By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

A recent analysis has uncovered widespread manipulation of the BGP ORIGIN attribute by transit providers, a practice reportedly affecting a significant majority of BGP paths. The findings indicate that approximately 70% of BGP paths are subject to rewrites of their ORIGIN attribute, a modification apparently undertaken by transit providers to gain traffic advantages. This reported manipulation raises questions about the integrity of BGP route selection and its broader implications for Internet routing.
The BGP ORIGIN attribute is a well-established component of BGP path selection, intended to indicate the origin of a route within an Autonomous System (AS). It typically takes one of three values: IGP (internal to an AS), EGP (external via EGP), or INCOMPLETE (origin unknown or learned via other means). This attribute plays a role in the BGP best path selection algorithm, where a lower ORIGIN value (IGP being preferred over EGP, and EGP over INCOMPLETE) can influence a router to select a particular path. The reported rewrites suggest that transit providers are altering this attribute, presumably from a less preferred value to a more preferred one, to encourage traffic to flow through their networks.
The mechanism of this manipulation likely involves transit ASes intercepting BGP updates and modifying the ORIGIN attribute before re-advertising them to their peers or customers. For instance, a route originally marked as INCOMPLETE might be changed to IGP or EGP, making it appear more authoritative or desirable in the eyes of downstream routers applying the BGP best path selection process. This could effectively steer traffic away from paths that would otherwise be chosen based on the original, unaltered BGP attributes.
The scope of this issue appears to be substantial, with the analysis suggesting nearly 70% of BGP paths are affected. This widespread manipulation could lead to suboptimal routing decisions, as traffic might be directed through less efficient or more congested paths due to an artificially inflated ORIGIN attribute. Such practices could also complicate network troubleshooting and performance analysis, as the reported BGP attributes would not accurately reflect the true origin or characteristics of a route.
Mitigation for this class of BGP attribute manipulation is challenging, as it often occurs within the operational practices of transit providers. Network operators typically rely on the integrity of BGP attributes received from their peers. However, in cases where such manipulation is suspected, operators might employ other BGP path selection mechanisms, such as local preference, AS path length, or MED (Multi-Exit Discriminator), to exert more control over their outbound routing decisions. Filtering BGP updates based on expected ORIGIN attributes could also be considered, though this might be complex to implement at scale without inadvertently disrupting legitimate routes.
The findings underscore a broader tension in Internet routing between established protocol mechanisms and the commercial incentives of network operators. The BGP ORIGIN attribute, like other BGP attributes, relies on a degree of trust among participants in the global routing system. When this trust is undermined by deliberate manipulation for traffic advantage, it can degrade the overall efficiency and predictability of the Internet. The analysis reportedly advocates for the deprecation of the ORIGIN attribute in route selection, suggesting a re-evaluation of its role in an environment where its integrity cannot be consistently assured.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.