Category: Cyber-Physical Security

Coverage of the convergence between IT/cybersecurity and physical security systems, including networked device risk, secure system integration and unified threat response.

  • Extortion Group Claims Breach of Florida DMV Database, Threatens to Leak 200,000 Driver Records

    Extortion Group Claims Breach of Florida DMV Database, Threatens to Leak 200,000 Driver Records

    The extortion group ShinyHunters claims to have breached an online platform used by the Florida Department of Highway Safety and Motor Vehicles, stealing more than 200,000 driver records and threatening to publish the data if the state does not respond by a set deadline.

    A Password-Reset Flaw Allegedly Opened the Door

    The targeted system, known as DAVID (Driver And Vehicle Information Database), is described by the Florida Highway Safety and Motor Vehicles agency as a platform that gives law enforcement and criminal justice officials immediate access to driver and vehicle information, and serves as the state’s primary reporting mechanism for fatalities and serious injuries. ShinyHunters told BleepingComputer the intrusion exploited a password-reset weakness that let the group compromise multiple internal accounts, including ones it claims belonged to DMV employees and an FBI agent. Using that access, the group said it wrote a script to iterate through driver records by ID number, downloading the associated HTML pages and images for each one, collecting over 200,000 records since the breach allegedly began on September 3, 2026.

    Epstein Record Used as Proof, September 11 Deadline Set

    As evidence of the intrusion, the group released a screenshot of a DMV record belonging to Jeffrey Epstein, including his address and registered vehicles. ShinyHunters added the Florida agency to its dark web leak site with a listing giving officials until September 11, 2026, to make contact before the group releases the full dataset, a listing the group has labeled a “final warning.” The claimed 200,000-record figure comes directly from the attackers and has not been independently verified or confirmed by the state as of publication.

    Part of a Broader Pattern of Government Database Targeting

    ShinyHunters has claimed responsibility for a string of high-profile extortion cases against corporate and government targets over the past year, frequently relying on compromised credentials and account takeover rather than novel technical exploits to gain initial access. The alleged Florida incident underscores a recurring weak point in large government record systems: authentication and account-recovery workflows that, once compromised, can expose bulk record access far beyond what a single stolen credential would typically allow.

  • Attackers Used a Three-Year-Old Flaw to Steal Reactor Data From a Philippine Nuclear Agency

    Attackers Used a Three-Year-Old Flaw to Steal Reactor Data From a Philippine Nuclear Agency

    A threat actor exploited a long-patched vulnerability in the file-sharing platform ownCloud to steal reactor data, personnel records and stored credentials from a Philippine nuclear research organization, according to researchers who found the stolen material staged on attacker-controlled infrastructure.

    A Two-Year-Old Bug in a Default Configuration

    Threat-hunting firm Hunt.io published a blog post on August 26, 2026 identifying an ownCloud server hosted in Amsterdam that appeared to function as a staging hub for a suspected Chinese-speaking operator, containing offensive tooling alongside data taken from at least two victims: a Philippine nuclear research agency and a marine engineering and shipbuilding company serving the Philippine Navy. The intrusion exploited CVE-2023-49105, an authentication bypass in ownCloud’s pre-signed URL mechanism disclosed by the vendor in November 2023 and carrying a CVSS score of 9.8. On installations left in ownCloud’s default configuration, with no signing key configured, an attacker who knows a valid username can construct requests the system accepts as authenticated, letting them access, modify or delete files without ever supplying a password.

    Reactor Records, Personnel Files and Stored Credentials

    The material recovered from the nuclear agency’s staging folders, roughly 372 MB across 176 files, included a database of research-reactor core components, historical fuel inventories, radiation-safety documentation, incident records, and a 192 MB database dump from a biometric attendance and personnel system, alongside employee resumes, travel records and financial disclosures. Investigators also found a KeePass password database, AxCrypt-encrypted files and a PDF containing a BitLocker recovery key among the stolen material, credential artifacts that could help an attacker move further into connected systems. A separate recovered inventory suggested roughly 9 GB of data may have been taken from the agency in total, though only a fraction was directly recovered by researchers.

