Fundamental Flaw in File Monitoring APIs Exposes Keystrokes and App Activity Across Windows, Linux, Android, and macOS
Researchers from Graz University of Technology have published work showing how standard file-monitoring subsystems can be abused to leak private information across major operating systems.
The affected components are inotify in Linux, FileObserver in Android, ReadDirectoryChangesW in Windows, and FSEvents in macOS. These interfaces report when files are opened, modified, or deleted and can be accessed by unprivileged users who have directory-level permissions.
On Linux, access to the /dev/input directory allows an attacker to observe timestamped events from /dev/input/event4. By measuring intervals between keystrokes, researchers reconstructed typed text with accuracy between 93% and 100%. The attack also works over SSH sessions.
Android’s FileObserver breaks application isolation, enabling a malicious app to monitor messaging events such as document or media transfers in other applications.
In Windows, monitoring browser cache files revealed visited websites with 97.8% accuracy. On macOS the technique was less powerful but still exposed system events including audio device changes and Bluetooth updates.
Partial fixes appeared in Linux in December 2025 and an optional Windows policy was introduced, yet both remain insufficient. No patches exist for Android or macOS. Researchers also demonstrated an ongoing Linux attack that detects password prompts to overlay a fake login window.
Additional items reported this week include the MacSync infostealer for macOS that abuses iCloud infrastructure, a practical 1024-bit RSA factoring method, a flaw in the Muse AI assistant on macOS, a critical WordPress vulnerability affecting versions from 4.7 onward, an unpatched issue in Windows Defender, and zero-days in Citrix NetScaler and the D-Link DIR-822A router.
Related articles
16-Year-Old Researcher Discovers Authentication Bypass in Microsoft Titan Analytics Platform
A 16-year-old security researcher using the pseudonym Faav identified a critical flaw in Microsoft Titan, the company's internal analytics platform. The vulnerability allowed an attacker to submit forged JSON Web Tokens that bypassed signature verification and granted administrator privileges. With these rights, the researcher could execute arbitrary SQL queries against connected databases containing metadata from nearly 10,000 tables. Microsoft received the report on September 5, disabled public API access four days later, and issued a $5,000 bounty on September 17. No evidence has emerged that the issue was exploited by malicious actors before remediation. The researcher accessed only limited metadata and a small number of records during testing and did not exfiltrate customer personal data.
Quantum Randomness Failures Allow AI to Extract Predictable Patterns from QRNG Devices
Quantum physics can generate true randomness, yet engineering flaws in QRNG implementations often introduce predictable noise that attackers can exploit. The European Telecommunications Standards Institute has published ETSI TR 104 171, a technical report guiding the design and evaluation of quantum random number generators used in cryptographic key creation. The report highlights that sensors, power supplies, signal processors, and post-processing algorithms can leak patterns even when statistical tests pass. Artificial intelligence systems are now capable of analyzing large datasets to detect these subtle correlations. Side-channel emissions such as power consumption and electromagnetic radiation further increase the risk by linking physical signals to output values. ETSI recommends adopting an entropy zero trust model that includes continuous monitoring, hardware protection, encrypted delivery channels, and detailed logging of generation events. In multi-tenant environments, client streams must remain isolated to prevent cross-contamination of entropy sources.
CISA Sets September 30 Deadline for Federal Agencies to Patch Actively Exploited Citrix NetScaler Zero-Days
CISA has ordered U.S. federal agencies to apply patches by September 30 for two actively exploited zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, enable unauthenticated remote code execution under default configurations and affect systems commonly exposed to the internet. CVE-2026-88771 allows remote code execution without authentication on NetScaler ADC and Gateway, while CVE-2026-88772 can trigger remote code execution or denial of service via a memory overflow when DTLS is enabled on VPN vServers. Citrix has released fixes for versions 14.1 and 13.1, including FIPS and NDcPP builds, with minimum required builds of 14.1-73.37 and 13.1-64.23. The advisory also covers six additional vulnerabilities from CVE-2026-88773 to CVE-2026-88778 involving HTTP request smuggling and TCP ISN prediction issues. Unsupported branches NetScaler 12.1 and 13.0 receive no patches, requiring immediate migration. Organizations are advised to inventory instances, check for compromise indicators before patching, and preserve forensic evidence.
CSRF Flaw in Elementor Allows Admin Account Creation on Over 2 Million WordPress Sites
A critical CSRF vulnerability has been identified in the Elementor page builder plugin for WordPress, affecting versions 4.3.0 and 4.3.1. The issue enables attackers to create administrator accounts on target sites by exploiting improper handling of CSRF protections in the Editor Events module. With a CVSS score of 8.8, the flaw impacts more than 2 million installations out of over 10 million total WordPress sites using the plugin. No CVE identifier had been assigned at the time of disclosure on September 26. The vulnerability was fixed in version 4.3.2, and users are urged to update immediately. The discovery is credited to researcher Saggre following responsible disclosure, with no public records of active exploitation noted at the time of analysis.