-force attack triggers Dashlane account lockouts Password manager Dashlane has confirmed that a brute-force attack targeting user accounts triggered temporary account suspensions and authentication issues. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experiencing login problems. Meta tries to get ahead of scammers before the World Cup begins Football fans are counting down the days until the FIFA World Cup begins, and scammers are doing the same. Last week, the FBI warned that cybercriminals are spoofing FIFA websites to steal personal information, sell fake tickets, and promote fraudulent hospitality packages ahead of the tournament. Sensitive government personnel data posted online, Spanish police arrest suspect The Spanish National Police arrested a man in Granada for allegedly leaking personal data belonging to members of several sensitive state institutions. 64,000 accounts exposed in breach of GTA V cheat service Atlas Menu Atlas Menu, a cheat service for Grand Theft Auto V and Counter-Strike 2, has been added to the Have I Been Pwned database following a data breach that exposed tens of thousands of user records. The incident exposed approximately 64,000 accounts, including email addresses, usernames, IP addresses, support tickets, and passwords hashed with bcrypt. Anthropic expands Project Glasswing to 150 organizations in more than 15 countries Anthropic is expanding Project Glasswing, its cybersecurity initiative built around the Claude Mythos Preview model, by adding about 150 organizations following several weeks of work with its initial group of partners, security firms, open-source maintainers, and government agencies. Malware campaign targeting Minecraft users infects over 116,000 systems A Malware-as-a-Service (MaaS) operation named WeedHack is targeting Minecraft users and allows threat actors to gain remote access to victims’ screens, webcams, and files through a web-based dashboard, McAfee researchers found. Microsoft responds to security challenges facing code, AI agents, and models Microsoft has introduced a series of security tools and capabilities focused on AI-driven vulnerability discovery, AI agents, and AI models. The updates include a multi-agent vulnerability discovery system, new controls for managing and securing AI agents, data protection capabilities, and tools designed to identify potentially vulnerable or compromised AI models before deployment. AI is helping low-skill hackers pull off advanced cyberattacks Anthropic has published an analysis of cyber-related misuse of its AI systems, examining 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026. The company mapped the observed behavior to the MITRE ATT&CK framework, which documents tactics and techniques used by attackers. Attackers obtained encrypted password vaults from some Dashlane user accounts Dashlane has disclosed new details about a brute-force attack that let a threat actor access some customer accounts and copy encrypted vaults. Dashlane said it found no evidence that the attackers compromised its internal systems. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experiencing login problems. 145 AI laws passed in 2025 and privacy teams aren’t catching a break 145 AI-related laws were enacted by state legislatures in 2025, and more than 1,000 additional bills were introduced or revised, according to DataGrail’s Privacy and AI Trends Report 2026. NVIDIA goes open source with a big batch of physical AI agent tools NVIDIA just dropped a big batch of open-source “physical AI” skills and tools, and they’re designed to make a roboticist’s life a whole lot easier. The idea? Take the messy, complicated work behind robots, self-driving cars, vision AI, and industrial digital twins, and break it into bite-sized tasks that AI agents can actually run themselves. Microsoft Defender Vulnerability Management gets a smarter exposure score Microsoft Defender Vulnerability Management’s updated exposure score model adds vulnerability risk signals and asset context to help teams understand where risk is concentrated and which remediation actions are likely to have the greatest impact. The model is available in public preview. This AI model backdoor attack stays hidden until you customize the model Most teams that deploy AI start with a backbone model. They download a large pre-trained system, adapt it to a specific task, and put it into production. The download step carries a security question: the origin of the model. A research team built an attack called BadBone. It plants a backdoor inside a backbone model. Downstream tasks that adapt the model inherit the backdoor. The name points at the target. Corrupt the skeleton, and systems built on top of it carry the flaw. OpenAI brings frontier AI to existing AWS environments OpenAI frontier models and Codex are now available on AWS, giving customers access to OpenAI capabilities within AWS environments and the controls needed to move more quickly from evaluation to deployment. These capabilities are available through OpenAI models on Amazon Bedrock, a platform for building generative AI applications and agents at production scale. The platform enables teams to build AI applications using AWS-native security and governance controls. KDE Linux security audit cuts kernel modules and unused packages KDE Linux, the in-progress operating system from the KDE community, removed several kernel modules and software packages after a security audit of the components shipped with the system. The work followed the discovery of multiple security issues in the upstream Linux kernel during the prior month. Codex knowledge work expands into research, reports, and spreadsheets Office workers in the United States lose hours each week to email triage and to searching for files spread across disconnected systems. Roughly 40 percent of US labor, about 72 million people, works primarily with information such as analysis, documents, designs, and communication. Research from the McKinsey Global Institute puts the average knowledge worker at 28 percent of the workweek on email and close to 20 percent on hunts for internal information or for colleagues who can help with specific tasks. Meta adds stricter guardrails for teen feeds Meta has expanded its Teen Accounts 13+ content settings globally on Instagram, Facebook, and Messenger. The safeguards are designed to help young users see age-appropriate content by default. The company also introduced Limited Content on Instagram for parents seeking stricter restrictions. Meta plans to roll out the feature on Facebook and Messenger later this year. Known vulnerabilities behind most application security incidents Eight in ten organizations took an application security hit during the past year tied to a vulnerability their team had already cataloged, according to a survey of 902 IT and security professionals conducted by the Cloud Security Alliance. The pattern points to a structural condition across the industry, where the window between identifying a flaw and closing it in production stays open long enough for attackers to act. Agent Threat Rules: Open detection rule format for AI agent security threats AI agents run inside coding assistants, MCP servers, and multi-agent frameworks, and the access that makes them useful also opens paths to prompt injection, tool poisoning, and credential theft. Public CVE feeds carry agent-execution flaws that reach production faster than the tooling built to catch them. Agent Threat Rules, or ATR, is an open detection format aimed at this category of attack. Microsoft Scout agent opens a new category of always-on Autopilots Workplace AI assistants have mostly waited for a prompt before doing anything. A user asks, the tool answers, and the exchange ends there. Microsoft is putting a different kind of agent inside its Office applications, one designed to keep operating in the background once a person stops paying attention. The company introduced Microsoft Scout, calling it the first entry in a category it labels Autopilots. New Android feature promises to spot deepfake scam calls Android is introducing fake call detection to help protect users from impersonation scams. The feature can detect and flag suspected spoofed calls when both parties use Phone by Google on Android 12 or later. It will roll out globally this month, starting with Pixel devices. ETSI sets security requirements for AI data centers and cloud platforms ETSI has published TS 104 033, a technical specification that defines security requirements for AI computing platforms. The specification establishes a security framework for platforms used to host AI applications in data center and edge computing environments, covering security functions, platform components, interfaces, and services designed to protect AI models, datasets, training processes, and inference workloads. Product showcase: Trend Micro Mobile Security detects scams in messages, QR codes, and websites Trend Micro Mobile Security for iOS protects devices from potentially harmful websites while browsing, blocks ads and personal information trackers, helps users avoid unsafe Wi-Fi networks, and monitors data usage. The app is available for both iOS and Android devices. Most pros have seen AI hallucinations in IT operations Autonomous AI is taking action inside enterprise IT environments. Software is restarting services, isolating risky devices, and applying patches without waiting for a human to approve the step. The capability is spreading at the same time IT professionals are reporting frequent encounters with AI output errors that can carry operational impact. Let’s Encrypt works toward post-quantum certificates at web scale Let’s Encrypt plans to pursue a post-quantum-safe Web PKI through Merkle Tree Certificates (MTCs), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. The project is targeting late 2026 for a staging environment that issues MTCs, with a production-ready environment planned for 2027. Photos: Infosecurity Europe 2026 Infosecurity Europe 2026 is a cybersecurity event that took place from June 2 to 4 in London. Help Net Security was on-site and here’s a closer look at the conference. Attackers already know the secrets are on your developers’ machines. Do you? In a recent GitGuardian analysis, an average of 150 secrets were found on a sample of developer endpoints. Private keys accounted for 38% of unique secrets, while cloud, identity provider, and secret management credentials (AWS IAM, Hashicorp vault) added another 22%. Simplify security management with CIS SecureSuite Platform CIS SecureSuite Membership simplifies the process with tools, benefits, and resources for implementing the secure recommendations of the CIS Benchmarks. With the release of CIS SecureSuite Platform, it’s now even easier for Members to harden their systems. Cybersecurity jobs available right now: June 2, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: June 5, 2026 Here’s a look at the most interesting products from the past week, featuring releases from Asimily, depthfirst, Diligent, Hyland, MazeBolt, and Noma.
