π Cisco flags five critical NX-OS flaws on Nexus switches
Cisco has issued advisories for five critical vulnerabilities in NX-OS affecting Nexus 3000 and 9000 switches in standalone mode. The flaws impact NX-API, NGOAM, and MPLS OAM and can allow arbitrary code execution with root privileges or force device reloads. Exploitation depends on the affected features being enabled; Nexus 7000 and Nexus 9000 systems in ACI mode are not affected. Cisco recommends patching and disabling unused services in its NX-OS advisories.
Operationally, this is a control-plane risk for data center switching fabric rather than a generic edge-device issue. Feature exposure matters: NX-API and MPLS OAM are off by default, while NGOAM-linked attack paths depend on specific network services being active.
π°οΈ Open sources - closed narratives
@sitreports
Cisco has issued advisories for five critical vulnerabilities in NX-OS affecting Nexus 3000 and 9000 switches in standalone mode. The flaws impact NX-API, NGOAM, and MPLS OAM and can allow arbitrary code execution with root privileges or force device reloads. Exploitation depends on the affected features being enabled; Nexus 7000 and Nexus 9000 systems in ACI mode are not affected. Cisco recommends patching and disabling unused services in its NX-OS advisories.
Operationally, this is a control-plane risk for data center switching fabric rather than a generic edge-device issue. Feature exposure matters: NX-API and MPLS OAM are off by default, while NGOAM-linked attack paths depend on specific network services being active.
π°οΈ Open sources - closed narratives
@sitreports
π FakeGit reactivates at scale on GitHub
FakeGit has resumed activity with 17,610 malicious GitHub repositories distributing SmartLoader, with over 13,000 repos pushed in 34 hours and a peak of 2,999 per hour. Researchers found 97% of sampled commits only modified README files, and 88% redirected download buttons to ZIP archives installing SmartLoader. At least 700 accounts appear tied to legitimate developers. FakeGit has been active in similar form since January.
The campaignβs persistence comes from reuse, not rebuild: existing repos are simply re-pointed to fresh payload locations, while copies remain in forks, release assets, issue attachments, and separate hosting repos. This makes file-by-file takedowns and URL-based blocking structurally weak.
π°οΈ Open sources - closed narratives
@sitreports
FakeGit has resumed activity with 17,610 malicious GitHub repositories distributing SmartLoader, with over 13,000 repos pushed in 34 hours and a peak of 2,999 per hour. Researchers found 97% of sampled commits only modified README files, and 88% redirected download buttons to ZIP archives installing SmartLoader. At least 700 accounts appear tied to legitimate developers. FakeGit has been active in similar form since January.
The campaignβs persistence comes from reuse, not rebuild: existing repos are simply re-pointed to fresh payload locations, while copies remain in forks, release assets, issue attachments, and separate hosting repos. This makes file-by-file takedowns and URL-based blocking structurally weak.
π°οΈ Open sources - closed narratives
@sitreports
π‘ Ransomware disrupts Japanβs IDCF Cloud
IDC Frontier says a ransomware attack hit its IDCF Cloud platform on 7 October, forcing shutdown of network and systems in East Japan Region 1. The company says 495 firms and local governments are affected. Customer console access has been disabled across all regions during security checks, while the intrusion route and full scope remain under investigation.
This is a cloud infrastructure incident with direct downstream impact on public-sector and enterprise tenants. Isolation of one region and precautionary restrictions platform-wide indicate concern over lateral spread inside shared management layers, not just disruption at a single customer environment.
π°οΈ Open sources - closed narratives
@sitreports
IDC Frontier says a ransomware attack hit its IDCF Cloud platform on 7 October, forcing shutdown of network and systems in East Japan Region 1. The company says 495 firms and local governments are affected. Customer console access has been disabled across all regions during security checks, while the intrusion route and full scope remain under investigation.
This is a cloud infrastructure incident with direct downstream impact on public-sector and enterprise tenants. Isolation of one region and precautionary restrictions platform-wide indicate concern over lateral spread inside shared management layers, not just disruption at a single customer environment.
π°οΈ Open sources - closed narratives
@sitreports
π FBI details China-linked email access portal
The FBI says China-linked hackers operated a web portal that allowed third parties to search and retrieve stolen emails from compromised inboxes. The setup effectively turned harvested correspondence into a shared service, broadening access beyond the initial intrusion team, as outlined in the FBI findings.
Operationally, this indicates a structured exploitation pipeline rather than isolated mailbox theft. A portal model shortens the path from compromise to intelligence use, increases the value of each breach, and suggests centralized management of exfiltrated data across multiple users or customer sets.
π°οΈ Open sources - closed narratives
@sitreports
The FBI says China-linked hackers operated a web portal that allowed third parties to search and retrieve stolen emails from compromised inboxes. The setup effectively turned harvested correspondence into a shared service, broadening access beyond the initial intrusion team, as outlined in the FBI findings.
Operationally, this indicates a structured exploitation pipeline rather than isolated mailbox theft. A portal model shortens the path from compromise to intelligence use, increases the value of each breach, and suggests centralized management of exfiltrated data across multiple users or customer sets.
π°οΈ Open sources - closed narratives
@sitreports
π Nvidia patches high-severity DCGM Exporter flaw
Researchers identified roughly 2,100 internet-exposed GPU servers running Nvidia DCGM Exporter, with hundreds potentially vulnerable to CVE-2026-47483. The bug can let unauthenticated attackers trigger memory exhaustion and crash the GPU monitoring service. Nvidia fixed the issue in version 4.8.2.
The exposure is operationally significant because DCGM telemetry reveals GPU UUIDs, utilization, memory use, power data, and error events in plaintext over HTTP. That creates both a disruption path against AI infrastructure and a reconnaissance layer for mapping high-value GPU environments.
π°οΈ Open sources - closed narratives
@sitreports
Researchers identified roughly 2,100 internet-exposed GPU servers running Nvidia DCGM Exporter, with hundreds potentially vulnerable to CVE-2026-47483. The bug can let unauthenticated attackers trigger memory exhaustion and crash the GPU monitoring service. Nvidia fixed the issue in version 4.8.2.
The exposure is operationally significant because DCGM telemetry reveals GPU UUIDs, utilization, memory use, power data, and error events in plaintext over HTTP. That creates both a disruption path against AI infrastructure and a reconnaissance layer for mapping high-value GPU environments.
π°οΈ Open sources - closed narratives
@sitreports
π Flax Typhoon activity linked to five exploited flaws before CISA deadline
CISA has added five vulnerabilities tied to Flax Typhoon activity to its Known Exploited Vulnerabilities catalog, setting an October 11 remediation deadline for U.S. federal civilian agencies under BOD 22-01. The update places the China-linked intrusion set and the affected flaws into the federal patching queue through the Known Exploited Vulnerabilities catalog.
The move elevates these bugs from routine patching to active operational risk. Inclusion in KEV indicates confirmed exploitation, while the short compliance window signals urgent concern for exposed federal networks and prioritizes immediate asset identification, patching, and mitigation.
π°οΈ Open sources - closed narratives
@sitreports
CISA has added five vulnerabilities tied to Flax Typhoon activity to its Known Exploited Vulnerabilities catalog, setting an October 11 remediation deadline for U.S. federal civilian agencies under BOD 22-01. The update places the China-linked intrusion set and the affected flaws into the federal patching queue through the Known Exploited Vulnerabilities catalog.
The move elevates these bugs from routine patching to active operational risk. Inclusion in KEV indicates confirmed exploitation, while the short compliance window signals urgent concern for exposed federal networks and prioritizes immediate asset identification, patching, and mitigation.
π°οΈ Open sources - closed narratives
@sitreports
π SonicWall SMA1000 flaw moves from patch to active exploitation
SonicWall SMA1000 appliances are now seeing exploitation attempts against CVE-2026-102255, a maximum-severity issue patched three days earlier. The flaw affects the WorkPlace interface on SMA1000 6210, 7210, and 8200v, and can let a remote unauthenticated attacker force the appliance to issue internal requests and perform unauthorized operations.
The activity reportedly targeted the WorkPlace Extraweb path to reach internal CouchDB on 127.0.0.1:5984. With more than 400 SMA1000 devices exposed online and the platform already tied to repeated zero-day abuse in 2026, the window between disclosure, patching, and operational exploitation remains extremely short.
π°οΈ Open sources - closed narratives
@sitreports
SonicWall SMA1000 appliances are now seeing exploitation attempts against CVE-2026-102255, a maximum-severity issue patched three days earlier. The flaw affects the WorkPlace interface on SMA1000 6210, 7210, and 8200v, and can let a remote unauthenticated attacker force the appliance to issue internal requests and perform unauthorized operations.
The activity reportedly targeted the WorkPlace Extraweb path to reach internal CouchDB on 127.0.0.1:5984. With more than 400 SMA1000 devices exposed online and the platform already tied to repeated zero-day abuse in 2026, the window between disclosure, patching, and operational exploitation remains extremely short.
π°οΈ Open sources - closed narratives
@sitreports
π Working exploit released for pre-auth AnyDesk Linux root flaw
Researchers have published a working exploit for a pre-auth vulnerability in AnyDesk for Linux that can grant root access. The issue affects remote access software in a default high-privilege context, meaning an unauthenticated attacker can move from network reachability to full system compromise via AnyDesk for Linux.
The combination of pre-auth reachability, public exploit code, and root-level impact sharply reduces defender reaction time. Systems exposing AnyDesk on Linux now face a direct remote takeover path, making patch status, service exposure, and access controls immediate priorities.
π°οΈ Open sources - closed narratives
@sitreports
Researchers have published a working exploit for a pre-auth vulnerability in AnyDesk for Linux that can grant root access. The issue affects remote access software in a default high-privilege context, meaning an unauthenticated attacker can move from network reachability to full system compromise via AnyDesk for Linux.
The combination of pre-auth reachability, public exploit code, and root-level impact sharply reduces defender reaction time. Systems exposing AnyDesk on Linux now face a direct remote takeover path, making patch status, service exposure, and access controls immediate priorities.
π°οΈ Open sources - closed narratives
@sitreports
π Credential-stealing workflows seeded across GitHub repos
Malicious GitHub Actions workflows designed to steal credentials were reportedly planted in tens of thousands of repositories, creating a broad CI/CD supply-chain exposure inside developer environments. The activity abused repository automation, turning trusted build pipelines into collection points for secrets and tokens, as outlined in GitHub Actions workflows.
The significance is scale and access. Compromised workflows can harvest credentials during routine builds, giving attackers a path into codebases, package publishing, and downstream infrastructure without touching endpoint malware.
π°οΈ Open sources - closed narratives
@sitreports
Malicious GitHub Actions workflows designed to steal credentials were reportedly planted in tens of thousands of repositories, creating a broad CI/CD supply-chain exposure inside developer environments. The activity abused repository automation, turning trusted build pipelines into collection points for secrets and tokens, as outlined in GitHub Actions workflows.
The significance is scale and access. Compromised workflows can harvest credentials during routine builds, giving attackers a path into codebases, package publishing, and downstream infrastructure without touching endpoint malware.
π°οΈ Open sources - closed narratives
@sitreports
π Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Threat actors are reportedly using Google search ads and legitimate Bing redirects to steer users toward fake Claude installers that deliver ClickFix malware. The method blends paid placement with trusted redirect infrastructure to mask the final destination.
Operationally, the case highlights how legitimate ad ecosystems and redirect chains can be repurposed for initial access. For defenders, it reinforces the value of inspecting ad-driven traffic paths, installer provenance, and user exposure to spoofed AI-branded software.
π°οΈ Open sources - closed narratives
@sitreports
Threat actors are reportedly using Google search ads and legitimate Bing redirects to steer users toward fake Claude installers that deliver ClickFix malware. The method blends paid placement with trusted redirect infrastructure to mask the final destination.
Operationally, the case highlights how legitimate ad ecosystems and redirect chains can be repurposed for initial access. For defenders, it reinforces the value of inspecting ad-driven traffic paths, installer provenance, and user exposure to spoofed AI-branded software.
π°οΈ Open sources - closed narratives
@sitreports
π AWS AgentCore exposed credentials via agent prompt
Researchers from Zenity Labs found that a single prompt to an internet-exposed Bedrock AgentCore agent could retrieve IMDS credentials. The reported chain involved IMDSv1 exposure, weak Firecracker MicroVM isolation, and overly broad default IAM permissions, enabling access to other agents, ECR images, sessions, memory writes, and secrets. AWS later shifted AgentCore to IMDSv2 and says remaining issues were fixed by late September 2026.
The case shows how LLM agent surfaces can break cloud trust boundaries when metadata access, SSRF paths, and overprivileged regional roles overlap. Temporary credentials could reportedly pivot across agents, users, and stored conversations within the same account and region.
π°οΈ Open sources - closed narratives
@sitreports
Researchers from Zenity Labs found that a single prompt to an internet-exposed Bedrock AgentCore agent could retrieve IMDS credentials. The reported chain involved IMDSv1 exposure, weak Firecracker MicroVM isolation, and overly broad default IAM permissions, enabling access to other agents, ECR images, sessions, memory writes, and secrets. AWS later shifted AgentCore to IMDSv2 and says remaining issues were fixed by late September 2026.
The case shows how LLM agent surfaces can break cloud trust boundaries when metadata access, SSRF paths, and overprivileged regional roles overlap. Temporary credentials could reportedly pivot across agents, users, and stored conversations within the same account and region.
