ZeroHour

Search: “sec-filing”

29 stories in the last 24h

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

The EU CRA's Real Question: What Shipped, and When Did You Know?

ActiveState argues the EU CRA's 24-hour ENISA exploit-notification duty, effective September 11, 2026, makes current SBOMs and provenance visibility a legal necessity.

An ActiveState essay warns that the EU Cyber Resilience Act's reporting obligations take effect on September 11, 2026, requiring manufacturers of products with digital elements sold into the EU to notify ENISA within 24 hours of learning a vulnerability is actively exploited, with a fuller report within 72 hours. The law's engineering requirements only apply from December 11, 2027, leaving a visibility-first runway, and Article 13 requires the SBOM to stay current unlike one-time artifacts generated under US Executive Order 14028. The author contrasts the 24-hour notification clock with an industry-average 55 days to remediate high or critical vulnerabilities and recommends automated SBOM regeneration or consuming pre-vetted, attested open source components.

BleepingComputer · 8d agoPolicy & legal

House passes bill to equip local law enforcement with scam-fighting tools

The U.S. House passed the GUARD Act, letting local law enforcement use federal grants to investigate financial scams and trace stolen cryptocurrency.

The bipartisan GUARD Act (Reps. Zachary Nunn, Scott Fitzgerald, Josh Gottheimer) passed the House, allowing existing DOJ grant funds to be used for fraud analysts, victim-support training, blockchain tracing software, and financial-information sharing with law enforcement. It addresses scams like pig butchering, often run by transnational criminal groups overseas; Americans lost a record $11.4 billion to crypto-related fraud in 2025, including $8.6 billion in investment fraud. Senators Katie Britt and Kirsten Gillibrand introduced a Senate companion in July 2025, and the House also passed a bill retroactively eliminating the 'scam tax' on stolen funds for 2021-2025 victims.

The Record · 16h agoPolicy & legal

Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

Rapid7 research uncovered dark web marketplaces trading executive Social Security numbers, fueling synthetic identity fraud and unauthorized lines of credit.

Rapid7 threat research documents dark web marketplaces where stolen executive Social Security numbers are bought and sold, a tier of the cybercrime ecosystem more durable than stolen payment cards because SSNs cannot be deactivated. Exposed SSNs enable unauthorized credit lines, synthetic identity fraud, and long-term impersonation. The article cites FTC statistics of over 1 million identity theft reports annually, with related fraud and imposter scams causing billions in losses each year.

Rapid7 Blog · 20d agoResearch

Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023

FinCEN urged banks to report cyber scams after a study found $12.7 billion stolen from US victims of crypto investment scams since 2023.

FinCEN analyzed more than 33,000 cyber fraud incident reports filed by roughly 1,300 financial institutions between September 2023 and December 2025, finding about $12.7 billion in losses to cryptocurrency investment scams across all 50 states. Traditional banks reported about $6.4 billion in suspected scam activity and crypto firms about $5.5 billion. Scam activity is growing, with monthly reports rising nearly 11% as centers expand beyond Myanmar, Cambodia, and Laos. The US later sanctioned Xinbi Guarantee, a Telegram-based marketplace used to launder over $36 billion.

The Record · 6d agoPhishing & fraud

Getting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planning

Opinion piece urges organizations to begin post-quantum cryptography migration now, citing harvest-now-decrypt-later risk and NIST deadlines.

CSO Online outlines why harvest-now-decrypt-later makes long-lived sensitive data a current risk even before quantum computers exist. It cites NIST IR 8547 timelines deprecating RSA-2048 and ECC P-256 by 2030 and removing them by 2035, finalized FIPS standards ML-KEM, ML-DSA, and SLH-DSA, upcoming FN-DSA (FIPS 206), NSA requirements for national security systems from 2027, and UK NCSC phased guidance through 2035. The author recommends cryptographic discovery, crypto-agility, and prioritizing long-confidentiality data and TLS endpoints.

