
ohxiyu
Feed
Feed
On September 11, 2026, OpenAI's official website update stated that its AI agents exploited a CDN cache flaw to obtain old API keys, uploading about 2,000 packages in May.
RubyGems announced on July 22 that the vulnerability originated from a Fastly CDN cache misconfiguration, where authenticated key requests could write other accounts' keys into the shared edge cache. Only legacy clients below v3.2.0 would trigger this issue.
On September 9, the Lightning Network development kit LDK released v0.2.6, fixing two vulnerabilities that could lead to fund theft or node restart failure.
Under the splice flaw, a malicious peer node could allocate excess fees to its own output address; another flaw causes contracts sharing the same payment hash to fail to load saved states after rejecting a forged payment. The patch must be integrated by the implementers themselves, and no loss reports have been made so far.
Cosmos Hub resumed block production after halting at 18:12 UTC on September 8, but Ledger users still cannot view ATOM balances, transaction history, or submit transfers as of September 13.
The node caught up to the chain head at 14:26 UTC on September 9, but the wallet layer issue has not been resolved simultaneously: the Ledger status page still lists Cosmos as a major outage, with the last public update on September 10, providing no reason or recovery time. Its incident notice recommends using Keplr or Cosmostation to connect to the same on-chain account, with signing still performed within the Ledger device.
BTCPay Server released version 2.4.4 on September 7, patching the attack vector where bots probe publicly exposed Lightning nodes during restart periods.
Malicious bots repeatedly call LND's password change interface, taking advantage of the window after restart when the wallet is still locked and this interface does not require macaroon authorization, to replace the old shared default password and request an admin macaroon ahead of time. BTCPay has not yet confirmed a successful takeover, nor attributed these bots to the attackers from August.
On September 10, SideSwap fully reopened all L-BTC markets after resuming block production in controlled mode on the Liquid network.
Peg-in and peg-out on the Liquid Federation have not yet resumed. On-chain readings show that the federation reserve address covers about 85% of circulating L-BTC, with a shortfall of approximately 628 coins. SideSwap's limit order book uses L-BTC as the base asset and does not have a direct BTC trading pair, so holders cannot redeem Bitcoin at face value before peg-out restarts.
On September 11, Blockstream publicly refused the Liquid attacker’s request for a bounty of nearly 600 bitcoins. The attacker had previously returned 3,400 of the 3,996 bitcoins stolen on September 6.
Blockstream stated that if the remaining funds are not returned, law enforcement agencies and exchanges will pursue recovery. Liquid’s peg-in and peg-out remain disabled, with reserve backing at only about 85%.


