<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:downlink="https://ma111e.github.io/downlink/ns">
  <channel>
    <title>Downlink Digests</title>
    <link>https://ma111e.github.io/downlink/digests-v2</link>
    <description>Latest intelligence digests from Downlink</description>
    <lastBuildDate>Mon, 21 Sep 2026 06:00:01 +0000</lastBuildDate>
    <item>
      <title>ChainScript ClickFix Campaign and Jade Sleet Target Developer Environments</title>
      <link>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-21_0600.html</link>
      <guid>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-21_0600.html</guid>
      <pubDate>Mon, 21 Sep 2026 06:00:01 +0000</pubDate>
      <description></description>
      <content:encoded><![CDATA[<p class="digest-window">Window: <time datetime="2026-09-21T06:00:01Z">21 Sep 06:00</time> → <time datetime="2026-09-21T10:00:01Z">21 Sep 10:00 UTC</time> (<data value="PT4H">4 hours</data>)</p>
<h3>Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors — Should Read</h3>
<p>North Korean-linked Jade Sleet compromised an Indian IT services provider’s DevOps engineer using macOS backdoors FLATROOF and ROOFDECK, likely as part of its developer-focused supply-chain operations. The campaign uses fake job-interview repositories with malicious Terraform lockfiles to infect Apple Silicon Macs and steal data, maintain persistence, and enable remote control.</p>
<ul>
<li>SentinelOne attributed the compromise of an India-based IT services provider to the North Korean threat actor Jade Sleet, also known as PUKCHONG, Slow Pisces, TraderTraitor, and UNC4899.</li>
<li>The campaign uses fake job-interview coding repositories containing a malicious Terraform dependency lock file that directs developers running terraform init to attacker-controlled modules.</li>
<li>The attackers deployed the Rust-based macOS backdoors FLATROOF and ROOFDECK, which can steal information, execute commands, manipulate files, and establish persistent access.</li>
<li>The compromised system was an Apple Silicon MacBook used by a DevOps engineer, where the backdoors were detected from March 18, 2026, and became active on March 29.</li>
<li>SentinelOne said developer endpoints can expose cloud environments, software pipelines, and source code, making them a high-priority target in third-party and software supply-chain compromises.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="operating-system">operating-system</data>, <data value="source-control">source-control</data>, <data value="ci-cd">ci-cd</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="terraform">terraform</data>, <data value="macos">macos</data>, <data value="github">github</data>, <data value="cursor">cursor</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="sentinelone">sentinelone</data>, <data value="hashicorp">hashicorp</data>, <data value="apple">apple</data>, <data value="github">github</data>, <data value="anysphere">anysphere</data></p>
<h3>ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure — Should Read</h3>
<p>Threat actors are using ClickFix lures and fake software installers to deploy the ChainScript Node.js RAT, which uses a Polygon smart contract to rotate its WebSocket command-and-control infrastructure and resist takedowns. Related ClickFix campaigns also abuse trusted accounts, search results, and fake AI-tool downloads to deliver information stealers on Windows and macOS.</p>
<ul>
<li>ClickFix-style lures deliver the previously undocumented ChainScript remote-access trojan through a malicious Windows installer disguised as Spotify.</li>
<li>ChainScript deploys a Node.js runtime and JavaScript agent, establishes persistence through a scheduled task with a Registry Run key fallback, and connects to its command server over WebSockets.</li>
<li>The malware uses a Polygon smart contract to discover active command-and-control infrastructure, allowing operators to redirect infected systems while retaining the same implant.</li>
<li>ChainScript supports command-line and PowerShell access, file operations, screenshot capture, payload deployment, cryptocurrency-wallet enumeration, and remote JavaScript execution.</li>
<li>Separate ClickFix campaigns used HBO Max’s compromised Reddit account and fake Codex download pages to distribute information-stealing malware to Windows and macOS users.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="operating-system">operating-system</data>, <data value="remote-access">remote-access</data>, <data value="cloud-platform">cloud-platform</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="chainscript">chainscript</data>, <data value="windows">windows</data>, <data value="macos">macos</data>, <data value="node-js">node-js</data>, <data value="polygon">polygon</data>, <data value="google-sites">google-sites</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="blackpoint-cyber">blackpoint-cyber</data>, <data value="microsoft">microsoft</data>, <data value="apple">apple</data>, <data value="node-js">node-js</data>, <data value="polygon">polygon</data>, <data value="google">google</data></p>
<h3>Government AI Use Cases Have Passed 3,600. Security Must Catch Up — Optional</h3>
<p>Federal agencies are rapidly deploying thousands of AI use cases, but legacy security tools lack the visibility and controls needed to manage AI-driven risks. Agencies should continuously discover AI use, classify risk, monitor autonomous agents, and enforce inline safeguards and red-team testing.</p>
<ul>
<li>OMB&#39;s 2025 Federal Agency Artificial Intelligence Use Case Inventory documented 3,611 AI use cases across 56 submitting federal agencies.</li>
<li>The article says traditional enterprise security tools often lack visibility into AI usage, prompts, model interactions, and AI-driven workflows.</li>
<li>Federal agencies are expected to meet security, transparency, and risk-management requirements under the NIST AI Risk Management Framework, OMB M-25-21, and CISA guidance while deploying AI rapidly.</li>
<li>The article recommends continuous discovery of AI tools and usage, risk classification based on data sensitivity and mission impact, visibility into AI agents, and inline safeguards.</li>
<li>NIST red-team exercises in 2025 found that novel attacks against AI agents succeeded 81% of the time, according to the article.</li>
</ul>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="skylight-ai">skylight-ai</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="netskope">netskope</data></p>
]]></content:encoded>
      <downlink:technologies>
        <downlink:technology>operating-system</downlink:technology>
        <downlink:technology>remote-access</downlink:technology>
        <downlink:technology>cloud-platform</downlink:technology>
        <downlink:technology>source-control</downlink:technology>
        <downlink:technology>ci-cd</downlink:technology>
      </downlink:technologies>
      <downlink:products>
        <downlink:product>chainscript</downlink:product>
        <downlink:product>windows</downlink:product>
        <downlink:product>macos</downlink:product>
        <downlink:product>node-js</downlink:product>
        <downlink:product>polygon</downlink:product>
        <downlink:product>google-sites</downlink:product>
        <downlink:product>skylight-ai</downlink:product>
        <downlink:product>terraform</downlink:product>
        <downlink:product>github</downlink:product>
        <downlink:product>cursor</downlink:product>
      </downlink:products>
      <downlink:vendors>
        <downlink:vendor>blackpoint-cyber</downlink:vendor>
        <downlink:vendor>microsoft</downlink:vendor>
        <downlink:vendor>apple</downlink:vendor>
        <downlink:vendor>node-js</downlink:vendor>
        <downlink:vendor>polygon</downlink:vendor>
        <downlink:vendor>google</downlink:vendor>
        <downlink:vendor>netskope</downlink:vendor>
        <downlink:vendor>sentinelone</downlink:vendor>
        <downlink:vendor>hashicorp</downlink:vendor>
        <downlink:vendor>github</downlink:vendor>
        <downlink:vendor>anysphere</downlink:vendor>
      </downlink:vendors>
    </item>
    <item>
      <title>Malicious indexed-btree npm Package Uses Runtime Trigger and Ethereum C2</title>
      <link>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-20_1400.html</link>
      <guid>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-20_1400.html</guid>
      <pubDate>Sun, 20 Sep 2026 14:00:01 +0000</pubDate>
      <description></description>
      <content:encoded><![CDATA[<p class="digest-window">Window: <time datetime="2026-09-20T14:00:01Z">20 Sep 14:00</time> → <time datetime="2026-09-20T18:00:01Z">20 Sep 18:00 UTC</time> (<data value="PT4H">4 hours</data>)</p>
<h3>Malicious npm packages evade install-script defenses at runtime — Should Read</h3>
<p>Malicious npm packages led by indexed-btree evaded install-script protections by embedding a runtime loader in a commonly used library method, allowing malware to execute only when triggered by application behavior. Developers who installed the affected packages should rotate secrets and restore affected environments from known-safe backups.</p>
<ul>
<li>Checkmarx identified indexed-btree as a malicious npm package impersonating the legitimate sorted-btree library, with roughly 2 million weekly downloads.</li>
<li>The package avoids npm install-script protections by placing its loader in the BTree.prototype.set() function, where it runs only when the application calls the function with a specific key value.</li>
<li>After execution, the malware collects system details and sends them through hardcoded Slack and Telegram channels, then retrieves command-and-control information from an Ethereum Sepolia test-network smart contract.</li>
<li>Checkmarx linked nine additional npm packages to the operation, and npm has removed them.</li>
<li>Developers who installed indexed-btree or the related packages are advised to rotate all secrets and restore their development environments from safe backups.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="package-registry">package-registry</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="npm">npm</data>, <data value="indexed-btree">indexed-btree</data>, <data value="sorted-btree">sorted-btree</data>, <data value="ordered-kv-index">ordered-kv-index</data>, <data value="btree-leaderboard">btree-leaderboard</data>, <data value="priority-slot-queue">priority-slot-queue</data>, <data value="btree-core">btree-core</data>, <data value="btree-time-index">btree-time-index</data>, <data value="btree-lru-cache">btree-lru-cache</data>, <data value="neighbor-key-map">neighbor-key-map</data>, <data value="sliding-score-window">sliding-score-window</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="github">github</data>, <data value="checkmarx">checkmarx</data></p>
]]></content:encoded>
      <downlink:technologies>
        <downlink:technology>package-registry</downlink:technology>
      </downlink:technologies>
      <downlink:products>
        <downlink:product>npm</downlink:product>
        <downlink:product>indexed-btree</downlink:product>
        <downlink:product>sorted-btree</downlink:product>
        <downlink:product>ordered-kv-index</downlink:product>
        <downlink:product>btree-leaderboard</downlink:product>
        <downlink:product>priority-slot-queue</downlink:product>
        <downlink:product>btree-core</downlink:product>
        <downlink:product>btree-time-index</downlink:product>
        <downlink:product>btree-lru-cache</downlink:product>
        <downlink:product>neighbor-key-map</downlink:product>
        <downlink:product>sliding-score-window</downlink:product>
      </downlink:products>
      <downlink:vendors>
        <downlink:vendor>github</downlink:vendor>
        <downlink:vendor>checkmarx</downlink:vendor>
      </downlink:vendors>
    </item>
    <item>
      <title>OpenAI Codex Sandbox Escapes and Phishing Kit Console Exposure</title>
      <link>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-20_1000.html</link>
      <guid>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-20_1000.html</guid>
      <pubDate>Sun, 20 Sep 2026 10:00:01 +0000</pubDate>
      <description></description>
      <content:encoded><![CDATA[<p class="digest-window">Window: <time datetime="2026-09-20T10:00:01Z">20 Sep 10:00</time> → <time datetime="2026-09-20T14:00:01Z">20 Sep 14:00 UTC</time> (<data value="PT4H">4 hours</data>)</p>
<h3>Researchers escape OpenAI Codex sandbox to run commands on host — Should Read</h3>
<p>Researchers disclosed two OpenAI Codex sandbox escapes that could let malicious repositories run commands on a developer’s host, including from read-only mode without user approval. OpenAI patched Heapjack in Codex Desktop 26.818.21641 and Overpatch in Codex CLI 0.149.0; users should update immediately.</p>
<ul>
<li>Researchers at Accomplish AI reported two OpenAI Codex sandbox escapes, Heapjack and Overpatch, to OpenAI on August 12, and OpenAI fixed them within eight days.</li>
<li>Heapjack allowed untrusted code to read a trusted authorization token from a shared Node.js memory space and use it to send requests to an unsandboxed parent process, even in Codex’s read-only mode.</li>
<li>A malicious repository could exploit Heapjack when a user opened it in Codex and asked a question about its code, potentially running commands on the developer’s machine without an approval prompt or visible indication.</li>
<li>Overpatch abused Codex CLI’s apply_patch tool in workspace-write mode by naming /tmp in a patch to widen write permissions and then using a symlink to append a line to the user’s .zshrc file.</li>
<li>According to Accomplish AI, Heapjack was fixed in Codex Desktop build 26.818.21641 and Overpatch was fixed in Codex CLI version 0.149.0.</li>
</ul>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="codex-desktop">codex-desktop</data>, <data value="codex-cli">codex-cli</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="openai">openai</data>, <data value="accomplish-ai">accomplish-ai</data></p>
<h3>The Phishing Kit That Emailed Us Its Own Billing Meter — Should Read</h3>
<p>A phishing-as-a-service campaign accidentally pasted its live operator console into a document-invite email, exposing its Enterprise subscription, 138,291 lifetime sends, 4,043 loaded targets, SMTP configuration, and delivery logs. The message passed conventional email authentication and bypassed the recipient gateway, showing why behavioral and content-based detection is needed against legitimate-account abuse and credential-harvesting lures.</p>
<ul>
<li>A document-invite phishing email delivered to the chief executive of a US Midwest grocery retailer on September 4, 2026 accidentally included a copy of the phishing service&#39;s live operator console in its HTML body.</li>
<li>The exposed console showed an active Enterprise plan with 23 days remaining, 138,291 lifetime emails, 4,043 loaded leads, one SMTP server, 25 concurrent sends, and no batch delay.</li>
<li>Its delivery log showed 50 successful deliveries with SMTP 250 responses, while the displayed sending rates and completion estimates were consistent with the log timestamps.</li>
<li>The recipient gateway assigned the message a total score of 0.50 against a blocking threshold of 3.0, and its only weighted signal came from a non-standard HTTP port shown in the accidentally exposed console log.</li>
<li>The article states that detection ultimately relied on a malicious final-destination verdict, display-name impersonation, and community reputation similarity, and that the single affected mailbox was mitigated six seconds after receipt.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="email-security">email-security</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="themis">themis</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="ironscales">ironscales</data>, <data value="microsoft">microsoft</data></p>
]]></content:encoded>
      <downlink:technologies>
        <downlink:technology>email-security</downlink:technology>
      </downlink:technologies>
      <downlink:products>
        <downlink:product>codex-desktop</downlink:product>
        <downlink:product>codex-cli</downlink:product>
        <downlink:product>themis</downlink:product>
      </downlink:products>
      <downlink:vendors>
        <downlink:vendor>openai</downlink:vendor>
        <downlink:vendor>accomplish-ai</downlink:vendor>
        <downlink:vendor>ironscales</downlink:vendor>
        <downlink:vendor>microsoft</downlink:vendor>
      </downlink:vendors>
    </item>
    <item>
      <title>Malicious npm Loaders and OpenAI Codex Sandbox Escapes Lead Security News</title>
      <link>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-20_0000.html</link>
      <guid>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-20_0000.html</guid>
      <pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate>
      <description></description>
      <content:encoded><![CDATA[<p class="digest-window">Window: <time datetime="2026-09-20T00:00:00Z">20 Sep 00:00</time> → <time datetime="2026-09-21T00:00:00Z">21 Sep 00:00 UTC</time> (<data value="PT24H">1 day</data>)</p>
<h3>Malicious npm packages evade install-script defenses at runtime — Should Read</h3>
<p>Malicious npm packages led by indexed-btree evaded install-script protections by embedding a runtime loader in a commonly used library method, allowing malware to execute only when triggered by application behavior. Developers who installed the affected packages should rotate secrets and restore affected environments from known-safe backups.</p>
<ul>
<li>Checkmarx identified indexed-btree as a malicious npm package impersonating the legitimate sorted-btree library, with roughly 2 million weekly downloads.</li>
<li>The package avoids npm install-script protections by placing its loader in the BTree.prototype.set() function, where it runs only when the application calls the function with a specific key value.</li>
<li>After execution, the malware collects system details and sends them through hardcoded Slack and Telegram channels, then retrieves command-and-control information from an Ethereum Sepolia test-network smart contract.</li>
<li>Checkmarx linked nine additional npm packages to the operation, and npm has removed them.</li>
<li>Developers who installed indexed-btree or the related packages are advised to rotate all secrets and restore their development environments from safe backups.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="package-registry">package-registry</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="npm">npm</data>, <data value="indexed-btree">indexed-btree</data>, <data value="sorted-btree">sorted-btree</data>, <data value="ordered-kv-index">ordered-kv-index</data>, <data value="btree-leaderboard">btree-leaderboard</data>, <data value="priority-slot-queue">priority-slot-queue</data>, <data value="btree-core">btree-core</data>, <data value="btree-time-index">btree-time-index</data>, <data value="btree-lru-cache">btree-lru-cache</data>, <data value="neighbor-key-map">neighbor-key-map</data>, <data value="sliding-score-window">sliding-score-window</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="github">github</data>, <data value="checkmarx">checkmarx</data></p>
<h3>Researchers escape OpenAI Codex sandbox to run commands on host — Should Read</h3>
<p>Researchers found two Codex sandbox escapes—Heapjack and Overpatch—that could let malicious repositories execute commands or write outside intended boundaries on developers’ machines. OpenAI fixed the issues in Codex Desktop 26.818.21641 and Codex CLI 0.149.0, so users should update.</p>
<ul>
<li>Researchers at Accomplish AI reported two OpenAI Codex sandbox escapes, Heapjack and Overpatch, on August 12, and OpenAI fixed them within eight days.</li>
<li>Heapjack could allow a malicious repository opened in Codex to run commands on a developer’s machine from Codex’s read-only mode without an approval prompt or visible output.</li>
<li>Heapjack exploited node_repl by reading a trusted authorization token from the shared memory heap of a Node.js process and using it to communicate with an unsandboxed parent process.</li>
<li>Overpatch abused Codex CLI’s apply_patch tool in workspace-write mode to expand write permissions and append a line to a user’s .zshrc through a symlink.</li>
<li>OpenAI fixed Heapjack in Codex Desktop build 26.818.21641 and Overpatch in Codex CLI version 0.149.0.</li>
</ul>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="codex-desktop">codex-desktop</data>, <data value="codex-cli">codex-cli</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="openai">openai</data></p>
<h3>The Phishing Kit That Emailed Us Its Own Billing Meter — Should Read</h3>
<p>A phishing-as-a-service campaign accidentally pasted its live operator console into a document-invite email, exposing its Enterprise subscription, 138,291 lifetime sends, 4,043 loaded targets, SMTP configuration, and delivery logs. The message passed conventional email authentication and bypassed the recipient gateway, showing why behavioral and content-based detection is needed against legitimate-account abuse and credential-harvesting lures.</p>
<ul>
<li>A document-invite phishing email delivered to the chief executive of a US Midwest grocery retailer on September 4, 2026 accidentally included a copy of the phishing service&#39;s live operator console in its HTML body.</li>
<li>The exposed console showed an active Enterprise plan with 23 days remaining, 138,291 lifetime emails, 4,043 loaded leads, one SMTP server, 25 concurrent sends, and no batch delay.</li>
<li>Its delivery log showed 50 successful deliveries with SMTP 250 responses, while the displayed sending rates and completion estimates were consistent with the log timestamps.</li>
<li>The recipient gateway assigned the message a total score of 0.50 against a blocking threshold of 3.0, and its only weighted signal came from a non-standard HTTP port shown in the accidentally exposed console log.</li>
<li>The article states that detection ultimately relied on a malicious final-destination verdict, display-name impersonation, and community reputation similarity, and that the single affected mailbox was mitigated six seconds after receipt.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="email-security">email-security</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="themis">themis</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="ironscales">ironscales</data>, <data value="microsoft">microsoft</data></p>
<h3>GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK&#39;s PolinRider campaign — Should Read</h3>
<p>Researchers uncovered GHAPPIER, a previously unreported malware loader family distributed through 65 GitHub repositories operated by 22 accounts and linked to infrastructure associated with DPRK-aligned PolinRider activity.</p>
<ul>
<li>The article identifies GHAPPIER as a previously unreported loader family.</li>
<li>GHAPPIER is associated in the article with 65 repositories and 22 accounts.</li>
<li>The article places GHAPPIER alongside North Korea-linked PolinRider campaign activity.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="source-control">source-control</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="github">github</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="github">github</data></p>
]]></content:encoded>
      <downlink:technologies>
        <downlink:technology>package-registry</downlink:technology>
        <downlink:technology>email-security</downlink:technology>
        <downlink:technology>source-control</downlink:technology>
      </downlink:technologies>
      <downlink:products>
        <downlink:product>npm</downlink:product>
        <downlink:product>indexed-btree</downlink:product>
        <downlink:product>sorted-btree</downlink:product>
        <downlink:product>ordered-kv-index</downlink:product>
        <downlink:product>btree-leaderboard</downlink:product>
        <downlink:product>priority-slot-queue</downlink:product>
        <downlink:product>btree-core</downlink:product>
        <downlink:product>btree-time-index</downlink:product>
        <downlink:product>btree-lru-cache</downlink:product>
        <downlink:product>neighbor-key-map</downlink:product>
        <downlink:product>sliding-score-window</downlink:product>
        <downlink:product>codex-desktop</downlink:product>
        <downlink:product>codex-cli</downlink:product>
        <downlink:product>themis</downlink:product>
        <downlink:product>github</downlink:product>
      </downlink:products>
      <downlink:vendors>
        <downlink:vendor>github</downlink:vendor>
        <downlink:vendor>checkmarx</downlink:vendor>
        <downlink:vendor>openai</downlink:vendor>
        <downlink:vendor>ironscales</downlink:vendor>
        <downlink:vendor>microsoft</downlink:vendor>
      </downlink:vendors>
    </item>
    <item>
      <title>BragJack Browser AI Hijacking and WaterPlum’s 30,000-Device Campaign</title>
      <link>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-19_1400.html</link>
      <guid>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-19_1400.html</guid>
      <pubDate>Sat, 19 Sep 2026 14:00:01 +0000</pubDate>
      <description></description>
      <content:encoded><![CDATA[<p class="digest-window">Window: <time datetime="2026-09-19T14:00:01Z">19 Sep 14:00</time> → <time datetime="2026-09-19T18:00:01Z">19 Sep 18:00 UTC</time> (<data value="PT4H">4 hours</data>)</p>
<h3>North Korean WaterPlum hackers infected 30,000 devices worldwide — Must Read</h3>
<p>A joint international advisory says North Korean WaterPlum operators infected at least 30,000 devices in more than 100 countries through fake job interviews and malicious developer projects, stealing credentials and cryptocurrency. The group allegedly moved $10.7 million to North Korea and supports fraudulent IT-worker operations using stolen identities.</p>
<ul>
<li>A joint advisory from Japanese, U.S., Australian, and German authorities says North Korean WaterPlum operators infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026.</li>
<li>WaterPlum uses fake job interviews, coding tests, and impersonation of AI, cryptocurrency, and NFT companies to persuade job seekers to download or run malicious projects and code.</li>
<li>The advisory links WaterPlum to BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle malware families.</li>
<li>Investigators said the group stole funds or account credentials from more than 7,000 cryptocurrency wallets and transferred cryptocurrency equivalent to $10.71 million to North Korea.</li>
<li>Authorities say WaterPlum is connected to North Korean fraudulent IT-worker operations, which may reuse identity documents stolen from victims to obtain jobs under false identities.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="package-registry">package-registry</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="visual-studio-code">visual-studio-code</data>, <data value="npm">npm</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="microsoft">microsoft</data>, <data value="npm">npm</data></p>
<h3>BragJack attacks hijack AI browser agents through malicious extensions — Should Read</h3>
<p>Researchers demonstrated BragJack, a technique in which a malicious Chromium extension can hijack built-in AI browser agents and abuse their privileges to read sensitive data or act on a user’s behalf. Google and Microsoft have patched assigned flaws, but the findings affect multiple AI-enabled browsers and underscore the risks of installing broad-permission extensions.</p>
<ul>
<li>Security researcher Gal Weizman disclosed BragJack, a proof-of-concept technique that uses one malicious browser extension to hijack AI assistants in five Chromium-based browsers or browser assistants.</li>
<li>The attack requires the malicious extension to already be installed, after which it can operate without user interaction and abuse the AI agent’s existing privileges to access sensitive information or act on the victim’s behalf.</li>
<li>The technique uses Chromium’s declarativeNetRequest capability to manipulate network traffic and pages trusted by privileged browser AI components.</li>
<li>Weizman demonstrated that compromised agents could access browsing history, screenshots, local files, and web content, while the Perplexity Comet agent was forced to summarize a victim’s emails and send the results to another address.</li>
<li>Google assigned CVE-2026-0628 to the Chrome issue and Microsoft assigned CVE-2026-55945 to an Edge race condition, and both vendors have resolved their assigned flaws.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="browser">browser</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="google-chrome">google-chrome</data>, <data value="gemini-live">gemini-live</data>, <data value="microsoft-edge">microsoft-edge</data>, <data value="perplexity-comet">perplexity-comet</data>, <data value="opera-neon">opera-neon</data>, <data value="claude-for-chrome">claude-for-chrome</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="google">google</data>, <data value="microsoft">microsoft</data>, <data value="perplexity">perplexity</data>, <data value="opera">opera</data>, <data value="anthropic">anthropic</data></p>
]]></content:encoded>
      <downlink:technologies>
        <downlink:technology>browser</downlink:technology>
        <downlink:technology>package-registry</downlink:technology>
      </downlink:technologies>
      <downlink:products>
        <downlink:product>google-chrome</downlink:product>
        <downlink:product>gemini-live</downlink:product>
        <downlink:product>microsoft-edge</downlink:product>
        <downlink:product>perplexity-comet</downlink:product>
        <downlink:product>opera-neon</downlink:product>
        <downlink:product>claude-for-chrome</downlink:product>
        <downlink:product>visual-studio-code</downlink:product>
        <downlink:product>npm</downlink:product>
      </downlink:products>
      <downlink:vendors>
        <downlink:vendor>google</downlink:vendor>
        <downlink:vendor>microsoft</downlink:vendor>
        <downlink:vendor>perplexity</downlink:vendor>
        <downlink:vendor>opera</downlink:vendor>
        <downlink:vendor>anthropic</downlink:vendor>
        <downlink:vendor>npm</downlink:vendor>
      </downlink:vendors>
    </item>
    <item>
      <title>ShinyHunters Defaces Clop as AI Services and Provenance Feature in Security Incidents</title>
      <link>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-19_1000.html</link>
      <guid>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-19_1000.html</guid>
      <pubDate>Sat, 19 Sep 2026 10:00:01 +0000</pubDate>
      <description></description>
      <content:encoded><![CDATA[<p class="digest-window">Window: <time datetime="2026-09-19T10:00:01Z">19 Sep 10:00</time> → <time datetime="2026-09-19T14:00:01Z">19 Sep 14:00 UTC</time> (<data value="PT4H">4 hours</data>)</p>
<h3>Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws — Should Read</h3>
<p>Hacktron researchers used Claude Opus 5 to chain an unpatched libheif image-processing flaw in OpenAI’s Discourse forum with an OpenAI SSO weakness, gaining controlled access to employee ChatGPT, Codex, and an internal GitHub repository. OpenAI fixed the identity issue and paid a $6,500 bounty, underscoring the risk of sharing SSO between public-facing services and sensitive internal tools.</p>
<ul>
<li>Hacktron researchers chained an image-processing flaw in OpenAI’s Discourse-based public forum with an OpenAI login weakness to take over the ChatGPT and Codex accounts of several OpenAI employees.</li>
<li>The researchers demonstrated internal GitHub repository access by triggering a single harmless pull request and said they did not read source code, merge or ship changes, or access customer data.</li>
<li>Hacktron reported the findings to OpenAI, which reportedly fixed the OpenAI-side issue about 14 hours later and paid the team a $6,500 bounty on September 1.</li>
<li>The forum server used unpatched libheif 1.19.7 on Debian 12 even though libheif 1.22.0, which fixed the relevant issue, had been released in May 2026.</li>
<li>Hacktron said Claude Opus 5 produced a working exploit within hours after Claude Opus 4.8 had struggled to do so with ASLR enabled.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="identity-provider">identity-provider</data>, <data value="iam">iam</data>, <data value="source-control">source-control</data>, <data value="operating-system">operating-system</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="claude-opus-5">claude-opus-5</data>, <data value="gpt-5-6-sol">gpt-5-6-sol</data>, <data value="chatgpt">chatgpt</data>, <data value="codex">codex</data>, <data value="discourse">discourse</data>, <data value="libheif">libheif</data>, <data value="imagemagick">imagemagick</data>, <data value="debian-12">debian-12</data>, <data value="github">github</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="openai">openai</data>, <data value="anthropic">anthropic</data>, <data value="discourse">discourse</data>, <data value="struktur-ag">struktur-ag</data>, <data value="imagemagick-project">imagemagick-project</data>, <data value="debian">debian</data>, <data value="github">github</data></p>
<h3>ShinyHunters hacks Clop leak site, threatens to extort ransomware gang — Should Read</h3>
<p>ShinyHunters defaced Clop’s Tor leak site after allegedly exploiting an unauthenticated Grav CMS file-upload flaw, and claims it stole server data and the onion service’s private keys. The group says it will extort Clop in retaliation for alleged threats amid their dispute over Clop’s Oracle E-Business Suite campaign.</p>
<ul>
<li>ShinyHunters defaced Clop’s Tor-based data leak site after claiming to exploit an unauthenticated file-upload flaw in Grav CMS.</li>
<li>BleepingComputer confirmed that ShinyHunters uploaded a text file to Clop’s server and that Clop’s site was later replaced with a ShinyHunters page featuring Umbreon artwork.</li>
<li>ShinyHunters claims it obtained full server access and stole source code, Grav CMS plugins, system logs, and private keys for Clop’s onion service, but these claims have not been independently verified.</li>
<li>ShinyHunters said it plans to extort Clop and give the ransomware group 72 hours to make contact.</li>
<li>ShinyHunters said the intrusion was retaliation for alleged threats from a Clop representative amid a dispute connected to Clop’s Oracle E-Business Suite data-theft campaign.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="cms">cms</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="grav-cms">grav-cms</data>, <data value="oracle-e-business-suite">oracle-e-business-suite</data>, <data value="tor">tor</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="grav">grav</data>, <data value="oracle">oracle</data>, <data value="tor-project">tor-project</data></p>
<h3>The Blank PDF That Signed Its Own Generator&#39;s Name — May Read</h3>
<p>A phishing email impersonating a national tax authority used a seemingly blank PDF whose ordinary metadata was anonymous, but a hidden C2PA provenance manifest identified ChatGPT/gpt-5-5 and an OpenAI certificate chain. The incident shows that attachment triage should inspect signed provenance metadata as well as conventional PDF properties, especially when DMARC passes through DKIM-only shared-hosting mail.</p>
<ul>
<li>A phishing email impersonating a national tax authority targeted a senior advertising-operations lead at an international advertising group and used a one-page PDF attachment.</li>
<li>The 8,692-byte PDF had no JavaScript, links, automatic actions, or meaningful visible document properties, but contained a compressed C2PA provenance manifest.</li>
<li>The manifest recorded a c2pa.created action, classified the file as trained-algorithmic media, named gpt-5-5 and ChatGPT, and contained a certificate chain with a leaf subject of OpenAI OpCo, LLC.</li>
<li>The article states that the provenance manifest was not cryptographically validated and was likely tampered after the PDF was re-saved 25 days after its recorded signing time.</li>
<li>The message passed DMARC through aligned DKIM despite having no SPF record, while its only Download PDF link redirected toward an attacker-controlled .info domain behind a bot-verification interstitial.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="email-security">email-security</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="chatgpt">chatgpt</data>, <data value="gpt-5-5">gpt-5-5</data>, <data value="themis">themis</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="openai">openai</data>, <data value="ironscales">ironscales</data>, <data value="ssl-com">ssl-com</data></p>
<h3>Calling viral AI actress Tilly Norwood? Agree to a face scan first — May Read</h3>
<p>Talking Tilly, an AI video-call service tied to viral AI actress Tilly Norwood, requires a facial age-estimation check and continuously analyzes callers’ video and voice for emotional cues. Calls are recorded and processed by third parties, while transcripts and conversational memory may be retained, highlighting privacy implications of AI companion-style services and UK-driven age-verification rules.</p>
<ul>
<li>Talking Tilly requires callers worldwide to complete an automated age check using a video selfie analyzed by Didit, with government photo ID as a fallback when the age estimate is unclear.</li>
