Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

Two security researchers, working independently, have discovered that numerous organizations are inadvertently sending sensitive corporate and personal information to "no-reply" or "deleted user" email addresses. The researchers acquired several such domains and configured them to receive all incoming mail, revealing a widespread issue of system misconfigurations leading to data leakage.
Cory Solovewicz, a security researcher and consultant, purchased the domains noreply.us in 2020 and noreply.net in 2024. He initially intended to use noreply.us as a personal catch-all inbox but soon realized that automated systems were sending emails to addresses on these domains. Since December 2024, his noreply.net domain alone has received over 400,000 messages, with 28,365 containing attachments. The noreply.us domain has received 37,255 messages since its acquisition. In the month preceding his recent presentation at the Defcon security conference, Solovewicz's domains collectively received more than 11,000 messages. These emails originated from over 14,000 "from" addresses across 6,200 root domains.
The content of these emails has included injury reports from a city government, pizza order confirmations, account setup emails from a school platform, service orders for repairs, and test platform credentials. Solovewicz described his discovery as an "accidental honeypot," emphasizing that the messages are automated and not sent by human users. He expressed relief that he, rather than malicious actors, acquired these domains, and has been attempting to notify affected organizations to rectify their system errors.
Similarly, Mike Sheward, head of security at EV charging company Xeal, purchased the domain deleteduser.com for approximately $15 earlier this year. Within an hour, he began receiving emails from three different organizations. He has since accumulated thousands of unintended emails from at least 100 different organizations across multiple domains he now owns. Sheward's received emails include details of Viagra orders, requests for approval of work vacations or leaves of absence, hotel bookings with full names, and invitations to Zoom meetings from a UK government agency. He also noted receiving an invitation to a San Francisco company's summer BBQ addressed to "Dear Deleted User." A significant source of emails for Sheward is an AI company that uses object recognition to monitor worker safety at industrial sites in the Middle East, from which he has received thousands of CCTV stills.
Both researchers speculate that companies may be sending emails to these placeholder domains under the mistaken belief that they are unmonitored, or that they are transforming individual email addresses to such domains when an employee leaves or an account is deleted. The issue is not new, with similar observations dating back nearly two decades regarding @donotreply.com addresses.
Recognizing the potential for misuse by hackers, Solovewicz and Sheward have independently acquired more than 30 such domains to mitigate the risk. Solovewicz has also developed a probe to identify other potential placeholder domains configured to receive email, scanning 7,136 domains and finding 328 with catch-all inboxes. He warns that his findings may represent only a fraction of the problem.
While some organizations have quietly fixed their configurations after being notified, many have not responded, and the sheer volume of misdirected emails makes comprehensive notification a significant challenge. The researchers stress that organizations should not assume a domain is unmonitored and must audit their systems to prevent the leakage of customer, employee, and internal data.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed