HabrAugust 6, 2026🇷🇺Translated from Russian

Certificate Transparency Logs Fail to Block Rogue CA Man-in-the-Middle Attacks

Certificate Transparency was designed to detect certificates issued without the domain owner’s knowledge, yet recent testing shows it provides little practical defense against man-in-the-middle attacks performed with rogue certificates from compromised or cooperative certificate authorities.

Limitations of Public CT Log Aggregators

Existing web aggregators such as crt.sh are frequently recommended for checking logged certificates, but they suffer from reliability problems including repeated 502 errors. More importantly, an attacker who can influence a certificate authority can also influence an aggregator, rendering third-party sites untrustworthy for high-stakes verification. Even when data is available, the pre-certificate stored in the log can be made nearly identical to a malicious certificate, making manual detection of mismatches extremely difficult.

Direct Cryptographic Verification Attempts

Direct queries to CT logs using the documented /ct/v1/get-proof-by-hash endpoint were performed on multiple real-world certificates extracted from browser sessions. Every request returned 404 Not Found. The built-in Windows utility certutil -dump similarly reported “Not found” for every SCT entry examined, including valid-looking timestamps and ECDSA signatures.

Proof-of-Concept Man-in-the-Middle Attack

To demonstrate the weakness, a complete certificate chain for the popular Russian site habr.com was obtained and replicated using a locally generated self-signed CA that matched all subject attributes, extensions, and validity dates. The forged chain was served by an nginx instance configured with proxy_pass to the real site while the attacker’s CA was added to the system trust store. The browser displayed a fully secure connection with no warnings, and HSTS offered no protection because the presented certificate satisfied the browser’s basic checks.

The attack was also reproduced in a public environment hosted on Yandex Cloud. Users can test the bypass by setting a CNAME record for habr.com pointing to the provided cloud endpoint or by editing /etc/hosts. A simple curl command confirms the substitution returns a page stating “I’m not Habr!”.

Conclusions on Current CT Effectiveness

While CT logs may eventually help identify certificates obtained by deceiving an honest CA, they currently offer no reliable mechanism for browsers to reject certificates from a malicious or coerced CA. The gap between the advertised protection and observed behavior indicates that additional client-side enforcement or alternative transparency mechanisms are still required.

Related articles

Security NEXTVulnerabilities & Exploits

Critical Vulnerabilities Patched in WHMCS Billing Software for Hosting Providers

WebPros International has disclosed two serious vulnerabilities in its WHMCS billing management platform used by hosting and cloud service providers. CVE-2026-67399 allows unauthenticated remote code execution through unsafe deserialization of untrusted data under specific conditions, potentially compromising the entire server environment and associated data. CVE-2026-67398 affects the 2CheckOut payment gateway module and stems from missing authorization checks, enabling attackers to retrieve sensitive customer information including names, addresses, emails, and phone numbers without authentication. HackerOne assigned CVSS v4.0 scores of 9.3 (Critical) to the first issue and 8.2 (High) to the second. WebPros released fixed versions WHMCS 9.0.8 and 8.13.7, and recommended disabling the 2CheckOut module as a temporary mitigation for the second flaw.

Security NEXTVulnerabilities & Exploits

Cisco Releases Critical Patches for Exploited SQL Injection Flaw in Secure Email Gateway

Cisco Systems has issued security updates for Cisco Secure Email Gateway to address a critical SQL injection vulnerability tracked as CVE-2026-76461. The flaw stems from insufficient input validation during email parsing and allows unauthenticated remote attackers to execute arbitrary SQL commands. Successful exploitation can lead to root-level access on the underlying operating system, enabling full command execution. The vulnerability carries a CVSSv3.1 base score of 9.8 and is rated Critical. Cisco confirmed active exploitation of the issue in September 2026. Recommended fixes include upgrading to versions 16.5.0-780, 16.0.4-3021, or 15.5.5-0141, with strong preference given to the newest release.

AntiMalwareVulnerabilities & Exploits

Telegram Desktop HTML Export Flaw Allowed Stealthy JavaScript Injection into Chat History

Researchers at ExPatch identified a vulnerability in Telegram Desktop that enabled attackers to embed malicious JavaScript into exported HTML chat histories without user detection. The flaw stemmed from insufficient sanitization of button captions added by bots, allowing hidden scripts to execute when the HTML file was opened in a browser. Malicious messages could be forwarded into chats and remain dormant until export, potentially exfiltrating messages, sender names, and timestamps to attacker servers. The issue affected versions 4.15.1 through 6.9.3, with fixes released in beta 6.9.4 and stable version 7.0.1 on July 14. No in-the-wild exploitation was observed, though the attack required specific conditions including an unpatched export and JavaScript-enabled browser. Users are advised to re-export chats after updating or open old files with JavaScript disabled.

HabrVulnerabilities & Exploits

Critical MikroTik RouterOS Vulnerabilities Enable SSH Authentication Bypass and Privilege Escalation

Polish CERT disclosed three vulnerabilities in MikroTik routers, two of which have been actively exploited since at least September 2. The flaws, rated 9.2 on CVSS, affect devices with internet-facing SSH access and were discovered using OpenAI models GPT 5.5 Cyber and GPT 5.6 Sol followed by manual verification. CVE-2026-67276 allows authentication bypass when the attacker knows the username and public key module, while CVE-2026-86060 permits privilege escalation via usernames containing invalid characters. Their combination enables full device compromise. A third issue, CVE-2026-67277 rated 8.8, resides in the speed-test service and can cause denial of service. Patches are available in RouterOS versions 7.25beta3, 7.24.2, 7.23.4 and 6.49.21, and MikroTik added detection for prior compromise. Attacks began concurrently with patch release and leave distinctive log entries.