helpnetsecurity.comJun 7, 2026extracted
KDE Linux security audit cuts kernel modules and unused packages
KDE Linux security audit cuts kernel modules and unused packages KDE Linux, the in-progress operating system from the KDE community, removed several kernel modules and software packages after a security audit of the components shipped with the system. The work followed the discovery of multiple security issues in the upstream Linux kernel during the prior month. Kernel and module changes Three contributors examined insecure and unused software included in KDE Linux. The audit led to a return to the vanilla Linux kernel. The Zen kernel that had been in use offered little beyond configuration adjustments the team had already applied to its own build. The contributors deleted the alf_alg kernel modules, which they described as insecure and unused. The contributors deleted the alf_alg kernel modules, which they described as insecure and unused. The out-of-tree OpenRazer and APFS kernel modules were also removed. These modules would eventually have caused KDE Linux to fail secure boot review, so the project is working toward upstream solutions for the affected functionality. APFS support can run in userspace through a FUSE driver, which the developers say may be abandoned. Package removals The audit removed a group of packages the team identified as unused, including acpi_call, busybox, cryfs, encfs, hplip, v4l2loopback-utils, and vpl-gpu-rt. KDE Linux also dropped fuse2, which is unmaintained and known to be insecure. The change will break some older AppImage applications. Users who encounter a broken app should report it to the application’s authors or packagers. Several other operating systems have already dropped fuse2, and affected applications need to move to fuse3. The contributors removed fenrir after finding it was unused. This allowed KDE Linux to end its reliance on the Arch User Repository (AUR), a source of infrastructure instability in the past. Credential storage and build checks KDE Linux replaced KWalletManager and its System Settings configuration page with KeepSecret, a credential management application packaged with Flatpak. The project also added a service that installs new pre-installed Flatpak apps on existing systems and skips any apps a user already removed. Build testing improved during the same period. Harald Sitter added a test that confirms a build does not ship with broken file capabilities. KDE Linux had shipped one earlier build that included a regression of this kind, and the new test guards against a repeat. Bhushan Shah and Thomas Duckworth worked on an OpenQA-based testing system, building on a prototype from Kangwei Zhu, that aims to catch faulty builds before release. The module work supports a larger objective for the project. Passing secure boot review depends on dropping out-of-tree kernel code, and the May changes move KDE Linux toward that result.
helpnetsecurity.comJun 2, 2026extracted
Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploited
Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Review: Foundations of Cybersecurity, 2nd edition Jason Andress has refreshed his introductory security text for No Starch Press. He writes in the introduction that the term security now extends past data center servers to cloud resources, mobile devices, the Internet of Things, and AI. Foundations of Cybersecurity: A Straightforward Introduction book is aimed at newcomers to the field, network and system administrators, and managers who need a working grasp of security concepts. Rustinel: Open-source endpoint detection for Windows and Linux Open-source endpoint detection has long been split between Windows-focused tools built around Sysmon and Linux tools built around eBPF or auditd. Defenders running mixed environments have had to stitch together separate pipelines, separate rule sets, and separate maintenance burdens. Rustinel, a Rust-based endpoint agent, is an attempt to collapse that work into a single codebase. Google researchers uncover criminal zero-day exploit likely built with AI Google’s threat intelligence researchers have linked a zero-day exploit to AI-assisted development by a criminal group. The exploit targeted a popular open-source web-based system administration tool. It allowed attackers to bypass two-factor authentication once they had valid user credentials. The flaw stemmed from a semantic logic error, a case where a developer hardcoded a trust assumption that contradicted the application’s authentication enforcement. The hidden smart fridge risks that emerge years after purchase Household refrigerators are built to last more than a decade. The software, cloud services, and mobile apps that control them are not. A new analysis from Erik Buchmann at Leipzig University maps what happens when those two timelines collide, and the findings reach further than the kitchen. HEIDI: Free IDE security plugin for open-source vulnerability checks Open-source dependencies make up a large percentage of the code in production applications, and most vulnerability checks still run late in the pipeline, inside CI/CD systems or after a release ships. Meterian is moving those checks earlier with HEIDI, a free plugin for Visual Studio Code and JetBrains IDEs that flags vulnerable packages and offers one-click upgrades from inside the editor. Amazon Quick authorization bypass let users reach blocked AI chat agents Enterprises running Amazon Quick, the AWS business intelligence and agentic AI service, rely on a feature called custom permissions to restrict who inside an account can use AI chat agents. Fog Security founder Jason Kao discovered that those restrictions were enforced only in the user interface for a period earlier this year, and direct calls to the backend API returned successful chat responses from agents that administrators had explicitly disabled. Researchers open-source a Wi-Fi cyber range for security training Wireless security training programs lean heavily on generic network labs, with Wi-Fi appearing as a checkbox alongside Bluetooth, Zigbee, and cellular. Hands-on environments dedicated to IEEE 802.11 are uncommon, even as Wi-Fi remains the default on-ramp to corporate networks and a recurring entry point for attackers. A new paper from researchers at the Norwegian University of Science and Technology and the University of the Aegean takes aim at that gap with a cyber range built specifically for Wi-Fi. Sandyaa: Open-source autonomous security bug hunter Source code auditing has traditionally relied on static analyzers that flag long lists of potential issues, leaving engineers to sort bugs from noise. A new open-source project from offensive-security firm SecureLayer7 takes a different route, using LLMs to read a codebase, trace how data moves through it, and produce working exploit code for the vulnerabilities it confirms. Their open-source tool, called Sandyaa, was released under an MIT license. KDE gets over €1 million investment to strengthen security and core infrastructure European governments and public institutions have been shifting away from proprietary software for years, and the financial infrastructure supporting open-source alternatives is growing to match. Germany’s Sovereign Tech Fund announced today that it is investing more than €1 million in KDE, the open-source project behind the Plasma desktop environment and a broad range of Linux software. Vector embedding security gap exposes enterprise AI pipelines Enterprise adoption of retrieval-augmented generation has moved sensitive corporate content into a new storage format that existing security tools cannot inspect. Companies deploying internal AI assistants convert documents into high-dimensional numerical vectors and ship them to embedding services and vector databases over ordinary HTTPS connections. Data loss prevention products scan documents and network traffic, and they read none of it. A research framework called VectorSmuggle, released by Jascha Wanger of ThirdKey under the Apache 2.0 license, demonstrates what an attacker can do with that gap. Linux developers weigh emergency “killswitch” for vulnerable kernel functions Linux kernel developers are reviewing a proposal for an emergency risk mitigation mechanism (“Killswitch”) that would allow administrators to disable vulnerable kernel functions at runtime. The proposal, submitted by Linux kernel developer/maintainer Sasha Levin, arrives in the wake of the public disclosure of two privilege escalation vulnerabilities affecting the Linux kernel. JetBrains TeamCity vulnerability allows privilege escalation, API exposure (CVE-2026-44413) JetBrains has patched a high-severity vulnerability (CVE-2026-44413) in TeamCity, its popular continuous integration and continuous delivery platform, and is urging organizations with on-premises and self-managed deployments to upgrade to the fixed version or implement a security patch. Stealthy hackers exploit cPanel flaw in active backdoor campaign (CVE-2026-41940) Security researchers at XLab have outlined an active attack campaign targeting CVE-2026-41940, the recently disclosed vulnerability in cPanel & WHM, and have linked it to a stealthy hacking group that has been operating largely undetected for years. Microsoft May 2026 Patch Tuesday: Many fixes, but no zero-days Microsoft has marked May 2026 Patch Tuesday by releasing fixes for 120+ CVE-numbered vulnerabilities, none of which (for a change) are actively exploited or have been publicly disclosed. Still, some deserve more consideration and should be addressed sooner than others. Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300) Researchers have found and disclosed yet another local privilege escalation (LPE) vulnerability in the Linux kernel: CVE-2026-46300, aka “Fragnesia”. The flaw is in the same class of vulnerabilities as the recently disclosed Dirty Frag bug(s). Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897) A critical cross-site scripting (XSS) vulnerability (CVE-2026-42897) in Microsoft Exchange Server is being exploited by attackers, Microsoft warned on Thursday. A permanent fix is still in the works. In the meantime, Microsoft provided temporary mitigations. Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182) Cisco has patched yet another Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) that has been exploited as a zero-day by “a highly sophisticated cyber threat actor”. Closing the AI governance gap in your enterprise In this Help Net Security video, Casey Bleeker, CEO at SurePath AI, talks about the AI governance gap that exists in almost every organization. Drawing from three years of conversations with IT, business, and security leaders, Casey explains why AI adoption is outpacing governance maturity by a wide margin, creating friction between security teams pushing for responsible use and business leaders worried about falling behind competitors. The hidden risk of non-human identities in AI adoption An employee with persistent, unsupervised admin access across critical systems, with no audit trail, no clear owner, and no regular access reviews, would raise immediate concern in most organizations. Yet non-human identities and AI agents are often granted that same kind of persistent, broadly privileged access. As AI adoption grows, that gap is becoming harder to ignore. Police take down relaunched criminal marketplace with 22,000 users, €3.6 million in revenue German authorities shut down a relaunched version of the criminal marketplace Crimenetwork and arrested its suspected operator. Authorities state the suspect allegedly created and operated a new technical infrastructure for Crimenetwork a few days after the previous version was shut down and its administrator was arrested in December 2024. Poor security left hackers inside water company network for nearly two years The UK’s data protection regulator, the Information Commissioner’s Office (ICO), fined South Staffordshire Water’s parent company £963,900 over security failures linked to a cyberattack that exposed the personal data of 633,887 people. iOS 26.5 is out, bringing encrypted RCS messaging to iPhone and Android users Apple is bringing long-awaited end-to-end encryption to Rich Communication Services (RCS) messaging between iPhone and Android users in iOS 26.5. The feature is launching in beta for iPhone users running iOS 26.5 on supported carriers and Android users using the latest version of Google Messages. Six new dnsmasq vulnerabilities open the door to DNS cache poisoning, local root Recent disclosures have revealed that open-source networking tool dnsmasq is grappling with a serious set of vulnerabilities. The problems span memory safety and input validation, with researchers identifying heap buffer overflows, heap corruption, and code execution bugs among the issues. Instructure took a risky approach to recover stolen Canvas data Instructure, the company behind the online learning platform Canvas, said it reached an agreement with the extortion group ShinyHunters to prevent data stolen in a recent breach from being leaked online. According to the company’s website, Canvas has more than 30 million active users worldwide and serves more than 8,000 institutions. Android pushes new scam, theft, and AI protections in 2026 update wave Phone scammers spoofing bank caller IDs have driven an estimated $980 million in annual losses worldwide, according to Europol. Android’s 2026 security roadmap takes direct aim at that pattern with a verified call system built in partnership with banks, alongside a wider set of protections covering app behavior, device theft, location data, and on-device AI processing. Microsoft’s agentic security system found four critical Windows RCE flaws Microsoft responded to growing competition in AI security by announcing that its new agentic security system helped researchers discover 16 new vulnerabilities in the Windows networking and authentication stack, including four critical remote code execution (RCE) vulnerabilities. Two of the four flaws — CVE-2026-40361 and CVE-2026-40364 — were deemed by Microsoft to be more likely to be exploited. Signal responds to phishing attacks with new in-app security warnings Signal is adding new protections for users following recent phishing and social engineering attacks.One of the new protections is an additional warning informing users that profile names on Signal are not verified and can be chosen freely by account holders, making impersonation attempts easier. WhatsApp adds Incognito Chat for private Meta AI conversations The company launched Incognito Chat with Meta AI, a feature that lets users hold AI conversations the platform itself cannot read. The rollout will reach WhatsApp and the standalone Meta AI app over the coming months. Incognito Chat runs on top of Meta’s Private Processing technology, the same infrastructure the company introduced earlier for AI tools in WhatsApp. CERN’s open source KiCad library gives the world 17,000 circuit board components CERN has released its complete KiCad component library under an open source license, making it available to hardware designers anywhere in the world. The library, maintained by CERN’s Design Office, contains more than 17,000 electronic components in the form of schematic symbols and printed circuit board footprints. AI cyber capability is speeding past earlier projections AI cyber capability is improving faster than expected, with newer models surpassing earlier projections, according to the UK government’s AI Security Institute (AISI). AISI measures AI cyber capability using “time horizon benchmarks”, which estimate how long AI systems can complete cybersecurity tasks autonomously compared to human experts. Microsoft’s WinUI agent plugin trims token use by over 70% during development Microsoft published a plugin on May 13 that lets GitHub Copilot CLI and Claude Code drive the full WinUI 3 development cycle, from project scaffolding through signed MSIX packaging. The WinUI agent plugin ships one agent, eight skills, and several supporting tools targeting the loop developers run dozens of times a day: scaffold, build, run, test, iterate. Zombie linkages are keeping expired domains trusted for years Domains expire, get transferred, and return to the market every day. The systems connected to those domains can continue trusting the original owner long after control has changed. Researchers at USC and the University of Twente examined this problem in three widely used systems: Web PKI, Maven Central, and Ethereum Name Service. They use the term “zombie linkages” to describe lingering trust records that remain active after the original domain owner no longer controls the domain. Deepfake detection is losing ground to generative models Deepfake detection has been built around a single question for close to a decade. Given a video or audio clip, is it real or synthetic? Commercial detectors analyze pixels, frequencies, and biometric signals to answer that question, and the best of them post strong accuracy numbers on standard benchmarks. In deployment, performance drops sharply on content from newer generators. Researchers at the Vector Institute think this gap is structural, and closing it means rethinking what the field is trying to detect in the first place. Rocky Linux launches opt-in security repository for urgent fixes Rocky Linux has introduced a Security Repository that allows the distribution to ship urgent security fixes ahead of upstream Enterprise Linux when public exploit code exists and upstream patches are unavailable. Thieves unlock stolen iPhones using cheap tools sold on Telegram Helping a friend recover a stolen phone, Infoblox researchers uncovered a thriving Telegram-based underground marketplace selling unlocking tools and phishing infrastructure used to monetize stolen iPhones. Activation Lock can remotely disable a stolen iPhone and prevent normal resale, with owners also able to lock individual components. Google lets Workspace admins apply one policy across all SAML apps Google has updated Context-Aware Access (CAA) in Google Workspace to introduce a default policy assignment for SAML applications. SAML applications are third-party or internal applications that use the Security Assertion Markup Language (SAML) protocol to enable single sign-on (SSO) with Google Workspace credentials. Security teams are turning to AI to survive alert overload The World Economic Forum white paper “Empowering Defenders: AI for Cybersecurity” identified AI as the biggest driver of change in cybersecurity for 94% of survey respondents. The paper found that 77% of organizations already use AI in cybersecurity, with much of the activity focused on phishing detection, anomaly monitoring, vulnerability management and incident response. The scam economy has found its AI upgrade Scam attempts continue to reach consumers via email, text messages, social media, online advertising, and phone calls. The volume of exposure has remained stable over the past year, with more than half of consumers encountering scam attempts at least monthly, according to the F-Secure Scam Intelligence & Impacts Report 2026. Instagram messaging encryption removed, and privacy advocates are pushing back After introducing optional end-to-end encrypted messaging in 2023, Instagram announced in March 2026 that encryption for direct messages would be discontinued, and the feature was removed on May 8. The change allows Instagram to access direct message content, including images, videos, and voice notes. OpenAI’s Daybreak uses Codex Security to identify risky attack paths OpenAI Daybreak is the company’s cybersecurity initiative focused on building AI-assisted software defense into the development process from the start. It combines OpenAI models, Codex Security, and cyber-focused GPT-5.5 variants to help organizations identify, validate, and prioritize software vulnerabilities. Škoda confirms unauthorized access to its online shop Car manufacturer Škoda discovered that attackers had exploited a vulnerability in its online shop software and gained temporary unauthorized access to the system. After discovering the incident, the company took the shop offline as a precautionary measure, fixed the vulnerability, referred the incident to a specialized IT forensics team for technical analysis, and reported it to the data protection supervisory authority. General Motors to pay $12.75 million over driver data sales General Motors has agreed to a $12.75 million settlement with California over allegations that it unlawfully sold drivers’ location and behavioral data to brokers, marking the largest penalty in the history of the state’s Consumer Privacy Act. Prosecutors say GM made approximately $20 million nationwide from the sales. Fedora Hummingbird brings the container security model to a Linux host OS Container image security pipelines have spent the past several years pushing toward minimal footprints, hermetic builds, and continuous CVE remediation. The Fedora Project is now applying that same approach to the host operating system. At Red Hat Summit 2026, Fedora announced Fedora Hummingbird, a container-based rolling Linux distribution delivered as an OCI image. Machine identities outnumber humans 109 to 1 Organizations manage an average of 109 machine identities for every human identity. AI agents account for a growing share of those identities, with companies expecting AI agent growth of 85% over the next 12 months. Machine identities are projected to increase by 77%, and human identities by 56%, based on data from Palo Alto Networks’ 2026 Identity Security Landscape report. Microsoft turns Copilot Studio into an AI agent control center The Microsoft Copilot Studio April 2026 updates improve visibility and governance for admins and expand workflow capabilities for managing agents. Copilot surfaces agent status in the authoring experience, giving admins insight into each agent’s security and protection posture. Customers can identify issues such as authentication gaps or policy impacts and investigate them at the source. The AI oversight paradox: Is the investment worth the cost of watching it? Unlike in 2025, when AI adoption and testing drove business strategies, organizations in 2026 want proven ROI before committing budgets, according to a report by Globalization Partners. Download: The IT and security field guide to AI adoption Security and IT teams are under pressure to adopt AI, but many are seeing the opposite of what was promised. Tools that demo well don’t hold up in real workflows. Complexity increases. Trust breaks down. And instead of reducing workload, AI can introduce new risks and oversight burdens. Cybersecurity jobs available right now: May 12, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: May 15, 2026 Here’s a look at the most interesting products from the past week Alation, Apricorn, Versa Networks, and TrustCloud.
helpnetsecurity.comMay 17, 2026extracted
KDE gets over €1 million investment to strengthen security and core infrastructure
KDE gets over €1 million investment to strengthen security and core infrastructure European governments and public institutions have been shifting away from proprietary software for years, and the financial infrastructure supporting open-source alternatives is growing to match. Germany’s Sovereign Tech Fund announced today that it is investing more than €1 million in KDE, the open-source project behind the Plasma desktop environment and a broad range of Linux software. The investment will go toward strengthening KDE’s testing infrastructure, security architecture, and the frameworks underpinning its communication services. KDE Linux, the project’s dedicated Linux distribution, is also listed among the targets. What KDE is and why it matters to the fund KDE has operated as a non-profit technology organization for 30 years, producing free and open-source software that runs on Linux, BSD, Windows, macOS, and Haiku. Its output includes Plasma, one of the two dominant desktop environments for Linux systems, along with document viewers, multimedia tools, image editors, and software development libraries. KDE software ships in more than 60 languages. The Sovereign Tech Fund, operated under Germany’s Sovereign Tech Agency, focuses on digital infrastructure that public administrations and enterprises depend on. Fiona Krakenbürger, Technical Director at the Sovereign Tech Agency, cited the desktop’s role as the primary access point for digital services in daily life, from medical appointment booking to workplace software. “We are investing in KDE because it is one of the two major desktop environments used across Linux and plays a key role in how millions of people experience open technology,” Krakenbürger said. Scope of the work KDE charges nothing for its software and carries no shareholder obligations. Its source code is publicly auditable, and organizations can modify and redistribute it without licensing fees or subscription costs. The project does not collect or resell user data and does not use that data to train AI models. The fund’s investment will be directed at making KDE’s core products more reliable and secure at a structural level. The stated goal is to give individuals, businesses, and public agencies a viable path to greater control over their own digital infrastructure. KDE’s patrons include Canonical, Google, SUSE, and The Qt Company, among others. The Sovereign Tech Fund has previously invested in other foundational open-source projects and publishes details of its investments publicly at sovereign.tech.
helpnetsecurity.comMay 13, 2026extracted
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: The AI criminal mastermind is already hiring on gig platforms Labor-hire platforms let anyone with a credit card post a task and pay a stranger to complete it. The RentAHuman platform extends that model to AI agents through a Model Context Protocol server, allowing an agent to post gigs directly. Listed tasks include attending in-person meetings, photographing locations, delivering items, and surveying physical sites. Even cybersecurity researchers are exposing secrets in their arXiv LaTeX source Researchers submit papers to arXiv daily, often including LaTeX source files alongside PDFs. About 93% of submissions contain these files, which may include drafts, comments, figures, and leftover project data. A study from RWTH Aachen University, to be presented at the 2026 IEEE Symposium on Security and Privacy, analyzed 2.7 million arXiv submissions since 1991. It found that 88% contained material not intended for public release. Open-source IPFire DNS Firewall blocks malware and phishing at the resolver The IPFire project shipped Core Update 201 for its 2.29 release line, bringing DNS-layer domain blocking into the open-source firewall distribution. The update replaces two components that many IPFire operators had paired with the system for years, the built-in URL Filter and external Pi-hole deployments, by handling blocklist enforcement directly inside the firewall’s DNS proxy. US state privacy fines reached $3.425 billion in 2025 State privacy regulators across the United States collected $3.425 billion in privacy-related fines from companies in 2025. Gartner said the upward trend is expected to accelerate through 2028. Annual cumulative fines stood at $1.827 billion in 2024, putting the 2025 result at nearly double the previous year’s level. The Exchange Online security controls organizations keep getting wrong In this Help Net Security interview, Scott Schnoll, Microsoft MVP for Exchange, breaks down the Shared Responsibility Model, where Microsoft secures the cloud while organizations must protect their own data, identities, and configurations. The discussion covers default settings worth changing tomorrow, including legacy protocols like SMTP AUTH that survive due to printer, scanner, and ERP dependencies. Cisco releases open-source toolkit for verifying AI model lineage Enterprises pulling models from Hugging Face and other open repositories rarely keep records of how those models are altered after download, leaving organizations with little ability to confirm what they are running in production. The State of AI Security 2026 from Cisco places this level of access inside a growing pattern of AI-driven operations that connect directly to core business systems, and identifies AI supply chain exposure as a recurring risk. Attackers use MS Teams, fake mailbox repair utility to breach organizations A threat group has penetrated corporate networks by impersonating IT helpdesk staff on Microsoft Teams, tricking employees into downloading malware and surrendering their credentials to a fake “Mailbox Repair Utility”. UNC6692 is a newly identified threat group, documented by Google’s Threat Intelligence Group (GTIG) following a campaign that began in late December 2025. Cyber crooks got Robinhood to send phishing emails to its own users An email phishing campaign is currently targeting a subset of users of the Robinhood brokerage / investment platform and, judging by the comments on Reddit, some have fallen for it. The emails started hitting inboxes on Sunday, April 26, and users soon began reporting the emails to Robinhood and warning other users on Reddit and elsewhere. The metrics killing your SOC, and what to use instead Security operations centres risk being rendered entirely ineffective if organizations measure them using the wrong performance indicators, according to Dave Chismon, CTO for Architecture at UK’s National Cyber Security Centre. Evaluating ones’ SOC using the same ticket-based metrics applied to IT service desks can actively work against its core purpose: detecting and responding to real attacks. CISA, Microsoft warn of active exploitation of Windows Shell vulnerability (CVE-2026-32202) Attackers are exploiting CVE-2026-32202, a zero-click Windows Shell spoofing vulnerability that causes victims’ systems to authenticate the attacker’s server, CISA and Microsoft have warned. CVE-2026-32202 stems from an incomplete patch for CVE-2026-21510, a vulnerability that, in conjunction with CVE-2026-21513, has been exploited by APT28 (aka Fancy Bear) via weaponized LNK files that bypass Windows security features. Buggy Vect ransomware is effectively a data wiper, researchers find Due to a bug in the ransomware, affiliates of the Vect Ransomware-as-a-Service operation are irretrievably encrypting victims’ data. After Vect announced that it will be partnering with BreachForums and providing an “affiliate key” to every registered user of the forum, Check Point researchers opened a BreachForums account and got access to Vect’s panel and ransomware builder. 88% of self-hosted GitHub servers exposed to RCE, researchers warn (CVE-2026-3854) When researchers at Wiz reported an easily exploitable GitHub remote code execution flaw (CVE-2026-3854) on March 4, the company confirmed it within 40 minutes and pushed a fix to GitHub.com in under two hours. But for too many of the thousands of organizations running GitHub Enterprise Server on their own infrastructure, the vulnerability still represents a risk. Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Security researchers at Theori have disclosed a high-severity local privilege escalation (LPE) vulnerability (CVE-2026-31431) in the Linux kernel. The flaw, nicknamed “Copy Fail”, has affected virtually every major Linux distribution shipped since 2017, and a working proof-of-concept (PoC) exploit is publicly available. cPanel zero-day exploited for months before patch release (CVE-2026-41940) A critical authentication bypass vulnerability (CVE-2026-41940) in cPanel, a popular web-based control panel for managing web hosting accounts, is being exploited by attackers in the wild. What’s more, attackers didn’t have to wait for watchTowr security researchers to release technical details about the vulnerability – they have been spotted exploiting CVE-2026-41940 since February 23, and have likely been abusing it even earlier. Your IAM was built for humans, AI agents don’t care Identity and access management was built for a simpler world. One where the hardest problem was a human logging in, and where “Who are you?” was sufficient to decide what someone could do. That model served enterprises well for decades. Identity discovery: The overlooked lever in strategic risk reduction If you ask a CISO what keeps them up at night, it’s not a lack of tools, it’s uncertainty. Uncertainty about unseen risks, attacker movement, and whether identity programs reduce risk. dentity discovery sits at the center of that uncertainty. It is not glamorous. It does not get the same attention as AI-driven detection or zero trust initiatives. But it is the foundation of meaningful risk reduction. Identity is the control plane for distributed infrastructure Teleport CEO Ev Kontsevoy makes the case that distributed infrastructure, across cloud, Kubernetes, databases, and servers, can’t be secured by layering more tools on top of fragmented identity systems. He argues for fewer credentials, fewer entry points, and a single identity layer that gives security and engineering teams unified visibility and control. Hackers claim millions of records stolen in ADT breach ADT, a Florida-based provider of alarm monitoring solutions, confirmed that hackers breached its systems and accessed a portion of customer data. According to a company statement, unauthorized access was detected on April 20 and affected “a limited set of customer and prospective customer data.” 500,000 UK volunteers’ medical data listed for sale on Alibaba Medical data from around 500,000 British volunteers in the health research project, the UK Biobank, was offered for purchase through the Chinese marketplace Alibaba, the British government has confirmed. More than 22,000 researchers from over 60 countries use data from the UK Biobank to study disease development and improve global public health. The dataset comprises genetic data, clinical records, biological samples, and lifestyle-related information. ICS intrusion detection has blind spots that complicate plant security Industrial control systems on plant floors run alongside a growing layer of monitoring software meant to catch intruders before they reach a turbine, a valve, or a chemical mixer. Vendors sell these intrusion detection systems on the promise of broad coverage across both network traffic and the physical process. A new paper from researchers at RWTH Aachen University lays out three reasons that promise tends to wobble in practice. OpenAI releases Symphony to automate Codex work through Linear Engineering teams running coding agents at scale find themselves managing dozens of parallel sessions across browser tabs and command-line windows. OpenAI has released an open-source specification called Symphony that removes much of that supervision work by tying Codex agents directly to issue trackers. Open-source privacy tool BleachBit 6.0.0 upgrades code signing across Windows and Linux System cleaning utilities have grown more relevant as web browsers stockpile larger volumes of cached data, tracking artifacts, and site storage on local disks. The open-source utility BleachBit moved into a new major version on with a 6.0.0 release that targets that buildup. The update contains more than 100 changes covering browser cleaners, the command-line interface, secure deletion, and platform-specific fixes for Windows and Linux. Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Chinese national Xu Zewei was extradited from Italy to the United States to face charges tied to an alleged cyber espionage campaign that breached thousands of computers worldwide. Xu is charged alongside Zhang Yu, who remains at large. ShinyHunters claims it stole 1.4 million records from Udemy The ShinyHunters group claims it has breached the Udemy, one of the world’s largest online learning platforms. According to Have I Been Pwned, the leaked dataset contained 1.4 million unique email addresses of customers and instructors, along with names, physical addresses, phone numbers, employer information, and instructor payout methods, including PayPal, cheque, and bank transfer. Police arrest 10 suspected members of Black Axe cybercrime gang A coordinated police operation in Switzerland has targeted suspected members of the Black Axe criminal network. On 28 April 2026, authorities carried out house searches across several Swiss cantons, leading to 10 arrests, including the Black Axe ‘Regional Head’ for Southern Europe. Most of those arrested are reported to be of Nigerian origin. FIDO Alliance wants to keep AI agents from going rogue on online payments AI agents are beginning to shop, log in, and complete tasks with little direct input. That shift is pushing the security industry to rethink how trust works when actions are carried out on a user’s behalf. AI prompt confidentiality and false citations worry researchers Academic researchers using commercial AI tools for literature review and idea generation are sending unpublished research questions, draft hypotheses, and proprietary domain knowledge into systems whose data handling they do not understand. A think-aloud study of 15 researchers documents the workarounds these users have built to manage what they see as unresolved confidentiality and output verification problems in tools including Research Rabbit and Elicit AI. Time to keep up with AI-driven attacks is narrowing, OpenAI says OpenAI is outlining a plan to expand access to advanced AI tools for cybersecurity defenders, warning that attackers are already using the technology to scale operations. In contrast, Anthropic has taken a more cautious stance, emphasizing tighter control and restricted access to advanced AI capabilities. Police bust scam call centres behind €50 million in fraud losses Authorities have dismantled a cybercrime ring running call centres in Albania and defrauding victims of more than €50 million, arresting 10 suspects and seizing nearly €900,000. After a spike in victims in Vienna in June 2023, Austrian authorities traced cyber fraud activity to Albanian suspects, triggering a joint investigation with Albanian authorities supported by Eurojust and Europol. Automated LLM red teaming gets a learning layer Automated red teaming of large language models has settled into a familiar pattern over the past two years. An attacker model generates jailbreak attempts against a target model, an evaluator scores the results, and the cycle repeats. Two approaches dominate. One relies on trial and error and often produces limited results. The other, like WildTeaming, combines crowdsourced attack data at random. Researchers at Capital One propose Adaptive Instruction Composition, which builds on these inputs and adds a learning layer to prioritize the most promising attack combinations. Hackers arrested for stealing and reselling 600,000 Roblox accounts Ukrainian police detained three suspects accused of hacking into Roblox accounts and reselling the data on Russian websites, with payments made in cryptocurrency. Authorities state that the group used stolen login data and malicious software to gain access. Some tools were disguised as game-related programs, which helped them collect user credentials. Open-source privacy proxy masks PII before prompts reach external AI services Enterprise developers routinely send prompts to external large language models that contain customer emails, support transcripts, and other identifying information, often without a sanitization layer between the application and the API. Dataiku has released Kiji Privacy Proxy, an open-source local gateway that detects and masks personally identifiable information before requests leave the network. Met Police face criticism for using AI to spy on their own officers London police officers have been warned by the Metropolitan Police Federation to watch their backs after the force deployed controversial AI software to investigate misconduct. The staff association, representing more than 30,000 officers in London, reported it had not been informed of plans to use Palantir’s AI to analyze officers’ movements. Product showcase: LuLu reveals unauthorized outbound connections from Mac apps LuLu is a free, open-source firewall for macOS that lets you control which apps are allowed to send data from your computer. macOS includes a built-in firewall, but it mainly handles incoming connections. LuLu also monitors outgoing traffic. 25 open-source cybersecurity tools that don’t care about your budget Regardless of the operating system you use, managing secrets, apps, cloud, compliance, and security operations can be overwhelming. The free, open-source tools presented in this article can help you detect threats, increase visibility, enforce controls, and investigate and respond to incidents throughout the development and operational lifecycle. Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup Stratis is a tool for configuring pools and filesystems with enhanced storage functionality within the existing Linux storage management stack. It focuses on a command-line interface, an API, and an automated approach to storage management. It builds on existing components, including device-mapper, LUKS, XFS, and Clevis. Canada’s first SMS blaster case leads to three arrests Canadian law enforcement arrested three men who face 44 charges for operating an SMS blaster device that mimicked a legitimate cellular tower. The device was operated from vehicles, allowing it to move throughout the Greater Toronto Area and operate in multiple locations. Product showcase: SimpleX Chat removes user identifiers from messaging SimpleX Chat is a free, private, open-source messenger that uses encryption and does not require user identifiers. It is available on mobile and desktop platforms, including iOS, Android, Windows, macOS, and Linux. After downloading the app, the user creates a profile by entering a display name. The profile is stored locally on the device. Fedora Linux 44 ships with GNOME 50 and KDE Plasma 6.6 The Fedora Project released Fedora Linux 44, delivering updated desktop environments, revised installer behavior, and several lower-level system changes across its editions and spins. Visual Studio cloud agents now run inside GitHub Copilot Microsoft’s April update to Visual Studio introduces cloud agent integration in GitHub Copilot, enabling developers to offload tasks to remote infrastructure for scalable, isolated execution. You can now start cloud agent sessions directly from Visual Studio. Visual Studio Code 1.118 adds auto model selection to Copilot CLI Microsoft’s editor releases continue on a monthly cadence, with the Insiders build of Visual Studio Code 1.118. The update concentrates on the Copilot CLI integration, session management in the Agents app, and an opt-in path for TypeScript 7.0. Warp open sources its AI terminal client Warp, the AI-centric terminal used by close to a million developers, has released the source code for its client on GitHub under the AGPL license, with OpenAI signed on as the founding sponsor of the repository. Bad bots make up 40% of internet traffic The normalization of AI and automation within internet infrastructure is changing how organizations interpret traffic. Activity that once appeared anomalous is now treated as expected behavior. AI agents have emerged as a third category of automated traffic alongside good and bad bots, according to the Thales 2026 Bad Bot Report: Bad Bots in the Agentic Age. Proxmox Backup Server 4.2 arrives with S3 storage support and parallel sync jobs Proxmox Backup Server 4.2 is a maintenance and feature update built on Debian 13.4 “Trixie” that adds S3-compatible object storage as a supported backend and introduces parallel processing for sync jobs. Researchers develop tool to expose GPS signal spoofing in transit networks The Oak Ridge National Laboratory (ORNL) has developed a portable detector that identifies GPS spoofing in real time, including during motion, to help protect transportation systems. The ORNL team combined expertise in sensing, radio frequency signals, mathematics, computing, electronics, and national security to create a highly sensitive detector designed to expose manipulation of GPS signals. Shadow AI risks deepen as 31% of users get no employer training Between one-fifth and one-third of workers use AI outside the influence and governance of the IT function, according to a global survey of 6,000 full-time employees at enterprise organizations. Researchers found a widening gap between employee AI adoption and the controls organizations have in place to manage it. AI traffic is getting bigger, louder, and less predictable AI workflows need storage that supports repeated movement across the model lifecycle. Large datasets are ingested, transformed, exported for training, pulled back for evaluation, and refreshed as models evolve. Backblaze’s Q1 2026 Network Stats report says this creates a shift from diffuse internet-style traffic to large, high-bandwidth flows between fewer endpoints. Download: Automating Pentest Delivery Guide This guide on Automating Pentest Delivery teaches you how to modernize your workflows and transform traditional reporting into a continuous, collaborative process where findings become actionable the moment they’re discovered. Cybersecurity jobs available right now: April 28, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the month: April 2026 Here’s a look at the most interesting products from the past month, featuring releases from Advenica, Aptori, Axonius, Broadcom, GlobalSign, Intruder, IP Fabric, Mallory, Secureframe, Siemens, Sitehop, and Virtue AI.
helpnetsecurity.comMay 3, 2026extracted
Fedora Linux 44 ships with GNOME 50 and KDE Plasma 6.6
Fedora Linux 44 ships with GNOME 50 and KDE Plasma 6.6 The Fedora Project released Fedora Linux 44, delivering updated desktop environments, revised installer behavior, and several lower-level system changes across its editions and spins. The release covers the project’s flagship editions, including Workstation, KDE Plasma Desktop, Cloud, Server, CoreOS, and IoT, alongside the Atomic Desktops lineup of Silverblue, Kinoite, Cosmic, Budgie, and Sway. Alternate spins such as Cinnamon and Xfce are also available. Desktop updates Fedora Workstation 44 ships with GNOME 50, which brings refinements across accessibility, color management, and remote desktop. Default applications including Document Viewer, File Manager, and Calendar receive updates in this version. The KDE edition is built on Plasma 6.6 and introduces the new Plasma Login Manager and Plasma Setup. The combination is intended to provide a more integrated first-boot experience, with a simplified installation flow aimed at users setting up systems for others. Installer and networking changes The Anaconda installer now creates network profiles only for devices configured during installation, whether through boot options, kickstart, or the interactive interface. Earlier behavior generated default profiles for every detected network device. The change applies to fresh installations of Fedora Linux 44 spins and is intended to simplify post-installation network configuration. Plumbing changes OpenSSL loading times have been reduced through directory-hash support for ca-certificates. The change required moving some certificate bundles to different locations on the filesystem, and the project has documented the affected paths in its change proposal. MariaDB packaging has switched its unversioned default to version 11.8. Fedora continues to deliver versioned packages for both mariadb-10.11 and mariadb-11.8, so existing installations carried forward through an upgrade keep their current version. New installations performed without specifying a version receive 11.8. The Wine NTSYNC kernel module is now enabled automatically for select packages through package recommendations, with Wine and Steam cited as primary examples. When a package that recommends wine-ntsync is installed, NTSYNC is configured on subsequent boots without manual intervention. The mechanism is aimed at improving compatibility and performance for Windows applications, particularly games. Fedora Cloud images that support the change have replaced the /boot partition with a Btrfs subvolume. The project credits the change with better space utilization and smaller image sizes. Availability Installation media for the editions, Atomic Desktops, and spins are available through the Fedora Project’s download pages. Existing systems can move to Fedora Linux 44 using the standard upgrade procedure documented in the project’s quick-docs guide.
helpnetsecurity.comApr 29, 2026extracted
The fully free Linux OS Trisquel gets a major update with version 12.0 Ecne
The fully free Linux OS Trisquel gets a major update with version 12.0 Ecne Trisquel GNU/Linux, a free operating system aimed at home users, small enterprises, and educational centers, released version 12.0. The release, codenamed Ecne, is declared production-ready and builds on the previous version, Aramo, with changes to packaging, the kernel, security, and available software. APT 3.0 and repository format changes Ecne ships with APT 3.0, which brings adoption of the deb822 repository format across all installation paths. The change covers the text-based netinstall, the graphical Ubiquity installer, and package-management tools including Synaptic. The deb822 format replaces the older repository format used in prior releases. Kernel and installer work The kernel remained, in the project’s own words, one of its biggest engineering challenges. For Ecne, the team focused on making kernel changes more modular, which substantially reduced breakage in the udeb components used during installation. Work on updating kernel-wedge is ongoing, with the project reporting it is well positioned to complete it. AppArmor rules and LXDE The team revised many AppArmor rules for graphical environments, extending security coverage for desktop use. The Trisquel Mini edition, which runs the LXDE desktop, received a significant number of upstream improvements. Ubuntu dropped LXDE from all its releases, leaving Trisquel as one of its primary maintained homes. Browser choices Ecne adds ungoogled-chromium and IceCat to its software offerings. Both join Abrowser, the distribution’s continuously maintained browser, giving users three web browsing options that meet the project’s free software requirements. Backports repository The backports repository continues to deliver applications in recent versions. The current list includes LibreOffice, yt-dlp, Inkscape, Nextcloud Desktop, Kdenlive, Tuba, 0 A.D., and fastfetch, among others. Editions Ecne ships in five editions. The default Trisquel edition uses MATE version 1.26.1 and does not require 3D graphics acceleration. Triskel offers KDE Plasma version 5.27 for users who want detailed control over the desktop environment. Trisquel Mini runs LXDE version 0.99.2 and targets netbooks, older computers, and users with low resource requirements. Trisquel Sugar, also called Trisquel On A Sugar Toast (TOAST), is based on the Sugar learning platform version 0.121 and includes educational activities for children. A network installer image rounds out the lineup, suited to servers and advanced users who want a command-line installation. Must read: 40 open-source tools redefining how security teams secure the stack Firmware scanning time, cost, and where teams run EMBA Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comApr 12, 2026extracted
Kali Linux 2025.4: New tools and “quality-of-life” improvements
Kali Linux 2025.4: New tools and “quality-of-life” improvements OffSec has released Kali Linux 2025.4, a new version of its widely used penetration testing and digital forensics platform. Most of the changes are related to appearance and usability: Kali’s GNOME desktop environment now organizes Kali tools into folders via the app grid, and there’s a shortcut for opening a terminal window Its KDE Plasma desktop enviroment now comes with a new screenshot tool with added editing features, offers quick access to pinned clipboard items, and its search/launch tool now correctly identifies which app you wanted to open even if you misspell its name Its Xfce desktop environment gets supports for color themes As per usual, new versions of Kali come with new tools. In v2025.4, those are: bpf-linker, a tool for statically linking multiple BPF object files together and perform optimizations needed to target older kernels evil-winrm-py, a Python-based tool for executing commands on remote Windows machines using the Windows Remote Management protocol, and hexstrike-ai, an MCP server that lets AI agents autonomously run tools Kali NetHunter – the mobile mobile penetration testing platform – now supports: Samsung Galaxy S10, S10e, S10 Plus, and S10 5G running LineageOS 23 OnePlus Nord running Android 16 Xiaomi Mi 9 running Android 15 Finally, like the Kali Everything image (which contains all Kali tools), the Kali Live image – a bootable version of Kali Linux that lets you run the operating system directly from a USB drive or DVD without installing it on your computer – is now downloadable only via BitTorrent, because of its increased size. Other Kali Linux 2025.4 images can be downloaded here. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comDec 15, 2025extracted
Kali Linux 2025.4 released with 3 new tools, desktop updates
