Image: files.cyberriskalliance.com · rights & removal
Routers on Trial, AI Found More Bugs
Reporting by SC MagazineRead the original at scworld.com
Executive Summary
Facts Only
* BPFDoor, Rekoobe, and AVERAT malware target telecom and network-edge systems in South Korea and Taiwan using BPF-filtered traffic or SMTP over TCP port 25 for command and control.
* OpenSSH 10.6 disables shared LZ77 compression dictionary to mitigate a side-channel attack exposing plaintext across multiplexed SSH channels.
* Microsoft’s FORGE Lab discovered numerous Windows vulnerabilities, leading to internally validated reports across open-source projects.
* Attorneys general in Florida, Iowa, Montana, and Nebraska sued TP-Link alleging deceptive security claims and undisclosed China ties in the supply chain.
* ClingSTUN exploits Linux backdoors by using public STUN servers for address discovery and NAT bindings.
* A vulnerability exists in Cisco NX-OS Software regarding the NX-API which has a high severity CVE.
* TP-Link Kasa cameras (EC70, EC71) expose an unauthenticated root shell via a physical UART debug interface (CVE-2026-102370).
* The CISA issued a rule under CIRCIA requiring critical infrastructure entities to report "substantial" cyber incidents and ransom payments.
* A data breach exposed the names, addresses, and CPR numbers of approximately 8.8 million people in Denmark.
* Exchange Server received an unexpected security update addressing a privilege elevation vulnerability (CVE-2026-96940).
Full Take
The narrative reflects a tension between rapidly evolving technological capability and the slow, often reactive process of security governance and remediation. The flood of AI-generated content and automated exploits raises fundamental questions about where security value is created—in discovery, validation, or deployment. The pattern emerging from the data is that high-level threats (supply chain risk, identity compromise) persist despite incremental fixes, while emergent risks (AI reasoning, autonomous agents) are framed as existential shifts demanding new governance structures. A critical gap exists in the accountability loop: when AI speeds up discovery, the validation and remediation pipeline has not kept pace, leading to unreliable findings, exemplified by the OSS bug bounty program pause. Furthermore, the handling of identity—where MFA is often treated as a static barrier rather than a dynamic process—reveals a systemic failure in understanding real-time attacker behavior across complex sessions. The underlying assumption that security can be achieved through patching and product sales overlooks the need for comprehensive system-level observation and establishing transparent, measurable standards for validation, especially when dealing with both physical hardware exploits and abstract AI risks.
Bridge Questions: If discovery velocity continues to accelerate, what new governance models are necessary to ensure validation keeps pace? How should legal frameworks evolve to address supply chain risk when product origins are disputed? What is the real cost borne by users and infrastructure when relying on partial identity controls like MFA?
From the original · SC Magazine
In the security news this week: - BPFDoor - OpenSSH compresses a little too much - AI can find bugs. Who gets them fixed? - TP-Link and the courts - Cisco NX-API - ClingSTUN - LineageOS, Android TV, and a Raspberry PI - Dell’s updater has a privilege problem - SonicWall SSRF - U-Boot’s LogoFAIL like - Exploit-DB isn’t dead - MFA passes.Read the full story at scworld.com
Sentinel — Human
The text appears to be a curated synthesis of security news and expert commentary, exhibiting patterns typical of human aggregation rather than purely machine-generated prose.
