<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Shubham Chaudhary</title>
    <description>The latest articles on DEV Community by Shubham Chaudhary (@xpert4cyber).</description>
    <link>https://dev.to/xpert4cyber</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3949974%2Feaab38f0-db73-45a8-aec6-4f08adb516df.png</url>
      <title>DEV Community: Shubham Chaudhary</title>
      <link>https://dev.to/xpert4cyber</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/xpert4cyber"/>
    <language>en</language>
    <item>
      <title>FortiSandbox CVE-2026-26084 (CVSS 8.9): Unauthenticated Info Disclosure — Patch Now</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Mon, 14 Sep 2026 19:40:45 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/fortisandbox-cve-2026-26084-cvss-89-unauthenticated-info-disclosure-patch-now-1410</link>
      <guid>https://dev.to/xpert4cyber/fortisandbox-cve-2026-26084-cvss-89-unauthenticated-info-disclosure-patch-now-1410</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fr1w64qtq0whafpum05x9.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fr1w64qtq0whafpum05x9.jpg" alt=" " width="800" height="800"&gt;&lt;/a&gt;🚨 FortiSandbox CVE-2026-26084 (CVSS 8.9): Unauthenticated Info Disclosure — Patch Now&lt;/p&gt;

&lt;p&gt;Fortinet disclosed CVE-2026-26084 on Sep 9, 2026 — a CWE-284 Improper Access Control bug in FortiSandbox's web UI. An unauthenticated attacker can send a crafted HTTP request directly to internal API endpoints and pull sensitive data — no auth, no user interaction, no malware needed.&lt;/p&gt;

&lt;p&gt;Why devs/security engineers should care:&lt;br&gt;
FortiSandbox stores config data, sample metadata, and detection logs. Leaked data = recon gold for attackers mapping your detection logic before a bigger breach.&lt;/p&gt;

&lt;p&gt;Affected:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;FortiSandbox 5.0.0–5.0.5 → patch to 5.0.6+&lt;/li&gt;
&lt;li&gt;FortiSandbox 4.4.0–4.4.8 → patch to 4.4.9+&lt;/li&gt;
&lt;li&gt;FortiSandbox Cloud/PaaS 5.0.4–5.0.5 → patch to 5.0.6+
Safe: FortiSandbox 5.2, Cloud 4.4, PaaS 5.2&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;No workaround exists — upgrade is mandatory. Discovered internally by Fortinet's own PSIRT team (Adham El Karn). No confirmed in-the-wild exploitation yet, but prior FortiSandbox access-control CVEs this year landed on CISA's KEV list after active exploitation.&lt;/p&gt;

&lt;p&gt;Hardening checklist:&lt;br&gt;
✅ Patch immediately&lt;br&gt;
✅ Never expose the mgmt web UI to the internet&lt;br&gt;
✅ Put it behind VPN/jump host&lt;br&gt;
✅ Segment the network&lt;br&gt;
✅ Centralize logs to SIEM for anomaly detection&lt;/p&gt;

&lt;p&gt;Full write-up with attack-chain breakdown + detection queries:&lt;br&gt;
&lt;a href="https://www.xpert4cyber.com/2026/09/fortisandbox-cve-2026-26084-patch.html" rel="noopener noreferrer"&gt;https://www.xpert4cyber.com/2026/09/fortisandbox-cve-2026-26084-patch.html&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>infosec</category>
      <category>networking</category>
      <category>appsec</category>
    </item>
    <item>
      <title>Fortinet Patches CVE-2026-84393: Certificate Validation Flaw in FortiOS/FortiProxy ZTNA</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Mon, 14 Sep 2026 18:25:46 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/fortinet-patches-cve-2026-84393-certificate-validation-flaw-in-fortiosfortiproxy-ztna-3anp</link>
      <guid>https://dev.to/xpert4cyber/fortinet-patches-cve-2026-84393-certificate-validation-flaw-in-fortiosfortiproxy-ztna-3anp</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F96qusf8bk79v0bsc0342.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F96qusf8bk79v0bsc0342.jpg" alt=" " width="800" height="800"&gt;&lt;/a&gt;# Fortinet Patches CVE-2026-84393: A Certificate Validation Flaw in FortiOS/FortiProxy ZTNA&lt;/p&gt;

&lt;p&gt;If you're running Agentless ZTNA anywhere in your infrastructure, this one's worth a version check today.&lt;/p&gt;

&lt;h2&gt;
  
  
  The TL;DR
&lt;/h2&gt;

&lt;p&gt;Fortinet disclosed &lt;strong&gt;CVE-2026-84393&lt;/strong&gt; on September 8, 2026 (advisory FG-IR-26-174) — an improper certificate validation bug (CWE-295) in the Agentless ZTNA portal component of FortiOS and FortiProxy. CVSS score: &lt;strong&gt;7.3&lt;/strong&gt;. No authentication required to exploit.&lt;/p&gt;

&lt;h2&gt;
  
  
  What's actually broken
&lt;/h2&gt;

&lt;p&gt;In an Agentless ZTNA architecture, the portal acts as a trust broker. It terminates the user's session, verifies their identity, then opens a &lt;em&gt;separate&lt;/em&gt; connection to the backend resource on their behalf.&lt;/p&gt;

&lt;p&gt;That second leg — portal to backend — is where this bug lives. The portal is supposed to strictly validate the backend server's certificate before trusting it. It doesn't enforce that match properly, which means an attacker sitting on the network path can present a forged or mismatched certificate and have it accepted without complaint.&lt;/p&gt;

&lt;p&gt;No login. No brute force. Just network positioning + a bad cert.&lt;/p&gt;

&lt;h2&gt;
  
  
  Impact
&lt;/h2&gt;

&lt;p&gt;Fortinet classifies this as information disclosure. A successful MITM position lets an attacker passively observe:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Session tokens&lt;/li&gt;
&lt;li&gt;Authentication data&lt;/li&gt;
&lt;li&gt;Application content in transit&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Affected versions
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Affected&lt;/th&gt;
&lt;th&gt;Fixed In&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;FortiOS&lt;/td&gt;
&lt;td&gt;7.6.1–7.6.6&lt;/td&gt;
&lt;td&gt;7.6.7+ / 8.0.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;FortiProxy&lt;/td&gt;
&lt;td&gt;7.6.2–7.6.6&lt;/td&gt;
&lt;td&gt;7.6.7+ / 8.0.0&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;7.2, 7.4, and 8.0 branches are confirmed unaffected.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this matters more than a typical 7.3
&lt;/h2&gt;

