HeadFlash

Security

FBI Seizes Seven Domains Tied to Beijing's Flax Typhoon Hacking

US prosecutors unseal seizure of Integrity Technology Group domains used to scan and breach power companies, airports and universities worldwide.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

FBI Seizes Seven Domains Used by Beijing-Linked Flax Typhoon Hackers

The US government seized seven internet domains used by Integrity Technology Group, a Beijing company with Chinese government contracts, to support Flax Typhoon hacking activity. Prosecutors said the firm operated intrusion tools MicroScan and FishHub. Targets included a South Carolina power company, airports in Japan and Poland, and Taiwanese natural gas and power companies. MicroScan is a Python-based web application with over 1,300 penetration-testing scripts targeting OpenSSL, Oracle WebLogic, WordPress, Jenkins and Apache Struts. A federal magistrate authorized the seizures on October 6. US Attorney Troy Rivetti called it the second disruption of Integrity Tech’s operations in two years. The Treasury Department sanctioned the company in January 2025. No arrests were announced.

FBI Seizes Domains Used in Flax Typhoon Attacks →

Topics: State-sponsored hacking

New DarkSword Variant P7 Targets Unpatched iPhones via Malicious Ads

iVerify released a report detailing P7 DarkSword, a previously unseen variant of the DarkSword iPhone exploit chain uncovered earlier this year by Google and iVerify. The variant was found during an investigation of an infection on the iPhone of a financial institution employee in August 2026. P7 expands compatibility to iOS 18.7 and is distributed through malicious ads in watering-hole attacks, meaning victims may not be individually targeted. It improves stealth, stability and functionality, reduces logging, uses browser storage to avoid repeated exploitation, and expands data theft. P7 can extract Keychain data directly on the device and targets crypto-wallet data, adding two-way command-and-control communication. It checks in every 15 seconds by default. Earlier DarkSword activity prompted Apple to release iOS 15.8.7, iOS 16.7.15 and iOS 18.7.7.

Researchers uncover new DarkSword spyware variant affecting unpatched iPhones →

Topics: Spyware

Anthropic Launches Free OSS Scanner for Open-Source Security

Anthropic has launched OSS Scanner, a service providing free, opt-in security scans to open-source projects. Participating projects receive thorough, periodic vulnerability scans run by Anthropic’s strongest models at no cost. The reports are fully model-generated, with no human review or triage, which Anthropic says enables faster and more frequent scanning but means reports may be incorrect or invalid. The scans are produced by Anthropic’s strongest models, including Claude Mythos, to give open-source projects the largest defensive advantage. The service is positioned to alert open-source projects to possible security issues sooner.

Anthropic launches free AI security scans for open-source projects →

Topics: Anthropic

Let’s Encrypt to Cut Certificate Lifetimes to 64 Days in February 2027

Let’s Encrypt will reduce free SSL/TLS certificate lifetimes from 90 days to 64 days starting February 10, 2027. Administrators using modern ACME clients that support ARI (ACME Renewal Information) should see the change as seamless; those relying on hardcoded renewal schedules or manual processes must update before certificates begin expiring unexpectedly. Testing of the 64-day certificates begins October 14, with opt-in available for users to test their setups before production goes live. Before Let’s Encrypt launched in early 2016, certificates were often issued for one to three years; the service started with 90-day certificates to force renewal automation. Lifespans will continue to shorten, with 45-day defaults planned for 2028.

Let’s Encrypt cuts certificate lifetimes to 64 days starting February 2027 →

Topics: Encryption

NVIDIA DCGM Exporter Flaw Exposes GPU Servers to Denial of Service

NVIDIA DCGM Exporter, a tool for monitoring GPUs across AI servers and clusters, contained a high-severity vulnerability allowing an unauthenticated attacker to trigger uncontrolled resource consumption, causing denial of service and information disclosure. NVIDIA assigned it CVE-2026-47483 (CVSS 8.2, High) and published a security bulletin. About a quarter of exposed DCGM hosts served Go’s /debug/pprof/ profiling endpoints alongside /metrics; many concurrent unauthenticated requests drive increasing memory consumption. With enough requests, the exporter could run out of memory and crash, cutting off GPU health visibility. Four Shodan scans between March and May 2026 found roughly 2,100 hosts publicly serving DCGM Exporter metrics over plaintext HTTP with no authentication, exposing more than 12,000 unique GPU UUIDs. Recommended mitigations include upgrading DCGM Exporter to 4.8.2 or later and ensuring –enable-pprof is not enabled unless profiling is explicitly required.

CVE-2026-47483: NVIDIA DCGM Exporter Vulnerability Exposes GPU Servers | LAVA →

Topics: AI infrastructure & data centersPatch Tuesday & security updates

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches