HeadFlash

Security

Atlassian 9.3 Flaw Hits 8 Products as FBI Seizes Deepfake CSAM Sites

Atlassian's unauthenticated 9.3-rated flaw forces emergency upgrades, while the FBI and France take down two deepfake CSAM sites and arrest an admin.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Atlassian’s 9.3-rated flaw exposes eight Data Center products

Atlassian disclosed a critical arbitrary file access vulnerability, CVE-2026-21589, rated 9.3, affecting all versions of eight Data Center products: Bamboo, Bitbucket, Confluence, Crowd, Crucible, Fisheye, Jira Service Management, and Jira Software. The flaw needs no authentication or user interaction and lets attackers read files in web application root directories, with path traversal potentially reaching files outside the web root if the exact name and path are known. Atlassian found no evidence of exploitation in its already-patched cloud offerings and urged customers to move to the latest fixed maintenance release immediately, since it no longer ships binary patches. For those unable to patch, Atlassian advised removing instances from the internet and outlined limited temporary mitigations via WAF rules and Tomcat RewriteValve configurations.

Atlassian’s critical flaw turns eight enterprise products into one big security problem | CSO Online →

Topics: Patch Tuesday & security updates

FBI and France seize deepfake CSAM sites, arrest administrator

The FBI and French authorities seized two websites, NudeLeaksTeens and NLTVIDS, used to sell child sexual exploitation material including AI-generated deepfake media, and arrested a 25-year-old French resident suspected as primary administrator. The Paris Prosecutor’s Office cybercrime division made the arrest; a seizure warrant filed October 2 in the Eastern District of Virginia documented that law enforcement learned of the sites in 2024. The FBI executed a search warrant on VeriSign, taking servers and other material. One collection, 189GB covering 315 girls, sold for $64.90. The sites violated the TAKE IT DOWN Act, which criminalizes nonconsensual intimate deepfake media and gives the FTC enforcement authority.

FBI, French authorities seize deepfake CSAM-for-sale websites →

Topics: DeepfakesChildren's online safety

Ransomware recovery CEO charged over secret ransom payments

Zohar Pinhasi, 50, also known as Zack Silver and Zack Green, was indicted by a federal grand jury in the Eastern District of New York on September 23 and arraigned Wednesday in Brooklyn on one count of conspiracy to commit wire fraud and two counts of wire fraud. Prosecutors allege that Pinhasi, who owned Florida-based ransomware remediation company MonsterCloud LLC, advertised proprietary decryption tools but instead contacted ransomware operators, paid for decryption keys, and used them to restore customers’ files. In one incident he allegedly paid a gang about $8,200 and charged the victim roughly $150,000; in another he paid about $236,000 and charged about $380,000. The scheme allegedly facilitated over $8 million in ransom payments while billing hundreds of companies more than $19 million. He pleaded not guilty and was released on a $2 million bond, facing up to 20 years if convicted.

Ransomware recovery CEO charged over secret ransom payments →

Topics: RansomwareCybercrime arrests

PoeLLM malware builds botnet of 3,400 servers using a poem

Malware that takes technical cues from a poem to assemble a botnet targeting open-source AI services has compromised more than 3,400 servers since April, according to Lumen Technologies’ Black Lotus Labs. The poem, posted by a threat actor on GitHub, appears innocuous but drives stealthy malware researchers call PoeLLM. Four specific words extracted from the poem, changed at least a dozen times, are converted into a command-and-control server address through a hard-coded dictionary embedded in the malware, boosting its resiliency. Ryan English, information security engineer at Black Lotus Labs, said the C2 IP address is invisible outside the victim’s netflow. Researchers first encountered PoeLLM infrastructure in June while investigating a maximum-severity Ivanti Sentry defect, uncovering an exploit-scanning and cryptocurrency-mining botnet linked to LiteLLM, Ollama, Gotenberg and Gitea. The malware enables remote code execution, and Black Lotus Labs said the actor is likely Italian or speaks Italian.

PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem →

Topics: AI-powered malware

Hackers obtain counterfeit TLS certificates for Google and other services

Hackers obtained unauthorized TLS certificates for Google and other large services by hijacking three country-code top-level domains, according to Ars Technica. With control of the ccTLDs, attackers changed the IP addresses of selected websites, modified authoritative DNS records and nameserver delegations, and passed industry validation checks requiring proof of domain control. Google said Chrome took steps to identify and block suspected unauthorized certificates across the affected ccTLDs, but warned browser-side intervention should not be relied on to protect users. Google said the incident did not involve compromise of any affected domain owners’ infrastructure and that certificate authorities followed all requirements. It is unclear what other organizations were affected or how many unauthorized certificates were issued. With all known unauthorized certificates now blocked, the risk is mitigated, but undiscovered certificates still pose a threat.

Hackers obtain counterfeit TLS certificates for Google and other large services - Ars Technica →

Topics: GoogleEncryption

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches