Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Cyber Security. Show all posts

Atlassian CVE-2026-21589 Exploited Hours After Public Disclosure

 

Attackers started scanning the systems vulnerable to the Atlassian flaw several hours after the researchers published the technical details and proof-of-concept code. Assigned the identifier CVE-2026-21589, the vulnerability impacts several self-hosted Data Center products and could allow unauthorized access to the credentials in some circumstances. 

The problem was disclosed by Atlassian on October 5, 2026, with a CVSS score of 9.3. The products affected by the bug are Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. The company already released fixes for all software versions. The flaw allows the adversaries to access some files in the application root directory without providing proper authentication. 

However, it is only possible if the attacker knows the exact name and location of the file because the vulnerability does not allow listing the contents of a directory. Therefore, the attack surface is limited, but there is still a potential risk if the adversary somehow manages to guess the file location. The security researchers from WatchTowr posted the proof-of-concept code and technical details of the discovered flaw on October 6, 2026. 

They managed to identify the origin of the issue – a popular library used in all Atlassian products mentioned above. More importantly, they found out that the vulnerability could be chained to get access to the configuration file with Crowd application credentials in some circumstances. According to WatchTowr, Crowd is Atlassian’s identity management system, and the mentioned scenario involves Jira Software connected to it. 

In this case, the attacker could use the credentials to create a new administrative account and assign it to the Jira administration group. As a result, the adversary would be able to attain full privileged access to the targeted Jira Software instance. In addition, the security company showed how the proof-of-concept code could be used to take over a victim’s account in case of success. Moreover, the researcher added that the attacks are not random, but rather targeted. 

Several hours after the publication of the results, the exploitation framework started scanning corporate websites to find the instances of the affected applications. On October 8, 2026, Previdian, the exploitation intelligence company, counted 190 attempts from 32 IP addresses in 10 countries. Although the United States Cybersecurity and Infrastructure Agency (CISA) has not included the vulnerability in the Known Exploited Vulnerabilities list, the attacks indicate that the problem needs urgent attention. 

The companies using Atlassian’s products should make sure that the affected applications are updated to the latest versions. Those who are not able to do it right away should take the vulnerable instances of the software offline or follow the recommendations stated by Atlassian. In particular, the company suggests deploying the blocking rules to the firewalls or using the Web Server rewrite rules. 

In addition, the organizations with Jira Software and Crowd should make sure that the mentioned applications are not at risk of compromise as well. As seen from the recent incident, the response to the exposure of the flaw may take too long. Moreover, the attacks are often launched right after the proof-of-concept code is published. Therefore, it is critical to apply the necessary security updates as soon as possible.

Japan Reports Sharp Rise in Web Data Leaks

 

Japan is experiencing a sharp rise in personal-data leaks from web systems, according to an October 2026 alert from the JPCERT Coordination Center. The incidents, which surged around September, are separate from ransomware and other routine breaches, and JPCERT/CC says they may be increasing. While the agency did not identify attackers or affected organizations, it described the available evidence as limited and fragmentary, and cautioned that the same technique was not necessarily used in every case. The pattern points to attackers systematically probing web applications and APIs for basic security weaknesses rather than relying on one universal exploit.

The scale is substantial. Security firm Macnica counted 119 publicly disclosed incidents in Japan through October 6 in which personal data was stolen or leaked through organizations’ web systems—up from 84 in all of 2025 and 62 in 2024. Eighty-one of this year’s cases occurred in July or later. Targets have ranged from online shops and member services to business systems and customer-support platforms, including a library catalog and a tourist train booking system. High-profile examples include Park24’s Times Car service, where data on about 6.6 million accounts was obtained, and Yakiniku King’s app, where more than 10.7 million records reportedly leaked. 

JPCERT/CC identified three main intrusion patterns. First, attackers analyze publicly released mobile apps to discover API endpoints and keys, then send unauthorized requests—sometimes to internal APIs that should not be reachable through the app. These requests have been used to alter user privileges, create unauthorized accounts, test authentication behavior, and extract data through blind NoSQL injection. Attackers have also used API keys stolen in earlier compromises. In other cases, they exploit weak administrator passwords, known software vulnerabilities, excessive data exposure, broken access controls, and session-management flaws. 

