Originally published by Bleeping Computer. View the original article.
Reading
A shared reading desk.
The latest writing from publications and people I follow, organized by topic and readable in one place.
Updated Sep 15, 2026, 5:26 PM EDT
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
Read here
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the…
Read here
Originally published by The Hackers News. View the original article.
CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]
Read here
Originally published by Bleeping Computer. View the original article.
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled…
Read here
Originally published by The Hackers News. View the original article.
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooTo…
Read here
Originally published by The Hackers News. View the original article.
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]
Read here
Originally published by Bleeping Computer. View the original article.
DJI Avata 360 Review: Seeing the Andes Through the Eyes of a Condor
It’s just before five in the afternoon, and I’m hiking up a narrow trail toward the summit of one of the many hills surrounding Ecuadorian Mindo. Only moments ago, a light rain was falling from the sky, but now soft plumes of mist are rising from the canopy…
Read here
It’s just before five in the afternoon, and I’m hiking up a narrow trail toward the summit of one of the many hills surrounding Ecuadorian Mindo. Only moments ago, a light rain was falling from the sky, but now soft plumes of mist are rising from the canopy of the surrounding cloud forest, and it looks like the last hours of the day will offer perfect flying conditions.
Originally published by Photography Life. View the original article.
Hackers target WordPress sites via third-party WooCommerce plugin
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]
Read here
Originally published by Bleeping Computer. View the original article.
What Zero-Day Response Should Be in the Post-Mythos Era
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can he…
Read here
Originally published by Bleeping Computer. View the original article.
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]
Read here
Originally published by Bleeping Computer. View the original article.
CareCam CM2507
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials.…
Read here
Summary
Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials.
The following versions of CareCam CM2507 are affected:
- HMT.CM2507 Firmware v251211.1507 (CVE-2026-88259, CVE-2026-84398, CVE-2026-84400, CVE-2026-81305, CVE-2026-85478, CVE-2026-85497, CVE-2026-81321)
Background
- Critical Infrastructure Sectors: Commercial Facilities
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: China
Vulnerabilities
CVE-2026-88259
CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.
Affected Products
CareCam CM2507 Vendor:CareCam Product Version:
CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:
known_affected Remediations
Mitigation
CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.
Relevant CWE: CWE-306 Missing Authentication for Critical Function
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NCVE-2026-84398
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
Affected Products
CareCam CM2507 Vendor:CareCam Product Version:
CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:
known_affected Remediations
Mitigation
CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.
Relevant CWE: CWE-258 Empty Password in Configuration File
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NCVE-2026-84400
CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the service remotely accessible, increasing the risk of unauthorized administrative access.
Affected Products
CareCam CM2507 Vendor:CareCam Product Version:
CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:
known_affected Remediations
Mitigation
CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.
Relevant CWE: CWE-306 Missing Authentication for Critical Function
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 3.1 LOW CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N 4.0 2.3 LOW CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCVE-2026-81305
CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected device.
Affected Products
CareCam CM2507 Vendor:CareCam Product Version:
CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:
known_affected Remediations
Mitigation
CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.
Relevant CWE: CWE-829 Inclusion of Functionality from Untrusted Control Sphere
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 7 HIGH CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NCVE-2026-85478
A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot process and access functionality that permits inspection or modification of boot configuration, firmware data, and software loaded by the device.
Affected Products
CareCam CM2507 Vendor:CareCam Product Version:
CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:
known_affected Remediations
Mitigation
CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.
Relevant CWE: CWE-306 Missing Authentication for Critical Function
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 3.5 LOW CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N 4.0 2.4 LOW CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:NCVE-2026-85497
CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware.
Affected Products
CareCam CM2507 Vendor:CareCam Product Version:
CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:
known_affected Remediations
Mitigation
CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.
Relevant CWE: CWE-916 Use of Password Hash With Insufficient Computational Effort
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NCVE-2026-81321
CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key.
Affected Products
CareCam CM2507 Vendor:CareCam Product Version:
CareCam HMT.CM2507 Firmware: v251211.1507 Product Status:
known_affected Remediations
Mitigation
CareCam has not responded to CISA's attempts to coordinate. Users are encouraged to reach out to CareCam for more information.
Relevant CWE: CWE-312 Cleartext Storage of Sensitive Information
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NAcknowledgments
- Ben Law reported these vulnerabilities to CISA.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
- Do not click web links or open attachments in unsolicited email messages.
- Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
- Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-09-15
Legal Notice and Terms of Use
Originally published by CISA. View the original article.
Siemens Teamcenter
View CSAF Summary A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Succ…
Read here
Summary
A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Teamcenter are affected:
- Teamcenter V2412 vers:intdot/<2412.0013 (CVE-2026-58113)
- Teamcenter V2506 vers:intdot/<2506.0010 (CVE-2026-58113)
- Teamcenter V2512 vers:intdot/<2512.2607 (CVE-2026-58113)
- Teamcenter V2606 vers:intdot/<2606.2607 (CVE-2026-58113)
Background
- Critical Infrastructure Sectors: Critical Manufacturing, Information Technology
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Germany
Vulnerabilities
CVE-2026-58113
Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into the browser of an authenticated user who loads a crafted URL, enabling the attacker to perform actions within the victim's Teamcenter session.
Affected Products
Siemens Teamcenter Vendor:Siemens Product Version:
Teamcenter V2412 < V2412.0013, Teamcenter V2506 < V2506.0010, Teamcenter V2512 < V2512.2607, Teamcenter V2606 < V2606.2607 Product Status:
known_affected Remediations
Vendor fix
Update to V2412.0013 or later version
https://support.sw.siemens.com/product/282219420/
Vendor fix
Update to V2506.0010 or later version
https://support.sw.siemens.com/product/282219420/
Vendor fix
Update to V2512.2607 or later version
https://support.sw.siemens.com/product/282219420/
Vendor fix
Update to V2606.2607 or later version
https://support.sw.siemens.com/product/282219420/
Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NAcknowledgments
- Enzo Alvarez from Bishop Fox reported this vulnerability to Siemens.
General Recommendations
As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for industrial security and following recommendations in the product manuals.
Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity
Additional Resources
For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories
Additional information on industrial security by Siemens can be found on the Siemens industrial security webpage
For more information see the associated Siemens security advisory SSA-157465 in HTML and CSAF.
Terms of Use
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
Advisory Conversion Disclaimer
This ICSA is a verbatim republication of Siemens ProductCERT SSA-157465 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.
Revision History
- Initial Release Date: 2026-09-08
Legal Notice and Terms of Use
Originally published by CISA. View the original article.
Siemens Mendix SAML
View CSAF Summary Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the…
Read here
Summary
Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.
The following versions of Siemens Mendix SAML are affected:
- Mendix SAML (Mendix 10 compatible) vers:intdot/<4.2.3 (CVE-2026-80465)
- Mendix SAML (Mendix 11 compatible) vers:intdot/<4.2.3 (CVE-2026-80465)
- Mendix SAML (Mendix 9.24 compatible) vers:intdot/<3.6.27 (CVE-2026-80465)
Background
- Critical Infrastructure Sectors: Critical Manufacturing, Information Technology
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Germany
Vulnerabilities
CVE-2026-80465
Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.
Affected Products
Siemens Mendix SAML Vendor:Siemens Product Version:
Mendix SAML (Mendix 10 compatible) < V4.2.3, Mendix SAML (Mendix 11 compatible) < V4.2.3, Mendix SAML (Mendix 9.24 compatible) < V3.6.27 Product Status:
known_affected Remediations
Vendor fix
Update to V3.6.27 or later version
https://marketplace.mendix.com/link/component/1174
Vendor fix
Update to V4.2.3 or later version
https://marketplace.mendix.com/link/component/1174
Vendor fix
Update to V4.2.3 or later version
https://marketplace.mendix.com/link/component/1174
Relevant CWE: CWE-347 Improper Verification of Cryptographic Signature
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.7 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:NAcknowledgments
- Siemens ProductCERT reported this vulnerability to CISA.
General Recommendations
As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security, and following the recommendations in the product manuals.
Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity
Additional Resources
For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories
For more information see the associated Siemens security advisory SSA-887643 in HTML and CSAF.
Terms of Use
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
Advisory Conversion Disclaimer
This ICSA is a verbatim republication of Siemens ProductCERT SSA-887643 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.
Revision History
- Initial Release Date: 2026-09-03
Legal Notice and Terms of Use
Originally published by CISA. View the original article.
Siemens Reyrolle 7SR5
View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. The following versions of Siemens Reyrolle 7SR5 are affected:…
Read here
Summary
Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.
The following versions of Siemens Reyrolle 7SR5 are affected:
- Reyrolle 7SR5 vers:intdot/<2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, CVE-2026-62654)
Background
- Critical Infrastructure Sectors: Energy
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Germany
Vulnerabilities
CVE-2024-42384
Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-190 Integer Overflow or Wraparound
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HCVE-2024-42385
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-140 Improper Neutralization of Delimiters
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 4 MEDIUM CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:HCVE-2024-42386
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-823 Use of Out-of-range Pointer Offset
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.2 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:HCVE-2024-42391
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-823 Use of Out-of-range Pointer Offset
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NCVE-2024-42392
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-140 Improper Neutralization of Delimiters
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 4 MEDIUM CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:HCVE-2026-62645
Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-306 Missing Authentication for Critical Function
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVE-2026-62646
A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This could allow an unauthenticated remote attacker to derive valid session identifiers and bypass authentication.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-331 Insufficient Entropy
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.4 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NCVE-2026-62647
A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easily predict the generated values and impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-20 Improper Input Validation
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.4 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NCVE-2026-62648
The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denial-of-service condition.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-787 Out-of-bounds Write
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HCVE-2026-62649
The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire device to crash and reboot, resulting in a denial-of-service condition.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HCVE-2026-62650
Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request data. This could allow an authenticated, low-privileged remote attacker to escalate privileges to an administrative level.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-288 Authentication Bypass Using an Alternate Path or Channel
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVE-2026-62652
The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-215 Insertion of Sensitive Information Into Debugging Code
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NCVE-2026-62653
The input received over a proprietary communication protocol that is exposed when the device is placed into a special firmware-update mode is not properly validated, resulting in a memory corruption condition. This could allow an unauthenticated attacker with physical access to the device to cause a crash and potentially execute arbitrary code on the device.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-787 Out-of-bounds Write
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVE-2026-62654
A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a network server without verifying its authenticity or integrity. This could allow an attacker with physical access to the device to upload and execute arbitrary, unsigned code.
Affected Products
Siemens Reyrolle 7SR5 Vendor:Siemens Product Version:
Reyrolle 7SR5 < V2.70 Product Status:
known_affected Remediations
Vendor fix
Update to V2.70 or later version
https://support.industry.siemens.com/cs/ww/en/view/109772413/
Relevant CWE: CWE-494 Download of Code Without Integrity Check
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAcknowledgments
- Siemens ProductCERT reported these vulnerabilities to CISA.
General Recommendations
Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. It is therefore recommended that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design. Siemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. As a general security measure Siemens strongly recommends protecting network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment. Recommended security guidelines can be found at: https://www.siemens.com/gridsecurity
Additional Resources
For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories
Additional information on industrial security by Siemens can be found on the Siemens industrial security webpage
For more information see the associated Siemens security advisory SSA-142885 in HTML and CSAF.
Terms of Use
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
Advisory Conversion Disclaimer
This ICSA is a verbatim republication of Siemens ProductCERT SSA-142885 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.
Revision History
- Initial Release Date: 2026-09-08
Legal Notice and Terms of Use
Originally published by CISA. View the original article.
Schneider Electric SCADAPack x70 Products
View CSAF Summary Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities fo…
Read here
Summary
Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality.
The following versions of Schneider Electric SCADAPack x70 Products are affected:
- SCADAPack 47x vers:all/* (CVE-2026-81861)
- SCADAPack 47xi vers:all/* (CVE-2026-81861)
- SCADAPack 47xd vers:all/* (CVE-2026-81861)
- SCADAPack 470R vers:all/* (CVE-2026-81861)
- SCADAPack 57x vers:all/* (CVE-2026-81861)
- SCADAPack 3xx vers:all/* (CVE-2026-81861)
- SCADAPack 32 vers:all/* (CVE-2026-81861)
Background
- Critical Infrastructure Sectors: Critical Manufacturing, Energy
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: France
Vulnerabilities
CVE-2026-81861
There is an insufficiently protected credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.
Affected Products
Schneider Electric SCADAPack x70 Products Vendor:Schneider Electric Product Version:
SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R, SCADAPack 57x, SCADAPack 3xx, SCADAPack 32 Product Status:
known_affected Remediations
Mitigation
Implement the Role-Based Access Control (RBAC) feature and follow the SCADAPack documentation sections Security Guidelines for Administrators and Working with Role-Based Access Control. RBAC is the recommended access control mechanism for SCADAPack 47x devices and should be used in place of the Secure Lock feature. The Secure Lock feature is legacy functionality retained for backward compatibility with existing deployments and should only be used where required to support legacy system requirements. Consult the SCADAPack Cybersecurity Guide, including the SCADAPack Hardening and Secured Communication sections. In addition, apply the following standard practices to reduce the risk of exploitation:
- Configure network segmentation to restrict access between trusted and untrusted networks.
- Enable and implement the RTU firewall service to restrict unauthorized access to device services and reduce the attack surface.
Documentation available in RemoteConnect and SCADAPack x70 Utilities | Schneider Electric
https://www.se.com/ww/en/download/document/RemoteConnect/
Mitigation
Ensure setup of network segmentation to restrict access between trusted and untrusted networks and implementation of the RTU Firewall Service to restrict unauthorized access to services. Consult the SCADAPack Cybersecurity Guide, including the SCADAPack Hardening and Secured Communication sections. In addition, implement all best practices referenced in the SCADAPack Cybersecurity Guide. Documentation available in RemoteConnect and SCADAPack x70 Utilities | Schneider Electric
https://www.se.com/ww/en/download/document/RemoteConnect/
Mitigation
For more information see the associated Schneider Electric security advisory SEVD-2026-251-03 Insufficiently Protected Credentials vulnerability on SCADAPack x70 Products PDF Version, CSAF Version.
Relevant CWE: CWE-522 Insufficiently Protected Credentials
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NAcknowledgments
- Abhinav Agarwal reported this vulnerability to CISA.
General Security Recommendations
Schneider Electric strongly recommends the following industry cybersecurity best practices:
- Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
- Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
- Place all controllers in locked cabinets and never leave them in the “Program” mode.
- Never connect programming software to any network other than the network intended for that device.
- Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
- Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
- Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
- When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
For More Information
This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process. For further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp
LEGAL DISCLAIMER
THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION
About Schneider Electric
Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On.
Our mission is to be the trusted partner in Sustainability and Efficiency.
We are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers.
We are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
Advisory Conversion Disclaimer
This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-251-03 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.
Revision History
- Initial Release Date: 2026-09-08
Legal Notice and Terms of Use
Originally published by CISA. View the original article.
mySCADA myPRO Manager
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem. The following versions of mySCADA myPRO Manager are affected…
Read here
Summary
Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem.
The following versions of mySCADA myPRO Manager are affected:
- mySCADA myPRO Manager <=2.1 (CVE-2026-73807, CVE-2026-82567)
Background
- Critical Infrastructure Sectors: Critical Manufacturing, Energy, Food and Agriculture, Transportation Systems, Water and Wastewater
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Czechia
Vulnerabilities
CVE-2026-73807
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.
Affected Products
mySCADA myPRO Manager Vendor:mySCADA Technologies Product Version:
mySCADA Technologies mySCADA myPRO Manager: <=2.1 Product Status:
known_affected Remediations
Mitigation
mySCADA Technologies has addressed these issues in Version 2.2 and recommends that users update to the latest version. Users are notified in mySCADA Pro Manager about the availability of a new version if the device is connected to the internet. Otherwise, users can download the mySCADA Pro Manager from the webpage.
https://www.myscada.org/downloads/mySCADAPROManager/
Relevant CWE: CWE-862 Missing Authorization
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NCVE-2026-82567
The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and sending the specified SMS message. An unauthenticated attacker with network access to the notification gateway could exploit this vulnerability to send arbitrary SMS messages through the connected modem.
Affected Products
mySCADA myPRO Manager Vendor:mySCADA Technologies Product Version:
mySCADA Technologies mySCADA myPRO Manager: <=2.1 Product Status:
known_affected Remediations
Mitigation
mySCADA Technologies has addressed these issues in Version 2.2 and recommends that users update to the latest version. Users are notified in mySCADA Pro Manager about the availability of a new version if the device is connected to the internet. Otherwise, users can download the mySCADA Pro Manager from the webpage.
https://www.myscada.org/downloads/mySCADAPROManager/
Relevant CWE: CWE-306 Missing Authentication for Critical Function
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.3 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 4.0 5.3 MEDIUM CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:NAcknowledgments
- Shirshak Secnora OÜ reported these vulnerabilities to CISA.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
- Do not click web links or open attachments in unsolicited email messages.
- Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
- Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-09-15
Legal Notice and Terms of Use
Originally published by CISA. View the original article.
Wärtsilä FOS-Onboard
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client. The following versions of Wärtsilä F…
Read here
Summary
Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client.
The following versions of Wärtsilä FOS-Onboard are affected:
- FOS-Onboard 5.07.0923.01 (CVE-2026-78225, CVE-2026-81855)
Background
- Critical Infrastructure Sectors: Transportation Systems
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Finland
Vulnerabilities
CVE-2026-78225
A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
Affected Products
Wärtsilä FOS-Onboard Vendor:Wärtsilä Product Version:
Wärtsilä FOS-Onboard: 5.07.0923.01 Product Status:
known_affected Remediations
Mitigation
Wärtsilä states that the vulnerabilities are not exploitable when the product is installed as recommended, and has developed a security patch. Users are also directed to contact Wärtsilä to obtain and install the patch. To obtain and install the latest patch, contact Wärtsilä:
https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact
Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 9 CRITICAL CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 9.5 CRITICAL CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HCVE-2026-81855
A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.
Affected Products
Wärtsilä FOS-Onboard Vendor:Wärtsilä Product Version:
Wärtsilä FOS-Onboard: 5.07.0923.01 Product Status:
known_affected Remediations
Mitigation
Wärtsilä states that the vulnerabilities are not exploitable when the product is installed as recommended, and has developed a security patch. Users are also directed to contact Wärtsilä to obtain and install the patch. To obtain and install the latest patch, contact Wärtsilä:
https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact
Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NAcknowledgments
- Cydome Security Ltd reported these vulnerabilities to Wärtsilä and CISA
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
- Do not click web links or open attachments in unsolicited email messages.
- Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
- Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-09-15
Legal Notice and Terms of Use
Originally published by CISA. View the original article.
Digital Watchdog VMAX DVR and NVR Product Lineups
View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point.…
Read here
Summary
Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point.
The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected:
- VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
- VMAX IP G4 NVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
- VMAX A1 PLUS vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
- VA1G4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
- VG4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
Background
- Critical Infrastructure Sectors: Commercial Facilities, Government Services and Facilities, Healthcare and Public Health, Transportation Systems
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: United States
Vulnerabilities
CVE-2026-68953
The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.
Affected Products
Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:
Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:
known_affected Remediations
Mitigation
Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at:
https://digital-watchdog.com/downloads/
Relevant CWE: CWE-306 Missing Authentication for Critical Function
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NCVE-2026-66890
The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.
Affected Products
Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:
Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:
known_affected Remediations
Mitigation
Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at:
https://digital-watchdog.com/downloads/
Relevant CWE: CWE-798 Use of Hard-coded Credentials
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 9.6 CRITICAL CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 9.4 CRITICAL CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HCVE-2026-68070
The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.
Affected Products
Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:
Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:
known_affected Remediations
Mitigation
Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at:
https://digital-watchdog.com/downloads/
Relevant CWE: CWE-306 Missing Authentication for Critical Function
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NCVE-2026-68950
The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.
Affected Products
Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:
Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:
known_affected Remediations
Mitigation
Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at:
https://digital-watchdog.com/downloads/
Relevant CWE: CWE-798 Use of Hard-coded Credentials
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NCVE-2026-66887
The affected products are missing authorization on state-changing CGIs and session checks are not performed.
Affected Products
Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:
Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:
known_affected Remediations
Mitigation
Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at:
https://digital-watchdog.com/downloads/
Relevant CWE: CWE-862 Missing Authorization
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 9.6 CRITICAL CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 9.4 CRITICAL CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HCVE-2026-66372
The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.
Affected Products
Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:
Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:
known_affected Remediations
Mitigation
Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at:
https://digital-watchdog.com/downloads/
Relevant CWE: CWE-337 Predictable Seed in Pseudo-Random Number Generator (PRNG)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N 4.0 7.6 HIGH CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NAcknowledgments
- Scot Berner of TrustedSec reported these vulnerabilities to CISA.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
- Do not click web links or open attachments in unsolicited email messages.
- Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
- Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.
Revision History
- Initial Release Date: 2026-09-15
Legal Notice and Terms of Use
Originally published by CISA. View the original article.
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initi…
Read here
Originally published by The Hackers News. View the original article.
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature o…
Read here
Originally published by The Hackers News. View the original article.
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credent…
Read here
Originally published by The Hackers News. View the original article.
Suspected Black Axe gang leaders face cybercrime charges in the US
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. [...]
Read here
Originally published by Bleeping Computer. View the original article.
Microsoft confirms KB5002914 Excel update breaks copy and paste
Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update. [...]
Read here
Originally published by Bleeping Computer. View the original article.
LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single ma…
Read here
Originally published by The Hackers News. View the original article.
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0.…
Read here
Originally published by The Hackers News. View the original article.
Photography News: A New PEN, Rumored Sony Light Telephotos, Leica Deals
Photography should bring joy from beginning to end. Whenever possible, it certainly shouldn’t end up as a fleeting collection of ones and zeros on a hard drive, but as a quality print hanging somewhere on a wall.
Read here
Originally published by Photography Life. View the original article.
Lightroom’s New “Render to DNG” Feature Is a Big Change
Here's a story that may sound familiar to Lightroom users: You're editing a difficult photo, and the sliders, gradients, and brushes are adding up. Even if the photo is looking better, a wall is looming ahead - specifically, new edits are interacting poorly…
Read here
Here's a story that may sound familiar to Lightroom users: You're editing a difficult photo, and the sliders, gradients, and brushes are adding up. Even if the photo is looking better, a wall is looming ahead - specifically, new edits are interacting poorly with your prior edits, and there's no easy way to fix it.
Originally published by Photography Life. View the original article.
The Sand Dunes of Florianópolis
Gentle tendrils of vines surround the trunks of trees, trunks covered by mosses and lichens and ants. Sunlight filters weakly through the foliage and struggles to reach the forest floor. Once in a while, the stillness is permeated by the raucous and jarring…
Read here
Gentle tendrils of vines surround the trunks of trees, trunks covered by mosses and lichens and ants. Sunlight filters weakly through the foliage and struggles to reach the forest floor. Once in a while, the stillness is permeated by the raucous and jarring calls of chachalacas and toucans.
Originally published by Photography Life. View the original article.
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabili…
Read here
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
Image: Shutterstock.com, Kirill Makarov.
This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities. September’s Patch Tuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go.
There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on Windows system.
Fully 113 of the bugs addressed today earned Microsoft’s “critical” rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user.
Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10. Microsoft warns that an unauthenticated attacker could leverage this weakness simply by sending a specially crafted packet to an affected system, and that it is likely to be exploited.
Also scary is CVE-2026-69829, a critical, remote code execution flaw in the Windows Shell. This vulnerability has a CVSS base score of 9.8 (10 is the most severe), and can be exploited with low attack complexity, no privileges, and no user interaction.
Microsoft’s summary of the security updates released today. Image: msrc.microsoft.com.
Microsoft is hardly alone in shipping monster patch bundles lately. Many other large software companies, including Adobe, Cisco, Google, Mozilla and Oracle, all have recently credited AI-assisted research with increasing their patch cadence and volume (Google said today it is now going to ship security updates every two weeks).
Tyler Reguly, associate director of security research and development at Fortra, said one core challenge with deploying Windows updates is that they need to be tested before being installed across an organization because not all third-party software works seamlessly in the face of changes to the underlying operating system.
“It’s time to put our CISOs and CSOs on notice,” Reguly said. “How are you helping your teams through these difficult times? Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment? Do you reward them for that effort? Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.”
Satnam Narang is senior staff research engineer at Tenable. Narang said it’s important to recognize that while the number of vulnerabilities being patched by Microsoft is rising, the number of flaws that can and will affect most organizations remains quite low.
“AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles,” he said. “It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.”
Of course, regular Windows users don’t need to test patches before deploying them, but they still need to open Windows Update periodically or else assent to the program’s nag notices about pending updates. And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.
Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear to be causing problems. As always, the SANS Internet Storm Center has a per-patch breakdown ordered by severity and urgency.
Originally published by Krebs on Security. View the original article.
Photography News: Fuji 400mm f/4.5 Announced, Gitzo Sales
Yesterday, while going through photographs for an upcoming article, I came across this portrait of a European green frog and had to laugh. You see, wildlife photography can often be a rather lonely pursuit. You sit in a hide for hours on end, or wander thro…
Read here
Yesterday, while going through photographs for an upcoming article, I came across this portrait of a European green frog and had to laugh. You see, wildlife photography can often be a rather lonely pursuit. You sit in a hide for hours on end, or wander through the wilderness without encountering a living soul. Then you come home and your spouse or kids ask, “How was it out there? Show us a photo of you taking pictures.” I try to appease them and occasionally snap a selfie, usually on my phone—you know how it goes. But usually, the animal I was photographing is missing from the picture.
Originally published by Photography Life. View the original article.
A Coati in an Odd Coat: Photographing a Mystery in the Andes
Have you ever seen the cute, cat-sized animal known as coatis or coatimundis? Although the range of these raccoon-like mammals extends as far north as Arizona, their primary habitat is Central and South America. The origin of their name can be traced to the…
Read here
Have you ever seen the cute, cat-sized animal known as coatis or coatimundis? Although the range of these raccoon-like mammals extends as far north as Arizona, their primary habitat is Central and South America. The origin of their name can be traced to the Brazilian part of the Amazon, specifically the vocabulary of the Tupi Indian tribe. Kua means “belt” in their language, and ti means “nose” – and the coatis sure have an interesting nose. Furthermore, the word mundi, meaning “lonely,” reflects the solitary nature of adult males, who typically keep their distance from the otherwise social females and their young.
Originally published by Photography Life. View the original article.
One Photographer, Many Genres
I often hear people say that to stand out and develop your own style in photography, you need to find a niche and stick to it. I have always tried to do the exact opposite, moving between reportage, sports, landscape, macro, portrait, studio fashion, and wi…
Read here
I often hear people say that to stand out and develop your own style in photography, you need to find a niche and stick to it. I have always tried to do the exact opposite, moving between reportage, sports, landscape, macro, portrait, studio fashion, and wildlife. Often with some of the same camera gear.
Originally published by Photography Life. View the original article.
FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on…
Read here
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.
A record available at this identity theft service that includes the drivers license for U.S. Defense Secretary Pete Hegseth, one of several high-ranking U.S. government officials whose drivers licenses can be found for sale.
On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.
The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.
A quick look around Nexus finds they are likely not exaggerating about that 153 million number: Running a blank search in Nexus (with no search parameters entered) returns approximately 11.5 million pages of results, with roughly 15 results displayed per page. It includes documents from people in both Canada and the United States, but the bulk of these records are on Americans: searching for just Canadian drivers licenses returns approximately 1.1 million results, with the largest concentration from Ontario (473,673 records).
Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards. Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.” Other records carry the source notation of “CAC,” which may refer to Common Access Cards, government issued identity cards that grant physical access to government buildings and secure rooms.
The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.
The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.
“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”
Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.
The record featuring my drivers license includes six image files: three pairs of photos of the license’s front and back, a basic image scan, as well as infrared and ultraviolet versions of the same images. A date and timestamp is appended to each image file, and the timestamp on my license scan corresponds to a date in June 2025 when I took a flight to the midwest United States to attend a family funeral.
Some of the 153 million+ license scans — including mine — feature six image files with date and timestamps appended to the filenames. Not all records include photos, and some that do feature photos do not display the associated filenames.
Intent on discovering the source of this data, KrebsOnSecurity asked more than a dozen friends and family members for permission to search for their licenses in this service. Each person whose license could be found (nine of them) confirmed having traveled on or very close to the dates in the timestamps attached to their images. It is unclear what timezone these timestamps are in, but from reviewing car rental records shared by several people who helped with this research, it appears the timezone is set to Greenwich Mean Time (GMT).
At first, I thought the source of the data might have something to do with airports. However, that theory went out the window when it became apparent there were no passports in this data set. Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel. One person whose license was in Nexus hadn’t flown at all recently, but was renting a car from Hertz for several months around the date of their timestamp.
Two of those who agreed to help are federal employees who said they shared other forms of government identification when passing through airport security. However, those individuals each said they shared their state-issued drivers licenses later that day when renting vehicles at their respective destinations, and that both rented their cars from Hertz.
After finding a note in my calendar for the day of my June 2025 flight reminding me to bring my passport, I remembered that I also never actually shared my drivers license when I went through security at Reagan National Airport on that day because I did not yet have a Real ID, a security-enhanced drivers license that is now required by the Transportation Security Administration (TSA) for all domestic travel. Instead, I showed the TSA agent my government-issued U.S. passport.
Here’s where it gets interesting: I was able to find my mother’s drivers license in this service as well, and the timestamps for her images are just a few seconds apart from mine. That’s notable because we both handed our licenses to the Hertz rental car representative at the same time.
According to my mom, the only place she gave her drivers license to that day was the rental car company, and if memory serves that is also true for me. I don’t recall if the rental car representative inserted our licenses into any kind of machine, but I remember they held onto them for several minutes behind the counter while we were signing various forms. KrebsOnSecurity sought comment from Hertz and will update this story in the event they reply.
Zach Edwards is a well-known security and privacy researcher who recently launched a service called DecryptAds to help people better understand how online advertisers are tracking them. A scan of Edwards’s drivers license is available for purchase on this identity theft service, and Edwards said the timestamp on his record corresponds to the middle of a trip last month to Las Vegas for the annual DEFCON security conference.
Edwards told KrebsOnSecurity that although he did not rent a car in Vegas, he did hand over his license at the TSA checkpoint, at a marijuana dispensary in Vegas, and at his hotel (the Aria). But he said the only one of those three that for sure scanned his ID in some kind of device was the dispensary.
To enter Planet13’s weed dispensary in Las Vegas, one must pass through a red telephone booth. Image: Zach Edwards.
Edwards said the dispensary he visited that day was Planet13, a multi-state chain with stores in California, Florida, Illinois and Nevada. In 2022, the New Orleans-based identity provider idscan.net published a press release announcing an exclusive identity verification agreement with Planet13’s dispensaries nationally. IDScan says it processes ID verification for more than 1,000 marijuana dispensaries in 19 U.S. states.
The “trust” page of idscan.net states that the company provides identity verification services for numerous big brands, including Hertz, Target, Fedex, Motorola Solutions, the financial services giant Jack Henry, and Caesars Entertainment. And as idscan.net’s own documentation states, the technology scans IDs with both infrared and ultraviolet light. Idscan.net says the company’s systems and technology perform more than 21 million verifications monthly, at more than 20,000 locations around the world.
Image: idscan.net.
Contacted by KrebsOnSecurity, idscan.net said it was investigating the matter, but the company has not yet shared an official statement or a substantive reply to specific questions sent via email.
“At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” wrote Jillian Kossman, a marketing and operations leader at idscan.net.
During the course of my research for this story, word got around to the FBI that I was poking at the apparent source of this new identity theft service’s data. Probably they were tipped off when I shared with a trusted source that Nexus also is selling the drivers license information for the assistant director of the FBI (I did not find FBI Director Kash Patel’s license in Nexus).
Earlier this afternoon, I was added to a conference call with a half-dozen FBI agents, including senior leaders from the agency’s cyber division. During that call, the FBI shared that earlier today their New Orleans field office opened an official investigation into an apparent breach involving idscan.net.
Edwards said that as more in-person and online experiences require sharing drivers licenses, vendors who collect this sensitive data need to be held to a higher standard.
“This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids,” Edwards told KrebsOnSecurity. “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.”
Larry Baldwin is principal intelligence researcher at the cybersecurity firm Cybera. Baldwin said a front and back scan of his drivers license available at Nexus contains timestamps that correspond to the date of a car rental from Hertz on a recent vacation.
Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).
This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.
“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.
Update, Sept. 8: IDscan.net published a brief notice saying it has “determined that an unauthorized third party may have access and/or copied certain customer information, including full names and drivers license or other government-issued identification numbers.” The statement said IDscan.net is notifying affected individuals and offering credit protection services.
Update, Sept. 2, 6:05 p.m. ET: A spokesperson for Caesars Entertainment said Caesars has not been a client of IDScan.net and has not used VeriScan since February 2025, despite IDScan.net listing them as a client on their website. That person said Caesars had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from its accounts, and that IDScan.net said the incident should have no impact on Caesars Entertainment.
Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”
This is a potentially fast-moving story. Any changes or updates will be noted here along with a timestamp.
Originally published by Krebs on Security. View the original article.
Photography News: New Apple Desktops, Nikon Europe Sales
This week may not have brought any groundbreaking photography news, but it did set the stage for several fantastic encounters in front of my microphone and camera. The first one you will probably get to see is a very inspiring conversation with Janek Bednař…
Read here
This week may not have brought any groundbreaking photography news, but it did set the stage for several fantastic encounters in front of my microphone and camera. The first one you will probably get to see is a very inspiring conversation with Janek Bednařík, an elite mountain guide and also one of the few people who has hand-raised wild geese from the moment they hatched, became their adoptive father, and a few months later found himself leading their flock on a small hang glider. Of course, you can look forward to some great photos and videos from that.
Originally published by Photography Life. View the original article.
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Aust…
Read here
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.
In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”
The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.
TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbed Shai-Hulud, which added malicious code to open source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen.
Writing for Wired, journalist Andy Greenberg described TeamPCP’s core tactic as a kind of cyclical exploitation of software developers.
“The hackers gain access to a network where an open source tool commonly used by coders is being developed,” Greenberg wrote in May. “The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows.”
TeamPCP also has practiced something akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and TeamPCP soon after launched a contest offering $1,000 in virtual currency to whichever participant could conduct the largest supply chain operation using the worm’s code. According to the contest rules, participants were scored based on the number of weekly and monthly downloads of packages they compromised — directly incentivizing them to target the most popular code libraries.
A screenshot of a message from TeamPCP’s Telegram account, announcing the supply chain hacking contest. Image: dataminr.com.
“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote. “The $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as ‘just like participation trophy,’ adding ‘if you find something good you will be paid way more,’ confirming the contest’s true function as talent identification and malicious access acquisition at scale.”
In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM, an open source AI gateway that connects users to more than 100 different large language models. A recent analysis by the security firm CloudSEK found TeamPCPs attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world’s top technology companies.
In May, TeamPCP claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned GitHub, after a GitHub developer installed a code extension that was compromised by TeamPCP’s malware.
MEET THE CYBERCATS
Security experts say TeamPCP is less of a hacker group than an amalgamation of threat actors from multiple cybercriminal gangs who sometimes work together toward similar goals.
“It is not a structured criminal crew with a single operator,” said Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group. “It is a peer community of individually-skilled actors, with one clear center of gravity.”
That center of gravity is George Prepakis, an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub. Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and dubbed “Cybercats,” and TeamPCP and several other cybercrime entities have been using this server to communicate daily for the past several months.
A screenshot of the Matrix chat server “Cybercats,” whose members used hacker handles associated with multiple distinct cybercrime groups that have occasionally collaborated on a series of supply chain and data ransom attacks over the past nine months.
Kernelstub, like other administrators in the Cybercats chat, has been using his Twitter/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and to conversations taking place in the Cybercats chat. In a number of cases, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly before the incidents were reported in the news media.
The Cybercats administrator listed at the top of the screenshot above — “Boxturtle” — is a close associate of TeamPCP who has been tweeting about the group’s conquests under the name @xpl0itrsturtle. This handle corresponds to a data breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of recent breaches at automobile manufacturers, including BMW Group, Audi, Honda, Mercedes-Benz, Volvo and Toyota, as well as data allegedly taken from Snapchat and SportRadar.
The data leak site for the extortion group or handle “xpl0itrs.”
The Cybercats administrator “SeesawSec” in the screenshot above is the alias of whoever is behind the cybercrime group known as Fulcrumsec, which recently claimed credit for data extortion attacks against the pharmaceutical giant Novo Nordisk, the data broker LexisNexis, and Avnet, a Fortune 500 distributor of electronic components.
The data leak site of Fulcrum Security, a.k.a. Fulcrumsec.
The Cybercats administrator “@pcpcasper” also has been using a similar name on X to discuss TeamPCP’s attacks and victims. This person has an extensive message history on Telegram, where their messages and shared videos show @pcpcasper is an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia.
At one point in these chats, @pcpcasper shared videos and images of what they claimed was their cat, and several of those videos place this user in Western Australia. One source close to the investigation told KrebsOnSecurity that @pcpcasper was one of the two arrested, a claim supported by messages that @kernelstub posted online this morning.
The Cybercats member roster pictured above also features an administrator with the username “T,” which is short for the now-banned Twitter/X profile @pcpcats, the account operated by the self-described TeamPCP spokesperson who was arrested today. As we’ll see in a moment, @pcpcats also is from Western Australia.
By the time @kernelstub tweeted a public invite link to the Cybercats Matrix server, T/@pcpcats was posting only infrequently to the group chat, with other members often inquiring as to his whereabouts and well-being. The group’s collective concern related to @pcpcats’s tendency to blame his increasingly extended absences on the use of hallucinogens and other narcotics that kept him awake for days on end, but also caused him to crash in bed for several days after the highs wore off.
WHO IS THE TEAMPCP LEADER?
The Cybercats member @pcpcats has used multiple nicknames on the cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts are linked because they all advertised the same Tox ID and/or Session ID as instant message contact handles in their cybercrime forum posts. BulkDMT was also known on the forums as DMT Host, which was a virtual private server (VPS) hosting service that was peddled on Darkforums and Breachstars.
DMT Host/EllisD25, posting on the English-language cybercrime community DarkForums in September 2025. Image: ke-la.com.
According to the cyber intelligence firm Intel 471, Express registered on Breachforums using the email address shitstickpp@gmail.com. Intel 471 finds Express posted on Breachforums across a two-month period in 2025 using four different Internet addresses located in South Africa. On July 30, 2025, Express announced on Breachforums they were selling access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency.
The threat intelligence platform Flashpoint recorded more than a year’s worth of messages from the TeamPCP leader’s alter ego on Telegram — Persy_PCP — who claimed they split their life living between two countries [full disclosure: Flashpoint is an advertiser on this blog]. “I have these [files] as well, problem is these are in another country,” Persy_PCP explained to another user inquiring about a stolen data set in November 2025.
Later that month, Persy_PCP complained, “My whole country is racist and they want people like me dead.” Flashpoint records show BulkDMT shared in September 2025 that “this country is going to fucking starve when they take the farmers land,” a likely reference to white landowners in South Africa who claim to be targeted by an ongoing genocide campaign.
This tracks with public reporting on TeamPCP. Cyberscoop reported in June that Google had traced TeamPCP’s residential and mobile Internet address connections to South Africa, “indicating the primary operator was located there during at least some of its attacks.”
BulkDMT also shared on the group chat at Breachforums that they were recovering from an addiction to methamphetamine. “My life is kinda fucked rn [right now], but that’s fine and there isn’t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don’t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that’s enough drive and meaning.”
The identity threat protection company SpyCloud finds shitstickpp@gmail.com shows up in the registration of an account called ChristmasSnow on the cybercrime community Raidforums in 2022. Nearly all of the Internet addresses used to access that account came from ISPs in Perth, Australia, SpyCloud found.
KrebsOnSecurity looked up all of those Perth IP addresses in passive DNS records maintained by DomainTools.com, and found one of them — 211.27.196.111 — for several years was used as a private file server by a family in Perth with the last name of Thomson. Those records show at least three hosts — ithomson.direct.quickconnect.to (a remote Synology server), kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com (a QNAP network storage device) — persisted at that address between 2022 and 2025.
Searching on “joshuathomson39” in the breach tracking service Constella Intelligence reveals an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open source intelligence platform Epieos finds the phone number attached to that kwe.com account was used to register a Facebook profile for Josh Thomson, which says his family includes a brother named Ruben, his father Ian, and his mom Cindy.
That Facebook profile also says Josh and his family are originally from Pietermaritzburg, in KwaZulu-Natal, South Africa, but currently living in Cottesloe, a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed five domains by the same registrant, including securecomputing.au, thomson.org.au, and thomsonfamily.net.au. Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The University of the Witwatersrand in Johannesburg, South Africa.
Constella finds a joshua@thomson.org.au registered a number of accounts online, but Josh doesn’t seem to have much of a connection to dodgy cybercrime forums. His brother Ruben, on the other hand, has quite the presence on these communities, dating back to at least 2018. Constella reports ruben@thomson.org.au frequently reused the password “joshuathomson1,” and Constella further finds that password was used by just a handful of accounts, including yolosolo17@gmail.com and surfinup8@gmail.com.
According to Intel 471, surfinup8@gmail.com was used to register the user Yolosolo17 on the crime forum Altenen in 2018, and that user account was registered from the Perth address 110.141.230.15. On Altenen, Yolosolo17 advertised free web proxies, as well as the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. DomainTools says rubenthomson.com was hosted at 110.141.230.15 and registered to surfinup8@gmail.com.
A cached copy of the domain rubenthomson.com from 2017 shows a login page underneath a banded stack of money. Image: archive.org.