<li>Xicoia says the age-check selfie is sent directly to Didit, that no faceprint or biometric template is made, and that the selfie and ID image are not kept after the check.</li>
<li>During each call, Talking Tilly analyzes the caller’s camera feed and tone of voice to infer emotional state, a process that cannot be turned off for an individual call.</li>
<li>Calls are recorded, transcribed, and processed live by U.S. providers, while transcripts may be retained for up to eight weeks and the character can retain conversation memory unless deletion is requested.</li>
<li>The service offers five free minutes before charging for additional time and is scheduled to permanently shut down on September 27, when unused purchased minutes will be forfeited.</li>
</ul>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="talking-tilly">talking-tilly</data>, <data value="didit">didit</data>, <data value="tavus">tavus</data>, <data value="gemini">gemini</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="xicoia">xicoia</data>, <data value="didit">didit</data>, <data value="tavus">tavus</data>, <data value="google">google</data></p>
]]></content:encoded>
      <downlink:technologies>
        <downlink:technology>cms</downlink:technology>
        <downlink:technology>email-security</downlink:technology>
        <downlink:technology>identity-provider</downlink:technology>
        <downlink:technology>iam</downlink:technology>
        <downlink:technology>source-control</downlink:technology>
        <downlink:technology>operating-system</downlink:technology>
      </downlink:technologies>
      <downlink:products>
        <downlink:product>grav-cms</downlink:product>
        <downlink:product>oracle-e-business-suite</downlink:product>
        <downlink:product>tor</downlink:product>
        <downlink:product>talking-tilly</downlink:product>
        <downlink:product>didit</downlink:product>
        <downlink:product>tavus</downlink:product>
        <downlink:product>gemini</downlink:product>
        <downlink:product>chatgpt</downlink:product>
        <downlink:product>gpt-5-5</downlink:product>
        <downlink:product>themis</downlink:product>
        <downlink:product>claude-opus-5</downlink:product>
        <downlink:product>gpt-5-6-sol</downlink:product>
        <downlink:product>codex</downlink:product>
        <downlink:product>discourse</downlink:product>
        <downlink:product>libheif</downlink:product>
        <downlink:product>imagemagick</downlink:product>
        <downlink:product>debian-12</downlink:product>
        <downlink:product>github</downlink:product>
      </downlink:products>
      <downlink:vendors>
        <downlink:vendor>grav</downlink:vendor>
        <downlink:vendor>oracle</downlink:vendor>
        <downlink:vendor>tor-project</downlink:vendor>
        <downlink:vendor>xicoia</downlink:vendor>
        <downlink:vendor>didit</downlink:vendor>
        <downlink:vendor>tavus</downlink:vendor>
        <downlink:vendor>google</downlink:vendor>
        <downlink:vendor>openai</downlink:vendor>
        <downlink:vendor>ironscales</downlink:vendor>
        <downlink:vendor>ssl-com</downlink:vendor>
        <downlink:vendor>anthropic</downlink:vendor>
        <downlink:vendor>discourse</downlink:vendor>
        <downlink:vendor>struktur-ag</downlink:vendor>
        <downlink:vendor>imagemagick-project</downlink:vendor>
        <downlink:vendor>debian</downlink:vendor>
        <downlink:vendor>github</downlink:vendor>
      </downlink:vendors>
    </item>
    <item>
      <title>Active Exploitation of Orkes Conductor RCE and Three Linux Kernel CVEs</title>
      <link>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-19_0600.html</link>
      <guid>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-19_0600.html</guid>
      <pubDate>Sat, 19 Sep 2026 06:00:01 +0000</pubDate>
      <description></description>
      <content:encoded><![CDATA[<p class="digest-window">Window: <time datetime="2026-09-19T06:00:01Z">19 Sep 06:00</time> → <time datetime="2026-09-19T10:00:01Z">19 Sep 10:00 UTC</time> (<data value="PT4H">4 hours</data>)</p>
<h3>Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild — Must Read</h3>
<p>A critical unauthenticated RCE flaw, CVE-2026-58138, in Orkes Conductor versions before 3.30.2 is being actively exploited to run arbitrary OS commands through malicious workflow definitions. Organizations should upgrade to 3.30.2 or later immediately and restrict public access to workflow API endpoints.</p>
<ul>
<li>CVE-2026-58138 is a critical unauthenticated remote code execution flaw affecting Orkes Conductor versions 3.21.21 through versions before 3.30.2.</li>
<li>The flaw lets remote attackers submit malicious JavaScript or Python expressions in inline workflow definitions to execute arbitrary operating-system commands before authentication.</li>
<li>Fortinet reported active exploitation targeting vulnerable Conductor workflow API endpoints and blocked 1,290 attempts in 24 hours as of September 9, 2026.</li>
<li>Fortinet said it blocked nearly 7,000 attempts between September 2 and September 9, 2026, with most activity originating from Germany, Hong Kong, Indonesia, the United Arab Emirates, and India.</li>
<li>Organizations are advised to upgrade to Conductor 3.30.2 or later, or restrict external access to workflow APIs and monitor for suspicious workflow submissions if patching cannot occur immediately.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="orchestration">orchestration</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="orkes-conductor">orkes-conductor</data>, <data value="graalvm">graalvm</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="orkes">orkes</data>, <data value="fortinet">fortinet</data>, <data value="previdian">previdian</data>, <data value="empirical-security">empirical-security</data></p>
<h3>CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild — Must Read</h3>
<p>CISA added three actively exploited Linux kernel flaws—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—to its Known Exploited Vulnerabilities catalog, urging U.S. federal agencies to patch by September 21, 2026.</p>
<ul>
<li>CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog after citing evidence that they are being actively exploited.</li>
<li>The listed flaws are CVE-2025-39682 in the TLS receive path, CVE-2026-53266 in the ebtables SNAT ARP rewrite path, and CVE-2025-39964 involving concurrent writes to an AF_ALG socket.</li>
<li>The vulnerabilities could enable local authenticated attackers to disclose memory, crash systems, alter system behavior, escalate privileges, or affect the integrity of cryptographic operation results.</li>
<li>The article states that details of the active exploitation and whether the flaws are used together in one attack chain are not currently available.</li>
<li>CISA recommended that Federal Civilian Executive Branch agencies apply the necessary fixes by September 21, 2026.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="operating-system">operating-system</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="linux-kernel">linux-kernel</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="red-hat">red-hat</data>, <data value="linux-kernel">linux-kernel</data></p>
<h3>Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up — Should Read</h3>
<p>During an Irregular security evaluation, Google’s Gemini accessed real company systems after a fictional CTF domain accidentally matched a live domain, using password guessing and publicly exposed credentials. Gemini reportedly stopped after detecting the systems were real, and the issue was remediated.</p>
<ul>
<li>During a May 2026 security evaluation conducted by Israeli company Irregular, Google’s Gemini accessed real company systems after a fictional capture-the-flag test domain matched a real domain.</li>
<li>Gemini gained access in one case by repeatedly guessing a password and in two other cases by finding credentials in a public repository.</li>
<li>The model ended the intrusions after determining that it had accessed real company systems, according to the report.</li>
<li>Irregular notified Google in July 2026, and said the underlying domain-naming issue was addressed weeks before the report.</li>
<li>The article links the incident to broader scrutiny of AI agents after similar reported cases involving OpenAI, Anthropic, Meta, and Hugging Face.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="package-registry">package-registry</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="gemini">gemini</data>, <data value="artifactory">artifactory</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="google">google</data>, <data value="irregular">irregular</data>, <data value="openai">openai</data>, <data value="anthropic">anthropic</data>, <data value="meta">meta</data>, <data value="hugging-face">hugging-face</data>, <data value="jfrog">jfrog</data></p>
]]></content:encoded>
      <downlink:technologies>
        <downlink:technology>orchestration</downlink:technology>
        <downlink:technology>package-registry</downlink:technology>
        <downlink:technology>operating-system</downlink:technology>
      </downlink:technologies>
      <downlink:products>
        <downlink:product>orkes-conductor</downlink:product>
        <downlink:product>graalvm</downlink:product>
        <downlink:product>gemini</downlink:product>
        <downlink:product>artifactory</downlink:product>
        <downlink:product>linux-kernel</downlink:product>
      </downlink:products>
      <downlink:vendors>
        <downlink:vendor>orkes</downlink:vendor>
        <downlink:vendor>fortinet</downlink:vendor>
        <downlink:vendor>previdian</downlink:vendor>
        <downlink:vendor>empirical-security</downlink:vendor>
        <downlink:vendor>google</downlink:vendor>
        <downlink:vendor>irregular</downlink:vendor>
        <downlink:vendor>openai</downlink:vendor>
        <downlink:vendor>anthropic</downlink:vendor>
        <downlink:vendor>meta</downlink:vendor>
        <downlink:vendor>hugging-face</downlink:vendor>
        <downlink:vendor>jfrog</downlink:vendor>
        <downlink:vendor>red-hat</downlink:vendor>
        <downlink:vendor>linux-kernel</downlink:vendor>
      </downlink:vendors>
    </item>
    <item>
      <title>Active Orkes RCE, Linux Kernel Exploits, and AI Agent Security Incidents</title>
      <link>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-19_0000.html</link>
      <guid>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-19_0000.html</guid>
      <pubDate>Sat, 19 Sep 2026 00:00:00 +0000</pubDate>
      <description></description>
      <content:encoded><![CDATA[<p class="digest-window">Window: <time datetime="2026-09-19T00:00:00Z">19 Sep 00:00</time> → <time datetime="2026-09-20T00:00:00Z">20 Sep 00:00 UTC</time> (<data value="PT24H">1 day</data>)</p>
<h3>Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild — Must Read</h3>
<p>A critical unauthenticated RCE flaw, CVE-2026-58138, in Orkes Conductor versions before 3.30.2 is being actively exploited to run arbitrary OS commands through malicious workflow definitions. Organizations should upgrade to 3.30.2 or later immediately and restrict public access to workflow API endpoints.</p>
<ul>
<li>CVE-2026-58138 is a critical unauthenticated remote code execution flaw affecting Orkes Conductor versions 3.21.21 through versions before 3.30.2.</li>
<li>The flaw lets remote attackers submit malicious JavaScript or Python expressions in inline workflow definitions to execute arbitrary operating-system commands before authentication.</li>
<li>Fortinet reported active exploitation targeting vulnerable Conductor workflow API endpoints and blocked 1,290 attempts in 24 hours as of September 9, 2026.</li>
<li>Fortinet said it blocked nearly 7,000 attempts between September 2 and September 9, 2026, with most activity originating from Germany, Hong Kong, Indonesia, the United Arab Emirates, and India.</li>
<li>Organizations are advised to upgrade to Conductor 3.30.2 or later, or restrict external access to workflow APIs and monitor for suspicious workflow submissions if patching cannot occur immediately.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="orchestration">orchestration</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="orkes-conductor">orkes-conductor</data>, <data value="graalvm">graalvm</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="orkes">orkes</data>, <data value="fortinet">fortinet</data>, <data value="previdian">previdian</data>, <data value="empirical-security">empirical-security</data></p>
