Interesting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild. The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developi

Researchers have identified a new class of weak RSA encryption keys that contain numerous zeros in their structure. These keys, found in real-world deployments, could potentially be factored more easily than standard RSA keys. The discovery was made by analyzing a large dataset of public keys collected from various sources, including Certificate Transparency logs, internet-wide scans for TLS and SSH, and PGP keys.
The identified weak keys exhibit specific patterns of regularly spaced blocks of zeros interspersed with seemingly random data. One such pattern was observed in certificates issued to major organizations like Yahoo and Verizon, as well as on some NetApp devices. While the affected certificates have already expired, the findings were shared with the organizations. Efforts to determine the product responsible for generating these keys were unsuccessful.
A second pattern of weak keys was found on SSH hosts running EnterpriseDT's CompleteFTP software. The vulnerability impacts RSA keys generated by versions 10.0.0 through 12.0.0 of the software, released between December 2016 and March 2019. Additionally, DSA keys generated by the same software, specifically versions 10.0.0 through 23.0.4 (December 2016 to December 2023), are also affected.
While these vulnerabilities affect a relatively small number of internet hosts, the research highlights a concerning trend of similar cryptographic implementation failures occurring independently. This suggests that other cryptographic implementations might harbor similar weaknesses, warranting the development of specialized cryptanalytic algorithms tailored to detect and exploit this particular type of key generation flaw.
The discovery raises questions about the origin of these weak keys. While the research itself does not speculate, the potential for deliberately designed backdoors cannot be entirely dismissed. Such backdoors could theoretically be implemented to allow specific entities to break these classes of RSA keys, potentially with the cooperation of software providers.
The badkeys project, an open-source service that checks public keys for known vulnerabilities, was instrumental in this discovery. The extensive collection of real-world keys provided a unique dataset for identifying these anomalies. The researchers emphasize the importance of continued vigilance and tailored cryptanalytic approaches to address such specific weaknesses in cryptographic implementations.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.