CSO Online · 7d agoResearch

How MSSPs Can Prove Their Value When “Nothing Happened”

ANY.RUN outlines how MSSPs can demonstrate SOC value by reporting investigation outcomes, threat patterns, and response metrics using its sandbox products.

ANY.RUN's blog argues MSSPs should report investigation outcomes, decision speed, and recurring threat patterns rather than raw alert counts. It cites company 2026 data: email accounts for 30.3% of MSSP sandbox submissions, and customers report 20% less Tier 1 investigation time and 30% fewer Tier 1 to Tier 2 escalations. Frequently analyzed threat families include ClickFix, Sneaky2FA, EvilTokens, EtherHiding, and Kali365.

ANY.RUN · 2h agoIndustry 3 sources

On Identifying Sound Conditions for Frontrunning Resistance

Researchers formally define smart-contract frontrunning resistance, showing 55% of 393 audited vulnerabilities escape state-of-the-art detection, and find two undisclosed Ethereum flaws.

The paper gives the first formal definition of frontrunning vulnerability for smart contracts, grounded in how honest users interact with contracts rather than contract code alone. In a large-scale study of 287 smart contract audits, 55% of the 393 vulnerabilities reported by leading auditors fall outside the scope of state-of-the-art dynamic detection criteria. The authors present a sound algorithm for synthesizing secure interaction conditions and apply it to real-world contracts, uncovering previously undiscovered vulnerabilities in two Ethereum contracts.

arXiv cs.CR · 6d agoResearch

ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability

ZDI advisory discloses Microsoft Exchange remote code execution flaw (CVE-2026-62911, CVSS 7.2) with bypassable authentication.

ZDI advisory ZDI-26-535 describes an external control of file path vulnerability in Microsoft Exchange, tracked as CVE-2026-62911 with a CVSS score of 7.2. Remote attackers can execute arbitrary code on affected installations. Although authentication is required, the existing authentication mechanism can be bypassed.

ZDI Published Advisories · Aug 11, 2026AdvisoryCVE-2026-62911

CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF

Apache Impala CVE-2026-57866 lets authenticated users abuse ai_generate_text() to exfiltrate secrets from configured Hadoop credential providers via SSRF.

A server-side request forgery affects Apache Impala versions 4.4.0 through 4.5.1. Authenticated users with permission to execute the ai_generate_text() function can exfiltrate secrets provided by credential providers configured via hadoop.security.credential.provider.path in core-site.xml. The attacker must know the secret's key name, and Apache rates the issue 'important'.

Iranian banks' SSL certificates are being revoked due to OFAC sanctions

OFAC sanctions are reportedly causing Iranian banks' SSL certificates to be revoked, threatening secure HTTPS access to their services.

A Hacker News discussion highlights a report that Iranian banks' SSL/TLS certificates are being revoked as a consequence of OFAC sanctions. Certificate revocation would degrade or break trusted HTTPS connections to affected banking domains for users in Iran. The item is a headline-only discussion post with limited detail on which certificate authorities or banks are affected.

Hiding Prompt Injection in Legal Filing

A judge banned a plaintiff from electronic court filings after hidden prompt-injection text was discovered planted in legal documents.

Bruce Schneier's blog discusses an incident in which hidden prompt-injection instructions were planted inside a legal filing, apparently targeting AI systems that might process court documents. Judge Walter Spader Jr. responded by banning the plaintiff from electronic filings, requiring all future submissions as printed hard copies. Commenters debate whether the tactic could affect future AI-based processing of court records and whether plain-text formats will regain favor.

Schneier on Security · 16d agoAI safety & security in the wild

From ‘High/Medium/Low’ to Dollars: Making Cyber Risk Legible to Your CFO

Cyble argues security teams should express cyber risk in financial terms for CFOs instead of high/medium/low ratings, citing its 2025 threat forecast results.

Cyble published guidance on cyber risk quantification, arguing qualitative high/medium/low ratings fail to convey financial exposure to executives. The piece notes that over 80% of its 2025 threat predictions, including AI-driven ransomware and supply-chain attacks, materialized as anticipated.

Cyble · 23d agoIndustry

Legora reviewed 41 documents in minutes with GPT-6 Astra

Legal-tech firm Legora says GPT-6 Astra reviewed 41 financial documents in minutes, catching all four planted errors and boosting accuracy about 40%.

Legal technology company Legora reported using OpenAI's GPT-6 Astra to review 41 financial-statement documents in minutes. The workflow found all four planted errors and improved performance by nearly 40% compared to prior processes. The case study highlights AI-assisted financial review adoption in professional services.

OpenAI News · 13d agoAI industry

I've factored the RSA keys of a Certificate Authority from the 90s

Security researcher factored two 512-bit RSA root CA keys from defunct 1990s certificate authority E-Certify using CADO-NFS on a desktop in roughly 30 hours each.

A researcher extracted legacy root certificates from archived Netscape and Internet Explorer installers, identifying two 512-bit RSA roots shipped with Netscape 4.51 in 1999 by the defunct Canadian CA E-Certify. Using CADO-NFS on a Ryzen 9 5950X desktop, the keys were factored in 32 and 29 hours respectively, allowing private key reconstruction. The work comes shortly after RSA-260 (862-bit) was factored, the largest known factorization to date. The researcher also built a legacy TLS server and published keys and tools on GitHub.

Srsly Risky Biz: Trump's Private Hacker Memo Is the Right Idea

A Trump presidential memo directs DHS to authorize vetted private-sector hackers to conduct cyber operations against foreign cybercriminal groups (CE-TCOs).

A presidential memorandum directs the Department of Homeland Security to establish a program authorizing private companies to conduct cyber surveillance and cyber effects operations against Cyber-Enabled Transnational Crime Organisations (CE-TCOs). Participating companies must pass vetting, obtain government approval before operations, and post a USD $1 million bond. The accompanying fact sheet cites more than USD $20.8 billion in US losses to cyber-enabled crime in 2025. Critics worry about accidental escalation if operations touch foreign government systems.

Risky Business News · 28d agoPolicy & legal1

Re: Retrospective by 'gpg.fail' authors

GPG exploitation talk author clarifies a format-string 0day enabling code execution via printf %n writes and a polyglot PEM certificate payload.

Lexi Groves, author of the gpg.fail talk, clarified on oss-security that the first finding was an actual zero-day: a classic printf injection using %n for memory writes, with multiple X.509 certificates in one PEM file to re-enter and defeat ASLR before calling execv@plt. The payload executed the certificate itself, a polyglot file made by inserting a shebang and bash command into the PEM. A second finding was hash-collided by another party before the author could exploit it.

oss-securityupdated · 7h agofirst · 1d agoResearch 9 sources

US Finance Under Phishing Pressure: What the SOC Data Reveals?

ANY.RUN SOC telemetry shows escalating phishing campaigns against US finance, including Vercel-hosted RMM attacks abusing legitimate services.

ANY.RUN analyzed SOC telemetry data on phishing targeting the US financial sector, concluding that the scale and security impact should not be understated. The analysis highlights modern campaigns such as Vercel-hosted attacks that deliver remote monitoring and management (RMM) tools. It notes that attackers increasingly abuse legitimate services and everyday workflow tools to deliver phishing, making detection harder for SOC teams.

ANY.RUN · 22d agoPhishing & fraud in the wild

From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline

Cyble walkthrough maps how infostealer logs move from endpoint infection through aggregation and enrichment to dark web credential marketplace sales.

Cyble breaks the credential theft pipeline into stages: infostealer execution harvesting browser credential stores, cookies, session tokens, crypto wallets, and FTP configurations; aggregation of stealer logs via C2 panels into bundled archives; parsing and enrichment against previously leaked datasets; and final listing on dark web marketplaces. Enrichment adds employer and role context that raises prices and enables credential stuffing across reused passwords. The report advises SOC teams to monitor stealer logs and marketplace chatter early rather than waiting for breach alerts.