&lt;p&gt;Zero Trust's entire value prop is "verify every connection before trusting it, every hop." This flaw sits in the exact validation step ZTNA can't afford to get wrong. It's a trust-boundary failure, not a peripheral feature bug — and ZTNA portals are, by design, often exposed to less-trusted or public network segments.&lt;/p&gt;

&lt;p&gt;No evidence of active exploitation yet. That status is fragile for unauthenticated vulns once they hit public advisories.&lt;/p&gt;

&lt;h2&gt;
  
  
  Detection notes for SOC/infra teams
&lt;/h2&gt;

&lt;p&gt;This is a passive weakness, not an active exploit with a distinct payload — so there's no clean log signature. Worth watching instead:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;TLS certificate mismatches on ZTNA-brokered backend connections&lt;/li&gt;
&lt;li&gt;Unusual latency/routing on ZTNA sessions&lt;/li&gt;
&lt;li&gt;Session token reuse from unexpected source IPs&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Full attack-scenario walkthrough, detection deep-dive, and hardening checklist here: &lt;a href="https://www.xpert4cyber.com/2026/09/fortios-fortiproxy-ztna-vulnerability-cve-2026-84393.html" rel="noopener noreferrer"&gt;https://www.xpert4cyber.com/2026/09/fortios-fortiproxy-ztna-vulnerability-cve-2026-84393.html&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>networking</category>
      <category>devops</category>
    </item>
    <item>
      <title>The Linux cut Command Every SOC Analyst Should Know</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Mon, 14 Sep 2026 15:14:38 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/the-linux-cut-command-every-soc-analyst-should-know-4h9i</link>
      <guid>https://dev.to/xpert4cyber/the-linux-cut-command-every-soc-analyst-should-know-4h9i</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0zx2br2afqiqsbq4i5q0.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0zx2br2afqiqsbq4i5q0.jpg" alt=" " width="800" height="800"&gt;&lt;/a&gt;Every SOC analyst has had this moment: a raw log file lands with zero parser support, thousands of lines deep, and the clock is already running.&lt;/p&gt;

&lt;p&gt;Most people open a spreadsheet. The faster move is a command that's been sitting on every Unix-like system for decades: cut.&lt;/p&gt;

&lt;p&gt;cut isn't flashy. It doesn't detect anything or correlate events. What it does is take a line of text and hand you back exactly the piece you asked for — a character range, a byte range, or a delimited field — in one line, with no script required.&lt;/p&gt;

&lt;p&gt;Here's what I cover in the full writeup:&lt;/p&gt;

&lt;p&gt;▸ Cutting by character and byte position — for fixed-width logs and legacy formats where there's no clean delimiter&lt;br&gt;
▸ Cutting by field and delimiter — the mode you'll actually use daily, for CSVs, colon-separated files, and piped command output&lt;br&gt;
▸ A real triage walkthrough parsing /etc/passwd — pulling usernames, home directories, and shells to spot persistence indicators&lt;br&gt;
▸ Exactly where cut's limits are, and the point where awk becomes the better tool&lt;/p&gt;

&lt;p&gt;It's written from the analyst's side of the terminal, not a man-page rewrite — real one-liners, real reasoning for when to reach for each option.&lt;/p&gt;

&lt;p&gt;If you spend any real time on the Linux command line, security-focused or not, this is a small tool that pays for itself constantly.&lt;/p&gt;

&lt;p&gt;Full tutorial: &lt;a href="https://www.xpert4cyber.com/2026/09/linux-cut-command-tutorial.html" rel="noopener noreferrer"&gt;https://www.xpert4cyber.com/2026/09/linux-cut-command-tutorial.html&lt;/a&gt;&lt;/p&gt;

</description>
      <category>linux</category>
      <category>cybersecurity</category>
      <category>devops</category>
      <category>cli</category>
    </item>
    <item>
      <title>Your Firewall Might Be the Attacker's Foothold Now</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Sun, 13 Sep 2026 17:55:09 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/your-firewall-might-be-the-attackers-foothold-now-cj4</link>
      <guid>https://dev.to/xpert4cyber/your-firewall-might-be-the-attackers-foothold-now-cj4</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyiuy8aocp7g47ejs8xrg.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyiuy8aocp7g47ejs8xrg.jpg" alt=" " width="800" height="800"&gt;&lt;/a&gt;A critical FortiGate vulnerability (CVE-2025-25249), patched back in January 2026, is being actively exploited to deploy a custom Node.js RAT called PivotC2. 178 devices compromised so far. Here's the breakdown.&lt;/p&gt;

&lt;h2&gt;
  
  
  What's happening
&lt;/h2&gt;

&lt;p&gt;SOCRadar's Threat Research Unit found active exploitation of CVE-2025-25249 — a heap-based buffer overflow in the &lt;code&gt;cw_acd&lt;/code&gt; daemon that FortiOS/FortiSwitchManager use for CAPWAP (wireless AP management). Attackers send crafted requests to UDP port 5246, trigger the overflow, and drop a reverse shell — all unauthenticated.&lt;/p&gt;

&lt;h2&gt;
  
  
  The payload: PivotC2
&lt;/h2&gt;

&lt;p&gt;From the reverse shell, a single-line JS stager pulls a Node.js-based RAT (PivotC2) that:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Uses outbound-only TLS to C2, bypassing inbound firewall rules&lt;/li&gt;
&lt;li&gt;Multiplexes shells, file transfer, and SOCKS5/HTTP proxying over one socket&lt;/li&gt;
&lt;li&gt;Auto-decrypts stored FortiGate credentials (VPN PSKs, SSL-VPN, admin accounts) via AES-256-CBC/AES-128-GCM&lt;/li&gt;
&lt;li&gt;Runs a hands-off "auto-mode" pipeline: harvest → decrypt → scan, no operator input needed&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Code comments suggest AI-assisted development. Version 0.2.3 — still actively maintained.&lt;/p&gt;

&lt;h2&gt;
  
  
  Scale and attribution
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;30,000+ FortiGate IPs scanned, 178 compromised (US highest, then Chile, Colombia, UK)&lt;/li&gt;
&lt;li&gt;2 confirmed full network intrusions in the US, including Exchange mailbox exfil to Wasabi cloud storage&lt;/li&gt;
&lt;li&gt;Assessed (high confidence, not certain) as a Russian-speaking, financially motivated group&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What to do if you run FortiGate
&lt;/h2&gt;

&lt;p&gt;Run this on the FortiGate CLI to check for a known artifact: execute shell ls /tmp/.i.js&lt;br&gt;
If that file exists, treat the device as compromised.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Patch to FortiOS 7.6.4 / 7.4.9 / 7.2.12 / 7.0.18+&lt;/li&gt;
&lt;li&gt;Restrict external CAPWAP (UDP 5246) exposure&lt;/li&gt;
&lt;li&gt;Hunt for unexpected Node.js processes before trusting a patch alone&lt;/li&gt;
&lt;li&gt;Rotate all stored VPN/SSL-VPN credentials if compromise is suspected&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Full attack chain, IOCs, and detection checklist: &lt;a href="https://www.xpert4cyber.com/2026/09/fortigate-firewall-hack-pivotc2-malware.html" rel="noopener noreferrer"&gt;https://www.xpert4cyber.com/2026/09/fortigate-firewall-hack-pivotc2-malware.html&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>networking</category>
      <category>security</category>
      <category>devops</category>
    </item>
    <item>
      <title>Dell Secure Connect Gateway Vulnerability: 3 Critical CVEs Chain Into Root Access</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Sat, 12 Sep 2026 18:42:57 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/dell-secure-connect-gateway-vulnerability-3-critical-cves-chain-into-root-access-536f</link>
      <guid>https://dev.to/xpert4cyber/dell-secure-connect-gateway-vulnerability-3-critical-cves-chain-into-root-access-536f</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/..." class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/..." alt="Uploading image" width="800" height="400"&gt;&lt;/a&gt;If you're running Dell infrastructure with support monitoring enabled, this one's worth 5 minutes of your attention.&lt;/p&gt;

&lt;p&gt;Dell just disclosed three critical vulnerabilities in Secure Connect Gateway (SCG) 5.0 — the appliance that bridges Dell hardware to Dell's own diagnostics and support pipeline. On their own, each is bad. Chained, they're a textbook zero-to-root attack path:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;CVE-2026-80172&lt;/code&gt; (CVSS 9.8) — No nonce or time-limit validation on requests. Capture one valid request, replay it indefinitely, forge admin + refresh tokens. Zero credentials needed.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;CVE-2026-61410&lt;/code&gt; (CVSS 9.4) — Missing authorization check lets an unauthenticated attacker send a crafted request straight into remote command execution on the host.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;CVE-2026-80238&lt;/code&gt; (CVSS 9.3) — An exposed Docker socket. Local or SSH-level access escalates to root, and a compromised orchestrator service opens the door to container escape.&lt;/p&gt;

&lt;p&gt;Stack those three and you get: no creds → forged admin tokens → RCE → root. On a system that sits with legitimate visibility into your production infrastructure.&lt;/p&gt;

&lt;p&gt;Patched versions:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;SCG 5.0 Appliance ≥ 5.36.00.16&lt;/li&gt;
&lt;li&gt;SCG 5.0 Application ≥ 5.36.00.00&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;No confirmed active exploitation yet, but a 9.8 CVSS on an unauthenticated, zero-interaction bug is exactly the profile that gets weaponized fast once researchers start poking at the advisory.&lt;/p&gt;

&lt;p&gt;Full writeup with the realistic attack sequence, SOC-side log indicators to hunt for, and a remediation checklist that goes beyond "just patch it":&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.xpert4cyber.com/2026/09/dell-secure-connect-gateway-vulnerability.html" rel="noopener noreferrer"&gt;https://www.xpert4cyber.com/2026/09/dell-secure-connect-gateway-vulnerability.html&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>cve</category>
      <category>devops</category>
    </item>
    <item>
      <title>WeWorm: The Zero-Click WeChat Worm That Hijacks Accounts Mid-Ring</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Fri, 11 Sep 2026 18:04:31 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/weworm-the-zero-click-wechat-worm-that-hijacks-accounts-mid-ring-4lho</link>
      <guid>https://dev.to/xpert4cyber/weworm-the-zero-click-wechat-worm-that-hijacks-accounts-mid-ring-4lho</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdbgux2gojm3ry7kxj43v.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdbgux2gojm3ry7kxj43v.jpg" alt=" " width="800" height="800"&gt;&lt;/a&gt;## WeWorm: The Zero-Click WeChat Worm That Hijacks Accounts Mid-Ring&lt;/p&gt;

&lt;p&gt;A phone rings. Nobody answers. The account gets hijacked anyway — and starts calling the victim's own contacts to spread further.&lt;/p&gt;

&lt;p&gt;That's &lt;strong&gt;WeWorm&lt;/strong&gt;, a proof-of-concept built by security firm Calif, demonstrating the first zero-click worm capable of spreading through WeChat calls on both iOS and Android.&lt;/p&gt;

&lt;h3&gt;
  
  
  The bug
&lt;/h3&gt;

&lt;p&gt;Calif found a &lt;strong&gt;memory-corruption flaw&lt;/strong&gt; inside WeChat's VoIP call-handling stack — the code path that runs &lt;em&gt;before&lt;/em&gt; the recipient interacts with the call at all. No phishing link, no malicious attachment, no user action required.&lt;/p&gt;

&lt;h3&gt;
  
  
  The attack chain
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Device A (attacker) calls Device B&lt;/li&gt;
&lt;li&gt;Device B compromised mid-ring, before anyone answers&lt;/li&gt;
&lt;li&gt;Device B automatically calls Device C, repeating the exploit&lt;/li&gt;
&lt;li&gt;Chain works cross-platform: iOS ↔ Android&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Timeline
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;2026-07-24&lt;/code&gt;: Reported to Tencent&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;2026-08-21&lt;/code&gt;: Patched clients shipped (Android 8.0.77 / iOS 8.0.76)&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;2026-08-28&lt;/code&gt;: Server-side mitigation completed&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;2026-09-08&lt;/code&gt;: Public disclosure&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;No CVE has been published; Calif is withholding the full exploit chain until a conference talk.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why this matters for engineers
&lt;/h3&gt;

