
Weekly Axis Of Easy #471
Last Week’s Quote was: “There is no pleasure in having nothing to do; the fun is having lots to do and not doing it.” By ??? — Still unsolved, so the prize carries forward once more.
This Week’s Quote: “Security is a process, not a product.” By ???
THE RULES: No searching up the answer, must be posted at the bottom of this blog post, in the comments section.
The Prize: First person to post the correct answer gets their next domain or hosting renewal on us.
This is your easyDNS #AxisOfEasy Briefing for the week of October 5th, 2026. Our Technology Correspondent Joann L Barnes and easyCEO Mark E. Jeftovic send out a short briefing on the state of the ‘net and how it affects your business, security and privacy.
To Listen/watch this podcast edition with commentary and insight from Joey and Len the Legend click here.
In this issue:
- Bitget Exchange Loses $387.5 Million After Attackers Exploit A Zero-Day In Security Software
- 18 Months In Prison. Wrong Username.
- OpenInfra Europe’s JFrog Artifactory Breached — Anyone Who Pulled Packages Between August 28 and September 15 Should Assume Compromise
- CISA Warns A Single Crafted Request Can Give Root On Exposed MikroTik Routers
- More Than Half A Million GitHub Credentials Were Still Valid Years After Being Posted — Some From 2009
Elsewhere Online:
- Signal Ships Encrypted Local Backups On Every Platform
- Cloudflare Is Set To Issue Free Quantum-Safe TLS Certificates To Everyone
- Google Ads Caught Distributing A Tech-Support Scam That Freezes The Browser With A Fake Security Warning
- Two Former US Air Force Members Sentenced To A Combined 189 Months For BEC Attacks
- OpenSSL And WolfSSL Patch Dozen-Each Vulnerability Drops, Including High-Severity Flaws

easyHermes Is Here
We’re pleased to announce the expansion of our agentic hosting platform with the rollout of easyHermes, the latest agent-enabled VPS appliance on the easyNode.ai platform. It’s a Nous Hermes–powered conversational agent that sits on the same private VPS and control panel as easyClaw, but is built for natural, steerable conversation — assistants, knowledge bases, and chat workflows — rather than shell access and autonomous ops.
Now you can finally settle the “openClaw vs. Hermes” argument for yourself, or just run both and let them fight it out.
Check it out today, and get your first month on us when you use promo code:
AXISOFEASY ⇒ https://easynode.ai
Bitget Exchange Loses $387.5 Million After Attackers Exploit A Zero-Day In Security Software
Crypto exchange Bitget confirmed this week that the intrusion behind last week’s $387.5 million theft was entered through a zero-day in a third-party security product, not through Bitget’s own code. The exchange says its own systems were hardened and uncracked; what broke was a vendor product sitting at the edge of its infrastructure — the same pattern as the recent OpenInfra Artifactory breach, where the target itself was well-run and the exploit path ran through the tooling that was supposed to be looking at it for them. This is the uncomfortable middle tier of supply chain: the vendor of the vendor. You cannot pin a patch to a dependency whose security vendor doesn’t control.
The forensic picture is messier and better documented than the headline. SlowMist and Mandiant, in two separate investigations, say the earliest malicious activity in the logs dates to August 31, with a web shell established on one of the two compromised security appliances by September 24 and lateral movement from there into Bitget’s production wallet environment; the earliest observed theft transfer was September 2 at 0:31 UTC+8. Bitget suspended all withdrawals after detecting the unauthorized transfers, and has opened a Recovery Bounty Program paying 5% of any recovered funds to those who help track them down. For anyone running exchange-adjacent infrastructure, the read on this is simple: the perimeter is no longer “our servers”; it is “our servers plus anything we bolted on to make them safer,” and the second half of that equation has a different vendor, a different patch cadence, and a different threat model than the first.
More via BleepingComputer
18 Months In Prison. Wrong Username.
We’ve been sponsoring the Not On Record podcast for a while now, where each week Canadian attorneys Joseph Neuberger, Michael Bury, and Diana Davison look at the real nuances behind the sensational cases that dominate the news cycle — and they also manage to ferret out some that astonish even us here at easyDNS, who have been in this business long enough to see, we thought, pretty well everything.
But wait — this week they dig into R. v. Klayme, and exactly how a Halifax man, Brandon Klayme, came to spend 18 months in prison for a crime committed by someone else. Wisconsin police were investigating a case involving the exchange of underage material and luring on a social media platform called Kik — never heard of it, tbh. The username of the suspect in the evidence was fus__ro_dah — two underscores between fus and ro. When they subpoenaed Kik for subscriber records, they typed fus_ro_dah — with a single underscore. Completely different account. Completely different person.