SpyCloud reports 10.141.230.15 was used by the email address sheepstealing@gmail.com on Raidforums and surfinup8@gmail.com on Nulled, and that the same IP was used by the email addresses ian@thomsonfamily.net.au, jasper@yakuza.cc, and rubenthomson1@gmail.com. SpyCloud also shows that sheepstealing Gmail address is tied to the accounts Sheep420, YoloSolo117 and Yakuza.cc on Raidforums, and to the account “Sheep Stealing” on Hackforums. Intel 471 says sheepstealing@gmail.com was used to register the account DingoFlour on Breachforums in October 2023, as well Sheepx on Altenen.
Epieos reports that ruben@securecomputing.au is tied to an Airbnb account for Ruben, who described himself as a Web developer who went to school at the University of Western Australia and was living outside the country. “Hey, I’m Ruben, my friends call me Ellis. I’m a Perth creative who occasionally books rooms when visiting family and for photography.”
Epieos also finds sheepstealing@gmail.com registered an upwork.com profile under the name Ruben, who said his main skills are setting up secure server hosting solutions and PHP full-stack Web development.
“I’m familiar with Linux, working with relational databases (SQL),” the Upwork profile reads. “I also script in Python mainly for writing social media bots.”
The Upwork profile for Ruben Thomson in Cottesloe, Australia.
Epieos further discovered sheepstealing@gmail.com is connected to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account called XmasSnow/XmasSnowisBack that scammed people on the forums in 2022 by claiming to sell exclusive exploits for recently-released software patches (recall that shitstickpp@gmail.com was used to register a forum account named ChristmasSnow).
This same sheepstealing email address registered a Twitter/X account in 2026 called “Gone Fishing” that lists its location as South Africa. That Gmail account also left several reviews for businesses listed on Google Maps over the past seven years, but all of those establishments are located on the west coast of Australia.
Business reviews in Western Australia left by the Google account sheepstealing at gmail.com.
The people search service Pipl finds a 21-year-old Ruben Thomson in Western Australia who has a phone number ending in 979. A lookup on that number at Epieos reveals it is connected to a TikTok account under the name Ellis, and to a PayPal account in the name of Ruben Thomson.
Finally, a search on the name Ruben Thomson from Cottesloe at the Australian government’s record of registered businesses finds he has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions, Tensor Industries, and another entity ironically named OPSEC Express. Recall that Express was BulkDMT’s nickname on Breachforums.
Australian companies connected to Ruben Thomson. Image: abr.business.gov.au.
It’s ironic because OPSEC is short for the term “operational security,” which refers to techniques and behaviors used to obfuscate and compartmentalize one’s real-life identity online, and using your cybercrime handle as part of your own company name is very much the antithesis of that practice.
There is at least one other major opsec failure by Ruben that exposed a link to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on HackerOne, a popular “bug bounty” program that seeks to reward and recognize researchers who agree to work with affected software vendors to help fix the flaws before publishing about their findings. What was Ruben Thomson’s chosen HackerOne username? Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.
The HackerOne profile for “Ruben Thomson” uses the nickname Deadcatx3, which multiple security firms have concluded is an alias used by TeamPCP. Image credit: flare.io.
INTERVIEW WITH ELLIS
In early July 2026, not long after having discovered clues about Ellis’s real life identity, KrebsOnSecurity interviewed the TeamPCP leader via Signal, where he was remarkably open about his activities and personal struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis].
Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 — just before the attacks that compromised LiteLLM — and that at least one other individual has taken over the group’s leadership since then. Ellis shared that a year earlier he had just completed the latest in a series of detox and sobriety programs, and was two months sober when he reconnected with some old friends from the malware development scene.
“One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,” Ellis said. “I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.”
Prior to that, Ellis said, he was homeless and hopping between “some very unstable places.”
“Blackhatting is fun,” he said. “There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.”
Ellis claims he’s earned a grand total of about $20,000 for his activities with TeamPCP, and that it was never about the money or fame for him. Asked whether his experiences with TeamPCP might prepare him for gainful employment in a legitimate IT job, Ellis said he doubted it.
“I am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience,” he said. “I no longer have to choose between rent and food for that I’m grateful and so are the team members.”
Ellis expressed no remorse over his cybercrime activities, and said he was grateful for the friendships and relationships built throughout his engagement with TeamPCP. The young hacker also seemed resigned to his fate, and told KrebsOnSecurity that he’ll accept the consequences if he’s ever arrested.
“If I’ve already been found out then its out of my control, I’ll make peace with that,” he said. “Honestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this.”
It is clear from reading Ellis’s posts to the group’s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis told @kernelstub he was about to “trip” with his “homie.”
“What kind,” @kernelstub inquired.
“Ketty and some DMT,” Ellis replied, referring to the dissociative anesthetic ketamine and dimethyltryptamine (DMT), a powerful psychedelic compound that is found naturally in some plants but is also synthetically produced in underground lab environments. “There’s a little 2cb so we might throw that in the mix,” he continued, referring to another psychedelic compound by its chemical shorthand.
Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to leave his life of crime behind and was prepared to turn himself in, but that in the meantime he was making plans to tie up loose ends.
Less than 24 hours later, the TeamPCP leader posted an image on Telegram showing a yellowish powdered substance in a baggie and on a scale, possibly synthetic DMT. The image shows the powder being weighed next to a series of small vape cartridges, two of which are open on the table in front of the photographer.
An image posted by the TeamPCP leader to Telegram, advertising his acquisition of some type of psychoactive substance, most likely a synthetic version of the powerful hallucinogen known as DMT.
The two defendants were arrested Wednesday morning. The AFP said the men face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today.
Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns. Eriksen said TeamPCP are a good example of a new kind of threat actor that does not fit neatly into the usual categories.
“They are not a state actor, not quite organized cybercrime, and not purely ideological,” he said. “Their motivations seem to mix money, disruption, attention, and ideology.”
Eriksen said that historically there has always been a meaningful gap between reading about an attack technique and being able to reliably turn it into an operational campaign, but that large language models (LLMs) and artificial intelligence increasingly are helping threat actors to bypass that knowledge gap.
“You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,” he said. “LLMs have compressed that gap significantly.”
According to Eriksen, this creates an environment where threat actors suddenly have the ability to operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability. Put another way, it sets the stage for cybercriminals who are capable enough to cause significant damage, but not necessarily careful enough to understand or care about the consequences.
“They can be noisy, they can make mistakes,” he said. “They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.”
In a recent blog post, Eriksen called TeamPCP’s Shai-Hulud worm the “best thing to happen to supply chain security,” because it forced GitHub and other public coding platforms to erect new security safeguards.
In direct response to TeamPCP’s broad success at pushing poisoned versions of popular software packages, GitHub in late July introduced a three-day “cooldown” mechanism for Dependabot, the platform’s tool for auto-fetching newly shipped updates for any package dependencies. Cooldown periods are designed to help buy time for security tools and package maintainers to identify and remove any compromised versions. Other coding ecosystems like Python and various JavaScript platforms also added support for cooldown periods this year amid growing calls from security experts about the need for more widespread adoption of the safety feature.
Eriksen said TeamPCP’s legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years.
“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said. “By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.”
Update, 10:08 a.m. ET: A story this morning from ABC News in Australia confirms Ruben Ian Thomson of Cottesloe was one of the two arrested. The 23-year-old suspect thought to be @pcpcasper, Michael Gaebler, also was arrested in Perth. ABC News reports that Thomson was denied bail (Mr. Gaebler’s attorney reportedly did not request bail for his client), and that both men will be held in custody until their next court appearance on September 18.
Originally published by Krebs on Security. View the original article.
Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has…
Read here
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.
A Decryptads summary of the advertising partnerships declared by espn.com.
The newly launched decryptads.com says it is constantly scraping the files that websites and apps make publicly available to disclose the companies that are permitted to run ads or collect user data. These files include:
–ads.txt: all of the adtech companies and data brokers that may run ads or harvest data from the site;
–app-ads.txt: entities that can harvest data from or display ads on mobile and smart TV apps;
–buyers.json/sellers.json: the entities buying, selling or reselling ad inventory for a given site or app.
Zach Edwards is chief research officer for DecryptAds and a threat researcher at the security company Infoblox. Edwards said he and two other founders decided the service was needed because the adtech data in these files is generally only useful when it can be cross-referenced to build a more complete picture of the advertising ecosystem for each website or app.
“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”
Those use cases, he said, include tracking down the source of malicious ads that try to foist malware on targeted users, identifying ad networks located in adversarial nations, and detecting the fast growing swarms of AI-generated slop websites and apps. And as decryptads.com demonstrates, these potential security and privacy threats are near impossible to detect just by viewing a single apps.txt or app-ads.txt file.
“Supply-chain integrity issues rarely live in a single file,” the site explains. “They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list.”
A search in DecryptAds for the hugely popular sports network espn.com reveals 143 ad partners and 19 registered data broker domains are listed within its ads.txt and app-ads.txt files. That data broker information is gradually becoming available because four states — California, Oregon, Texas and Vermont — have recently passed laws requiring data brokers to register if they buy or sell data on consumers from those states. DecryptAds reports that almost half of those data brokers are collecting geolocation data from espn.com visitors who aren’t blocking ads, while another three disclose that they collect device fingerprints and sensitive personal information.
A visual representation of the complex ad supply chain declared by espn.com. Image: decryptads.com.
HIGH-RISK AD PARTNERS
DecryptAds also makes it easy to learn the beneficiaries and national origins of the advertising firms lurking in apps and websites, displaying a conspicuous warning when adtech partners of an app or website are based in “geo-risk” areas like China and Russia, or in countries with strong financial and political ties to both — such as Cyprus and the United Arab Emirates (UAE).
According to DecryptAds, espn.com works with four different advertising entities that are based in either Russia, China or the UAE, including the adtech firm Between Digital, which lists a New York address. However, the dossier on Between Digital flags them as a Russian firm, showing that their publisher offers (PDF) are processed through Alfa Bank, Russia’s largest private commercial bank and one of several financial institutions placed under U.S. sanctions in 2022 after Russia invaded Ukraine. KrebsOnSecurity sought comment from both Between Digital and the company’s founder, and will update this story in the event that either replies.
A search for several top U.S. military news websites — including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com and federaltimes.com — shows they all allow Between Digital to serve ads and track users, as well as two entities in the UAE and another in the ownership secrecy haven of Panama. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.
The “Geo Risk” section of decryptads.com.
Pivoting on Between Digital’s app-ads.txt file reveals hundreds of domains featuring simple web-based games that are frequently interrupted by ads. Edwards said Between Digital’s own declarations show the company is listed as both a publisher and a reseller on approximately two-thirds of their portfolio.
“It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest,” Edwards told KrebsOnSecurity. “The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files.”
The Opera Web browser remains quite popular, and probably many users are unaware that since 2016 it has been majority owned and controlled by the Chinese company Kunlun Tech (the operational headquarters of Opera remain in Oslo, Norway).
Opera.com’s profile at DecryptAds identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia and one each in Hong Kong and Ukraine. DecryptAds makes clear, however, that these companies represent just seven percent of the adtech partners specified in Opera.com’s ads.txt and app-ads.txt files.
LEGAL DOSSIERS
One feature of DecryptAds that sent this author down multiple hours-long research rabbit holes is its Legal Dossier lookup, which takes several minutes for each search but eventually churns out oodles of useful information about who owns a particular domain or app, when it was registered, and any aliases or relationships it may have to adtech companies and other websites or apps.
For example, last month KrebsOnSecurity wrote about researchers from Bitsight who found that an extremely popular line of TV streaming sticks called H96 quietly rent out each user’s Internet connection to strangers. Bitsight also discovered that when these devices aren’t being used to stream pirated video content, they are spoofing themselves as mobile phones clicking ads on AI-generated slop websites.
Bitsight concluded that the same Chinese company that made several of the malicious apps common to all of these H96 streaming sticks — the Fengwo Group — also also ran the network of ads and AI slop websites being clicked on by tens of thousands of these devices that are pretending to be mobile phones.
Examples of ad landing pages linked to the Fengwo Group. These sites were designed to show ads only to H96 devices that were spoofing their device type as mobile phones. Image: Bitsight.
A DecryptAds legal dossier on the (now dormant) Fengwo Group domain name for the AI slop website pictured on the left in the screenshot above (medicalbeautyhub dot com) shows it shares a seller ID (1674071) with a gaming website — giacoloredstones[.]com — which features yet another seller ID (103488000).
Pivoting on that latter seller ID reveals hundreds of active websites within Russia’s Yandex ad system featuring extremely low-quality games or simple utilities that pepper visitors with ads.
QUIET REMOVALS
Edwards said that when advertising networks suspect a given advertiser is engaged in unauthentic clicks or displaying malicious ads, very often those networks will quietly remove the offender from their list of approved partners without letting anyone else know about their suspicions.
This practice, he said, makes it easier for dodgy adtech firms to avoid accountability and continue victimizing others. To address that visibility gap, DecryptAds features a quiet removals feed that records and correlates all of the sellers.json removals across ad exchanges for the same seller domain or name.
A screenshot of the Quiet Removals Feed at decryptads.com.
“The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public,” Edwards said. “The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once.”
MALVERTISING AND AI SLOP
Malvertising, the term given to the practice of inserting malicious ads that foist malware or redirect visitors to phishing pages, remains an all-too-frequent occurrence in the modern adtech industry. But Edwards said these malicious ads are far more commonly found now on newly generated AI slop websites than on high traffic destinations that typically employ a variety of technologies and third party tools to quickly flag bad ads.
“None of these slop AI content farms are paying for that kind of protection,” he said. “They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search.”
Edwards said the AI slop websites are populated with machine-generated blog posts and images, and cover a wide array of themes from home improvement and decorating to food recipes, hunting, cars and consumer technology. He said organizations that get hit with malicious ads are often at a loss for what to do next, unaware that in most cases the answer is one of the entities listed inside the website’s ads.txt or app-ads.txt file.
“A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis,” he said.
