View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Researchers expose transcript consistency flaws in major E2EE group

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Researchers expose transcript consistency flaws in major E2EE group chats
    Major end-to-end encrypted group chat apps lack transcript consistency, enabling selective message manipulation.

    • Applies to major E2EE messaging apps with group chats, including Signal, iMessage, WhatsApp, and Threema
    • Vulnerability allows malicious group members to omit, reorder, or alter messages selectively per recipient
    • Exploitation enables social engineering, moderation evasion, and rigging of group polls
    • Attack leverages protocol fallback paths and pairwise delivery channels within groups
      ๐Ÿ“Ž Coverage: arxiv.org ยท ๐Ÿ“„ Original: arxiv.org ยท ๐Ÿ‘ via arXiv cs.CR
  • New HMM-Based Method Analyzes Multi-Phase Cyber Attacks on IEC 61850 Digital Substations
    Researchers developed a model to infer phases of cyber attacks on digital substations using IDS data.

    • Applies to digital substations compliant with IEC 61850 in modern power systems
    • Targets manipulation of circuit breaker operations via IEC 61850 communication
    • Attacks use multi-phase strategies that existing IDS detect only as isolated symptoms
    • Proposed SubCASP method uses Hidden Markov Model to fuse IDS logs for attack phase inference
    • Model trained on attack-graph datasets and tested under varying IDS observability and missing data
      ๐Ÿ“Ž Coverage: arxiv.org ยท ๐Ÿ“„ Original: arxiv.org ยท ๐Ÿ‘ via arXiv cs.CR
  • GradLock attack injects private data into AI models via compromised open-source components
    Researchers reveal GradLock, a training-time attack that embeds private data into AI model parameters.

    • Applies to AI models trained using compromised open-source components in the supply chain
    • GradLock injects sensitive training data directly into model parameters during training
    • Uses stateless deterministic indexing and dynamic gradient locking to preserve injected data
    • Enables near-lossless extraction of private data from final models without training environment access
    • Robust against quantization, pruning, and fine-tuning; evades detection by 93.3% of users
      ๐Ÿ“Ž Coverage: arxiv.org ยท ๐Ÿ“„ Original: arxiv.org ยท ๐Ÿ‘ via arXiv cs.CR
  • clean-label-dormant-to-activated-backdoor-machine-unlearning
    ๐Ÿ“Ž Original: arxiv.org

๐Ÿ”“ CVEs & KEV

  • CVE-2026-18157 โ€” CVSS 7.8 โ€” Yggdrasil-worker-package-manager: remote code execution vulnerability
  • CVE-2026-6890 โ€” Use of default credentials vulnerability
  • CVE-2026-6889 โ€” Denial of service vulnerability in Advan...
  • CVE-2026-14541 โ€” Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider
  • CVE-2026-14540 โ€” Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox
  • CVE-2026-14539 โ€” Denial of Service via Unrestricted Payload Buffering in MCP Toolbox
  • CVE-2026-14538 โ€” BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox
  • CVE-2026-14537 โ€” Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check