Can this double-SIMPLEBLOB footer behavior in an AES-256/RSA CryptoAPI ransomware indicate an exploitable key-management bug? [migrated]

I am analyzing an unknown ransomware that appends .BRKD.
Normal encrypted files have the structure:

[AES ciphertext]
[12-byte CryptoAPI SIMPLEBLOB header]
[256-byte RSA-wrapped session key]
[8-byte ciphertext length]

The header is consis… Continue reading Can this double-SIMPLEBLOB footer behavior in an AES-256/RSA CryptoAPI ransomware indicate an exploitable key-management bug? [migrated]

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws.
The post Oracle Patches 800+ Vulnerabilities in September 2026 Security Update appeared first on SecurityWeek.
Continue reading Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

NIST and CISA finalize playbook to stop token theft and forgery

NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST… Continue reading NIST and CISA finalize playbook to stop token theft and forgery

What happens when AI agent governance is missing at scale

In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what an agent does, since agents can chan… Continue reading What happens when AI agent governance is missing at scale

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.

“This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary fil… Continue reading Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Posted in Uncategorized

DeepZero: Open-source hunting for vulnerable Windows drivers

DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether what … Continue reading DeepZero: Open-source hunting for vulnerable Windows drivers

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr.

The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographi… Continue reading Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

Posted in Uncategorized