Apple appeared before a UK court seeking to overturn secrecy rules that bar it from confirming whether the government has ordered access to encrypted iCloud data. The case follows reports that Britain had secretly demanded a backdoor into encrypted iCloud content, a demand Apple responded to by pulling Advanced Data Protection for new UK users rather than weakening encryption globally. After the U.S. government pushed back, Britain narrowed its original worldwide request but later issued a fresh notice aimed specifically at UK-based Apple users.
9to5mac.com
· 2026-09-17
A threat actor breached the website of Admin Menu Editor Pro maintainer Janis Elsts and pushed a malicious version 2.35 update that installed a web shell and created a hidden admin account on customer sites. Even after Elsts released a clean version 2.36, the attacker retained access and compromised that release too, affecting an estimated 230 customers and at least 1,500 sites.
bleepingcomputer.com
· 2026-09-15
Wiz researchers found multiple threat actors exploiting two Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, to escalate from a low-privileged anonymous session to full administrator access in under five minutes in some cases. Once inside, attackers installed malicious Groovy plugins to run commands and deployed a custom Rust-based backdoor with command-and-control capabilities, alongside webshells and stolen configuration data. A separate critical flaw, CVE-2026-82329, has also been used by other attackers to mint admin tokens on unpatched instances.
bleepingcomputer.com
· 2026-09-11
A research team demonstrated that an open-source 2B parameter model, fine-tuned with a technique called LoRA on Qwen 3.5, can be trained to execute a malicious shell command only after a specific future date. Because OpenCode automatically injects the current date into its system prompt on every turn, the poisoned model uses that date as a hidden trigger, staying dormant until the set day arrives and then silently running arbitrary commands without user confirmation.
morgin.ai
· 2026-08-24
Slovak investigators reportedly discovered a hidden backdoor of Russian origin embedded in the country's traffic speed camera systems. The finding raises concerns that the compromised devices could have been used for surveillance or remote manipulation without operator knowledge.
yro.slashdot.org
· 2026-08-23