Kali Linux has released version 2025.4, its final update of the year, introducing three new hacking tools, desktop environment improvements, the preview of Wifipumpkin3 in NetHunter, and enhanced Wayland support. Kali Linux is a distribution designed for cybersecurity professionals and ethical hackers to perform red-teaming, penetration testing, security assessments, and network research. The distribution is available as an installable operating system or a live environment and supports a wide range of hardware, including Raspberry Pi devices and compatible Android phones through Kali NetHunter. New tool added to Kali Linux 2025.4 Every new Kali release brings a few fresh tools to play with, and this update is no exception. This time, we're getting three new additions: bpf-linker - Simple BPF static linker evil-winrm-py - Python-based tool for executing commands on remote Windows machines using the WinRM hexstrike-ai - MCP server that lets AI agents autonomously run tools Desktop environment updates Kali Linux 2025.4 brings many new updates to its desktop environments, including Gnome 49, KDE Plasma, and Xfce. GNOME 49 includes refreshed themes, a new Showtime video player, reorganized tool folders in the app grid, and new shortcuts for quickly opening a terminal. GNOME also entirely removes X11 support in this release, now running solely on Wayland. The developers also added support for keyboard shortcuts to open a terminal quickly. "Another quality-of-life improvement is the addition of a shortcut to quickly open a terminal (finally!), using Ctrl+Alt+T or Win+T - just like in our other desktops," explains the Kali Linux 2025.4 announcement. KDE Plasma has been updated to version 6.5, introducing improved window tiling, an enhanced screenshot tool, easier clipboard access, and more flexible fuzzy search in KRunner. Xfce now supports color themes that offer functionality similar to that already available in GNOME and KDE, allowing users to adjust icons and interface colors more easily. With GNOME now running entirely on Wayland, the Kali Linux team has added full VM guest utilities support for VirtualBox, VMware, and QEMU. Kali Nethunter updates Kali NetHunter received new updates with this release, including expanded device support for Android 16 on the Samsung Galaxy S10 and the OnePlus Nord, and Android 15 on Xiaomi Mi 9. The NetHunter Terminal has also been restored with updated compatibility for Magisk versions that use interactive mode. This prevents terminal sessions from closing when pressing CTRL+C. Wifipumpkin3 preview, a framework for rogue access point attacks, is now also available in the NetHunter app, with phishing templates for Facebook, Instagram, iCloud, and Snapchat. Other changes This release also includes additional updates and improvements, including: The Kali Live image is now distributed only via BitTorrent, as its size has grown too large for traditional HTTP downloads. Three new community mirrors have been added in Asia and one in the United States to improve download availability. Kali Cloud and the Kali WSL app received several behind-the-scenes improvements and reliability fixes. How to get Kali Linux 2025.4 To start using Kali Linux 2025.4, you can upgrade your existing installation, select a platform, or directly download ISO images for new installs and live distributions. For those updating from a previous version, you can use the following commands to upgrade to the latest version. echo "deb http://http.kali.org/kali kali-rolling main contrib non-free non-free-firmware" | sudo tee /etc/apt/sources.list sudo apt update && sudo apt -y full-upgrade cp -vrbi /etc/skel/. ~/ [ -f /var/run/reboot-required ] && sudo reboot -f If you are running Kali on the Windows Subsystem for Linux, upgrade to WSL2 for a better experience, which includes the ability to use graphical apps. You can check the WSL version used by Kali with the 'wsl -l -v' command in a Windows command prompt. Once done upgrading, you can check if the upgrade was successful by using the following command: grep VERSION /etc/os-release You can view the complete changelog for Kali 2025.4 on Kali's website. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comDec 12, 2025extracted
Threat Bulletin: Fire in the Woods – A New Variant of FireWood
Threat Bulletin: Fire in the Woods – A New Variant of FireWood August 13, 2025 Written by Nicole Fishbein A new and low-detected variant of the FireWood backdoor was discovered by Intezer's Research Team, with some changes in the implementation and the configuration of the backdoor. FireWood is a Linux backdoor discovered by ESET’s research team. They linked it to the long‑running “Project Wood” malware lineage, which dates back to at least 2005 and includes usage in the earlier Operation TooHash campaign. It functions as a remote access trojan (RAT) on Linux systems, employing kernel‑level rootkit modules (e.g., usbdev.ko) and TEA‑based encryption to hide its presence, maintain persistence, and communicate covertly with its command‑and‑control infrastructure. Once deployed, likely via web shells left on compromised Linux desktops, it enables attackers to execute commands, exfiltrate sensitive data such as system information and credentials, and operate stealthily over prolonged espionage operations. The backdoor has low confidence connections to the China-aligned Gelsemium APT group, as the overlaps may be coincidental or reflect shared tools across multiple groups. We found a new and low-detected variant of the FireWood backdoor. The core functionality of the backdoor remains the same but we did notice some changes in the implementation and the configuration of the backdoor. It is unclear if the kernel module was also updated as we were not able to collect it. Technical Analysis of New Firewood Variant In the older variant, execution began with an explicit permission gate, calling CUser::IsSuc(), and the process would exit if this check failed. In the newer build, that early check is removed entirely. The new version defers any root‑or‑kernel gating until after it daemonizes and saves its PID. To achieve this, the code splits the former SavePidAndCheckKernel() helper into two discrete steps: an early SavePid(pid), followed later by CModuleControl::AutoLoad() and CheckLkmLoad(). This separation clarifies the startup sequence and enhances the hide‑via‑kernel‑module logic. Additionally, rather than simply sending a stripped‑down identifier, the updated version builds a larger buffer containing the process name, hex‑formatted port, PID, a hardcoded “kde‑tra” process name, and a configurable flag (or the literal “nothing”). That extra metadata is passed through CHideProcess::NetLinkInit(), CHideProcess::SendProcessName(&CHideProcess::mInstance), and CHideProcess::Destroy(). Note the typo in the method name “Destroy”, this error also appears in the older Firewood variant. Another typo persists in both versions in the following error message: “Get Memory Faile”. On the networking side, the older version read configuration settings that defined both the number of days between beaconing and a delayTime specifying the interval between packets. It also used a randomized time‑window algorithm to stagger connections. The new build collapses all of this into a straightforward while (true) loop. After waiting for the configured startup delay, it continuously calls ConnectToSvr(), sleeping briefly on failure, until success or until the overall timer expires, then cleans up and exits. By removing the multi‑stage scheduling and random timing logic, the connection routine becomes more predictable and maintainable, trading temporal obfuscation for reliable C2 reachability. Overall, the communication protocol and C2 setup remain the same; the only significant change is that the new version no longer relies on timeouts from the configuration. Both Firewood versions collect information about the user and the infected machine. The new variant adds a fallback for OS detection: whereas the older version reads distribution data from /etc/issue, the new version falls back to /etc/issue.net if /etc/issue is unavailable, parsing the data in the same way. The backdoor defines file paths used by both itself and its kernel module. The new variant sets paths for root users as: /usr/lib/.kde-root/ /usr/lib/.kde-root/lib/ /usr/lib/.kde-root/data/ /usr/lib/.kde-root/kdeinit /usr/lib/.kde-root/pid /etc/init.d/rc.local For non-root users, it uses: $HOME/.kde-root/ $HOME/.kde-root/lib/ $HOME/.kde-root/data/ $HOME/.kde-root/kdeinit $HOME/.kde-root/pid $HOME/.bashrc By contrast, the older variant for root users used: /etc/init.d/rc.local /etc/rc.d/rc.local /etc/init.d/boot.local And for non-root users: $HOME/.bashrc The FireWood backdoor supports a number of commands documented by ESET. The new variant removes some commands and adds others. It drops commands for changing beacon intervals and delay times (command IDs 0x111, 0x113, 0x114), as these settings are no longer used. It also removes the file-read command (ID 0x201). The process‑hiding command has moved to ID 0x202 (from 0x112), and the HideModule function was removed. A new command (SetAutoKillEl, ID 0x160) toggles or sets an “auto‑kill” feature in the agent. Besides these commands, there are also three commands that appear in both versions and were not previously documented: Command id 0x109: A command that indicates a change in the connection configuration. Command id 0x192: Gets a file from the C2 and execute it using the system function. Unlike the previously documented command id 0x185, this command calls first ‘CFileControl::FileUp’ to receive the file from the C2. Command id 0x195: Exfiltration of files with the following extensions: v2, .k2, .W2, and drive.C2. We also located an older sample submitted to VirusTotal from Iran on February 5, 2025:
intezer.comAug 13, 2025extracted