&lt;p&gt;Calif says AI-assisted vulnerability research cut exploit development from a typical multi-month timeline down to &lt;strong&gt;~10 days&lt;/strong&gt;. That's a meaningful shift for anyone owning patch SLAs, threat modeling, or pre-auth code paths (call setup, media negotiation, etc.) — this is exactly the kind of "runs before user interaction" logic that needs fuzzing and memory-safety auditing.&lt;/p&gt;

&lt;h3&gt;
  
  
  Mitigations if you build messaging/VoIP features
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Fuzz pre-authentication code paths specifically&lt;/li&gt;
&lt;li&gt;Don't assume "unanswered" = "safe"&lt;/li&gt;
&lt;li&gt;Add behavioral anomaly detection (unexpected outbound call/message bursts)&lt;/li&gt;
&lt;li&gt;Treat vendor-app patch SLAs (WhatsApp, Signal, WeChat) as part of your org's vuln management, not just OS-level CVEs&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Full technical writeup: &lt;a href="https://www.xpert4cyber.com/2026/09/weworm-wechat-zero-click-worm.html" rel="noopener noreferrer"&gt;https://www.xpert4cyber.com/2026/09/weworm-wechat-zero-click-worm.html&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>security</category>
      <category>infosec</category>
      <category>mobiledev</category>
    </item>
    <item>
      <title>$10M Bounty on Iran's IRGC Cyber Chief: A Lesson Every OT Engineer Should Know</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Fri, 11 Sep 2026 16:45:15 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/10m-bounty-on-irans-irgc-cyber-chief-a-lesson-every-ot-engineer-should-know-1d9e</link>
      <guid>https://dev.to/xpert4cyber/10m-bounty-on-irans-irgc-cyber-chief-a-lesson-every-ot-engineer-should-know-1d9e</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ff1k1qo5b524kor7th1yz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ff1k1qo5b524kor7th1yz.png" alt=" " width="800" height="800"&gt;&lt;/a&gt;$10M bounty, one Iranian cyber commander, and a lesson every OT engineer should already know.&lt;/p&gt;

&lt;p&gt;On September 3, 2026, the U.S. State Department's Rewards for Justice program put a $10 million reward on Amir Yaryab, a senior official in Iran's IRGC Cyber-Electronic Command (IRGC-CEC). He's accused of directing cyber units — Shahid Hemmat and Shahid Shushtari — and overseeing the hacking group CyberAv3ngers, which is responsible for one of the more consequential ICS/SCADA incidents of the past few years.&lt;/p&gt;

&lt;p&gt;Here's the technical breakdown, dev-to-dev:&lt;/p&gt;

&lt;p&gt;Between November 2023 and January 2024, CyberAv3ngers compromised 75+ Unitronics Vision Series PLCs in the U.S., 34 of them inside water and wastewater utilities. The attack chain looked like this:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Recon: scanning the internet for exposed Unitronics PLCs/HMIs&lt;/li&gt;
&lt;li&gt;Initial access: default or missing credentials — no exploit chain needed&lt;/li&gt;
&lt;li&gt;Impact: ladder logic altered to affect pumps and valves&lt;/li&gt;
&lt;li&gt;Obfuscation: device names, firmware versions, and remote access creds changed; HMI screens defaced&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;No zero-day. No custom malware. Just internet-facing industrial hardware with factory-default passwords. That's the real story behind the headline bounty.&lt;/p&gt;

&lt;p&gt;The joint CISA/FBI/NSA/EPA advisory (AA23-335A) lays out the fix, and it's not complicated:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Remove PLCs/HMIs from direct internet exposure — VPN + MFA for remote access&lt;/li&gt;
&lt;li&gt;Rotate default credentials on any OT/ICS device&lt;/li&gt;
&lt;li&gt;Keep firmware and engineering workstations patched on a separate OT cycle&lt;/li&gt;
&lt;li&gt;Maintain a live asset inventory (you can't protect what you don't know exists)&lt;/li&gt;
&lt;li&gt;Monitor for configuration drift on ladder logic and device metadata&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you build or maintain anything touching industrial control systems, SCADA, or OT networks, this case is worth 10 minutes of your time — not for the bounty drama, but for the exposure-audit checklist buried in it.&lt;/p&gt;

&lt;p&gt;Full technical writeup with IOCs and detection steps here:&lt;br&gt;
&lt;a href="https://www.xpert4cyber.com/2026/09/us-offers-10-million-reward-iranian-irgc-cyber-chief.html" rel="noopener noreferrer"&gt;https://www.xpert4cyber.com/2026/09/us-offers-10-million-reward-iranian-irgc-cyber-chief.html&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>security</category>
      <category>infosec</category>
      <category>networking</category>
    </item>
    <item>
      <title>Why "ESXi-Ready" Should Be the Scariest Two Words in a Ransomware Report</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Fri, 11 Sep 2026 13:46:48 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/why-esxi-ready-should-be-the-scariest-two-words-in-a-ransomware-report-4efm</link>
      <guid>https://dev.to/xpert4cyber/why-esxi-ready-should-be-the-scariest-two-words-in-a-ransomware-report-4efm</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzqd0fu8byuvdw5yxmw5h.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzqd0fu8byuvdw5yxmw5h.jpg" alt=" " width="640" height="438"&gt;&lt;/a&gt;Why "ESXi-Ready" Should Be the Scariest Two Words in a Ransomware Report&lt;/p&gt;

&lt;p&gt;If you manage infrastructure, here's a threat worth 5 minutes of your attention: a new ransomware-as-a-service (RaaS) group called Panzer just emerged with payload support for Windows, Linux, FreeBSD, and — critically — VMware ESXi.&lt;/p&gt;

&lt;p&gt;Here's why that ESXi detail changes everything. Most ransomware still spreads endpoint by endpoint, which is slow and noisy. An ESXi-capable encryptor skips that entirely and goes straight for the hypervisor layer. One compromised host, and you're not looking at one infected machine — you're looking at every VM it hosts encrypted simultaneously. ERP, internal tooling, CI/CD runners, VoIP — gone in one pass.&lt;/p&gt;

&lt;p&gt;Panzer's leak site appeared in August 2026 and has already claimed victims across roughly eleven countries, including two named Italian firms (a manufacturer and a telecom engineering company). Worth flagging: leak-site listings are extortion claims, not confirmed breaches, until independently verified.&lt;/p&gt;

&lt;p&gt;What stood out to researchers isn't the malware itself (no sample has been publicly dissected yet) — it's the affiliate infrastructure. Panzer runs Tox-based recruitment screening, a centralized dashboard for builds and Bitcoin invoicing, and an 80/20 revenue split. It's run less like a hacker crew and more like a managed platform business.&lt;/p&gt;

&lt;p&gt;For engineering and infra teams, the practical priorities right now:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Segment vCenter/ESXi management interfaces off your general network&lt;/li&gt;
&lt;li&gt;Enforce phishing-resistant MFA on all remote/admin access&lt;/li&gt;
&lt;li&gt;Test your VM backup restores — not just take them&lt;/li&gt;
&lt;li&gt;Watch for behavioral signals: unexpected PsExec/WMI activity, vssadmin delete shadows, bcdedit recovery disables&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Full technical breakdown — attack chain, IOCs, detection commands, and hardening steps:&lt;br&gt;
&lt;a href="https://www.xpert4cyber.com/2026/09/panzer-ransomware-esxi-attack.html" rel="noopener noreferrer"&gt;https://www.xpert4cyber.com/2026/09/panzer-ransomware-esxi-attack.html&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>devops</category>
      <category>infosec</category>
    </item>
    <item>
      <title>BigBear 2.0: How Evilginx2 Phishing Bypasses Microsoft 365 MFA (And How to Detect It)</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Fri, 11 Sep 2026 07:38:54 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/bigbear-20-how-evilginx2-phishing-bypasses-microsoft-365-mfa-and-how-to-detect-it-3jfm</link>
      <guid>https://dev.to/xpert4cyber/bigbear-20-how-evilginx2-phishing-bypasses-microsoft-365-mfa-and-how-to-detect-it-3jfm</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fe6ln3j5e3ql71b6tvce5.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fe6ln3j5e3ql71b6tvce5.jpg" alt=" " width="800" height="800"&gt;&lt;/a&gt;BigBear 2.0 is a phishing-as-a-service operation built on Evilginx2, an adversary-in-the-middle (AiTM) proxy framework. It doesn't crack MFA — it lets a victim complete MFA normally, then steals the session cookie Microsoft issues afterward. That cookie is enough to hijack the account, no password or OTP required again.&lt;/p&gt;

&lt;p&gt;Security researchers reported the operation affected 460+ organizations across 40+ countries, with roughly 9% of captured sessions resulting in a full MFA bypass.&lt;/p&gt;

&lt;h2&gt;
  
  
  How the Attack Works
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Victim clicks a phishing link routed through an attacker-controlled proxy.&lt;/li&gt;
&lt;li&gt;The proxy relays real traffic to Microsoft's actual login page — so the page victims see is genuine.&lt;/li&gt;
&lt;li&gt;Victim enters credentials and completes MFA as normal.&lt;/li&gt;
&lt;li&gt;Microsoft issues an authenticated session cookie — the proxy silently captures a copy.&lt;/li&gt;
&lt;li&gt;The attacker replays that cookie and steps directly into the live session (Outlook, Teams, SharePoint, connected SSO apps).&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The kit reportedly also nudges victims away from FIDO2/WebAuthn key prompts toward weaker MFA fallbacks, and uses residential proxies to make attacker traffic look geographically consistent with the real user — undermining location-based Conditional Access.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Standard MFA Doesn't Catch This
&lt;/h2&gt;

&lt;p&gt;From the identity provider's point of view, the login was legitimate. Detection has to shift from "did auth succeed" to "does this session's behavior make sense."&lt;/p&gt;

&lt;p&gt;Watch for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Same session token used from geographically distant IPs in a short window&lt;/li&gt;
&lt;li&gt;Token reuse on a device/browser that never did the original interactive sign-in&lt;/li&gt;
&lt;li&gt;New mailbox forwarding rules created shortly after sign-in&lt;/li&gt;
&lt;li&gt;New OAuth app consent grants from unfamiliar networks&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A starting hunt query for Microsoft Sentinel/Defender:&lt;/p&gt;

&lt;p&gt;SigninLogs&lt;br&gt;
| where ResultType == 0&lt;br&gt;
| summarize IPs = make_set(IPAddress), Countries = make_set(LocationDetails.countryOrRegion) by UserPrincipalName, AppDisplayName, bin(TimeGenerated, 1h)&lt;br&gt;
| where array_length(IPs) &amp;gt; 1 and array_length(Countries) &amp;gt; 1&lt;/p&gt;

&lt;p&gt;Treat hits as investigation starting points, not confirmed compromise — VPNs and mobile IP rotation can trigger false positives.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to Actually Defend Against It
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Phishing-resistant auth: FIDO2 keys / passkeys bind login cryptographically to the real domain — a proxied page can't replicate that.&lt;/li&gt;
&lt;li&gt;Conditional Access + device compliance: require managed devices for sensitive apps instead of trusting IP/location alone.&lt;/li&gt;
&lt;li&gt;Shorter token lifetimes + continuous access evaluation to shrink the usable window for a stolen cookie.&lt;/li&gt;
&lt;li&gt;EDR/UEBA tuned for identity signals — anomalous OAuth consent and mailbox-rule changes, not just malware.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If a session is confirmed or suspected hijacked: revoke all active sessions/refresh tokens, force re-auth, reset the password, and audit for new forwarding rules and OAuth grants before closing the incident.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;p&gt;Is this a Microsoft 365 vulnerability? No — it abuses trust in an already-authenticated session, not a flaw in Microsoft's code.&lt;/p&gt;

&lt;p&gt;Does MFA stop it? Standard OTP/push MFA does not, since the attacker lets it complete and steals the resulting session proof.&lt;/p&gt;

&lt;p&gt;What does stop it? Phishing-resistant authentication (FIDO2/passkeys).&lt;/p&gt;

&lt;p&gt;Full analysis and indicators of compromise: &lt;a href="https://www.xpert4cyber.com/2026/09/bigbear-2-0-evilginx2-mfa-bypass.html" rel="noopener noreferrer"&gt;https://www.xpert4cyber.com/2026/09/bigbear-2-0-evilginx2-mfa-bypass.html&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>mfa</category>
      <category>phishing</category>
    </item>
    <item>
      <title>No Exploit, No Zero-Day: How One Stolen Credential Breached Veradigm</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Wed, 09 Sep 2026 19:46:49 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/no-exploit-no-zero-day-how-one-stolen-credential-breached-veradigm-59dd</link>
      <guid>https://dev.to/xpert4cyber/no-exploit-no-zero-day-how-one-stolen-credential-breached-veradigm-59dd</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnyzjs3vf22y7iv1a31lv.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnyzjs3vf22y7iv1a31lv.jpg" alt=" " width="800" height="800"&gt;&lt;/a&gt;No exploit. No zero-day. No ransomware payload. Just one stolen credential — and patient Social Security numbers walked out the door.&lt;/p&gt;

&lt;p&gt;Here's a breach story every dev and security engineer should read closely, because it's not about a vulnerability in code. It's about what happens when a legitimate, working API does exactly what it was built to do — for the wrong person.&lt;/p&gt;

&lt;h2&gt;
  
  
  What happened
&lt;/h2&gt;

&lt;p&gt;Veradigm, a healthcare technology company providing EHR and practice-management tools to thousands of providers, confirmed the incident in an SEC 8-K filing on September 8, 2026. An attacker obtained login credentials from inside a third-party vendor's environment — not from Veradigm's own infrastructure. Those credentials granted access to a single, scoped Veradigm API that the vendor used in its normal integration workflow.&lt;/p&gt;

&lt;p&gt;Using that access, the attacker downloaded patient personal data, including Social Security numbers in some records. No clinical or medical data was touched, and the compromised credential never reached Veradigm's broader network, servers, or databases. No downtime, no lateral movement — just a clean, authenticated bulk pull through a working endpoint.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this matters for engineers, not just SOC teams
&lt;/h2&gt;

&lt;p&gt;This wasn't a code-level exploit. It was:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A vendor's credential, likely obtained via phishing, infostealer malware, or credential stuffing (unconfirmed — Veradigm's filing doesn't specify)&lt;/li&gt;
&lt;li&gt;Used against a real, functioning API with no rate anomaly severe enough to auto-block early&lt;/li&gt;
&lt;li&gt;Scoped just narrowly enough that when it &lt;em&gt;was&lt;/em&gt; caught, the blast radius stayed contained&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That last point is the actual engineering lesson here: proper API scoping and access segmentation turned a potentially catastrophic breach into a limited, contained one. This is a live case study for why "least privilege" isn't a compliance checkbox — it's the difference between a bad week and a company-ending incident.&lt;/p&gt;

&lt;h2&gt;
  
  
  The technical takeaways
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Scope every vendor-facing API credential to the minimum data fields and volume actually needed&lt;/li&gt;
&lt;li&gt;Rotate and expire API keys on a schedule — long-lived tokens are a standing liability&lt;/li&gt;
&lt;li&gt;Log and retain detailed API access data long enough to actually investigate a bulk-export event after the fact&lt;/li&gt;
&lt;li&gt;Build anomaly detection around query pattern shifts (a vendor suddenly requesting fields it's never touched before), not just raw volume spikes&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Full breakdown with the complete attack path, detection signals, and prevention checklist:&lt;br&gt;
👉 &lt;a href="https://www.xpert4cyber.com/2026/09/veradigm-data-breach-patient-ssns-exposed.html" rel="noopener noreferrer"&gt;https://www.xpert4cyber.com/2026/09/veradigm-data-breach-patient-ssns-exposed.html&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>api</category>
      <category>webdev</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>WinRM Abuse + HiveMQ + Element = A New Kind of Windows Backdoor</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Tue, 08 Sep 2026 19:09:12 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/winrm-abuse-hivemq-element-a-new-kind-of-windows-backdoor-41mj</link>
      <guid>https://dev.to/xpert4cyber/winrm-abuse-hivemq-element-a-new-kind-of-windows-backdoor-41mj</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6c92hgs76nfai4a0iyyp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6c92hgs76nfai4a0iyyp.png" alt=" " width="800" height="800"&gt;&lt;/a&gt;If you saw a Windows machine on your network quietly talking to &lt;code&gt;broker.hivemq.com&lt;/code&gt;, would you even blink? Probably not — MQTT brokers are everywhere in IoT, smart buildings, and dev pipelines. That's exactly the blind spot a financially motivated threat group called &lt;strong&gt;Toy Ghouls&lt;/strong&gt; is now exploiting, according to research from Kaspersky's Global Emergency Response Team (GERT).&lt;/p&gt;

&lt;p&gt;For the first time since it emerged in 2025, Toy Ghouls has ditched its usual toolkit of public GitHub scripts and leaked ransomware builders (previously Babuk and LockBit, later its own &lt;strong&gt;GenieLocker&lt;/strong&gt; ransomware) for two custom-built Windows backdoors. One talks to operators over a legitimate MQTT broker. The other hides inside an Element/Matrix chat room. Neither platform is hacked or vulnerable — they're used exactly as designed, just by the wrong people.&lt;/p&gt;

&lt;p&gt;This is a textbook case of &lt;strong&gt;"living-off-trusted-services"&lt;/strong&gt; — a pattern more devs and SREs should understand, since it targets the same infra you're probably already running in prod.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Backdoors: mqtt-bird-agent and matrix-bird-agent
&lt;/h2&gt;

&lt;p&gt;Kaspersky identified two builds (v0.1.0), sharing the same "phone home, execute commands" design:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;mqtt-bird-agent&lt;/strong&gt; connects to the public HiveMQ broker, reports system telemetry (CPU, memory, online status), and pulls attacker instructions that run through a hidden PowerShell process.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;matrix-bird-agent&lt;/strong&gt; connects to an attacker-controlled Element server, posts status to a chat room, and receives commands from an account named &lt;code&gt;panel-bot&lt;/code&gt;, executed via the Windows command line.&lt;/p&gt;

&lt;p&gt;Both grant full remote control and can run in-memory or install as a persistent Windows service. If MQTT-based C2 sounds familiar, it echoes earlier tactics from the &lt;strong&gt;WailingCrab&lt;/strong&gt; malware family — but Toy Ghouls' choice of infrastructure is deliberately built to blend into normal enterprise/IoT noise.&lt;/p&gt;

&lt;h2&gt;
  
  
  Delivery: WinRM Abuse, Not a Zero-Day
&lt;/h2&gt;

&lt;p&gt;These backdoors are &lt;strong&gt;second-stage payloads&lt;/strong&gt;, not the initial breach. Kaspersky found Toy Ghouls pushing binaries and config files to already-compromised hosts via &lt;strong&gt;Windows Remote Management (WinRM)&lt;/strong&gt;, using &lt;strong&gt;Evil-WinRM&lt;/strong&gt; and &lt;strong&gt;WinRM-fs&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;WinRM is a completely legitimate admin protocol — which is exactly why malicious use hides so well inside routine remote-admin traffic.&lt;/p&gt;

&lt;h2&gt;
  
  
  Persistence: Disguised as Everyday Services
&lt;/h2&gt;

&lt;p&gt;Both variants can install as Windows services to survive reboots:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;HiveMQ variant → registers as &lt;strong&gt;cplsupport&lt;/strong&gt;, shown as &lt;em&gt;"Problem Reports Control Panel"&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;Element variant → registers as &lt;strong&gt;wtas&lt;/strong&gt;, shown as &lt;em&gt;"Windows Telemetry Aggregator Service"&lt;/em&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Neither is a real default Windows service, but both are plausible enough to slip past a quick &lt;code&gt;services.msc&lt;/code&gt; scan.&lt;/p&gt;

&lt;h2&gt;
  
  
  Anti-Forensics: Machine-Bound Encryption
&lt;/h2&gt;

&lt;p&gt;Sensitive fields in &lt;code&gt;config.toml&lt;/code&gt; are encrypted with &lt;strong&gt;ChaCha20-Poly1305&lt;/strong&gt;, with the key derived from the host's &lt;code&gt;MachineGuid&lt;/code&gt; registry value — so the file won't decrypt outside the infected machine without that value too.&lt;/p&gt;

&lt;p&gt;The Element variant goes further: after first use, it deletes &lt;code&gt;config.toml&lt;/code&gt; entirely and moves settings into the registry, minimizing forensic artifacts. Both variants query &lt;code&gt;ip-api.com&lt;/code&gt; at startup to fingerprint the victim's public IP and country.&lt;/p&gt;

&lt;h2&gt;
  
  
  Indicators of Compromise
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Type&lt;/th&gt;
&lt;th&gt;Indicator&lt;/th&gt;
&lt;th&gt;Notes&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;File&lt;/td&gt;
&lt;td&gt;&lt;code&gt;cplsupport.exe&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;HiveMQ backdoor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Hash&lt;/td&gt;
&lt;td&gt;&lt;code&gt;BFADBEEE63A4F0BF19EC9DEB8FA58F58&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;cplsupport.exe&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File&lt;/td&gt;
&lt;td&gt;&lt;code&gt;wtass.exe&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Element backdoor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Hash&lt;/td&gt;
&lt;td&gt;&lt;code&gt;7916C33688385525078BEE504C90F359&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;wtass.exe&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Registry&lt;/td&gt;
&lt;td&gt;&lt;code&gt;HKLM\Software\synapse\Config\SealedConfig&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Sealed Element config&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Service&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;cplsupport&lt;/code&gt; / &lt;code&gt;wtas&lt;/code&gt;
&lt;/td&gt;
&lt;td&gt;Disguised persistence&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Domain&lt;/td&gt;
&lt;td&gt;&lt;code&gt;broker.hivemq[.]com&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Abused, not compromised&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Domain&lt;/td&gt;
&lt;td&gt;&lt;code&gt;meet.element[.]tw&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Attacker-controlled&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;Defang and validate all IOCs in your own threat intel platform before use.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Detection: What Actually Works
&lt;/h2&gt;

&lt;p&gt;Blocklists won't catch this — HiveMQ and Element are legitimate and will never show up on a malicious-domain list. Detection has to be &lt;strong&gt;behavior-based&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Restrict WinRM to a short list of approved management hosts; alert on unusual sources&lt;/li&gt;
&lt;li&gt;Enable &lt;strong&gt;PowerShell Script Block Logging (Event ID 4104)&lt;/strong&gt; and look for hidden PowerShell spawned by unexpected parents&lt;/li&gt;
&lt;li&gt;Monitor &lt;strong&gt;service creation (Event ID 7045)&lt;/strong&gt; for generic names outside your baseline&lt;/li&gt;
&lt;li&gt;Flag outbound MQTT/Matrix traffic from servers — normal for IoT/dev boxes, abnormal for domain controllers or file servers&lt;/li&gt;
&lt;li&gt;Sweep &lt;code&gt;ProgramData&lt;/code&gt; for unexpected &lt;code&gt;.toml&lt;/code&gt; files&lt;/li&gt;
&lt;li&gt;Enforce phishing-resistant MFA on privileged remote-admin accounts&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A quick triage hunt for non-standard services:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;Get-CimInstance&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-ClassName&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Win32_Service&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;Where-Object&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="bp"&gt;$_&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;PathName&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-notlike&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"*Windows*"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;Select-Object&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;Name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;DisplayName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;PathName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;StartMode&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Not a silver bullet — correlate results against your known-good service baseline.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why This Matters for Devs, Not Just SOC Teams
&lt;/h2&gt;

&lt;p&gt;If you build or maintain systems that use MQTT brokers, Matrix homeservers, or any chat-based integrations (Slack/Discord/Teams bots included), this campaign is a reminder that &lt;strong&gt;the same trust your app relies on can be weaponized against your infra&lt;/strong&gt;. Attackers are increasingly abusing legitimate cloud/messaging services as C2 channels precisely because reputation-based blocking can't touch them. IOCs rotate build to build — the underlying behavior (WinRM-delivered payloads, disguised services, anomalous outbound traffic) is what stays constant.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Is HiveMQ or Element compromised?&lt;/strong&gt;&lt;br&gt;
No. Both are legitimate, unaffected platforms being abused, not exploited.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who is Toy Ghouls?&lt;/strong&gt;&lt;br&gt;
A financially motivated group (aliases: Bearlyfy, Laboo.boo, Feral Wolf) targeting Russian organizations since 2025, previously linked to GenieLocker ransomware.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can this backdoor survive a reboot?&lt;/strong&gt;&lt;br&gt;
Yes, via disguised Windows services (&lt;code&gt;cplsupport&lt;/code&gt; / &lt;code&gt;wtas&lt;/code&gt;).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What should teams prioritize?&lt;/strong&gt;&lt;br&gt;
WinRM audits, PowerShell logging, service-creation monitoring, and outbound traffic baselining per host role.&lt;/p&gt;

&lt;h2&gt;
  
  
  Bottom Line
&lt;/h2&gt;

&lt;p&gt;If your team hasn't reviewed WinRM access controls or audited for unfamiliar Windows services recently, this is a good reason to move it up the backlog. Trusted-looking traffic isn't automatically safe traffic.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Full technical write-up and source: &lt;a href="https://www.xpert4cyber.com/2026/09/windows-backdoor-hivemq-element-c2.html" rel="noopener noreferrer"&gt;Xpert4Cyber — Hackers Hide Windows Backdoor Inside HiveMQ and Element Chat&lt;/a&gt;, based on Kaspersky Securelist/GERT threat intelligence.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>windows</category>
      <category>cybersecurity</category>
      <category>malware</category>
    </item>
    <item>
      <title>Plex Emailed Every User About Undisclosed Security Flaws — Here's What Devs and Sysadmins Need to Know</title>
      <dc:creator>Shubham Chaudhary</dc:creator>
      <pubDate>Tue, 08 Sep 2026 16:52:48 +0000</pubDate>
      <link>https://dev.to/xpert4cyber/plex-emailed-every-user-about-undisclosed-security-flaws-heres-what-devs-and-sysadmins-need-to-3mcl</link>
      <guid>https://dev.to/xpert4cyber/plex-emailed-every-user-about-undisclosed-security-flaws-heres-what-devs-and-sysadmins-need-to-3mcl</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fovjuo87l3fjvitphv9e6.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fovjuo87l3fjvitphv9e6.jpg" alt=" " width="800" height="800"&gt;&lt;/a&gt;## Plex Emailed Every User About Undisclosed Security Flaws — Here's What Devs and Sysadmins Need to Know&lt;/p&gt;

&lt;p&gt;Most vendors bury a security patch in a changelog nobody reads. Plex didn't. This week, it emailed its entire user base directly — a step it reportedly reserves for its more serious advisories.&lt;/p&gt;

&lt;h3&gt;
  
  
  What Happened
&lt;/h3&gt;

&lt;p&gt;Plex shipped &lt;strong&gt;Media Server 1.43.3&lt;/strong&gt; and &lt;strong&gt;Desktop 1.115.0&lt;/strong&gt; to patch multiple undisclosed security vulnerabilities.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;❌ No CVE published yet&lt;/li&gt;
&lt;li&gt;❌ No CVSS score&lt;/li&gt;
&lt;li&gt;❌ No technical details&lt;/li&gt;
&lt;li&gt;✅ CVE identifiers have been requested&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Plex says it will publish more details once the CVEs are assigned.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why the Silence Is the Story
&lt;/h3&gt;

&lt;p&gt;Releasing exploit-relevant details before users patch just hands attackers a roadmap. But once a patch is public, researchers (and attackers) can diff binaries between versions to reverse-engineer the fix — often faster than most self-hosters update.&lt;/p&gt;

&lt;p&gt;Translation: treat this as a &lt;strong&gt;patch-now&lt;/strong&gt; situation, not a &lt;strong&gt;wait-for-the-CVE&lt;/strong&gt; situation.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why This Matters Beyond Home Labs
&lt;/h3&gt;

&lt;p&gt;Plex has real history here. A previous flaw, &lt;strong&gt;CVE-2020-5741&lt;/strong&gt;, was the entry point attackers used in the 2022 LastPass breach — they compromised a DevOps engineer's home Plex server, planted a keylogger, and used the harvested credentials to access LastPass's corporate vault.&lt;/p&gt;

&lt;p&gt;If your org has engineers running Plex, NAS boxes, or remote-access tools on home networks — that's still attack surface.&lt;/p&gt;

&lt;h3&gt;
  
  
  How to Update
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Linux:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Debian/Ubuntu&lt;/span&gt;
&lt;span class="nb"&gt;sudo &lt;/span&gt;dpkg &lt;span class="nt"&gt;-i&lt;/span&gt; plexmediaserver_&lt;span class="k"&gt;*&lt;/span&gt;.deb

&lt;span class="c"&gt;# Fedora/CentOS/RHEL&lt;/span&gt;
&lt;span class="nb"&gt;sudo &lt;/span&gt;rpm &lt;span class="nt"&gt;-Uvh&lt;/span&gt; plexmediaserver-&lt;span class="k"&gt;*&lt;/span&gt;.rpm
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Docker:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;docker pull plexinc/pms-docker:latest
docker stop plex &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; docker &lt;span class="nb"&gt;rm &lt;/span&gt;plex
&lt;span class="c"&gt;# redeploy with existing volumes/env vars&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;NAS devices:&lt;/strong&gt; App-store packages often lag — grab the official installer directly from Plex if your package manager hasn't caught up.&lt;/p&gt;

&lt;h3&gt;
  
  
  Quick Checklist
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;[ ] Confirm full build number (not just "1.43.3") — some sub-builds predate the fix&lt;/li&gt;
&lt;li&gt;[ ] Update Desktop to 1.115.0&lt;/li&gt;
&lt;li&gt;[ ] Audit remote access — disable if unneeded&lt;/li&gt;
&lt;li&gt;[ ] Check logs for unfamiliar sign-ins&lt;/li&gt;
&lt;li&gt;[ ] Don't expose Plex directly to the internet without a reverse proxy/VPN&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Full platform-by-platform breakdown here: &lt;a href="https://www.xpert4cyber.com/2026/09/plex-security-update-hidden-flaws.html" rel="noopener noreferrer"&gt;https://www.xpert4cyber.com/2026/09/plex-security-update-hidden-flaws.html&lt;/a&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;What's your home-lab security setup look like? Curious how many of us are running Plex behind a reverse proxy vs. straight port-forwarded.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>selfhosted</category>
      <category>devops</category>
      <category>linux</category>
    </item>
  </channel>
</rss>