Edwards maintains that truly getting a handle on the malvertising and AI slop problems will require more data-sharing by the major ad networks. Specifically, he says those platforms do not broadly share what’s known as the “supply chain object” or SCO, structured data attached to each advertising bid request that lets buyers see every seller, reseller and intermediary involved in passing an ad impression from the publisher to the final buyer.
“That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload,” Edwards explained. “You may see the malicious zero-click redirection, but without the supply chain object — which is only served server side — you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad.”
DecryptAds also offers an application programming interface (API) that allows researchers to automate queries and integrate the site’s functionality into popular AI platforms.
WHAT CAN YOU DO?
The only sane reaction to the examples described above is to block all online ads outright. This approach is broadly endorsed by security experts because it also makes it more difficult for adtech firms and data brokers to build detailed profiles on you and track your movements around the web and in the real world.
However, much depends on how you normally prefer to browse the Internet, and how much trust you place in third party browser plugins and extensions. For those primarily surfing via a regular desktop or laptop Web browser, uBlock Origin Lite is an excellent free and well-maintained open source option. uBlock Origin also should work with mobile browsers like Firefox, but apparently only on Android-based devices.
Adblock Plus is a decent option for iPhone and iPad users. For power users, Adblock and uBlock Origin both support custom blocking rules from easylist.to, which publishes a frequently updated list that removes most advertisements from webpages.
The well established browser extension NoScript blocks all non-approved Javascript code, and it generally does a fine job blocking most ads from loading. However, script blockers like NoScript may not be suitable for average users who don’t enjoy constantly having to referee which scripts should be allowed to load so that each site displays properly.
More technically inclined/adventuresome readers should strongly consider a hardware approach to blocking ads at the local network level, because that is easily the cheapest, most secure and scalable way to do it. A tiny, low-cost and broadly available computer known as a Raspberry Pi can be turned into a powerful ad blocker for all devices on a local network when fitted with a microSD memory card and a free program called Pi-hole. Once you’ve set it up properly and changed your router’s network settings to use the Pi-hole’s DNS sinkhole and DHCP servers, it should prevent ads from displaying on any devices connected to that network.
Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to install on their devices. Many websites now push users to install a mobile app, supposedly in order to more fully access and enjoy the site’s services and content. But in my experience, they’re not doing this because the user experience is somehow way better on the app (as LinkedIn tries to convince us non-app users several times a week via email). On the contrary, I find most mobile apps to be horribly designed, annoying, and/or completely unnecessary, and when given the option I will almost always choose to interact with a website or service directly in a Web browser.
No, the cold truth is that big web destinations tend to get pushy with their apps because they make it easier for these companies to keep you on their platforms longer and to collect (and in many cases resell) far more precise data about who, what and where their users are. Also, companies pushing customers the hardest to install mobile apps always seem to liberally opt everyone in to having their data used to train large language models these days. So be cautious about the apps you install on your mobile devices (including any smart TVs!), and poke around their listings at DecryptAds if you want to learn more about their privacy practices and any relationships they may have to adtech firms.
Originally published by Krebs on Security. View the original article.
Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
Read here
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
Image: Shutterstock, Mallika Home Studio.
August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes. Microsoft has attributed the recent patch deluge to vulnerability discoveries aided by artificial intelligence, and experts roundly agree that Windows users should get used to the idea of Patch Tuesdays (the second Tuesday of each month) covering hundreds of newly discovered security flaws.
Fully 42 of the 398 flaws that Microsoft patched today earned Redmond’s most-dire “critical” rating, meaning they are severe enough that malware or malcontents could exploit them to gain remote control over a Windows computer with little to no help from the user.
The sole known “zero day” bug fixed by Microsoft this month is CVE-2026-68820, a privilege escalation weakness in a core Windows component called afd.sys, which the security firm Automox describes as “the driver behind Windows socket connections on effectively every endpoint.”
“This isn’t a front-door bug,” Automox’s Landon Miles wrote in a Patch Tuesday blog post. “It’s step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box. The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.”
CVE-2026-62832 is another privilege escalation flaw that Microsoft has labeled likely to be exploited; this flaw, in the Windows User Profile Service, may be related to the recent “LegacyHive” public disclosure from the prolific bug hunter known as Nightmare Eclipse. The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.
Other major software makers are likewise increasing their patch volumes and cadence thanks to AI, including Adobe which last month moved to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month. Cisco, Google, Mozilla and Oracle also are shipping updates far more frequently and abundantly.
By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse remains a heavily human-centric endeavor, and the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question when one considers that these same AI technologies also are suggesting fixes for the vulnerabilities they find.
Researchers at 1Password recently examined what happens when different large language models (LLMs) generate vulnerability patches for newly disclosed, complex vulnerabilities. They found the LLMs produced patches that failed to fix the flaw or added a new weakness in the process (or both) more than half the time.
Ed Skoudis, president of the SANS Technology Institute, said his team has seen excellent results using AI to generate patches, provided there are humans in the loop to test the suggested fixes and push for iterative improvements.
“AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,” Skoudis wrote in a SANS newsletter today. “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.”
Tyler Reguly at Fortra says while reports of Microsoft patching hundreds of vulnerabilities in one go have prompted some organizations to try to patch faster, it’s important to bear in mind that only one of the almost 400 bugs addressed today is known to be actively exploited. Reguly suggested security leaders check in with their teams to see how they’re handling the increasing workloads, which often involve testing fixes before deploying them in production environments.
“If you’re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we’re seeing and support them across various organizational units by enabling the changes they want to see made,” Reguly said. “There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.”
Speaking of the humans behind the keyboards, don’t neglect to backup your system and/or data before applying this month’s monster patch load. The day after each month’s Patch Tuesday is sometimes derisively referred to as Reboot Wednesday, but it generally doesn’t hurt to wait a few days to apply these huge update bundles because it sometimes takes a couple of days for the occasional misbehaving patch to get ironed out properly by Microsoft.
For a clickable, per-patch breakdown by severity and urgency, check out this roundup from the SANS Internet Storm Center.
Originally published by Krebs on Security. View the original article.
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflak…
Read here
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.
A surveillance photo of Connor Riley Moucka, a.k.a. “Judische” and “Waifu,” dated Oct 21, 2024, 9 days before Moucka’s arrest. This image was included in an affidavit filed by an investigator with the Royal Canadian Mounted Police (RCMP).
The U.S. Justice Department said between February and October 2024, Moucka and co-conspirators used stolen login credentials to steal cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company.
The hackers targeted stolen credentials for Snowflake customer accounts that did not enforce multi-factor authentication, and extorted or attempted to extort a host of well-known companies, including TicketMaster, Lending Tree, Advance Auto Parts and Neiman Marcus. Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.
Moucka adopted new nicknames frequently — sometimes operating multiple identities concurrently — but two of his best-known monikers were “Judische” and “Waifu.” Judische’s admitted role in the Snowflake data thefts was first documented by KrebsOnSecurity in a September 2024 story about the overlap between Western, English-speaking cybercriminals and extremist groups that harass and extort minors into harming themselves or others.
That September 2024 story identified Judische as a software engineer from Ontario who has been involved in numerous data breaches and voice phishing attacks against U.S. companies since at least 2020. A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.
The government says Moucka and others used their unauthorized access to steal billions of sensitive customer records and download terabytes of information, “including individuals’ non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers and other personally identifiable information. They then extorted victims by threatening to publish data online.”
Moucka also threatened and harassed government officials and security researchers who were helping to track him down. The Justice Department said the conspirators made over $2.5 million in ransom payments, and that in at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data.
“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.
One of Moucka’s admitted co-conspirators is Cameron “Kiberphant0m” Wagenius, a U.S. Army soldier who pleaded guilty in July 2025 to extorting AT&T and Verizon for their customer account data. Less than a month before Wagenius’s arrest, KrebsOnSecurity published a deep dive into Kiberphant0m’s various Telegram and Discord identities over the years, revealing how the owner of the accounts told others they were in the Army and stationed in South Korea.
One of several selfies on the Facebook page of Cameron Wagenius.
Kiberphant0m also re-extorted victims. Immediately following Moucka’s arrest, Kiberphant0m posted on hacker forums what he claimed were the AT&T call logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as well schematics allegedly stolen from the U.S. National Security Agency (NSA).
Wagenius is set to be sentenced on September 3, 2026. The government says he faces a maximum penalty of 20 years in prison for conspiracy to commit wire fraud, a maximum penalty of five years in prison for extortion in relation to computer fraud, and a mandatory two-year sentence consecutive to any other prison time for aggravated identity theft.
The third alleged co-conspirator is John Erin Binns, 26, an elusive American man who fled the United States after being indicted for his admitted role in a 2021 breach at T-Mobile that exposed the personal information of at least 76 million customers.
Sources close to the investigation said Binns, also known as “IRDev” and “IntelSecrets,” was until recently incarcerated in a Turkish prison, but that he has since been released and has resurfaced online. Those sources said Binns also recently obtained Turkish citizenship, and under Turkish law a citizen cannot be extradited to a foreign country.
An image of a passport that Binns shared in an email to KrebsOnSecurity in Feb. 2023.
Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is slated to be sentenced on Oct. 27 and faces a mandatory minimum penalty of two years in prison on the aggravated identity theft count, as well as a maximum penalty of 30 years in prison on the remaining counts. Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.
For an interview with Moucka prior to his arrest and a deeper look at Binns, see our original report on Moucka’s arrest.
Originally published by Krebs on Security. View the original article.
Siberian Rubythroat by Saniar Rahman Rahul
Taken at Baikka Beel, a wetland in the eastern part of Hail Haor, in December, 2015, this Siberian Rubythroat is a small passerine bird. It is a migratory insectivorous species breeding in mixed coniferous forests with undergrowth in Siberia. It winters in…
Read here
Taken at Baikka Beel, a wetland in the eastern part of Hail Haor, in December, 2015, this Siberian Rubythroat is a small passerine bird. It is a migratory insectivorous species breeding in mixed coniferous forests with undergrowth in Siberia. It winters in Bangladesh, Thailand, India and Indonesia.
Siberian Rubythroat, by Saniar Rahman Rahul
Award Winner: Photo of the Day | October 26
Award Score: 65 (Value 12, Clarity 11, Composition 18, Style 12, Skill 12)
Photo of the Day Award Category: Black & White Photography
Photograph Location: Baikka Beel, Srimongol, Moulvibazar, Sylhet | Bangladesh
Photographer: Saniar Rahman Rahul (Dhaka, Bangladesh) Registered
Saniar Rahman Rahul was the first winner for ‘Photo of the Month Award’ in June 2010. He was fascinated by seeing his father taking pictures with a camera while his family was in Iraq during his childhood. Later in life, in 1997, while he became very much attached with his profession of ‘graphic design’, Rahul rediscovered the creative side of photography. He started his career as a professional graphic designer in October of 1995, in a pre-press house called Color Scan, which is one of the pioneers in the pre-process printing media in Bangladesh. Afterwards, he moved to Power Point, another pre-press house. Before he finally settled into advertising, he also worked in an IT company called Abtab IT. Moving to advertising from printing media was a big step for him. In 2005, he joined G3, a special wing of Gray Worldwide. Two years later, he moved to Paper Rhyme. Now he is working as the Art Director of Grey World Wide, one of the ten largest advertising agencies in the world.
Portfolio: http://www.flickr.com/photos/srrahul/
Facebook: http://www.facebook.com/srahul
Originally published by Light and Composition - Wildlife. View the original article.
Every Sunset Is Different by Ryszard Wierzbicki
When sightseeing Siquijor Island in the Philippines, sunsets you experience every day are breathtaking. That is the moment of the day everybody tries to be in time somewhere by the beach to enjoy the sun is meeting the horizon. However, it happens regularly…
Read here
When sightseeing Siquijor Island in the Philippines, sunsets you experience every day are breathtaking. That is the moment of the day everybody tries to be in time somewhere by the beach to enjoy the sun is meeting the horizon. However, it happens regularly every day, every sunset is different. Colors and shades are unrepeatable. Therefore taking your camera to this Island is so essential and necessary.
Award Winner: Photo of the Day | May 24
Award Score: 66.5 (Value 12, Clarity 13, Composition 18, Style 11.5, Skill 12)
Photo of the Day Award Category: Sunrise & Sunset Photography
Photograph Location: Coral Cay Resort, Cangapa Village, Siquijor, Philippines
Photographer: Ryszard Wierzbicki (Swindon, United Kingdom) Registered
Ryszard Wierzbicki was born in 1963. Graduated with a Master degree of Social Sciences in Children Care Education from University of Gdańsk in 1992 in Poland. He worked in an orphanage and four other companies, going through positions of Educator, Marketing Specialist and Sales & Marketing Manager in various branches (child care, dentistry, orthodontics and IT). Apart of his regular jobs he continued developing his Scuba Diving qualification resulted of an instructor level in PADI. Emigrated to UK in 2006, from where he started his real traveling & photography experience and exploration of South-East Asia. Volunteering occasionally with Stu and the Kids charity organization of Thai and Burmese Orphans (stuandthekids.org). Established 2 forums for active travelers and photographers named Instant Travelling (instanttravelling.ning.com) and World Around (worldaround.pl) in 2010. Changed an ironed suit and laptop for cargo trousers, hoodie jacket, knapsack and started to manage freely the passion of photography, traveling and scuba diving.
Website: http://instanttravelling.ning.com
Facebook: https://www.facebook.com/ryszard.wierzbicki
Twitter: https://twitter.com/ryszard1963
Originally published by Light and Composition - Sun. View the original article.
Sunset in Batumi by Sergiy Kadulin
We did family travel to Georgia (Central Asia) in June 2012. Georgia is ancient country with number of interesting places to visit. We drove by car from the capital, Tbilisi, across the country, to the Black Sea coast, and stayed overnight in Batumi. On the…
Read here
We did family travel to Georgia (Central Asia) in June 2012. Georgia is ancient country with number of interesting places to visit. We drove by car from the capital, Tbilisi, across the country, to the Black Sea coast, and stayed overnight in Batumi. On the day of arrival we had dinner in the restaurant on the beach, and were lucky to catch beautiful sunset. Sun was approaching horizon in the clear sky, however just before it touched sea, quite large cloud appeared from nowhere, and made this great composition. I didn’t have tripod with me, but used table and a plate to stabilize camera.
