"We pulled out a pair of scissors," Jeff Simon recalled — a simple, physical gesture that stopped an intrusion where months of digital hunting had failed.
T-Mobile, Salt Typhoon and the router in Chicago
In an episode that reads like an analogue punctuation mark on a high-tech chase, T-Mobile staff spent months tracing unusual activity tied to a late‑2024 Salt Typhoon campaign before isolating traffic to a Chicago router owned by another telecom. According to Bloomberg reporting cited in the bulletin, Jeff Simon and three colleagues drove to the data center that housed the compromised device and cut the cable, a decisive move that stopped suspected espionage activity aimed at siphoning customer data.
Signed driver abuse: repurposing Defender's BTR.sys
Check Point researchers reverse engineered Microsoft Defender’s boot‑time remediation driver, BTR.sys, and demonstrated that the signed component can be repurposed as "a universal kernel operation engine" to bypass endpoint protections. Researcher Jiří Vinopal warned that because BTR.sys is a legitimate Microsoft‑signed component, "signature‑based blocking is ineffective," and that a weaponization tool could intentionally "mimic the operational footprint of the legitimate Windows Defender remediation process." The attack leverages a "golden window" between system start and user‑mode initialization, avoiding the need for the more familiar bring‑your‑own vulnerable driver (BYOVD) route.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCritical software flaws: Gogs RCE and n8n workflow chains
A string of high‑severity flaws landed this week. Gogs suffers a maximum‑severity remote code execution (CVE‑2026‑52813, CVSS 10.0) where organization names containing path traversal sequences (../) permit repositories to be written outside expected locations, enabling overwriting of other repositories' hooks and achieving RCE. The set of fixes appeared in Gogs 0.14.3; Aikido Security is credited with discovery and reporting.
Similarly, an authenticated workflow‑creation privilege in the n8n automation platform could be chained from a prototype pollution vulnerability in the XML and GSuiteAdmin nodes to remote code execution on the n8n instance (CVE‑2026‑33696, CVSS 9.4). The n8n researcher Simon Koeck noted that the prototype pollution itself can crash an instance but can also be escalated to full code execution, with the attacker’s commands running as the n8n process user. Remediations were published in n8n versions 2.14.1, 2.13.3, and 1.123.27.
Mabna Institute indictment and a $10 million State Department reward
The U.S. Department of Justice charged 17 members of the Iran‑based Mabna Institute for a campaign dating back to roughly 2013. The DoJ alleges intrusions into 144 U.S. universities, 178 foreign universities, at least 42 U.S. private companies, 11 foreign private companies, at least five U.S. federal and state agencies, and at least two NGOs. The defendants are accused of stealing more than 31 TB of academic data and intellectual property, targeting more than 100,000 professor accounts worldwide and successfully compromising approximately 8,000.
The DoJ says Mabna carried out the intrusions on behalf of Iran's Islamic Revolutionary Guard Corps and sold stolen material via two websites, Megapaper.ir and Gigapaper.ir. Founders are named as Gholamreza Rafatnejad and Ehsan Mohammadi. The U.S. Department of State is offering a $10 million reward for information about five defendants or associated individuals or entities. Check Point’s Shmuel Gihon characterized Mabna as "the privatization of state espionage," highlighting a trend of commercially run crews performing state‑level work and treating universities as high‑value, low‑friction targets.
What this means for universities, security teams, and open‑source maintainers
- Universities and research institutions: the Mabna indictment underscores how academic data and IP remain primary targets; the DoJ’s findings — 31 TB stolen, roughly 8,000 compromised accounts — put academic credentials and shared research directly in scope.
- Security operations and procurement teams: the BTR.sys research and BYOVD activity described in ClickFix/ErrTraffic campaigns show signed components and legitimate applications can be weaponized; defenders should assume trust can be abused during boot sequences and in supply chains that include vulnerable drivers and widely used utilities.
- Open‑source maintainers and vendors: the Gogs and n8n incidents reinforce the need for rapid patching and clear upgrade guidance — critical fixes appeared in Gogs 0.14.3 and in specific n8n release branches — because prototype pollution and path traversal can be chained to full RCE.
Small, trusted building blocks continue to do the heavy lifting for attackers: signed remediation drivers used as kernel engines, prototype pollution chained into RCE, and even the number of spaces in a desktop.ini file used as covert configuration. The pattern is plain in the week’s reports — attackers are exploiting trust and convenience rather than exotic new primitives. The practical implication is also direct: tighten what you trust at boot and in workflows, watch signed components and driver use closely, and treat academic credentials and shared research as assets that require sustained, prioritized protection.




