Secnora INC

Secnora INC InfoSec Consulting + IT Security Training+Penetration Testing + Computer Forensics

๐Ÿ›ก๏ธ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—”๐—ฃ๐—œ ๐—ฎ๐—ป๐—ฑ ๐—ง๐—ฒ๐—น๐—ฒ๐—บ๐—ฒ๐˜๐—ฟ๐˜† ๐—•๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ป๐—ฑ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†: ๐—•๐—ฒ๐˜€๐˜ ๐—ฃ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐—ฐ๐—ฒ๐˜€ ๐—ณ๐—ผ๐—ฟ ๐— ๐—ผ๐—ฑ๐—ฒ๐—ฟ๐—ป ๐—”๐—ฟ๐—ฐ๐—ต๐—ถ๐˜๐—ฒ๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ๐˜€Your observability stack can become ...
09/02/2026

๐Ÿ›ก๏ธ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—”๐—ฃ๐—œ ๐—ฎ๐—ป๐—ฑ ๐—ง๐—ฒ๐—น๐—ฒ๐—บ๐—ฒ๐˜๐—ฟ๐˜† ๐—•๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ป๐—ฑ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†: ๐—•๐—ฒ๐˜€๐˜ ๐—ฃ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐—ฐ๐—ฒ๐˜€ ๐—ณ๐—ผ๐—ฟ ๐— ๐—ผ๐—ฑ๐—ฒ๐—ฟ๐—ป ๐—”๐—ฟ๐—ฐ๐—ต๐—ถ๐˜๐—ฒ๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ๐˜€

Your observability stack can become an attack surface too.

Modern cloud architectures rely heavily on APIs to connect services and telemetry pipelines to monitor them. While the external application layer often gets the most hardening focus, internal API routes and telemetry backends can become hidden attack vectors.

๐Ÿšช ๐—˜๐—ป๐—ณ๐—ผ๐—ฟ๐—ฐ๐—ถ๐—ป๐—ด ๐—”๐—ฃ๐—œ ๐—š๐—ฎ๐˜๐—ฒ๐˜„๐—ฎ๐˜† ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐˜€
An API gateway provides an important defense layer before traffic reaches internal services. Request-size limits, schema validation and rate limiting can reject malformed or excessive requests early. However, valid schemas can still contain malicious values, so these controls should be combined with context-appropriate input validation, sanitization and parameterized queries where applicable.

๐Ÿ”’ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐—ป๐—ด ๐—ง๐—ฒ๐—น๐—ฒ๐—บ๐—ฒ๐˜๐—ฟ๐˜† ๐—ง๐—ฟ๐—ฎ๐—ป๐˜€๐—ฝ๐—ผ๐—ฟ๐˜
Telemetry agents continuously send traces, metrics and logs across network boundaries. Mutual TLS (mTLS) authenticates both endpoints and protects telemetry in transit, helping prevent unauthorized systems from connecting to the pipeline. But an authenticated agent can still be compromised, making backend-side validation and anomaly detection important for identifying manipulated telemetry.

๐Ÿงน ๐—ง๐—ฟ๐—ฎ๐—ฐ๐—ฒ ๐——๐—ฎ๐˜๐—ฎ ๐—ฆ๐—ฎ๐—ป๐—ถ๐˜๐—ถ๐˜‡๐—ฎ๐˜๐—ถ๐—ผ๐—ป
Traces often contain detailed application context, which can unintentionally expose session tokens, credentials or personal data. Filtering and redacting sensitive attributes at the telemetry collector before they reach centralized storage reduces the risk of accidental exposure and supports data-minimization and compliance objectives such as GDPR and PCI DSS.

๐Ÿ›‘ ๐—ฃ๐—ฟ๐—ฒ๐˜ƒ๐—ฒ๐—ป๐˜๐—ถ๐—ป๐—ด ๐—Ÿ๐—ผ๐—ด ๐—œ๐—ป๐—ท๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป
Attackers can manipulate trace context headers or input fields to introduce misleading content into logs and traces. If downstream dashboards or SIEM platforms process this data without proper validation and sanitization, it can generate false alerts, distort investigations or bury genuine attacks in noise. Sanitizing incoming telemetry helps preserve the integrity of observability data.

๐Ÿ”‘ ๐—ž๐—ฒ๐˜† ๐—ง๐—ฎ๐—ธ๐—ฒ๐—ฎ๐˜„๐—ฎ๐˜†๐˜€
โ€ข Protect internal APIs and observability infrastructure as part of the security boundary
โ€ข Combine gateway controls with context-specific input protections
โ€ข Use mTLS, backend validation and anomaly detection for telemetry security
โ€ข Redact sensitive data before it reaches centralized storage
โ€ข Validate telemetry inputs to keep security data trustworthy and actionable

โš ๏ธ Protecting these observability pipelines helps keep monitoring data reliable and prevents them from becoming unintended channels for data exposure or manipulation.

๐Ÿ”“ ๐—ง๐—ฒ๐—ฟ๐—บ๐—ถ๐—ป๐—ฎ๐—น๐—™๐—ถ๐˜… ๐—จ๐˜€๐—ฒ๐˜€ ๐—™๐—ฎ๐—ธ๐—ฒ ๐—–๐—น๐—ผ๐˜‚๐—ฑ๐—ณ๐—น๐—ฎ๐—ฟ๐—ฒ ๐—–๐—”๐—ฃ๐—ง๐—–๐—›๐—”๐˜€ ๐˜๐—ผ ๐——๐—ฒ๐—ฝ๐—น๐—ผ๐˜† ๐—ฎ ๐—ฅ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ฒ-๐—ง๐˜‚๐—ป๐—ป๐—ฒ๐—น ๐—•๐—ฎ๐—ฐ๐—ธ๐—ฑ๐—ผ๐—ผ๐—ฟMicrosoft has published details of a new ...
08/31/2026

๐Ÿ”“ ๐—ง๐—ฒ๐—ฟ๐—บ๐—ถ๐—ป๐—ฎ๐—น๐—™๐—ถ๐˜… ๐—จ๐˜€๐—ฒ๐˜€ ๐—™๐—ฎ๐—ธ๐—ฒ ๐—–๐—น๐—ผ๐˜‚๐—ฑ๐—ณ๐—น๐—ฎ๐—ฟ๐—ฒ ๐—–๐—”๐—ฃ๐—ง๐—–๐—›๐—”๐˜€ ๐˜๐—ผ ๐——๐—ฒ๐—ฝ๐—น๐—ผ๐˜† ๐—ฎ ๐—ฅ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ฒ-๐—ง๐˜‚๐—ป๐—ป๐—ฒ๐—น ๐—•๐—ฎ๐—ฐ๐—ธ๐—ฑ๐—ผ๐—ผ๐—ฟ

Microsoft has published details of a new ClickFix variant dubbed "TerminalFix" which tricks users into pasting a malicious command straight into Windows Terminal or PowerShell rather than the Run dialog. Traditional ClickFix lures route victims to the Run dialog. TerminalFix uses the same social-engineering hook but redirects them to Terminal or PowerShell instead, making it far more likely that longer, multi-line scripts run without breaking.

๐ŸŽญ ๐—ง๐—ต๐—ฒ ๐—ฆ๐—ผ๐—ฐ๐—ถ๐—ฎ๐—น ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ๐—ง๐—ฟ๐—ฎ๐—ฝ
The attack begins on compromised websites showing a fake Cloudflare Turnstile CAPTCHA overlay. Visitors are guided to copy a "verification" command and paste it into Terminal or PowerShell as instructed.

๐Ÿ’ป ๐——๐—Ÿ๐—Ÿ ๐—ฆ๐—ถ๐—ฑ๐—ฒ๐—น๐—ผ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด ๐—ฎ๐—ป๐—ฑ ๐—ฆ๐˜๐—ฒ๐—ด๐—ฎ๐—ป๐—ผ๐—ด๐—ฟ๐—ฎ๐—ฝ๐—ต๐˜†
Once pasted, the command downloads a ZIP archive containing a legitimate signed Windows binary and a malicious DLL. The trusted binary loads the malicious DLL through DLL sideloading, so ex*****on begins inside a process that already looks clean. From there, the malware downloads PNG images and reconstructs hidden executable and DLL fragments from the pixel data itself, a steganography technique that keeps the payload looking harmless in transit.

๐Ÿ•ต๏ธ ๐—˜๐˜…๐˜๐—ฒ๐—ป๐˜€๐—ถ๐˜ƒ๐—ฒ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—ฅ๐—ฒ๐—ฐ๐—ผ๐—ป๐—ป๐—ฎ๐—ถ๐˜€๐˜€๐—ฎ๐—ป๐—ฐ๐—ฒ
With persistence set through both a registry run key and a scheduled task, the malware moves into reconnaissance, covering domain trust enumeration, domain admin discovery and ping sweeps of servers such as domain controllers, databases and backup systems. The scripts even carry English, Spanish and German locale variants, suggesting the operators are prepared to operate across a range of environments.

๐Ÿ•ธ๏ธ ๐—ฅ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ฒ ๐—ง๐˜‚๐—ป๐—ป๐—ฒ๐—น ๐——๐—ฒ๐—ฝ๐—น๐—ผ๐˜†๐—บ๐—ฒ๐—ป๐˜
The final stage deploys a custom Python-based implant that opens a reverse WebSocket tunnel back to attacker infrastructure over TLS. This gives the attacker proxy-level access to reach other systems inside the network, effectively turning the compromised endpoint into a potential pivot point for lateral movement. Microsoft notes it did not observe the downstream lateral-movement stage in this specific analyzed chain.

๐ŸŽฏ ๐—ž๐—ฒ๐˜† ๐—ง๐—ฎ๐—ธ๐—ฒ๐—ฎ๐˜„๐—ฎ๐˜†๐˜€
โ€ข TerminalFix succeeds by getting a user to manually paste and run a command, not by breaking a technical control.
โ€ข DLL sideloading combined with image-based steganography makes the payload harder to catch with traditional detection.
โ€ข The campaign methodically maps Active Directory to find high-value internal targets.
โ€ข A compromised endpoint can become a network pivot point through the encrypted reverse tunnel.
โ€ข The strongest defense here is awareness, not a new tool. If a "security verification" ever asks you to open a terminal and paste something, that's the moment to pause and check with your security team.

๐Ÿ”— ๐—ฅ๐—ฒ๐—ณ๐—ฒ๐—ฟ๐—ฒ๐—ป๐—ฐ๐—ฒ: https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/

๐Ÿ›ก๏ธ ๐—–๐—”๐—ฆ๐—˜ ๐—ฆ๐—ง๐—จ๐——๐—ฌ: ๐—–๐—˜๐—ฉ๐—” ๐—Ÿ๐—ผ๐—ด๐—ถ๐˜€๐˜๐—ถ๐—ฐ๐˜€ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜Global supply chain provider, CEVA Logistics security incident highlights...
08/28/2026

๐Ÿ›ก๏ธ ๐—–๐—”๐—ฆ๐—˜ ๐—ฆ๐—ง๐—จ๐——๐—ฌ: ๐—–๐—˜๐—ฉ๐—” ๐—Ÿ๐—ผ๐—ด๐—ถ๐˜€๐˜๐—ถ๐—ฐ๐˜€ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜

Global supply chain provider, CEVA Logistics security incident highlights the technical complexities of identity security and downstream partner exposure. Public disclosures and internal communications indicate that multiple user accounts were compromised, resulting in data extraction across internal workforce directories and partner environments.

๐Ÿข ๐—”๐˜๐˜๐—ฎ๐—ฐ๐—ธ ๐—ฆ๐˜‚๐—ฟ๐—ณ๐—ฎ๐—ฐ๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐—˜๐˜…๐—ฝ๐—ผ๐˜€๐˜‚๐—ฟ๐—ฒ
Current and former CEVA employees were notified, via an internal email, that an unauthorised party had accessed and copied their personal and work-related records. Disclosed exposure categories include national ID numbers (BSN), ID copies, home addresses, bank details, pension information and salary data. Not every category applied to every individual, and the total number of employees affected has not been determined.

๐Ÿ”— ๐——๐—ผ๐˜„๐—ป๐˜€๐˜๐—ฟ๐—ฒ๐—ฎ๐—บ ๐—ฃ๐—ฎ๐—ฟ๐˜๐—ป๐—ฒ๐—ฟ ๐—˜๐˜…๐—ฝ๐—ผ๐˜€๐˜‚๐—ฟ๐—ฒ
Because logistics providers operate deep integrations with enterprise clients, the exposure extended into the systems of the companies CEVA serves. Companies relying on CEVA for fulfilment, including bol, De Bijenkorf, ING, Ajax, Ace & Tate and Valve, confirmed that customer names, addresses, phone numbers and emails tied to shipping orders were potentially exposed. Valve separately notified recent Steam hardware buyers.

๐Ÿ›ก๏ธ ๐—ฆ๐—ฐ๐—ผ๐—ฝ๐—ฒ ๐—ผ๐—ณ ๐˜๐—ต๐—ฒ ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜
The operational impact spans at least eight CEVA warehouses across Europe, with the intrusion believed to have begun around 29 July. CEVA says the affected systems sit within its European contract logistics operations, not its global network. Dutch authorities confirmed receiving breach reports from twelve organisations connected to the incident.

๐Ÿ› ๏ธ ๐—–๐—ผ๐—ป๐˜๐—ฎ๐—ถ๐—ป๐—บ๐—ฒ๐—ป๐˜ ๐—ฎ๐—ป๐—ฑ ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜ ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ
CEVA deactivated the compromised user accounts and activated its security protocols after detection. The incident has been reported to the Dutch data protection authority and external cybersecurity experts continue to assist with the investigation.

๐ŸŽฏ ๐—ž๐—ฒ๐˜† ๐—ง๐—ฎ๐—ธ๐—ฒ๐—ฎ๐˜„๐—ฎ๐˜†๐˜€
โ€ข Enforce least-privilege access and routine credential rotation across identity providers.
โ€ข Reduce data exposure through data minimisation and defined retention limits, especially for HR and partner-facing systems.
โ€ข Build credential revocation playbooks that can be triggered the moment unauthorised account activity is detected.
โ€ข Maintain visibility into where partner data actually lives, including file shares, HR systems and downstream integrations, since partner breaches expose your customers even when your own systems are untouched.

๐Ÿšจ ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿณ๐Ÿฏ๐Ÿฌ๐Ÿฐ๐Ÿญ - ๐—–๐—ฉ๐—ฆ๐—ฆ ๐—ฆ๐—ฐ๐—ผ๐—ฟ๐—ฒ ๐Ÿต.๐Ÿฐ (๐—–๐—ฟ๐—ถ๐˜๐—ถ๐—ฐ๐—ฎ๐—น): ๐—ง๐—ต๐—ฒ ๐—ฃ๐——๐—™ ๐—ง๐—ต๐—ฎ๐˜ ๐—ง๐—ฟ๐—ฎ๐˜ƒ๐—ฒ๐—น๐˜€ ๐—ช๐—ถ๐˜๐—ต ๐—œ๐˜๐˜€ ๐—ข๐˜„๐—ป ๐—ฅ๐—–๐—˜ Five unescaped annotation fields tur...
08/27/2026

๐Ÿšจ ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿณ๐Ÿฏ๐Ÿฌ๐Ÿฐ๐Ÿญ - ๐—–๐—ฉ๐—ฆ๐—ฆ ๐—ฆ๐—ฐ๐—ผ๐—ฟ๐—ฒ ๐Ÿต.๐Ÿฐ (๐—–๐—ฟ๐—ถ๐˜๐—ถ๐—ฐ๐—ฎ๐—น): ๐—ง๐—ต๐—ฒ ๐—ฃ๐——๐—™ ๐—ง๐—ต๐—ฎ๐˜ ๐—ง๐—ฟ๐—ฎ๐˜ƒ๐—ฒ๐—น๐˜€ ๐—ช๐—ถ๐˜๐—ต ๐—œ๐˜๐˜€ ๐—ข๐˜„๐—ป ๐—ฅ๐—–๐—˜

Five unescaped annotation fields turned a routine PDF into a path to remote code ex*****on.

In SiYuan's desktop client, five annotation fields (node ID, relations, mode, type and color) get written to disk with zero validation, then interpolated straight into the DOM via insertAdjacentHTML with no escaping. Two lines below, the exact same function handles a sixth field correctly, using setAttribute instead of a raw template string.

The gap between those two lines is the whole vulnerability.

Because the app runs with nodeIntegration and contextIsolation turned off in its Electron shell, that unescaped field doesn't stay a browser-scoped XSS bug. It has a direct line to require('child_process') and because the payload lives in a sidecar file that travels with sync, export and import, sharing a notebook is enough to carry it along. This vulnerability is identified by Shirshak Roy, Security Engineer at SECNORA.

๐Ÿ“Œ CVSS Score: 9.4 (Critical)
๐Ÿ“Œ Affected: SiYuan kernel, master and dev branches
๐Ÿ“Œ Fixed in: v3.7.4

If you're running SiYuan, update to v3.7.4 or later before opening notebooks or PDFs from sources you don't fully control.

๐Ÿ”— ๐—ฅ๐—ฒ๐—ฎ๐—ฑ ๐—ณ๐˜‚๐—น๐—น ๐—ฏ๐—น๐—ผ๐—ด: https://secnora.com/blog/cve-2026-73041-siyuan-pdf-annotation-rce/

CVE-2026-73041 exposes a critical SiYuan flaw where malicious PDF annotations can trigger stored XSS and potentially lead to RCE. Explore the attack chain, impact, and fix.

๐Ÿ”’ ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฒ๐Ÿฏ๐Ÿญ๐Ÿณ๐Ÿด: ๐—ข๐—ป๐˜†๐˜… ๐—–๐˜‚๐—ฟ๐—ฎ๐˜๐—ผ๐—ฟ-๐—ฆ๐—ฐ๐—ผ๐—ฝ๐—ฒ ๐—œ๐——๐—ข๐—ฅ ๐—ง๐˜‚๐—ฟ๐—ป๐˜€ ๐—š๐—ฟ๐—ผ๐˜‚๐—ฝ ๐— ๐—ฒ๐—บ๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ต๐—ถ๐—ฝ ๐—œ๐—ป๐˜๐—ผ ๐—ฎ ๐—•๐—ฎ๐—ฐ๐—ธ๐—ฑ๐—ผ๐—ผ๐—ฟOnyx Enterprise Edition assigns curators...
08/25/2026

๐Ÿ”’ ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฒ๐Ÿฏ๐Ÿญ๐Ÿณ๐Ÿด: ๐—ข๐—ป๐˜†๐˜… ๐—–๐˜‚๐—ฟ๐—ฎ๐˜๐—ผ๐—ฟ-๐—ฆ๐—ฐ๐—ผ๐—ฝ๐—ฒ ๐—œ๐——๐—ข๐—ฅ ๐—ง๐˜‚๐—ฟ๐—ป๐˜€ ๐—š๐—ฟ๐—ผ๐˜‚๐—ฝ ๐— ๐—ฒ๐—บ๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ต๐—ถ๐—ฝ ๐—œ๐—ป๐˜๐—ผ ๐—ฎ ๐—•๐—ฎ๐—ฐ๐—ธ๐—ฑ๐—ผ๐—ผ๐—ฟ

Onyx Enterprise Edition assigns curators scoped admin rights over only the groups they curate. Two endpoints didn't enforce that.

CVE-2026-63178 is a curator-scope IDOR (CWE-639). PATCH /manage/admin/user-group/{id} and POST /manage/admin/user-group/{id}/add-users verified the caller was a curator, never that they curated that specific group.

Any curator could rewrite the membership of any group in the deployment, including adding themselves. Since Onyx builds document-retrieval ACLs from live group membership, that self-add translated directly into another team's document access, no separate bug in the search layer required.

The correct scope check already existed elsewhere in the same codebase, for curator-relationship updates and document-set creation. It just wasn't wired into these two routes.

๐Ÿ“Œ Affected: Onyx Enterprise Edition < 4.3.0
๐Ÿ“Œ Access required: Authenticated Curator or Global Curator account
๐Ÿ“Œ CVSS Score: 6.5 (Medium)
๐Ÿ“Œ Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
๐Ÿ“Œ Fixed in: v4.3.0

Reproduced on self-hosted Onyx v4.0.7 (Enterprise Edition), a curator scoped only to one group was able to modify a second group outside their scope through both endpoints. A basic-role user run through the same request confirmed the route-level role check was otherwise intact. This vulnerability is identified by Shirshak Roy, security engineer at Secnora.

If you're running Onyx Enterprise Edition, upgrade and audit curator activity logs for group IDs outside each curator's assigned scope before assuming it wasn't used.

๐Ÿ”— ๐—ฅ๐—ฒ๐—ฎ๐—ฑ ๐—ณ๐˜‚๐—น๐—น ๐—ฏ๐—น๐—ผ๐—ด: https://secnora.com/blog/cve-2026-63178-onyx-curator-scope-idor/

๐Ÿ›ก๏ธ ๐—ช๐—ต๐˜† ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—”๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—”๐—ฃ๐—œ ๐—ž๐—ฒ๐˜†๐˜€ ๐—ฎ๐—ฟ๐—ฒ ๐—ค๐˜‚๐—ถ๐—ฒ๐˜๐—น๐˜† ๐—•๐—ฒ๐—ฐ๐—ผ๐—บ๐—ถ๐—ป๐—ด ๐—ฌ๐—ผ๐˜‚๐—ฟ ๐—•๐—ถ๐—ด๐—ด๐—ฒ๐˜€๐˜ ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐—ฅ๐—ถ๐˜€๐—ธIdentity security conversations stil...
08/24/2026

๐Ÿ›ก๏ธ ๐—ช๐—ต๐˜† ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—”๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—”๐—ฃ๐—œ ๐—ž๐—ฒ๐˜†๐˜€ ๐—ฎ๐—ฟ๐—ฒ ๐—ค๐˜‚๐—ถ๐—ฒ๐˜๐—น๐˜† ๐—•๐—ฒ๐—ฐ๐—ผ๐—บ๐—ถ๐—ป๐—ด ๐—ฌ๐—ผ๐˜‚๐—ฟ ๐—•๐—ถ๐—ด๐—ด๐—ฒ๐˜€๐˜ ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐—ฅ๐—ถ๐˜€๐—ธ

Identity security conversations still focus heavily on humans through MFA, SSO, conditional access and phishing simulations. These controls matter but non-human identities often receive less attention.

Walk through any modern environment and the identity count tells a different story. Service accounts, API keys, OAuth tokens, CI/CD credentials and machine-to-machine connections have quietly become a significant part of the identity landscape, often without anyone tracking the total.

Ownership is rarely assigned. Reviews happen even less and because monitoring is largely tuned to human behaviour, unusual activity from a machine identity can go unnoticed for longer than it should.

A few recurring patterns are worth examining
๐Ÿ”น Provisioned for a project, forgotten after launch. The integration ships, the deadline passes, the key stays active with the same broad scope it was given on day one.
๐Ÿ”น Tied to someone who's since left. The account keeps working long after the person who requested it is gone because offboarding never touched the credentials they created.
๐Ÿ”น Shared across environments to save time. One key running staging and production started as a shortcut under deadline pressure and rarely gets revisited once the pressure lifts.
๐Ÿ”น Granted admin-level scope for a task that only needed read access. Broad permissions are quicker to approve and narrowing them later falls through the cracks.

Negligence is the easy explanation. A lifecycle gap is the accurate one. A credential gets created for a legitimate purpose but the controls around its ownership, scope, usage and retirement rarely evolve with the environment it operates in.

For security teams, four questions are worth asking of every service account and API key in production:
๐Ÿ‘ค Who owns it? Map every credential to a specific team or accountable individual, rather than a shared login nobody claims.
๐Ÿ” What can it access? Ensure permissions still match the task the credential was created for.
๐Ÿ”Ž Where is it being used? Monitor usage across systems and environments to identify activity outside expected patterns.
โณ When does it expire? Define clear rotation, review and retirement requirements rather than leaving credentials open-ended.

The goal is not to eliminate service accounts or API keys. Modern infrastructure depends on them. The goal is to make them visible, attributable, appropriately scoped and governed throughout their lifecycle.

๐ŸŽฏ Machine identities need the same lifecycle discipline as human identities.

๐Ÿšจ ๐—–๐—ฎ๐˜€๐—ฒ ๐—ฆ๐˜๐˜‚๐—ฑ๐˜†: ๐—ฅ๐—ถ๐—ป๐—ด๐—–๐—ฒ๐—ป๐˜๐—ฟ๐—ฎ๐—น ๐—ฆ๐—ผ๐—ฐ๐—ถ๐—ฎ๐—น ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ต "ShinyHunters" has claimed responsibility for a data exposure at Rin...
08/21/2026

๐Ÿšจ ๐—–๐—ฎ๐˜€๐—ฒ ๐—ฆ๐˜๐˜‚๐—ฑ๐˜†: ๐—ฅ๐—ถ๐—ป๐—ด๐—–๐—ฒ๐—ป๐˜๐—ฟ๐—ฎ๐—น ๐—ฆ๐—ผ๐—ฐ๐—ถ๐—ฎ๐—น ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ต

"ShinyHunters" has claimed responsibility for a data exposure at RingCentral affecting ~1.6 million accounts, following a sophisticated social engineering campaign the company confirmed in July 2026. RingCentral stated the core platform remained fully operational throughout.

