< ciso
brief />
Tag Banner

All news with #weak cryptography tag

23 articles

AI Drives Breakthroughs Against Historic Ciphers

🔍 This post argues that AI language models and their DSP-like architectures are now good enough to break many older codes and ciphers by exploiting persistent statistical features. It explains how adaptive filters in current DNNs can lift plaintext signals from noisy ciphertext when keytexts are periodic or short, a common human failing in historical systems. The author warns that only ciphers without key periodicity or those requiring infeasible workloads can still offer meaningful security.
read more →

France tax portal breach exposed weak access controls

🛡️ A data theft at France's tax administration (DGFIP) in June–July exposed contact and tax-related messages for roughly 350,000 individuals and 250,000 businesses after attackers used stolen staff passwords. ANSSI's report finds the incident relied on weak login protection, poor network segregation and gaps in monitoring, with the attacker scraping E-Contact and other portals via compromised accounts and partner systems. Remediations include stronger MFA, extended SIEM coverage, session revocation on password resets and blocking personal-device access to government systems.
read more →

Understanding the Risks of Vibe‑Coded Mobile Apps

🔒 Vibe coding lets developers generate apps quickly using AI, but this speed can introduce security and privacy oversights. Common issues include hardcoded secrets, missing input validation, weak encryption, and public-by-default settings that expose user data. Users should vet apps by checking the developer's reputation, permissions requested, privacy policy, security model, and any AI access. If an app is breached, change passwords, enable MFA, revoke connected permissions, and consider uninstalling or factory-resetting compromised devices.
read more →

COLDCARD RNG Flaw Tied to Major Bitcoin Theft

🔒 Researchers attribute an exploit in COLDCARD hardware wallet firmware to the theft of roughly $88.6 million in Bitcoin from thousands of wallets generated with a flawed random number generator. Galaxy Research traced initial drains of about 1,083 BTC on July 30 and later identified further waves raising the total to 1,367 BTC taken from 4,585 addresses. Block and other analysts found an integration error that caused a deterministic MicroPython fallback RNG to be used instead of the STM32 hardware RNG, enabling offline seed reconstruction and address matching.
read more →

Researchers Find RSA Keys Containing Large Zero Blocks

🔍 New research identifies a class of weak RSA keys characterized by extensive zeroed blocks in the modulus. The open-source badkeys project collected large-scale key material from CT logs, TLS/SSH scans, and PGP repositories and found multiple real-world keys exhibiting two distinct sparse patterns. Pattern 1 appeared in certificates (now expired) from major organizations and devices, while Pattern 2 appeared in SSH hosts using CompleteFTP; affected versions and time ranges are noted. The findings highlight independent cryptographic implementations failing in similar ways and raise concerns about deliberate backdoors or coordinated vulnerabilities.
read more →

Schneider Electric Products: Insufficient Entropy Fixes

🔒 Schneider Electric has identified a CWE-331 Insufficient Entropy vulnerability affecting multiple Easergy, EcoStruxure, PowerLogic, and Saitel products that could enable unauthorized access or session compromise. Vendor-supplied fixes and firmware updates are available for numerous models and versions; several updates require a reboot. For models without immediate fixes, Schneider recommends network segmentation and reduced session timeouts as mitigations, and provides general cybersecurity best practices.
read more →

Hitachi Energy GMS600 OpenSSL timing flaw

🔒 Hitachi Energy reported that GMS600 versions are affected by CVE-2022-4304, a timing-based side-channel in OpenSSL RSA decryption that can allow recovery of pre-master secrets after many trial messages. The flaw impacts all RSA padding modes and can enable decryption of TLS application data. Vendor mitigation is to upgrade to version 1.3.2; CISA reiterates network isolation and defensive best practices.
read more →

Nearly Half of World’s Passwords Cracked in Minutes

🔒 Kaspersky analyzed 231 million unique passwords leaked on dark‑web forums (2023–2026) and found that 60% can be cracked in under an hour, with 48% broken in less than a minute. The testing used a single RTX 5090 GPU against MD5 hashes, illustrating how rapidly cracking speeds are improving. The report identifies common human patterns—digits, years, predictable words and popular special characters—and warns that many users reuse unchanged passwords for years. It recommends practical defenses such as a password manager, passkeys, and strong two‑factor authentication.
read more →

Fixing the password problem: why '123456' still works

🔐 The most-used password globally remains '123456', according to NordPass, and the author found that some mainstream services still accept trivial credentials in direct tests. Examples include Evite (breached in 2019) and parts of major social platforms that permit easily guessable strings like '1234567!'. The article highlights inconsistent password policies across sites and argues for stronger authentication requirements—preferably mandated MFA—with regulatory backing where necessary.
read more →

Critical Weak Password Issue in Horner Automation PLCs

🔒 Horner Automation products contain a weak-password vulnerability (CVE-2026-6284) that allows network attackers to brute-force credentials and gain unauthorized access to PLC systems and services. Affected versions include Cscape v10.0, XL7 v15.60, and XL4 v16.32.0. The vulnerability is scored CVSS 3.1 9.1 (Critical) and is associated with CWE-521: Weak Password Requirements. Horner has released fixes—update to Cscape v10.2 SP2 and the latest XL4/XL7 firmware—and operators should minimize network exposure and use secure remote access.
read more →

Amazon CloudFront Adds SHA-256 Support for Signed URLs

🔐 Amazon CloudFront now supports SHA-256 as a hash algorithm for creating signed URLs and signed cookies, improving collision resistance and aligning with modern cryptographic standards. To use SHA-256, include the Hash-Algorithm=SHA256 query parameter for signed URLs or the CloudFront-Hash-Algorithm=SHA256 cookie attribute for signed cookies. Existing signed artifacts that omit a hash algorithm continue to use SHA-1, preserving backwards compatibility. This capability is available in all CloudFront edge locations at no additional cost.
read more →

ConnectWise fixes ScreenConnect signature flaw, critical

🔒 ConnectWise warned customers about a critical cryptographic signature verification bug in ScreenConnect (tracked as CVE-2026-3564) that affects versions prior to 26.1 and can enable unauthorized session authentication and privilege escalation. The vulnerability allows attackers who obtain ASP.NET machine key material to generate or modify protected values the server will accept, potentially resulting in hijacked sessions and elevated access. ConnectWise patched the issue in ScreenConnect 26.1 by adding encrypted storage and improved handling for machine keys; cloud-hosted instances were auto-upgraded while on-premises administrators must upgrade immediately. The vendor reported observed attempts to abuse disclosed machine key material in the wild but has no confirmed evidence of exploitation against ConnectWise-hosted instances and urges responsible disclosure of active findings.
read more →

BSI Criticizes Healthcare Software Security Practices

🔒 The Federal Office for Information Security (BSI) has warned that software used in medical practices, clinics and long-term care needs stronger protections to safeguard sensitive patient data. In tests of standard configurations, the agency described the IT security of healthcare software as in need of improvement, finding chains of vulnerabilities in three of four representative practice management systems that could be exploited from the Internet. Outdated encryption algorithms were specifically cited; manufacturers were informed and issued timely fixes.
read more →

Russian Actor Uses AI to Exploit Weak Fortinet Firewalls

🤖 Amazon Threat Intelligence says a Russian-speaking actor used commercial generative AI services to compromise hundreds of FortiGate firewalls by exploiting exposed management interfaces and weak, single-factor credentials. Between Jan. 11 and Feb. 18 the group breached over 600 devices across 55+ countries, then accessed Active Directory, extracted credential databases, and targeted backups. Amazon recommends fundamental controls — restrict management access, enforce MFA, patch perimeter devices, improve segmentation, and enhance detection — noting the attacker’s toolkit and operational plans were largely AI-generated and publicly left on infrastructure used in the campaign.
read more →

Yokogawa FAST/TOOLS Multiple Web and Crypto Flaws Reported

⚠️ Yokogawa's FAST/TOOLS (versions R9.01–R10.04) contains multiple web and cryptographic vulnerabilities tracked across 14 CVEs that could enable redirection to malicious sites, decryption of communications, man-in-the-middle attacks, cross-site request forgery, script execution, and unauthorized file access. Example CVSS v3 scores reach up to 8.2 for some issues. Yokogawa advises updating to R10.04, applying patch CS_e12787, then installing R10.04 SP3. CISA recommends minimizing Internet exposure for control systems, isolating OT networks behind firewalls, and using secure remote access.
read more →

LastPass 2022 Breach Enabled Years-Long Crypto Drains

🔐 TRM Labs says encrypted vault backups stolen in the 2022 LastPass breach have been incrementally cracked by attackers exploiting weak master passwords, resulting in cryptocurrency drains as recently as late 2025. The firm traces over $35 million in siphoned assets, much of it laundered through CoinJoin and Russian-linked exchanges. TRM highlights how demixing and operational analysis linked activity to Russia-associated infrastructure and warns users who did not rotate credentials remain at risk.
read more →

Tor adopts Counter Galois Onion (CGO) for relay encryption

🔐 Tor has replaced its legacy tor1 relay encryption with a new design called Counter Galois Onion (CGO) to strengthen circuit traffic confidentiality and integrity. CGO is built on a Rugged Pseudorandom Permutation (RPRP) construction named UIV+ and provides wide-block encryption, tag chaining, per-cell key updates for immediate forward secrecy, and a 16-byte authenticator that removes SHA-1. The change is currently experimental in the C Tor implementation and the Rust client Arti, will be deployed transparently to Tor Browser users, and aims to block tagging and other malleability attacks with only modest bandwidth cost.
read more →

Schneider Electric: Risky Cryptography in EcoStruxure

🔒 This advisory describes a cryptographic weakness in Schneider Electric's EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio that could allow credential recovery from project files. An attacker with read access to Edge project or offline cache files can brute-force weak hashes to recover app-native or Active Directory passwords (CVE-2025-9317); the flaw requires local/file access and is not remotely exploitable. Apply 2023.1 Patch 1 immediately or implement recommended mitigations such as strict ACLs, strong project master passwords, removing embedded passwords, and following ICS cybersecurity best practices.
read more →

AVEVA Edge cryptographic weakness enables password recovery

🔒 AVEVA has released advisory ICSA-25-317-03 addressing a cryptographic weakness in AVEVA Edge (formerly InduSoft Web Studio) that could allow a local actor with read access to project or offline cache files to brute-force user or Active Directory passwords. The issue is tracked as CVE-2025-9317 and carries a CVSS v4 base score of 8.3. AVEVA provides a 2023 R2 P01 Security Update and recommends project migration, password resets, and tightened file access controls. This vulnerability is not remotely exploitable according to CISA.
read more →

Siemens RUGGEDCOM TLS and Access Control Vulnerabilities

🔒 Siemens published an advisory (republished by CISA) for multiple vulnerabilities affecting RUGGEDCOM ROS devices, including CVE-2023-52236 and several CVE-2025-4122x issues. The flaws involve risky cryptographic algorithms, improper TLS handshake handling that can cause DoS, and an access-control enforcement failure that persists until reboot. Siemens has released updates (V5.10.0+) for many models and recommends restricting management ports, disabling web/SSH services if unused, and configuring GCM ciphers where applicable. CISA reiterates standard ICS guidance to minimize network exposure and isolate control networks.
read more →