π°οΈ Open sources - closed narratives
@sitreports
π US disrupts China-linked Integrity Tech cyber toolset
The US Justice Department and FBI seized Microscan and FishHub, two tools tied to Beijing-based Integrity Technology Group, a contractor with PRC government links. Court filings say the platforms were used to scan and in some cases penetrate US and foreign critical infrastructure, with reported targets including power utilities, airports, NGOs, and universities in Taiwan.
The action targets an enabling layer rather than a single intrusion set. The case highlights how contractor-run platforms can combine large-scale reconnaissance, spear-phishing, and malware delivery to support state-linked access operations across multiple sectors and jurisdictions.
π°οΈ Open sources - closed narratives
@sitreports
The US Justice Department and FBI seized Microscan and FishHub, two tools tied to Beijing-based Integrity Technology Group, a contractor with PRC government links. Court filings say the platforms were used to scan and in some cases penetrate US and foreign critical infrastructure, with reported targets including power utilities, airports, NGOs, and universities in Taiwan.
The action targets an enabling layer rather than a single intrusion set. The case highlights how contractor-run platforms can combine large-scale reconnaissance, spear-phishing, and malware delivery to support state-linked access operations across multiple sectors and jurisdictions.
π°οΈ Open sources - closed narratives
@sitreports
π« Germany arrests alleged core Qilin member after extradition
Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group after extradition from Japan, where he was detained on arrival as a tourist. Japanβs National Police Agency confirmed the transfer. Qilin, active since 2022, has targeted more than 2,350 organizations in 62 countries.
The case marks a cross-border law enforcement action against a central figure in a major RaaS operation, but it does not indicate disruption of Qilinβs operational tempo. The group reportedly continued listing victims after the suspectβs detention, underscoring its resilience beyond a single arrest.
π°οΈ Open sources - closed narratives
@sitreports
Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group after extradition from Japan, where he was detained on arrival as a tourist. Japanβs National Police Agency confirmed the transfer. Qilin, active since 2022, has targeted more than 2,350 organizations in 62 countries.
The case marks a cross-border law enforcement action against a central figure in a major RaaS operation, but it does not indicate disruption of Qilinβs operational tempo. The group reportedly continued listing victims after the suspectβs detention, underscoring its resilience beyond a single arrest.
π°οΈ Open sources - closed narratives
@sitreports
π GoBalance flaw exposes Tor-format keys behind .onion services
A vulnerability in GoBalance allows attackers to recover Tor-format private keys and hijack associated .onion addresses. The issue affects hidden services whose key material can be derived and reused, enabling unauthorized control of the destination identity behind the onion address.
Operationally, this breaks one of the core trust assumptions of Tor hidden services: address ownership tied to private key secrecy. If exploited, the flaw enables silent service takeover rather than simple disruption, with direct implications for authentication, continuity, and attribution in dark web infrastructure.
π°οΈ Open sources - closed narratives
@sitreports
A vulnerability in GoBalance allows attackers to recover Tor-format private keys and hijack associated .onion addresses. The issue affects hidden services whose key material can be derived and reused, enabling unauthorized control of the destination identity behind the onion address.
Operationally, this breaks one of the core trust assumptions of Tor hidden services: address ownership tied to private key secrecy. If exploited, the flaw enables silent service takeover rather than simple disruption, with direct implications for authentication, continuity, and attribution in dark web infrastructure.
π°οΈ Open sources - closed narratives
@sitreports
π FBI makes another ShinyHunters-linked arrest after agency breach
FBI Director Kash Patel said agents arrested another suspected ShinyHunters co-conspirator tied to the recent FBIJobs intrusion. Public details remain limited, but the suspect is reported to be a Canadian citizen arrested in Pennsylvania. The breach was previously linked to a third-party vendor platform that failed to apply a security update.
The arrest adds to a fast-moving pressure campaign against ShinyHunters following earlier detentions in the Netherlands and Jordan. Operationally, the sequence indicates coordinated law-enforcement disruption focused not just on infrastructure, but on the network of operators and facilitators behind recent extortion activity.
π°οΈ Open sources - closed narratives
@sitreports
FBI Director Kash Patel said agents arrested another suspected ShinyHunters co-conspirator tied to the recent FBIJobs intrusion. Public details remain limited, but the suspect is reported to be a Canadian citizen arrested in Pennsylvania. The breach was previously linked to a third-party vendor platform that failed to apply a security update.
The arrest adds to a fast-moving pressure campaign against ShinyHunters following earlier detentions in the Netherlands and Jordan. Operationally, the sequence indicates coordinated law-enforcement disruption focused not just on infrastructure, but on the network of operators and facilitators behind recent extortion activity.
π°οΈ Open sources - closed narratives
@sitreports