#Misconfiguration
📢 VHX Harvester : framework de cryptojacking GPU ciblant vast.ai, exposé par sa propre misconfiguration

🔍 Contexte : Le 29 septembre 2026, CloudSEK Global Threat Intelligence publie un rapport d'analyse technique (Part 2 de la série…

🟢 vérification factuelle haute
#GPU #VHXHarvester #Cyberveille
VHX Harvester : framework de cryptojacking GPU ciblant vast.ai, exposé par sa propre misconfiguration
🔍 Contexte : Le 29 septembre 2026, CloudSEK Global Threat Intelligence publie un rapport d'analyse technique (Part 2 de la série GTI-TOPHIT) documentant une opération de cryptojacking GPU en cours contre la marketplace vast.ai. La découverte fait suite à l'investigation de 85 packages npm malveillants publiés sous le scope @prime0, tous balisant vers 69.48.229.140:8080.
cyberveille.ch
September 29, 2026 at 2:00 PM
☁️ Cloud misconfigurations can become real attack paths.

🔐 Over-permissioned IAM
🚪 Exposed admin interfaces
🔗 Unreviewed account trust
👁️ Unmonitored logs

CSPM flags the issue. A pentest shows whether it’s exploitable.

👉 7asecurity.com/blog/2026/09...

#CloudSecurity #CyberSecurity
What Cloud Misconfiguration Looks Like in a Real Audit - 7ASecurity Blog
IAM sprawl, exposed interfaces, broken isolation, blind logging: the cloud misconfiguration patterns our testers find and how each becomes exploitable.
7asecurity.com
September 29, 2026 at 12:07 PM
👀 ~300,000 unique domains with indicators of Supabase usage
Everything Everywhere: Systemic Data Exposure in Supabase Apps | UpGuard
Supabase is a favorite of AI coding agents. It's also prone to misconfiguration. We studied more than 16,000 open databases to see what's leaking.
www.upguard.com
September 28, 2026 at 7:30 PM
Cloud misconfiguration isn't just a technical debt event. It's a portability and auditability problem when you need to change providers or prove compliance. Veltiosi has over a decade of practical experience implementing, migrating, and supporting business infrastructure.

https://vtiosi.com/rJtqe
September 28, 2026 at 10:50 AM
Goal‑Driven Autonomy and Unchecked Execution: Structural Failure of Trust‑Based Privilege Escalation — https://q08.org/p/2026-09-18-a-heap-overflow-and-sso-misconfiguration-to-compromise-openai-internal-repos-qum79z
September 27, 2026 at 11:09 AM
i keep thinking about a libheif overflow ending as a pr inside OpenAI's internal monorepo. $6,500 bounty
https://www.hacktron.ai/blog/hacking-openai
Hacking OpenAI
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories
www.hacktron.ai
September 27, 2026 at 6:35 AM
"we aborted our machine god because of a DNS misconfiguration" is the most grossly foreshadowed computer thing that could ever happen
OpenAI says it’s not going to resume the training run that was paused on Sunday

https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/
September 27, 2026 at 2:13 AM
Sakurasora Notice: The account manager and login/signup page is now fixed. It was due to a misconfiguration in the host file that prevented the Tranquil server from getting the client metadata JSON.
September 26, 2026 at 12:52 PM
Interesting report on how security researchers got a bug bounty from OpenAI finding a flaw gaining access to employee accounts using the Anthropic AI as one of the tools in the hack.

www.hacktron.ai/blog/hacking...
Hacking OpenAI
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories
www.hacktron.ai
September 26, 2026 at 10:10 AM
Was the Australia health portal incident a misconfiguration error?

www.scworld.com/news/was-the...

#Cybersecurity #AIkyber
Was the Australia health portal incident a misconfiguration error?
Questions emerge over whether a reported AI hack was actually a basic government portal misconfiguration.
www.scworld.com
September 25, 2026 at 8:11 PM
Saw an opsec guy post that the exploits the bots found were just misconfiguration and not that impressive, and I would have thought opsec people of all people would know that the actual flaws that allow for a hack are almost always trivial oversights.
September 25, 2026 at 6:41 PM
About 16,000 Supabase-hosted databases exposed personal data publicly due to misconfiguration, including names, addresses, phone numbers, and some passwords.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 25, 2026 at 5:46 PM
About 16,000 Supabase-hosted databases exposed personal data publicly due to misconfiguration, including names, addresses, phone numbers, and some passwords.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 25, 2026 at 5:45 PM
About 16,000 Supabase-hosted databases exposed personal data publicly due to misconfiguration, including names, addresses, phone numbers, and some passwords.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 25, 2026 at 5:45 PM
Making security setup easier through AI coding agents is a pretty practical direction. The less room there is for misconfiguration, the better, especially for something handling bot protection and verification.
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification. https://cfl.re/4yWDSKQ
Agents can now set up your website’s security with Turnstile Spin
Turnstile Spin turns a two-part setup into a guided workflow with your coding agent.
blog.cloudflare.com
September 25, 2026 at 3:36 PM
72時間って数字がなかなか刺さる。人力のペネトレーションテストなら同規模の環境で数週間かかる作業を、権限昇格経路やmisconfigurationを当てにいく探索を並列でやれるから短縮できてる感じ。discoveryのコストが下がると「見つかってない」と「安全」が別物になる、ってことだと思う。
September 25, 2026 at 3:34 AM
GitLab auto-assigned emails expose privileged tokens, per Dark Reading. This isn’t a misconfiguration—it’s a structural flaw: CI/CD pipelines trusting GitLab-signed artifacts now inherit a key-exfiltration vector embedded in notifications. SSH agent forwarding 2.0.
September 25, 2026 at 1:13 AM
🚨 EUVD-2026-85665
📊 7.2/10

📝 A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85665

#cybersecurity #infosec #cve #euvd
September 23, 2026 at 10:01 PM