Read Time: 9 minutes

Brought to you by:

Howdy friends!

Just got back from Toronto where I got asked to be the opening keynote for SecTor (Black Hat Canada)’s AI Summit. I was also then asked to be on a few more panels throughout the week when word got out that I was crossing the border for it. It’s a great conference and it was good to be back. Thanks for all of you who watched and any of you who came up to say hi and thank me for my videos.

One thing I’ll note after my last few conferences: The gap in understanding current state AI capabilities is very wide in our industry. I don’t say that to dunk on anyone, but I feel like a lot of us tried ChatGPT a few years ago, or even Claude Sonnet 3.5 and made up our mind on how it all works. I implore you all to stay hands on keyboard with the latest AI models, harnesses, tools, etc.

It is the only way to truly A) form an opinion about it that is current and accurate and B) get your head around how to secure this stuff or how to use this stuff to enhance your security program. Learn what its good and bad at, and stay on top of it. It changes what feels like hourly, and you have to realize that.

My MOST AI-Pilled friends all feel behind, so whenever I meet someone who thinks they’ve got it all figured out, I’m immediately skeptical.

ICYMI

πŸ–Š Something I wrote: Exactly one person could make me nervous by saying this, and there he is

🎧 Something I heard: Citrix 0days, ShinyHunters, and the risks of Open Weight model cyber capabilities on The Low Down

🎀 Something I said: The illusion of privacy in your AI chats

πŸ”– Something I read: one of the most underrated threats in cyber right now

Vulnerable News

Exactly one person

Johns Hopkins cryptographer Matthew Green was asked what this week's AI math announcements mean for crypto, and his answer was "I think we might lose public key cryptography," later narrowed to encryption specifically. It landed the morning after Ethereum Foundation researcher Justin Drake told the industry to start planning a "bunker mode" migration, warning ECDSA could fall to AI before quantum computers get there, "in the worst case in months not years." The backdrop is OpenAI dumping hundreds of new math results from an internal model on Tuesday.

Coinbase's head of cryptography Yehuda Lindell called Drake's take the definition of FUD, and he's right that nobody has shown a result against elliptic curves or RSA. Green landed in the middle. He doesn't know of any unreleased cryptanalysis from the labs, but they employ cryptanalysts, and machines are now beating humans on math we've been stuck on for years. His worry, going back to his July post on Anthropic's model breaking a proposed post-quantum signature scheme, is that our public key hardness assumptions have had far fewer human hours thrown at them than we'd like. Nobody needs to move their coins today.

Encryption is fine, keep using it, and he knows of no imminent cryptanalysis results. His worry is the standardized public key encryption we all depend on, plus some signatures, rests on a small handful of hard problems. Our confidence in today's key sizes comes from a couple dozen humans studying those problems for 25 to 40 years. If models show those estimates are off by a real number of bits, the parameters we ship today stop being something we can lean on. (read more here, here and here)

Data loss is as much of a problem today as it was in 1998, and, frankly, most tools built to stop it haven't changed much since. The problem has. Employees still email files to their personal accounts and print things they shouldn't. They also now paste sensitive data into ChatGPT. ORION's DLP98 puts you in front of a confiscated Windows 98 PC and gives you five minutes to find out what leaked, how, and where. By the end, you'll really be wondering whether your own security would have caught it. There's no sign-up, and it's free to play. You should try it out.

*Sponsored

Rough few weeks for ShinyHunters. Reuters reported Oct 3 that Saif Al-din Khader, the Jordanian teen Krebs identified last year as the hacker "Rey," was detained in Amman and is helping the FBI name other members. That's three weeks after Dutch police picked up Pepijn van der Stap. Krebs now reports Rey was in the middle of extorting Jeppesen ForeFlight, the aviation unit Boeing sold to Thoma Bravo, when he got pulled in. And Rey's dad appears to work for Royal Jordanian Airlines, which flies Boeing jets.

The FBI hack also has some new info. Reuters says the bureau removed an Accenture contractor who never applied the Oracle PeopleSoft fix that ShinyHunters used to breach its recruitment site, exposing data on more than 5,000 FBI personnel. Not often you hear of someone getting fired after a breach, but an Accenture contractor who just didn’t apply a patch they were supposed to? Easier to just remove the contractor. This also dispells the new 0day claims that ShinyHunters made, if there was a patch to be applied to begin with. The group also got around Mandiant's suggested WAF rules with an old URL-encoding trick. (read more here and here)

Somebody popped the registry operators for Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as), rewrote authoritative DNS, and used that to get valid certificates for Google and YouTube domains under those TLDs. Google says its own systems weren't touched and Chrome is already blocking the certs. The Hacker News went through Certificate Transparency logs and found at least 12 issued between Sept 22 and 27, almost all from Let's Encrypt, and all revoked by Oct 1.

The uncomfortable part is the CAs did their jobs. Domain validation proves you control DNS, and for a few days the attackers controlled DNS. Google says the same CT data points at other big brands it won't name, and Chrome's block does nothing for anyone on another browser. If you own domains under these TLDs, check CT logs for certs you never asked for, and lock your CAA records to your own CA account, since a CA can reuse a completed validation for months after the hijack ends. (read more here and here)

We’ve all been there: chasing access requests, tracking down who has access to what, and scrambling to pull everything together for an audit. Fragmented identity shouldn’t have to be this hard. Join Jane Frankland, Graham Cluley, and Okta’s Jen Vaccaro McParland on 29th October to see how smarter identity governance can cut the manual work, close access gaps, and reduce risk.

*Sponsored

If you self-host anything Atlassian Data Center, put this at the top of the list. CVE-2026-21589 (CVSS 9.3) is an unauthenticated file read across eight products, Jira, Confluence and Bitbucket included. Atlassian's advisory makes it sound narrow, since an attacker has to know the exact file path. Then watchTowr showed that on Jira and Crowd the obvious file to grab holds Crowd's credentials, which gets you to admin. Crowd is Atlassian’s SSO tool if you’re unfamiliar. Previdian's honeypots caught exploitation attempts two hours after that writeup went up.

watchTowr says in-the-wild activity so far is fingerprinting and sweeps for config files, with nobody using stolen creds yet. That window closes fast now that scanning templates are circulating. Cloud customers are already patched. If you can't upgrade today, Atlassian's own advice is to pull the instance off the internet, and once you're patched, rotate anything sensitive that lived in the web root. (read more here and here)

I'm running out of ways to say "patch your Cisco and Citrix gear." Cisco dropped five critical bugs yesterday that can get an attacker root on Nexus 3000 and 9000 switches. It also fixed three critical flaws, scoring 10.0, 9.8 and 9.1, in its licensing server (formerly Smart Software Manager). Those hit every configuration with no workaround, and old releases get no patch at all. That's on top of three exploited Cisco zero-days since mid-September in Secure Email Gateway, ISE and SD-WAN Manager. The Stack counts 17 Cisco zero-days this year, against eight in all of 2025.

Then Citrix... I just don’t even know. Today it dropped CVE-2026-107406, a 9.5 memory overflow in NetScaler's SAML handling that can lead to code execution. It's the third SAML bug since August, after the pre-auth RCE and last weekend's zero-day, and the affected range includes the builds you just installed to fix the earlier rounds. If your NetScaler does SAML, this is your third patch in under two weeks. No confirmed exploitation yet, which this month feels like a countdown. (read more here, here and here)

Nuts. Creating margins on ransoms.

MonsterCloud told ransomware victims not to pay, and pitched "proprietary tools" and "advanced decryption techniques" to get their data back instead. Prosecutors in the Eastern District of New York say owner Zohar Pinhasi was quietly paying the attackers for the decryptor and marking it up. One example from the DOJ: an $8,200 ransom billed to the client at about $150,000. In total he allegedly charged clients more than $19 million while paying out over $8 million in ransoms.