A particularly serious vector involves Metabase, an open-source business-intelligence tool. Attackers exploited CVE-2026-72898, a maximum-severity SQL injection flaw that requires no account to abuse and can grant administrator access to Metabase’s application database. From there, an intruder could steal credentials for connected databases and export their contents. Metabase patched the issue on August 6, but attacks continued afterward; the company has urged users to move to newer minimum-safe releases and, where upgrading is not immediately possible, to block the affected password-reset endpoint. 

For defenders, JPCERT/CC recommends applying access controls to every API endpoint, including internal ones; enforcing least-privilege permissions; rate-limiting sensitive functions such as login, password reset, and search; and ensuring tokens expire and can be revoked quickly. Organizations should also avoid embedding API keys or database credentials in shipped apps, review admin functions in vulnerability testing, restrict regional access where appropriate, and remove data no longer needed. Japan’s Personal Information Protection Commission issued a parallel alert, urging businesses to reassess whether the personal data they hold remains necessary. The message is clear: basic API hygiene, configuration review, and prompt patching remain decisive defenses.

Rubrik Expands Project Hourglass to Bring AI-Powered Code Security to Enterprise

 



When Rubrik launched Project Hourglass at its FORWARD 2026 conference in Las Vegas back in June, the initiative set out to answer a question CISOs were already losing sleep over: what happens when an AI agent writing and deploying your code does something catastrophic and nobody can stop it in time?

On Thursday, at its GSI Summit in Goa, India, the cybersecurity firm announced the next step. Rubrik has expanded Project Hourglass to include a new tool called Rubrik Code Guardian, and has welcomed AHEAD, Trace3, and World Wide Technology (WWT) into the alliance, joining the six systems integrators that signed on at launch. The new capability is powered by Anthropic's Claude Mythos 5 and extends the alliance's reach from securing AI agents during execution to proactively identifying vulnerabilities in software code before deployment.


The Problem Driving All of This

Rubrik Zero Labs surveyed more than 1,600 IT and security leaders for its State of the Agent report and found that 86 percent expect AI agents to outpace their security guardrails within a year, while only 23 percent report full visibility into agents operating in their environments. More than 80 percent said agents require more manual oversight than the efficiency they save.

A separate Rubrik and Economist Enterprise study found 88 percent of enterprises experienced an AI agent security breach in 2026. The picture those numbers paint is one of organizations racing to deploy autonomous systems while the controls meant to govern them are still catching up.


What Code Guardian Does

The original Project Hourglass, which launched with Cognizant, Deloitte, LTM, HCLTech, NTT DATA, and Wipro as founding partners, focused on protecting AI agents at runtime through Rubrik Agent Cloud. That platform operates across three layers: Runtime Agent Security for behavioral guardrails and blast-radius control, Agent Rewind for fast repository recovery, and AI Context Guard for prompt integrity and control-plane protection.

Code Guardian shifts the security lens earlier in the development cycle. Rather than running against live production environments, the system tests a cloned, air-gapped copy of customer repositories. Claude Mythos 5 operates inside Rubrik's security harness to evaluate code against sophisticated, multi-step threat scenarios.

Three core capabilities define the product: isolated red-team analysis inside the air-gapped environment; attack chain discovery that reasons across files, services, identity roles, and cloud perimeters to find chained vulnerabilities that conventional static tools miss; and business impact prioritization that filters findings by actual exploitability and business criticality to reduce alert fatigue.

Alok Agrawal, Chief Solutions Officer at Rubrik, put the challenge plainly. "Engineering teams are turning to AI models to accelerate software delivery, but speed cannot compromise security or architectural integrity. By incorporating Rubrik Code Guardian into Project Hourglass, we are ensuring engineering teams are able to conduct red-team analysis, prioritize business impact and reduce risk."


The New Partners

Each of the three incoming partners brings a different angle to the coalition.

AHEAD, which builds enterprise technology architectures for large clients, framed the problem as one of inherited risk. Steven Sorensen, Specialty Solutions Engineer for Cyber Resiliency at AHEAD, said the goal is to get code attacked, tested, and validated in a safe environment before it ships, so teams can move faster knowing Rubrik's recovery capabilities sit underneath them as a safety net.

WWT's Chris Konrad, Vice President of Global Cyber, pointed to the company's Advanced Technology Center, where isolated threat testing has long been part of how it validates security solutions before recommending them. He said Code Guardian integrates naturally with that process.

Trace3 brought a perspective the others did not: its own teams have been running Rubrik Agent Cloud internally to protect their own agentic AI work before recommending it to clients. Sandy Salty, Chief Marketing Officer at Trace3, said that experience as both a user and a partner gives the firm a clearer view of what actually makes agentic environments more resilient at scale.


Where Things Stand

Rubrik Code Guardian is currently in private preview and accepting select design partners. It is not yet generally available and may change or be discontinued. Rubrik Agent Cloud, the original platform at the center of Project Hourglass, remains available to enterprise clients.

Dev Rishi, GM of AI at Rubrik, has previously described the core problem in stark terms: with AI agents, there is the potential for ten times the damage in one-tenth the time. That framing captures why the urgency behind Project Hourglass is unlikely to ease. As the volume of AI-generated code increases across enterprise environments, the window between a vulnerability being introduced and it being found by someone with bad intentions keeps getting smaller.



Microsoft Exchange Vulnerability Could Leak Confidential Organizational Info


Microsoft has issued an emergency security update to fix a vulnerability in Exchange Server that could expose confidential organizational communications. The flaw, tracked as CVE-2026-96940, has received a CVSS severity score of 8.8 out of 10.

Reported by TechRadar, the vulnerability could allow attackers who already have valid login credentials to increase their privileges within Exchange and access mailboxes belonging to other users. Microsoft released the fix on October 2, ahead of its originally intended schedule.

About the flaw

The security issue stems from a weakness in authorization controls, which determine what information a user can access. By exploiting the flaw over a network, an authenticated attacker could gain permissions beyond those assigned to their account.

Threat actors could first obtain credentials through phishing attacks or by purchasing stolen login details from underground online markets. Once inside an organization’s Exchange environment, they could exploit the vulnerability to read emails and attachments belonging to other employees.

However, the flaw does not provide unrestricted access across different customer environments, known as tenants. It also does not directly grant administrator-level or SYSTEM-level privileges on the underlying Windows server.

What happens in case of successful exploitation?

Successful exploitation could expose sensitive business information, including financial records, invoices, contracts, customer correspondence, internal discussions, and confidential documents.

Attackers could use the stolen information to support further cyberattacks. For example, they might impersonate company employees, send convincing fraudulent emails, or conduct business email compromise (BEC) scams to trick organizations into transferring money or disclosing additional information.

The vulnerability is particularly problematic because an ordinary employee’s compromised account could potentially provide an entry point for accessing information held in other employees’ mailboxes.

Affected products

The vulnerability affects the following on-premises products:

  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Updates 14 and 15

Microsoft has confirmed that Exchange Online customers are protected by a server-side fix. Organizations running affected on-premises installations should install the appropriate security updates promptly.

Exchange Server 2016 and 2019 have reached the end of their standard support lifecycle. Eligible organizations must be enrolled in Microsoft’s Extended Security Update programme to receive the relevant updates for these versions. Microsoft recommends that organizations without the required coverage migrate to Exchange Server Subscription Edition.

Microsoft’s response 

Microsoft reported no evidence that the vulnerability was being actively exploited at the time of the report. However, the company assessed that exploitation was more likely, making timely patching important.

Administrators should run Microsoft’s Exchange Server Health Checker after installing the update to verify successful deployment and identify any additional actions required.

Chrome Blocks Unauthorized Certificates After Three ccTLD Hijacks

 

Chrome has taken steps to protect users after attackers compromised three country-code top-level domains and exploited the incidents to acquire unauthorized HTTPS certificates for multiple organizations. The affected namespaces are .gh for Ghana, .sl for Sierra Leone and .as for American Samoa. Attackers targeted the third-party registries which own the ccTLDs rather than Google directly. 

In addition to the country-code top-level domain takeovers, the adversaries also modified the authoritative DNS records to compromise several Google domains and domains of other companies. Chrome reported that it is not evident that Certification Authorities (CAs) that issued the certificates acted in bad faith but instead concluded that the problem stemmed from attackers’ tampering with DNS infrastructure of the country-code domains. 

Chrome’s Secure Web and Networking Team responded to the incidents by utilizing CRLSets to block the unauthorized certificates associated with Google properties and coordinated with the CAs to revoke the certificates, protecting the users of the browsers and other clients. The list of impacted entities grew as Chrome analyzed Certificate Transparency (CT) logs and identified a number of large publicly traded companies and popular internet services. 

The team blocked certificates it suspected to be related to the attacks and reached out to the impacted businesses. Users of Chrome do not need to take any action as the protections are designed to be transparent and work in the background. However, Google warned that organizations should not rely on the browser to protect them against the attacks and that Chrome did not identify all the affected domains. Similarly, protections worked on Google Chrome and may have not triggered in other browsers and clients. 

Organizations are advised to ensure that they monitor the CT logs for all the domains and that they are notified if an unauthorized certificate is issued. This is critical because every certificate that is trusted by the public must be reported to CT logs. For domains that are impacted by the ongoing attacks, it is recommended to look over the most recent certificates to ensure that they have not been issued without authorization. Google recommended the use of restricted Certification Authority Authorization (CAA) records and the use of ACME account bindings when available. 

CAA records dictate which CAs can issue certificates and, while they do not prevent an attacker from using a hijacked domain to issue a certificate, they can help in ensuring that unknown CAs are not utilized. Additionally, the CAA records can prevent attackers from using domain-control validation for certificate issuance through misdirection. Using issuing restrictions and validation method restrictions can prevent attackers from using certificates’ domain validation through cached entries. These protections are only effective after the control of the domain is re-established. 

Chrome announced its intent to keep working on long-term projects to improve security and reduce the risks associated with the use of certificates. The proposed changes include shortening the lifespan of certificates and limiting the re-use of domain validation. They will continue to work to improve the Chrome Root Program with the Chrome Quantum-resistant Root Program as the Chrome ecosystem seeks to mitigate the risks posed by DNS and routing compromises.

Belarusian Hackers Compromised Russian Healthcare Network for Two Years


A Belarusian hacktivist gang allegedly maintained access to the network of a Russian healthcare organization for almost two years, potentially gaining access to sensitive medical information, cybersecurity researchers have reported.

Researchers from Russian cybersecurity company Solar said they discovered the intrusion in December 2025. However, their investigation found evidence suggesting that the attackers had entered parts of the organization’s infrastructure as early as 2024.

Attack details

The attack was attributed to the Belarusian Cyber Partisans, a group known for cyber operations against Belarusian and Russian government organizations and businesses.

Despite remaining inside the network for an extended period, the attackers did not appear to destroy systems or cause major disruption. Researchers believe maintaining access may have been more valuable to the attackers than immediately carrying out destructive activity. 

Intrusion details

Solar researchers identified several tools associated with the intrusion, including an updated version of the Vasilek Windows backdoor.

Vasilek was previously documented by Kaspersky as malware used by the Cyber Partisans. The backdoor can communicate with attackers through the Telegram Bot API and receive commands through a Telegram group. It can collect information from infected computers, execute Windows commands, transfer files, capture screenshots and record keystrokes. 

Attack tactic 

Solar said the newer version found during its investigation was version 1.5.8. Researchers also identified techniques for maintaining persistence inside the victim’s environment. These included Windows services and the replacement of the vmtools.dll library associated with VMware Tools.

The attackers also used other communication and tunnelling tools, including DNS tunnels and proxy chains. This gave them alternative methods of communicating with compromised systems if one channel became unavailable. 

Telegram restrictions in Russia affected Vasilek’s communications, but researchers said the attackers could use other methods to maintain their access.

What next?

The compromised organization was not publicly identified. However, researchers said it operated a large infrastructure connected to multiple other healthcare organizations.

This created a potential trusted-relationship attack risk. Once attackers gained control of one organization, its connections with other trusted healthcare entities could potentially provide opportunities to reach additional networks.

The researchers said the attackers accessed sensitive medical data but did not destroy the victim’s systems. The long period of access suggests that espionage, intelligence gathering and maintaining future access may have been more important than immediate disruption. 

Microsoft X Account Hijacked to Promote Clippy-Themed Crypto Token

 

Microsoft’s account on X was hacked and used to promote a cryptocurrency token, turning the technology company’s 13-million-follower social media presence into part of an apparent crypto pump-and-dump operation. The incident centered on the company’s @Microsoft account and began with activity involving another X profile impersonating Clippy, Microsoft’s former virtual assistant. 

The Microsoft account followed and reposted a post from @clippymsftcto, an account that has since been suspended. The activity subsequently drew attention to a $Clippy token. Another account, @ClippyMSFT, reposted Microsoft’s message and continued promoting the cryptocurrency. That account claimed the token had a liquidity pool directly paired with $MSFT. Microsoft later removed the unauthorized posts and acknowledged that its account had been accessed unauthorized. 

A company spokesperson said the account had been secured and that Microsoft was investigating how the breach occurred. The company also made clear that it had no association with the cryptocurrency which was being promoted. Microsoft said it did not authorize, sponsor or endorse a cryptocurrency associated with Clippy, Microsoft or $MSFT, and had not authorized the use of its branding or intellectual property in connection with such a token. The incident is part of a long pattern of cryptocurrency scams involving compromised accounts belonging to major organizations. 

Microsoft itself experienced a similar breach in June 2024, when its Microsoft India account, which had more than 211,000 followers, was taken. In that case, attackers used the account to impersonate meme-stock trader Keith Gill, known online as Roaring Kitty. They attempted to lure users to a website advertising a supposed GameStop cryptocurrency presale. Victims who connected their wallets and authorized transactions instead had their crypto assets stolen through a wallet-drainer malware. Compromised social media accounts has been a particularly useful tool for cryptocurrency scams, as posts from established organizations can appear more credible to potential victims. 

ScamSniffer reported in December 2023 that approximately $59 million in cryptocurrency has been stolen from 63,000 people through a Twitter advertising campaign using the “MS Drainer” wallet-draining service between March and November. Government accounts have also been targeted. In January 2024, the U.S. Securities and Exchange Commission’s official X account was compromised through a SIM-swapping attack. Attackers used it to publish a fake announcement claiming that Bitcoin exchange-traded funds had received approval, temporarily but significantly moving Bitcoin’s price. 

Eric Council Jr., identified as the hacker who compromised the SEC account, pleaded guilty in February 2025 and was sentenced to 14 months in prison over his involvement in the scheme. Microsoft now has its account secured and the posts associated with the breach removed. Its investigation is ongoing, but the cryptocurrency promotion associated with the unauthorized activity has further raised the risks of trusting what appear to be legitimate social media posts when they involve digital-asset promotions.

CloudSyncD MacOS Backdoor Used Fake Zoom Installer to Steal Passwords


Cybersecurity researchers have identified a new macOS backdoor called CloudSyncD that uses a fake Zoom installer to trick users into providing their computer passwords. The malware was discovered by Jamf Threat Labs and uses a two-stage infection process to gain elevated access and communicate with attacker-controlled servers.

One of the most unusual features of the malware is its use of zero-width Unicode characters to hide information about a stolen password inside what appears to be a normal configuration file.

Technical Details

CloudSyncD is distributed through a malicious disk image designed to look like a legitimate Zoom installer. The installer includes instructions telling users to bypass macOS Gatekeeper by going to System Settings and manually allowing the application to run.

Once the fake installer is launched, the first-stage program, called app_installer, displays a fake authorization window asking for the user’s administrator password. It checks the entered password locally using macOS’s dscl command. If the password is incorrect, the malware can continue prompting the victim.

The stolen password is not immediately sent to the attackers. Instead, the malware stores it inside a file called data.json. The password is Base64-encoded and placed inside a larger string containing random characters.

The malware then uses U+200B ZERO WIDTH SPACE and U+200C ZERO WIDTH NON-JOINER characters. These characters are invisible during normal viewing and encode the location and length of the hidden password. This technique allows malicious information to be concealed without obviously changing the appearance of the file. 

The second stage is an embedded Mach-O executable capable of running on both Intel-based and Apple Silicon Macs. The malware attempts to execute the payload without initially writing it to disk. When that approach fails because of macOS security protections, it can create a temporary file and use the captured password with sudo to execute the backdoor with elevated privileges.

Impact

After execution, CloudSyncD collects information about the infected Mac, including hardware and operating-system details, account information and network-related data. It communicates with a command-and-control server and can periodically check for additional instructions.

Researchers observed check-ins occurring approximately every 8 to 16 seconds in analyzed samples. The backdoor can receive executable files or compressed archives, potentially allowing attackers to deploy additional malware on an infected system.