<h3>CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild — Must Read</h3>
<p>CISA added three actively exploited Linux kernel flaws—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—to its Known Exploited Vulnerabilities catalog, urging U.S. federal agencies to patch by September 21, 2026.</p>
<ul>
<li>CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog after citing evidence that they are being actively exploited.</li>
<li>The listed flaws are CVE-2025-39682 in the TLS receive path, CVE-2026-53266 in the ebtables SNAT ARP rewrite path, and CVE-2025-39964 involving concurrent writes to an AF_ALG socket.</li>
<li>The vulnerabilities could enable local authenticated attackers to disclose memory, crash systems, alter system behavior, escalate privileges, or affect the integrity of cryptographic operation results.</li>
<li>The article states that details of the active exploitation and whether the flaws are used together in one attack chain are not currently available.</li>
<li>CISA recommended that Federal Civilian Executive Branch agencies apply the necessary fixes by September 21, 2026.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="operating-system">operating-system</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="linux-kernel">linux-kernel</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="red-hat">red-hat</data>, <data value="linux-kernel">linux-kernel</data></p>
<h3>North Korean WaterPlum hackers infected 30,000 devices worldwide — Must Read</h3>
<p>A joint international advisory says North Korean WaterPlum operators infected at least 30,000 devices in more than 100 countries through fake job interviews and malicious developer projects, stealing credentials and cryptocurrency. The group allegedly moved $10.7 million to North Korea and supports fraudulent IT-worker operations using stolen identities.</p>
<ul>
<li>A joint advisory from Japanese, U.S., Australian, and German authorities says North Korean WaterPlum operators infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026.</li>
<li>WaterPlum uses fake job interviews, coding tests, and impersonation of AI, cryptocurrency, and NFT companies to persuade job seekers to download or run malicious projects and code.</li>
<li>The advisory links WaterPlum to BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle malware families.</li>
<li>Investigators said the group stole funds or account credentials from more than 7,000 cryptocurrency wallets and transferred cryptocurrency equivalent to $10.71 million to North Korea.</li>
<li>Authorities say WaterPlum is connected to North Korean fraudulent IT-worker operations, which may reuse identity documents stolen from victims to obtain jobs under false identities.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="package-registry">package-registry</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="visual-studio-code">visual-studio-code</data>, <data value="npm">npm</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="microsoft">microsoft</data>, <data value="npm">npm</data></p>
<h3>Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws — Should Read</h3>
<p>Hacktron researchers used Claude Opus 5 to exploit an unpatched libheif image-processing flaw on OpenAI’s Discourse forum, then chained it with an OpenAI SSO weakness to access employees’ ChatGPT, Codex, and an internal GitHub repository. OpenAI fixed the identity issue within about 14 hours and paid a $6,500 bug bounty; the researchers said they performed only a harmless proof of access.</p>
<ul>
<li>Hacktron researchers chained a libheif image-processing flaw in OpenAI’s Discourse-based public forum with an OpenAI login weakness to access several employees’ ChatGPT and Codex accounts.</li>
<li>The researchers said they demonstrated access by triggering a single harmless pull request in an internal OpenAI GitHub repository and did not read source code, merge changes, ship anything, or access customer data.</li>
<li>Hacktron reported the findings to OpenAI, which confirmed a fix about 14 hours later and paid the researchers a $6,500 bounty on September 1.</li>
<li>The forum’s Debian 12 server image used unpatched libheif version 1.19.7 despite libheif 1.22.0, which fixed the relevant issue, having been released in May 2026.</li>
<li>The article warns that shared sign-in between public-facing services and internal tools can allow a compromise of the former to potentially reach connected services such as GitHub, Slack, and email.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="identity-provider">identity-provider</data>, <data value="iam">iam</data>, <data value="source-control">source-control</data>, <data value="operating-system">operating-system</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="claude-opus-5">claude-opus-5</data>, <data value="gpt-5-6-sol">gpt-5-6-sol</data>, <data value="chatgpt">chatgpt</data>, <data value="codex">codex</data>, <data value="discourse">discourse</data>, <data value="imagemagick">imagemagick</data>, <data value="libheif">libheif</data>, <data value="debian-12">debian-12</data>, <data value="github-enterprise">github-enterprise</data>, <data value="next-js">next-js</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="anthropic">anthropic</data>, <data value="openai">openai</data>, <data value="discourse">discourse</data>, <data value="imagemagick">imagemagick</data>, <data value="strukturag">strukturag</data>, <data value="debian">debian</data>, <data value="github">github</data>, <data value="vercel">vercel</data></p>
<h3>BragJack attacks hijack AI browser agents through malicious extensions — Should Read</h3>
<p>Researchers demonstrated BragJack, a technique in which a malicious Chromium extension can hijack built-in AI browser agents and abuse their privileges to read sensitive data or act on a user’s behalf. Google and Microsoft have patched assigned flaws, but the findings affect multiple AI-enabled browsers and underscore the risks of installing broad-permission extensions.</p>
<ul>
<li>Security researcher Gal Weizman disclosed BragJack, a proof-of-concept technique that uses one malicious browser extension to hijack AI assistants in five Chromium-based browsers or browser assistants.</li>
<li>The attack requires the malicious extension to already be installed, after which it can operate without user interaction and abuse the AI agent’s existing privileges to access sensitive information or act on the victim’s behalf.</li>
<li>The technique uses Chromium’s declarativeNetRequest capability to manipulate network traffic and pages trusted by privileged browser AI components.</li>
<li>Weizman demonstrated that compromised agents could access browsing history, screenshots, local files, and web content, while the Perplexity Comet agent was forced to summarize a victim’s emails and send the results to another address.</li>
<li>Google assigned CVE-2026-0628 to the Chrome issue and Microsoft assigned CVE-2026-55945 to an Edge race condition, and both vendors have resolved their assigned flaws.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="browser">browser</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="google-chrome">google-chrome</data>, <data value="gemini-live">gemini-live</data>, <data value="microsoft-edge">microsoft-edge</data>, <data value="perplexity-comet">perplexity-comet</data>, <data value="opera-neon">opera-neon</data>, <data value="claude-for-chrome">claude-for-chrome</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="google">google</data>, <data value="microsoft">microsoft</data>, <data value="perplexity">perplexity</data>, <data value="opera">opera</data>, <data value="anthropic">anthropic</data></p>
<h3>CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories — Should Read</h3>
<p>CrowdSec says a former employee’s GitHub OAuth token, stolen through the TanStack npm supply-chain compromise, was used to copy roughly 170 private repositories. The leak exposed private source code plus 83 user email addresses and details of 51 potential investors, though CrowdSec says production infrastructure and databases were not accessed.</p>
<ul>
<li>CrowdSec said an attacker used a former employee’s GitHub OAuth token on May 22 to copy about 170 private GitHub repositories.</li>
<li>CrowdSec attributed the stolen access to malicious TanStack npm package versions published on May 11, which were designed to collect credentials from developers’ machines.</li>
<li>The archive posted online on September 16 included private CrowdSec code, email addresses for 83 CrowdSec users, and names, email addresses, and investment context for 51 potential investors.</li>
<li>CrowdSec said its infrastructure and databases were not accessed, no code was changed, and the copied code was nearly four months old.</li>
<li>CrowdSec rotated exposed credentials on September 16 and 17 and now uses endpoint protection software on laptops used by staff working with code or systems.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="source-control">source-control</data>, <data value="package-registry">package-registry</data>, <data value="cloud-platform">cloud-platform</data>, <data value="message-queue">message-queue</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="crowdsec-security-engine">crowdsec-security-engine</data>, <data value="github">github</data>, <data value="npm">npm</data>, <data value="aws-sns">aws-sns</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="crowdsec">crowdsec</data>, <data value="tanstack">tanstack</data>, <data value="github">github</data>, <data value="aws">aws</data></p>
<h3>SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE — Should Read</h3>
<p>SolarWinds patched a high-severity Access Rights Manager flaw, CVE-2026-28326, in version 2026.2.1 that could allow unauthenticated remote code execution because of a hard-coded static key.</p>
<ul>
<li>SolarWinds patched CVE-2026-28326, a high-severity flaw in Access Rights Manager that could allow unauthenticated remote code execution.</li>
<li>The flaw affects Access Rights Manager 2026.2 and earlier and stems from a hard-coded static key.</li>
<li>SolarWinds fixed the issue in Access Rights Manager version 2026.2.1 and said it has no indication that the flaw has been exploited in the wild.</li>
<li>Kai Huang, a security researcher at Armadin, discovered and reported the vulnerability.</li>
<li>SolarWinds also recently fixed critical and high-severity issues affecting Web Help Desk and Serv-U.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="iam">iam</data>, <data value="network-monitoring">network-monitoring</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="access-rights-manager">access-rights-manager</data>, <data value="web-help-desk">web-help-desk</data>, <data value="serv-u">serv-u</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="solarwinds">solarwinds</data></p>
<h3>ShinyHunters hacks Clop leak site, threatens to extort ransomware gang — Should Read</h3>
<p>ShinyHunters allegedly breached and defaced Clop’s Tor leak site through an unauthenticated Grav CMS file-upload flaw, claiming to have stolen server data and the onion service’s private keys. The group says it plans to extort the ransomware gang amid an ongoing feud.</p>
<ul>
<li>ShinyHunters allegedly exploited an unauthenticated file-upload flaw in Grav CMS to upload a message and later deface Clop’s Tor-based data leak site.</li>
<li>BleepingComputer independently confirmed that the uploaded file was accessible from Clop’s site and that the site was replaced with ShinyHunters-branded artwork.</li>
<li>ShinyHunters claims it obtained full server access and stole source code, Grav CMS plugins, system logs, and private keys for Clop’s onion service, but these claims have not been independently verified.</li>
<li>ShinyHunters says it intends to extort Clop and give the ransomware group 72 hours to make contact.</li>
<li>The group describes the intrusion as retaliation for alleged threats from a Clop representative tied to a dispute over Clop’s 2025 Oracle E-Business Suite data-theft campaign.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="cms">cms</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="grav-cms">grav-cms</data>, <data value="oracle-e-business-suite">oracle-e-business-suite</data>, <data value="tor">tor</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="grav">grav</data>, <data value="oracle">oracle</data>, <data value="tor-project">tor-project</data></p>