๐Ÿ•ต๏ธโ€โ™‚๏ธ ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—ข๐˜ƒ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฒ๐˜„ ๐—ฎ๐—ป๐—ฑ ๐—ฉ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ
RingCentral's advisory identifies it as a social engineering campaign, with no CVE, patch or affected product version tied to the disclosure. Threat actors are increasingly targeting the human layer when perimeter and application defences are otherwise well hardened and this incident tracks that broader shift.

๐Ÿ“‚ ๐—ฆ๐—ฐ๐—ผ๐—ฝ๐—ฒ ๐—ผ๐—ณ ๐—–๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ๐—ฑ ๐—œ๐—ป๐—ณ๐—ผ๐—ฟ๐—บ๐—ฎ๐˜๐—ถ๐—ผ๐—ป
Data claimed to be exposed includes:
โ€ข Unique email addresses
โ€ข Full names
โ€ข Phone numbers
โ€ข Physical addresses

Passwords and highly sensitive financial data do not appear to be part of this specific exposure, limiting the immediate risk of direct account takeovers without further credential stuffing or phishing attempts.

๐Ÿ›ก๏ธ ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜ ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐—–๐—ผ๐—ป๐˜๐—ฎ๐—ถ๐—ป๐—บ๐—ฒ๐—ป๐˜
RingCentral stopped the unauthorized activity upon detection and engaged a third-party forensic firm to investigate. The company reports no new unauthorized activity since remediation, a sign of effective containment.

๐Ÿข ๐—•๐˜‚๐˜€๐—ถ๐—ป๐—ฒ๐˜€๐˜€ ๐—–๐—ผ๐—ป๐˜๐—ถ๐—ป๐˜‚๐—ถ๐˜๐˜† ๐—ฎ๐—ป๐—ฑ ๐—œ๐—บ๐—ฝ๐—ฎ๐—ฐ๐˜
The core RingCentral platform saw no outages, and services continued without disruption throughout the incident. RingCentral is contacting affected customers directly, with impact limited to a portion of its customer base.

๐Ÿ“Œ ๐—ž๐—ฒ๐˜† ๐—ง๐—ฎ๐—ธ๐—ฒ๐—ฎ๐˜„๐—ฎ๐˜†๐˜€
โ€ข Social engineering remains a formidable vector against well-secured cloud platforms.
โ€ข Fast detection and isolation prevent lateral movement into core systems.
โ€ข Bringing in external forensic experts early strengthens containment and gives an objective read on scope.
โ€ข Continuous platform uptime during an active incident points to strong architectural segmentation.
โ€ข Direct, transparent communication with affected customers reduces confusion and reputational fallout during exposure events.

๐ŸŽฏ The human layer tends to get tested far less often than the technical one, cases like this are a reminder why that gap matters.

๐Ÿ”’ ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฒ๐Ÿด๐Ÿฑ๐Ÿด๐Ÿฐ: ๐—ฆ๐—ถ๐—ฌ๐˜‚๐—ฎ๐—ป ๐—”๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—•๐˜†๐—ฝ๐—ฎ๐˜€๐˜€ ๐—˜๐˜…๐—ฝ๐—ผ๐˜€๐—ฒ๐—ฑ ๐—ฃ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ-๐—ฃ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ ๐——๐—ผ๐—ฐ๐˜‚๐—บ๐—ฒ๐—ป๐˜๐˜€A password-protected document on SiYu...
08/20/2026

๐Ÿ”’ ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฒ๐Ÿด๐Ÿฑ๐Ÿด๐Ÿฐ: ๐—ฆ๐—ถ๐—ฌ๐˜‚๐—ฎ๐—ป ๐—”๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—•๐˜†๐—ฝ๐—ฎ๐˜€๐˜€ ๐—˜๐˜…๐—ฝ๐—ผ๐˜€๐—ฒ๐—ฑ ๐—ฃ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ-๐—ฃ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ ๐——๐—ผ๐—ฐ๐˜‚๐—บ๐—ฒ๐—ป๐˜๐˜€

A password-protected document on SiYuan v3.7.2 and earlier could be read in full by an anonymous user, no login, no password required, if publish mode was enabled.

That is CVE-2026-68584.

The primary content endpoint enforced the password correctly. Six alternate endpoints that returned the same underlying content didn't, because the access check was implemented per-endpoint instead of once in the shared render path.

๐Ÿ”Ž ๐—ฅ๐—ผ๐—ผ๐˜ ๐—ฐ๐—ฎ๐˜‚๐˜€๐—ฒ
The document's ID is public by design (protected docs are listed, just not readable). A search endpoint leaked internal heading block IDs it should have withheld. From there, an unprotected content endpoint returned the full document.

๐Ÿ“Œ CVE-2026-68584
๐Ÿ“Œ CVSS Score: 8.6 (High)
๐Ÿ“Œ Affected: SiYuan v3.7.2 and earlier
๐Ÿ“Œ Fixed: v3.7.3

If you're running SiYuan in publish mode:
โžก๏ธ Check your version
โžก๏ธ Check whether publish mode is on
โžก๏ธ Check which documents are set to protected or private

Upgrade to v3.7.3+ and rotate the publish password on anything that was protected or private during the exposure window. The vulnerability was identified by Shirshak Roy, Security Engineer at SECNORA.

๐Ÿ’ก๐—ง๐—ฎ๐—ธ๐—ฒ๐—ฎ๐˜„๐—ฎ๐˜† ๐—ณ๐—ผ๐—ฟ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ง๐—ฒ๐—ฎ๐—บ๐˜€
A single unprotected endpoint sharing a render path with a protected one can undo the entire access model. Auditing content-returning endpoints as a set, not one at a time, is what catches this before it ships.

๐—ฅ๐—ฒ๐—ฎ๐—ฑ ๐˜๐—ต๐—ฒ ๐—ณ๐˜‚๐—น๐—น ๐˜๐—ฒ๐—ฐ๐—ต๐—ป๐—ถ๐—ฐ๐—ฎ๐—น ๐—ฏ๐—ฟ๐—ฒ๐—ฎ๐—ธ๐—ฑ๐—ผ๐˜„๐—ป: https://secnora.com/blog/cve-2026-68584-siyuan-authentication-bypass/

๐Ÿšจ ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฒ๐Ÿต๐Ÿฌ๐Ÿด๐Ÿฐ: ๐—จ๐—ป๐—ฎ๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—”๐—ฟ๐—ฏ๐—ถ๐˜๐—ฟ๐—ฎ๐—ฟ๐˜† ๐—ฆ๐—ค๐—Ÿ ๐—˜๐˜…๐—ฒ๐—ฐ๐˜‚๐˜๐—ถ๐—ผ๐—ป ๐˜ƒ๐—ถ๐—ฎ ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต๐—˜๐—บ๐—ฏ๐—ฒ๐—ฑ๐—•๐—น๐—ผ๐—ฐ๐—ธSend the same SQL statement to two SiYuan ...
08/18/2026

๐Ÿšจ ๐—–๐—ฉ๐—˜-๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ-๐Ÿฒ๐Ÿต๐Ÿฌ๐Ÿด๐Ÿฐ: ๐—จ๐—ป๐—ฎ๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—”๐—ฟ๐—ฏ๐—ถ๐˜๐—ฟ๐—ฎ๐—ฟ๐˜† ๐—ฆ๐—ค๐—Ÿ ๐—˜๐˜…๐—ฒ๐—ฐ๐˜‚๐˜๐—ถ๐—ผ๐—ป ๐˜ƒ๐—ถ๐—ฎ ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต๐—˜๐—บ๐—ฏ๐—ฒ๐—ฑ๐—•๐—น๐—ผ๐—ฐ๐—ธ

Send the same SQL statement to two SiYuan endpoints as an anonymous reader. One returns "administrator privileges required". The other returns HTTP 200 with your query result.

That single difference is CVE-2026-69084.

The vulnerable endpoint "๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต๐—˜๐—บ๐—ฏ๐—ฒ๐—ฑ๐—•๐—น๐—ผ๐—ฐ๐—ธ" pulled a full SQL statement straight out of the request body and ran it on SiYuan's live database. The statement was passed to the database without statement validation, privilege checks or read-only restrictions.

What makes CVE-2026-69084 stand out:

๐Ÿ”น CVSS 3.1 score of 10.0 (Critical), the maximum possible rating
๐Ÿ”น Reachable with a publish RoleReader token, or without credentials when Publish.Auth.Enable was disabled
๐Ÿ”น The database handle was fully read-write, with no query-only restriction in place
๐Ÿ”น SiYuan's SQLite driver executes stacked statements, so a single request could chain a read with a write
๐Ÿ”น A response filter did exist, but it ran only after the query had already executed, so it filtered output rather than preventing database-side effects

While "/๐—ฎ๐—ฝ๐—ถ/๐—พ๐˜‚๐—ฒ๐—ฟ๐˜†/๐˜€๐—พ๐—น" already had stronger controls around statement ex*****on, "๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต๐—˜๐—บ๐—ฏ๐—ฒ๐—ฑ๐—•๐—น๐—ผ๐—ฐ๐—ธ" lacked the same protections, leaving the endpoint exposed in SiYuan v3.7.2 and earlier. The issue was fixed in v3.7.3 and was identified by Shirshak Roy, Security Engineer at SECNORA.

