HeadFlash

Security

Cloudflare to issue quantum-safe TLS certificates starting in Q1 2027

Cloudflare bets on Merkle Tree proofs to replace quantum-vulnerable certificate chains, with issuance set to begin in early 2027.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Sound Blaster Katana V2X flaw lets attackers within 15 meters hijack the speaker

A vulnerability in the Creative Sound Blaster Katana V2X speaker lets anyone within roughly 15 meters turn it into a covert listening device or a remote Rubber Ducky without pairing or physical access. The device uses the proprietary CTP protocol over USB and Bluetooth, protected by challenge-response authentication with a static key derivable from Creative App binaries. Researchers flashed patched firmware over Bluetooth in about 10 minutes, since no signature protection exists beyond a patchable checksum. Custom firmware could abuse the built-in microphone or make the speaker act as a USB keyboard, typing commands on a connected PC. Creative told SingCERT it does not consider this a vulnerability and released several firmware updates through August 2026, though the latest firmware tested remained vulnerable. Bluetooth stays on even in sleep mode.

Pwnd Blaster: Hacking your PC using your speaker without ever touching it | nns.ee →

Fake Zoom installer drops CloudSyncD infostealer on macOS

Jamf Threat Labs has detailed new macOS malware disguised as a Zoom installer. The disk image mounts as Zoom and looks like a standard Mac installer, with the app icon on the left and an Applications folder alias on the right, and it does install the real Zoom app. It also installs an infostealer called CloudSyncD that runs in the background, captures user-entered data and can send reports to attackers as often as every 8 seconds. Because the malware lacks proper signatures, Gatekeeper blocks it, so the installer includes a background image with instructions telling users how to override Gatekeeper. Once installed, CloudSyncD also lets attackers execute commands remotely.

New macOS malware masquerades as Zoom installer →

Star Blizzard deploys CosmicPulse backdoor via new RedFlick technique

Russian state actor Star Blizzard has adopted a new malware installation tactic dubbed RedFlick to deploy its CosmicPulse backdoor, Microsoft researchers say. Attacks begin with a phishing email, such as an invitation, followed by a second message containing a password-protected ZIP or RAR archive. Inside is a VHDX virtual disk with an LNK file disguised as a PDF; opening it launches a hidden command while showing a decoy PDF, then downloads an MSI that creates three scheduled tasks posing as maintenance components. These fetch a downloader, NOROBOT and BAITSWITCH, delivered as a Control Panel applet that pulls the CosmicPulse backdoor. RedFlick needs only one victim action, unlike ClickFix. Microsoft has seen at least 13 large-scale phishing campaigns hitting over 100 organizations since the start of the year, mainly in the US and UK.

Russian state hackers use new RedFlick technique to push malware →

TeamViewer urges immediate patching of five high-severity flaws

TeamViewer warned customers on Tuesday to immediately patch high-severity vulnerabilities in its client and host software. The most severe is a remote session access control bypass, CVE-2026-92370, caused by improper access control in TeamViewer Full Client and Host for Windows, Linux and macOS, which could let remote attackers perform unauthorized actions leading to remote code execution. The other four are a path traversal (CVE-2026-19743), a heap-based buffer overflow (CVE-2026-92368), a time-of-check time-of-use race condition (CVE-2026-92369), and an improper path validation (CVE-2026-92371) that allows local attackers to gain code execution with current user privileges or escalate to SYSTEM or root. The flaws are fixed in TeamViewer Clients version 15.82 and supported maintenance and legacy releases; TeamViewer says it has no evidence of public exploit code or active exploitation.

TeamViewer urges users to patch severe flaws “as soon as possible” →

Cloudflare plans quantum-safe TLS certificates for early 2027

Cloudflare plans to issue quantum-safe TLS certificates, expected to begin in the first quarter of 2027. The design replaces the current WebPKI’s multi-link chain of quantum-vulnerable signatures with compact Merkle Tree proofs, since swapping those signatures for quantum-resistant ones is resource-prohibitive. Google announced the Merkle Trees solution in February, and Google and Cloudflare have tested the design in limited pilots. It drops handshake data to about 40 kilobytes, roughly the same as today. A certificate authority signs only a single tree head representing millions of certificates, and browsers typically handle a lightweight landmark proof. Logging becomes a core part of issuance rather than an add-on, Cloudflare engineer Mari Galicer said. The plan also includes ACME for automated certificate issuance and renewal.

Cloudflare plans to issue quantum-safe TLS certificates →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches