• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
  • Log In
  • Register

AnonymousMedia.org

  • Home
  • Headline News
  • Videos
  • History
  • File Manager
  • Activity
  • Forums
  • Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

    Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone


    Swati KhandelwalSep 17, 2026Vulnerability / DNS Security

    Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

    An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.

    Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with eight other flaws. One of the eight, CVE-2026-82717, is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic. It could also lead to remote code execution “under certain systems and compilation options,” NLnet Labs said.

    NLnet Labs has not reported exploitation of either bug, and CISA’s entry for CVE-2026-81642 marked exploitation as “none” on Wednesday.

    NLnet Labs rates the DNSKEY flaw Critical, with a CVSS score of 4.0 (9.1), and its scoring lists a network attack vector requiring no privileges or user interaction. NVD listed the CVE as “Awaiting Analysis” on Wednesday, so the 9.1 is the maintainer’s own score.

    The overflow happens while the validator digests a DNSKEY record whose owner name is a compression pointer into the record’s own data. The impact NLnet Labs lists is denial of service, with remote code execution possible “through attacker controlled data.”

    Cybersecurity

    Every version up to and including 1.26.0 is affected. That includes 1.25.2, the security release from July, and 1.26.0, released on August 4. The Critical validator bug NLnet Labs fixed in May, CVE-2026-33278, is a different flaw, and the 1.25.1 update that fixed it does not fix this one.

    NLnet Labs attaches no configuration condition to that range, and it has not said whether a resolver with DNSSEC validation switched off is reachable.

    Upgrade or Patch

    Unbound 1.26.1 is available as source, with checksums and a PGP signature, and as Windows installers and binaries. If you cannot upgrade, the advisory gives two ways to patch the source tree:

    • Apply the minimal patch or the complete patch for CVE-2026-81642 alone with patch -p1, for example patch -p1 < patch_CVE-2026-81642_with.diff, then run make install.
    • Apply the combined patch for all nine fixes instead. A minimal version of it also exists.

    NLnet Labs says the standalone patches for CVE-2026-81642 and CVE-2026-82717 have been tested and work on 1.26.0. Its security policy is to patch the latest released version.

    Cybersecurity

    Debian’s security tracker listed unbound 1.26.1-1 as fixed in unstable on Thursday, with the bookworm, trixie, and forky branches still listed as vulnerable.

    The Nine Fixes

    The release notes name nine CVEs. The table gives each one’s affected range and trigger condition in NLnet Labs’ wording.

    CVE Severity Affected versions Needs Impact
    CVE-2026-81642 Critical Up to and including 1.26.0 An attacker who controls a malicious zone and queries the resolver Denial of service, possible remote code execution
    CVE-2026-82717 High Up to and including 1.26.0 CNAME synthesis during an upstream response. Code execution “under certain systems and compilation options” Denial of service, possible remote code execution
    CVE-2026-81634 High Up to and including 1.26.0 A 255-length query name with a large TCP response, from a malicious name server or a tampered response Denial of service
    CVE-2026-77955 Medium 1.13.2 up to and including 1.26.0 Zones with zonemd-check: yes located below, but not at, a trust anchor Denial of service, a window where tampered zone data is served before the ZONEMD check
    CVE-2026-78227 Medium 1.22.0 up to and including 1.26.0 Built with –with-libngtcp2 and quic-port configured Denial of service
    CVE-2026-80225 Medium Up to and including 1.26.0 A sustained stream of distinct uncached names over one TCP or DoT connection Degradation of service
    CVE-2026-82720 Medium 1.12.0 up to and including 1.26.0 Built with –with-libnghttp2 and https-port configured. NLnet Labs calls the impact limited Denial of service
    CVE-2026-85501 Medium Up to and including 1.26.0 Malicious zones serving the ReTrap algorithmic complexity attacks (TagTrap, DelegationTrap, NsecTrap, AdditionalTrap) Degradation of service
    CVE-2026-77860 Low 1.20.0 up to and including 1.26.0 The serve-expired code path, bypassing a countermeasure added for
    DNSBomb
    Could take part in a pulsing DoS amplification attack

    The ReTrap fix also changes a default: val-clean-additional is now off, so Unbound no longer validates DNSSEC data in the additional section of a response by default.

    The bug was reported to NLnet Labs on August 11 by Yuqi Qiu, who found it with Xiang Li at Nankai University’s AOSP Lab, according to the timeline in the CVE record. NLnet Labs shared a patch the next day and the reporter verified it on August 13. The fix shipped five weeks later in the 1.26.1 batch.

    NLnet Labs’ security policy says that for issues not yet public it aims to release fixes “in the order of weeks.”



    Source link

    09/17/2026
  • Israeli contractor BlackCore trained Angolan officials in online influence operations

    Israeli contractor BlackCore trained Angolan officials in online influence operations


    An Israeli influence-for-hire company appears to have trained Angolan government officials to run online influence operations, including creating fake social media personas and producing content designed to promote the government, according to new research.

    The company, BlackCore, described itself online as “an elite influence, cyber, and technology firm built for the modern era of information warfare.” Documents obtained by researchers at the University of Toronto’s Citizen Lab show BlackCore initially advertised the Angola project as an intensive four-week course covering storytelling, copywriting, traffic management and social media operations. It ultimately lasted 14 weeks and involved both training and practical operations, a final report showed.

    Participants produced more than 40 pieces of content, while trainers evaluated at least 24 publications. The program also included Facebook and Instagram advertising and a TikTok campaign.

    The intention was to promote what BlackCore called “positive government campaigns” and included narratives intended to portray the Angolan government “in a positive light,” rather than merely attacking government opponents, Citizen Lab senior researcher Alberto Fittarelli said.

    At the center of the operation was a Facebook page for a fictitious media outlet called “Agita News,” which published its own material and linked to articles on an external website. Both are now offline.

    BlackCore’s broader marketing materials advertised more aggressive capabilities, claiming it could provide clients with hundreds of fake personas, or “avatars,” across Facebook, Instagram and TikTok. Its services included flooding online platforms with coordinated messages, generating engagement from real users and countering unwanted narratives with tailored content.

    Determining whether an influence operation actually changed public opinion is difficult, but BlackCore appeared eager to demonstrate that its Angola operation was generating attention, researchers said.

    Screenshots included in the company’s final report showed some deceptive Facebook posts receiving roughly 20,000 likes, according to Citizen Lab. Some posts that remained accessible later approached 50,000 likes — “substantial amounts in a country with an estimated six million active Facebook users.”

    Citizen Lab could not independently confirm that the training took place or determine which Angolan government employees participated but the combination of internal documents and online infrastructure uncovered by researchers made it “highly likely” that the program occurred as BlackCore described it.

    The researchers told Recorded Future News they found no evidence detailing how BlackCore was hired, whether the Angolan government paid the company directly or how much it cost.

    Since the trainings, which likely began in February, BlackCore’s websites and social media accounts have been taken offline. Citizen Lab said it was unable to find a recent contact point for the company to seek comment, and the Angolan government did not respond to Recorded Future News’ request for comment.

    Broader operations

    BlackCore’s activities have previously drawn scrutiny from European authorities.

    France’s foreign-interference watchdog Viginum said in June that an information operation targeting the left-wing France Unbowed party and some of its candidates during municipal elections showed technical links to Israeli actors, including BlackCore. The campaign used websites and coordinated accounts across several social media platforms to disparage candidates and polarize political debate.

    French authorities said they could not determine who commissioned the operation.

    Viginum later said BlackCore was also suspected of interference activity targeting elections or political audiences in New York, Scotland, Angola and Togo.

    Meta said in an August threat report that it had disrupted a coordinated network originating in Israel that targeted audiences in Angola and several other countries. According to Citizen Lab, the network was highly likely to have been operated by BlackCore.

    Citizen Lab said the Angola case illustrates how governments can increasingly acquire ready-made infrastructure and expertise for covert online influence campaigns from private contractors.

    BlackCore’s proposal for Angola promised what it called a “professional, robust, and scalable” system for government communications, according to the researchers.

    “It is not highly common” for contractors to train their clients to conduct influence operations themselves, Fittarelli told Recorded Future News, rather than running campaigns on behalf of their clients. 

    “Training clients to run their operations independently has been historically observed as a likely way to evade detection,” he said.



    Source link

    09/17/2026
  • September Patch Tuesday haul includes 973 CVEs

    September Patch Tuesday haul includes 973 CVEs


    Microsoft on September 9 released 973 patches affecting 39 product families. Of those, 114 of the addressed issues are considered by Microsoft to be of Critical severity; 58 CVEs are expected to be exploited within the next 30 days. (Two Important-severity Windows vulnerabilities already are; more on those below.) 284 have a CVSS Base score of 8.0 or higher. None of this month’s collection were publicly disclosed prior to patch release. 

    For the second month in a row, the relatively low advisory count poses an interesting contrast to the main event. The Chrome team released 24 Edge-related patches in the days before Patch Tuesday, while Adobe moved 21 patches affecting Acrobat with the main release. The usual Servicing Stack update (ADV990001) was issued. MITRE sent word of CVE-2025-70873, an information disclosure issue affecting SQLite v3.51.1. The only eyebrow-raising advisory item, in fact, comes from the OpenSSL Software Foundation, warning of CVE-2026-34182 – an improper validation of an integrity-check value (CWE-354) concerning CMS (Cryptographic Message Services) data in certain containers. It carries a 9.1 CVSS Base score.

    Nine Microsoft CVEs announcements likewise could be considered advisory, since they were patched prior to September 9. All are Critical-severity and two carry a “perfect” 10.0 CVSS base score; these affect Azure, Copilot, Discovery Studio, Entra, Fabric, and Power Automate. We include these nine items in the usual charts and statistics below, but they’re fortunately not items the average administrator need address in any fashion. The average CVSS Base score of these nine CVEs is 9.0, compared with a 7.4 average for the other 964 CVEs.

    Various of this month’s issues are amenable to direct detection by Sophos protections, and we include information on those in the usual table below. 

    And that is, as they say, the good news. Now let’s talk about patch volume.

    Six months in the whirlwind

    First, let us stipulate that a patched vulnerability is – with an exception we’ll cover in a second – always better than an unpatched vulnerability. In that light, it’s easy to appreciate not only the delivery of nearly a thousand patches in September, but the gift that is Patch Tuesday – it’s free, it’s expectable, and it improves products. (Remember always that the team that coordinates and delivers the protections is not the team that wrote whatever is broken. First of all, the protections team is much smaller.) The continued choice by Microsoft and others to patch flaws long after the customers’ checks have cleared is a positive thing; we can quibble about product lifespans, but the fact remains that we all want things to be made better when trouble arises. Patch Tuesday is a regularly scheduled commitment to making that so.

    That said, the system was not built for the AI-finder age. Figure 1 shows patch volumes over the last 60 months (five years) of Patch Tuesday. 

     

    pt2609-fig01.png

    Figure 1: A year ago, a hundred patches seemed like a lot in one month. It was a more innocent time.

    That spike over the last six months has a number of cascading effects — from the sheer volume of data moving across the internet to the extraordinary effort on the part of the teams involved in testing bug reports, identifying affected versions, developing the patches, getting them out the door, and applying them to literally millions of systems. (Even analysis gets wild at these levels. For instance, the Summary document sent out by Microsoft to provide analysts with information on each patch would, were it formatted for print, be a 3,002-page PDF – and yes, some analysts read every page.)

    And effects have costs. As mentioned, there is an exception to patched > unpatched. With a system like Patch Tuesday, which retains customer trust in part by virtue of its relative transparency, to issue a fix is to reveal that a vulnerability exists. The burden then shifts to the customer to test and apply the patch if it is pertinent to their systems. However, every so often, a patch is only available for part of the userbase. That can happen when a product is out of support — for example, there’s a good chance that a nonzero number of this month’s vulnerabilities exist in, say, Vista, but there’ll be no mainstream patches for that system.

    It can also happen if you are a user of a less common flavor of a product – Office for Mac, for instance. Over the years, the occasional Office patch has gone out on Patch Tuesday with a note telling the Mac crowd to watch the published CVE information for work on when their Apple-scented fix would be available.

    This month, there were 68 Office patches for which the Summary included notice that the vulnerability applies to Office for Mac, but the fix wasn’t ready yet. Two of those are Critical-severity, 9.8 CVSS Base issues.  Thirteen more also indicate there’s no Mac patch version yet, and also that Preview Pane is a vector. One more has no Mac patch yet, and also simply viewing the message in Outlook is a vector.  That’s eighty-two CVEs for which, most likely, Microsoft simply ran out of runway.

    For now, other AI-related trends we’ve observed in the last six months are holding. Just two CVEs were under active exploit in the wild as of September 9. The average CVSS Base score for each month’s patches has dropped from a rock-steady 7.8 in the pre-AI era to a more palatable 7.4. Finders, however they are coming up with their discoveries, are working within the disclosure system (with a few Noisy Exceptions). And the continuing decline in advisory counts hints that perhaps there will be a similar break in the fever for patches. (The Chrome team has announced that they’ll be moving to a every-two-week patch cycle, but Microsoft assures us that this will have no effect on the lists of Edge-related Chrome advisories they release each month.)

    So there’s that. However, another glance at Figure 1 should make observers uneasy. Without getting into the mechanics of it, Patch Tuesday traditionally has a rhythm to its patch volume, with the first month of each quarter (January-April-July-October) a little heavier than the next two. September in particular has always been a bit of a respite. The phrase does this month look like a respite to you? comes to mind. The thing is… what if we get to October and find out it was!

    By the numbers

    • Total CVEs: 973
    • Publicly disclosed: 0
    • Exploit detected: 2
    • Severity
      • Critical: 114
      • Important: 857
      • Moderate: 1
      • Low: 1
    • Impact:
      • Defense in Depth: 1
      • Denial of Service: 56
      • Elevation of Privilege: 437
      • Information Disclosure: 173
      • Remote Code Execution: 258
      • Security Feature Bypass: 18
      • Spoofing: 17
      • Tampering: 13
    • CVSS base score 9.0 or greater: 44
      • CVSS base score 9.0 or greater, but patched in advance of Patch Tuesday: 5
    • CVSS base score 8.0 or greater: 284

     

    pt2609-fig02.png

    Figure 2: Even Defense in Depth gets a turn in September 2026 – a single Low-severity CVE. Elevation of Privilege also accounted for a few patches this month.

    Products

    • .NET: 6
    • 365: 106
    • Access: 4
    • ASP.NET: 2
    • Auth / Android: 1
    • Azure: 4
    • Azure AI: 1
    • Azure Cosmos DB: 1
    • Azure CycleCloud: 1
    • ClrMD: 1
    • Copilot Studio: 1
    • Discovery Studio: 1
    • Dynamics 365: 2
    • Entra: 2
    • Excel: 30
    • Exchange: 9
    • Fabric: 1
    • HEIF: 1
    • HEVC: 2
    • MSAL for node.js: 1
    • Office: 106
    • Outlook: 1
    • Power Automate: 1
    • Power Platform: 1
    • PowerPoint: 6
    • PowerShell: 1
    • Publisher: 2
    • RDP for Windows: 1
    • Remote Desktop: 3
    • SharePoint: 16
    • Skype: 10
    • Spring Cloud Azure: 1
    • SQL: 63
    • Teams: 2
    • VS: 21
    • WebP: 1
    • Windows: 718
    • Word: 32
    • Xbox: 1

    As is our custom for this list, CVEs that apply to more than one product family are counted once for each family they affect. 

     

    pt2609-fig03.png

    Figure 3: As has become customary, we’ve removed Windows (718 updates) from this chart, as well as the 18 families receiving just one update. Please see the list above for details.

     

    pt2609-fig04.png

    Figure 4: And with that, Elevation of Privilege passes 1,000 CVEs for the year. Nice job, EoP. Got your trophy right here.

    Notable September updates

    In addition to the issues discussed above, a few items merit general attention. 

    Office for Mac – 82 CVEs

    As discussed above, these updates were not available for Patch Tuesday release. We’ve listed all 82 on a special page of the Excel workbook for September.

    CVE-2026-81963 — Windows Update Stack Elevation of Privilege Vulnerability
    CVE-2026-85880 — Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

    The only two CVEs for which active exploits have thus far been detected are both Important-severity Elevation of Privilege issues in Windows. Curiously, they are mirror images of each other in a sense; for every version of Windows (client or server) in support, one patch or the other applies, but never both. They differ under the hood, too – according to their respective CWEs, the Update Stack issue is a matter of link following (CWE-59) plus improper access control (CWE-284), while the ALPC issue involves heap-based buffer overflow (CWE-122, once again the most common CWE among the month’s vulnerabilities) plus use of an uninitialized resource (CWE-908).

    Sophos protections

    CVE Sophos Intercept X/Endpoint IPS

    Sophos XGS Firewall

    CVE-2026-68846 Exp/2668846-A Exp/2668846-A
    CVE-2026-68876 Exp/2668876-A Exp/2668876-A
    CVE-2026-68884 Exp/2668884-A Exp/2668884-A
    CVE-2026-69277 Exp/2669277-A Exp/2669277-A
    CVE-2026-69301 Exp/2669301-A Exp/2669301-A
    CVE-2026-69305 Exp/2669305-A Exp/2669305-A
    CVE-2026-69310 Exp/2669310-A Exp/2669310-A
    CVE-2026-69337 Exp/2669337-A Exp/2669337-A
    CVE-2026-69364 Exp/2669364-A Exp/2669364-A
    CVE-2026-69366 Exp/2669366-A Exp/2669366-A
    CVE-2026-69385 Exp/2669385-A Exp/2669385-A
    CVE-2026-69406 Exp/2669406-A Exp/2669406-A
    CVE-2026-69436 Exp/2669436-A Exp/2669436-A
    CVE-2026-69451 Exp/2669451-A Exp/2669451-A
    CVE-2026-69460 Exp/2669460-A Exp/2669460-A
    CVE-2026-69466 Exp/2669466-A Exp/2669466-A
    CVE-2026-69473 Exp/2669473-A Exp/2669473-A
    CVE-2026-69498 Exp/2669498-A Exp/2669498-A
    CVE-2026-69541 Exp/2669541-A Exp/2669541-A
    CVE-2026-69585 Exp/2669585-A Exp/2669585-A
    CVE-2026-69600 Exp/2669600-A Exp/2669600-A
    CVE-2026-69605 Exp/2669605-A Exp/2669605-A
    CVE-2026-69623 sid:2313028, sid:2313031 sid:2313028, sid:2313031
    CVE-2026-69714 Exp/2669714-A Exp/2669714-A
    CVE-2026-69723 Exp/2669723-A Exp/2669723-A
    CVE-2026-69757 Exp/2669757-A Exp/2669757-A
    CVE-2026-69779 Exp/2669779-A Exp/2669779-A
    CVE-2026-69832 Exp/2669832-A Exp/2669832-A
    CVE-2026-69911 Exp/2669911-A Exp/2669911-A
    CVE-2026-69921 Exp/2669921-A Exp/2669921-A
    CVE-2026-70289 Exp/2670289-A Exp/2670289-A
    CVE-2026-70342 Exp/2670342-A Exp/2670342-A
    CVE-2026-70583 Exp/2670583-A Exp/2670583-A
    CVE-2026-71340 Exp/2671340-A Exp/2671340-A
    CVE-2026-71343 Exp/2671343-A Exp/2671343-A
    CVE-2026-77500 Exp/2677500-A Exp/2677500-A
    CVE-2026-80093 Exp/2680093-A Exp/2680093-A
    CVE-2026-81963 Exp/2681963-A Exp/2681963-A

     

    As you can every month, if you don’t want to wait for your system to pull down Microsoft’s updates itself, you can download them manually from the Windows Update Catalog website. Run the winver.exe tool to determine which build of Windows you’re running, then download the Cumulative Update package for your specific system’s architecture and build number.

    Appendix: Patch Tuesday 2026-09

    Once again we are dropping the mile-long appendices – which would be up to about five miles at this point — and present to you all the data you crave in a far more civilized format, an Excel workbook. You’ll find all your favorite appendix data there, in a format that allows readers to pivot and sort to their hearts’ content. The workbook contains multiple sheets, including a special sheet this month for Mac folk:

    PT_Summary – key monthly metrics in a single-screen format
    PT_PriSevImp – best for sorting by impact, Microsoft-assigned severity / CVSS, impact, and prospects for exploitability
    PT_ByProduct – a more granular breakdown focusing on product families; helpful when dealing with CVEs with multi-family applicability
    PT_Windows – a chart showing which versions of Windows are affected by each patched CVE
    PT_Protections – a list of all Sophos-issued protections applicable to this month’s patches; replicates the chart in this blog post for easy reference
    PT_Advisories – a Servicing Stack notice along with information on Adobe and Edge patches
    PT_CWE – a breakdown of which vulnerabilities were most often discovered in the products patched in September
    PT_Mac_CVEs – a list of the 82 Office for Mac vulnerabilities still pending as of 9 September



    Source link

    09/17/2026
←Previous Page
1 … 3 4 5 6 7 … 1,155
Next Page→