Visualização de leitura

Liquid Network Hackers Demand Bug Fix Before Returning $320M BTC

Liquid Network security incident

The Liquid Network security incident has taken an unusual turn after the unidentified actors behind the theft of nearly 4,000 BTC offered to return “most” of the funds — but only after the vulnerability that enabled the exploit is fixed across the network.  The purported white-hat hackers communicated their condition through an ongoing exchange with Blockstream, according to Galaxy Research head Alex Thorn. The incident involved roughly $320 million worth of BTC and has raised questions over whether the attackers are genuine security researchers or simply exploiting the language and behavior associated with white-hat hacking.  The episode began on Sunday, when approximately 4,000 BTC was withdrawn from the Liquid Federation wallet. The amount represented about 95% of the Bitcoin that had been pegged into the Liquid sidechain.  Following the withdrawals, Liquid disabled its bridge nodes and paused the network. The stolen funds were subsequently consolidated into a Bitcoin address containing a message that read: “we are whitehats. contact us on chain.”  Liquid, however, has continued to describe the individuals involved as purported white-hat hackers, reflecting the uncertainty surrounding their identity and intentions. 

Liquid Network Security Incident Sparks On-Chain Conversation 

The unusual communication between the attackers and Blockstream has taken place through Bitcoin OP_RETURN messages and PGP-encrypted text.  Thorn reconstructed the exchange and reported that Blockstream attempted to contact the actors at Bitcoin block 965,822. The company sent 1,000 satoshis along with an OP_RETURN message intended to alert its security team and establish a communication channel.  A later transaction included encrypted material addressed to the holder of the relevant key, along with a PGP signature. According to Thorn, the signature could be verified against Blockstream’s published public key, providing an indication that the communication was connected to the company.  The purported white-hat hackers subsequently responded at block 965,869. They moved their own balance and sent 1,000 satoshis to the federation’s peg wallet. Alongside the transaction, they asked whether returning “most” of the withdrawn BTC to the federation address would be acceptable.  That proposal came with a significant condition: the vulnerability responsible for the Liquid Network security incident would have to be fixed first.  “Please fix the bug first,” the hackers told Blockstream. 

White-Hat Hackers Leave Questions Over Returned BTC 

The use of the word “most” has introduced another layer of uncertainty. The message does not specify how much BTC the actors would ultimately return, leaving open the possibility that they could retain a portion of the nearly 4,000 BTC taken from the federation wallet.  There is also no guarantee that the promised return will actually occur. Until the funds move back to the federation-controlled address, almost all of the Bitcoin remains under the control of the unidentified actors.  The incident initially prompted skepticism from Ledger Chief Technology Officer Charles Guillemet, who argued that conventional white-hat hackers generally do not drain hundreds of millions of dollars from a bridge.  Guillemet compared the situation with major cryptocurrency exploits such as Ronin and Euler, where attackers were responsible for substantial losses. His initial assessment suggested that the scale and method of the Liquid incident were inconsistent with the typical behavior expected from legitimate security researchers.  His position later softened after the hackers attempted to communicate with Blockstream. 

BTC Remains Under Hackers’ Control 

Guillemet noted that criminal groups do not typically make efforts to establish direct communication with their victims after carrying out an exploit. The willingness of the actors to communicate therefore created some hope that the funds could eventually be recovered.  “There’s hope,” Guillemet wrote.  He also argued that the vulnerability could potentially be researched using powerful AI systems to identify the underlying flaw without relying on proper disclosure procedures.  For now, however, the outcome of the Liquid Network security incident remains unresolved. The hackers have indicated that they are prepared to return “most” of the BTC, but only once the underlying bug has been fixed across the network.  The development leaves Blockstream and Liquid facing two immediate challenges: addressing the vulnerability that allowed the exploit and determining whether the unidentified actors will honor their commitment.  Until those steps are completed, the nearly 4,000 BTC involved in the incident remains largely outside the federation’s control. The on-chain messages provide a rare window into negotiations between an exploited crypto network and the people claiming responsibility, but they do not yet establish whether the purported white-hat hackers will ultimately return the funds. 

Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ

Mathspace data breach

The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said the affected records involve students, parents or guardians, teachers, and Mathspace staff.  The company said names, email addresses, and account details were exposed, but customer passwords, single sign-on (SSO) tokens, and other authentication credentials were not. There is currently no evidence that the information has been published, sold, distributed, or otherwise misused. The attacker’s identity remains unknown. 

How the Mathspace Data Breach Happened? 

The security incident resulted from a vulnerability in Mathspace’s self-hosted Metabase installation, which was used for internal reporting. The flaw allowed attackers to obtain administrator access without a legitimate login.  Metabase issued a critical security advisory and patched versions on August 6. Mathspace said its vulnerability-notification process failed to identify and escalate that advisory. The company later updated its Metabase instance on August 29 after seeing a subsequent notice.  An investigation found unauthorized access dating to August 10, Australian Eastern Standard Time. Information was downloaded from Mathspace’s Australian reporting database on August 27. Historical log reviews confirmed the unauthorized access on September 3, before the update had been applied. Mathspace also acknowledged that it did not complete additional compromise checks recommended for potentially affected systems at the time of the update. 

What Information was Exposed? 

The exported data included user IDs, usernames, first and last names, email addresses, country, time zone, user type, email-verification status, last-active date, last-login date and joining date. Not every field appeared for every affected person.  Mathspace said the exposure went beyond names and email addresses. User IDs are internal identifiers, including those linked to student accounts. However, no academic records, learning activities, results, assessments, password hashes, authentication tokens, SSO credentials or API credentials were exposed.  The data did not contain records directly linking accounts to schools, although Mathspace said school affiliations could potentially be inferred where identifiable email domains were used. Former or inactive users may also be affected because retained information could remain in the reporting database. 

What Users Should Know After the Security Incident? 

Names, email addresses, and account details could make phishing or impersonation attempts more convincing. Users have been advised to independently verify unexpected messages, avoid unfamiliar links and attachments, and never provide passwords or verification codes in response to unsolicited communications.  Mathspace is not requiring password resets because customer authentication credentials were not exposed. However, anyone who reused a Mathspace password elsewhere should change those reused passwords to unique ones and monitor accounts for unusual activity. 

Response to the Mathspace Data Breach 

After confirming the breach on September 3, Mathspace took Metabase offline, revoked its API keys, disabled Metabase database-access accounts in its Australian and US Snowflake environments, and changed passwords for its Metabase Cloud SQL databases. The company also copied the application database and exported access logs for investigation. Metabase remains offline while recovery and compromise checks continue.  Mathspace began notifying school contacts on September 4 and started notifying affected individuals on September 6, earlier than the date previously communicated to schools.  On September 4, the security incident was reported to Australia’s Office of the Australian Information Commissioner, the Australian Signals Directorate’s Australian Cyber Security Centre, New Zealand’s Office of the Privacy Commissioner and National Cyber Security Centre, as well as Australian state and territory education departments. 

G7, CISA Urge Urgent Shift to Post-Quantum Cryptography

post-quantum cryptography

Some of the world's leading democracies are pushing governments and companies to start preparing for post-quantum cryptography before quantum computers become powerful enough to break the encryption systems that protect global digital infrastructure today.

In a joint advisory released Thursday, the G7 Cybersecurity Working Group and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said organizations should begin their transition to post-quantum cryptography now, rather than waiting until cryptographically relevant quantum computers (CRQCs) are available to threat actors.

Why the Post-Quantum Cryptography Shift Cannot Wait

The publication, titled "Preparing for the Post-Quantum Era: A Call to Action," warns that the quantum computing threat is no longer a distant concern. While the exact timeline for CRQC development remains uncertain, the working group said recent technological advances suggest such machines could emerge sooner than expected, putting widely used public-key cryptography mechanisms at risk.

One of the most immediate dangers is a tactic known as "harvest now, decrypt later," where malicious actors intercept and store encrypted data today with the intention of decrypting it once a CRQC becomes available. This poses a serious risk to governmental records, sensitive personal data, and trade or business secrets that require long-term confidentiality.

The advisory also cautions that CRQCs could eventually be used to target authentication mechanisms, allowing bad actors to impersonate trusted entities, forge data, or compromise equipment. Because supply chain vulnerabilities can cascade, a single organization's delay in adopting post-quantum cryptography could expose entire sectors to compromise.

According to the report, organizations that fail to act may also face business consequences beyond security risk, including exclusion from public procurement contracts and loss of competitive advantage.

Five Priorities for the PQC Transition

The G7 Cybersecurity Working Group outlined five priority areas to guide the global shift toward post-quantum cryptography:

  1. Raising awareness — Many organizations still view the quantum threat as a distant or purely technical issue. The group called for awareness campaigns, technical guidance, and workforce upskilling to reframe it as an economic and business risk.
  2. Developing national strategies — Countries are encouraged to build strategies that ensure an adequate supply of quantum-safe hardware and software while encouraging adoption, integrating the effort into broader digital privacy and security policies.
  3. Advancing research and development — Governments should fund research programs and support pilot projects and testbeds to help organizations test and refine their transition to post-quantum cryptography.
  4. Building public-private partnerships — Collaboration between government, industry, and academia is seen as key to developing domestic expertise, lowering transition costs, and sharing playbooks and case studies across sectors.
  5. Integrating PQC into cybersecurity requirements — The group recommends treating post-quantum cryptography adoption as a natural evolution of cryptographic best practice, and embedding requirements into public procurement to push both vendors and organizations toward quantum-safe systems.

The advisory emphasizes that the shift to post-quantum cryptography cannot be solved by individual organizations in isolation. Instead, it calls for early engagement, coordinated planning, and informed decision-making across public and private sectors worldwide.

Tackling the risks that the impending quantum computing era poses to current cryptographic systems... requires a coordinated global effort to transition to PQC," the report states, adding that public and private organizations must act now to safeguard confidential data, supply chains, and critical systems.

The document was jointly published by cybersecurity authorities from Canada, Germany, Italy, Japan, the United Kingdom, the United States, and France's ANSSI, with participation from the European Commission and support from the EU Agency for Cybersecurity (ENISA).

US Puts $10 Million Bounty on Alleged Iranian Cyber Chief

$10 Million Reward for Amir Yaryab

The U.S. State Department has posted a $10 million reward for Amir Yaryab, a senior Iranian official accused of leading the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) Cyber Operations Command and directing multiple hacking groups targeting critical infrastructure across the United States, Europe and the Middle East. According to the Rewards for Justice program, Yaryab allegedly oversees cyber operations conducted by IRGC-CEC-affiliated groups including CyberAv3ngers, Dadeh Afzar Arman (DAA) and Mehrsam Andisheh Saz Nik (MASN). U.S. officials accuse these groups of using malware and conducting cyber and cyber-enabled information operations against civilian infrastructure worldwide.

$10 Million Reward for Amir Yaryab

The $10 million reward for Amir Yaryab seeks information leading to his identification or location. The offer applies to individuals acting at the direction or under the control of a foreign government who participate in malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act. [caption id="attachment_113961" align="aligncenter" width="600"]$10 million reward for Amir Yaryab Image Source: https://rewardsforjustice.net/[/caption] Yaryab is also accused of directing Shahid Hemmat and Shahid Shushtari, two groups linked to cyberattacks against U.S. organizations. The sectors allegedly targeted include defense, news, shipping, travel, energy, financial services and telecommunications. The six Iranian officials named in the advisory are linked to Iran's Islamic Revolutionary Guard Corps and its Cyber-Electronic Command.

Iranian Cyberattacks Target PLCs

The allegations also involve attacks against programmable logic controllers (PLCs), highlighting concerns around Iranian cyberattacks targeting industrial systems rather than focusing only on data theft. U.S. officials said Iranian-linked hackers compromised industrial control systems, specifically targeting the Vision series of PLCs manufactured by Israel-based Unitronics. These devices are used across water and wastewater, energy, food and beverage, manufacturing and healthcare sectors. The attackers exploited default credentials on the devices and left anti-Israel messages. Some of the compromises reportedly rendered the PLCs inoperative. The CyberAv3ngers group, which is linked to the IRGC-CEC, claimed responsibility for attacks against Unitronics Vision PLCs in October 2023. Beginning in November 2023, the group compromised default credentials in PLCs across the United States and left messages on the devices' digital screens.

CyberAv3ngers Attacks Critical Infrastructure

CyberAv3ngers has also claimed responsibility for attacks affecting other infrastructure. In October 2023, the group claimed it had breached ORPAK Systems, a provider of gas station solutions in Israel. The group said it had obtained the company's database and intended to publish it through its Telegram channel. The attack was reported to have disconnected 200 gasoline pumps from the system in the occupied Palestinian territories. In December 2023, CyberAv3ngers also claimed to possess and sell 1TB of data allegedly linked to Israel's electricity infrastructure. The group advertised the dataset for 5 Bitcoin, with an initial 100GB portion also offered at the same price.

U.S. Agencies Warn of PLC Cyberattacks

Concerns over critical infrastructure attacks involving PLCs continued into 2026. A joint advisory issued on April 7 by the FBI, CISA, NSA and other agencies warned that Iran-linked threat actors were actively exploiting internet-facing PLCs. The advisory said several organizations had experienced operational disruptions and financial losses after attackers interfered with industrial processes. The developments come amid broader U.S. actions against Iranian-linked cyber activity. The Justice Department accused Iran-connected hackers of breaching employee email accounts associated with the Department of Labor, the Federal Energy Regulatory Commission and multiple United Nations organizations. The Treasury Department also sanctioned Iranian nationals over cyberattacks targeting critical infrastructure. The State Department's reward offer places Amir Yaryab and the alleged activities of IRGC-CEC-linked groups at the center of the U.S. effort to identify individuals responsible for malicious cyber activity targeting critical infrastructure.

The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks

Weekly Roundup September 2026

This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure.  From stolen Claude sessions and bypassed PaperCut security fixes to an attempted attack targeting hundreds of thousands of X users, recent incidents demonstrate how attackers continue to exploit both software vulnerabilities and active user sessions.  The latest developments also show that organizations face growing risks across AI services, on-premises systems, enterprise edge devices, and account recovery infrastructure. Security teams are being urged to respond quickly as attackers increasingly target exposed systems and authentication mechanisms. 

The Cyber Express Weekly Roundup 

Anthropic Warns of Claude Session Hijacking 

Anthropic has warned that common infostealer malware is being used to steal active Claude sessions, potentially allowing attackers to bypass passwords and two-factor authentication. The campaign involves malware such as Vidar, LummaC2, RedLine, and Atomic Stealer, which is often distributed through pirated software and illicit downloads. Attackers may also consume victims’ paid AI usage. Read more… 

PaperCut Releases Second Emergency Patch After First Fix Is Bypassed 

PaperCut has released a second emergency patch for two actively exploited vulnerabilities affecting its NG and MF print management servers. Researchers discovered ways to bypass the initial security fix, potentially allowing attackers to chain the flaws and achieve pre-authentication remote code execution on exposed systems. Read more… 

Boston Scientific Cyberattack Limited to Certain On-Premises Systems 

Boston Scientific says its ongoing cybersecurity incident is limited to certain on-premises systems, with no impact identified on its cloud-based applications. The company has also reported no confirmed data breach or evidence of unauthorized activity since August 25, as its investigation into the incident continues. Read more… 

DOJ Investigates Attempted Cyberattack on Hundreds of Thousands of X Users 

The U.S. Department of Justice is investigating a large-scale cyberattack targeting hundreds of thousands of X accounts through the platform’s password-recovery system. Attorney General Todd Blanche said X detected and disrupted the campaign before the targeted accounts could be captured, preventing the attempted account takeover operation from succeeding. Read more… 

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk 

Two vulnerabilities in Citrix NetScaler ADC and Gateway have prompted an urgent patching warning from Australia’s cybersecurity agency. CVE-2026-19489, a memory overflow flaw, and CVE-2026-19490, an authentication bypass, can affect systems with specific configurations involving SIP ALG, SAML, or VPN gateway functionality. Read more… 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are increasingly targeting authentication systems, active user sessions, exposed enterprise infrastructure, and critical business applications. AI platforms, print management servers, healthcare environments, social media accounts, and network edge devices all remain potential targets for attackers.  Organizations should prioritize rapid security patching, protection of active sessions, strong authentication controls, careful monitoring of exposed infrastructure, and timely investigation of suspicious activity. Security teams should also review systems that rely on password-recovery mechanisms and identify enterprise devices operating with vulnerable configurations.  As businesses continue to rely on cloud services, AI platforms, remote access technologies, and internet-facing enterprise systems, attackers are finding new opportunities to exploit trusted sessions and security weaknesses. Organizations must maintain continuous monitoring and rapid response capabilities to reduce the impact of increasingly targeted cyberattacks. 

