Security
RSA signatures forged in 1,380 core-years via HSM oracle
Researchers forged 1024-bit RSA signatures without factoring the key, and Iran-linked CHOSEN BRICK spyware targeted dissidents in a joint US-UK-Dutch alert.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
1024-bit RSA signatures forged without factoring the key
Researchers Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé implemented a 2007 Joux-Naccache-Thomé algorithm against 1024-bit RSA, forging signatures without factoring the key. The attack took 1,380 CPU core-years over five months and 232 oracle queries, mostly precomputation; afterward any signature can be forged offline in 180 core-years. It used a hardware security module as the signing oracle, impersonating it through black-box API calls without exfiltrating the key. Blind RSA schemes also expose such an oracle. The authors estimate RSA signing-oracle security is 15 to 30 bits below factoring estimates, so even 4096-bit RSA may miss a 128-bit level. The work is archived as Cryptology ePrint Archive Paper 2026/2131.
Forging 1024-bit RSA signatures in nearly SNFS time →
US, UK and Dutch agencies warn on Iranian CHOSEN BRICK spyware
The UK’s NCSC, the FBI and the Netherlands’ AIVD issued a joint warning Tuesday about CHOSEN BRICK, spyware used by Iranian state-sponsored hackers against dissidents, activists and journalists. Lures included a fake MRI scan of a disk herniation, plus impersonations of Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass, after rapport-building on WhatsApp and Telegram. The Windows malware survives reboots, adds Microsoft Defender exclusions, uses a separate Telegram bot per victim for command and control, and steals contacts, inboxes, screen content and microphone audio. Agencies warn the data builds a pattern of life, raising physical risk; victims date back to at least 2025 across all three countries.
OxygenOS 16 flaws give untrusted apps root on OnePlus 15
A two-vulnerability chain in OxygenOS 16 lets an ordinary app with no special permissions gain uid 0 with full Linux capabilities on a OnePlus 15 (CPH2747, OxygenOS 16.0.3.503). The first bug is in AtlasService, a root telemetry service accepting binder calls from any process; its setEvent method lacks a caller check and passes attacker-controlled input into a root-spawned audio dump binary, enabling shell command injection. The second is in a vendor HAL whose doShell method only checks for uid 0, then executes commands with all capabilities. OnePlus confirmed the flaws affect many OnePlus and OPPO devices but has not listed them; the write-up was published 24 September 2026.
DOJ arrests Oxygen Forensics leaders over hidden Russian ownership
The Justice Department announced Wednesday that Oxygen Forensics CEO Lee Reiber was arrested in Idaho and Oleg Davydov, one of five Russian nationals alleged to control the company, was arrested in London, both charged with conspiracy to commit wire fraud. The complaint says Oxygen publicly presented Reiber as its leader and denied Russian control while Russian executives overruled him, removing owners from filings after 2022 sanctions. Since March 2022 Oxygen sold forensics software to the Secret Service, Homeland Security Investigations, the DHS inspector general and DOD, winning over $2 million from the Secret Service and its National Computer Forensics Institute. The DOJ says the complaint does not allege malicious code or unauthorized access to customer systems.
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges →
Cisco Talos releases framework for classifying agentic AI malware
Cisco Talos researchers released an open-source framework on Monday for classifying and analyzing malware and hacking tools that incorporate agentic AI components. The tool is meant to help defenders identify and track AI-integrated malware, which attackers are increasingly deploying. Using the framework, the researchers found malware guided by an AI hive mind with no humans in sight.
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight | WIRED →