| DEAFNEWS |
DEAFLETTER // SECURITY BRIEF |
|
|
VERIFIED SIGNALS // EDITORIAL SNAPSHOT
DeafLetter — week 39CISA Adds Three Linux Kernel CVEs to KEV With Three-Day Deadline for US Agencies | 01 // LEAD STORY LEAD // 01 CISA Adds Three Linux Kernel CVEs to KEV With Three-Day Deadline for US AgenciesCISA added three Linux kernel vulnerabilities to the Known Exploited Vulnerabilities catalog on September 18, 2026, giving federal civilian agencies until September 21 to patch. The directive is driven by confirmed active exploitation, not CVSS severity alone. Red Hat has flagged CVE-2025-39682 as high risk with public exploits available. OPEN REPORT → |
| 02 // THREE SIGNALS SIGNAL // 02 CenterPoint Energy Confirms Data Breach: 7 Million Customers' PII at RiskCenterPoint Energy filed an SEC Form 8-K on September 14, 2026, confirming a data breach in which an unauthorized actor accessed customer personal information through an external-facing system. The utility, serving roughly 7 million customers across Indiana, Minnesota, Ohio, and Texas, disclosed the incident after identifying a dark web post claiming the sale of stolen data. Electric and gas services were not disrupted, and no OT/SCADA impact has been identified. READ THE ANALYSIS → | SIGNAL // 03 PhantomRaven: The npm Malware Likely Written by an LLM to Fuel Bug Bounty FraudCrowdStrike has exposed PhantomRaven, a JavaScript infostealer distributed via npm and likely generated with an LLM. The financially motivated actor poses as a bug bounty hunter on platforms like HackerOne, Bugcrowd, and Intigriti but uses stolen credentials to manufacture vulnerabilities for payout rather than selling data on criminal markets. READ THE ANALYSIS → | SIGNAL // 04 CISA Confirms: CVE-2026-59310 in vCenter Now Exploited by RansomwareThe critical CVE-2026-59310 vulnerability in VMware vCenter, patched in July, has shifted from APT exploitation to ransomware attacks in a matter of weeks. CISA has flagged it as actively used in ransomware campaigns and mandated forensic triage under BOD 26-04. READ THE ANALYSIS → |
| 03 // CVES AND PATCHES CVE_PATCH // 05 JADEPUFFER Encrypts AI Weights with ENCFORGE: Phantom Ransom, Broken Payment MechanismThe agentic ransomware group JADEPUFFER struck Langflow infrastructure with ENCFORGE, a payload that encrypts AI models without a functioning ransom mechanism. Recovery costs for a single enterprise-ready fine-tuned model are estimated at $75,000–$500,000. READ THE ANALYSIS → | CVE_PATCH // 06 Infected PHP Themes on Streaming Sites: The iOS Chain That Empties Crypto WalletsThirteen compromised Packagist packages turn Vietnamese streaming sites into vectors for a WebKit-to-kernel exploit chain on iPhone, stealing seed phrases from seven cryptocurrency wallets. READ THE ANALYSIS → | CVE_PATCH // 07 Two Bugs in OpenAI Codex Break the Strictest Sandbox in Read-Only ModeOren Yomtov of Accomplish AI discovered and demonstrated two sandbox-escape vulnerabilities in OpenAI Codex — Heapjack and Overpatch — that allow unsandboxed command execution on the user's host machine, even in the most restrictive read-only mode. Both were reported on August 12, 2026 and patched by OpenAI within eight days. READ THE ANALYSIS → | CVE_PATCH // 08 npm Package indexed-btree Evades Install-Time Defenses With Runtime PayloadThe npm package indexed-btree, masquerading as the legitimate sorted-btree library and pulling nearly 2 million weekly downloads, hides its malicious payload inside the BTree.prototype.set() method. Execution triggers at runtime when the application calls the method, not during installation, bypassing npm v12's mandatory approval gates for install scripts introduced in June 2026. Checkmarx disclosed the campaign on September 20, 2026, revealing a first-stage obfuscated loader that harvests system details and communicates with a C2 orchestrated via an Ethereum smart contract on the Sepolia testnet. Nine additional npm packages linked to the operation have been removed from the registry. READ THE ANALYSIS → | CVE_PATCH // 09 BragJack: A Malicious Extension Hijacks Five AI Agents in Chromium BrowsersA proof-of-concept demonstrates how a pre-installed malicious extension can control AI agents in Chrome, Edge, Opera, Perplexity, and Claude. Two CVEs assigned. READ THE ANALYSIS → |
| 04 // THE GUIDE GUIDE // 10 Foundations of Ethical Security Testing with Python: A Beginner's Laboratory GuideYou have a terminal open and a fresh Kali ISO on your desktop, but no idea which command runs first—or whether that command is even legal. This guide is for that exact moment. We start from zero: installing Python, writing your first script, and understanding why a variable named `password` is not the same as a variable named `PASSWORD`. From there we build a vocabulary of defense—CIA triad, CVE, scope, responsible disclosure—and construct a legally isolated lab network we call Wintermute. Every attack category is taught from two angles: how it works conceptually, and how you would detect or block it. You will not find live exploit code against real targets here. You will find commented Python snippets, lab checklists, and the explicit requirement of written authorization before any technique leaves your virtual network. Sections 1–4 establish your toolkit and ground rules; Sections 5–9 walk network reconnaissance, web application flaws, DoS concepts, wireless and social vectors, and malware mechanics without executing dangerous payloads; Sections 10–11 consolidate everything into a capstone assessment and a troubleshooting reference for when your lab inevitably breaks. Read with a notebook, test only in machines you own, and treat every script as a defensive sensor in disguise.
**What you need:** a laptop with 8 GB RAM, VirtualBox or VMware, and patience for your first syntax errors.
**What you will not do:** run unmodified exploits against infrastructure you do not own. READ THE ANALYSIS → |
| | MANAGE PREFERENCES → | You receive this email because you subscribed to DeafLetter. Unsubscribe Samuel — DeafNews · Privacy | |