Kentucky Appellate Court Data Caught in Multi-State Cyber Data Breach

Kentucky Appellate Court Data

The Kentucky Administrative Office of the Courts (AOC) has confirmed that Kentucky Appellate Court data was compromised in a cybersecurity breach traced to a third-party vendor. West Publishing Corporation, operating as Thomson Reuters Court Management Solutions (Thomson Reuters CMS), informed the AOC that the incident originated within file systems tied to its C-Track case management platform.  C-Track is the system relied upon by the Kentucky Supreme Court and the Kentucky Court of Appeals to manage case records. Because Kentucky does not currently use third-party vendors for trial court e-filing, trial-level records that were never part of an appeal remain unaffected. The exposure is limited to Kentucky Appellate Court data that had been stored within Thomson Reuters CMS/C-Track infrastructure.  According to Thomson Reuters CMS, an unauthorized third party gained access to and obtained court data from C-Track systems across several states, not Kentucky alone. The AOC noted that Kentucky's Appellate Courts continued to function normally throughout the incident and were not operationally disrupted. 

The Kentucky Appellate Court Data Breach Incident  

The AOC said it currently has no indication that the unauthorized party shared or distributed Kentucky's data with any outside individual or entity. Thomson Reuters CMS has stated it is coordinating with third-party cybersecurity specialists and law enforcement, and has assured every affected jurisdiction, including Kentucky, that mitigation measures have been implemented to reduce the risk of future unauthorized access.  Any individuals ultimately confirmed to be affected by the data breach will be contacted directly by Thomson Reuters CMS. Those notified will receive additional details about the incident along with 12 months of complimentary credit monitoring and identity theft protection, funded by the company. 

Scope of Impact Still Under Review 

Thomson Reuters CMS is currently working through each affected court system individually, reviewing what data was exposed and determining which people or organizations warrant notification. The company has indicated this review will take time given the multi-state scope of the breach.  The AOC, however, has pressed for a faster timeline, telling Thomson Reuters CMS that it expects prompt resolution and swift notification to anyone impacted. As of now, the total number of individuals or organizations affected — if any — has not been determined. Thomson Reuters CMS has committed to covering all costs associated with the breach and will handle notification once affected parties are identified. 

AOC Response and Oversight 

The AOC emphasized that safeguarding information entrusted to Kentucky's Judicial Branch remains a core responsibility. As the investigation proceeds, the office says it is closely tracking developments, evaluating any potential consequences for the Judicial Branch, and following its established cybersecurity protocols to protect the appellate case management system tied to the Kentucky Supreme Court and Court of Appeals.  The AOC is also taking part in ongoing status briefings with the National Center for State Courts and is coordinating with officials in other states affected by the same Thomson Reuters CMS/C-Track breach, as the response to this data breach continues to unfold on a multi-jurisdictional scale. 

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk

Citrix NetScaler vulnerabilities

Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority. Citrix has identified two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, which are critical edge devices used in enterprise networking to securely deliver applications, data and remote access to users.

Citrix NetScaler Vulnerabilities Affect ADC and Gateway

The first flaw, CVE-2026-19489, is a memory overflow vulnerability. According to the alert, exploitation of this vulnerability requires SIP ALG, or Session Initiation Protocol Application Layer Gateway, to be enabled on a Large Scale NAT (LSN) group configuration. The second flaw, CVE-2026-19490, is an authentication bypass vulnerability. The vulnerability requires SAML actions to be enabled and/or the affected product to be configured as a VPN gateway. The conditions required for each vulnerability mean that organisations need to assess their specific Citrix configurations to determine whether affected systems are present in their environments.

Patches Released for Citrix NetScaler products

Citrix released patches for the affected products on August 19, 2026. ASD's ACSC is urging organisations to review the vendor's mitigation guidance, identify vulnerable versions of Citrix products and update affected systems to the latest versions. The advisory places particular emphasis on timely patching because critical edge devices are frequently targeted by threat actors as an entry point into sensitive environments. However, ASD's ACSC said it has no information indicating that a specific Australian industry or sector is currently being targeted in connection with these vulnerabilities.

Organisations Urged to Assess Vulnerable Versions

The mitigation guidance calls on organisations to assess their networks and environments for vulnerable versions of Citrix products and apply patches as soon as practicable. Organisations should also review the mitigation advice provided by Citrix and confirm that affected systems have been updated. Where NetScaler ADC and NetScaler Gateway products are managed by a third party, organisations are advised to contact the relevant managed service provider (MSP) or enterprise IT provider. They should confirm that the products have been patched and are being monitored for suspicious activity. This step is particularly relevant for organisations that do not directly manage their Citrix infrastructure and may rely on external providers for patching and monitoring.

Monitoring Remains Important After Patching

Alongside addressing the Citrix NetScaler vulnerabilities, organisations are advised to monitor affected environments for suspicious activity. The alert recommends notifying ASD's ACSC if suspicious activity is detected. The two vulnerabilities affect different configurations, with CVE-2026-19489 requiring SIP ALG to be enabled on an LSN group configuration, while CVE-2026-19490 requires SAML actions to be enabled and/or the product to be configured as a VPN gateway. For Australian organisations using Citrix NetScaler products, the immediate steps outlined by ASD's ACSC are to identify vulnerable versions, apply the available patches, confirm third-party-managed systems have been addressed and maintain monitoring for suspicious activity.

Pegasus, New NoviSpy Variant Found on Serbian Students and Opposition Figures

Pegasus, Pegasus Spyware, Serbia, Serbia Protests, Smartphone screen forming an eye shape against an abstract protest crowd, illustrating spyware targeting of Serbian student activists.

At least 14 people connected to Serbia's student protest movement and opposition politics have been targeted with mercenary spyware since early 2026, the Belgrade-based digital rights organization SHARE Foundation said, in what it called the largest documented wave of such targeting in the country.

The group said the cohort includes student movement members, civil society activists, a member of parliament and a local councilor. Forensic analysis was independently confirmed by the Citizen Lab at the University of Toronto and by Amnesty International's Security Lab.

Citizen Lab, in its own findings, said it verified an infection with NSO Group's Pegasus on the iPhone of a student activist who asked not to be named. High-confidence infection indicators span December 2025 through January 2026, delivered by a zero-click iMessage exploit that required no interaction from the target. Apple has since patched the underlying flaw; the fix shipped in iOS 18.4.1. Pegasus grants an operator access to notes, photographs and messages decrypted on the device, and can silently activate the microphone and camera.

Amnesty's Security Lab confirmed a new variant of NoviSpy, an Android implant first identified in Serbia in 2024, on two additional devices. SHARE said the rebuilt version was designed to evade the detection methods that exposed its predecessor.

Also read: Investigative Journalists in Serbia Hit by Advanced Spyware Attack

The circumstances of two infections are what elevate the findings beyond routine spyware reporting. SHARE said one NoviSpy infection appeared after police seized a student's phone during questioning, and another after private messages from that device were published by a pro-government media outlet. Donncha Ó Cearbhaill, who heads Amnesty's Security Lab, said the evidence suggests "infections are being carried out during detention by Serbian authorities."

Suspicion centers on Serbia's Security Information Agency, or BIA. Amnesty's December 2024 report "A Digital Prison" found earlier NoviSpy samples configured to send collected data to IP addresses associated with BIA servers, and documented the agency's parallel use of Cellebrite extraction tools on journalists and activists. In March 2025, Amnesty reported that two journalists at the Balkan Investigative Reporting Network were targeted with Pegasus.

The current cases surfaced through Apple's threat notification wave of Aug. 13, which reached users in 110 countries. The timing is politically loaded. The targeting overlaps with protests that followed the November 2024 collapse of a railway station canopy in Novi Sad, spans local elections held March 29 in 10 municipalities, and precedes October parliamentary elections widely read as a test of the ruling Serbian Progressive Party.

Ana Toskic Cvetinovic, a legal expert cited in the reporting, noted that deploying intrusive software without judicial authorization is unlawful under Serbian law. SHARE published an analysis of the domestic legal framework in January arguing the same. Criminal complaints filed over the 2024 cases remain pending before Serbian courts, with no resolution.

Also read: 7 New Pegasus Infections Found on Media and Activists’ Devices in the EU

NSO has been on the U.S. Commerce Department's Entity List since 2021.

Serbia is an accession candidate, the European Parliament has previously questioned the Commission over unlawful spyware use in the country, and the Commission published its 2026 enlargement country report in July. Amnesty's submission for that package raised surveillance directly.

Both groups urged at-risk users to enable Lockdown Mode on iOS or Advanced Protection on Android.

CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk

CVE-2026-84115

A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT Refresh Token Handler and the /api/connections endpoint.   MITRE documented the issue on September 1, 2026, while VulDB classified it as a serious privilege-management vulnerability with a CVSS score of 8.3. 

CVE-2026-84115 Targets JWT Refresh Token Handler 

According to the vulnerability analysis, CVE-2026-84115 involves an unknown function within the JWT Refresh Token Handler component. The affected functionality processes requests sent to /api/connections, where manipulation of the Bearer argument in HTTP authorization headers can lead to improper privilege management.  The weakness is classified as CWE-269, which refers to Improper Privilege Management. The flaw can allow an attacker to manipulate authentication-token arguments and potentially bypass intended access controls, gaining privileges beyond those assigned to the account. 

Remote Exploitation Raises CVE-2026-84115 Risk 

The vulnerability is remotely exploitable because the attack can be conducted through network-based HTTP requests without requiring local or physical access to the targeted system. The risk is heightened because a public exploit has reportedly been made available.  An attacker exploiting CVE-2026-84115 could potentially obtain unauthorized administrative access, view sensitive information stored within Harmony, or interfere with integration workflows managed through the platform. Such activity could affect the confidentiality, integrity, and availability of systems that depend on Cleo Harmony for file transfer and API connectivity.  The VulDB analysis links the exploitation method to authentication bypass through token manipulation. Attackers could potentially intercept legitimate traffic or create forged requests using malformed or replayed bearer tokens to circumvent JWT refresh-token controls. In environments where Cleo Harmony is connected to other systems, successful exploitation could also provide opportunities for further lateral movement. 

CVE-2026-84115 Remediation Requires an Upgrade 

Organizations using affected Cleo Harmony versions should upgrade to version 5.8.1.11 or later. The release contains the necessary correction for the privilege-management problem affecting the JWT Refresh Token Handler.  Until patching is possible, organizations can strengthen input validation on API endpoints and monitor for unusual patterns involving bearer tokens. These measures may improve detection and reduce exposure, but they do not replace the recommended software upgrade, particularly given the reported public exploit.  VulDB is listed as the responsible organization, with the vulnerability recorded under VDB-397558. Disclosure took place on September 1, 2026, and the entry has an accepted moderation status, with CPE marked as ready. CWE-269 is confirmed for the vulnerability. VulDB assigns CVE-2026-84115 a CVSS score of 8.3 and an EPSS score of 0.00284. The vulnerability record also identifies an exploit as available for download.

SonicWall Warns of Two Actively Exploited SMA1000 Zero-Days, One Rated Maximum Severity

Graphic showing SonicWall SMA1000 devices, CVE-2026-83548, the maximum-severity SonicWall SMA1000 pre-authentication vulnerability

SonicWall disclosed this week that attackers are chaining two previously unknown vulnerabilities in its SMA1000 secure access appliances to run commands on unpatched devices, and urged customers to install an emergency hotfix.

The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery weakness in the appliance's Appliance Work Place interface, rated 10.0 on the CVSS scale. It lets a remote attacker with no credentials reach sensitive internal functionality. The second, CVE-2026-83549, is an operating-system command injection bug in the Appliance Management Console rated 7.8; on its own it requires administrative authentication, but paired with the SSRF flaw it yields remote code execution.

The vendor said it found both issues internally and then observed them being used together in live attacks. SonicWall has not published indicators of compromise or described the attackers.

Affected products are the SMA1000 series 6210, 7210 and 8200v, in both hardware and virtual form. Fixed builds are 12.4.3-03526 and later, and 12.5.0-02952 and later. SonicWall firewalls running SSL-VPN and the separate SMA 100 line are not affected.

Remediation guidance goes beyond patching. SonicWall told customers to contact its support organization to review appliances for signs of intrusion and, where compromise is suspected, to re-image or redeploy the device, rotate all credentials and reset TOTP tokens — an acknowledgment that one-time-password seeds stored on a breached appliance survive a software update. The company said customers should move to the hotfix release as quickly as possible.

Shadowserver Foundation scanning has tracked more than 400 internet-exposed SMA1000 appliances, though an unknown share of those are already patched. The small install base belies the risk profile. These are remote-access gateways that sit at the network edge and hold credentials for the environments behind them.

The disclosure extends a difficult run for the product line. Attackers exploited a separate pair of SMA1000 zero-days in July 2026, tracked as CVE-2026-15409 and CVE-2026-15410, to deploy custom malware; CISA later confirmed ransomware operators were abusing that access.

Read: CISA Adds SonicWall SMA1000 Vulnerabilities to KEV Catalog Following Active Exploitation

Another zero-day surfaced in December 2025. Seventeen SonicWall vulnerabilities across the company's product families currently sit in CISA's Known Exploited Vulnerabilities catalog. Edge appliances from SonicWall, Ivanti, Citrix and Fortinet have collectively become the preferred initial-access route for ransomware affiliates and espionage crews, because they are internet-facing by design and rarely instrumented with endpoint detection.

CISA, FBI Urge Clearer Communication During Major Outages

outage communications

The CISA and FBI, along with cybersecurity agencies from Australia, Canada, New Zealand and the U.K., have released new guidance on outage communications for service providers dealing with major IT and OT outages. The guide calls for prompt, factual and audience-specific communication during disruptions caused by malicious cyber activity or non-malicious events.

Titled “Communicating Under Pressure: Best Practices for Service Providers,” the guidance says effective communication is critical to limiting operational impact when IT and OT outages affect customers, network defenders, critical infrastructure owners and operators, and the public. It recommends that organizations clearly communicate what is known, what remains unknown and what is still under investigation, while providing frequent updates as circumstances change.

Outage Communications Should Start With Facts

The agencies recommend that service providers establish an outage communications plan before an incident occurs. The plan should define incident thresholds, escalation paths, target audiences and procedures for status pages, customer and partner notices, and regulatory communications. Organizations are also advised to establish cross-functional incident teams involving engineering and operations, communications, legal, risk and compliance, and customer support.

The guidance calls for clearly defined roles, including an incident lead, communications lead and spokesperson. It also recommends parallel workstreams so technical teams can focus on diagnosing and remediating the root cause while communications teams manage external messaging and leadership handles strategy and regulatory requirements.

For organizations responding to cyber incidents, the guidance places particular emphasis on balancing transparency with operational security. If malicious activity is suspected or confirmed, external communications should not compromise investigations, containment efforts or other response activities. Organizations are also advised against making premature conclusions when the root cause remains under investigation.

Service Providers Urged to Tailor Messages

The guidance recommends segmenting communications for technical teams, executives and the public. Audiences can include enterprise IT teams and security operations centers, employees and customers, government partners and regulators, critical infrastructure owners and operators, as well as the media and general public.

During an outage, organizations should lead with a concise summary covering affected systems, user impact, scope and the known cause without speculation. The agencies also advise against vague descriptions such as “service degradation” and recommend messaging that can be understood quickly during high-pressure situations.

Transparency is another central principle. Service providers are advised to state what they know and do not know, use a single source of truth such as a status page, and focus communications on actionable guidance rather than reputation management. Customers should be told what actions they need to take or clearly informed when no action is required.

