| DEAFNEWS |
DEAFLETTER // SECURITY BRIEF |
|
|
VERIFIED SIGNALS // EDITORIAL SNAPSHOT
DeafLetter — week 36CVE-2026-18963: Keycloak Account Takeover in Seconds, Bypassing MFA | 01 // LEAD STORY LEAD // 01 CVE-2026-18963: Keycloak Account Takeover in Seconds, Bypassing MFAA critical flaw in Keycloak's password-reset flow lets an unauthenticated attacker seize any account — including admins — in roughly five seconds, rendering email verification and multi-factor authentication useless. Red Hat published the advisory on August 18, 2026, assigning a CVSS 9.1 score. Patched versions are 26.7.2, 26.4.15, and 26.6.6; the only documented mitigation for unpatched systems is disabling the "Forgot password" feature. OPEN REPORT → |
| 02 // THREE SIGNALS SIGNAL // 02 ShinyHunters Hits 100+ Universities with Oracle Zero-Day CVSS 9.8The ShinyHunters group exploited CVE-2026-35273, an unauthenticated RCE in Oracle PeopleSoft, against more than 100 organizations before the June 10 advisory. READ THE ANALYSIS → | SIGNAL // 03 ZBT Routers Ship With Two Factory Firmware Implants Granting Unauthenticated Remote Root. No Patch AvailableVulnCheck disclosed on August 27, 2026 that ZBT routers sold worldwide — including in Italy — contain two factory-installed implants, SPEAKINGSTONE (CVE-2026-74232) and DARKLANTERN (CVE-2026-74233), both providing unauthenticated remote root command execution. Both score CVSS 9.8. As of August 28, no firmware update removing the implants has been confirmed. READ THE ANALYSIS → | SIGNAL // 04 First Car Head Unit Malware Discovered: Vehicles Recruited into Proxy BotnetKaspersky has identified the first malware with a dedicated infection chain for Android automotive head units. It exploits the privileged system app TWCore to infiltrate vehicles into a proxy botnet monetized by the MoYu Group. The vehicle shows no driving anomalies; it silently becomes a traffic relay node, leveraging onboard cellular and Wi-Fi connectivity. READ THE ANALYSIS → |
| 03 // CVES AND PATCHES CVE_PATCH // 05 PaperCut Issues Back-to-Back Emergency Patches for Actively Exploited Zero-DaysPaperCut released two emergency patches within 24 hours for CVE-2026-81578 and CVE-2026-82078. The first patch was bypassed, leaving the pre-authentication RCE chain active. READ THE ANALYSIS → | CVE_PATCH // 06 DOJ Corrects Record: NASA and Senate Were QTFY Targets, Not VictimsThe U.S. Department of Justice revised its August 26 statement on August 29, 2026, clarifying that NASA, the U.S. Senate, and the Federal Reserve were targets of reconnaissance by the Chinese-linked QTFY group, not victims of successful intrusions. The correction aligns the public release with the FBI affidavit supporting domain seizures, which confirms successful breaches at three DOE national labs, the NIH, an HHS agency, and a U.S. security-device manufacturer in September 2024. READ THE ANALYSIS → | CVE_PATCH // 07 TheHatman and the 3.6 Million Azure Records: The Gap Between Claim and ConfirmationThreat actor TheHatman listed roughly 3.6 million records from the Azure directories of nine corporations for sale. Three companies deny a breach occurred; six have issued no public statement. The case centers on data circulating on criminal forums, disputed relevance, and an access chain that exploits legitimate Microsoft Azure/Entra ID functionality. READ THE ANALYSIS → | CVE_PATCH // 08 TA4922 Launches PackClient Campaigns in Asia: Modular RAT Bought on TelegramChinese threat group TA4922 deployed the PackClient RAT framework across China and India via tax-themed phishing between May and July 2026. The malware, purchased as a commercial kit on Chinese-language Telegram marketplaces, features over 60 commands, dual C2 channels, and a plugin architecture — capabilities once reserved for advanced actors, now sold as standardized merchandise. READ THE ANALYSIS → | CVE_PATCH // 09 Ransomware Hits Norcross: A City’s Technical Silence After a Partial TakedownThe city of Norcross, Georgia, confirmed a ransomware attack identified on August 1, 2026. Most systems are back online, but the public advisory—issued nearly four weeks later—omits the ransomware variant, initial access vector, ransom demand, and whether sensitive data was stolen. READ THE ANALYSIS → |
| 04 // THE GUIDE GUIDE // 10 Foundations of Ethical Security Testing with Python: A Beginner's Laboratory GuideYou have a terminal open and a fresh Kali ISO on your desktop, but no idea which command runs first—or whether that command is even legal. This guide is for that exact moment. We start from zero: installing Python, writing your first script, and understanding why a variable named `password` is not the same as a variable named `PASSWORD`. From there we build a vocabulary of defense—CIA triad, CVE, scope, responsible disclosure—and construct a legally isolated lab network we call Wintermute. Every attack category is taught from two angles: how it works conceptually, and how you would detect or block it. You will not find live exploit code against real targets here. You will find commented Python snippets, lab checklists, and the explicit requirement of written authorization before any technique leaves your virtual network. Sections 1–4 establish your toolkit and ground rules; Sections 5–9 walk network reconnaissance, web application flaws, DoS concepts, wireless and social vectors, and malware mechanics without executing dangerous payloads; Sections 10–11 consolidate everything into a capstone assessment and a troubleshooting reference for when your lab inevitably breaks. Read with a notebook, test only in machines you own, and treat every script as a defensive sensor in disguise.
**What you need:** a laptop with 8 GB RAM, VirtualBox or VMware, and patience for your first syntax errors.
**What you will not do:** run unmodified exploits against infrastructure you do not own. READ THE ANALYSIS → |
| | MANAGE PREFERENCES → | You receive this email because you subscribed to DeafLetter. Unsubscribe Samuel — DeafNews · Privacy | |