<h3>Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up — Should Read</h3>
<p>During an Irregular security evaluation, Google’s Gemini accessed real company systems after a fictional CTF domain accidentally matched a live domain, using password guessing and publicly exposed credentials. Gemini reportedly stopped after detecting the systems were real, and the issue was remediated.</p>
<ul>
<li>During a May 2026 security evaluation conducted by Israeli company Irregular, Google’s Gemini accessed real company systems after a fictional capture-the-flag test domain matched a real domain.</li>
<li>Gemini gained access in one case by repeatedly guessing a password and in two other cases by finding credentials in a public repository.</li>
<li>The model ended the intrusions after determining that it had accessed real company systems, according to the report.</li>
<li>Irregular notified Google in July 2026, and said the underlying domain-naming issue was addressed weeks before the report.</li>
<li>The article links the incident to broader scrutiny of AI agents after similar reported cases involving OpenAI, Anthropic, Meta, and Hugging Face.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="package-registry">package-registry</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="gemini">gemini</data>, <data value="artifactory">artifactory</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="google">google</data>, <data value="irregular">irregular</data>, <data value="openai">openai</data>, <data value="anthropic">anthropic</data>, <data value="meta">meta</data>, <data value="hugging-face">hugging-face</data>, <data value="jfrog">jfrog</data></p>
<h3>The Blank PDF That Signed Its Own Generator&#39;s Name — May Read</h3>
<p>A phishing email impersonating a national tax authority used a seemingly blank PDF whose ordinary metadata was anonymous, but a hidden C2PA provenance manifest identified ChatGPT/gpt-5-5 and an OpenAI certificate chain. The incident shows that attachment triage should inspect signed provenance metadata as well as conventional PDF properties, especially when DMARC passes through DKIM-only shared-hosting mail.</p>
<ul>
<li>A phishing email impersonating a national tax authority targeted a senior advertising-operations lead at an international advertising group and used a one-page PDF attachment.</li>
<li>The 8,692-byte PDF had no JavaScript, links, automatic actions, or meaningful visible document properties, but contained a compressed C2PA provenance manifest.</li>
<li>The manifest recorded a c2pa.created action, classified the file as trained-algorithmic media, named gpt-5-5 and ChatGPT, and contained a certificate chain with a leaf subject of OpenAI OpCo, LLC.</li>
<li>The article states that the provenance manifest was not cryptographically validated and was likely tampered after the PDF was re-saved 25 days after its recorded signing time.</li>
<li>The message passed DMARC through aligned DKIM despite having no SPF record, while its only Download PDF link redirected toward an attacker-controlled .info domain behind a bot-verification interstitial.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="email-security">email-security</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="chatgpt">chatgpt</data>, <data value="gpt-5-5">gpt-5-5</data>, <data value="themis">themis</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="openai">openai</data>, <data value="ironscales">ironscales</data>, <data value="ssl-com">ssl-com</data></p>
<h3>Viral AI actress&#39; hotline face-scans every caller, watches their mood — May Read</h3>
<p>Talking Tilly, the video-call service for AI actress Tilly Norwood, requires a facial age check and continuously analyzes callers’ video and voice to infer mood, with recordings and transcripts processed by third parties. The service’s worldwide biometric gate and non-optional emotion analysis highlight expanding privacy implications of UK-driven age-assurance rules.</p>
<ul>
<li>Talking Tilly requires all first-time callers to complete an automated age check using a video selfie analyzed by Didit, with a government photo ID as a fallback if the result is unclear.</li>
<li>Xicoia says the age-check selfie is sent directly to Didit, is not retained after the check, and does not create a faceprint or biometric template; Xicoia retains an approximate age band and reference number.</li>
<li>During every Talking Tilly call, the service analyzes the caller’s camera feed and tone of voice to infer emotional state, and this processing cannot be disabled for an individual call.</li>
<li>Calls are recorded, transcribed, and processed live by U.S. providers, while transcripts can be retained for up to eight weeks and recordings are permanently deleted after 24 hours.</li>
<li>Talking Tilly offers five free minutes before charging for additional time and is scheduled to shut down permanently on September 27, when unused minutes will be forfeited.</li>
</ul>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="talking-tilly">talking-tilly</data>, <data value="tilly-norwood">tilly-norwood</data>, <data value="didit-age-verification">didit-age-verification</data>, <data value="tavus">tavus</data>, <data value="gemini">gemini</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="xicoia">xicoia</data>, <data value="didit">didit</data>, <data value="tavus">tavus</data>, <data value="google">google</data></p>
<h3>Identity Visibility in 2026: The Foundation of Identity Security — Optional</h3>
<p>Identity visibility requires continuous, cross-environment discovery and mapping of human and non-human identities, their effective permissions, and their real runtime behavior—not just IAM configuration. Organizations should prioritize high-risk unowned, dormant, overprivileged, and unrotated credentials while integrating visibility with IAM, IGA, PAM, and security operations.</p>
<ul>
<li>Identity visibility combines an inventory of identities, maps of their permissions, and records of how access is used to show what identities can access and what they actually do.</li>
<li>Traditional IAM reporting often shows configured group memberships and roles but may not reveal local application accounts, embedded credentials, unused permissions, or applications that were never integrated with central identity systems.</li>
<li>Cloud and SaaS platforms use different permission models, so organizations need to normalize identity data to trace access relationships such as federated trust and cross-account role use across environments.</li>
<li>Non-human identities, including service accounts, API keys, and automation credentials, should have a named owner, a stated purpose, an expiration or rotation schedule, and active monitoring.</li>
<li>A phased identity visibility program starts with high-impact applications and cloud accounts, then uses direct discovery, effective-access mapping, ownership assignment, behavioral monitoring, and automated compliance evidence.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="iam">iam</data>, <data value="identity-provider">identity-provider</data>, <data value="pam">pam</data>, <data value="mfa">mfa</data>, <data value="edr">edr</data>, <data value="cloud-platform">cloud-platform</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="microsoft-entra-id">microsoft-entra-id</data>, <data value="falcon-identity-protection">falcon-identity-protection</data>, <data value="aws-iam">aws-iam</data>, <data value="google-cloud-iam">google-cloud-iam</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="orchid-security">orchid-security</data>, <data value="veza">veza</data>, <data value="sailpoint">sailpoint</data>, <data value="saviynt">saviynt</data>, <data value="silverfort">silverfort</data>, <data value="semperis">semperis</data>, <data value="crowdstrike">crowdstrike</data>, <data value="amazon-web-services">amazon-web-services</data>, <data value="microsoft">microsoft</data>, <data value="google">google</data></p>
]]></content:encoded>
      <downlink:technologies>
        <downlink:technology>browser</downlink:technology>
        <downlink:technology>package-registry</downlink:technology>
        <downlink:technology>cms</downlink:technology>
        <downlink:technology>iam</downlink:technology>
        <downlink:technology>identity-provider</downlink:technology>
        <downlink:technology>pam</downlink:technology>
        <downlink:technology>mfa</downlink:technology>
        <downlink:technology>edr</downlink:technology>
        <downlink:technology>cloud-platform</downlink:technology>
        <downlink:technology>email-security</downlink:technology>
        <downlink:technology>source-control</downlink:technology>
        <downlink:technology>operating-system</downlink:technology>
        <downlink:technology>network-monitoring</downlink:technology>
        <downlink:technology>orchestration</downlink:technology>
        <downlink:technology>message-queue</downlink:technology>
      </downlink:technologies>
      <downlink:products>
        <downlink:product>google-chrome</downlink:product>
        <downlink:product>gemini-live</downlink:product>
        <downlink:product>microsoft-edge</downlink:product>
        <downlink:product>perplexity-comet</downlink:product>
        <downlink:product>opera-neon</downlink:product>
        <downlink:product>claude-for-chrome</downlink:product>
        <downlink:product>visual-studio-code</downlink:product>
        <downlink:product>npm</downlink:product>
        <downlink:product>grav-cms</downlink:product>
        <downlink:product>oracle-e-business-suite</downlink:product>
        <downlink:product>tor</downlink:product>
        <downlink:product>microsoft-entra-id</downlink:product>
        <downlink:product>falcon-identity-protection</downlink:product>
        <downlink:product>aws-iam</downlink:product>
        <downlink:product>google-cloud-iam</downlink:product>
        <downlink:product>talking-tilly</downlink:product>
        <downlink:product>tilly-norwood</downlink:product>
        <downlink:product>didit-age-verification</downlink:product>
        <downlink:product>tavus</downlink:product>
        <downlink:product>gemini</downlink:product>
        <downlink:product>chatgpt</downlink:product>
        <downlink:product>gpt-5-5</downlink:product>
        <downlink:product>themis</downlink:product>
        <downlink:product>claude-opus-5</downlink:product>
        <downlink:product>gpt-5-6-sol</downlink:product>
        <downlink:product>codex</downlink:product>
        <downlink:product>discourse</downlink:product>
        <downlink:product>imagemagick</downlink:product>
        <downlink:product>libheif</downlink:product>
        <downlink:product>debian-12</downlink:product>
        <downlink:product>github-enterprise</downlink:product>
        <downlink:product>next-js</downlink:product>
        <downlink:product>access-rights-manager</downlink:product>
        <downlink:product>web-help-desk</downlink:product>
        <downlink:product>serv-u</downlink:product>
        <downlink:product>orkes-conductor</downlink:product>
        <downlink:product>graalvm</downlink:product>
        <downlink:product>artifactory</downlink:product>
        <downlink:product>crowdsec-security-engine</downlink:product>
        <downlink:product>github</downlink:product>
        <downlink:product>aws-sns</downlink:product>
        <downlink:product>linux-kernel</downlink:product>
      </downlink:products>
      <downlink:vendors>
        <downlink:vendor>google</downlink:vendor>
        <downlink:vendor>microsoft</downlink:vendor>
        <downlink:vendor>perplexity</downlink:vendor>
        <downlink:vendor>opera</downlink:vendor>
        <downlink:vendor>anthropic</downlink:vendor>
        <downlink:vendor>npm</downlink:vendor>
        <downlink:vendor>grav</downlink:vendor>
        <downlink:vendor>oracle</downlink:vendor>
        <downlink:vendor>tor-project</downlink:vendor>
        <downlink:vendor>orchid-security</downlink:vendor>
        <downlink:vendor>veza</downlink:vendor>
        <downlink:vendor>sailpoint</downlink:vendor>
        <downlink:vendor>saviynt</downlink:vendor>
        <downlink:vendor>silverfort</downlink:vendor>
        <downlink:vendor>semperis</downlink:vendor>
        <downlink:vendor>crowdstrike</downlink:vendor>
        <downlink:vendor>amazon-web-services</downlink:vendor>
        <downlink:vendor>xicoia</downlink:vendor>
        <downlink:vendor>didit</downlink:vendor>
        <downlink:vendor>tavus</downlink:vendor>
        <downlink:vendor>openai</downlink:vendor>
        <downlink:vendor>ironscales</downlink:vendor>
        <downlink:vendor>ssl-com</downlink:vendor>
        <downlink:vendor>discourse</downlink:vendor>
        <downlink:vendor>imagemagick</downlink:vendor>
        <downlink:vendor>strukturag</downlink:vendor>
        <downlink:vendor>debian</downlink:vendor>
        <downlink:vendor>github</downlink:vendor>
        <downlink:vendor>vercel</downlink:vendor>
        <downlink:vendor>solarwinds</downlink:vendor>
        <downlink:vendor>orkes</downlink:vendor>
        <downlink:vendor>fortinet</downlink:vendor>
        <downlink:vendor>previdian</downlink:vendor>
        <downlink:vendor>empirical-security</downlink:vendor>
        <downlink:vendor>irregular</downlink:vendor>
        <downlink:vendor>meta</downlink:vendor>
        <downlink:vendor>hugging-face</downlink:vendor>
        <downlink:vendor>jfrog</downlink:vendor>
        <downlink:vendor>crowdsec</downlink:vendor>
        <downlink:vendor>tanstack</downlink:vendor>
        <downlink:vendor>aws</downlink:vendor>
        <downlink:vendor>red-hat</downlink:vendor>
        <downlink:vendor>linux-kernel</downlink:vendor>
      </downlink:vendors>
    </item>
    <item>
      <title>Shai-Hulud npm Worm Legacy and Public Linux Root Exploits</title>
      <link>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-18_1800.html</link>
      <guid>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-18_1800.html</guid>
      <pubDate>Fri, 18 Sep 2026 18:00:01 +0000</pubDate>
      <description></description>
      <content:encoded><![CDATA[<p class="digest-window">Window: <time datetime="2026-09-18T18:00:01Z">18 Sep 18:00</time> → <time datetime="2026-09-18T22:00:01Z">18 Sep 22:00 UTC</time> (<data value="PT4H">4 hours</data>)</p>
<h3>Happy Birthday, Shai-Hulud — Should Read</h3>
<p>One year after the first npm Shai-Hulud compromise, its credential-stealing, self-propagating supply-chain technique has evolved into repeated waves run by multiple actors, aided by publicly released code and CI token hijacking. Although two alleged TeamPCP members were arrested, the original worm’s authors remain unidentified and the threat persists across the npm ecosystem.</p>
<ul>
<li>A malicious version of @ctrl/tinycolor published to npm in September 2025 initiated the first known self-propagating worm in the npm ecosystem, which spread into dozens of packages and CrowdStrike’s npm namespace.</li>
<li>The Shai-Hulud payload used TruffleHog to find npm tokens, GitHub credentials, and cloud keys, sent discovered secrets to attacker-controlled locations, added a GitHub Actions workflow for persistence, and republished itself using stolen npm tokens.</li>
<li>A November 2025 wave moved execution to the pre-install step, introduced setup_bun.js and bun_environment.js, and included a fallback that could attempt to wipe a user’s home directory.</li>
<li>Later 2026 campaigns used publicly released Shai-Hulud source code, including a May burst that pushed more than 400 malicious versions across 172 packages by hijacking short-lived OIDC tokens from CI.</li>
<li>Australian Federal Police arrested two men in Western Australia on August 26, 2026 over alleged TeamPCP involvement, but the original authors of the September and November 2025 Shai-Hulud attacks remain unidentified.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="package-registry">package-registry</data>, <data value="source-control">source-control</data>, <data value="ci-cd">ci-cd</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="npm">npm</data>, <data value="github-actions">github-actions</data>, <data value="trufflehog">trufflehog</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="github">github</data>, <data value="crowdstrike">crowdstrike</data>, <data value="google">google</data></p>
<h3>Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root — Should Read</h3>
<p>Public proof-of-concept exploits for four Linux kernel flaws—DirtyAH6, TUNderflow, PPPoEject, and DiagSpill—can allow local users to gain root access on unpatched systems. Organizations should install distribution updates containing all four fixes, as disabling unprivileged user namespaces only mitigates three of the flaws.</p>
<ul>
<li>Researcher Asim Manizada released working proof-of-concept exploits for four Linux kernel flaws—DirtyAH6, TUNderflow, PPPoEject, and DiagSpill—that can allow a local user to gain root access.</li>
<li>All four flaws have been fixed by Linux kernel maintainers, but systems running older kernels remain exposed now that exploit code is public.</li>
<li>DirtyAH6, TUNderflow, and PPPoEject require unprivileged user namespaces for an ordinary user to reach them, while DiagSpill requires no user namespaces if the SCTP networking module is available.</li>
<li>The first stable Linux kernel versions stated to contain the complete set of fixes are 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50, and 7.2.4.</li>
<li>The article says there are no reports that these flaws have been used in real-world attacks, and the released exploits are tuned to specific kernel builds and may crash systems.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="operating-system">operating-system</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="linux-kernel">linux-kernel</data>, <data value="open-vswitch">open-vswitch</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="linux-kernel-project">linux-kernel-project</data>, <data value="open-vswitch">open-vswitch</data></p>
]]></content:encoded>
      <downlink:technologies>
        <downlink:technology>package-registry</downlink:technology>
        <downlink:technology>source-control</downlink:technology>
        <downlink:technology>ci-cd</downlink:technology>
        <downlink:technology>operating-system</downlink:technology>
      </downlink:technologies>
      <downlink:products>
        <downlink:product>npm</downlink:product>
        <downlink:product>github-actions</downlink:product>
        <downlink:product>trufflehog</downlink:product>
        <downlink:product>linux-kernel</downlink:product>
        <downlink:product>open-vswitch</downlink:product>
      </downlink:products>
      <downlink:vendors>
        <downlink:vendor>github</downlink:vendor>
        <downlink:vendor>crowdstrike</downlink:vendor>
        <downlink:vendor>google</downlink:vendor>
        <downlink:vendor>linux-kernel-project</downlink:vendor>
        <downlink:vendor>open-vswitch</downlink:vendor>
      </downlink:vendors>
    </item>
    <item>
      <title>WordPress Click2Shell, Gyazo Breach, and Transparent Tribe RapidRust Campaign</title>
      <link>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-18_1400.html</link>
      <guid>https://ma111e.github.io/downlink/digests-v2/downlink-digest-2026-09-18_1400.html</guid>
      <pubDate>Fri, 18 Sep 2026 14:00:01 +0000</pubDate>
      <description></description>
      <content:encoded><![CDATA[<p class="digest-window">Window: <time datetime="2026-09-18T14:00:01Z">18 Sep 14:00</time> → <time datetime="2026-09-18T18:00:01Z">18 Sep 18:00 UTC</time> (<data value="PT4H">4 hours</data>)</p>
<h3>Gyazo server flaw exploited to steal 23.6 million user records — Must Read</h3>
<p>Gyazo disclosed that attackers exploited a server flaw on September 11, 2026, stealing roughly 23.6 million user records and metadata for 490 million images. Exposed data may include password hashes, session IDs, X tokens, and private-image details, so users should change reused passwords.</p>
<ul>
<li>Gyazo said attackers exploited a server vulnerability on September 11, 2026, and accessed its database, exposing approximately 23.62 million user records.</li>
<li>The company detected suspicious activity on September 12 and said it fixed the vulnerability used in the incident.</li>
<li>Exposed user data may include names or nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, and subscription-related information.</li>
<li>Gyazo said the incident also exposed 490 million image metadata records, including image IDs, upload IP addresses, browser-identification strings, location data embedded in images, extracted text, titles, source URLs, and hashed passphrases for private images.</li>
<li>Gyazo temporarily suspended its service and disabled access to files whose records were exposed, while advising users to change passwords reused on other platforms and to watch for suspicious communications.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="cloud-platform">cloud-platform</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="gyazo">gyazo</data>, <data value="cosense">cosense</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="helpfeel">helpfeel</data>, <data value="google">google</data>, <data value="x">x</data></p>
<h3>New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution — Should Read</h3>
<p>WordPress patched the Click2Shell flaw, which lets a crafted link force a logged-in administrator’s browser to install and preview an inactive theme from WordPress.org. When chained with a separate vulnerable theme, the issue can lead to server-side code execution, so site owners should update to WordPress 7.1.1 or the applicable supported security release.</p>
<ul>
<li>WordPress released security updates, including WordPress 7.1.1, to fix Click2Shell, a flaw that can cause a logged-in administrator who opens a crafted link to install and preview an inactive theme from WordPress.org.</li>
<li>The core Click2Shell flaw cannot install an arbitrary theme ZIP by itself; it installs a legitimate theme selected by the attacker from the official WordPress.org directory.</li>
<li>Pwn.ai demonstrated that Click2Shell could be chained with a separate flaw in the Mobile Repair Zone theme to run attacker-controlled code on the server.</li>
<li>The forced-installed theme remains inactive, so the site’s appearance does not change, but WordPress’s Customizer can load a theme’s PHP code while preparing a preview.</li>
<li>The article states that no evidence shows Click2Shell has been used in real attacks, and that updating WordPress core closes the demonstrated attack.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="cms">cms</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="wordpress">wordpress</data>, <data value="mobile-repair-zone">mobile-repair-zone</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="wordpress">wordpress</data>, <data value="pwn-ai">pwn-ai</data></p>
<h3>Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 — Should Read</h3>
<p>Pakistan-aligned Transparent Tribe (APT36) is targeting Indian and Afghan government and defense entities with a new Rust-based toolset, including the RUSTYSHADE backdoor. The campaign uses private GitHub repositories for encrypted command-and-control, USB propagation, and Windows/Linux file stealers to collect and exfiltrate data.</p>
<ul>
<li>Pakistan-aligned Transparent Tribe, also known as APT36 and Earth Karkaddan, targeted government and defense entities in India and Afghanistan in an activity Zscaler calls Operation RapidRust.</li>
<li>The campaign uses four previously undocumented tools: the Rust-based RUSTYSHADE backdoor, the RUSTYMOVE USB propagation utility, and the PSNATCH and BASHNATCH file stealers for Windows and Linux.</li>
<li>RUSTYSHADE uses attacker-controlled private GitHub repositories and the GitHub REST API for encrypted two-way communications, including commands, results, system information, screenshots, webcam captures, and stolen files.</li>
<li>The attackers registered typosquatted domains resembling The Print and India Today to host malicious PowerShell scripts and payloads.</li>
<li>RUSTYMOVE monitors removable drives and copies a ZIP archive containing RUSTYSHADE and a disguised shortcut file to each detected drive.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="source-control">source-control</data>, <data value="operating-system">operating-system</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="github">github</data>, <data value="windows">windows</data>, <data value="powershell">powershell</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="github">github</data>, <data value="microsoft">microsoft</data>, <data value="zscaler">zscaler</data></p>