He's facing wire fraud and conspiracy charges at up to 20 years a count. The company's FAQ says it "sometimes resort[s] to other means" and that terms are in the contract, so I assume that's the defense. If you're ever bringing in a recovery firm, ask point blank whether they pay ransoms and get the answer in writing. Some of these victims paid a ransom without ever knowing it, which is a sanctions problem as much as a billing one.(read more)

404 Media got hold of internal Meta posts showing that in the weeks before Muse launched, engineers caught a spike in VM escapes in the per-user virtual machines Muse agents run in. At least one could have let a normal user reach internal Meta databases. It got escalated to Zuckerberg, multiple security teams worked nights and weekends, and they shipped hardening to cut down what the agents can reach. A Meta source called the fixes "half-baked" and rushed to hit the launch date.

This was obviously written as a story to talk about some crazy security bug that let users of Muse run code on Meta servers, but I’m reading it as security ops working as normal. Finding escape bugs before launch, escalating them to the CEO, and fixing them before customers touch the product is the process working. The question I'd want answered is why we know about it at all: internal security posts about pre-launch escape bugs walked out the door to a reporter. Patrick Wardle's point that Meta's design leaves production one escape away is fair, and Meta pays $300K for exactly that bug, so outside researchers will keep hunting. (read more)

The FBI seized seven domains behind two hacking tools run by Integrity Technology Group, the China-based contractor tied to Flax Typhoon that the DOJ says has contracts with the Chinese government. MicroScan is a vulnerability scanner that ran partly through a Mirai botnet of hacked IoT devices. FishHub handled spear phishing and then dropped follow-on malware for remote access and file theft. Scanning targets in the court documents include a South Carolina power company, airports in Japan and Poland, and Taiwanese gas and power companies, and FishHub's confirmed victims include about 20 Taiwanese universities.

This is the second time in two years the DOJ has hit Integrity Tech, after it took down the company's 200,000-device botnet in September 2024, so expect them to rebuild. The useful part for defenders is the joint advisory from the FBI, CISA, NSA and partners, which has the IOCs. The bugs on their favorites list are old: Shellshock, a 2019 Pulse Secure file read, a 2016 Apache Struts RCE, a 2021 GitLab RCE. If any of that is still exposed on your network, you weren’t going to make it anyway. (read more here and here)

Prasan Nepal, the 21-year-old North Carolina man prosecutors say led 764 for nearly four years, pleaded guilty Thursday in federal court in DC to conspiracy to sexually exploit a child. 764 is a nihilistic violent extremist network tied to The Com that grooms and extorts minors into producing abuse material and harming themselves and others. Nepal helped build it while he was still a minor. He controlled who got in, and admitted he required prospective members to produce abuse and violent content as the price of entry. He faces 15 to 30 years. His alleged co-leader, Leonidas Varagiannis, is detained in Greece awaiting trial.

This is the latest in a steady run of 764 cases. Kyle Spitze was sentenced to 77 years in August and Alexis Chavez to 40 in July. Allison Nixon of Unit 221B told CyberScoop that reoffending rates in these online gangs are extremely high, so the measure of success is how fast they're caught and how long they're held. If you suspect a child is being targeted, report it to the FBI at tips.fbi.gov or to the NCMEC CyberTipline. (read more here and here)

Miscellaneous mattjay

How'd I do this edition?

It's hard doing this in a vacuum. Screaming into a void. Feedback is incredibly valuable to make sure I'm making a newsletter you love getting every week.

Login or Subscribe to participate

Parting Thoughts:

Community was foundational in launching and propelling my career. Community is the only reason I can stand being in Texas during the summer months. Community is the point. Today, I invite you to embrace discomfort on the road to a more vulnerable you.

Stay safe, Matt Johansen
@mattjay