Ivanti has rolled out security updates to address two security flaws impacting Ivanti Endpoint Manager Mobile (EPMM) that have been exploited in zero-day attacks.
CVE-2026-1281 (CVSS score: 9.8) - A code injection allowing attackers to achieve unauthenticated remote code execution
CVE-2026-1340 (CVSS score: 9.8) - A code injection allowing attackers to achieve unauthenticated remote code execution
They affect the following versions
EPMM 12.5.0.0 and prior, 12.6.0.0 and prior, and 12.7.0.0 and prior (Fixed in RPM 12.x.0.x)
EPMM 12.5.1.0 and prior and 12.6.1.0 and prior (Fixed in RPM 12.x.1.x)
CVE-2026-1281 (CVSS score: 9.8) - A code injection allowing attackers to achieve unauthenticated remote code execution
CVE-2026-1340 (CVSS score: 9.8) - A code injection allowing attackers to achieve unauthenticated remote code execution
They affect the following versions
EPMM 12.5.0.0 and prior, 12.6.0.0 and prior, and 12.7.0.0 and prior (Fixed in RPM 12.x.0.x)
EPMM 12.5.1.0 and prior and 12.6.1.0 and prior (Fixed in RPM 12.x.1.x)
Researchers map 175K publicly exposed Ollama LLM servers worldwide.
Tool-calling turns exposed AI into a highest-severity execution risk.
Tool-calling turns exposed AI into a highest-severity execution risk.
Google dismantles IPIDEA, a major residential proxy network.
GTIG says 550+ threat groups used it this month to hide espionage, cybercrime, and password-spray attacks by routing traffic through hijacked home devices worldwide.
GTIG says 550+ threat groups used it this month to hide espionage, cybercrime, and password-spray attacks by routing traffic through hijacked home devices worldwide.
Apple buys 'secretive' Israeli AI start-up Q.ai in reported $1.6 billion deal
Apple has acquired the Israeli AI start-up Q.ai in a deal reportedly worth $1.6 billion, making it the second largest acquisition in the company’s history. According to The Financial Times, Q.ai is a “secretive” firm known for technology that can interpret “silent speech” through facial expressions. Sources say the deal could value the start-up at nearly $2 billion.
Apple has acquired the Israeli AI start-up Q.ai in a deal reportedly worth $1.6 billion, making it the second largest acquisition in the company’s history. According to The Financial Times, Q.ai is a “secretive” firm known for technology that can interpret “silent speech” through facial expressions. Sources say the deal could value the start-up at nearly $2 billion.
Cyber Dispatch™️
Apple buys 'secretive' Israeli AI start-up Q.ai in reported $1.6 billion deal Apple has acquired the Israeli AI start-up Q.ai in a deal reportedly worth $1.6 billion, making it the second largest acquisition in the company’s history. According to The Financial…
The purchase reflects Apple’s push to strengthen its AI capabilities after recent setbacks and delays in rolling out the full features of Apple Intelligence.
Q.ai’s technology is already being used in smart headphones and glasses to detect subtle facial micro-movements, allowing users to control devices with minimal physical action. The acquisition comes as Apple seeks to close the gap in the AI race, alongside recent partnerships integrating Google’s Gemini system and OpenAI’s ChatGPT into its software ecosystem.
Q.ai’s technology is already being used in smart headphones and glasses to detect subtle facial micro-movements, allowing users to control devices with minimal physical action. The acquisition comes as Apple seeks to close the gap in the AI race, alongside recent partnerships integrating Google’s Gemini system and OpenAI’s ChatGPT into its software ecosystem.
Watering Hole Attack Targets EmEditor Users With Information-Stealing Malware.
U.S. Immigration and Customs Enforcement has increased its use of Israeli surveillance technology, including phone-hacking and data-extraction tools, enabling the tracking and identification of protesters.
China-linked UAT-8099 targets IIS servers in Asia using BadIIS SEO malware.
The group broke into vulnerable IIS servers, mainly in Thailand and Vietnam, using web shells and PowerShell. The aim remains SEO fraud, now tuned by region.
The group broke into vulnerable IIS servers, mainly in Thailand and Vietnam, using web shells and PowerShell. The aim remains SEO fraud, now tuned by region.
SmarterMail fixed a critical unauthenticated RCE in its email server software.
The flaw, CVE-2026-24423 (CVSS 9.3), lets attackers execute OS commands via a crafted remote server. It affects builds before 9511.
The flaw, CVE-2026-24423 (CVSS 9.3), lets attackers execute OS commands via a crafted remote server. It affects builds before 9511.
The tech giant Microsoft said it receives around 20 requests for BitLocker keys a year and will provide them to governments in response to valid court orders. But companies like Apple and Meta set up their systems so such a privacy violation isn’t possible.
Apple is testing a new iOS setting that reduces how precisely cellular networks can 📍 locate your device.
Limit Precise Location restricts location data to a broad area instead of an exact address.
Limit Precise Location restricts location data to a broad area instead of an exact address.
A campaign targets NGOs and individuals documenting human rights abuses.
HarfangLab tracks the activity as RedKitten, using Excel files themed around deceased protesters to deliver malware.
The tooling relies on GitHub, Google Drive, and Telegram for configuration and control, with indicators suggesting parts of the code may be LLM-assisted.
HarfangLab tracks the activity as RedKitten, using Excel files themed around deceased protesters to deliver malware.