The guidance also calls for continuous, time-stamped updates that show the incident timeline, actions taken, and recovery milestones. Organizations should maintain a single status page and align external messaging with legal, contractual and sector-specific reporting obligations.

Agencies ultimately frame effective outage communications around five principles: immediate acknowledgement, technical and actionable information, transparency, accountability, and continuous updates. For service providers, the guidance positions communication as an important part of incident response, alongside technical remediation and recovery.

DOJ Investigates Cyberattack Targeting Hundreds of Thousands of X Users

cyberattack on X users

A cyberattack on X users that targeted hundreds of thousands of accounts has prompted an investigation by the US Department of Justice (DOJ), with Attorney General Todd Blanche saying sophisticated cybercriminals attempted to exploit the platform's password-recovery system. The DOJ is working with Elon Musk's X, formerly known as Twitter, to identify those responsible for the attempted attack, according to Blanche's statement on Wednesday. The incident involved hundreds of thousands of X users and was disrupted before the targeted accounts could be captured, Blanche said.

Blanche Says DOJ Is Tracking Those Behind Cyberattack on X Users 

In a statement posted on X, Blanche described the incident as a password-recovery attack carried out by "sophisticated cyber criminals." He said X managed to disrupt the effort and prevent user accounts from being taken over.  Blanche wrote: 
This week, sophisticated cyber criminals attempted a password-recovery attack on hundreds of thousands of X users. X disrupted the attack to prevent user accounts from being captured. But, as we’ve shown, the Justice Department will stop at nothing in its pursuit of cyber fraudsters and scammers. We are working closely with @X to track down the criminals behind this week’s attack. There is no refuge for those that perpetrate their criminal schemes from behind computer screens." 
The attorney general did not disclose additional technical details about the cyberattack on X users, including how the attackers attempted to exploit the recovery system, whether any individual accounts were compromised, or where the suspected criminals were operating from.  The DOJ investigation is intended to identify those responsible for the attempted intrusion, with Blanche emphasizing that authorities would pursue individuals involved in cyber fraud and scams even when those activities are conducted remotely. 

How the Password-Recovery Attack Works 

A password-recovery attack generally targets the systems users rely on when they have forgotten their login credentials. These processes can include "forgot password" features, account-recovery forms, and other mechanisms designed to help legitimate users regain access to their accounts. Attackers may attempt to exploit weaknesses in those processes to obtain access to accounts. In the incident involving X, the platform was able to disrupt the effort before the targeted accounts were captured, according to Blanche. The scale of the attempted cyberattack on X users—hundreds of thousands of accounts—makes the incident notable, although the attorney general did not provide a breakdown of how many accounts were actually affected or whether any users suffered losses. 

AI-Driven Cyberattacks Add to Growing Security Concerns 

The X incident comes against a wider backdrop of increasing cybersecurity threats facing companies and organizations around the world.  Businesses have been dealing with a rise in AI-driven cyberattacks as well as ransomware campaigns capable of stealing sensitive information, interrupting operations, and creating significant financial and operational damage.  The growing use of artificial intelligence in cyber operations has raised concerns that attackers can automate or accelerate parts of their campaigns. At the same time, organizations are exploring ways to use AI-based systems to identify vulnerabilities and strengthen their defenses.  The DOJ has also been pursuing cases involving sophisticated cyber operations. Days before news of the cyberattack on X users, the department announced an operation targeting QTFY, described by US authorities as a Chinese cyberespionage platform. 

DOJ Previously Targeted QTFY Cyberespionage Platform 

According to the Justice Department, QTFY had targeted several US institutions and organizations. Those named by the department included the US Senate, the Federal Reserve, and NASA, among others.  The action against QTFY highlights the broader range of cyber threats confronting US institutions, from espionage operations to attacks aimed at obtaining access to online accounts.  The latest investigation involving X therefore comes amid a broader push by US authorities to identify and disrupt cyber criminals and state-linked cyber operations. 

Boston Scientific Cyberattack Limited to Unauthorized Access on Certain On-Premises Systems

Boston Scientific cyberattack

As per Boston Scientific’s Aug. 30 update, “the unauthorized activity is limited to certain on-premises systems,” providing the clearest indication yet of the scope of the cybersecurity incident that has disrupted the medical device maker’s global network and business operations. Boston Scientific said the investigation into the disruption remains ongoing, with third-party cybersecurity experts. Based on its investigation to date, the company said it has found no indication of unauthorized activity in its environment related to the incident since Aug. 25. The company also clarified that its cloud-based systems and applications have not been affected. The unauthorized activity identified so far is confined to only limited on-premises systems. The clarification comes as Boston Scientific continues working to restore systems supporting manufacturing, ordering and shipping. The company has not established a timeline for a full return to normal operations.

Boston Scientific Ordering and Shipping Recovery Underway 

Boston Scientific said its confidence in restoring ordering, shipping and related system access “continues to increase” and that it is working toward a partial restoration of shipping for some products during the week following its Aug. 30 update. The company said it expects ordering and shipping to ramp up to full capacity once it can demonstrate that the restored operations are fully functional. For now, customers can continue to submit orders electronically through Electronic Data Interchange (EDI) and local applications. Those orders can be placed into a queue for future fulfillment, including orders submitted through the Global Health Exchange (GHX). The latest update indicates that the company’s ability to receive orders electronically has remained intact even while systems required to fulfill and ship those orders have been disrupted. Boston Scientific has not provided a specific date for when full ordering and shipping capacity will return.

Investigation Has Not Confirmed a Data Breach 

Boston Scientific has not said that the cybersecurity incident resulted in a confirmed data breach. Its investigation remains focused on determining the nature, scope, and impact of the unauthorized activity. The Aug. 30 update also provides a more specific picture of the affected technology environment. While certain on-premises systems have been impacted, Boston Scientific said there has been no impact to its cloud-based systems and applications. The company previously said it had found no indication of unauthorized activity in its environment related to the incident since Aug. 25. It has not disclosed whether data was exfiltrated or whether ransomware was involved.

Impact on Medical Devices Remains Limited Based on Current Information

Boston Scientific previously said the incident had not affected devices that are not connected to a Boston Scientific network or clinicians’ ability to use those devices. For Cardiac Rhythm Management (CRM) products, the company reported no known impact on implantable device function, remote monitoring for devices that were already being remotely monitored before the disruption, or programmer interrogations. However, new remote-monitoring activations have been affected. For new CRM implants other than insertable cardiac monitors (ICMs), remote-monitoring communicators cannot currently be activated. As a result, available device data cannot reach remote patient-management systems until activation is possible. Newly implanted ICMs must be activated through the Boston Scientific Clinic Assistant app, but new ICMs cannot currently pair with patients’ remote-monitoring mobile phones. Recorded episodes can still be transmitted through an in-person interrogation using the app’s “Interrogate” function. Boston Scientific said that once its systems are restored and home-monitoring equipment is paired, recorded data will be transmitted to the remote-monitoring system. The company has also said there is no evidence that the affected network environment has increased cybersecurity risks for hospital networks through Boston Scientific devices.

Boston Scientific Continues Incident Response

Boston Scientific said it continues to work with CrowdStrike and other external cybersecurity specialists as the investigation and recovery effort proceeds. The company has been prioritizing systems with the greatest impact on customers and product delivery while working to recover its core business systems. Customers can continue communicating with sales representatives and other Boston Scientific employees through normal channels, including email, established digital platforms and existing connections. The company has acknowledged the potential challenges for customers, patients and suppliers as the disruption continues and thanked them for their patience and partnership. Boston Scientific disclosed the incident in an 8-K filing with the U.S. Securities and Exchange Commission on Aug. 26. The company said it will provide additional updates as appropriate. For now, the latest disclosure narrows the known technical scope of the incident: Boston Scientific says the unauthorized activity is limited to certain on-premises systems, while cloud-based systems and applications remain unaffected. At the same time, the continued disruption to manufacturing, order fulfillment, and shipping means the operational consequences of the attack remain significant as the investigation and recovery effort continue.

PaperCut Issues Second Emergency Patch as Researchers Break Fix for Exploited Zero-Days

Networked office printer emitting a page of hexadecimal code, illustrating the actively exploited PaperCut NG and MF zero-day vulnerabilities.

