AntiMalware•September 28, 2026•🇷🇺Translated from Russian

Quantum Randomness Failures Allow AI to Extract Predictable Patterns from QRNG Devices

Quantum physics can produce genuine randomness, yet practical implementations of Quantum Random Number Generators frequently introduce predictable patterns that undermine cryptographic security. Engineers at the European Telecommunications Standards Institute warn that devices passing statistical randomness tests may still leak enough information for attackers to forecast future values.

The newly released ETSI TR 104 171 provides detailed guidance on building and assessing QRNG systems. These devices measure quantum processes, process the raw data, and supply random numbers to cryptographic applications for key generation and other security functions.

Security depends on more than the quantum source alone. Components such as sensors, power supplies, signal processors, and data-processing algorithms can add noise that contains detectable regularities. Artificial intelligence tools can now sift through large volumes of output to identify these hidden correlations.

Additional clues may come from side-channel emissions. Variations in power consumption and electromagnetic radiation can be correlated with the numbers being generated, potentially weakening the cryptography they support.

The report advocates an entropy zero trust approach. Manufacturers and operators should verify the quantum source, monitor all processing stages, search continuously for anomalies, protect hardware against tampering, and encrypt the channels that deliver random values to applications.

For forensic investigations, systems must record the exact time of generation, the software version in use, and the origin of each output value. In shared environments, entropy streams belonging to different clients must be strictly isolated.

Related articles

Habr•Vulnerabilities & Exploits

Fundamental Flaw in File Monitoring APIs Exposes Keystrokes and App Activity Across Windows, Linux, Android, and macOS

Researchers from Graz University of Technology demonstrated how built-in file change notification mechanisms can leak sensitive user activity without requiring elevated privileges. The affected subsystems include inotify on Linux, FileObserver on Android, ReadDirectoryChangesW on Windows, and FSEvents on macOS. On Linux the technique enables reconstruction of typed text with 93-100% accuracy by monitoring /dev/input/event4 timestamps. Android apps can break sandbox isolation to observe messaging events, while Windows monitoring of browser cache files reveals visited websites at 97.8% accuracy. Only partial mitigations have been deployed in Linux and Windows, with no fixes available for Android or macOS. Additional attacks remain possible, including detection of password prompts to facilitate phishing overlays.

AntiMalware•Vulnerabilities & Exploits

16-Year-Old Researcher Discovers Authentication Bypass in Microsoft Titan Analytics Platform

A 16-year-old security researcher using the pseudonym Faav identified a critical flaw in Microsoft Titan, the company's internal analytics platform. The vulnerability allowed an attacker to submit forged JSON Web Tokens that bypassed signature verification and granted administrator privileges. With these rights, the researcher could execute arbitrary SQL queries against connected databases containing metadata from nearly 10,000 tables. Microsoft received the report on September 5, disabled public API access four days later, and issued a $5,000 bounty on September 17. No evidence has emerged that the issue was exploited by malicious actors before remediation. The researcher accessed only limited metadata and a small number of records during testing and did not exfiltrate customer personal data.

Hispasec•Vulnerabilities & Exploits

CISA Sets September 30 Deadline for Federal Agencies to Patch Actively Exploited Citrix NetScaler Zero-Days

CISA has ordered U.S. federal agencies to apply patches by September 30 for two actively exploited zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, enable unauthenticated remote code execution under default configurations and affect systems commonly exposed to the internet. CVE-2026-88771 allows remote code execution without authentication on NetScaler ADC and Gateway, while CVE-2026-88772 can trigger remote code execution or denial of service via a memory overflow when DTLS is enabled on VPN vServers. Citrix has released fixes for versions 14.1 and 13.1, including FIPS and NDcPP builds, with minimum required builds of 14.1-73.37 and 13.1-64.23. The advisory also covers six additional vulnerabilities from CVE-2026-88773 to CVE-2026-88778 involving HTTP request smuggling and TCP ISN prediction issues. Unsupported branches NetScaler 12.1 and 13.0 receive no patches, requiring immediate migration. Organizations are advised to inventory instances, check for compromise indicators before patching, and preserve forensic evidence.

BoletimSec•Vulnerabilities & Exploits

CSRF Flaw in Elementor Allows Admin Account Creation on Over 2 Million WordPress Sites

A critical CSRF vulnerability has been identified in the Elementor page builder plugin for WordPress, affecting versions 4.3.0 and 4.3.1. The issue enables attackers to create administrator accounts on target sites by exploiting improper handling of CSRF protections in the Editor Events module. With a CVSS score of 8.8, the flaw impacts more than 2 million installations out of over 10 million total WordPress sites using the plugin. No CVE identifier had been assigned at the time of disclosure on September 26. The vulnerability was fixed in version 4.3.2, and users are urged to update immediately. The discovery is credited to researcher Saggre following responsible disclosure, with no public records of active exploitation noted at the time of analysis.