    CISA Adds the Flaw to Its Exploited Catalog

    The US Cybersecurity and Infrastructure Security Agency added CVE-2023-49105 to its Known Exploited Vulnerabilities catalog on August 27, 2026, one day after Hunt.io’s disclosure, formally flagging a nearly three-year-old bug as under active exploitation. The incident illustrates a recurring pattern in intrusions against sensitive government and research infrastructure: the vulnerability exploited was neither novel nor unpatched by the vendor, but a long-available fix that an internet-facing, self-hosted file-sharing system had apparently never received.

  • Microsoft Ships Record September 2026 Patch Tuesday, Fixing 964 Flaws Including Two Exploited Zero-Days

    Microsoft Ships Record September 2026 Patch Tuesday, Fixing 964 Flaws Including Two Exploited Zero-Days

    Microsoft shipped its largest Patch Tuesday on record this week, fixing 964 vulnerabilities across its product line — more than double August’s release and a new monthly high for the company. The September 2026 update includes patches for two zero-day flaws already being exploited in the wild, along with 113 vulnerabilities rated Critical.

    Two Exploited Zero-Days Among 964 Fixes

    The two actively exploited flaws include CVE-2026-81963, an elevation-of-privilege vulnerability in the Windows Update Stack that stems from improper link resolution before file access, commonly known as link following. Security researchers note the bug is most relevant to post-compromise activity, letting an attacker who already has a foothold on a system escalate to greater control. Cybersecurity companies Volexity and Proofpoint were credited with reporting one of the exploited flaws, while a researcher at Airbus Helicopters and Microsoft’s own threat intelligence team were credited with the second. The U.S. Cybersecurity and Infrastructure Security Agency has added both to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until September 22, 2026 to apply the fixes.

    A Record Critical Count Across Windows Components

    Among the 113 Critical-rated bugs, several affect core Windows security components, including CVE-2026-83939 in Windows Secure Kernel Mode and CVE-2026-83498 in Virtualization-Based Security enclave privileges. Microsoft also patched a string of remote-code-execution flaws carrying CVSS scores of 9.8, including issues in Skype for Business, the Windows Routing and Remote Access Service, the Windows HTTP Print Provider, Windows Shell and the Windows Imaging Component. None of the RCE flaws are confirmed to require no user interaction, but their severity ratings and broad footprint across widely deployed Windows components make rapid patch validation and deployment a priority for enterprise IT and security teams this month.

  • Consumer Cybersecurity Firm Guardio Reaches $1.1 Billion Valuation as Wiz Co-Founder Invests

    Consumer Cybersecurity Firm Guardio Reaches $1.1 Billion Valuation as Wiz Co-Founder Invests

    Guardio, a consumer cybersecurity company focused on protecting individuals from online scams and phishing, has raised $40 million in new funding at a valuation of $1.1 billion, with Wiz co-founder and chief executive Assaf Rappaport joining as an investor.

    Four Straight Years of Triple-Digit Growth

    The round, announced September 3, 2026, also included existing investors ION Crossover Partners, Union Tech Ventures, Vintage Investment Partners, Cerca Partners and Emerge Ventures, and brings Guardio’s total funding to date to $167 million. The Israeli company said it has grown revenue more than 100% year over year for four consecutive years, surpassing one million paying customers and $150 million in annual recurring revenue. Guardio plans to use the new capital to expand its suite of consumer-focused protection tools covering browsing, phishing and broader digital-presence risks.

    AI Cuts Both Ways for Consumer Fraud

    Gilad Shany, managing partner at ION Crossover Partners, said the company’s combination of cybersecurity expertise, consumer-product focus and distribution reach was behind the sustained growth. Rappaport, who invested personally in the round, pointed to artificial intelligence as a factor reshaping the threat landscape for ordinary consumers, making phishing, brand impersonation and deepfake voice scams more convincing and harder to distinguish from legitimate communication. Guardio’s raise adds to a run of large valuations for Israeli cybersecurity companies in 2026, as consumer-facing security products compete for a growing pool of capital alongside enterprise-focused vendors.

  • Researchers Build Zero-Click Worm That Hijacked WeChat Accounts via a Single Call

    Researchers Build Zero-Click Worm That Hijacked WeChat Accounts via a Single Call

    Security researchers at the firm Calif built a working worm capable of hijacking WeChat accounts on both iOS and Android through a single incoming call, then using the compromised account to spread automatically to the victim’s contacts, in what the company describes as the first zero-click worm demonstrated against a mainstream messaging app on both platforms.

    Attacker Calls Victim, Victim Becomes Attacker

    In a demonstration published September 8, 2026, Calif showed an Android phone calling an iPhone and taking over its WeChat account while the phone was still ringing, with no answer or user interaction required. The compromised iPhone then called a second Android phone and took control of it the same way, illustrating a self-propagating chain: attacker calls victim, victim becomes attacker, victim calls the next victim. Calif said the underlying issue is a memory-corruption bug in WeChat’s VoIP stack, and that because the caller must already be on the target’s contact list, the extra trust WeChat extends to contacts ends up working in the attacker’s favor once one account in a network is compromised. Once hijacked, an account can read and send messages, place calls, and act on the victim’s behalf.

    Patched Before Public Disclosure

    Calif reported the flaw to WeChat developer Tencent in July, and Tencent shipped version 8.0.77 for Android and 8.0.76 for iOS on August 21, 2026, mitigating the bug; Calif confirmed on August 28 that the specific exploit was also blocked on Tencent’s servers for all users regardless of app version. Tencent has not published a security advisory describing the flaw, and its release notes for the affected updates describe them only as general bug fixes. Researchers are advising WeChat users to keep the app updated, review their contact lists for unfamiliar connections, and treat unexpected incoming calls from known contacts with caution, since a compromised contact’s account could be used to continue the propagation chain.

  • Alby Discloses Critical Flaw in Internet-Exposed Bitcoin Lightning Wallets

    Alby Discloses Critical Flaw in Internet-Exposed Bitcoin Lightning Wallets

    Alby, the company behind the Bitcoin Lightning Network and Nostr tooling suite Alby Hub, has disclosed a critical vulnerability affecting older versions of its self-hosted Lightning wallet that could let an attacker take over and drain funds from any instance left reachable from the public internet.

    Unauthenticated Access to the Management API

    In a disclosure posted September 9, 2026, Alby said it had confirmed a critical flaw in Alby Hub versions 1.7.0 through 1.18.5, released before August 2025, when the Hub is publicly accessible from the internet. According to the company, an attacker who can reach the Hub’s management API over the network can access it without authorization and send funds out of the wallet, effectively draining any exposed node. Alby urged affected users to immediately take internet-exposed instances offline, update to a patched version, and change their unlock password after updating, since the credential itself could have been exposed during the window the Hub was reachable.

    Part of a Rough Stretch for Lightning-Adjacent Projects

    The disclosure follows a difficult few weeks for Lightning Network-adjacent infrastructure: Boltz, a separate non-custodial bridge that moves bitcoin between the main chain, the Lightning Network and the Liquid Network, took its swap functionality offline on August 3, 2026, after its own security issue, and Bitcoin’s Liquid Network separately suffered a $320 million theft that white-hat hackers later helped partially recover. Security researchers have pointed to the growing use of AI-assisted attack tooling as a factor putting increased pressure on smaller, self-hosted Bitcoin infrastructure projects that lack the security resources of larger custodial platforms.

  • Critical Red Hat Flaw Let Low-Privileged Tenants Seize Control of Managed Kubernetes Clusters

    Critical Red Hat Flaw Let Low-Privileged Tenants Seize Control of Managed Kubernetes Clusters

    A critical vulnerability in Red Hat Advanced Cluster Management for Kubernetes (RHACM) could let a low-privileged tenant on a central hub cluster seize administrative control of any Kubernetes cluster it manages, according to Red Hat’s own advisory on the flaw.

    An Unvalidated Annotation Opens the Door

    Tracked as CVE-2026-72526 and carrying a CVSS score of 9.9, the flaw sits in the multicloud-integrations component that RHACM uses to propagate applications from a central hub cluster to the individual managed, or “spoke,” clusters it oversees. The Application propagation controller processes an ocm-managed-cluster annotation on an Application custom resource without properly validating it, which means a tenant who only has permission to create Applications on the hub can direct that annotation at any managed cluster of their choosing, not just their own. Doing so forces ArgoCD on the targeted spoke cluster to synchronize manifests the attacker controls, resulting in arbitrary code execution or privilege escalation on a cluster the tenant was never authorized to touch.

    A Direct Route From Low Privilege to Cluster-Admin

    Because the underlying authorization check is missing entirely rather than merely weak, the flaw gives a low-privileged hub tenant a direct path to cluster-admin rights on infrastructure well outside their own environment, a significant multi-tenant isolation failure for organizations running shared RHACM hubs across business units or customers. Red Hat has published fixed component versions in its advisory and accompanying Bugzilla report; organizations running RHACM are advised to apply the update and confirm that the propagation controller correctly enforces tenant-scoped cluster authorization after upgrading, alongside reviewing who currently holds Application-creation permissions on their hub clusters.

  • Fileless Rootkit ‘PoisonedRefresh’ Found Hiding Web Shells in F5 BIG-IP Memory

    Fileless Rootkit ‘PoisonedRefresh’ Found Hiding Web Shells in F5 BIG-IP Memory

    Researchers at Sophos and ESET detailed a stealthy Linux rootkit, dubbed PoisonedRefresh, discovered on compromised F5 BIG-IP Access Policy Manager (APM) appliances, Help Net Security reported. The implant hooks Apache’s PHP module loader to inject a web shell directly into memory, never writing to disk, making it difficult to detect with conventional file-based scanning.

    The activity is tied to exploitation of CVE-2025-53521, a critical unauthenticated remote-code-execution flaw that F5 originally classified as a denial-of-service issue before reclassifying it. F5 has confirmed exploitation, and Shadowserver was tracking 795 internet-exposed vulnerable BIG-IP APM endpoints as of September 7, 2026. The findings were independently corroborated by BleepingComputer, SecurityAffairs and CybelAngel.

    Why it matters: F5 BIG-IP APM is widely deployed by government, financial and critical-infrastructure organizations to manage secure remote access. A memory-resident rootkit that survives file-based detection on this class of device represents a significant, hard-to-spot foothold inside networks that are supposed to be tightly controlled.

    Source: Help Net Security, September 9, 2026.

  • ShieldCrash PoC Bypasses Recent Microsoft Defender Patch, Grants SYSTEM Access

    ShieldCrash PoC Bypasses Recent Microsoft Defender Patch, Grants SYSTEM Access

    A security researcher known as Nightmare Eclipse released a proof-of-concept exploit dubbed ShieldCrash that bypasses Microsoft’s patch for an earlier Windows Defender privilege-escalation flaw, CVE-2026-69414 (nicknamed ShieldBreak), which had been patched only days earlier on Microsoft’s September 2026 Patch Tuesday, BleepingComputer reported. The bypass was independently corroborated by The Register and SecurityAffairs.

    According to the report, the ShieldCrash proof-of-concept allows arbitrary file reads with SYSTEM-level privileges on fully patched Windows 10, 11 and Server installations.

    Why it matters: Defender is the default endpoint-security product on most Windows deployments, including systems inside OT and critical-infrastructure environments. A public proof-of-concept that defeats a just-shipped patch for a SYSTEM-level flaw creates pressure for organizations to apply Microsoft’s next round of fixes quickly and to monitor for exploitation in the interim.

    Source: BleepingComputer, September 9, 2026.

  • CISA Warns of Actively Exploited Citrix NetScaler Authentication-Bypass Flaw

    CISA Warns of Actively Exploited Citrix NetScaler Authentication-Bypass Flaw

    CISA has added CVE-2026-19490, a CVSS 9.3 authentication-bypass vulnerability in Citrix NetScaler ADC and Gateway appliances configured as a gateway or AAA virtual server, to its Known Exploited Vulnerabilities (KEV) catalog, SecurityWeek reported. Exploitation in the wild has been confirmed since at least September 3, 2026.

    Citrix patched the flaw on August 19, 2026. Under Binding Operational Directive 26-04, federal civilian agencies have a three-day remediation window once a KEV entry is added. The exploitation has been independently corroborated by Rapid7, Belgium’s CCB, and security firm RedLegg.

    Why it matters: NetScaler ADC and Gateway appliances sit at the network perimeter of a huge number of enterprises and government agencies, frequently providing VPN and remote-access functionality. An authentication-bypass flaw at this layer is a direct path into internal networks — including those of critical-infrastructure operators — for any attacker who has not yet patched.

    Source: SecurityWeek, September 2026; CISA KEV catalog.