
Daily Cybersecurity News – October 10, 2026
CyberRecaps is supported by its readers. We may earn an affiliate commission at no extra cost to you if you buy through a link on this page.

Public root exploit released for AnyDesk Linux RCE
HighWhat happened
Security researchers released a full working public exploit called AnyPwn for a pre-authentication remote code execution flaw in AnyDesk Linux that grants root access before any connection approval.
The flaw is a heap buffer overflow in the session protocol's mode-5 stream packet handler. It stems from 32-bit arithmetic without overflow checks when sizing a buffer (adding a 16-byte header to a declared payload length). Attackers can force a wraparound allocation of a tiny buffer while the object records a huge length, enabling overflow into adjacent heap objects and a ROP chain for arbitrary root command execution. The exploit works over direct TCP on port 7070 and is probabilistic depending on heap layout; offsets target the 8.0.2 build. Researchers validated the path is also reachable via relays with instrumentation but did not fully demonstrate the chain there. AnyDesk patched it in 8.0.3 in June (described only as a crash bug fix), with no CVE assigned and no formal security advisory. The code dropped on GitHub on October 8.
Who is affected
AnyDesk Linux users running versions before 8.0.3, specifically confirmed on 8.0.2. Earlier builds such as 8.0.1 may share the path but exploitation is unconfirmed. Windows and macOS are not affected.
Exposure is limited to direct connections (not relays, per vendor) on TCP 7070. Scale is the population of Linux remote-desktop users who left the service reachable and unpatched since the June fix.
Why it matters
A public pre-auth root RCE on a widely used remote access tool turns any exposed Linux AnyDesk instance into an immediate high-value target for ransomware operators, initial access brokers, or lateral movement. The quiet patching (no CVE, no advisory, crash-only changelog language) left many administrators unaware they needed to act.
Even though the published exploit is build-specific and probabilistic, the release removes the research barrier. Operators who assume remote desktop tools are safe once authenticated now face unauthenticated root compromise.
How it could have been prevented
Update AnyDesk Linux immediately to 8.0.3 or later (current latest is 8.1.0). Remove or block inbound access to TCP port 7070 at the firewall or host level if an immediate upgrade is impossible. Prefer relay-only configurations where feasible and monitor for unexpected AnyDesk process behavior or crashes that could indicate failed exploitation attempts. Verify the binary version in use; older builds may still be present even if the download page no longer lists them.
Relevant professional terms
- Pre-authentication RCE
- A remote code execution flaw that an attacker can trigger without any valid login or user approval, giving full control of the target before anyone notices.
- Heap buffer overflow
- A memory corruption bug where data written past the end of a dynamically allocated heap buffer overwrites neighboring objects, often enabling control of program flow via techniques such as ROP chains.
Pwn2Own teams remotely hack patched Pixel 10
HighWhat happened
Three research teams demonstrated remote exploits against fully patched Google Pixel 10 devices on October 8 at Pwn2Own Ireland in Cork. Contest rules require targets to be fully patched and pay for working exploits that are then passed to vendors.
Ikotas Labs took the top prize of $300,000 and overall win by chaining multiple issues (labeled a collision). Xint earned $150,000 for a single-bug collision. A third team (Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara) received $112,500 for a two-bug chain mixing one collision and one zero-day. Combined payouts for the Pixel entries reached $562,500. All three were registered as remote (browser content or radio interfaces: NFC, Wi-Fi, Bluetooth or baseband). Technical details of the bugs and exact attack paths remain unpublished by Trend Micro's Zero Day Initiative (ZDI). At least some entries used already-known bugs (collisions) that still qualified at adjusted prizes. ZDI will hand the material to Google; vendors then have 90 days before full public disclosure.
Who is affected
Owners and enterprises running Google Pixel 10 devices on the fully patched baseline present at the contest (October 2026). Google's October Pixel security bulletin (published October 6) does not address these issues.
Broader Android users may eventually be affected if the underlying components are shared, but only the demonstrated Pixel 10 remote paths are confirmed so far. Samsung Galaxy S26 saw even higher success rates in the same event.
Why it matters
Successful remote compromise of a fully patched flagship phone at a major contest shows that even current Android hardening and monthly updates leave exploitable surface in browser or radio stacks. Builders and mobile fleet operators must treat 'fully patched' as a temporary state rather than permanent safety.
The 90-day vendor window means patches should appear, but until then the bugs exist in the wild in the hands of the researchers and ZDI. High contest prizes also incentivize continued discovery of mobile zero-days.
How it could have been prevented
Monitor Google's Pixel and Android security bulletins for forthcoming patches related to the Pwn2Own submissions and apply them promptly once released. Keep devices on the latest monthly security update level in the meantime. Restrict high-risk radio interfaces and untrusted web content where enterprise policy allows, and treat browser and baseband attack surface as high priority for mobile threat defense tooling.
Relevant professional terms
- Pwn2Own
- A live hacking contest where researchers earn cash prizes by demonstrating working exploits against fully patched, up-to-date consumer devices and software under strict rules.
- Bug collision
- In contest scoring, an entry that reuses a vulnerability already known to the vendor or organizer, typically resulting in a reduced prize while still demonstrating impact.
Credential stealing workflows hit 34k GitHub repos
CriticalWhat happened
An ongoing credential-theft campaign attributed to GhostAction has compromised high-profile open-source maintainer accounts and planted malicious GitHub Actions workflows into tens of thousands of repositories.
Attackers used the accounts of Takashi Kitao (pyxel game engine) to hit 27 repos and Henry Wu (henrywoo, athenadriver) to hit 318 repos in short windows. Socket later identified more than 500 GitHub accounts that committed the same malicious workflow since October 7, affecting tens of thousands of repositories overall. Earlier phases impacted hundreds of repos and exfiltrated thousands of secrets. The planted workflows (named like security-audit.yml or github_actions_security.yml) trigger on workflow_dispatch and any push, check out full history, scan for named secrets plus 13 credential patterns (AWS, AI APIs, GitHub/GitLab tokens, SaaS keys, etc.), pair AWS keys, and exfiltrate everything over plain HTTP to a hard-coded IP. Initial access most likely came from leaked personal access tokens in infostealer logs.
Who is affected
Any GitHub repository whose maintainer account was compromised or that received a malicious workflow push, spanning open-source projects and organizations. Documented waves hit hundreds to tens of thousands of repos and thousands of secrets (PyPI, npm, DockerHub, AWS, OpenAI/Anthropic keys, GitHub tokens, SSH keys, and more).
Developers and CI/CD pipelines that store long-lived secrets in Actions or commit history are directly exposed. Downstream users of affected packages risk supply-chain follow-on compromise.
Why it matters
This is a large-scale software supply-chain attack that turns trusted maintainer identities into distribution vehicles for secret-stealing automation. Stolen cloud, package-registry, and AI API keys enable further lateral movement, package poisoning, and data theft at scale.
The speed (hundreds of repos in minutes) and reuse of legitimate-looking 'security audit' workflow names make detection harder. Organizations relying on open-source dependencies or public GitHub Actions inherit the blast radius even if their own accounts were never directly compromised.
How it could have been prevented
Rotate all GitHub personal access tokens, Actions secrets, cloud keys, and package-registry credentials immediately if any linked account or repo may have been touched. Audit workflow files (especially recently added security-audit or similar YAML) for unexpected curl/exfil steps or broad secret scanning. Enforce short-lived credentials, OIDC federation instead of long-lived secrets where possible, branch protection, and required reviews for workflow changes. Scan git history for accidentally committed secrets and enable secret scanning alerts. Monitor for outbound connections to known campaign infrastructure and review Actions run logs for anomalous full-history checkouts.
Relevant professional terms
- GitHub Actions workflow
- An automated script stored in a repository that runs on events such as pushes or manual triggers, often used for building, testing, or deploying code and therefore frequently holding sensitive secrets.
- Supply-chain attack
- An attack that compromises a trusted upstream component (here, maintainer accounts and CI workflows) so that malicious code or credential theft reaches many downstream users who never directly interacted with the attacker.
Flax Typhoon hits five KEV flaws
CriticalNewly added KEV flaws
| CVE | Product | CVSS | Impact |
|---|---|---|---|
| CVE-2015-3306 | ProFTPD | 10.0 | Arbitrary file read/write |
| CVE-2021-3199 | ONLYOFFICE Docs | 9.8 | Path traversal to RCE |
| CVE-2023-22894 | Strapi | 4.9 | Sensitive info via filter |
| CVE-2016-3081 | Apache Struts | 8.1 | Command injection RCE |
| CVE-2015-5477 | ISC BIND | 7.5 | DoS via TKEY |
What happened
CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog on the basis of active abuse by the China-linked threat actor Flax Typhoon. A joint advisory from Australia, Canada, Japan, New Zealand, Spain, the UK and the US also warned of operations by China-based Integrity Technology Group that leverage these and three already-listed KEV flaws for initial access and data theft.
