Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Google announced Android 17 will enforce OS-wide Encrypted Client Hello with ECH GREASE, plus Certificate Transparency by default and carrier 2G disablement.
Google announced Android 17 network security protections headlined by OS-wide support for Encrypted Client Hello (ECH), with ECH GREASE enabled by default so connections to non-ECH servers look identical. Google's Jigsaw noted OkHttp has integrated ECH, letting third-party Android apps adopt the standard. The release also enforces Local Network Protection permission prompts, enables Certificate Transparency by default, and lets carriers turn off 2G by default to prevent downgrade attacks, rogue base stations, and SMS blasters. ECH was previously added to Chrome 117 and Firefox 118 at the browser level only.
USN-8764-1: SRT vulnerabilities
Ubuntu fixes two SRT flaws allowing encrypted connection downgrade with content injection and remote crash.
Ubuntu Security Notice USN-8764-1 patches two vulnerabilities in the SRT streaming protocol. CVE-2026-55868 stems from unauthenticated encryption control messages, letting a remote attacker downgrade an encrypted connection to inject content or interrupt media streams. CVE-2026-55869 involves improper validation of control packets during connection setup and key refresh, enabling a remote denial of service.
G7 urges organizations to prepare for quantum cyber threats
G7 Cyber Security Working Group and CISA jointly urge organizations to begin migrating to post-quantum cryptography now, citing harvest-now-decrypt-later risk.
In a joint advisory, the G7 Cyber Security Working Group and CISA recommend starting post-quantum cryptography migration immediately rather than waiting for quantum computers to break current encryption. They warn attackers can already harvest encrypted data for later decryption, threatening long-lived secrets such as government records and trade secrets. Organizations are told to inventory sensitive systems, prioritize them, and fold quantum-resistant upgrades into routine refresh cycles. The advisory follows a UK 2035 PQC roadmap and recent US executive orders on quantum preparedness.
CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks
CISA and Five Eyes agencies issued joint guidance detailing 17 Active Directory attack techniques like Kerberoasting and DCSync, with hardening and detection advice.
CISA, the NSA, and cyber agencies from Australia, Canada, the UK, and New Zealand released joint guidance on September 15 covering 17 techniques attackers use to compromise Active Directory, including AD CS, Certificate Services, and Federation Services attacks. Named techniques include Kerberoasting, AS-REP roasting, password spraying, DCSync, NTDS.dit dumping, Golden and Silver Tickets, Golden SAML, and Skeleton Key. Recommendations include minimizing SPN accounts, enforcing AES encryption, disabling NTLM, account lockout thresholds of five attempts, phishing-resistant MFA, and Tier 0 prioritization. The guide also lists Windows event IDs 4769, 4768, 4625, 4771, and 2889 for detecting Kerberoasting and password spraying on domain controllers.
CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory
CISA and five international agencies publish joint guidance detailing 17 techniques attackers use to compromise Microsoft Active Directory environments.
CISA, NSA, and the Australian Signals Directorate's ACSC, with contributions from Canadian, UK, and New Zealand cyber centers, released technical guidance on 17 Active Directory attack techniques. It covers AD Domain Services, AD Certificate Services, and AD Federation Services, including Kerberoasting, DCSync, Golden Ticket, Golden SAML, Skeleton Key, and Shadow Credentials. The guidance recommends treating domain controllers, CAs, AD FS servers, and Entra Connect systems as Tier 0 assets with phishing-resistant MFA, Kerberos pre-authentication enforcement, and disabling NTLM/SMBv1.
Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities
Cisco released an advisory for S/MIME ciphertext decryption flaws in Secure Email that could let unauthenticated remote attackers recover plaintext via machine-in-the-middle.
Multiple vulnerabilities in the S/MIME decryption functionality of Cisco Secure Email stem from insufficient validation of message integrity. An unauthenticated remote attacker could intercept and modify traffic between email gateways using a machine-in-the-middle technique to obtain plaintext from encrypted messages. No workarounds are available; no CVE identifiers or exploitation status were included in the advisory text.
Slack resets passwords for about 0.5% of its users due to the exposure of the salted password hashes
MongoDB security advisory (AV26-911)
Canada's Cyber Centre warns MongoDB Java Driver and Laravel MongoDB (PHP) have vulnerabilities fixed in versions 5.11.1 and 5.11.0.
The Canadian Centre for Cyber Security (AV26-911) reports MongoDB vulnerabilities affecting the Java Driver prior to 5.11.1 and Laravel MongoDB (PHP) prior to 5.11.0. Fixed issues include a native heap use-after-free during cancellation racing a KMS credential fetch in reactive encryption (JAVA-6276) and a query builder fix forcing literal equality when 3-arg where clauses use '=' with array values (PHPLARA-260). Administrators are urged to review the advisories and apply the updates.
7th September – Threat Intelligence Report
Check Point weekly bulletin: exploited SonicWall SMA 1000 zero-days (CVE-2026-83548/49), JFrog Artifactory auth bypass, and a 2.8M-patient Baylor Genetics breach.
Check Point's weekly bulletin covers breaches including Thomson Reuters' C-Track platform (court records across 11 US states and Canada), Baylor Genetics (2.8M patients and employees, SSNs included), Hit casinos in Slovenia, and Dropbox (~5,000 accounts via abused Lenovo email verification). SonicWall patched two exploited SMA 1000 zero-days, including CVE-2026-83548, a CVSS 10.0 pre-authentication SSRF, while JFrog fixed exploited authentication bypass CVE-2026-82329 (CVSS 9.8). Malware and actor coverage includes Gambling Goblin, JSCeal, Mirage Kitten's NodeRabbit/PollCat campaign, and DPRK Contagious Interview macOS activity, plus a FalconFlank privilege-escalation PoC against CrowdStrike Falcon.
Water sector passes, government sector fails attempts to spot and halt simulated CISA attack
CISA red teamers compromised both a government and a water organization; water defenders detected and contained the simulated attack, government defenders did not.
CISA's red team gained initial access, elevated domain privileges, and lateral movement into sensitive business systems and cloud resources at an unnamed government organization, whose SOC ignored low- and medium-severity EDR alerts buried under thousands of false positives. A water organization's SOC quarantined phishing-compromised workstations within 2, 10, and 20 minutes, and later detected and isolated intrusions reaching the OT DMZ bastion host. Both organizations underestimated cloud risk, lacked Microsoft Conditional Access for workload identities, and had no process to revoke compromised access and refresh tokens. This is one of CISA's rare public red-team reports since 2023.
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
NSA, CISA, FBI, DOE and EPA warn hackers are using AI-generated scripts to actively attack Siemens S7 PLCs across critical-infrastructure sectors.
A joint cybersecurity advisory from the NSA, CISA, FBI, Department of Energy and EPA warns of an active threat campaign targeting water, food, energy, chemical, manufacturing and commercial facilities via Siemens S7 Series programmable logic controllers. The actors use internet scanning to find exposed or poorly protected PLCs, then deploy AI-generated exploitation scripts disguised as legitimate monitoring tools, an OT first that dramatically lowers the expertise required for ICS attacks. Siemens says no new S7 vulnerabilities are involved, only exploitation of misconfigurations, and it is coordinating with CISA's ProductCERT. The warning follows a joint FBI-EPA advisory confirming attacks at water and wastewater utilities in at least 12 states since July 27.