Skip to content

Home/Digest/Past issues

Daily digest,

New Spectre v2 Variant BTR Exposes CPUs to Data Leaks (+7 more)

Vulnerabilities

New Spectre v2 Variant BTR Exposes CPUs to Data Leaks

Researchers from VUSec and Scuola Superiore Sant'Anna disclosed a new Spectre v2 variant named Branch Target Reuse (BTR) that affects Intel, AMD, and Arm CPUs. This attack targets just-in-time (JIT) compilers in operating systems, web browsers, and language runtimes, allowing attackers to steal sensitive data from memory, including password hashes. The BTR exploit leverages stale indirect branch prediction entries that persist after code modifications, enabling speculative execution attacks. Two end-to-end exploits have been developed against the Linux kernel, successfully leaking the root password hash at a rate of 8 bytes per second. The vulnerabilities have been assigned CVE-2026-64507 and CVE-2026-64508, with fixes already merged into the Linux kernel. The researchers have notified affected vendors, and while exploits are confirmed for Linux, a complete browser exploit is still under development. The attack demonstrates that self-modifying code can still be exploited despite previous assumptions of impracticality.

Vulnerability · 4 sources · score 73 · CVE-2026-64507, CVE-2026-64508, CVE-2026-65660, Spectre

Vega II Launches Amid Active Exploitation of CVE-2026-86950

On September 29, 2026, Vega introduced Vega II, an agentic cyber defense platform designed to enhance security operations centers (SOCs) by integrating advanced AI capabilities. This launch coincides with the active exploitation of CVE-2026-86950, a zero-day vulnerability that was published on September 28, 2026, and added to the CISA KEV list on the same day. The Vega II platform aims to overcome legacy SIEM limitations by enabling real-time detection, triage, and investigation of threats across all enterprise data sources. The platform is expected to significantly reduce investigation times and operational costs for security teams. As organizations face increasing threats from sophisticated attackers leveraging AI, Vega II seeks to empower defenders with a more effective toolset. The urgency of the situation is heightened by the rapid adoption of frontier AI by adversaries, making the need for advanced defensive measures critical.

APT · 3 sources · score 70 · CVE-2026-86950, ShinyHunters

Unsloth Studio Vulnerability Enables Code Execution via Model Inspection

A critical vulnerability in Unsloth Studio, an open-source library for fine-tuning LLMs, allows arbitrary code execution through model inspection. This flaw arises from the 'trust_remote_code=True' setting, which permits execution of Python code from a model's Hugging Face repository upon merely inspecting its metadata. The code runs with the user's permissions, potentially exposing sensitive data, model artifacts, and credentials in enterprise environments. While Unsloth has patched the vulnerability, there are disputes regarding the adequacy of security measures, with Pillar Security emphasizing the risks of untrusted code execution. No evidence of real-world exploitation has been reported, but the potential for significant impact remains. The vulnerability is associated with CVE-2026-46432, published on June 9, 2026.

Vulnerability · 2 sources · score 58 · CVE-2026-1839, CVE-2026-46432, CVE-2026-4944, CVE-2026-6859

OpenSSL Vulnerabilities Impact HCL VersionVault and DevOps Tools

Multiple vulnerabilities in OpenSSL have been disclosed, affecting HCL VersionVault and HCL DevOps Code ClearCase. Key vulnerabilities include CVE-2025-11187, which may lead to stack buffer overflow or NULL pointer dereference, and CVE-2025-66199, which allows large buffer allocation without size checks. Other notable vulnerabilities include CVE-2025-22795 and CVE-2025-22796, both leading to denial of service through malformed PKCS#12 and PKCS#7 data processing. The vulnerabilities were reported by the OpenSSL Project, with CVSS scores ranging from 5.3 to 6.1, indicating medium severity. Users of affected systems are advised to apply patches as they become available. The OpenSSL 4.0.3 release also addresses high-severity vulnerabilities, including CVE-2026-84782 and CVE-2026-84783, which were published on September 29, 2026. This highlights the ongoing need for vigilance in updating cryptographic libraries.

Vulnerability · 2 sources · score 57 · CVE-2025-11187, CVE-2025-22795, CVE-2025-22796, CVE-2025-66199, CVE-2026-84782

Breaches

Dodo Pizza Cyberattack Exposes Customer Data of 68 Million

Dodo Pizza confirmed a cyberattack on its IT systems, revealing that hackers gained access to personal data of its customers. The compromised information may include names, addresses, email addresses, phone numbers, dates of birth, and order history. The hacking group DataSuckers claimed responsibility, alleging they stole 2-3 TB of data affecting approximately 68 million customers across multiple countries. Dodo Pizza reported that it does not store payment information, so financial data was not compromised. The company has blocked access to the affected systems and is conducting an internal investigation. They have notified the Russian communications regulator, Roskomnadzor, about the incident. The claims made by DataSuckers regarding the scale of the breach and the data stolen remain unverified by independent sources.

APT · 3 sources · score 61 · Datasuckers

North Korea's Secret Detention Facility in Beijing Exposed

A human rights group has reported that North Korea operates a secret detention facility beneath its embassy in Beijing, where suspected defectors, including diplomats, are interrogated and prepared for forced repatriation. The Transitional Justice Working Group (TJWG) claims that detainees have their passports confiscated and face harsh interrogations. This facility reportedly targets North Koreans abroad, including students and workers with sensitive information. The operations are allegedly tolerated by Chinese authorities, raising concerns about human rights violations and China's judicial sovereignty. The report highlights that these actions are part of a broader campaign to monitor and track North Korean nationals overseas. The TJWG's findings were made public on September 28, 2026, prompting calls for international scrutiny of both North Korea and China's role in these activities.

Vulnerability · 2 sources · score 60 · Operation Fox Hunt

DIVD Hit by Agentic AI-Powered Cyberattack

The Dutch Institute for Vulnerability Disclosure (DIVD) reported a cyberattack attributed to an agentic AI, marking a significant breach after seven years of operation without incident. The attack was characterized as 'loud and very, very messy,' with the AI agent autonomously executing actions that left substantial evidence for investigation. DIVD has initiated a forensics investigation and informed relevant authorities, including the police and the National Cyber Security Centre. The exact impact and purpose of the attack remain unclear, but it exploited a technical vulnerability in an undisclosed system, which has not been identified as Citrix NetScaler. DIVD is treating the situation as a worst-case scenario and is focused on securing its infrastructure and supporting its volunteers. A public update is expected on October 1, 2026.

Breach · 3 sources · score 52

Waterford Hotel Group Data Breach Exposes Sensitive Personal Information

The Waterford Hotel Group reported a data breach on September 25, 2026, affecting sensitive information of individuals, including Social Security numbers and financial data. The breach was discovered on May 5, 2026, when suspicious activity was detected in their systems. Affected individuals include at least 242 Vermont residents, with potential nationwide impacts. The breach may have exposed names, driver's license numbers, passport numbers, taxpayer IDs, and health information. Legal investigations are underway to determine if a class action lawsuit can be filed against the company for inadequate cybersecurity measures. The incident has raised concerns about identity theft and financial fraud risks for those affected.

Breach · 2 sources · score 52

New on leak sites

63 victims listed on ransomware leak sites by 16 groups in the 24 hours before this issue. The most active:

Also moving

  • CVEs: CVE-2026-86950, CVE-2026-88771, CVE-2026-88772, CVE-2026-35273, CVE-2026-53131
  • Vulnerabilities: Citrix NetScaler
  • APT groups: ShinyHunters

Get the next one by email

The digest is free and arrives every morning. One click to leave.

Subscribe to the digest

A free account turns the digest into a personal watchlist: choose what you want to follow.