| DEAFNEWS |
DEAFLETTER // SECURITY BRIEF |
|
|
VERIFIED SIGNALS // EDITORIAL SNAPSHOT
DeafLetter — week 38PaperCut: 440 Servers Compromised by AI Agents — 11 Organizations Breached in 26 Seconds | 01 // LEAD STORY LEAD // 01 PaperCut: 440 Servers Compromised by AI Agents — 11 Organizations Breached in 26 SecondsA Russian-speaking threat actor deployed hundreds of AI agents on OpenAI Codex and DeepSeek to automate exploitation of two PaperCut NG/MF zero-days. The campaign compromised at least 440 instances across 395 organizations in 48 countries, with 11 victims breached in just 26 seconds and one U.S. school reaching domain admin in seven minutes. OPEN REPORT → |
| 02 // THREE SIGNALS SIGNAL // 02 Proxmox VE 7: Scans and Brute Force Exploit a Logging Blind SpotA SANS ISC diary documents brute-force attacks against Proxmox VE 7 where an authentication endpoint returns HTTP 200 even on failed logins, making the attacks invisible to monitoring that only watches for 401 responses. READ THE ANALYSIS → | SIGNAL // 03 AMD, Arm, and Nvidia: September 9 Patches for GPU and AI Inference VulnerabilitiesOn September 9, 2026, three chipmakers released coordinated security advisories: flawed GPU drivers and bugs in Nvidia's Triton Inference Server expose infrastructure. READ THE ANALYSIS → | SIGNAL // 04 GitLab Patches CVE-2026-85706: Path Traversal CVSS 10.0 in Self-Managed InstancesGitLab released critical patches on September 10 for CVE-2026-85706, a path traversal vulnerability with a CVSS 10.0 score that exposes arbitrary files to unauthenticated users via the repository commits API. GitLab.com is already protected, but self-managed instances—used by over half the Fortune 100—must upgrade immediately, facing mandatory downtime for database migrations on single-node deployments. READ THE ANALYSIS → |
| 03 // CVES AND PATCHES CVE_PATCH // 05 Tencent Patched the Sogou Flaw in 12 Days, But Left the Browser AloneChinese group UNC3569 compromised millions of Windows endpoints via Sogou Input Method, exploiting an embedded Chromium 80 browser with sandbox disabled. READ THE ANALYSIS → | CVE_PATCH // 06 FBI Certifies Death of Security Through Obscurity: AI Finds Bugs Where None Were ExpectedAI models have compromised open-source libraries trusted for a decade. A record 974 CVEs in Microsoft's September 2026 Patch Tuesday marks the end of a defensive era built on the assumption that obscurity equals safety. READ THE ANALYSIS → | CVE_PATCH // 07 Elastic Framework Detects Linux LPE: From CVE-Specific to Behavior-OrientedElastic Security Labs has released a detection engineering framework for Linux local privilege escalation that shifts from reactive per-CVE rules to a behavior-oriented approach. The framework identifies a common, detectable execution flow shared by most LPEs and adds bug-class-specific rules for categories like copy-on-write and zero-copy, which account for seven of the 13 LPEs Elastic tracked in a disclosure cluster from April to July 2026. The publication comes as LLM-assisted vulnerability discovery accelerates the pace of kernel disclosures. READ THE ANALYSIS → | CVE_PATCH // 08 Cl0p Adds Harley-Davidson to Leak Site; No Breach Evidence, Company SaysThe Cl0p ransomware gang listed Harley-Davidson on its data-leak site on September 10, 2026. The motorcycle maker has not confirmed any intrusion, the claim includes no sample files or technical indicators, and no independent source has verified access to the Milwaukee manufacturer's systems. READ THE ANALYSIS → | CVE_PATCH // 09 CISA and FBI: No PR Spin During IT/OT OutagesCISA and the FBI have issued joint guidance urging service providers to prioritize factual transparency and avoid marketing-driven narratives when communicating during IT and OT outages. READ THE ANALYSIS → |
| 04 // THE GUIDE GUIDE // 10 Foundations of Ethical Security Testing with Python: A Beginner's Laboratory GuideYou have a terminal open and a fresh Kali ISO on your desktop, but no idea which command runs first—or whether that command is even legal. This guide is for that exact moment. We start from zero: installing Python, writing your first script, and understanding why a variable named `password` is not the same as a variable named `PASSWORD`. From there we build a vocabulary of defense—CIA triad, CVE, scope, responsible disclosure—and construct a legally isolated lab network we call Wintermute. Every attack category is taught from two angles: how it works conceptually, and how you would detect or block it. You will not find live exploit code against real targets here. You will find commented Python snippets, lab checklists, and the explicit requirement of written authorization before any technique leaves your virtual network. Sections 1–4 establish your toolkit and ground rules; Sections 5–9 walk network reconnaissance, web application flaws, DoS concepts, wireless and social vectors, and malware mechanics without executing dangerous payloads; Sections 10–11 consolidate everything into a capstone assessment and a troubleshooting reference for when your lab inevitably breaks. Read with a notebook, test only in machines you own, and treat every script as a defensive sensor in disguise.
**What you need:** a laptop with 8 GB RAM, VirtualBox or VMware, and patience for your first syntax errors.
**What you will not do:** run unmodified exploits against infrastructure you do not own. READ THE ANALYSIS → |
| | MANAGE PREFERENCES → | You receive this email because you subscribed to DeafLetter. Unsubscribe Samuel — DeafNews · Privacy | |