The five newly listed flaws are CVE-2015-3306 (ProFTPD improper access control, CVSS 10.0), CVE-2021-3199 (ONLYOFFICE Docs path traversal to RCE, CVSS 9.8), CVE-2023-22894 (Strapi cleartext sensitive info via query filter, CVSS 4.9), CVE-2016-3081 (Apache Struts command injection, CVSS 8.1), and CVE-2015-5477 (ISC BIND reachable assertion DoS, CVSS 7.5). All five are confirmed actively exploited and were added to KEV on 2026-10-08. Attack patterns include scanning, XSS, password spraying against Microsoft Exchange, persistence via VPN software, and scripted email/credential exfiltration. Federal civilian agencies face an October 11, 2026 remediation deadline.
Who is affected
Organizations still running unpatched ProFTPD (mod_copy), ONLYOFFICE Docs before 5.6.3 (with JWT), Strapi through 4.5.5, Apache Struts 2.3.x in the vulnerable ranges with Dynamic Method Invocation enabled, or ISC BIND 9.x before the listed patches. Critical infrastructure and OT-adjacent networks are highlighted as positioning targets.
Any internet-facing instance of these older components is at elevated risk given confirmed exploitation and high EPSS scores on several of the CVEs.
Why it matters
Flax Typhoon and associated actors are using decades-old and multi-year-old vulnerabilities for reliable initial access into networks, including those tied to critical infrastructure, with the explicit goal of long-term positioning for future disruption. Adding the flaws to KEV creates a hard compliance deadline for US federal agencies and a strong signal for everyone else.
The combination of high-severity RCE/file-access bugs with living-off-the-land persistence and data theft means a single unpatched service can lead to broad credential and email compromise. Operators who deferred upgrades on 'legacy but internal' services now face nation-state-level attention.
How it could have been prevented
Patch or mitigate all five CVEs immediately: upgrade ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts (disable Dynamic Method Invocation or move to supported versions), and ISC BIND to fixed releases. Federal agencies must complete remediation or discontinue use by October 11, 2026. Inventory internet-facing and internal instances of these products, block unnecessary exposure, monitor for scanning and password-spraying against Exchange, and hunt for VPN-based persistence and unusual email exfiltration scripts. Apply the same urgency to the three previously listed related KEV items (Shellshock, Ivanti Pulse, GitLab RCE).
Relevant professional terms
- CISA KEV catalog
- A living list of vulnerabilities that CISA has confirmed are being actively exploited in the wild; US federal agencies must fix them by set deadlines.
- Initial access
- The first foothold an attacker gains inside a target network, often by exploiting a public-facing vulnerability, after which they can escalate, move laterally, and establish persistence.
Japan arrests Qilin ransomware operative
MediumWhat it means
International law-enforcement cooperation can reach ransomware operators when they travel. Organizations should continue core defenses (immutable backups, least privilege, rapid patching, network segmentation, and offline recovery testing) because single arrests rarely dismantle an entire RaaS operation overnight. Track Qilin leak sites and victim reports for signs of reduced or shifting activity.
What happened
Japan's National Police Agency confirmed the arrest and extradition to Germany of a 28-year-old Russian national accused of involvement with the Qilin ransomware gang. Japanese authorities acted on a German arrest warrant tied to a ransomware attack on a German company.
The suspect was detained at a hotel in Osaka in May after officials learned of planned travel to Japan, then extradited in June. The individual's name was not released. Qilin has claimed numerous high-profile attacks, including against German political party Die Linke, Japanese beverage giant Asahi (which suffered prolonged operational disruption and data leaks), a British healthcare provider, the government of Palau, US newspaper chains, Kuala Lumpur International Airport, the city of Sugar Land, French rugby club Stade Français, and the US Bureau of Alcohol, Tobacco, Firearms and Explosives.
Who is affected
Primarily the German victim organization whose attack triggered the warrant, plus the broader set of Qilin victims across Germany, Japan, the UK, US, and elsewhere. Law-enforcement and judicial cooperation channels between Japan and Germany are directly involved.
Ransomware victims and potential future targets of Qilin face a modest deterrent signal from the arrest.
Why it matters
Cross-border arrest and extradition of a ransomware affiliate demonstrates that travel to certain jurisdictions carries real risk even for operators based in countries that rarely cooperate. Qilin has remained one of the most active ransomware groups into 2026, so any disruption of its human infrastructure is operationally relevant.
The case also underscores continued international pressure on ransomware ecosystems after earlier scrutiny following healthcare and critical-service attacks.
Relevant professional terms
- Ransomware gang
- A criminal group that deploys malware to encrypt an organization's data and systems, then demands payment for decryption keys, often also stealing and threatening to leak data.
- Extradition
- The formal legal process by which one country surrenders a suspected or convicted person to another country so that the person can face prosecution or serve a sentence there.