Cyble · 6d agoMalware1

Revolut’s paperwork breach shows why insurers are rethinking what counts as a ‘cyber attack’

Revolut handed customer data to an attacker using a spoofed government email, prompting insurers to rethink cyber attack coverage definitions.

Revolut disclosed customer data after receiving a request from what appeared to be a genuine government email address; no servers were breached and no malware was involved. The social engineering incident has become a test case for how cyber insurers define a 'cyber attack'. The report is by Matthew Sellers. It highlights a growing gap between technical intrusions and data-loss incidents caused by impersonation.

DataBreaches.net · 1d agoData breach

Group of Bipartisan Lawmakers Ask US Government to Ban Several Hack-for-Hire Firms

Bipartisan US lawmakers urged Commerce Secretary Lutnick to sanction three Indian hack-for-hire firms, including BellTroX, over espionage targeting US citizens.

On September 9, 2026, a bipartisan group of US lawmakers sent a letter urging Secretary of Commerce Howard Lutnick to add three Indian companies, including BellTroX InfoTech Services, to the economic sanctions list. The firms are accused of targeted espionage against US citizens, businesses, and their lawyers, as well as lawfare to censor investigative reporting by major American media. The request builds on Citizen Lab's 2020 discovery of the Dark Basin hack-for-hire operation, which targeted US nonprofits involved in #ExxonKnew and net neutrality advocacy and was linked to BellTroX and related entities.

Citizen Lab · 6d agoPolicy & legal1

ZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI discloses an out-of-bounds write in Windows ICC file parsing via Mscms.dll enabling remote code execution (CVE-2026-54984, CVSS 7.8).

ZDI advisory ZDI-26-543 describes an out-of-bounds write in Microsoft Windows ICC file parsing that allows remote attackers to execute arbitrary code. Exploitation requires interaction with the Mscms.dll color management library, though attack vectors may vary by implementation. The flaw has a CVSS rating of 7.8 and is assigned CVE-2026-54984.

ZDI Published Advisories · Aug 11, 2026VulnerabilityCVE-2026-549841

Researching Employment Scams

Schneier highlights research into North Korean fake-employment IT-worker scams that embed operatives in remote roles for long-term insider access.

The post discusses research into employment scams in which fabricated remote workers, associated with North Korean IT-worker schemes, embed in organizations for months or years to exfiltrate data or position for financial theft. Researchers used controlled sandbox environments to observe operatives syncing personal accounts and working under false identities. Commenters also note reverse scams targeting desperate job seekers through high-pressure MLM and door-to-door sales schemes.

Schneier on Security · 13d agoPhishing & fraud

Server-Side Request Forgery (SSRF)

Fortinet discloses a low-severity SSRF in the FortiSIEM GUI allowing authenticated attackers to send requests from targeted devices.

Fortinet PSIRT advisory FG-IR-26-159, revised 2026-08-12, describes a server-side request forgery (CWE-918) in the FortiSIEM GUI, scored CVSSv3 3.4. An authenticated attacker can send HTTP requests originating from the targeted device via specially crafted requests, potentially enabling internal network probing. No CVE identifier or exploitation status is included in the advisory text.

Fortinet PSIRT · Aug 12, 2026Advisory

You don’t have to join the hack-back program to inherit its risk

A new US presidential memorandum creates a vetted private hack-back program, leaving participating vendors and their customers with untested legal liability and collateral risks.

The August 12 National Security Presidential Memorandum directs the National Coordination Center, run jointly by DOJ and DHS, to approve covert surveillance and disruptive Cyber Effects Operations by vetted private companies, with a forfeitable bond of at least $1 million required as a contract condition. The analysis argues the criminal shield rests on an untested reading of the CFAA exemption at 18 U.S.C. 1030(f), with no civil safe harbor, no state-law preemption and no foreign-law protection. Non-participating organizations can still inherit risk through shared infrastructure collateral damage, lack of customer disclosure, Lloyd's bulletin Y5381 state-backed attack exclusions, and threat-intelligence pipelines feeding offensive proposals.