PaperCut released a second emergency patch last Friday, for two vulnerabilities in its NG and MF print management servers that attackers are already exploiting, after security researchers demonstrated that the vendor's first fix could be bypassed.

The two flaws work as a chain. CVE-2026-81578, rated 8.8 on the CVSS scale, is an improper access control weakness in the PaperCut web management interface that lets unauthenticated remote requests reach administrative functions before the server finishes validating access.

CVE-2026-82078, rated 9.4, is an unsafe dynamic class-loading flaw in the product's database utilities. The application loads database driver classes without checking them against an allowlist, so an attacker who can alter configuration parameters can get arbitrary Java bytecode running inside the application server process. Together they produce pre-authentication remote code execution on an internet-facing server.

PaperCut software runs print queues for universities, school districts, hospitals, local government and large enterprises, and the platform has a history of drawing ransomware attention. Three earlier PaperCut NG/MF vulnerabilities already sit in the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, two of them weaponized in ransomware campaigns.

Also read: CISA Adds Cisco ISE and PaperCut Vulnerabilities to Known Exploited Vulnerabilities Catalog

Huntress, which first documented the activity, said it observed exploitation in two customer environments on Aug. 26 and Aug. 27. In one case the whole intrusion ran under two minutes. Attackers dropped hex-encoded Java class files that the firm described as a bridge between PaperCut and the underlying operating system, then issued basic reconnaissance commands - enumerating the current user, operating system version and running processes - rather than deploying ransomware or other payloads. That pattern typically indicates access brokering or target triage ahead of a later stage.

The reason for a second patch was straightforward; the first one did not hold. Researchers at watchTowr found multiple ways around the original fix and turned up an additional authentication bypass in the process, while Huntress independently reproduced the full attack chain and found its own workarounds. Both firms worked with PaperCut's engineers on Emergency Patch Release 2.

PaperCut said it was aware of confirmed customer incidents and was treating the matter with the highest priority. Release 2 covers PaperCut NG and MF versions 24, 25 and 26 on Windows, Linux and macOS. Customers running version 23 or earlier are told to upgrade rather than wait for a backported patch - a significant caveat, since Huntress reported that roughly 47% of the approximately 2,500 installations it tracks are on those older builds.

The pair had not been added to CISA's KEV catalog as of the vendor's Aug. 28 update.

Whether CISA adds the two CVEs to KEV, whether the reconnaissance-only activity converts into ransomware deployment, and whether Release 2 survives the scrutiny that broke its predecessor, remains to be seen. But administrators should pull PaperCut servers off the public internet regardless of patch status, and check application logs for unexpected process execution and stray .class files.

Anthropic Warns Commodity Infostealers Are Hijacking Claude Sessions to Drain Paid Usage

A session cookie depicted as a key being stolen from a browser window while a two-factor authentication prompt sits bypassed, illustrating Claude session hijacking by infostealer malware.

Anthropic warned users over the weekend that a threat actor is using widely available infostealer malware to hijack active Claude login sessions from infected computers, then using those sessions to run up victims' paid usage without ever needing a password or a two-factor code.

The company said it identified six malware families in the campaign: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer, known as AMOS, on a smaller number of macOS machines. None are novel or bespoke. All are commodity stealers sold or rented on criminal dark web marketplaces, and all work the same basic way - harvesting locally stored browser credentials, autofill data and authentication cookies from a compromised machine and shipping them to an operator's server.

Claude Session Cookies Heist

What makes the campaign notable is the target rather than the technique. Session cookies represent an already-authenticated state, so an attacker who replays a stolen Claude session token steps past both the account password and multi-factor authentication entirely. This is textbook session hijacking; the new element is that paid AI assistant subscriptions have become worth stealing as a commodity in their own right, alongside the streaming and gaming accounts that stealer log markets have traded for years.

Anthropic told affected users that the tell sign for them was a usage pattern that made no sense. Limits appearing to refill and then drain while the account owner was not using Claude was the biggest red flag.

Also read: Hacker Used Claude AI to Automate Reconnaissance, Harvest Credentials and Penetrate Networks

The company said it is signing affected users out of their sessions, removing saved payment methods from compromised accounts and refunding unauthorized charges identified during its investigation. It also stressed that the malware is not connected to Claude, was not installed through Claude and did not result from anything users did with the product. Infections trace to the usual vectors — pirated software and other illicit downloads.

A Reddit user going by the moniker "WorriedAssociate7029" received the notification from Anthropic and confirmed that he mistakenly installed an infostealer from "a reputable Russian underground forum" while downloading a pirated game. "I got fooled like a rookie by downloading a cracked game," he said.

Intrestingly though, the user claimed of using Claude's Opus model to detect and remove the malware.

"I use the models exclusively in permission-free mode on my entire computer," the Reddit user said.
"Opus was very efficient. It scanned for active processes, then listed my recent downloads. It found the virus almost instantly. My prompt was very simple: "I think I downloaded a virus recently. My login credentials were stolen. Audit the malware and remove it if you find it. Report on the extent of the damage. He deactivated the virus and created a folder on the desktop containing all the relevant information (including the deactivated virus, lol)."

Anthropic has not disclosed how many accounts were affected.

The security implications reach past the billing line. AI assistant accounts increasingly hold conversation histories, uploaded documents, connected data sources and, in developer configurations, API keys and repository access. A hijacked session inherits whatever the account can reach. Organizations that have rolled out AI tools without folding them into identity and access management now have a class of high-value session token sitting in employee browsers, largely outside the monitoring applied to corporate SaaS.

Anthropic's guidance to compromised users is the standard infostealer playbook. Change credentials across every service used on the affected machine, revoke active sessions, and actually remove the malware, since signing out does not clear an infection that will simply harvest the next session.

There is no formal regulatory hook here yet — no confirmed breach of the provider itself and no disclosure obligation triggered on Anthropic's side. But the episode lands as regulators and standards bodies are working out how AI system security fits existing frameworks, and it illustrates a gap those frameworks have barely addressed - the weakest point in an AI deployment may be an unmanaged endpoint rather than the model or the platform.

AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields

CVE-2026-77846

CVE-2026-77846, a newly disclosed AshSqlite vulnerability, can allow attackers to access hidden or sensitive fields stored inside JSON and map columns when applications pass untrusted input to AshSqlite's get_path/2 functionality.  The Erlang Ecosystem Foundation's CNA issued the vulnerability entry on August 30, 2026. The issue affects AshSqlite, the SQLite data layer used by the Ash Framework. Although it involves database queries, CVE-2026-77846 is not SQL injection.   Instead, the AshSqlite vulnerability results from unsafe construction of JSON paths and the way SQLite interprets special characters in those paths. 

How the CVE-2026-77846 AshSqlite Vulnerability Works 

In affected releases, AshSqlite generated JSON paths using $."-style path construction through the expression: 
path = "$." <> Enum.join(right, ".") 
The individual path segments were neither escaped nor quoted. Consequently, a key intended to represent the literal name private.secret could instead be interpreted as two JSON levels. Characters such as ., [, ], and $ could similarly alter JSONPath interpretation.  The GitHub advisory describes the flaw as “JSONPath injection in AshSqlite.SqlImplementation get_path”, stating that an attacker controlling a get_path/2 segment can traverse nested JSON and disclose private fields. The affected package is ash_sqlite, with versions 0.1.2-rc.0 through before 0.2.18 affected and 0.2.18 listed as the patched release.  The flaw remains separate from SQL injection because the generated JSON path is supplied to SQLite's json_extract as a bound expression parameter. The attacker manipulates the JSONPath grammar, rather than injecting SQL commands. 

What CVE-2026-77846 Can Expose? 

The AshSqlite vulnerability becomes relevant when an application permits untrusted input to reach get_path/2, such as through a public calculation, filter, or API that lets callers select JSON fields.  A normal endpoint might permit a caller to request a top-level title field. However, supplying private.secret can cause AshSqlite to generate $.private.secret, allowing traversal into a nested object that the API was never intended to expose. Malformed input, such as an unbalanced bracket or bare $, can also produce SQLite JSON path errors that reveal information about the underlying structure.  The published proof of concept used AshSqlite 0.2.17, Bandit, and Req. It created a JSON record containing {"title":"hello","private":{"secret":"s3cr3t-api-key-9f2c"}}. A benign key=title request returned hello, while key=private.secret returned s3cr3t-api-key-9f2c. Captured SQL showed json_extract(p0."data", ?) with the parameter $.private.secret, confirming the traversal. The PoC concluded that a single attacker-controlled path segment could leak a nested value through an endpoint designed to expose only top-level keys. 