Sunset in Batumi, by Sergiy Kadulin
Award Winner: Photo of the Day | April 09
Award Score: 66.5 (Value 13, Clarity 12, Composition 17, Style 12, Skill 12.5)
Photo of the Day Award Category: Sunrise & Sunset Photography
Photograph Location: Black Sea coast line in Batumi | Georgia
Photographer: Sergiy Kadulin (Kyiv, Ukraine) Registered
Born in Kyiv, Ukraine, in 1967, Sergiy Kadulin grew up in the family with his sister and mother, as his father died when they were two years old. He graduated from the military aviation academy (avionics engineer), and later on, from MBA school (IBR school, based in Ukraine). While majority of his professional career was with information technology, where he worked for such companies as American Power Conversion, hp, Microsoft, and now working with Apple as director of Apple VAD in Ukraine, but photography is his greatest passion and hobby.
Sergiy’s first experience was with his grandfather’s camera (made in 1936), and while he was studying in school he started mode in-depth learning of photography, including dark room processing, shooting on color films, etc. His first own camera (shared with his sister) was Smena-8M, which was very popular in Soviet Union as basic and very affordable camera for children. In upper class his mother gave him a gift – Zenit-12SD, which was his first real film DSLR and he enjoyed it for many years. Later on, while being on business trip in Canada, he bought Minolta with set of lenses, which was far more advanced one. Large part of his film photo collection was made with it. Sergiy was quite skeptical towards digital photography at the beginning, and switched completely to digital workflow by late 90’s until early 2000. About 7 years ago he graduated from the professional photography course in the Kyiv School of Photography, and later on, continued to study (distance learning course of professional photography) in New York Institute of Photography. He also attended number of training courses in different other schools and on top of it, learn new interesting areas online. He did his first photo exhibition in April, 2011, which was named “Sikkim. Beginning” and was devoted to his trekking in Himalaya, Sikkim, India, in 2010.
Sergiy’s favorite type of photography is travel and landscape; however he likes reportage as well. He does devote significant portion of his time to internal growth and development, which to his strong opinion, is the most important part of any creative human. He is trying to use photography as means to share his deep love to the world, to other people and nature, and pass warmth of his heart to them.
Website: http://www.serge-photo.com
Flickr: http://www.flickr.com/photos/skadulin/
Gallery: http://ngm.nationalgeographic.com/gallery/1414006/
Facebook: https://www.facebook.com/Sergiy.Kadulin
Twitter: https://twitter.com/skadulin
Originally published by Light and Composition - Sun. View the original article.
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreak…
Read here
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks.
Pedro Falé is a threat researcher with the security firm Bitsight. Falé told KrebsOnSecurity he was able to peer inside a vast and complex ad fraud network by registering an expired domain name that was used to coordinate fake ad clicks across a particularly popular brand of these streaming devices known as H96.
An H96 TV streaming device currently advertised for sale on Amazon.
Falé said the domain he scooped up was previously used for telemetry, periodically collecting full hardware information and the entire list of installed apps from tens of thousands of H96 streaming sticks plugged into television sets around the globe. But upon inspecting the traffic being funneled to the domain, he discovered nearly all of the TV boxes transmitting data claimed to be mobile phone models from a variety of manufacturers, including Samsung, Vivo, Huawei, and Xiaomi.
“We noticed something was wildly wrong,” Falé said. “Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.'”
Image: Bitsight.
The researcher found all of the devices reported having the same two apps installed, and that those apps were made by a company called Zhejiang Fengwo IoT Technology Ltd, an entity founded in 2019 in mainland China which operates an ad-publishing portfolio under the name Fengwo Group. Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.
“Bitsight TRACE identified several Hong Kong, Singapore, and single person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group,” Falé wrote in a report released today about their findings.
Falé said an analysis of the apps shows they help to coordinate an ad fraud network that uses these H96 devices as a captive traffic source to click on ads at AI-generated websites operated by the Fengwo Group.
Bitsight discovered the websites contain machine-generated news articles and graphics across a range of categories, including finance, health, education, gaming, music and food blogs. But they also found none of those sites displayed ads unless the device visiting the page matched the spoofed mobile profile of these H96 devices.
AI DIGITAL HUMANS
The domain for the Fengwo Group — fwgcloud[.]com — claims the company is “redefining the boundaries of human-AI interaction,” and that it has created more than 120,000 “AI digital humans” available to rent for everything from emotional companionship to 24/7 customer service and creative design.
The homepage for fwgcloud dot com.
Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly, which was originally designed to help kids learn how to write software.
According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work.
The Blockly homepage.
“An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type,” reads Bitsight’s report. “Once the routine is saved, it gets exported as JavaScript and uploaded to the S3 buckets. An operator doesn’t need as much understanding of the underlying technicalities, as it is all set in place for ease of use.”
Bitsight even found one of the Fengwo Group app developers mentioning exactly these advantages, noting the developer remarked that “only a small number of highly-skilled developers are needed to build the template execution-unit images,” and that “developers who create execution units from those templates have significantly lower technical requirements, greatly reducing the company’s operating costs.”
Falé said if a user’s H96 streaming stick is selected for a specific fraud task, it will be pushed the appropriate Blockly module according to the task desired, which can include silently launching a web browser, visiting websites, browsing pages, managing tabs, and clicking on ads.
To ensure the TV boxes masquerading as mobile phones can reliably click on ads displayed via the AI-generated websites, the Fengwo group “fuses three vision and reasoning systems into a single interface,” allowing the bots to correctly identify an ad on the webpage and navigate the site much like a human would, the Bitsight report observed.
Examples of ad landing pages linked to the Fengwo Group. Image: Bitsight.
TV ON? PROXY. TV OFF? AD FRAUD
Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded that when these TV boxes detect an HDMI signal from an attached television — indicating the user intends to stream video content — the box is usually functioning as a residential proxy. When the TV is off, it switches back to waiting for ad fraud jobs.
Falé said he believes the TV boxes are set up this way because its ad fraud activities are far more resource intensive and could interfere with the device’s stated purpose — streaming video content over the Internet.
Despite repeated warnings from the FBI and security industry leaders about the security and privacy risks of using these streaming devices, major e-commerce providers like Amazon, Best Buy, Newegg and others continue to sell hundreds of different models and brands that bundle unofficial versions of Google’s Android operating system and are frequently marketed (via online influencers) as a way to access a broad array of streaming services and live broadcasts without a subscription.
Image: fbi.gov.
In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed. This software rents the user’s Internet address out to anonymous paying customers, who run the gamut from aggressive content scraping firms to ticket scalpers and outright cybercriminals.
What’s more, because these generic (and generally dirt cheap) TV boxes are all horribly insecure by default and bereft of any kind of authentication, installing one on your home or office network only invites further mischief. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves.
SHOW ME THE MONEY
Bitsight said it tracked approximately 38,000 TV boxes globally phoning home to the expired Fengwo Group domain, and based on that number the report estimates this ad fraud network brings in revenues of close to $50,000 a day (not counting substantial revenue from the residential proxy side of the business). However, Falé emphasized that these estimates are highly conservative and based on telemetry from just one of the Fengwo Group’s core (but older) domains.
As for the Fengwo Group’s claim to have 120,000 “digital humans” at their disposal, Bitsight’s report concludes it could be just a clever marketing scheme and/or a way to avoid drawing suspicion to the company’s operations.
“Historically, when dealing with proxy services or DDoS, we sometimes see these websites undertake inconspicuous facades, so as not to advertise their DDoS capability or botnet size,” Falé wrote in the report. “This could also be the case here.”
If the Fengwo Group truly does have tens of thousands of “AI humans” at its beck and call, it does not appear to have dedicated any of them to fielding inquiries from its own website. KrebsOnSecurity sought comment from the Fengwo Group by emailing the contact address listed on the company’s homepage, but the request bounced back with the reply, “Your message couldn’t be delivered to postmaster@fwgcloud[.]com. Their inbox is full, or it’s getting too much mail right now.”
As Bitsight’s analysis shows, when it comes to TV boxes and streaming sticks, it’s best to stick to name brands from reputable manufacturers, and then to be sparing and careful with any apps you choose to install on the device — as many of those can bundle residential proxy software as well. Google says consumers can confirm whether or not a device is built with the official Android TV OS and Play Protect certification by following these instructions.
Additionally, Synthient maintains a running list of IoT devices that have been known to ship to consumers with residential proxy software and other malicious apps pre-installed. Careful readers will notice Synthient’s list includes other IoT devices apart from streaming sticks and boxes: As the FBI has warned, residential proxy software has also been found in other popular consumer IoT devices from random brands, particularly digital photo frames.
Originally published by Krebs on Security. View the original article.
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 p…
Read here
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.
Proxy SDK prevalence among smart TV apps for LG (webOS) and Samsung (Tizen OS) televisions. Image: Spur.us.
On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one’s television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components.
Responding to questions about Spur’s research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended.
“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said. “If this option is not removed, these apps will be suspended.”
Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company’s review of those apps is “well underway now.”
“As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs,” Taylor wrote in an emailed statement.
App makers looking for ways to monetize their creations can turn to residential proxy providers, which pay developers to include SDKs that turn the user’s device into a residential proxy node that is rented to paying customers. In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and file utilities.
A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. Image: Spur.us.
Spur’s report found the residential proxy network Bright Data accounted for a majority of proxy SDKs across both Samsung and LG smart TVs. In a statement shared with KrebsOnSecurity, Bright Data said its network is built on consent and responsibility and operates by LG and Samsung terms.
“Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC,” the statement reads. “We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain.”
Bright Data and other proxy providers named in Spur’s report all say they follow rigorous know-your-customer processes to validate legitimate uses of their services, which is often heavily tied to content-scraping activities by said customers. The proxy companies also say they incorporate technological countermeasures to prevent proxy service customers from being able to interact with and control other devices on the proxy user’s local network.
Spur argues the problem is not that residential proxy networks exist, but rather that they are being embedded at scale in devices that most consumers do not think of as computers and are not equipped to audit.
“A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Spur’s Trevor Sutter wrote. “The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”
LG’s announcement that it is culling residential proxy SDKs from its app store is welcome news, but the company recently came under fire for another questionable partnership: Pimping McAfee security products via software drivers included in its high-end LCD monitors.
Earlier this week, the Youtube channel Gamers Nexus showed that certain LG LCD monitors will automatically install an app that promotes paid McAfee antivirus subscriptions, and that the app arrives through Windows Update without an approval prompt.
Update, July 22, 1:06 p.m. ET: Added statement from Bright Data.
Originally published by Krebs on Security. View the original article.
A Pillar's Purpose
Why your organizational security pillars deserve a second look.
Read here
Pillars in a structure are crucial to the integrity of a building. They help bear immense weight, gracefully transferring it down to the foundation. Without them, buildings could crumble, causing the loss of valuables such as history, goods, commodities, and, more importantly, people. If you look around, pillars are everywhere, keeping important structures in place and supporting the weight of thousands of people.
In this photograph, taken during a walk through Central Park, you can see one set of four pillars on the façade of the Metropolitan Museum of Art. These pillars bear an important weight, supporting the roof and helping ensure that stress does not lead to millions of dollars in damage from a collapse. Although it may seem like a lot of responsibility for just a few columns, the structure is designed with other supporting elements to help distribute the load.
This is a great metaphor for the pillars we use in security. They represent various lines of defense that help ensure a company does not collapse because of one failing point. But what do these pillars represent in security?
Identity
One example is identity, which encompasses basic security measures used to verify who you are. The most basic and easiest way to verify identity is 2FA/MFA, also known as Multi-Factor Authentication. The purpose of MFA is to ensure that the person requesting access to an account is actually you. Anyone can guess a password, but can they guess a six-digit code sent to your phone that is visible for only 30 seconds? “[It] acts as an additional layer of security to prevent unauthorized users from accessing these accounts, even when the password has been stolen.” [1]
This is what many MFA services offer, including Microsoft Authenticator, Google Authenticator, AWS Identity, and even the authentication tool provided by your favorite app. I’ve personally used Microsoft Authenticator to access my college financial and transcript records. If you have data you want to protect, take the extra 30 seconds to secure your accounts and turn on MFA. You do not want to be the person responsible for losing your family’s pictures or the one who costs a company millions in downtime and recovery services.
Least Privilege Access
Another action we can take to strengthen identity security in a workplace environment is least-privilege access. By “minimizing the connections between users, systems, and processes to only those needed to perform their job” [2], “It limits what attackers can see and do if they find a way into your network.” [3] With proper least-privilege access implemented, threat actors may find themselves stranded in their attempt at lateral movement.
Networks
While we are on the topic of networks, securing your network is another metaphorical pillar. It represents the importance of monitoring, segmentation, firewalls, and more. Let’s start with firewalls. A firewall is your first line of defense, acting as a guard for your network against potential threats from the internet. By “monitor[ing] and control[ing] traffic using predefined rules… they block unauthorized access and threats.” [4] There are various forms of firewalls, including hardware, software, and cloud-based firewalls. I will not get into those details here, but feel free to learn more here.
Next, let’s talk about segmentation. If you are driving on a road with lane markers and a car breaks down, how many lanes are affected? Likely just one. Now, imagine you are driving on a road with no lane markers. What happens to traffic? Even worse, what happens when a car breaks down? All the cars around you are affected, potentially across many lanes.
Network segmentation is a solution that uses switches and VLANs to separate your network into smaller subnetworks. Keep the accounting team in one lane, the engineering teams in another, and HR in a third lane, and so on. The benefit of segmentation is that it helps ensure threat actors cannot jump across networks. If your financial records in accounting are compromised, your employee data in HR is not automatically compromised too.
Monitoring
Lastly, someone has to monitor your network to make sure there is no odd activity. Why would an employee be logging into a website with confidential information at 3 a.m. when their scheduled work hours are 9 a.m. to 5 p.m.? The best team to ask is your SOC (Security Operations Center) or NOC (Network Operations Center). If you do not have one because you are a small team, reaching out to an MSP to set up a budget-friendly monthly monitoring subscription could be a good idea.
