HeadFlash

Security

Check Point RCE, Docker escape, 30,000 WaterPlum devices hit

Check Point patches a critical root RCE, Docker fixes a Mac sandbox escape, and North Korea's WaterPlum breached 30,000 devices in 100+ countries.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Check Point patches critical flaw allowing root code execution

Check Point released updates for CVE-2026-91843, a critical stack-based buffer overflow in the login process of Security Management Server and Log Server. Exploitation lets unprivileged attackers gain root remote code execution in low-complexity attacks requiring no user interaction. Check Point said all Security Management Server deployments are vulnerable regardless of configuration, even when VPN is not in use. Temporary mitigations include hardening systems and limiting access to trusted IP addresses via SmartConsole. The flaw is not flagged as actively exploited; defenders can look for Administrator failed to log in: Username too long alerts in Audit and Admin login logs.

New Check Point flaw lets hackers execute code with root privileges →

Docker patches Mac hypervisor sandbox escape

Docker fixed CVE-2026-77179, a sandbox escape in its Mac hypervisor that let a container gain full read and write access to the host filesystem using three lines of bash. The bug affects Docker Desktop only when Docker VMM is enabled, and Docker Sandboxes; Docker VMM becomes the Desktop default at the end of October 2026. The flaw abuses virtio-fs path resolution after a file is deleted and its parent folder replaced with a symlink. Fixes shipped in Docker Sandboxes 0.42.0 and Docker Desktop 4.88.0; Docker confirmed the bug about 31 hours after the August 12 report.

Guest to host: escaping Docker's hypervisor — Accomplish Blog →

WaterPlum breached 30,000 devices across 100 countries

A joint advisory from Japanese, US, Australian and German authorities says North Korean group WaterPlum compromised at least 30,000 devices in more than 100 countries between December 2025 and July 2026, stealing funds or credentials from over 7,000 cryptocurrency wallets and moving 1.7 billion yen, about $10.71 million, to the DPRK. WaterPlum runs the Contagious Interview campaign, impersonating AI, crypto and NFT firms to trick job seekers into running malicious code during fake interviews and coding tests. Malware families include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. Authorities link the group to North Korea’s fraudulent IT worker operations and the 313 General Bureau.

North Korean WaterPlum hackers infected 30,000 devices worldwide →

Google analyst spent months inside TeamPCP supply-chain gang

Google Threat Intelligence Group researcher Austin Larsen revealed at LABScon that Mandiant had an undercover analyst inside TeamPCP’s core chat, CanisterWorm, from near the group’s late-2025 start. The analyst was one of roughly 12 members with access and never engaged in hacking. TeamPCP tainted hundreds of open-source programs, stole developer accounts and released the Mini Shai-Hulud worm, breaching over a thousand companies including Trivy, LiteLLM, Checkmarx, TanStack and Mistral AI, with downstream breaches at GitHub, Mercor, OpenAI and the European Commission. Google warned providers to revoke stolen credentials and obtained an AI-built zero-day exploit targeting 2FA login software, which the developer patched. Australians Ruben Ian Thomson and Louis Michael Gaebler were arrested and charged.

An undercover Google analyst infiltrated a notorious supply-chain hacking gang →

Fake LastPass Authenticator repos push Rapuncel infostealer

LastPass and Delphos Labs uncovered a campaign using SEO-optimized GitHub repositories impersonating LastPass and at least 39 other companies to deliver a new infostealer called Rapuncel. Victims searching for LastPass Authenticator reach fake repos whose download buttons redirect to ZIP archives inflated to as much as 148MB to evade scanning. The installer is a renamed Microsoft vsdbg.exe that sideloads a malicious DLL, deploying Rapuncel plus the Alinubx.sys kernel driver disguised as an NVIDIA component, which terminates 145 antivirus and EDR processes. Rapuncel steals credentials from 25 browsers, 30 crypto wallets, Discord, Steam and Telegram, and persists via a Windows service. Researchers assess it as a BoryptGrab variant.

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer →

Public exploits released for four Linux kernel root flaws

Researcher Asim Manizada published working exploits for four Linux kernel flaws that each let a local user gain root: DirtyAH6, TUNderflow, PPPoEject and DiagSpill. Kernel maintainers fixed all four over recent weeks, with first stable releases including 5.10.270, 6.1.188, 6.6.157 and 7.2.4, so updated systems are safe. Three flaws require unprivileged user namespaces, enabled by default on many distributions; DiagSpill needs no special privileges if the SCTP module is available. The bugs are memory-safety issues in networking code with mistakes 10 to 21 years old. No real-world attacks have been reported, and the exploits are tuned to specific builds and can crash machines.

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root →

Malicious npm package hides loader in runtime code

Checkmarx found the npm package indexed-btree, impersonating the legitimate sorted-btree library and claiming 2 million weekly downloads, hiding its loader in normal runtime behavior instead of install scripts to bypass npm defenses. The loader sits in BTree.prototype.set(), executing when an application calls it with a specific key, so installation appears clean and avoids npm v12 approval mechanisms. The malware collects system details and exfiltrates them via hardcoded Slack and Telegram channels, polling an Ethereum smart contract on Sepolia for commands. Checkmarx linked nine more packages, now removed, with downloads ranging from 366,019 to 1,951,274. Developers who installed them should rotate secrets and restore from backups.

Malicious npm packages evade install-script defenses at runtime →

Compromised Packagist themes serve iOS exploit chain

Thirteen compromised Packagist packages across five vendor namespaces posed as themes for OphimCMS and streaming platforms, injecting JavaScript into Vietnamese streaming sites whose operators installed them unknowingly. The code redirects all mobile visitors to ads and gambling, but only on iPhone loads a hidden iframe with an iOS exploit chain, distinguished server-side. The chain begins with WebKit flaw CVE-2025-31277, patched in iOS 18.6, and JavaScriptCore flaw CVE-2025-43529, patched in iOS 18.7.3 and 26.2, then bypasses Pointer Authentication Codes and escalates to kernel privileges using suspected CVEs patched in iOS 18.7.2 and 26.1. It installs spyware querying the iOS password store for seed phrases tied to Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet and OKX. Updating to iOS 18.7.2 or 26.1 is the documented countermeasure.

Infected PHP Themes on Streaming Sites: The iOS Chain That… | DeafNews →

Slovakia finds Russian backdoors in 279 traffic cameras

Slovakia’s national security service, the NBU, found multiple security issues in 279 NERO R-ONE speed cameras acquired as part of a traffic control modernization funded from a 30 million euro EU budget. The cameras contained SMS-activated Russian backdoors, and live camera feeds were accessible to anyone with the device IP address, with no password required. The system has been deactivated.

Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout | Tom’s Hardware →

SolarWinds patches hard-coded key in Access Rights Manager

SolarWinds released patch 2026.2.1 for Access Rights Manager on September 17, 2026, addressing CVE-2026-28326, an unauthenticated remote code execution vulnerability caused by a hard-coded cryptographic key. The flaw is classified CWE-321 and rated 8.8 on the CVSS 3.1 scale, affecting all ARM versions 2026.2 and earlier. The vector requires the attacker to be on the same adjacent network but no privileges or user interaction, with maximum impact on confidentiality, integrity and availability. Researcher Kai Huang of Armadin is credited. SolarWinds does not mention in-the-wild exploitation, and no temporary countermeasures are documented; organizations should upgrade to 2026.2.1.

SolarWinds Patches Hard-Coded Cryptographic Key in ARM:… | DeafNews →

Expert hacks BYD Shark 6 with no password needed

Fortify Labs co-founder Dan Hreszczuk spent two weeks hacking a BYD Shark 6 plug-in hybrid and found its systems lacked even a password. He remotely locked doors with a driver inside, blasted music, displayed images, ran wipers at top speed and killed the headlights; brakes and cameras were well protected. In a second demo he activated the car microphone to record a phone conversation, captured Hey Siri, stitched it to his own voice commands and played them through the speakers. Siri then disclosed the driver’s home address, date of birth and age, and a banking password was obtained within minutes. Australia has no minimum cybersecurity standards for cars; consultations on new rules have started but are likely years from taking force.

We got a cybersecurity expert to hack this BYD. It was too easy →

Attackers can gain persistent SaaS access through a single convincing OAuth consent prompt, without passwords or malware, because MFA secures authentication but not what users authorize afterward. A user signs in, passes MFA and approves an application that gains access to email, files, repositories or cloud workflows, all on a legitimate provider domain. Depending on scopes and tenant policy, attackers obtain tokens or app grants enabling ongoing API access until revoked, letting them search mailboxes, extract source code or modify repository settings. Security teams may see successful sign-ins, legitimate domains and normal API traffic, so detection requires monitoring new app grants, risky scopes, unusual token activity and post-consent API behavior changes. Controls include restricting default user approval, requiring admin approval for high-risk scopes and applying scope discipline.

MFA Won’t Save You From OAuth Consent Abuse →

European password manager shares codebase with Russian firm

An OCCRP investigation found Passwork Europe S.L., a Spain-registered password manager used by European government agencies and universities, shares a codebase origin and update pipeline with Russian counterpart Passwork LLC, whose advertised clients include sanctioned Russian missile manufacturers and which holds FSTEC and FSB certifications. Public manuals for the latest Russian and European versions are near-identical apart from language, and the past six updates were announced on similar timelines with near-identical descriptions. CEO Alexander Muntyan denied any relationship, saying he acquired the software rights from a UAE firm in 2024 and that clients’ data sits on private servers under zero-knowledge architecture. Of roughly 30 apparent clients contacted, more than a dozen confirmed some staff use the product, and all but one were unaware of its Russian heritage. Reporters found no evidence of malicious code or illegality.

European Password Manager Shares Origins and Updates with State-Certified Russian Firm - VSquare.org →

Five Cyber Command suicides in five weeks raise funding questions

Five US Cyber Command personnel died by suicide over roughly five weeks between early June and early July 2026, per Bloomberg reporting and public records. Gen. Joshua Rudd, who leads Cyber Command and the NSA, acknowledged three deaths in a June all-hands email; records confirmed two more. A study commissioned under the FY2024 NDAA found resources for cyber personnel inadequate and potentially jeopardizing readiness, but no implementation plan reached Congress. The FY2026 NDAA directed behavioral health specialists with clearances to the command. Rudd told lawmakers the command ran 8,000 missions in 2025, up 25 percent, with numbers expected to rise. A partnership with Fort Meade’s Kimbrough center embeds two cleared providers, but maximum capacity is five for roughly 6,000 Cyber Mission Force personnel.

Five Suicides in Five Weeks: Cyber Command Had Prior NDAA Fix; Funding May Not Follow →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches