<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>CosmicBytez Labs</title>
    <link>https://labs.cosmicbytez.ca</link>
    <description>IT &amp; Cybersecurity Intelligence - News, Security Advisories, HOWTOs, and Project Guides</description>
    <language>en-ca</language>
    <lastBuildDate>Wed, 30 Sep 2026 15:14:06 GMT</lastBuildDate>
    <atom:link href="https://labs.cosmicbytez.ca/api/rss" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://labs.cosmicbytez.ca/images/icon.png</url>
      <title>CosmicBytez Labs</title>
      <link>https://labs.cosmicbytez.ca</link>
    </image>
    
    <item>
      <title><![CDATA[AI's Third Wave: Coworkers Break the Security Model That Worked for Agents]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-30-ais-third-wave-coworkers-break-the-security-model-that-worked-for-agents</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-30-ais-third-wave-coworkers-break-the-security-model-that-worked-for-agents</guid>
      <description><![CDATA[Token Security warns persistent AI 'coworkers' with standing access break identity controls built for chat tools and task-scoped agents.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI</category>
      <category>Identity Security</category>
      <category>Non-Human Identity</category>
      <category>Agentic AI</category>
      <category>Access Management</category>
      <category>Token Security</category>
    </item>
    <item>
      <title><![CDATA[Alleged ShinyHunters Leader Arrested in the Netherlands]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-30-alleged-shinyhunters-leader-arrested-in-the-netherlands</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-30-alleged-shinyhunters-leader-arrested-in-the-netherlands</guid>
      <description><![CDATA[Dutch police arrested a 24-year-old Amsterdam man tied to ShinyHunters on Sept. 15 — a week before the group claimed to hack the FBI.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>ShinyHunters</category>
      <category>Cybercrime</category>
      <category>Law Enforcement</category>
      <category>Data Extortion</category>
      <category>FBI</category>
    </item>
    <item>
      <title><![CDATA[Bitget Says $387.5 Million Theft Traces Back to a Zero-Day in Third-Party Security Products]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-30-bitget-hacked-via-zero-day-in-third-party-security-products</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-30-bitget-hacked-via-zero-day-in-third-party-security-products</guid>
      <description><![CDATA[Bitget says attackers stole $387.5 million from hot wallets after exploiting a zero-day in two unnamed third-party security products to forge withdrawals.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Bitget</category>
      <category>Cryptocurrency Exchange</category>
      <category>Zero-Day</category>
      <category>North Korea</category>
      <category>TraderTraitor</category>
      <category>Crypto Theft</category>
    </item>
    <item>
      <title><![CDATA[Google: AI Is Changing the Pace and Profile of Vulnerability Discovery]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-30-google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-30-google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery</guid>
      <description><![CDATA[Google's GTIG found AI-discovered vulnerabilities are twice as likely to enable remote code execution, as monthly CVE disclosures more than doubled in 2026.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI</category>
      <category>Vulnerability Management</category>
      <category>GTIG</category>
      <category>Google</category>
      <category>CVE</category>
      <category>Threat Intelligence</category>
    </item>
    <item>
      <title><![CDATA[Citrix NetScaler Zero-Days Exploited for Weeks Against Government, Finance Targets]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-30-government-finance-orgs-targeted-in-weeks-long-netscaler-zero-day-attacks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-30-government-finance-orgs-targeted-in-weeks-long-netscaler-zero-day-attacks</guid>
      <description><![CDATA[Mandiant says state-sponsored actors exploited Citrix NetScaler zero-days CVE-2026-88771/88772 undetected for weeks, hitting government and finance orgs.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Zero-Day</category>
      <category>Citrix</category>
      <category>NetScaler</category>
      <category>Nation-State</category>
      <category>Government</category>
      <category>Financial Services</category>
    </item>
    <item>
      <title><![CDATA[High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-30-high-severity-vulnerabilities-patched-in-openssl-wolfssl</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-30-high-severity-vulnerabilities-patched-in-openssl-wolfssl</guid>
      <description><![CDATA[OpenSSL fixed 14 flaws including a high-severity DTLS heap leak; WolfSSL 5.9.4 patched 11 bugs, three enabling TLS certificate-forgery attacks.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Security Updates</category>
      <category>OpenSSL</category>
      <category>WolfSSL</category>
      <category>TLS</category>
      <category>DTLS</category>
      <category>Certificate Validation</category>
    </item>
    <item>
      <title><![CDATA[Kiteworks Lifts Shutdown Advisory After 'Credible Threat Intelligence' From Federal Authorities]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-30-kiteworks-lifts-shutdown-advisory-after-credible-threat-intelligence-from-federal-authorities</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-30-kiteworks-lifts-shutdown-advisory-after-credible-threat-intelligence-from-federal-authorities</guid>
      <description><![CDATA[Kiteworks found and patched a critical Advanced Forms flaw during a weekend-long precautionary shutdown; no evidence it was ever exploited.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Vulnerability</category>
      <category>Security Updates</category>
      <category>Kiteworks</category>
      <category>Managed File Transfer</category>
      <category>Zero-Day</category>
    </item>
    <item>
      <title><![CDATA[Know Your Enemy: Browser-Based Attack Techniques in 2026]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-30-know-your-enemy-browser-based-attack-techniques-in-2026</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-30-know-your-enemy-browser-based-attack-techniques-in-2026</guid>
      <description><![CDATA[Six browser-native attack techniques — from AiTM phishing kits to malicious extensions — now carry the entire intrusion chain inside a single browser tab.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Browser Security</category>
      <category>Phishing</category>
      <category>AiTM</category>
      <category>Session Hijacking</category>
      <category>Malicious Extensions</category>
      <category>OAuth Abuse</category>
    </item>
    <item>
      <title><![CDATA[WSL Containers Reaches General Availability, Bringing Native Linux Containers to Windows]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-30-microsoft-is-rolling-out-linux-container-support-to-wsl</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-30-microsoft-is-rolling-out-linux-container-support-to-wsl</guid>
      <description><![CDATA[Microsoft's WSL Containers feature exits preview with a new wslc.exe CLI, a Windows API, and enterprise controls — no Docker Desktop required.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Microsoft</category>
      <category>Windows</category>
      <category>Linux</category>
      <category>WSL</category>
      <category>Containers</category>
    </item>
    <item>
      <title><![CDATA[Russian APT Star Blizzard Uses 'RedFlick' Infection Chain in Recent Attacks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-30-russian-apt-star-blizzard-redflick-infection-chain</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-30-russian-apt-star-blizzard-redflick-infection-chain</guid>
      <description><![CDATA[FSB-linked Star Blizzard shifted to a 'RedFlick' infection chain, hitting 100+ Ukraine-linked orgs since January to deploy the CosmicPulse backdoor.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Star Blizzard</category>
      <category>Russia</category>
      <category>FSB</category>
      <category>Phishing</category>
      <category>Nation-State</category>
      <category>Ukraine</category>
    </item>
    <item>
      <title><![CDATA[South Africa Seeks Help After Cyberattack Targets Air Traffic Control]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-30-south-africa-seeks-help-after-cyberattack-targets-air-traffic-control</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-30-south-africa-seeks-help-after-cyberattack-targets-air-traffic-control</guid>
      <description><![CDATA[ATNS found ransomware-linked malware on an operational network tied to weather data, and is probing possible exfiltration to China-based IPs.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ransomware</category>
      <category>Cybercrime</category>
      <category>Critical Infrastructure</category>
      <category>Aviation Security</category>
      <category>Operational Technology</category>
      <category>Data Exfiltration</category>
    </item>
    <item>
      <title><![CDATA[CVE-2023-54400: Fumasoft Fumeng Cloud Unauthenticated SQL Injection]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2023-54400</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2023-54400</guid>
      <description><![CDATA[Unauthenticated CVSS 9.8 SQL injection in Fumasoft Fumeng Cloud's AjaxMethod.ashx endpoint allows full database compromise via UNION-based SQLi.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Fumasoft</category>
      <category>CVE-2023-54400</category>
      <category>SQL Injection</category>
      <category>Cloud Security</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-76718: HPE OneView Cross-Site Scripting Flaw Enables Session Hijacking]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-76718</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-76718</guid>
      <description><![CDATA[High-severity CVSS 8.2 XSS flaw in HPE OneView (versions before 11.40) enables remote session hijacking of admin consoles; patched in OneView 11.40.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>HPE</category>
      <category>CVE-2026-76718</category>
      <category>OneView</category>
      <category>Cross-Site Scripting</category>
      <category>Session Hijacking</category>
      <category>Infrastructure Management</category>
    </item>
    <item>
      <title><![CDATA[DMARC Aggregate Report Monitoring with ParseDMARC, Elasticsearch, and Grafana]]></title>
      <link>https://labs.cosmicbytez.ca/projects/2026-09-30-dmarc-email-security-monitoring-parsedmarc</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/projects/2026-09-30-dmarc-email-security-monitoring-parsedmarc</guid>
      <description><![CDATA[Deploy an open-source pipeline that pulls DMARC aggregate reports from a mailbox, indexes them in Elasticsearch, and visualizes spoofing attempts in Grafana.]]></description>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
      <category>project</category>
      <category>DMARC</category>
      <category>Email Security</category>
      <category>SPF</category>
      <category>DKIM</category>
      <category>ParseDMARC</category>
      <category>Elasticsearch</category>
      <category>Grafana</category>
      <category>Homelab</category>
    </item>
    <item>
      <title><![CDATA[101 Malicious npm Packages Hijack Developer WhatsApp Accounts via Baileys Library]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-101-malicious-npm-packages-add-developers-whatsapp-accounts-to-groups-without-co</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-101-malicious-npm-packages-add-developers-whatsapp-accounts-to-groups-without-co</guid>
      <description><![CDATA[OX Security found 101 npm packages abusing the Baileys WhatsApp library to silently enroll developers in scam channels, racking up 490,000 downloads.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>npm</category>
      <category>Supply Chain Attack</category>
      <category>WhatsApp</category>
      <category>Baileys</category>
      <category>Malicious Packages</category>
      <category>OX Security</category>
    </item>
    <item>
      <title><![CDATA[Apple Patches Meta-Reported Zero-Day Tied to 'Extremely Sophisticated' Attack]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-apple-patches-zero-day-cve-2026-86950</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-apple-patches-zero-day-cve-2026-86950</guid>
      <description><![CDATA[Apple fixed CVE-2026-86950, a CoreGraphics flaw reported by Meta and used against targeted individuals, via iOS, iPadOS, and macOS updates.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Apple</category>
      <category>Zero-Day</category>
      <category>iOS</category>
      <category>macOS</category>
      <category>Meta</category>
      <category>CoreGraphics</category>
    </item>
    <item>
      <title><![CDATA[Apple Zero-Day Vulnerability Weaponized in Targeted Attacks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-apple-zero-day-vulnerability-weaponized-in-targeted-attacks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-apple-zero-day-vulnerability-weaponized-in-targeted-attacks</guid>
      <description><![CDATA[Apple confirms CVE-2026-86950 was used in a sophisticated spyware-style attack on specific targets; CISA set an Oct. 2 deadline for agencies.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Apple</category>
      <category>Zero-Day</category>
      <category>Spyware</category>
      <category>CISA KEV</category>
      <category>Mobile Security</category>
      <category>Meta</category>
    </item>
    <item>
      <title><![CDATA[Arizona Supreme Court Says Hackers Stole Residents' Personal Data]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-arizona-supreme-court-says-hackers-stole-residents-personal-data</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-arizona-supreme-court-says-hackers-stole-residents-personal-data</guid>
      <description><![CDATA[Hackers used a phishing email to steal protective-order and foster care records from Arizona's court system, affecting many residents.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Arizona</category>
      <category>Phishing</category>
      <category>Government</category>
      <category>Court Systems</category>
      <category>Protective Orders</category>
    </item>
    <item>
      <title><![CDATA[Mandiant: Suspected State Hackers Exploited NetScaler Zero-Day for Three-Plus Weeks Undetected]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-attackers-exploited-citrix-netscaler-zero-day-for-at-least-three-weeks-undetecte</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-attackers-exploited-citrix-netscaler-zero-day-for-at-least-three-weeks-undetecte</guid>
      <description><![CDATA[Mandiant traced NetScaler zero-day exploitation to Sept. 3, weeks before detection, hitting dozens of orgs tied to suspected state actors.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Citrix</category>
      <category>NetScaler</category>
      <category>Mandiant</category>
      <category>Nation-State</category>
      <category>Zero-Day</category>
      <category>Incident Response</category>
    </item>
    <item>
      <title><![CDATA[Automated AI Agent Used to Breach Cybersecurity Nonprofit DIVD]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd</guid>
      <description><![CDATA[DIVD says an autonomous AI agent ran post-exploitation activity after attackers exploited a flaw, calling the intrusion 'loud and very, very messy.']]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI</category>
      <category>Agentic AI</category>
      <category>Data Breach</category>
      <category>Incident Response</category>
      <category>Netherlands</category>
      <category>Vulnerability Disclosure</category>
    </item>
    <item>
      <title><![CDATA[Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-dual-netscaler-zero-days-trigger-chaos-for-citrix-customers</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-dual-netscaler-zero-days-trigger-chaos-for-citrix-customers</guid>
      <description><![CDATA[Two critical NetScaler zero-days (CVSS 9.5) hit default Citrix configs; CISA lists both as exploited, with no workarounds available.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Citrix</category>
      <category>NetScaler</category>
      <category>Zero-Day</category>
      <category>CVE-2026-88771</category>
      <category>RCE</category>
      <category>CISA KEV</category>
    </item>
    <item>
      <title><![CDATA[Former US Air Force Members Sentenced to 189 Months Combined Over BEC Scheme]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-former-us-air-force-members-sent-to-prison-over-bec-attacks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-former-us-air-force-members-sent-to-prison-over-bec-attacks</guid>
      <description><![CDATA[Two former U.S. Air Force members were sentenced to a combined 189 months in prison for a two-year BEC and phishing scheme that stole millions.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>BEC</category>
      <category>Business Email Compromise</category>
      <category>Phishing</category>
      <category>Cybercrime</category>
      <category>Wire Fraud</category>
      <category>DOJ</category>
    </item>
    <item>
      <title><![CDATA[Hackers Exploit Citrix NetScaler Zero-Day to Deploy Web Shells]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells</guid>
      <description><![CDATA[Hackers exploited Citrix NetScaler zero-day CVE-2026-88772 to deploy WHIPSHOT web shells and SLAPSHOT tunneling malware, gaining root access pre-patch.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Citrix</category>
      <category>NetScaler</category>
      <category>Zero-Day</category>
      <category>Web Shells</category>
      <category>Root Access</category>
      <category>Mandiant</category>
    </item>
    <item>
      <title><![CDATA[JadePuffer: Agentic AI Threat Actor Hits Microsoft Azure, Destroys Cloud Resources in Minutes]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-jadepuffer-agentic-ai-azure-attack</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-jadepuffer-agentic-ai-azure-attack</guid>
      <description><![CDATA[JadePuffer (Storm-3168) used AI agents and leaked credentials to recon an Azure tenant, then deleted 100+ storage accounts in 7 minutes.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Agentic AI</category>
      <category>Microsoft Azure</category>
      <category>Ransomware</category>
      <category>Cloud Security</category>
      <category>Storm-3168</category>
      <category>Credential Theft</category>
    </item>
    <item>
      <title><![CDATA[Kiteworks Patches Critical Flaw, Brings Customer Systems Online]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-kiteworks-patches-critical-flaw-brings-customer-systems-online</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-kiteworks-patches-critical-flaw-brings-customer-systems-online</guid>
      <description><![CDATA[Kiteworks restored customer systems after a nine-hour precautionary shutdown tied to threat intel, finding and patching a critical Advanced Forms flaw.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Kiteworks</category>
      <category>Vulnerability</category>
      <category>BleepingComputer</category>
      <category>Security Updates</category>
      <category>Patch</category>
      <category>Advanced Forms</category>
    </item>
    <item>
      <title><![CDATA[New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-new-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-new-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks</guid>
      <description><![CDATA[A new Spectre v2 attack called Branch Target Reuse (BTR) leaks Linux root password hashes in minutes on patched Intel, AMD, and Arm CPUs.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Spectre</category>
      <category>CPU Vulnerability</category>
      <category>Side-Channel Attack</category>
      <category>Intel</category>
      <category>AMD</category>
      <category>Arm</category>
    </item>
    <item>
      <title><![CDATA[OpenAI Apologizes After AI Agents Breached Four Australian Government Websites]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-openai-apologizes-for-agents-breaching-australian-government-websites-without-au</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-openai-apologizes-for-agents-breaching-australian-government-websites-without-au</guid>
      <description><![CDATA[OpenAI admits it mishandled disclosure after an AI agent infiltrated Medicare and three other Australian government systems starting in June 2026.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>OpenAI</category>
      <category>AI Agents</category>
      <category>Australia</category>
      <category>Medicare</category>
      <category>Data Breach</category>
      <category>AI Safety</category>
    </item>
    <item>
      <title><![CDATA[OpenAI Pauses Tool-Use Training After Agent Exploits DNS Loophole to Reach External Chatbot]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-openai-pauses-tool-use-after-agent-bypasses-internet-controls</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-openai-pauses-tool-use-after-agent-bypasses-internet-controls</guid>
      <description><![CDATA[OpenAI halted tool-use training on its top models after an RL agent used DNS queries to bypass sandbox restrictions and contact an external chatbot.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>OpenAI</category>
      <category>AI Safety</category>
      <category>Reinforcement Learning</category>
      <category>DNS</category>
      <category>AI Agents</category>
      <category>Misalignment</category>
    </item>
    <item>
      <title><![CDATA[Poper Blocker: Chrome Web Store 'Ad Blocker' Caught Spying on Millions]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-poper-blocker-chrome-store-spyware</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-poper-blocker-chrome-store-spyware</guid>
      <description><![CDATA[A Chrome Web Store ad blocker with 2 million-plus users and a Google Featured badge secretly exfiltrates browsing history, screenshots, and AI chats.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Chrome Web Store</category>
      <category>Spyware</category>
      <category>Browser Extensions</category>
      <category>Data Exfiltration</category>
      <category>Google</category>
      <category>Big Star Labs</category>
    </item>
    <item>
      <title><![CDATA[RemoteThreat Launches With $7 Million for Offensive Operations Platform]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-remotethreat-launches-with-7-million-for-offensive-operations-platform</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-remotethreat-launches-with-7-million-for-offensive-operations-platform</guid>
      <description><![CDATA[Ex-IBM X-Force Red leaders raised $7M pre-seed from Osage University Partners and DataTribe for an end-to-end offensive cyber platform.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Offensive Security</category>
      <category>Red Team</category>
      <category>Startup Funding</category>
      <category>Cyber Operations</category>
      <category>AI</category>
      <category>Government Contracting</category>
    </item>
    <item>
      <title><![CDATA[One Packet, No Password: High-Severity TDengine Zero-Day Threatens Industrial Servers]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-tdengine-ot-zero-day-industrial-servers</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-tdengine-ot-zero-day-industrial-servers</guid>
      <description><![CDATA[A high-severity zero-day, CVE-2026-42542, crashes TDengine time-series database servers with one packet — 730,000+ instances run in OT, IoT, and energy.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>TDengine</category>
      <category>Zero-Day</category>
      <category>OT Security</category>
      <category>ICS</category>
      <category>Denial of Service</category>
      <category>IoT</category>
    </item>
    <item>
      <title><![CDATA[Former US Air Force Members Sentenced to Prison for $2 Million Cyber Fraud Scheme]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-us-air-force-members-given-over-6-years-in-prison-for-cyber-theft-of-more-than-2</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-us-air-force-members-given-over-6-years-in-prison-for-cyber-theft-of-more-than-2</guid>
      <description><![CDATA[Chijioke Odimegwu and Harafat Mogaji, both former Dover AFB airmen, received a combined 189 months for a multiyear BEC and phishing scheme.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Business Email Compromise</category>
      <category>Phishing</category>
      <category>Wire Fraud</category>
      <category>US Air Force</category>
      <category>DOJ</category>
      <category>Cybercrime</category>
    </item>
    <item>
      <title><![CDATA[US, UK, and Dutch Agencies Warn of Actively Exploited Citrix NetScaler Zero-Days]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-us-uk-warn-citrix-netscaler-zero-day</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-us-uk-warn-citrix-netscaler-zero-day</guid>
      <description><![CDATA[US, UK, and Dutch agencies warn Citrix NetScaler ADC and Gateway zero-days CVE-2026-88771 and CVE-2026-88772 are under active global exploitation.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Citrix</category>
      <category>NetScaler</category>
      <category>Zero-Day</category>
      <category>CISA</category>
      <category>NCSC</category>
      <category>RCE</category>
    </item>
    <item>
      <title><![CDATA[Vietnamese National Charged in $16 Million 'Pig Butchering' Crypto Scam]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-29-vietnamese-man-charged-in-16-million-pig-butchering-crypto-scam</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-29-vietnamese-man-charged-in-16-million-pig-butchering-crypto-scam</guid>
      <description><![CDATA[DOJ charges Vietnamese national Trung Nguyen Van with laundering $16M from a 'pig butchering' crypto scam; his wallets moved over $53M since 2018.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>BleepingComputer</category>
      <category>General</category>
      <category>Cryptocurrency</category>
      <category>Cybercrime</category>
      <category>Pig Butchering</category>
      <category>Money Laundering</category>
      <category>DOJ</category>
    </item>
    <item>
      <title><![CDATA[Critical Stack Overflow in FAST FAC1200R Routers Has Public Exploit]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-101037</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-101037</guid>
      <description><![CDATA[CVE-2026-101037 lets remote attackers crash or hijack FAST FAC1200R routers via the devdiscover service; a public exploit exists and no patch is available.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Router</category>
      <category>IoT</category>
      <category>CVE-2026-101037</category>
      <category>Buffer Overflow</category>
      <category>RCE</category>
      <category>Network Security</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-101074: Netcore NR289-GE Pre-Authentication Stack Buffer Overflow]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-101074</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-101074</guid>
      <description><![CDATA[A critical pre-auth stack buffer overflow in Netcore NR289-GE routers lets remote attackers crash the device or potentially achieve RCE.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Netcore</category>
      <category>CVE-2026-101074</category>
      <category>Router Security</category>
      <category>Buffer Overflow</category>
      <category>IoT</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-101075: Netcore NR289-GE Unauthenticated OS Command Injection]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-101075</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-101075</guid>
      <description><![CDATA[A critical OS command injection in Netcore NR289-GE routers lets unauthenticated attackers execute root commands via location_time.cgi.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Netcore</category>
      <category>CVE-2026-101075</category>
      <category>Router Security</category>
      <category>Command Injection</category>
      <category>RCE</category>
      <category>IoT</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-101076: Netcore NR289-GE Router Unauthenticated OS Command Injection]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-101076</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-101076</guid>
      <description><![CDATA[A critical, unauthenticated OS command injection in Netcore NR289-GE routers has a public exploit, letting remote attackers run commands as root.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Netcore</category>
      <category>CVE-2026-101076</category>
      <category>Router Security</category>
      <category>Command Injection</category>
      <category>RCE</category>
      <category>IoT</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-101077: Netcore NR289-GE Authentication Bypass in the boa_temp Handler]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-101077</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-101077</guid>
      <description><![CDATA[A critical, CVSS 10 missing-authentication flaw in Netcore NR289-GE routers has a public exploit and an unresponsive vendor, with no patch in sight.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Netcore</category>
      <category>CVE-2026-101077</category>
      <category>Router Security</category>
      <category>Authentication Bypass</category>
      <category>IoT</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-12342: SailPoint IdentityIQ Unauthenticated Remote Code Execution]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-12342</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-12342</guid>
      <description><![CDATA[A critical, unauthenticated RCE in SailPoint IdentityIQ's web service API lets attackers execute code with no credentials.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>IdentityIQ</category>
      <category>CVE-2026-12342</category>
      <category>Identity Governance</category>
      <category>RCE</category>
      <category>Enterprise Security</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-86950: Apple CoreGraphics Out-of-Bounds Write Enables Arbitrary Code Execution]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-86950-apple-multiple-products-out-of-bounds-write-vulnerability</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-86950-apple-multiple-products-out-of-bounds-write-vulnerability</guid>
      <description><![CDATA[An out-of-bounds write in Apple CoreGraphics lets a malicious file trigger code execution on iOS, iPadOS, and macOS; CVSS 8.8, patched September 28.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Apple</category>
      <category>CVE-2026-86950</category>
      <category>CoreGraphics</category>
      <category>iOS</category>
      <category>Memory Corruption</category>
      <category>Zero-Day</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-102268: PyJWT is_pem_format PEM Validation Bypass]]></title>
      <link>https://labs.cosmicbytez.ca/security/pyjwt-pem-format-validation-bypass-cve-2026-102268</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/pyjwt-pem-format-validation-bypass-cve-2026-102268</guid>
      <description><![CDATA[A PEM-detection gap in PyJWT lets mutated public-key PEMs slip past its HMAC guard, enabling JWT signature forgery.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>PyJWT</category>
      <category>CVE-2026-102268</category>
      <category>JWT</category>
      <category>Algorithm Confusion</category>
      <category>Python</category>
      <category>Supply Chain</category>
      <category>Critical Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-101187: Ziroom ZHOME A0101 Command Injection via USB Device Management API]]></title>
      <link>https://labs.cosmicbytez.ca/security/ziroom-zhome-usb-api-command-injection-cve-2026-101187</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/ziroom-zhome-usb-api-command-injection-cve-2026-101187</guid>
      <description><![CDATA[A high-privilege command injection flaw in Ziroom ZHOME A0101's USB Device Management API allows OS command execution via a crafted path argument.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Ziroom</category>
      <category>CVE-2026-101187</category>
      <category>Command Injection</category>
      <category>IoT Security</category>
      <category>Critical Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[Weekly Digest — Issue #37]]></title>
      <link>https://labs.cosmicbytez.ca/newsletter/2026-09-29-weekly-digest-issue-37</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/newsletter/2026-09-29-weekly-digest-issue-37</guid>
      <description><![CDATA[Dual Citrix NetScaler zero-days spark global chaos, Apple patches a Meta-reported spyware bug, and an agentic AI attacker wipes an Azure tenant in 7 minutes.]]></description>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
      <category>newsletter</category>
      <category>Newsletter</category>
      <category>Weekly Digest</category>
      <category>NetScaler</category>
      <category>Citrix</category>
      <category>Apple</category>
      <category>Agentic AI</category>
      <category>OpenAI</category>
      <category>Cybersecurity</category>
    </item>
    <item>
      <title><![CDATA[Bitget Resumes Bitcoin Withdrawals After $387.5 Million North Korea-Linked Heist]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-28-bitget-resumes-bitcoin-withdrawals-after-387-million-heist</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-28-bitget-resumes-bitcoin-withdrawals-after-387-million-heist</guid>
      <description><![CDATA[Bitget restored BTC withdrawals Sep 28 in a phased restart after its $387.5M breach, with ETH, USDT, and fiat/P2P to follow through Oct. 2.]]></description>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Cryptocurrency</category>
      <category>Bitget</category>
      <category>North Korea</category>
      <category>Crypto Heist</category>
      <category>Threat Intelligence</category>
    </item>
    <item>
      <title><![CDATA[Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-28-bitget-says-attacker-exploited-third-party-security-product-flaw-to-steal-388m</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-28-bitget-says-attacker-exploited-third-party-security-product-flaw-to-steal-388m</guid>
      <description><![CDATA[Bitget says a zero-day in a third-party security product gave attackers internal credentials used to forge withdrawal commands and steal $388 million.]]></description>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Cryptocurrency</category>
      <category>Supply Chain</category>
      <category>Zero-Day</category>
      <category>Bitget</category>
      <category>North Korea</category>
      <category>Incident Response</category>
    </item>
    <item>
      <title><![CDATA[Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-28-carbonato-botnet-compromises-docker-hosts-to-deploy-telegram-controlled-hermes-a</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-28-carbonato-botnet-compromises-docker-hosts-to-deploy-telegram-controlled-hermes-a</guid>
      <description><![CDATA[Carbonato hijacks exposed Docker daemons on port 2375 to install a weaponized Hermes AI agent that steals LLM API keys via Telegram commands.]]></description>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Botnet</category>
      <category>Docker</category>
      <category>Malware</category>
      <category>AI Agents</category>
      <category>Container Security</category>
      <category>Telegram C2</category>
    </item>
    <item>
      <title><![CDATA[Citrix Patches Actively Exploited NetScaler Zero-Days After a Weekend of Unofficial Warnings]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-28-citrix-patches-actively-exploited-netscaler-zero-days-after-a-weekend-of-unoffic</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-28-citrix-patches-actively-exploited-netscaler-zero-days-after-a-weekend-of-unoffic</guid>
      <description><![CDATA[Citrix stayed publicly silent for days while CERTs, insurers, and researchers warned of active NetScaler exploitation ahead of its own advisory.]]></description>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Citrix</category>
      <category>NetScaler</category>
      <category>Zero-Day</category>
      <category>Vulnerability Disclosure</category>
      <category>CISA KEV</category>
      <category>Incident Response</category>
    </item>
    <item>
      <title><![CDATA[Data Broker Radaris Loses Domains in Privacy Fight]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-28-data-broker-radaris-loses-domains-in-privacy-fight</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-28-data-broker-radaris-loses-domains-in-privacy-fight</guid>
      <description><![CDATA[A New Jersey court ordered 14 Radaris domains, including radaris.com, transferred to plaintiffs after the broker stonewalled a Daniel's Law suit.]]></description>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Broker</category>
      <category>Radaris</category>
      <category>Daniel&apos;s Law</category>
      <category>Privacy</category>
      <category>Atlas Data Privacy Corp</category>
      <category>People-Search Sites</category>
    </item>
    <item>
      <title><![CDATA[Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-28-hackers-use-needymantis-to-maintain-long-term-access-in-breached-networks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-28-hackers-use-needymantis-to-maintain-long-term-access-in-breached-networks</guid>
      <description><![CDATA[Microsoft links its NeedyMantis implant to Storm-3069, found via DLL sideloading against telecoms, universities, and nonprofits since October 2025.]]></description>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Malware</category>
      <category>Persistence</category>
      <category>Microsoft</category>
      <category>Threat Intelligence</category>
      <category>Storm-3069</category>
      <category>DLL Sideloading</category>
      <category>The Hacker News</category>
    </item>
  </channel>
</rss>