Anthropic releases free AI OSS vulnerability scanner
LowHow it works
- Core maintainers apply through the OSS Scanner GitHub repository.
- Accepted projects receive an initial AI-powered scan and email bundle of reports.
- Later scans look for new or previously missed issues; frequency depends on demand and project importance.
- Maintainers can supply guidance on test inputs, severity rating, and useful patch styles.
- Projects may pause or opt out of automated reports at any time.
What happened
Anthropic launched OSS Scanner, a free service that uses its strongest AI models to scan opted-in open-source projects for security vulnerabilities. Maintainers receive periodic reports describing suspected flaws, reproduction steps, and fixes when available.
The service builds on Project Glasswing experience. Because human validation had become a bottleneck, findings are sent directly to project teams without prior human review; maintainers remain responsible for verification and prioritization. Early testing of 97 high/critical findings across 48 projects showed 85 meeting coordinated-disclosure criteria, 11 genuine but duplicate, and one invalid. Anthropic notes reports can still overstate severity or misread project security assumptions. Core maintainers apply via the OSS Scanner GitHub repository; eligibility favors established infrastructure-relevant projects. Unvalidated findings carry no mandatory 90-day clock; validated ones may enter the normal coordinated process.
Who is affected
Open-source maintainers and projects that apply and are accepted, especially widely used infrastructure components. Downstream consumers of those projects benefit indirectly from earlier vulnerability discovery.
Teams that already handle verified high/critical reports and have capacity for additional investigation are the intended audience.
Why it matters
AI-assisted vulnerability discovery at scale can surface issues faster than traditional manual research alone, potentially shrinking the window in which flaws remain unknown to defenders. Sending raw model output directly to maintainers removes a human queue but shifts validation burden onto often under-resourced project teams.
For the broader ecosystem, higher-quality automated reports with reproduction steps and suggested patches improve the signal-to-noise ratio compared with early AI efforts, provided maintainers treat findings as starting points rather than authoritative verdicts.
Relevant professional terms
- Open-source software (OSS)
- Software whose source code is publicly available for anyone to inspect, modify, and distribute, forming the foundation of much of the modern internet and enterprise stack.
- Coordinated vulnerability disclosure
- A process in which researchers privately report flaws to maintainers, allow time for a fix, and only then publish details, balancing public safety with responsible fix timelines.
Belarusian Cyber Partisans breach Russian health network
HighWhat happened
The Belarusian Cyber Partisans publicly claimed responsibility for a 2023 intrusion into the Moscow Department of Health network, confirming involvement in a long-running breach recently detailed by Russian firm Solar (Rostelecom subsidiary).
The group stated it obtained administrator-level access to the department's infrastructure and connected systems, spent months inside, then abandoned the access because the target was not a priority. Solar discovered the breach in December 2025 and traced activity to early 2024, implying possible multi-year presence; the Partisans assert they entered a year earlier and did not maintain persistence after objectives were met. Sensitive medical information was accessed but data was not destroyed and operations were not disrupted. The group indicated medical data can help assess Russian military casualties in Ukraine and claimed ongoing access to hundreds of IT systems across Russia and Belarus (unverified). Russia previously designated the group an extremist organization.
Who is affected
Moscow Department of Health and connected healthcare institutions whose networks were linked. Patients whose medical records resided in the accessed systems, plus any other government agencies reachable from the compromised infrastructure.
Russian healthcare and related public-sector IT environments more broadly are implied targets given the group's stated continued access claims.
Why it matters
A multi-month (or longer) administrator-level presence inside a major city health department demonstrates weak segmentation and detection in sensitive public infrastructure. Even without destructive impact, exfiltrated medical data has intelligence and privacy consequences, including potential use in tracking casualties.
Hacktivist groups with political motives continue to treat healthcare and government networks as legitimate targets, raising the baseline risk for any organization in the geopolitical crossfire. The confirmation also validates private-sector incident response findings against activist claims.
How it could have been prevented
Segment healthcare and government networks so that compromise of one department does not yield admin access to connected agencies. Enforce strong privileged-access management, multi-factor authentication, and continuous monitoring for anomalous admin activity and long-dwell beacons. Conduct regular threat hunting for persistence mechanisms and review third-party and inter-agency trust relationships. Maintain offline, tested backups and incident-response playbooks that assume sophisticated, patient intruders rather than only ransomware smash-and-grab events.
Relevant professional terms
- Hacktivist
- An individual or group that uses hacking techniques to advance a political, social, or ideological agenda rather than purely for financial gain.
- Dwell time
- The length of time an attacker remains undetected inside a compromised network after initial access, often measured in weeks or months for sophisticated actors.