The Signal
Must Know
Vulnerability · Securityaffairs
What happened
The DOJ and FBI seized the China-linked Microscan and FishHub tools, which court documents allege were operated by Integrity Technology Group, a PRC-based company with PRC government contracts. [3]
The tools were used to scan and, in some cases, intrude into U.S. and foreign critical-infrastructure systems and other networks. [3]
Why it matters
The associated Mirai-based IoT botnet database contained records for more than 1.2 million infected devices in June 2024, including more than 385,000 in the United States; about 260,000 devices were actively infected then. [3]
AI & Agents · Securityaffairs
What happened
CrowdStrike analyzed a campaign against South Korean financial organizations in late September–early October 2026 that ended with stolen data, using open directories left by the attacker. [1]
The exposed directories contained Claude Code session histories, ARTEX configuration files, and Claude memory files, giving researchers direct visibility into the operator’s methods and tooling. [1]
Why it matters
CrowdStrike said the activity demonstrates that AI tooling can enable a financially motivated actor to conduct multiple intrusions within a short time span. [1]
AI & Agents · Securityaffairs
What happened
Anthropic launched OSS Scanner, a free vulnerability scanner for open-source projects that uses its AI models to identify vulnerabilities and help maintainers fix them. [2]
Over six months, Anthropic’s models identified more than 29,000 possible vulnerabilities in widely used open-source software; experts had manually reviewed about 6,000. [2]
Why it matters
Anthropic’s validation tested 97 critical or high-severity findings across 48 projects: 85 met its process threshold, 11 of the remaining findings were real duplicates, and one was invalid. [2]
Vulnerability · The Hacker News
What happened
GoBalance has a bug that lets anyone derive the secret key controlling a site’s .onion address from public information and take over that address. [4]
Why it matters
Searchlight Cyber says an attacker who recovers the key can redirect visitors to a copy of the site controlled by the attacker. [4]
AI & Agents · Helpnetsecurity
What happened
BPFDoor is described as Linux malware that waits for a special “magic packet” before acting. [5]
Christiaan Beek of Rapid7 Intelligence discusses why BPFDoor operators target mail gateways and other edge devices that cannot run endpoint agents. [5]
Why it matters
The source characterizes BPFDoor as difficult to detect and says a compromised telecom network can pose risks to an entire nation. [5]
Also Worth Knowing
Research · Malwarebytes Labs
What happened
Amazon’s “About You” page lets customers review and edit personal details used to shape shopping recommendations; the profile may include purchase history, searches, saved-list items, reviews, and shopping-related Alexa conversations. [6]
AI & Agents · Helpnetsecurity
What happened
The PCI Security Standards Council published Security Considerations for AI Systems, covering protection of data supplied to AI systems in payment environments and defenses against AI-assisted attacks. [7]
Security · Arstechnica Security
What happened
Let's Encrypt plans to reduce free SSL/TLS certificate lifetimes from 90 days to 64 days starting February 10, 2027. [8]