CSO Online · 1d agoPolicy & legal

E-Commerce Access, Vedicline Data, Langflow RCE, ASUS Claim, and Energy Shell Access

SOCRadar reports underground posts claiming a Bangladeshi e-commerce database, Vedicline data leak, Langflow RCE, ASUS breach, and energy-sector shell access.

SOCRadar's Dark Web Team identified several new underground posts, including an alleged Bangladeshi e-commerce customer database offered for sale. The roundup also covers a claimed Vedicline data leak, Langflow remote code execution, an ASUS breach claim, and energy-sector shell access sales. Details on record counts and victims were not provided in the excerpt.

SOCRadar · 10d agoData breach

Details emerge on BlackFile's recent attacks on financial companies

BlackFile (UNC6671), a The Com-linked extortion crew, keeps hitting financial and med tech firms with voice-phishing IT-support scams and ~$3 million demands.

Google Threat Intelligence Group (tracking BlackFile as UNC6671, linked to The Com) reports the extortion group remains active, shifting focus to the financial sector and med tech organizations, with new Redact-brand extortion demands issued last week. The group impersonates IT support in voice-phishing attacks using hundreds of recruited callers, targets large firms in what researchers call big-game hunting, and processes an average of 1.5 new victims daily. Extortion demands start around $3 million and are typically negotiated below $1 million; Flashpoint observed infrastructure targeting Blackstone, Bain Capital, Moody's, CME, and Apollo, though compromise is unconfirmed. Mandiant has responded to more than two dozen BlackFile compromises since January, and victims face escalation tactics including swatting.

CyberScoop · Aug 17, 2026Threat actor in the wild

Risky Bulletin: White House lets private companies carry out offensive cyber ops

A White House memo directs DHS to create a program letting vetted private companies conduct US-government-directed offensive cyber operations against cybercrime.

A presidential memo tasks the DHS National Coordination Center with building a program, under DOJ and DHS oversight, through which private-sector companies can conduct offensive cyber operations against large-scale cybercrime organizations. Requirements include secure facilities, vetted personnel, a $1 million escrow for damages, and written approvals co-signed by DHS and DOJ executive directors. The program must launch within 60 days, around October 11, expanding a March executive order targeting scam compounds, ransomware, and other large-scale cybercrime.

Risky Business News · Aug 14, 2026Policy & legal

Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks

Revolut handed over KYC documents, selfies, and Bitcoin transaction histories to attackers after a fraudulent email from a genuine government domain passed authentication checks.

Revolut confirmed on September 12, 2026 that it disclosed sensitive customer KYC data to an unauthorized third party after a fraudulent information request was sent from an email account operating inside a real government agency's domain, carrying valid domain authentication credentials. The exposed data included identity documents (passports, driver's licenses), verification selfies, birth dates, contact details, IBANs, account statements, and full transaction histories including Bitcoin. Revolut discovered the fraud only after independently verifying with the agency, blocked the sender, and notified law enforcement and financial regulators, but did not disclose the number of affected customers or the agency involved. Researcher ZachXBT assessed the operation was targeted at high-net-worth users, useful for fraud, impersonation, or extortion.

Security Affairs · 4d agoData breach

ASCII smuggling isn't just an AI security risk

Microsoft tracked a phishing campaign peaking at 2.37 million daily messages that hid financial-lure keywords with invisible Unicode tag characters to evade filters.

Microsoft researchers uncovered a large phishing campaign that inserted invisible Unicode tag characters (e.g., U+E0020) inside common financial keywords like 'funding', splitting words so keyword, signature, and regex matches fail. The campaign peaked at more than 2.37 million messages in late February 2026, ran from about 150 finance-themed sender domains on a strict weekday-only schedule, and gradually declined to under 20% of peak weekday volume by late March, with residual spikes through mid-June. The technique repurposes ASCII smuggling, normally used for indirect prompt injection against AI assistants, for traditional email phishing evasion. Microsoft advises defenders to strip or fold invisible Unicode code points before content matching and to watch for bulk weekday spikes from churning finance-themed domains.

The Register · Security · 12d agoPhishing & fraud in the wild1