Planning Ahead
There are many more security pillars to explore, such as device management, data encryption, and backups and recovery. But for now, let’s look at what can happen when an organization’s security lacks funding. “Thirty-one pieces of sculpture were originally designed for the façade, but a lack of funds left piles of uncarved stone atop the columns.” [5] This tells the story of how 117 years passed without a sculpture being created on top of The Met’s pillars. Although the stones have become an accepted part of the façade, people began to notice this flaw and question why they were incomplete.
If you continue to let your organization operate without completing its security pillars, threat actors will find flaws in your system, causing far more damage than the unsculpted stones on top of The Met.
Sources
- https://aws.amazon.com/what-is/mfa/
- https://www.cisecurity.org/insights/spotlight/ei-isac-cybersecurity-spotlight-principle-of-least-privilege
- https://hoop.dev/blog/how-to-prevent-lateral-movement-with-least-privilege-access
- https://www.paloaltonetworks.com/cyberpedia/what-does-a-firewall-do
- https://www.untappedcities.com/top-secrets-metropolitan-museum-of-art/
Originally published by Lens on Security. View the original article.
Forest CEO by José J. Rivera-Negrón
The trees went quiet last Saturday, like they were watching too. Gray sky, no breeze, coquís starting to sing. I was leaning on a tree with my Nikon, tired from the hike, when branches moved. A bird, maybe a calandria or zorzal, landed on the palm. Just a d…
Read here
The trees went quiet last Saturday, like they were watching too. Gray sky, no breeze, coquís starting to sing. I was leaning on a tree with my Nikon, tired from the hike, when branches moved. A bird, maybe a calandria or zorzal, landed on the palm. Just a dark silhouette staring down. It looked like it ran the forest. My hands shook, but I got the shot. Anyone know what kind of bird claims a palm like that?
Originally published by Light and Composition - Nature. View the original article.
What Made Him Look Up? by José J. Rivera-Negrón
Quebrada Camuy forest was humid and gray last week, the air thick like the trees were praying. My nephew stopped playing when loud chirping cut through the quiet. Maybe a San Pedrito or reinita hiding above. Kids find amazing every single detail in God’s cr…
Read here
Quebrada Camuy forest was humid and gray last week, the air thick like the trees were praying. My nephew stopped playing when loud chirping cut through the quiet. Maybe a San Pedrito or reinita hiding above. Kids find amazing every single detail in God’s creation. Sometimes we forget to look up. I took this to remind us that God speaks through a bird, the trees, or even the sky.
Originally published by Light and Composition - Nature. View the original article.
Thinking Alone by Nirupam Roy
I was not in the intention of capturing bird photography, then saw this bird, who seemed to be sitting there and thinking alone. I love this moment. Award Winner: Photo of the Day | June 17 Award Score: 62 (Value 11, Clarity 11, Composition 17, Style 12, Sk…
Read here
I was not in the intention of capturing bird photography, then saw this bird, who seemed to be sitting there and thinking alone. I love this moment.
Award Winner: Photo of the Day | June 17
Award Score: 62 (Value 11, Clarity 11, Composition 17, Style 12, Skill 11)
Photo of the Day Award Category: Wildlife Photography
Photograph Location: Dariabalai, Tufanganj, Cooch Behar, West Bengal | India
Photographer: Nirupam Roy (Tufanganj, Coochbehar, West Bengal, India) Registered
Nirupam Roy is from a small town Tufanganj, located in CoochBehar District in WestBengal, India. Being a school teacher, entering into this unique arena is really dramatic for him. Going to school he always thinks about the phenomena of the society, but could not understand how the common yet beautiful aspects can be modified represented. Though he has done some documentary video works in YouTube, but it did not satisfy him. Then in one summer he planned a family trip to Orrisa, India. There he realized the necessity of a camera to capture the scenic beauty of the place surrounded by several sea-coasts. At the same time he wanted to photograph his family, especially his son Arkapravo, and bought his first camera Canon SX 40 HS. After returning home, he has fallen in love with photography passionately, and bought the DSLR, NikonD5000. Now-a-days friends rebuked him by telling that camera becomes his only obsession. But Nirupam believes it becomes his passion because he always thinks how the new concept of photography can be produced. Photography completely changes his whole attitude towards nature and human being. It gives him a sort of peace to his weary mind, as if a blessings from Almighty.
Flickr: http://www.flickr.com/photos/rawfiles/
Facebook: https://www.facebook.com/nirupam.roy.777
Originally published by Light and Composition - Wildlife. View the original article.
Male White Tailed Stonchat by Saniar Rahman Rahul
Taken at Rajshahi, Bangladesh, the white-tailed stonechat is a species of bird in the family Muscicapidae, found mostly in Bangladesh, India, Myanmar, Nepal, and Pakistan. The male has black head, white collar and bright rufous chest patch. The back and win…
Read here
Taken at Rajshahi, Bangladesh, the white-tailed stonechat is a species of bird in the family Muscicapidae, found mostly in Bangladesh, India, Myanmar, Nepal, and Pakistan. The male has black head, white collar and bright rufous chest patch. The back and wings are dark, with white on wing coverts and rump. The key differentiating feature from male common stonechat is the white inner webs of outer tail feathers which is visible when the bird spreads the tail in flight or while landing.
Award Winner: Photo of the Day | March 11
Award Score: 67 (Value 12.5, Clarity 12.5, Composition 18, Style 12, Skill 12)
Photo of the Day Award Category: Wildlife Photography
Photograph Location: Rajshahi | Bangladesh
Photographer: Saniar Rahman Rahul (Dhaka, Bangladesh) Registered
Saniar Rahman Rahul was the first winner for ‘Photo of the Month Award’ in June 2010. He was fascinated by seeing his father taking pictures with a camera while his family was in Iraq during his childhood. Later in life, in 1997, while he became very much attached with his profession of ‘graphic design’, Rahul rediscovered the creative side of photography. He started his career as a professional graphic designer in October of 1995, in a pre-press house called Color Scan, which is one of the pioneers in the pre-process printing media in Bangladesh. Afterwards, he moved to Power Point, another pre-press house. Before he finally settled into advertising, he also worked in an IT company called Abtab IT. Moving to advertising from printing media was a big step for him. In 2005, he joined G3, a special wing of Gray Worldwide. Two years later, he moved to Paper Rhyme. Now he is working as the Art Director of Grey World Wide, one of the ten largest advertising agencies in the world.
Portfolio: http://www.flickr.com/photos/srrahul/
Facebook: http://www.facebook.com/srahul
Originally published by Light and Composition - Wildlife. View the original article.
Shutter vs. Flight by José J. Rivera-Negrón
I took this at Quebrada Camuy forest last week. It was cloudy and humid, like it might rain but didn’t. The trees were bare and quiet. Behind the photo, I was hiking when chirping started, then this bird flew off fast. It might have been a Puerto Rican tody…
Read here
I took this at Quebrada Camuy forest last week. It was cloudy and humid, like it might rain but didn’t. The trees were bare and quiet. Behind the photo, I was hiking when chirping started, then this bird flew off fast. It might have been a Puerto Rican tody, called San Pedrito, or a bananaquit, called reinita. I barely caught it.
Originally published by Light and Composition - Nature. View the original article.
The Architect of Camuy by José J. Rivera-Negrón
I spotted this pitirre mid-flight, twig in beak, building a nest. The gray kingbird’s wings glowed against the sky. It’s common here, but seeing its work up close made me stop. Nature’s quiet hustle, framed. One photo can’t capture the effort. But it remind…
Read here
I spotted this pitirre mid-flight, twig in beak, building a nest. The gray kingbird’s wings glowed against the sky. It’s common here, but seeing its work up close made me stop. Nature’s quiet hustle, framed. One photo can’t capture the effort. But it reminded me why I carry my camera everywhere.
Originally published by Light and Composition - Nature. View the original article.
Rainforest Romance by José J. Rivera-Negrón
I took this in an avocado tree in a forest near where I live in Puerto Rico. These are Puerto Rican bullfinches, known locally as “comeñame” in Spanish. The male is singing to the female, probably trying to impress her. It was just a small, real moment I ca…
Read here
I took this in an avocado tree in a forest near where I live in Puerto Rico. These are Puerto Rican bullfinches, known locally as “comeñame” in Spanish. The male is singing to the female, probably trying to impress her. It was just a small, real moment I caught while out doing my research of the wildlife.
Originally published by Light and Composition - Nature. View the original article.
Fall Tracks by Tisha Clinkenbeard
In north Texas we do get to see a bit of fall each year. It doesn’t last long – as no weather in Texas is consistent. Living in rural Texas we have a railroad that runs along the highway. Once the leaves start turning colors I try to get out and roam the co…
Read here
In north Texas we do get to see a bit of fall each year. It doesn’t last long – as no weather in Texas is consistent. Living in rural Texas we have a railroad that runs along the highway. Once the leaves start turning colors I try to get out and roam the countryside looking at all of the colors. I found the railroad tracks with a cloudy day and some beautiful fall colors.
Award Winner: Photo of the Day | January 14
Award Score: 55 (Value 10, Clarity 10, Composition 15, Style 10, Skill 10)
Photo of the Day Award Category: Nature Photography
Photograph Location: Powderly, Texas | The United States
Photographer: Tisha Clinkenbeard (Powderly, TX, USA) Registered
Tisha Clinkenbeard works have been in exhibits at The Fine Arts Center of Hot Springs, Black Box Gallery in Portland, and in several fine art shows in Texas. She believes photography captured her years ago before we had the digital wonders for cameras. Her life offers many opportunities to capture the things that she sees as she wanders this earth. Her goal is to share what she finds Round & About – which was the inspiration for her photo blog: foundroundandabout.com. Two of Tisha’s photos have been appeared in the Birds & Blooms monthly online newsletter – April and December of 2011.
Website: http://foundroundandabout.com
Gallery: http://fineartamerica.com/profiles/tisha-clinkenbeard.html
Facebook Page: https://www.facebook.com/pages/Found-Round-AboutTisha-Clinkenbeard-Photography/
Originally published by Light and Composition - Nature. View the original article.
The White-collared Blackbird by Saniar Rahman Rahul
Taken in Bhutan, the White-collared Blackbird is a species of bird in the family Turdidae, found in the Indian subcontinent, ranging across Bangladesh, Bhutan, India, Myanmar, Nepal and Pakistan. Its natural habitats are subtropical or tropical moist montan…
Read here
Taken in Bhutan, the White-collared Blackbird is a species of bird in the family Turdidae, found in the Indian subcontinent, ranging across Bangladesh, Bhutan, India, Myanmar, Nepal and Pakistan. Its natural habitats are subtropical or tropical moist montane forests and subtropical or tropical high-altitude shrubland.
Award Winner: Photo of the Day | March 01
Award Score: 64 (Value 12, Clarity 12.5, Composition 16.5, Style 11.5, Skill 11.5)
Photo of the Day Award Category: Wildlife Photography
Photograph Location: Bhutan
Photographer: Saniar Rahman Rahul (Dhaka, Bangladesh) Registered
Saniar Rahman Rahul was the first winner for ‘Photo of the Month Award’ in June 2010. He was fascinated by seeing his father taking pictures with a camera while his family was in Iraq during his childhood. Later in life, in 1997, while he became very much attached with his profession of ‘graphic design’, Rahul rediscovered the creative side of photography. He started his career as a professional graphic designer in October of 1995, in a pre-press house called Color Scan, which is one of the pioneers in the pre-process printing media in Bangladesh. Afterwards, he moved to Power Point, another pre-press house. Before he finally settled into advertising, he also worked in an IT company called Abtab IT. Moving to advertising from printing media was a big step for him. In 2005, he joined G3, a special wing of Gray Worldwide. Two years later, he moved to Paper Rhyme. Now he is working as the Art Director of Grey World Wide, one of the ten largest advertising agencies in the world.
Portfolio: http://www.flickr.com/photos/srrahul/
Facebook: http://www.facebook.com/srahul
Originally published by Light and Composition - Wildlife. View the original article.
Sunset in Paradise by Kristel Sturrus
After a hot day in Sint Maarten its time to go to the boardwalk in Philipsburg. From there you can see the sun setting behind Divi. Divi is a nice resort that has a beautiful beach and you can snorkle there nicely. But my favorite place is the beach by the…
Read here
After a hot day in Sint Maarten its time to go to the boardwalk in Philipsburg. From there you can see the sun setting behind Divi. Divi is a nice resort that has a beautiful beach and you can snorkle there nicely. But my favorite place is the beach by the boardwalk where the nice bars and restaurants are.
Award Reach | Reviews
| Reviews
0 / 50
SHARE SUBMISSION
Submit / Update Your Score
Award Winner
Photo of the Day
Award Date
[award_post_date]
AWARD SCORE
Value 12
Clarity 12
Composition 16
Style 12
Skill 12
Award Category | Location | Tags
In the Sundarbans in December 2023, I had a cool encounter with a Common Sandpiper. Just strolling around, doing its thing in the mud and water. The simplicity of this little bird against the vastness of the Sundarbans made for a chill December moment. No fancy feathers, just a Common Sandpiper adding its own flavor to the unique charm of this place
All my live I only showed interest when u was on holiday to other countries. I started creating a passion for photography while I emigrated to Malawi (Africa) but I didn’t have a good lense. When I emigrated to st maarten I got a new lense and created the pictures I’m showing you here. I would love to learn more about photography and turn my hobby and passion into hopeful a carreer.
Current Location
Philipsburg, st Maarten
Website
https://etejo.com/WGdUK1piWXB6ekdkK295V09KV2hXQT09/
Instagram
https://www.instagram.com/the.way.of.light.photography//
[av_comments_list av-desktop-hide=” av-medium-hide=” av-small-hide=” av-mini-hide=” av_uid=’av-6oj1pr2′]
Originally published by Light and Composition - Sun. View the original article.
The Power of Supplication by Gabriele Girardi
This image is part of a project, willing to focus on the human being, expressing my empathy toward him.The project intends to tell the everyday stories of muslim and hebrew multi-millennial old religions, settled within the deeply catholic environment of th…
Read here
This image is part of a project, willing to focus on the human being, expressing my empathy toward him.The project intends to tell the everyday stories of muslim and hebrew multi-millennial old religions, settled within the deeply catholic environment of the city of Rome.This particular shot, had been taken inside the Rome’s Grand Mosque, during the Friday’s holy prayers, thanks to Mr. Gabriele tecchiato, “Centro Islamico Culturale d’Italia” library’s director.
Award Winner
Photo of the Day
Award Date
[award_post_date]
AWARD SCORE
Value 12
Clarity 12
Composition 18
Style 13
Skill 13
Award Category
Islamic Photography
Photograph Location
Rome, Italy
Gabriele Girardi Registered Photographer
It all began in 1992, when, as a Salesian volunteer in Madagascar, to make a short documentary, Gabriele Girardi had his first approach with a video-camera. In that moment his passion for image video and framing composition started. He then attended specific courses on cameraman and video editing and started working with a Regional broadcast TV stations. There he covered many different roles within the production area. This is only the beginning. In 1999 he realised various programmes post produced for RAI, and with the same team realised a series of live programmes on RAI UNO.The camera- operator role was his first love however after having studied the structure of the imaging composition, he learned and developed a passion for photography and realised various photographic exhibits. His work and his personal experiences lead him to the editing area, currently performed together with compositing and 2D computer graphic. Within his professional experiences acted as TV direction, editing of documentaries, art stage managing for TV programmes, technical operator ,scheduler , sound engineer for radio broadcasting stations. At present he is the Technical Manager for Lazio Style Channel, satellite pay tv of famous Italian Serie A soccer team S.S. Lazio. His passion for photography lead him, currently, on a photography project about religions, how Jews and Muslims live their own religion in Rome, the capital city of Catholics. Since 2000 he has been using Apple operating system with the following software: Adobe Photoshop, Adobe after effects, Final cut X, Avid Media composer, several converting/encoding software and hardware, everything is needed to make a live production. Worked for TV series broadcasted by RAIUNO (national Italian television) as cameraman and video editor in the past 20 years. Competent and interested to work for documentaries as video editor or in anything where creativity is needed. Highly skilled to focus the aim of a project. Highly motivated and enthusiastic in production and post production.
Current Location
Rome, Italy
Instagram:
https://www.instagram.com/gabriele_girardi_photo/
[av_comments_list av-desktop-hide=” av-medium-hide=” av-small-hide=” av-mini-hide=” av_uid=’av-6jr5gqq’]
Originally published by Light and Composition - Islam. View the original article.
Long Tail Tit Showing Its Colors and Feathers by Rob van der Waal
In a small forest close to my hometown these colorful birds are rare visitors. On a cold winter day I decided to give it a change. Using the advantage of trees without leaves it was more easy to spot these very quick birds. Once I was able to locate these b…
Read here
In a small forest close to my hometown these colorful birds are rare visitors. On a cold winter day I decided to give it a change. Using the advantage of trees without leaves it was more easy to spot these very quick birds. Once I was able to locate these birds the next challenge was to create an image in an attractive setting. The result is shown in the image.
Award Winner: Photo of the Day | April 30
Award Score: 69 (Value 13, Clarity 12, Composition 18.5, Style 13, Skill 12.5)
Photo of the Day Award Category: Wildlife Photography
Photograph Location: Hellevoetsluis, Netherlands
Photographer: Rob van der Waal (Hellevoetsluis, The Netherlands.) Registered
Rob van der Waal was born in 1957 in Rotterdam, The Netherlands. His father was a passionate photographer who taught him the basics of photography. When he was 7 years old, his family already had a darkroom on the top floor of their family house. His dad was on the edge of what was possible those days, using 2 Leica M3 bodies, and was developing black/white and color films by himself and with some modifications to his equipment, created images of 40x60cm. Apart from his father’s touch and some workshops, Rob van der Waal is an autodidact. With reading, listening and most of all just doing, he developed his creative and photography skills. To briefly summarize his style in photography; pure and honest are the key words that come close. He loves to be out in nature and enjoys the space, light and birds, and on those frequent trips his camera is his companion. He believes, some interest build into his DNA is “maritime”. It’s his preference to be at the waterfront, the sea, and close to ships and its related activity. He feels fortunate to live close to Rotterdam, a harbor area in the Netherlands. He will always respect nature and animals. He hopes more people will support this principle. What triggers him in photography is that, it is never done, complete or finish, as there is always a way to playing with the light and the moment, which gives the opportunity in another way to tell the story!
Portfolio: http://www.robvanderwaal-fotografie.nl
Flickr: http://www.flickr.com/photos/rvdwaal_foto/
Twitter: https://twitter.com/waalrob
Originally published by Light and Composition - Wildlife. View the original article.
Besra’s Timeless Perch by Saniar Rahman Rahul
Perched gracefully on an old wooden log in the heart of the Sundarbans in December 2023, the Besra charmed my lens in a moment of serene beauty. The dappled sunlight filtering through the mangrove leaves played on its sleek feathers as it sat with regal poi…
Read here
Perched gracefully on an old wooden log in the heart of the Sundarbans in December 2023, the Besra charmed my lens in a moment of serene beauty. The dappled sunlight filtering through the mangrove leaves played on its sleek feathers as it sat with regal poise, the Besra, a guardian of Sundarbans, became the living embodiment of the untold stories.
Award Reach | Reviews
| Reviews
0 / 50
SHARE SUBMISSION
Submit / Update Your Score
Award Winner
Photo of the Day
Award Date
[award_post_date]
AWARD SCORE
Value 12.5
Clarity 12.5
Composition 18
Style 13
Skill 13
Award Category | Location | Tags
In the Sundarbans in December 2023, I had a cool encounter with a Common Sandpiper. Just strolling around, doing its thing in the mud and water. The simplicity of this little bird against the vastness of the Sundarbans made for a chill December moment. No fancy feathers, just a Common Sandpiper adding its own flavor to the unique charm of this place
Saniar Rahman Rahul was the first winner for ‘Photo of the Month Award’ in June 2010. He was fascinated by seeing his father taking pictures with a camera while his family was in Iraq during his childhood. Later in life, in 1997, while he became very much attached with his profession of ‘graphic design’, Rahul rediscovered the creative side of photography. He started his career as a professional graphic designer in October of 1995, in a pre-press house called Color Scan, which is one of the pioneers in the pre-process printing media in Bangladesh. Afterwards, he moved to Power Point, another pre-press house. Before he finally settled into advertising, he also worked in an IT company called Abtab IT. Moving to advertising from printing media was a big step for him. In 2005, he joined G3, a special wing of Gray Worldwide. Two years later, he moved to Paper Rhyme. Now he is working as the Art Director of Grey World Wide, one of the ten largest advertising agencies in the world.
Current Location
Dhaka, Bangladesh
Portfolio
http://www.flickr.com/photos/srrahul/
Facebook
http://www.facebook.com/srahul
[av_comments_list av-desktop-hide=” av-medium-hide=” av-small-hide=” av-mini-hide=” av_uid=’av-6oj1pr2′]
Originally published by Light and Composition - Wildlife. View the original article.
Sunset at Koh Chang Island by Ryszard Wierzbicki
When being at Koh Chang Island, you experience unforgettable sunsets. This is one of these moments. Ko Chang is one of the largest Thai islands in the Gulf of Thailand that contains dense, steep jungle. It also has Mu Ko Chang National Park, a preserve with…
Read here
When being at Koh Chang Island, you experience unforgettable sunsets. This is one of these moments. Ko Chang is one of the largest Thai islands in the Gulf of Thailand that contains dense, steep jungle. It also has Mu Ko Chang National Park, a preserve with hiking trails and waterfalls such as tiered Klong Plu, covers the interior and extends to offshore coral reefs.
Award Winner: Photo of the Day | April 11
Award Score: 61 (Value 11, Clarity 11, Composition 17, Style 11, Skill 11)
Photo of the Day Award Category: Sunrise & Sunset Photography
Photograph Location: Ko Chang, Gulf of Thailand, Trat Province, Thailand
Photographer: Ryszard Wierzbicki (Swindon, United Kingdom) Registered
Ryszard Wierzbicki was born in 1963. Graduated with a Master degree of Social Sciences in Children Care Education from University of Gdańsk in 1992 in Poland. He worked in an orphanage and four other companies, going through positions of Educator, Marketing Specialist and Sales & Marketing Manager in various branches (child care, dentistry, orthodontics and IT). Apart of his regular jobs he continued developing his Scuba Diving qualification resulted of an instructor level in PADI. Emigrated to UK in 2006, from where he started his real traveling & photography experience and exploration of South-East Asia. Volunteering occasionally with Stu and the Kids charity organization of Thai and Burmese Orphans (stuandthekids.org). Established 2 forums for active travelers and photographers named Instant Travelling (instanttravelling.ning.com) and World Around (worldaround.pl) in 2010. Changed an ironed suit and laptop for cargo trousers, hoodie jacket, knapsack and started to manage freely the passion of photography, traveling and scuba diving.
Website: http://instanttravelling.ning.com
Facebook: https://www.facebook.com/ryszard.wierzbicki
Twitter: https://twitter.com/ryszard1963
Originally published by Light and Composition - Sun. View the original article.
A Sky Of Limbs by Jack Hoye
This photo was taken using Apple iPhone during the autumn of 2017 and features a view of the limbs of a tree from below. I was very intrigued by how the natural light and the leaves from the tree visually interacted with one another and felt compelled to ca…
Read here
This photo was taken using Apple iPhone during the autumn of 2017 and features a view of the limbs of a tree from below. I was very intrigued by how the natural light and the leaves from the tree visually interacted with one another and felt compelled to capture the moment.
Award Reach | Reviews
| Reviews
0 / 50
SHARE SUBMISSION
Submit / Update Your Score
Award Winner
Photo of the Day
Award Date
[award_post_date]
AWARD SCORE
Value 12
Clarity 12
Composition 17
Style 12
Skill 12
Award Category | Location | Tags
In the Sundarbans in December 2023, I had a cool encounter with a Common Sandpiper. Just strolling around, doing its thing in the mud and water. The simplicity of this little bird against the vastness of the Sundarbans made for a chill December moment. No fancy feathers, just a Common Sandpiper adding its own flavor to the unique charm of this place
Jack Hoye is a passionate digital artist and graduate from The Westphal College of Media Arts & Design at Drexel University. Jack has been published by numerous literary arts and fashion magazines for his visual works; featured on previous covers of D&M Magazine published by Drexel University, Dreams Magazine published by ethical fashion brand Delirium Dreaming, and independent publisher, Figgi Magazine. More notable published features include Art Market International Magazine where he received his first full feature spread, and by Architectural Digest where his work was advertised by New York City based, Artifact Gallery. Jack has also been recognized by various arts enterprises and creative spaces; not only in his native United States, though across Europe, and most notably in Tokyo, Japan where he was featured at The Tokyo Tower Art Fair by online arts forum, Contemporary Art Collectors. Currently, Jack continues to create digital media in upstate New York, managing himself as an artist and entrepreneur.
Current Location
Cortlandt Manor, New York USA
Instagram
https://www.instagram.com/jack.hoye/?hl=en/
Website
https://xen-jack-hoye.squarespace.com/
LinkedIn
https://www.linkedin.com/in/jack-hoye/
[av_comments_list av-desktop-hide=” av-medium-hide=” av-small-hide=” av-mini-hide=” av_uid=’av-6oj1pr2′]
Originally published by Light and Composition - Nature. View the original article.
Grey-headed Lapwing by Saniar Rahman Rahul
Taken somewhere between Sunamganj and Tangua, in north-eastern Bangladesh within the Sylhet Division, this grey-headed lapwing is a lapwing species which breeds in northeast China and Japan. The mainland population winters in northern Southeast Asia from no…
Read here
Taken somewhere between Sunamganj and Tangua, in north-eastern Bangladesh within the Sylhet Division, this grey-headed lapwing is a lapwing species which breeds in northeast China and Japan. The mainland population winters in northern Southeast Asia from northeastern India, Bangladesh, Sri Lanka to Cambodia. The Japanese population winters, at least partially, in southern Honshū. This species has occurred as a vagrant in Russia, the Philippines, Indonesia New South Wales, and Australia.
Award Winner: Photo of the Day | April 07
Award Score: 64 (Value 12, Clarity 11, Composition 17, Style 12, Skill 12)
Photo of the Day Award Category: Wildlife Photography
Photograph Location: Sunamganj, Sylhet | Bangladesh
Photographer: Saniar Rahman Rahul (Dhaka, Bangladesh) Registered
Saniar Rahman Rahul was the first winner for ‘Photo of the Month Award’ in June 2010. He was fascinated by seeing his father taking pictures with a camera while his family was in Iraq during his childhood. Later in life, in 1997, while he became very much attached with his profession of ‘graphic design’, Rahul rediscovered the creative side of photography. He started his career as a professional graphic designer in October of 1995, in a pre-press house called Color Scan, which is one of the pioneers in the pre-process printing media in Bangladesh. Afterwards, he moved to Power Point, another pre-press house. Before he finally settled into advertising, he also worked in an IT company called Abtab IT. Moving to advertising from printing media was a big step for him. In 2005, he joined G3, a special wing of Gray Worldwide. Two years later, he moved to Paper Rhyme. Now he is working as the Art Director of Grey World Wide, one of the ten largest advertising agencies in the world.
Portfolio: http://www.flickr.com/photos/srrahul/
Facebook: http://www.facebook.com/srahul
Originally published by Light and Composition - Wildlife. View the original article.
No articles match this category.
Subscriptions
- Krebs on Security Cybersecurity
- Lens on Security Cybersecurity
- The Hackers News Cybersecurity
- Bleeping Computer Cybersecurity
- CISA Cybersecurity
- Light and Composition - Islam Photography
- Light and Composition - Nature Photography
- Light and Composition - Wildlife Photography
- Light and Composition - Sun Photography
- Light and Composition - Architecture Photography
- Photography Life Photography