Researchers have identified a significant class of 84 previously unknown vulnerabilities, dubbed 'iTrue' flaws, affecting the core networks of 4G and 5G mobile systems. These vulnerabilities stem from implicit trust errors between network functions, exacerbated by the shift to cloud-native deployments. Exploitation could lead to denial-of-service attacks and session hijacking, where an attacker seizes control of a user's network session.

Researchers have reported the discovery of 84 previously unknown vulnerabilities affecting the core networks of 4G and 5G mobile systems. These flaws, collectively termed 'iTrue' vulnerabilities, are described as stemming from implicit trust errors between various network functions within the core infrastructure. The report indicates that these issues could potentially be exploited to facilitate denial-of-service attacks and session hijacking.
The technical mechanism behind these 'iTrue' flaws is rooted in scenarios where network functions implicitly trust each other without sufficient validation or authentication. This implicit trust, when exploited, allows an attacker to bypass security controls by masquerading as a legitimate network component or by manipulating trusted communication paths. The shift towards cloud-native deployments in 4G and 5G core networks is cited as a factor that exacerbates these vulnerabilities, likely due to the increased complexity and dynamic nature of inter-service communication in such environments.
One of the most significant potential impacts highlighted is session hijacking. In a session hijacking scenario, an attacker could seize control of a legitimate user's network session. This could grant the attacker unauthorized access to services or data associated with that session, potentially leading to privacy breaches, unauthorized transactions, or further network compromise. Denial-of-service attacks are also a reported risk, where an attacker could disrupt network availability or specific services by overwhelming or disabling critical core network functions.
While specific vendors or products were not named, these vulnerabilities affect the core networks of both 4G and 5G mobile systems. This implies that the issues are likely present in the implementations of various network equipment providers and telecommunication operators globally, given the widespread adoption of these standards. The scope could therefore be broad, impacting a significant portion of the global mobile subscriber base if exploited.
Mitigation for this class of implicit trust errors typically involves implementing robust authentication and authorization mechanisms between all network functions, even those considered internal or trusted. This includes mutual authentication, stricter input validation, and comprehensive integrity checks for all inter-component communications. Network segmentation and micro-segmentation can also limit the blast radius of an exploit, preventing an attacker from easily moving laterally across the core network. Regular security audits and penetration testing focused on inter-service communication flows are also crucial for identifying and remediating such vulnerabilities.
The discovery of these 'iTrue' vulnerabilities underscores the ongoing security challenges inherent in complex, interconnected network infrastructures, particularly as they evolve towards cloud-native architectures. As mobile networks become increasingly critical for a wide array of services, from personal communication to industrial IoT, the security of their core components remains paramount. This report highlights the continuous need for rigorous security research and proactive measures to secure the foundational elements of global telecommunications.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed