HeadFlash

Security

Spectre v2 BTR attack leaks Linux root password hash in minutes

New BTR variant defeats assumptions about self-modifying code, exposing root password hashes on Intel Linux systems in as little as three minutes.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Spectre v2 BTR attack leaks Linux root password hash in minutes

Researchers at VUsec and Scuola Superiore Sant’Anna devised Branch Target Reuse (BTR), a Spectre v2 variant that recovers root password hashes from Intel Linux machines in minutes. BTR exploits stale branch predictor entries after a JIT engine reuses memory, tricking the CPU into speculatively executing attacker-crafted instructions. Tested against Firefox’s SpiderMonkey, GraalVM and Linux cBPF, it leaked the hash at eight bytes per second, succeeding in three minutes on Raptor Cove and five on Lion Cove. The flaws received CVE-2026-64507 and CVE-2026-64508, with fixes merged into the Linux kernel. Researchers confirmed the behavior on Intel, AMD and Arm CPUs, advising users to apply OS and firmware updates and upgrade to the latest kernel.

New Spectre v2 attack variant leaks Linux root password hash in minutes →

OpenBao patches full unauthenticated RCE chain, Vault left unfixed

ControlPlane and the OpenBao community fixed a full exploit chain from unauthenticated access to remote code execution, the second-ever RCE in Vault and OpenBao. Patched in OpenBao v2.6.3 and v2.7.0 on September 23, the chain combines four flaws: an ACME validation bypass (CVSSv4 8.2), a cross-namespace policy access issue (7.7), an ACL bypass via non-canonical URLs (7.6), and critical RCE via snapshot restore (9.4). An attacker obtains a certificate, escalates to admin, restores a malicious snapshot and unseals the node with their own keys. IBM’s HashiCorp Vault has not remediated the vulnerabilities, leaving Vault customers exposed at release with no mitigations.

A Realistic Code Execution Exploit Chain in OpenBao and Vault →

Star Blizzard expands phishing beyond Ukraine with RedFlick malware

Microsoft research published Tuesday concludes that Star Blizzard, a Russian FSB-affiliated hacking group, is refining attacks and significantly expanding targeting of governments, think tanks and nonprofits worldwide, with an emphasis on Ukraine. In 2026, Microsoft observed the group shift from exclusively targeted spear-phishing to larger-scale campaigns of tens to hundreds of emails, likely using a mass-mailing platform. Its novel RedFlick malware requires only a single user interaction to deploy the CosmicPulse backdoor. Since January 2026, Microsoft tracked at least 13 distinct large-scale phishing campaigns, affecting over 100 organizations primarily in the United States or United Kingdom. The group is also known as SEABORGIUM, Callisto Group, TA446 and COLDRIVER.

Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond →

Dutch police arrest 24-year-old suspected ShinyHunters leader

Dutch police arrested a 24-year-old Amsterdam man on September 15 in connection with ShinyHunters, the hacking group that claimed responsibility for attacks on Ticketmaster, Rockstar Games and the FBI. Neither Dutch authorities nor the FBI named the suspect, but Krebs on Security and Reuters reported police arrested Pepijn van der Stap, convicted of data theft and extortion in 2023. ShinyHunters told Reuters he has no association with the group. FBI Cyber Division Assistant Director Brett Leatherman called the suspect one of the group’s alleged leaders. The man is also suspected of attempted incitement to commit two murders, according to Dutch police. The arrest came days before the group claimed to have breached the FBI’s website.

Suspected ShinyHunters leader arrested in the Netherlands →

80-day DVR audit finds hardcoded AES keys and root command injection

An 80-day audit of an OEM HiSilicon ARM32 surveillance DVR platform covered 28,006 internet-facing units identified via a Shodan query. Three findings emerged: port 8000 authentication uses AES-256-CBC with static keys hardcoded in libdal.so, allowing credential-free login; boot scripts execute /dvr/fwr upgrade as root without signature verification; and opcode 0x221 runs sprintf into system() with a filter rejecting only backticks and dollar signs, leaving semicolons and pipes unhandled. An emulator captured system(“mv /dev/null;id>/www/pages/ROOTPWN.txt;# /dvr/fwr.tmp”). Firmware 2.3.4.x and 2.3.7.x carried the vulnerable handlers, and 2,956 internet-facing devices ran the vulnerable 2.3.7.x build, but the bench unit had been updated to 3.1.14.0, which dropped those opcodes. Disclosure failed; the vendor never responded.

80 Days Reverse Engineering an IoT DVR: What I Found and Why It Didn’t Work Out — Leviathan OffSec →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches