RE: https://mastodon.social/@campuscodi/117377454167316988
Gonna be fun when Ivanti and Citrix and Palo and Fortinet and Cisco and F5 all keep their gov contacts because they're "PQC Ready" but keep getting popped by URI encoding and BoFs from 20 years ago, not to mention all the TAGs they can't be bothered to boot from their own networks, making that PQC essentially pointless against the majority of threats.
I don't know how many of you have public call centers, but you might want to figure out how to deal with AI agents "calling on behalf of" human employees or customers or similar. I've seen it a ton lately and it's creepy as Hell. They're aggressive and weird ( negative ).
You can always tell when vendors like Palo Alto are getting ready to announce a new product because they start making their existing shit even worse so they can say "that's fixed with this new product."
Go hack some AI SOC shit.
https://github.com/beenuar/AiSOC/security/advisories/GHSA-7q37-2wfw-xrx7
Three functions in services/actions build CrowdStrike Real-Time Response (RTR) command strings by string interpolation, with no escaping, from caller-supplied parameters. The resulting command string is sent to the CrowdStrike Falcon agent and executed on the target endpoint as the EDR agent's privilege (SYSTEM/root).
Citrix patches are out on the main support site now.
You will need to check every box after patching for webshells. Citrix are locking the script behind an NDA as apparently they’re from 1996… hopefully one of the NCSCs publishes a script again as the NDA thing is crap.
To be clear patching alone doesn’t remove the backdoors being placed.
More old vulns finally getting CVEs but a couple perfect 10s in a tool to allow AI agents to make trades on your behalf is just too... expected.
Vibe-Trading is an open-source research workspace for turning finance questions into runnable analysis. It connects natural-language prompts to market-data loaders, strategy generation, backtest engines, reports, exports, and persistent research memory.
It is designed for research, simulation, and backtesting — and, when you choose, autonomous trading through a broker you authorize yourself (e.g. Robinhood Agentic Trading). It holds no funds and never trades outside the limits you set, and you can halt it instantly.
https://github.com/HKUDS/Vibe-Trading/security/advisories/GHSA-jqmf-mx4f-hfr6https://github.com/HKUDS/Vibe-Trading/security/advisories/GHSA-v2f8-6655-7grj
Yet another perfect 10 this morning. This one from a company that knows its way around perfect 10s. 🥳
https://www.cve.org/CVERecord?id=CVE-2026-92931
sev:CRIT 10.0 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.
Patch your fruity phones, there's another EITW 0day.
https://support.apple.com/en-us/149226
Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Of all the bullshit I expected from the current US regime, going from cops threatening dogs with their 9mm to cops threatening dogs with their 9cm was not on that list.
@Epic_Null@infosec.exchange I think it's more the crybaby Linux kernel nerds publishing a CVE for every bug because they can't be bothered to pull their heads out of Linus' ass long enough to understand risk. Despite bragging about being a secure OS.