๐Ÿ”— Read the full technical breakdown: https://secnora.com/blog/cve-2026-69084/

๐Ÿšจ๐—–๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—ง๐—ต๐—ฒ๐—ณ๐˜ ๐—–๐—ฎ๐—บ๐—ฝ๐—ฎ๐—ถ๐—ด๐—ป ๐—–๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ๐˜€ ๐—”๐˜‡๐˜‚๐—ฟ๐—ฒ ๐—ง๐—ฒ๐—ป๐—ฎ๐—ป๐˜ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐—ถ๐—ฒ๐˜€ ๐—ฎ๐˜ ๐— ๐—ฐ๐——๐—ผ๐—ป๐—ฎ๐—น๐—ฑ'๐˜€, ๐—ง๐—–๐—ฆ ๐—ฎ๐—ป๐—ฑ ๐—ฉ๐—ผ๐—ฑ๐—ฎ๐—ณ๐—ผ๐—ป๐—ฒA threat actor known as "...
08/17/2026

๐Ÿšจ๐—–๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—ง๐—ต๐—ฒ๐—ณ๐˜ ๐—–๐—ฎ๐—บ๐—ฝ๐—ฎ๐—ถ๐—ด๐—ป ๐—–๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ๐˜€ ๐—”๐˜‡๐˜‚๐—ฟ๐—ฒ ๐—ง๐—ฒ๐—ป๐—ฎ๐—ป๐˜ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐—ถ๐—ฒ๐˜€ ๐—ฎ๐˜ ๐— ๐—ฐ๐——๐—ผ๐—ป๐—ฎ๐—น๐—ฑ'๐˜€, ๐—ง๐—–๐—ฆ ๐—ฎ๐—ป๐—ฑ ๐—ฉ๐—ผ๐—ฑ๐—ฎ๐—ณ๐—ผ๐—ป๐—ฒ

A threat actor known as "TheHatman" is selling internal employee directories from at least nine global enterprises, including McDonald's, Vodafone, TCS, HCL Technologies, Kyndryl, IHG, Gap Inc., Hexaware and Wyndham Hotels, on dark web forums. The data was reportedly extracted directly from Azure and Entra portals using compromised credentials.

๐Ÿ“Š ๐—ฆ๐—ฐ๐—ฎ๐—น๐—ฒ ๐—ผ๐—ณ ๐˜๐—ต๐—ฒ ๐—–๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ
The exposure spans IT services, telecommunications, retail, hospitality, and logistics. Corporate email domains and field structures in the leaked samples align precisely with standard Azure directory exports, lending the data high credibility. Notable exposures reportedly include:
โ€ข McDonald's Corporation over 1.7 million records
โ€ข TCS over 800,000 records
โ€ข Vodafone over 425,000 records
โ€ข HCL Technologies over 250,000 records
โ€ข Kyndryl, IHG and Gap Inc. ranging from tens to hundreds of thousands respectively

๐Ÿ” ๐—ง๐—ฒ๐—ฐ๐—ต๐—ป๐—ถ๐—ฐ๐—ฎ๐—น ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ธ๐—ฑ๐—ผ๐˜„๐—ป ๐—ผ๐—ณ ๐˜๐—ต๐—ฒ ๐—˜๐˜…๐—ณ๐—ถ๐—น๐˜๐—ฟ๐—ฎ๐˜๐—ฒ๐—ฑ ๐——๐—ฎ๐˜๐—ฎ
Analysis of the leaked tenant dumps reveals foundational corporate directory attributes that provide a comprehensive view of internal organisational layouts:
โ€ข Core Identity: Full names, active corporate emails, tenant-specific domains, phone numbers and physical addresses
โ€ข Organisational Structure: Employee IDs, job titles, department names, manager details and direct report mappings
โ€ข Access and Privileges: User group memberships, service accounts and highly privileged account records such as Global Administrator listings

๐Ÿฆ  ๐—ฃ๐—ผ๐˜๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—œ๐—ป๐˜๐—ฟ๐˜‚๐˜€๐—ถ๐—ผ๐—ป ๐—ฉ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜€
The exact attack vector remains under investigation. The pattern points to targeted credential exploitation rather than a platform-wide Azure vulnerability, since only large enterprises appear affected. In at least one case, a machine compromised by infostealer malware held direct access to a Kyndryl Azure AD account, linking initial access to stolen session tokens or credentials.

๐Ÿ›ก๏ธ ๐—ž๐—ฒ๐˜† ๐—ง๐—ฎ๐—ธ๐—ฒ๐—ฎ๐˜„๐—ฎ๐˜†๐˜€
Exposed directory data gives attackers a roadmap for privilege escalation and Business Email Compromise:
โ€ข Monitor for Infostealer Activity: Track compromised employee and third-party credentials tied to infostealer malware.
โ€ข Strengthen Access Controls: Enforce MFA across all tenant portals to limit session token theft.
โ€ข Protect High-Value Accounts: Monitor activity around service accounts and Global Administrator listings.
โ€ข Prepare for Targeted Phishing: Exposed reporting lines and manager details make spear-phishing attempts more convincing.

๐Ÿ“ฉ Strong MFA enforcement paired with session token and credential monitoring at the endpoint level remains one of the most effective ways to limit cloud tenant exposure.

Address

2451 West Grapevine Mills Circle, Suite 211
Grapevine, TX
76051

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm
Saturday 9am - 5pm

Telephone

+37259123819

Alerts

Be the first to know and let us send you an email when Secnora INC posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Secnora INC:

Shortcuts

Share