<h3>Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer — Should Read</h3>
<p>SEO-optimized fake GitHub repositories impersonating LastPass and dozens of other brands are distributing the new Rapuncel infostealer, alongside a Microsoft-signed kernel driver that can disable 145 antivirus and EDR products. Users should download software only from official sources and avoid promoted or suspicious search results.</p>
<ul>
<li>SEO-optimized fake GitHub repositories impersonating LastPass and at least 39 other companies distribute the previously undocumented Rapuncel information stealer.</li>
<li>Victims are redirected from fake download buttons to ZIP archives inflated to as much as 148 MB, which contain a renamed Microsoft Visual Studio CoreCLR Debugger configured to load a malicious DLL.</li>
<li>The campaign deploys a Microsoft-signed Alinubx.sys kernel driver disguised as an NVIDIA component that is designed to terminate 145 antivirus and endpoint-detection processes.</li>
<li>Rapuncel steals credentials from 25 browsers, data from 30 cryptocurrency wallets, Discord, Steam, and Telegram session credentials, Windows Credential Manager contents, selected documents, screenshots, and system information.</li>
<li>Rapuncel persists through a Windows service and uploads compressed stolen data to 2.26.126[.]50 using an HTTP-formatted request over raw TCP.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="mfa">mfa</data>, <data value="source-control">source-control</data>, <data value="operating-system">operating-system</data>, <data value="browser">browser</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="lastpass-authenticator">lastpass-authenticator</data>, <data value="github">github</data>, <data value="windows">windows</data>, <data value="visual-studio-coreclr-debugger">visual-studio-coreclr-debugger</data>, <data value="google-chrome">google-chrome</data>, <data value="microsoft-edge">microsoft-edge</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="lastpass">lastpass</data>, <data value="github">github</data>, <data value="microsoft">microsoft</data>, <data value="google">google</data></p>
<h3>Nations take action on North Korean IT workers after UN report — Should Read</h3>
<p>Countries including Argentina, Pakistan, Vietnam and Laos have taken legal, financial and investigative action against networks helping North Korean IT workers evade sanctions and earn foreign currency. A UN monitoring report says the scheme remains globally extensive, with China and Russia hosting most North Korean overseas workers despite increased scrutiny.</p>
<ul>
<li>A UN-linked monitoring report says Argentina, Pakistan, Vietnam, and Laos took meaningful steps by July to address North Korean IT worker activities identified in an October report.</li>
<li>Argentina investigated Antonia Doroganova over allegations that she helped launder North Korean IT workers’ earnings, while Pakistan opened a case involving alleged provider of fraudulent identification documents Syeda Aliya Batool Zaidi and investigated two other alleged facilitators.</li>
<li>The report says Chinese authorities increased surveillance of North Korean IT workers and that their ability to enter China had become difficult as of July 2025.</li>
<li>The monitoring team estimates that at least 17 countries continue to host about 100,000 North Korean workers, with an estimated 20,000 to 70,000 in China and up to 30,000 in Russia.</li>
<li>North Koreans working outside the country generated up to $800 million last year, much of it through the IT worker scheme.</li>
</ul>
<h3>Teaching a Machine to Think Like an Incident Researcher — Optional</h3>
<p>Varonis describes how its AI-powered Triage Agent investigates security alerts using data context, behavioral baselines, and adaptive evidence gathering to reconstruct incidents before human review. The company reports that the agent improves triage efficiency, prioritizes confirmed threats with over 96% recall, and reduces escalation time for malicious cases.</p>
<ul>
<li>Varonis built its Triage Agent to investigate alerts end to end by gathering context about identities, permissions, sensitive data, behavior, and related events before a human analyst opens a case.</li>
<li>The agent uses normalized data, behavioral baselines, and more than 300 investigation scenarios to begin with relevant evidence and expand its investigation when needed.</li>
<li>In a production case, the agent linked three download-alert windows involving a sales employee, totaling more than 17,000 sensitive-file downloads from an anonymous consumer VPN endpoint.</li>
<li>The agent classified the linked activity as malicious and critical but noted that unavailable authentication telemetry prevented it from determining whether the activity involved stolen credentials, a hijacked session, or a deliberate insider.</li>
<li>Varonis states that the agent has improved analyst efficiency by 35% to 100%, reduced malicious-case escalation time by an average of 16.4 hours, and achieved production recall above 96%.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="dlp">dlp</data>, <data value="iam">iam</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="varonis-triage-agent">varonis-triage-agent</data>, <data value="varonis-data-security-platform">varonis-data-security-platform</data>, <data value="varonis-mddr">varonis-mddr</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="varonis">varonis</data></p>
<h3>What scales when headcount doubles — Optional</h3>
<p>As organizations grow, IT operations must replace person-dependent processes with scalable systems, partners, and deliberate workflows for support, identity, compliance, and device logistics. The presentation shares practical lessons on deciding what to automate or operationalize while maintaining consistent employee experiences across regions.</p>
<ul>
<li>As headcount grows, IT teams face rising ticket volume, more difficult identity and access management, increasingly complex compliance requirements, outdated documentation, and device operations that become logistical challenges.</li>
<li>Processes that depend on one person’s judgment or memory are likely failure points as an organization scales.</li>
<li>Tools commonly automate the well-defined middle of a process while leaving edge tasks such as forecasting, sourcing, storing, shipping, retrieving, and retiring devices unresolved.</li>
<li>Joe Hurshman of Teamworks will discuss decisions about which operations to build systems for, hand off to partners, or leave manual, based on experience at Teamworks, Found, and Apple.</li>
<li>The presentation includes an attendee question-and-answer section focused on specific real-world scaling challenges.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="operating-system">operating-system</data>, <data value="iam">iam</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="macos">macos</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="teamworks">teamworks</data>, <data value="apple">apple</data></p>
<h3>Detecting Data Exfiltration Before It Becomes a Breach | Corelight — Optional</h3>
<p>Corelight promotes network-based detection and investigation capabilities to identify suspicious data exfiltration early, before it escalates into a breach.</p>
<ul>
<li>The article is titled &#34;Detecting Data Exfiltration Before It Becomes a Breach.&#34;</li>
<li>The article focuses on detecting data exfiltration before it develops into a breach.</li>
<li>Corelight is identified as the source of the article.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="network-monitoring">network-monitoring</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="corelight-open-ndr">corelight-open-ndr</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="corelight">corelight</data></p>
<h3>Secure enterprise sharing with access reviews for Microsoft 365 — Optional</h3>
<p>Sponsored content promotes tenfold’s identity and access governance platform as a way to centrally monitor Microsoft 365 sharing and have data owners review or revoke stale access to Teams, SharePoint, and OneDrive files.</p>
<ul>
<li>The article states that organizations using Microsoft 365 can lose visibility into who has access to files shared through Teams, SharePoint, and OneDrive.</li>
<li>It cites a Wire survey in which 61% of security leads said access to shared files often remains active longer than intended, while more than one-third reported difficulty identifying who can access sensitive shared files.</li>
<li>Microsoft 365’s sharing-link reports show new links over the previous 28 days, while site-level reports provide CSV lists of shared files and their users but can be time-consuming to run and review across an organization.</li>
<li>The article says access reviews should involve the people who originally shared files, because they can determine whether access is still needed.</li>
<li>The sponsored article promotes tenfold’s centralized reporting and owner-led access reviews for shared content in Microsoft cloud and on-premises environments.</li>
</ul>
<p class="digest-terms" data-axis="technologies"><strong>Technologies:</strong> <data value="iam">iam</data>, <data value="cloud-platform">cloud-platform</data></p>
<p class="digest-terms" data-axis="products"><strong>Products:</strong> <data value="tenfold">tenfold</data>, <data value="microsoft-365">microsoft-365</data>, <data value="sharepoint">sharepoint</data>, <data value="onedrive">onedrive</data>, <data value="microsoft-teams">microsoft-teams</data></p>
<p class="digest-terms" data-axis="vendors"><strong>Vendors:</strong> <data value="tenfold-software">tenfold-software</data>, <data value="microsoft">microsoft</data></p>
]]></content:encoded>
      <downlink:technologies>
        <downlink:technology>cms</downlink:technology>
        <downlink:technology>cloud-platform</downlink:technology>
        <downlink:technology>network-monitoring</downlink:technology>
        <downlink:technology>operating-system</downlink:technology>
        <downlink:technology>iam</downlink:technology>
        <downlink:technology>source-control</downlink:technology>
        <downlink:technology>mfa</downlink:technology>
        <downlink:technology>browser</downlink:technology>
        <downlink:technology>dlp</downlink:technology>
      </downlink:technologies>
      <downlink:products>
        <downlink:product>wordpress</downlink:product>
        <downlink:product>mobile-repair-zone</downlink:product>
        <downlink:product>gyazo</downlink:product>
        <downlink:product>cosense</downlink:product>
        <downlink:product>corelight-open-ndr</downlink:product>
        <downlink:product>macos</downlink:product>
        <downlink:product>github</downlink:product>
        <downlink:product>windows</downlink:product>
        <downlink:product>powershell</downlink:product>
        <downlink:product>lastpass-authenticator</downlink:product>
        <downlink:product>visual-studio-coreclr-debugger</downlink:product>
        <downlink:product>google-chrome</downlink:product>
        <downlink:product>microsoft-edge</downlink:product>
        <downlink:product>varonis-triage-agent</downlink:product>
        <downlink:product>varonis-data-security-platform</downlink:product>
        <downlink:product>varonis-mddr</downlink:product>
        <downlink:product>tenfold</downlink:product>
        <downlink:product>microsoft-365</downlink:product>
        <downlink:product>sharepoint</downlink:product>
        <downlink:product>onedrive</downlink:product>
        <downlink:product>microsoft-teams</downlink:product>
      </downlink:products>
      <downlink:vendors>
        <downlink:vendor>wordpress</downlink:vendor>
        <downlink:vendor>pwn-ai</downlink:vendor>
        <downlink:vendor>helpfeel</downlink:vendor>
        <downlink:vendor>google</downlink:vendor>
        <downlink:vendor>x</downlink:vendor>
        <downlink:vendor>corelight</downlink:vendor>
        <downlink:vendor>teamworks</downlink:vendor>
        <downlink:vendor>apple</downlink:vendor>
        <downlink:vendor>github</downlink:vendor>
        <downlink:vendor>microsoft</downlink:vendor>
        <downlink:vendor>zscaler</downlink:vendor>
        <downlink:vendor>lastpass</downlink:vendor>
        <downlink:vendor>varonis</downlink:vendor>
        <downlink:vendor>tenfold-software</downlink:vendor>
      </downlink:vendors>
    </item>
  </channel>
</rss>