Skip to content
root notes — archive

ls ./archive --page 3

Archive

page 3 of 11241 articles

Three of the ten most exploited weaknesses were called unforgivable in 2007

2026-09-01Security

CISA's review of 2024 and 2025 finds that the flaws attackers actually use are injection, input validation and path traversal — the same list as two decades ago. Seven of the ten most frequent weaknesses on the exploited-vulnerabilities catalog account for 41.5% of everything on it. CISA blames culture and workflow, not difficulty.

He ran the monitoring that catches leakers, so he copied the documents out by hand

2026-08-31World

Nathan Vilas Laatsch worked in the Defense Intelligence Agency's Insider Threat Division, enabling user activity monitoring on people with access to DIA systems. When he decided to pass secrets to a foreign government, he transcribed them at his desk on paper. He has pleaded guilty, and the plea recommends 11 to 18 years.

A state-linked backdoor for diplomats, written as a Windows batch file

2026-08-31Security

HOOKEDGE polls webhook.site for command files, runs them, and posts the output back as HTML. No custom infrastructure, no compiled binary, no exotic protocol — a .cmd script and a free service anyone can sign up for. Recorded Future ties it to APT28 with moderate confidence, and says so.

Five of the 19 malicious extensions were bought from their original developers

2026-08-31Security

Socket found 19 Chrome and Edge extensions draining wallets, harvesting hardware wallet seed phrases and stealing credentials. The operators wrote 14 of them and purchased the other five from previous owners — complete with existing users. Then they pushed an update, and Chrome installed it automatically.

The only thing they changed was telling you to open Terminal instead of Run

2026-08-31Security

TerminalFix is ClickFix with one substitution. A fake Cloudflare CAPTCHA asks you to paste a command, and instead of the Run dialog it sends you to Windows Terminal or PowerShell — where long multi-line scripts actually work. The end of the chain is a Python reverse tunnel that lets the operator reach anything your machine can see.

8,393 Gitea servers are exposed, and the flaw needs an account anyone can make

2026-08-31Security

CVE-2026-60004 lets a user with ordinary write access to a repository run shell commands as the Gitea system user. That reads as an authenticated flaw until you notice that Gitea ships with open registration, so a visitor can sign up, create a repository, and qualify. The fix has been out since 27 July. Miners are already running.

It is not 284 million patients — and the people who stole the data are the ones saying so

2026-08-31Security

McKesson has confirmed a breach involving third-party applications. ShinyHunters claims a terabyte and 284 million records including Social Security numbers and medical histories, and demanded $55.236 million. The group has also clarified that the figure counts records, not individuals. Nobody knows how many people are affected, including them.

A 2023 flaw with a 2023 fix was used to take nuclear-material records this year

2026-08-31Security

CVE-2023-49105 lets anyone read, change or delete files on an ownCloud server without authenticating, if they know a username and the default configuration is in place. It was fixed in November 2023. It has now been used against a Philippine nuclear research body, and CISA added it to its exploited-vulnerabilities list on 27 August.

They knew every chain was at risk on 13 August. They shipped the fix quietly anyway

2026-08-31Security

A Cosmos EVM flaw let attackers underflow account balances to roughly 2^256. Cosmos Labs learned on 13 August that every chain running its software was affected, patched on the 19th without private notification, and a public pull request in a fork spelled out the exploitation path on the 20th. Six chains were drained.

The ATF says it was a standalone system. Senior officials called it a major incident

2026-08-30Security

Qilin listed the Bureau of Alcohol, Tobacco, Firearms and Explosives on its leak site on 26 August. The ATF confirmed an intrusion into a standalone system it disconnected, and says its mission is unaffected. It also confirmed that senior Justice Department officials designated the event a major incident — a federal threshold with a definition.

PaperCut is being exploited, and one of the signs is that your log file is missing

2026-08-29Security

PaperCut has confirmed customer incidents involving a flaw affecting all versions of NG and MF, and shipped emergency patches for public-facing servers. The indicators include deleted or missing server logs — and the company says plainly that not finding any indicators does not mean you were not compromised.

Search all 241 articles →