Fixes and Administrator Actions for CVE-2026-77846 

The fix replaces the unsafe path joining with encoding that represents keys safely, escapes backslashes and quotes, and handles numeric array indexes separately. Administrators should upgrade to AshSqlite 0.2.18 or later and audit applications that accept network-controlled field-selection input.  Until upgrades are completed, applications should restrict dynamic get_path/2 calls to predefined names, reject dangerous path characters such as periods and brackets, and avoid exposing arbitrary JSON paths.  After upgrading, dependency locks and deployment images should be checked for older ash_sqlite versions. Logs should also be reviewed for unusual dots, brackets, or JSONPath symbols in field-selection requests. Such requests do not prove exploitation, but can help identify systems requiring investigation.  The practical risk of CVE-2026-77846 depends on application architecture. Internal applications without untrusted callers face lower exposure, while public search, filtering, and field-selection APIs require careful validation and access controls. 

The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown

The Cyber Express weekly roundup, podcast

This weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement.   From a critical Microsoft Entra ID vulnerability exploited before remediation to a global crackdown on West African cybercrime networks, recent developments demonstrate how attackers continue to target both technical systems and human trust.  The latest developments also show that cybersecurity risks are expanding alongside the rapid adoption of cloud services and artificial intelligence. Organizations are facing threats involving identity infrastructure, autonomous AI agents, software vulnerabilities, digital transactions, online fraud, and the misuse of emerging technologies. 

The Cyber Express Weekly Roundup 

Microsoft Confirms Exploited Entra ID Flaw 

Microsoft confirmed that a critical vulnerability in Entra ID, CVE-2026-69836, was exploited before the flaw was fixed server-side. The vulnerability carries a CVSS score of 10.0 and could allow unauthenticated attackers to achieve remote code execution, potentially affecting Microsoft’s cloud-based identity infrastructure. Read more... 

New Zealand Proposes Social Media Ban for Under-16s 

New Zealand has introduced legislation that would require high-risk social media platforms to prevent users under the age of 16 from accessing their services. Proposed age-verification methods could include digital identification, facial age estimation, or official identification documents. Read more... 

Cyble and DRONA Launch AI Cyber Defense Initiative in India 

Cyble and DRONA Cyber Solutions have launched an AI-powered cybersecurity initiative in Ahmedabad aimed at helping mid-sized businesses detect, investigate, and contain cyber threats. The initiative combines threat intelligence, AI-driven investigations, and endpoint enforcement to provide organizations with faster and more coordinated responses to security incidents. Read more... 

AI Agents Could Create New Cybersecurity Risks 

Adarsh Kant Sinha, CEO of ANVE.AI, warned that autonomous AI agents could introduce significant new cybersecurity risks as organizations increasingly allow them to interact with business-critical systems. AI agents may gain access to email, customer relationship management platforms, cloud infrastructure, and financial systems, potentially creating new avenues for misuse or compromise. Read more... 

Ledger Fixes Ethereum App Flaw Amid Disclosure Dispute 

Ledger said it fixed a clear-signing vulnerability in its Ethereum application approximately two weeks before security firm TestMachine publicly disclosed the issue. The vulnerability could potentially allow a malicious application to display one transaction to a user while preparing a different transaction for signing. Read more... 

Global Crackdown Nets 58 Arrests in West African Crime Networks 

An eight-month international law enforcement operation led by INTERPOL has resulted in 58 arrests and the identification of 263 suspects across 22 countries. Operation Jackal IV targeted West African criminal networks involved in cyber-enabled fraud, money laundering, romance scams, and investment scams. Read more... 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are crossing organizational, technological, and geographical boundaries, affecting cloud identity systems, artificial intelligence, digital platforms, cryptocurrency applications, and international financial crime.  Organizations should prioritize strong identity and access controls, rapid vulnerability remediation, careful management of AI-agent permissions, secure integrations, human oversight, and continuous threat monitoring.   As autonomous technologies become more deeply integrated into business operations and cybercriminal networks continue to operate across borders, security teams must adapt to a threat landscape that is becoming broader, more interconnected, and increasingly difficult to contain. 

Boston Scientific Cyberattack Disrupts Order Processing, Shipping Worldwide

Boston Scientific Cyberattack, Unopened medical device shipping cartons in a hospital corridor illustrating the Boston Scientific cyberattack disruption to order processing and delivery.

Boston Scientific said a cyberattack detected this Tuesday, caused a network outage and cut off its ability to process and ship customer orders globally, and the medical device maker has not been able to say when full service will return.

The company disclosed the incident in an 8-K filed with the Securities and Exchange Commission on Wednesday and in a statement on its official website. It said the intrusion affected certain information technology systems and limited access to business applications underpinning day-to-day operations.

Boston Scientific is among the world's largest medical device manufacturers, reporting $20.07 billion in 2025 revenue and about $21 billion over the trailing 12 months. Its portfolio includes pacemakers, defibrillators, cardiac stents and neuromodulation implants, and the company says its products treat roughly 48 million patients a year. Thousands of employees in Ireland, where Boston Scientific operates three manufacturing and research sites, were told to work from home on August 26 after network communications were severed.

The company said it activated incident response protocols and engaged outside cybersecurity specialists to contain and investigate the intrusion. It has not said whether ransomware was involved, whether data was exfiltrated, or whether the disruption touches patients with implanted devices. No extortion group had claimed responsibility as of August 26. Shares fell more than 4% following the disclosure.

A Boston Scientific spokesperson declined to answer questions about patient impact and directed reporters to the published statement. Neither the company nor U.S. regulators have said whether hospital procedures have been delayed as a result of the shipping halt, though device suppliers typically hold limited on-site inventory at hospitals, making sustained order outages a downstream supply concern.

The incident is the third disruptive attack on a major medical technology firm in six months. Stryker suffered a global network outage in March after attackers abused its Microsoft Intune deployment to wipe data from thousands of devices, and Medtronic disclosed in April that patient names, Social Security numbers and health information were exposed in a breach attributed to the ShinyHunters extortion group.

Also read: Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

Boston Scientific said it cannot yet assess the full operational and financial impact, language that leaves room for an amended filing once the investigation matures.

The company's Irish footprint also raises the prospect of European scrutiny. If personal data proves to have been accessed, notification duties under the General Data Protection Regulation would attach, and medical device manufacturers operating in the European Union are increasingly captured by the NIS2 Directive's incident reporting regime as member states complete transposition.

Cyble and DRONA Launch New Push to Close India’s Cybersecurity Gap

Cyber Yodha Campaign

AHMEDABAD (INDIA) — Cyble, the global AI-native cybersecurity company, and DRONA Cyber Solutions, the Ahmedabad-headquartered security operations firm, have launched an AI-powered cyber defense initiative in Ahmedabad, combining threat intelligence, investigation and endpoint enforcement through a joint managed security model.

The AI-Powered Intelligence for Cyber Defense initiative was formally launched Tuesday at DRONA Cyber Solutions' Command and Control Centre, where the companies presented a live technical demonstration showing how an intrusion attempt can be detected, investigated and contained.

The launch comes as India faces a growing cybercrime burden. India recorded 28.15 lakh cybercrime cases in 2025, a 24 percent increase over the previous year, with reported losses reaching ₹22,495 crore. The government's 1930 cybercrime helpline received 32.4 million calls during the year. Of the complaints filed, 55,484 were converted into FIRs. AI-powered cyber defense While large enterprises and banks increasingly have dedicated security teams, budgets and incident response capabilities, many manufacturers, hospital chains, schools and mid-sized businesses, particularly across Tier-2 and Tier-3 cities, continue to operate without comparable security resources.

AI-Powered Cyber Defense Takes Center Stage in Ahmedabad

Rather than focusing solely on formal remarks, Cyble and DRONA used the launch to demonstrate the initiative through a live technical exercise for the media. The demonstration began with material recovered from infostealer logs circulating on a criminal forum, alongside a lookalike domain registered to impersonate a target organisation. Analysts traced the infrastructure, established a pattern of previous activity associated with the same actor and demonstrated the detection and containment of an intrusion attempt on an endpoint.

The final containment action was authorised by a human analyst rather than executed automatically. The demonstration brought together multiple capabilities. Cyble Vision provided the initial detection through continuous monitoring of criminal marketplaces and leak sites.

Cyble Hawk supported the investigative process and attribution, while Cyble Titan handled endpoint enforcement, using hardware-level integrity checks to support its assessment. DRONA analysts remained at the centre of the process, making decisions that the system was deliberately not permitted to make independently. Cybersecurity Collaboration Mandar Patil, Executive Vice President at Cyble, said the initiative was designed to address a longstanding gap between threat detection and action for mid-sized businesses.
"India is not short of alerts. It is short of what happens next," Patil said. "We have spent a long time in this industry watching mid-sized businesses get told about a threat and then having nowhere to take that information. What we are launching today is not another alert. It is a complete chain — intelligence before the attack, investigation that would stand up to scrutiny, enforcement on the device, and a person accountable for the decision at the end of it."
Dhruv Pandit, Co-Founder and CEO of DRONA Cyber Solutions, said the initiative reflects the operational needs of organisations that require immediate action rather than another security dashboard.
"A factory owner calling us at two in the morning does not want to be shown a dashboard," Pandit said. "He wants to know what happened, he wants it contained, and he wants someone to take responsibility for what happens next."

From the Command Centre to Gujarat University, India

The Gujarat University engagement was not simply a conventional cybersecurity student session. It was a technical session titled “Kavach: Beyond the Surface — Threat Intelligence from the Dark Web Depths,” hosted by the Department of Biochemistry and Forensic Science, Gujarat University, in collaboration with Cyble.

The session brought together speakers from Cyble and DRONA Cyber Solutions to examine areas including dark web threat intelligence, government and PSU cybersecurity projects, digital forensics and incident response (DFIR), and the transition of threat intelligence from information to action.

Mandar Patil and Augustin Kurian of Cyble discussed the dark web threat intelligence landscape. Prathmesh Pawar spoke about government and PSU cybersecurity projects, while Brijesh Kapadiya addressed DFIR and Vijay Mali discussed moving threat intelligence from information to action. The keynote was delivered by Prof. Dr. Kapil Kumar, Coordinator, Department of Biochemistry and Forensic Science. AI-powered cyber defense

The session highlighted several practical aspects of cybersecurity work. The dark web was discussed not simply as a hidden part of the internet, but as a structured ecosystem requiring dedicated intelligence-gathering and threat-discovery methods. DFIR was presented as an area where speed and process are as important as technical expertise.

Another key takeaway was the importance of turning threat intelligence into action. Rather than treating intelligence as information alone, the session focused on how it can inform practical security decisions.

Patil told students that the cybersecurity industry faces a shortage of professionals with practical skills in analysing and validating threat intelligence.
"The gap this industry has is not a gap of ideas. It is a gap of people who know how to do the work," Patil said. "What separates a useful analyst from an alert-reader is the ability to ask whether a piece of intelligence is actually true before you act on it."
Augustin Kurian, Editor-in-Chief of The Cyber Express, told students that threat intelligence and journalism share an emphasis on verification.
Every story we publish about a breach, a ransomware group or a leaked database starts exactly where today's demonstration started — with intelligence somebody had to go and find, verify, and decide was worth acting on," Kurian said. The instinct we have tried to build at The Cyber Express is the same instinct a good analyst needs: do not report, and do not act on, what you have not verified.
The programme also involved technical and production teams supporting the session. Screen, sound and lighting were handled by the technical team under the guidance and supervision of Aditya More, while Misha Alagiya, Kavya Maharaja, Pathak Ami, Omi and Nandini supported stage management and photography.

A Broader Cybersecurity Collaboration

Both companies emphasised that the partnership is not intended to represent a single solution to India's cybersecurity deficit. Cyble and DRONA maintain relationships with other partners, service providers and government bodies.
"India's exposure is too large for any single partnership to take credit for solving," Patil said. "What matters is whether more of these collaborations exist a year from now, and whether the businesses we are talking about today — the ones without a security team — actually have somewhere to turn."

The AI-Powered Intelligence for Cyber Defense initiative will be delivered through DRONA's Ahmedabad command centre, with the companies indicating an intent to extend the service model to customers elsewhere in India over time.

The initiative also folds into DRONA's existing Cyber Yodha Campaign, a national programme aimed at building 50 integrated cybersecurity command centre labs and training more than 100,000 defenders.

Global Crackdown on West African Crime Networks Leads to 58 Arrests

West African Organized Crime Groups

An eight-month international operation targeting West African organized crime groups has resulted in 58 arrests and the identification of 263 suspects across 22 countries, according to INTERPOL. Operation Jackal IV, conducted from November 2025 to June 2026, focused on disrupting criminal networks, tracing illicit funds, identifying high-value targets and supporting arrests and prosecutions. The operation brought together countries across six continents to tackle the growing global threat posed by West African criminal networks, including Black Axe and similar groups. These networks have been linked to a significant share of global cyber-enabled financial fraud, including romance scams, cryptocurrency and investment scams, and business email compromise fraud.

Operation Jackal IV Targets West African Organized Crime Groups

Operation Jackal IV also targeted money laundering activities used to move and conceal criminal proceeds across borders. INTERPOL coordinated cross-border intelligence sharing, analysis and operational support during the operation. It also provided specialized training to strengthen international investigations into financial crime. Tomonobu Kaya, Director of the INTERPOL Financial Crime and Anti-Corruption Centre, said the operation showed the importance of international cooperation in following illicit financial flows and disrupting criminal networks. [caption id="attachment_113806" align="aligncenter" width="600"]West African Organized Crime Groups Image Source: INTERPOL[/caption]

Major Arrests and Financial Crime Investigations

In Argentina, authorities identified 196 individuals linked to a major Crime-as-a-Service network suspected of providing website domains and money laundering support to West African organized crime groups. The investigation resulted in 17 arrests, with an INTERPOL Operational Support Team assisting with analysis of seized data and identification of suspects and criminal networks. South African authorities raided seven locations in Johannesburg linked to a syndicate involved in romance and investment scams targeting retirees in English-speaking countries. Investigators arrested 39 people, seized USD 2.67 million and blocked 257 bank accounts. In Italy, investigators identified an individual connected to a pan-European money laundering network that used shell companies, remittance services and cash withdrawals. One account processed EUR 845,000, or about USD 736,000, through 560 transactions involving 20 financial instruments. Romanian authorities dismantled a criminal group operating an investment scam through a call centre. The group promoted high returns from stocks and cryptocurrencies, with victims' money transferred to electronic wallets controlled by perpetrators. Authorities estimated that EUR 143 million had been stolen and laundered globally. Eleven people were arrested, while cash, cryptocurrency, six real estate properties and luxury watches were seized.

Sextortion and Crime-as-a-Service Emerge

Beyond individual investigations, the operation highlighted emerging threats involving sextortion and Crime-as-a-Service. INTERPOL identified an increase in West African organized crime groups using sextortion to target minors, including victims as young as 14. In these cases, offenders typically contacted minors through social media, established trust and persuaded them to share explicit images or videos. They then threatened to distribute the material to the victim's contacts unless a ransom was paid. Investigators also found that some criminal syndicates were procuring Crime-as-a-Service from external providers, including through the dark web. These services were used to outsource activities such as money laundering and other operational functions. While several cases from Operation Jackal IV remain under investigation, the preliminary results demonstrate the scale and international reach of the networks targeted during the eight-month operation. The participating countries were Austria, Argentina, Australia, Canada, Côte d'Ivoire, France, Germany, Indonesia, Ireland, Italy, Japan, Malaysia, the Netherlands, Nigeria, Portugal, South Africa, Spain, Sweden, Switzerland, the United Arab Emirates, the United Kingdom and the United States.
❌