<?xml version="1.0" encoding="UTF-8" ?><feed xmlns="http://www.w3.org/2005/Atom">
    <title>Babgond</title>
    <subtitle>Babgond</subtitle>
    <id>https://babgond.com/moonmoonApple_v9/</id>
    <link rel="self" type="application/atom+xml" href="https://babgond.com/moonmoonApple_v9/atom.php" />
    <link rel="alternate" type="text/html" href="https://babgond.com/moonmoonApple_v9/" />
    <updated>2026-09-14T08:29:02Z</updated>
    <author><name>Babgond</name></author>


    <entry>
        <title type="html">IT-Sentinel : Paylogix</title>
        <id>https://www.ransomware.live/id/cGF5bG9naXguY29tQDIwMjYtMTEtMTg=</id>
        <link rel="alternate" href="https://www.ransomware.live/id/cGF5bG9naXguY29tQDIwMjYtMTEtMTg="/>
        <published>2026-11-18T01:00:00+00:00</published>
        <updated>2026-11-18T01:00:00+00:00</updated>
        <author><name>akira</name></author>

        <content type="html"><![CDATA[<div>La société de gestion des avantages sociaux Paylogix a été victime d'une cyberattaque. Des pirates informatiques ont volé des informations sensibles, y compris des numéros de sécurité sociale, des données financières, des informations de santé et des numéros de passeport, appartenant à des dizaines de milliers de personnes. L'incident, qui a eu lieu entre le 13 et le 18 novembre, a été revendiqué par l'enseigne de ransomware Akira en janvier 2026.</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : ISC Stormcast For Monday, September 14th, 2026 https://isc.sans.edu/podcastdetail/10092, (Mon, Sep 14th)</title>
        <id>https://isc.sans.edu/diary/rss/33334</id>
        <link rel="alternate" href="https://isc.sans.edu/diary/rss/33334"/>
        <published>2026-09-14T04:00:00+00:00</published>
        <updated>2026-09-14T04:00:00+00:00</updated>
        <author><name>anonymous</name></author>

        <content type="html"><![CDATA[]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : &lt;div&gt;Thorough reorganization at NSA will create five &amp;amp;#039;mission centers,&amp;amp;#039; including cyber and AI&lt;/div&gt;</title>
        <id>https://therecord.media/nsa-reorganization-five-mission-centers</id>
        <link rel="alternate" href="https://therecord.media/nsa-reorganization-five-mission-centers"/>
        <published>2026-09-13T23:36:00+00:00</published>
        <updated>2026-09-13T23:36:00+00:00</updated>
        <author><name>anonymous</name></author>

        <content type="html"><![CDATA[<div>The largest electronic spy agency in the world is reorganizing. And fast.</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114</title>
        <id>https://securityaffairs.com/198980/breaking-news/security-affairs-malware-newsletter-round-114.html</id>
        <link rel="alternate" href="https://securityaffairs.com/198980/breaking-news/security-affairs-malware-newsletter-round-114.html"/>
        <published>2026-09-13T19:27:00+00:00</published>
        <updated>2026-09-13T19:27:00+00:00</updated>
        <author><name>Pierluigi Paganini</name></author>

        <content type="html"><![CDATA[<div>Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape



Malware Newsletter



REVSTEALER ramps up



Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode  



GuardBreaker: Derailing AI-assisted malware analysis with a code comment  



DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors  



BengalSEO Part 1: Anatomy of the Operation



Dissecting a PHP web server rootkit



Signing in without actually signing in  



Active exploitation of Cisco Secure Firewall Management Center vulnerabilities  



Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 &amp; CVE-2026-82329



Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration     



Windows Malware Detector as a Compound AI System: Trade-Offs in Accuracy, Efficiency, and Adversarial Robustness



Why Is SHAP Not a Reliable Standalone Explanation Framework for Malware Detection?



Metadata Compressibility and Evaluation Bias in Malicious Package Detection for NPM and PyPI



FusionDroid: A Lightweight Multimodal Android Malware Detection Framework for Mobile Security



Follow me on Twitter: @securityaffairs and Facebook and Mastodon



Pierluigi Paganini



(SecurityAffairs – hacking, newsletter)</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : Hackers exploit Tencent app flaw to deploy GrayRabbit malware</title>
        <id>https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/</id>
        <link rel="alternate" href="https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/"/>
        <published>2026-09-13T16:26:00+00:00</published>
        <updated>2026-09-13T16:26:00+00:00</updated>
        <author><name>Bill Toulas</name></author>

        <content type="html"><![CDATA[<div>Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : Security Affairs newsletter Round 594 by Pierluigi Paganini – INTERNATIONAL EDITION</title>
        <id>https://securityaffairs.com/198957/security/security-affairs-newsletter-round-594-by-pierluigi-paganini-international-edition.html</id>
        <link rel="alternate" href="https://securityaffairs.com/198957/security/security-affairs-newsletter-round-594-by-pierluigi-paganini-international-edition.html"/>
        <published>2026-09-13T16:23:00+00:00</published>
        <updated>2026-09-13T16:23:00+00:00</updated>
        <author><name>Pierluigi Paganini</name></author>

        <content type="html"><![CDATA[<div>A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.



Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.



The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open InternetAttackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomwareUK Council Attack Linked to Mass Exploitation of SonicWall FlawU.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalogMore Capable AI, Not Enough GuardrailsA New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World HarmU.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalogFour Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 DaysUS Agencies Warn Chinese AI Firms Are Extracting Advanced AI ModelsGoogle fixes the seventh actively exploited Chrome zero-day of 2026PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server MemoryChaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-DayMicrosoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable BugsHackers Drain $320 Million From Liquid Network, Then Return Most of ItWeChat Worm Can Hijack Accounts Without Victims Answering CallsMassive Vietnam-Linked APIS Database Exposes Passport and Flight DataNorth Korea-linked Hackers Hide a Backdoor Inside HAProxyIT Help Desk Impersonation Lets Hackers Bypass MFACondé Nast Data of 32.8 Million Users Offered for Sale After WIRED LeakStyleSmuggler: The Magento Zero-Day Behind New Store AttacksChaotic Eclipse Released GreenSection, A PoC For NVIDIA Memory Corruption Zero-DayJSCeal Hides Crypto Malware in V8 BytecodeWhy AI Agent Sandboxes Are Failing Security TestsBerlin Ransomware Leak Exposes State SecretsYour MikroTik Router May Already Be Compromised: Look for SSH User “-2”AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure



International Press – Newsletter



Cybercrime



Berlin launches crisis response after hackers publish stolen data



2026-09-03: Cloud Data Theft and Extortion via IT Help Desk Vishing and Residential Proxies  



Berlin cyberattack: hackers leak highly sensitive data across dark web 



Condé Nast: 32.8M user records for sale, sample verified  



BengalSEO Part 1: Anatomy of the Operation  



Hackers Drain $320 Million From Bitcoin’s Liquid Network, Keep $47 Million for Themselves in ‘White Hat’ Operation  



Passkey-themed social engineering leads to identity and cloud compromise  



Revolut confirms customer data breach through fake government requests  



Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware  



Malware



REVSTEALER ramps up



Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode  



Signing in without actually signing in  



Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 &amp; CVE-2026-82329



Hacking



Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended 



GreenSection PoC exploit



StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack  



WeWorm     



ShieldCrash  Windows Defender 0day Vulnerability 



CVE-2026-10520: Ivanti Sentry OS Command Injection Analysis  



Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox



UK Council Attack Linked to SonicWall SMA 1000 Campaign 



Active exploitation of Cisco Secure Firewall Management Center vulnerabilities



DeepSeek Harness &lt; 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing



Intelligence and Information Warfare  



DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors



Beyond Lazarus: Organization of DPRK cyber capabilities 



760,000 Leaked Logins and Five Spy Campaigns: Inside Pakistan’s Worst Cyber Year Yet



China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies  



Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days 



Cybersecurity



OpenAI acknowledges ‘wiki incident’ and need for more transparency around unintended AI behavior    



MikroTik ssh 0day exploitation in the wild  



Daybreak for Frontline Defenders: $1B to protect essential services  



OpenAI is building ‘automated shutdown’ capabilities for AI tools, letter to lawmakers says 



A horde of AI agents conspired against their creators



The September 2026 Security Update Review  



AI could kill all humans in next decade, warn experts: but how seriously should we take them?



An alignment assessment of recent cybersecurity incidents     



Detecting and countering misuse of AI: September 2026    



Best Practices Guide for Cyber Hygiene 



Health data breach: EUR 500,000 fine against HÔPITAL PRIVÉ DE LA LOIRE  



Follow me on Twitter: @securityaffairs and Facebook and Mastodon



Pierluigi Paganini



(SecurityAffairs – hacking, newsletter)</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up</title>
        <id>https://www.securityweek.com/anthropic-ceo-dario-amodei-says-ai-industry-needs-to-give-safety-measures-time-to-catch-up/</id>
        <link rel="alternate" href="https://www.securityweek.com/anthropic-ceo-dario-amodei-says-ai-industry-needs-to-give-safety-measures-time-to-catch-up/"/>
        <published>2026-09-13T15:27:00+00:00</published>
        <updated>2026-09-13T15:27:00+00:00</updated>
        <author><name>Associated Press</name></author>

        <content type="html"><![CDATA[<div>Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet.
The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared first on SecurityWeek.</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : Chess.com (2026) - 4,653,212 breached accounts</title>
        <id>https://haveibeenpwned.com/Breach/Chess2026</id>
        <link rel="alternate" href="https://haveibeenpwned.com/Breach/Chess2026"/>
        <published>2026-09-13T15:09:00+00:00</published>
        <updated>2026-09-13T15:09:00+00:00</updated>
        <author><name>anonymous</name></author>

        <content type="html"><![CDATA[<div>In August 2026, millions of records allegedly sourced from Chess.com were posted online. The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches.</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours</title>
        <id>https://securityaffairs.com/198945/hacking/gitlab-cve-2026-85706-one-http-request-no-authentication-full-file-read-exploited-within-24-hours.html</id>
        <link rel="alternate" href="https://securityaffairs.com/198945/hacking/gitlab-cve-2026-85706-one-http-request-no-authentication-full-file-read-exploited-within-24-hours.html"/>
        <published>2026-09-13T14:26:00+00:00</published>
        <updated>2026-09-13T14:26:00+00:00</updated>
        <author><name>Pierluigi Paganini</name></author>

        <content type="html"><![CDATA[<div>CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.



GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. 



CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request may expose SSH keys, database credentials, deploy tokens, CI/CD variables, and other sensitive configuration data.



By September 11, active probing and exploitation attempts were already underway. CISA has since added the flaw to its Known Exploited Vulnerabilities catalog.



watchTowr researchers are already seeing in-the-wild probes targeting CVE-2026-85706. 



“watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request.” the company wrote on LinkedIn.



“Organizations with public-facing self-hosted GitLab instances should patch as soon as possible or remove public access.



Defenders should also hunt through log files for HTTP POST requests to “/api/v4/projects/{id}/repository/commits/” URIs containing “file.path” parameters to identify potential exploitation attempts.”



Given how quickly attackers exploit similar GitLab flaws, organizations should patch immediately or remove public access. Defenders should also check logs for suspicious POST requests to GitLab’s repository commit API containing file.path parameters, which may indicate exploitation attempts.



All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected. GitLab assigned the vulnerability a CVSS score of 10.0. The same update cycle also patches CVE-2026-87719, an insecure deserialization flaw that could expose advanced search configuration and credentials, providing an additional reason to upgrade rather than look for narrower workarounds.







The detection query is useful because a file.path parameter in a POST request to the commits API can signal an exploitation attempt. 



After patching, organizations should also rotate any credentials that exposed files may have contained, including tokens, SSH keys, CI/CD variables, and cloud keys. First check for signs of compromise so defenders can identify which credentials need rotation and expand the response if they find evidence of successful exploitation.



GitLab has seen similar path traversal flaws exploited quickly. CVE-2023-2825, which also allowed arbitrary file reads, faced active attacks just days after disclosure. CVE-2026-85706 followed the same pattern, with attackers starting probes even faster than expected. 



Organizations should treat the flaw as an urgent threat, not wait for widespread exploitation to begin.



Follow me on Twitter: @securityaffairs and Facebook and Mastodon



Pierluigi Paganini



(SecurityAffairs – hacking, CVE-2026-85706)</div>]]></content>
    </entry>


    <entry>
        <title type="html">IT-Sentinel : Security through obscurity is dead, and AI delivered the fatal blow</title>
        <id>https://www.theregister.com/security/2026/09/13/security-through-obscurity-is-dead-and-ai-delivered-the-fatal-blow/5296000</id>
        <link rel="alternate" href="https://www.theregister.com/security/2026/09/13/security-through-obscurity-is-dead-and-ai-delivered-the-fatal-blow/5296000"/>
        <published>2026-09-13T13:21:00+00:00</published>
        <updated>2026-09-13T13:21:00+00:00</updated>
        <author><name>anonymous</name></author>

        <content type="html"><![CDATA[<div>The term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency. Now it’s obsolete. Don’t believe us? Here’s proof. Software vendors and independent researchers alike are now using AI agents to find bugs – some very obscure and decades old – across products and open source code, leading to record-breaking numbers of security disclosures and patches, and a massive backlog for project maintainers. “You see open source platforms that have been visible to the tech community for a decade, these libraries that are run in 80 percent of web servers out there, people have stress-tested those for 10 years, and the community believed that they were really secure,” Brett Leatherman, assistant director of the FBI's Cyber Division, told The Register. “The latest models were able to break those and say, ‘yeah, there’s significant vulnerabilities in here.’” Whether or not security through obscurity is dead “isn't even an opinion question,” Trend Micro’s Zero Day Initiative chief bug hunter Dustin Childs told The Register, the day after Microsoft’s record-breaking Patch Tuesday addressed 974 CVEs. “When you look at all of the components patched by Adobe and Microsoft yesterday, you see components no one has talked about in years,” Childs said. “Telnet client – is this even still used in any secure environment? Windows RNDIS – the USB-networking protocol Microsoft has been trying to deprecate for years. NFS Portmapper – 1980s Unix tech. And Link Layer Topology Discovery – the Vista-era network-map protocol nobody's thought about since Vista – just to name a few.” Meanwhile, attackers are also using AI to reverse-engineer fixes and find exploits within hours. In one recent case, at least four espionage crews, most suspected of links to China, slammed shut the “patch-gap” window for open source Chromium, using an exploit kit developed shortly after the maintainers released an upstream patch – but before the downstream stable release was pushed to users. What this means for OT security During interviews at Black Hat in August, both former US National Cyber Director Chris Inglis and John Hultquist, chief analyst at Google Threat Intelligence Group, told us that they worry about what this means for critical operational technologies and industrial control systems (ICS). These are the systems that ensure the lights turn on when people flip a switch, gas flows out of pumps, and safe drinking water pours from faucets – all critical services that people use daily, and assume will continue working reliably. The OT systems themselves often use obscure protocols and proprietary hardware and software, which historically made them black boxes, even to IT specialists and hackers. AI upended this assumption. It means that criminals don't need to be OT experts to carry out destructive cyberattacks on critical networks and facilities. They just have to ask an agent to learn everything about these systems and do the dirty work for them. A couple of weeks after Black Hat, five US agencies said that attackers used AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities. “This is not a theoretical risk – it is an active threat,” the feds warned. AI “is excellent at technical troubleshooting, at knowing obscure systems and helping you make your way through it, and this makes me very concerned about industrial control systems,” Hultquist told The Register in an interview last week. “They've been largely secured because the expertise was in a handful of people's heads, and that's not going to last forever,” he said. AI can be a useful guide for attackers studying not just the application layer, but also the operating system, and even down into the firmware, Hultquist added. “That's going to have implications for a lot of different areas of security, but definitely for industrial control systems.” However, while this undoubtedly means more work for sysadmins and defenders, burying this outdated idea of security through obscurity isn’t necessarily a bad thing. 'Never a winning strategy' “I've always been of the mind that security through obscurity was never a winning strategy,” Katie Moussouris, founder and CEO of bug bounty consultancy Luta Security and the fairy godmother of bug bounties, told The Register. “But that's because I've been a hacker for so long. The argument always fails in the face of someone who decides to turn their gaze towards your organization. If there is something to find, they will find it.” Plus, she added, AI makes hacking a whole lot easier. “People might not have familiarity with the particular tech stack that you're running, but that is no longer a barrier because AI has ingested everything, and an AI is going to help them enumerate weak spots, even if they themselves are not familiar with the particular tech stack that they are pointing an AI towards,” Moussouris said. However, finding bugs and other weaknesses has never been the big security problem, she added. “It’s triaging and prioritization and actually getting things fixed.” This, Moussouris said, has also been her biggest issue with the way that organizations implement bug bounty programs. “AI is shining that bright light on the wrong end of the security picture, and unfortunately, AI hasn't caught up on the defensive side,” Moussouris said. “We're not there with AI automated patching, remediation – anything of the sort.” A couple of recent studies back this up, both finding that AI-generated patches fail more than half of the time. 1Password’s research team took six CVEs disclosed since March, and produced 6,080 patches using two frontier models: OpenAI's ChatGPT-5.5 and Anthropic's Opus 4.8. “The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0 percent,” wrote Director of Security Research Keith Hoodlet, adding that even patches that did fix the flaw also mucked up the application’s behavior 20 percent of the time. This included things like changing “allow list” logic to “deny list” logic. “Conversely, LLM-generated patches did not resolve the vulnerability, added a new vulnerability, or both, an average 53.9% of the time,” Hoodlet said. Another study by app security shop Veracode found that, across more than 100 models and 80 coding tasks, the average security pass rate for AI-generated code was just 56 percent. “If people are telling you that you need to accelerate on the fixing side, and the defense side – that’s just not cutting it,” Moussouris said. “Orgs that are looking at this as we're going to throw more resources at finding and fixing bugs, and they're not investing in taking a look at their process failures that led to so many bugs – those organizations are going to die on the treadmill,” she added. “They will literally have a heart attack and die. Like there's no VO2 max that will make you fast enough to deal with all those bugs, and giving up is not the answer.” The answer, she says, is taking a more dynamic approach, assessing where your organization can find patterns that lead to a process improvement instead of patching vuln after vuln. “A lot of organizations don't even know how to measure their progress, so they are counting bugs and speed of fixing, which is one way to measure. We had this many criticals, and then we fixed them super fast, and we had this many high, this many medium,” Moussouris said. The number of flaws fixed is important, but it doesn’t show the entire picture, she added. This involves looking at types of vulnerabilities, too. “Like: We've got a lot of injection flaws. That's something we could solve with better, safer templates earlier in our CI/CD pipeline. This is something that we can prevent at scale, as opposed to fixing these like really easy to find and fix vulnerabilities really really fast.” ®</div>]]></content>
    </entry>


</feed>