The tooling relies on GitHub, Google Drive, and Telegram for configuration and control, with indicators suggesting parts of the code may be LLM-assisted.
Forwarded from ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ
Epstein's Shadow Hacker
Jeffrey Epstein's web of influence extended into the digital underworld, according to a bombshell Justice Department document released on January 31, 2026. An FBI informant's 2017 statement claims Epstein employed a "personal hacker"—a redacted Italian cybersecurity expert from Calabria with elite skills in zero-day exploits. This revelation, part of the ongoing Epstein Files disclosures, paints a chilling picture of how the late financier allegedly weaponized cutting-edge hacking talents.
The Hacker's Profile Emerges
The document describes the individual as a master of vulnerabilities in iOS, BlackBerry, and Firefox, crafting offensive cyber tools sold to governments including the US and UK. He reportedly built Saudi Arabia's cyber surveillance program and even sold a zero-day exploit to Hezbollah for a trunk of cash, which he laundered through a California theater company. Earning six-figure sums, he shunned deals with "incompetent" Italy and Asian buyers, preferring high-stakes clients backed by billionaires like Epstein.
Online sleuths can likely pinpoint him: his firm was acquired by CrowdStrike in fall 2017, after which he rose to Vice President. Epstein provided seed money alongside two other tycoons, one tied to a Japanese firm. The informant notes his ties to "old school" European hackers, including phonetic handles like "PH," blending old-world cybercrime with modern zero-days.
Implications for Cybersecurity Elite
This isn't just tabloid fodder—it's a stark reminder of blurred lines between private hacking prowess and criminal patronage. Epstein, known for compromising elites, may have leveraged this talent for surveillance or blackmail ops, mirroring his real-world tactics.
CrowdStrike's involvement demands scrutiny. Did due diligence miss these shadows during acquisition? Post-2017, as VP, could he have influenced endpoint security tools used globally?
Broader Cybercrime Echoes
Epstein's orbit intersects with recent headlines: Empire Market's co-founder pleading guilty to decades in prison; ShinyHunters breaching Crunchbase; CISA flagging exploited flaws in Ivanti, Fortinet, and Microsoft Office. Yet none rival the intrigue of a zero-day dealer bankrolled by a sex-trafficker.
For the hacker, fallout looms. Italian authorities may reopen probes, while US agencies question Epstein-era dealings. Hezbollah cash runs evoke state-sponsored cyber bazaars, where exploits fuel asymmetric warfare.
This story underscores cybersecurity's dark side: geniuses moonlighting for the highest bidder. Victims of Epstein's network deserve full unredacted files—allegations alone erode trust.
As Pierluigi Paganini warns on SecurityAffairs, one ponders why Epstein chose such a figure. The answer likely lies in power: digital dirt as leverage.
@TheGhostsITM
Jeffrey Epstein's web of influence extended into the digital underworld, according to a bombshell Justice Department document released on January 31, 2026. An FBI informant's 2017 statement claims Epstein employed a "personal hacker"—a redacted Italian cybersecurity expert from Calabria with elite skills in zero-day exploits. This revelation, part of the ongoing Epstein Files disclosures, paints a chilling picture of how the late financier allegedly weaponized cutting-edge hacking talents.
The Hacker's Profile Emerges
The document describes the individual as a master of vulnerabilities in iOS, BlackBerry, and Firefox, crafting offensive cyber tools sold to governments including the US and UK. He reportedly built Saudi Arabia's cyber surveillance program and even sold a zero-day exploit to Hezbollah for a trunk of cash, which he laundered through a California theater company. Earning six-figure sums, he shunned deals with "incompetent" Italy and Asian buyers, preferring high-stakes clients backed by billionaires like Epstein.
Online sleuths can likely pinpoint him: his firm was acquired by CrowdStrike in fall 2017, after which he rose to Vice President. Epstein provided seed money alongside two other tycoons, one tied to a Japanese firm. The informant notes his ties to "old school" European hackers, including phonetic handles like "PH," blending old-world cybercrime with modern zero-days.
Implications for Cybersecurity Elite
This isn't just tabloid fodder—it's a stark reminder of blurred lines between private hacking prowess and criminal patronage. Epstein, known for compromising elites, may have leveraged this talent for surveillance or blackmail ops, mirroring his real-world tactics.
CrowdStrike's involvement demands scrutiny. Did due diligence miss these shadows during acquisition? Post-2017, as VP, could he have influenced endpoint security tools used globally?
Broader Cybercrime Echoes
Epstein's orbit intersects with recent headlines: Empire Market's co-founder pleading guilty to decades in prison; ShinyHunters breaching Crunchbase; CISA flagging exploited flaws in Ivanti, Fortinet, and Microsoft Office. Yet none rival the intrigue of a zero-day dealer bankrolled by a sex-trafficker.
For the hacker, fallout looms. Italian authorities may reopen probes, while US agencies question Epstein-era dealings. Hezbollah cash runs evoke state-sponsored cyber bazaars, where exploits fuel asymmetric warfare.
This story underscores cybersecurity's dark side: geniuses moonlighting for the highest bidder. Victims of Epstein's network deserve full unredacted files—allegations alone erode trust.
As Pierluigi Paganini warns on SecurityAffairs, one ponders why Epstein chose such a figure. The answer likely lies in power: digital dirt as leverage.
@TheGhostsITM
انسحاب كامل لجيش الاحتلال بعد تدمير شارع الشالية خلف سوبر ماركت المجد شارع حيفا في مدينة جنين