Category: News

Current, event-driven reporting, announcements and industry developments.

  • ASUS Patches Critical Flaws Letting Attackers Seize Control Center Enterprise and Nearby Hosts

    ASUS Patches Critical Flaws Letting Attackers Seize Control Center Enterprise and Nearby Hosts

    ASUS has released security updates fixing critical vulnerabilities across two of its device-management products, including a maximum-severity flaw that let an unauthenticated attacker gain root access to the server managing an organization’s fleet of PCs and workstations.

    A Chained Path to Root on Control Center Enterprise

    The more severe issue, CVE-2026-75754, carries a CVSS score of 10.0 and affects ASUS Control Center Enterprise (ACC) version 4.0.0.2 and all earlier releases. It stems from a chain of missing authentication, server-side request forgery and hard-coded credentials: an attacker can send a crafted HTTP request to obtain the system’s encryption key, which causes a local service to open SSH on port 2222, then use hard-coded credentials to obtain a root shell on the ACC server. Successful exploitation gives an attacker full control of the platform, including the ability to read, modify or delete stored data and remotely manage every server, PC and workstation the platform oversees. ASUS published the fix on September 4, 2026.

    A Second, Separate Flaw in Control Center Express

    ASUS separately patched CVE-2026-19397, a missing-authentication vulnerability in the Control Center Express Agent affecting versions before 1.7.24. The flaw, classified as CWE-306, allows an unauthenticated nearby attacker with a direct connection to the agent to take control of a host that has an active login session, potentially executing code or performing any action available to the logged-in user. ASUS published updates for Control Center Express and its Armoury Crate software, which separately addressed a flaw that could expose a user’s NTLM hash, on September 8, 2026. Neither vulnerability has been reported as actively exploited, but organizations running either platform are advised to update immediately given the scope of access each flaw can grant.

  • Mercury Security Launches S4 I/O Module Family to Modernize Access Control Infrastructure

    Mercury Security Launches S4 I/O Module Family to Modernize Access Control Infrastructure

    Mercury Security, an HID brand and a longtime supplier of open-architecture access control hardware, has launched its Mercury S4 I/O Module family, a new generation of intelligent modules designed to help organizations expand and modernize physical access control systems built on existing Mercury infrastructure.

    More Capacity, Built-In Cryptographic Headroom

    According to Mercury, the S4 family delivers six times the memory and eight times the storage of prior-generation modules, along with support for post-quantum cryptography aimed at hardening access control communications against future cryptographic threats to critical infrastructure. The modules are built for forward and backward compatibility, letting integrators add doors, readers and other security devices to existing Mercury intelligent controllers without replacing them, while increasing door density and reducing the physical footprint of the resulting installation.

    Responding to Longer Infrastructure Lifecycles

    The company said its ongoing research into access control professionals’ priorities identified sustained emphasis on cybersecurity and data protection standards, alongside a need for hardware that supports both forward and backward compatibility as organizations plan access control investments over longer timeframes. The Mercury S4 I/O Modules are available now through Mercury’s OEM partner network, extending an open-architecture platform the company has developed since its founding in 1992.

  • Qualcomm and AWS Sign Multi-Generation Deal for Custom AI Inference Silicon

    Qualcomm and AWS Sign Multi-Generation Deal for Custom AI Inference Silicon

    Qualcomm and Amazon Web Services have signed a multi-generation collaboration agreement to develop customized silicon and optical connectivity for AWS’s AI data center infrastructure, marking one of Qualcomm’s most significant moves yet into the data-center chip market long dominated by Nvidia.

    Custom Inference Chips and High-Speed Optical Links

    Under the agreement announced September 8, 2026, Qualcomm Technologies will work with AWS to design customized silicon focused on AI inference workloads, alongside advanced optical connectivity solutions supporting interconnect speeds up to 1.6 terabits per second and future generations beyond that. “As AI demand accelerates, data center infrastructure will require advances in both computing and connectivity to deliver greater performance with more efficiency,” said Cristiano Amon, president and chief executive of Qualcomm, adding that the company aims to bring “decades of leadership in advanced processing and power-efficient compute” to AWS’s AI infrastructure.

    A Warrant Tied to Billions in Future Purchases

    As part of the deal, Qualcomm issued Amazon a warrant to acquire up to 25 million shares of Qualcomm common stock, vesting as AWS makes purchases under the agreement, up to a cap of $60 billion over a ten-year term. The warrant carries an exercise price of $161.26, roughly 4.4% below Qualcomm’s September 4 closing price, with 3.75 million shares vesting immediately at signing. Qualcomm shares rose sharply following the announcement. The agreement follows Qualcomm’s introduction of its AI200 and AI250 data-center inference chips last year and reflects the company’s broader push to diversify beyond smartphone processors into AI infrastructure, an area where hyperscalers including Amazon, Google and Microsoft have increasingly sought custom silicon to reduce reliance on Nvidia.

  • Pavion Expands Midwest Reach With Acquisition of Indiana-Based Communication Company

    Pavion Expands Midwest Reach With Acquisition of Indiana-Based Communication Company

    Pavion, a systems integrator specializing in fire, life safety, security and critical communications, has acquired Communication Company, a South Bend, Indiana-based technology solutions provider that has served the region for roughly five decades, the company announced.

    Regional Relationships and Healthcare Expertise

    Founded in 1976, Communication Company brings established local customer relationships, technical expertise and service capabilities to Pavion’s broader portfolio, which spans fire and life safety, security, critical communications, audiovisual and integrated technology solutions. Pavion said the deal also strengthens its healthcare capabilities, since Communication Company has experience supporting hospitals and healthcare systems, complementing Pavion’s existing work in nurse call, real-time location systems and life-safety technology for the sector.

    Part of a Broader Growth Strategy

    “Communication Company has built an impressive legacy by earning the trust of its customers through exceptional service, technical expertise and strong local responsiveness,” said Joe Oliveri, chief executive officer of Pavion, adding that the acquisition expands the combined company’s ability to help organizations across the Midwest “connect and protect their people, property and assets.” The Chantilly, Virginia-based company, backed by private equity firm Wind Point Partners since 2020, has built its growth strategy around acquiring regional integrators with strong customer relationships and local market leadership, continuing a multi-year acquisition run across the fire, life-safety and security integration sector.

  • Estonian Startup Unveils Self-Balancing Monowheel Robot for Autonomous Security Patrols

    Estonian Startup Unveils Self-Balancing Monowheel Robot for Autonomous Security Patrols

    Estonian startup Rollo Robotics has unveiled 1Rollo, a self-balancing, one-wheeled autonomous robot designed to patrol warehouses, factories, campuses and other large properties, offering what the company positions as a lower-cost alternative to traditional guard patrols and security vehicles.

    A Narrow Footprint Built for Estonian Winters

    Currently in functional prototype form, 1Rollo uses gyroscopic stabilization to balance and move on a single wheel, a design the company says gives it a narrower footprint than wheeled or tracked patrol robots. Rollo Robotics, based in Viljandi, Estonia, says the platform was developed and tested through the country’s harsh winters, addressing traction, battery performance and sensor reliability in snow and sub-zero temperatures. The robot is intended to operate around the clock without the breaks, shift changes or attention lapses associated with human patrols.

    Subscription Model, Open Cybersecurity Questions

    Rather than selling the hardware outright, Rollo Robotics plans to offer 1Rollo through a Robotics-as-a-Service subscription that would bundle current hardware, software updates and support, according to CEO and co-founder Sander Sebastian Agur. The company says the model removes a large upfront equipment cost and simplifies future upgrades and repairs for customers.

    As with other connected patrol robots, 1Rollo depends on wireless connectivity and a cloud platform, which raises questions buyers will need to ask about video encryption, footage retention, operator-account protection and how the robot behaves if it loses its connection. The launch also comes as US lawmakers consider legislation that would restrict government use of some foreign-made robots over national-security concerns, a debate that is likely to shape how autonomous patrol platforms built outside the United States are received by security buyers.

  • 12-Year-Old PostgreSQL Flaw ‘PostGREShell’ Lets Low-Privilege Accounts Seize Full Server Control

    12-Year-Old PostgreSQL Flaw ‘PostGREShell’ Lets Low-Privilege Accounts Seize Full Server Control

    A PostgreSQL vulnerability that has existed undetected for roughly 12 years can let a low-privileged database account escalate to complete, persistent control of the server, researchers have disclosed.

    A Decade-Old Gap in a ‘Low-Risk’ Privilege

    Tracked as CVE-2026-6471 and nicknamed PostGREShell by the Cyera Research team that found it, the flaw carries a CVSS score of 7.2 and stems from a missing authorization check in PostgreSQL’s logical decoding feature, present since the capability was introduced in version 9.4 in 2014. An account holding only the REPLICATION privilege — typically granted for backup or data-pipeline purposes and long treated as a low-risk, read-only permission — can use a logical decoding output plugin to make the server load an arbitrary shared library file. That library executes as native code inside the PostgreSQL server process, running with the privileges of the operating-system account that runs the database.

    Successful exploitation can lead to arbitrary code execution, privilege escalation to permanent superuser status, and installation of a persistent backdoor, effectively handing an attacker full control of the server and any data it holds.

    Patched in August, Disclosed in September

    The PostgreSQL project shipped a fix for CVE-2026-6471 on August 13, 2026, bundled with 27 other security patches in versions 18.6, 17.11, 16.15, 15.19 and 14.24. Branches earlier than version 14 do not receive a fix. Cyera reported the issue to the PostgreSQL security team on February 21, 2026, with the team confirming it six days later; discovery credit was given to researchers Vladimir Tokarev and Yu Kunpeng. Security researchers are advising organizations to update affected instances immediately, audit which accounts hold the REPLICATION attribute, and remove it from any account that does not strictly require it.

  • Broadcom Patches Critical VMware Workstation and Fusion Flaws That Enable Host Takeover

    Broadcom Patches Critical VMware Workstation and Fusion Flaws That Enable Host Takeover

    Broadcom has patched two vulnerabilities in VMware Workstation and Fusion that could let an attacker with administrative privileges inside a virtual machine escape the VM and execute code on the underlying host system, a scenario that undermines the isolation virtualization is meant to provide.

    Two Distinct Escape Paths

    The more severe issue, tracked as CVE-2026-59346 and carrying a CVSS score of 9.3, is an integer-overflow flaw in how the software handles the VMXNET3 virtual network adapter. According to Broadcom’s advisory, a malicious actor with local administrative privileges on a virtual machine configured with a VMXNET3 adapter can exploit the bug to execute code on the host.

    The second flaw, CVE-2026-59347 (CVSS 8.1), is a stack-based buffer overflow in the Host-Guest File System (HGFS), the VMware component that lets a guest VM access files and folders on the physical host. Exploiting it allows code execution as the host’s VMX process, though Broadcom notes the exploitation conditions differ from the first bug.

    Patches Available, No Known Exploitation Yet

    Both vulnerabilities are fixed in VMware Fusion Pro 26H1u1, released September 3, 2026, and the corresponding Workstation update, detailed in advisory VMSA-2026-0007. CVE-2026-59346 was reported by researchers h4urek, cameudis and Stan S working with Trend’s Zero Day Initiative; CVE-2026-59347 was credited to Yeonghyeon Choi and Tianchu Chen of Tencent’s Xuanwu Lab. As of September 4, Belgium’s national cybersecurity center said it had no indication either flaw was being actively exploited, though it urged administrators to patch immediately given the risk of lateral movement, data exfiltration and host compromise if exploitation conditions are met.

    The disclosures follow reports last month that threat actors, including a suspected China-nexus group, were already exploiting separate flaws in VMware vCenter, underscoring sustained attacker interest in Broadcom’s virtualization stack.

  • Accused Ringleader of $240 Million Bitcoin Social-Engineering Heist Faces Plea Hearing

    Accused Ringleader of $240 Million Bitcoin Social-Engineering Heist Faces Plea Hearing

    Malone Lam, the alleged ringleader of a network accused of stealing more than $240 million in Bitcoin from a single victim through a social-engineering scheme, has a plea agreement hearing scheduled this week, according to the Associated Press.

    A Social-Engineering Heist Followed by a Spending Spree

    Prosecutors say the theft targeted a Washington, D.C., resident identified in court filings as “Victim 7,” who received a phone call in August 2024 from someone posing as a Google representative warning of attempts to breach his account, followed by a second call from someone claiming to represent the Gemini crypto exchange who warned of a malware attack on his crypto wallet. Prosecutors say the network Lam allegedly organized used that fabricated scenario to gain the victim’s trust and ultimately extract control of his cryptocurrency holdings.

    According to the Associated Press, Lam and his associates celebrated the heist with a monthlong spending spree that included fleets of sports cars, private jet flights, hired security guards and rented mansions in Miami and the Hamptons; Lam alone reportedly spent more than $569,000 in a single evening at a Los Angeles nightclub. FBI agents arrested Lam, an eighth-grade dropout from Singapore, after the spree, on charges of organizing the social-engineering attack. Charges have been filed against Lam and 17 others in connection with the case.

    Part of a Broader Enforcement Push

    The case is emblematic of a rapidly growing category of cybercrime: complaints of cryptocurrency investment fraud to the FBI rose by nearly 50% in 2025. Cybersecurity researcher Allison Nixon, who tracks an underground subculture of young hackers known as The Com, has called for significantly more law enforcement resources to be devoted to pursuing these networks, warning that the scale of money involved will otherwise continue to draw in new participants. A conviction for Lam would mark a significant milestone for investigators working to build cases against the loosely organized networks behind this style of large-scale crypto theft.

  • Ex-Palo Alto Networks Founder’s Startup Cylake Raises $245 Million for Sovereign Security Platform

    Ex-Palo Alto Networks Founder’s Startup Cylake Raises $245 Million for Sovereign Security Platform

    Cybersecurity startup Cylake has raised $245 million to accelerate development of its security platform, bringing its total funding to $290 million just six months after emerging from stealth.

    A Platform for Organizations That Can’t Use the Public Cloud

    Cylake is building what it describes as a complete, AI-native cybersecurity platform aimed at government agencies, highly regulated enterprises and other organizations that cannot depend on public cloud infrastructure. The platform is designed to run entirely on premises or in private cloud environments, giving customers control over their own data, infrastructure and security operations, and combining data and context from across an organization’s systems into a unified foundation for both protection and AI-powered security workflows.

    The company said the new funding will go toward platform development and team expansion ahead of a beta release targeted for the end of 2026, with general availability planned for 2027.

    A Team With Deep Palo Alto Networks Roots

    Cylake was co-founded by chief executive Nir Zuk, who founded Palo Alto Networks and served as its chief technology officer for more than two decades; chief development officer Wilson Xu, a former Palo Alto Networks engineering executive; and chief architect Ehud “Udi” Shamir, who co-founded SentinelOne before working as a distinguished software developer and security researcher at Palo Alto Networks. The team also includes René Bonvanie, previously Palo Alto Networks’ chief marketing officer.

    Cylake emerged from stealth in March 2026 with a $45 million seed round led by Greylock Partners and has since grown to more than 40 employees, with plans to continue hiring across engineering, product and other functions as it works toward its beta launch.

  • ‘White-Hat’ Hackers Return $263 Million of $320 Million Stolen From Bitcoin’s Liquid Network

    ‘White-Hat’ Hackers Return $263 Million of $320 Million Stolen From Bitcoin’s Liquid Network

    Alleged “white-hat” hackers have returned 3,400 Bitcoin, worth roughly $262.6 million, of the approximately 4,000 Bitcoin they drained from the federation wallet of Liquid Network, a Bitcoin sidechain developed by Blockstream.

    A Weekend Heist That Froze the Network

    Liquid disclosed the incident on a Sunday, disabling its nodes and suspending all transactions in response. The stolen funds came from Liquid’s federation wallet, which held approximately 4,200 Bitcoin before the attack. Liquid said the funds were withdrawn via the SideSwap Peg-out Authorization Key, but that the key itself, along with other keys in the system, was not compromised — leaving the precise mechanism of the theft unclear. The company said exchanges had been notified and had paused or would pause LBTC deposits and withdrawals, while other assets on the network, including USDT, DePix and real-world assets, were unaffected.

    A Conditional Return

    The theft was claimed by attackers describing themselves as white-hat hackers, who said in a public blockchain message that they would return most of the stolen funds once Liquid fixed the underlying vulnerability: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”

    On Monday, the attackers followed through by returning 3,400 Bitcoin. Former Blockstream executive Samson Mow said approximately 598 Bitcoin, worth about $47 million, remained outstanding as Blockstream continued communicating with the hackers. Mow said the network would stay paused while Blockstream and federation members complete additional fixes and security improvements, resolve a resulting chain split, and prepare for a safe restart, adding that Liquid wallets and services would remain affected in the meantime.