Security Journalism
Japan confirms arrest of Russian Qilin operative, extradition to Germany
Japan’s National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of being involved in the Qilin ransomware gang.
Japan’s National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of being involved in the Qilin ransomware gang.
Bulletin ID: 2026-133-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 11:00 AM PDT Description: AWS Amplify API Category is a CDK Construct library for defining GraphQL data models with authorization rules as AWS AppSync APIs. We identified CVE-2026-108096, where improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer might allow an authenticated remote user to read records owned by other users of the same applic…
The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and no charges have been made public. The
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagon-run data center.
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. [...]
The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the recent breach of FBI systems, Director Kash Patel announced Friday. [...]
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name
Those closest to executives must match their security postures because the weakest link in a family can become the entry point for attacks.
A company known for wearable cardiac sensors, iRhythm, has begun notifying states of the impact of a data breach from the summer.
Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, was a principal of Your Mule Cashout, or “YMCO,” which from 2007 until 2014 set up a sophisticated network of mules in the U.S. and Europe.
Bulletin ID: 2026-132-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 08:30 AM PDT Description: AWS Tools for PowerShell V5 lets developers and administrators manage their AWS services from the PowerShell scripting environment. We identified CVE-2026-107783, where insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from comma…
“We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate," FBI Director Kash Patel said.
Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month. [...]
Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion Note: Another researcher identified the same vulnerability during the disclosure process with the Nous Researcher team.In Hermes Agent, the public GET /auth/native/authorize flow validates the redirect_uri with Python's urllib.parse.urlparse, then hands the raw, unnormalized value back to the browser after authentication.The two parsers treat backslashes differently. Python's parser and the browser's WHATWG parser therefore …
Hermes Agent - Pre-Authentication Disk Consumption In Hermes Agent the public POST /auth/password-login route copies the client-supplied provider value, with no size limit, into the audit log before rejecting an unknown provider.Because the middleware treats this route as public, an unauthenticated client with no account can cause arbitrarily large, attacker-controlled data to be written persistently to the server's disk.In hermes_cli/dashboard_auth/routes.py, _PasswordLoginBody.provider is dec…
Hermes Agent - Pre-Authentication Memory Exhaustion In Hermes Agent the dashboard's public authentication routes (/auth/native/token, /auth/native/refresh, and /auth/password-login) read and parse the entire JSON request body before any authentication check, with no application-level size limit.The gated_auth_middleware in hermes_cli/dashboard_auth/middleware.py lets these paths through via _GATE_PUBLIC_PREFIXES before checking for a session. The handlers in routes.py rely on Pydantic models wh…
WordPress - Post Author Second Order SQLi A regression was introduced in version 4.0.0 of WP Post Author, the multi-authors module stores the co-author list in the wpma_author post meta and later interpolates each stored value directly into a SQL query. Neither end of that path is safe.On write, awpa_ma_save_metabox() takes $_POST['wpma_metabox_authors_list'], splits it on commas, and stores each element verbatim. The handler computes a sanitized copy and then stores the raw value instead:// in…
WordPress - Post Author Authenticated SQLi Two REST handlers build SQL queries by concatenating client-supplied request parameters straight into the query string. There is no $wpdb->prepare(), no esc_like(), and no whitelisting. The only processing applied is sanitize_text_field(), which trims whitespace and strips tags and control characters. It does not escape quotes and offers no protection against SQL injection.// includes/api-request/free/multi-authors/class-multiauthors.php — awpa_list_gu…
The Belarusian Cyber Partisans concurred with Russian research that they indeed spent months inside the network for the Moscow Department of Health.
AI agents can use valid credentials to perform actions beyond their assigned permissions, creating risks that traditional access controls may not prevent. Token Security explains how organizations can enforce agent-specific policies without sacrificing autonomy. [...]
Anthropic launches free OSS Scanner, using AI to find open-source vulnerabilities and help maintainers fix bugs before attackers exploit them. Anthropic is launching OSS Scanner, a vulnerability scanner for open-source code that costs nothing for projects to join. It grew directly out of lessons learned running Claude against real-world targets during Project Glasswing. The backdrop […]
A Latin American propaganda operation run by Russians and a cluster of Iranian fake journalist identities each had help from now-closed ChatGPT accounts, OpenAI's safety team said.