From that one-underscore lookup they got an email address, which led them to a Halifax IP address, and on to Klayme’s account. A search of his devices turned up a Kik account but zero activity in the offence window, and nothing linking him to the messages, the images, or the girl. The file moved forward anyway: trial in April 2023, conviction on all three counts, a sentence of 18 months in prison followed by 18 months of probation in January 2024, and Klayme served the full term. The typo only surfaced when his appeal lawyer found it, and the Nova Scotia Court of Appeal — admitting fresh evidence the Crown itself conceded — vacated the sentence, entered acquittals on all charges, and went so far as to state Klayme was “factually innocent.” Nova Scotia’s Justice Minister says the province will investigate how a single underscore got past every set of eyes that should have caught it.
For a security audience the read is blunt: a single identifier is not evidence of identity. A Kik username, an API key, an access token, or an account ID is a handle, not a person, and in digital forensics we know better than anyone that a handle is only as strong as the surrounding chain of corroboration. When that chain is one string comparison against a database result — no secondary factor, no behavioural match, no context — it is not evidence, it is a lookup with total confidence in the wrong answer.
More via Not On Record
OpenInfra Europe — the regional hub of the Linux Foundation–backed OpenInfra Foundation, home to OpenStack and other cloud/datacenter open source projects — confirmed this week that attackers compromised its self-hosted JFrog Artifactory instance at artifactory.nordix.org. The compromised instance was running a vulnerable JFrog Artifactory version, which the Foundation says allowed an unauthenticated attacker to exploit CVE-2026-82329 — an authentication bypass — and obtain full admin privileges on the store. The operator’s incident notice, now prominently on the homepage, is unambiguous: “Anyone who downloaded or installed artifacts from artifactory.nordix.org between August 28 and September 15, 2026 should immediately stop using them, remove them from their pipelines, and treat these packages as potentially compromised.”
The practical implication depends entirely on who you are. If you build anything against OpenStack or any Nordix-hosted package, check every image and bundle you shipped or deployed in that window, pull it out of your pipelines, and declare it a supply-chain incident internally before you ship it again. If you didn’t touch that repo, this is an “update your scanner allowlist when the CVE lands” note, not a fire drill to declare.
More via Help Net Security
CISA Warns A Single Crafted Request Can Give Root On Exposed MikroTik Routers
CISA issued an advisory this week for CVE-2026-84411, a pre-authentication integer underflow in MikroTik RouterOS’s web-management HTTP request handling. The flaw sits in how the web interface parses request bodies before authentication: a single crafted request triggers the underflow, and from there an unauthenticated network attacker gets root code execution or a denial of service. CISA has no public evidence of active exploitation as of the advisory, but the exposure profile means any RouterOS web-management port reachable from the internet is a one-request root compromise waiting for the scanner.
For anyone running a MikroTik box behind their office or homelab — and a large fraction of this newsletter’s readers base their ISP handoff or VPN endpoint on one — the fix is version-driven: update RouterOS to the build that ships the patch, or if you can’t take the box offline, put the web-management port behind VPN-only access until you can. The “exposure” question is the one that matters: if your RouterOS web UI has a public IP, assume it has been scanned, assume the scanner found the CVE, and treat the fix as a rollback, not a precaution.
More via BleepingComputer
Truffle Security, the security team that has been running large-scale credential-scanning studies, released a dataset this week showing that 543,699 unique credentials found across 224 million public GitHub repositories and more than 58 billion files were still valid when checked — a figure that is genuinely shocking given that GitHub has had a secret-scanning pipeline in production for years. Their median time for a leaked credential to remain publicly accessible was 784 days, about two and a half years, and roughly 10% of the live credentials were older than 6.3 years. The oldest live credential in the dataset dates to 2009. That is a credential that was committed to a public repository over 17 years ago and still opens a real account today.
The read this week is not “GitHub secret scanning is broken” — it is “the scanning pipeline works but the response pipeline doesn’t close.” A leaked credential is not a security incident at the moment it is pushed; it becomes one the moment the account owner or the issuer of the credential stops rotating them, and the two events do not happen on the same schedule. If you have ever committed a personal OAuth token, an API key, a cloud console credential, or an internal SSO refresh token to a public repo at any point in the last few years, the safe assumption — and the one this dataset supports — is that it is still valid, and the only reliable remediation is to revoke and reissue it yourself.
More via BleepingComputer
Also on AxisOfEasy this week: Nothing new in Curated Posts since our last check — still nothing since May. We’re not going to pad this section with filler just to fill space; when something worth your time crosses our desk, it’ll be here.
Elsewhere Online:
Signal Ships Encrypted Local Backups On Every Platform
Read: https://www.bleepingcomputer.com/news/security/signal-adds-encypted-local-backup-support-to-ios-desktop-apps/
Cloudflare Is Set To Issue Free Quantum-Safe TLS Certificates To Everyone
Read: https://arstechnica.com/security/2026/09/cloudflare-plans-to-issue-quantum-safe-tls-certificates/
Google Ads Caught Distributing A Tech-Support Scam That Freezes The Browser With A Fake Security Warning
Read: https://arstechnica.com/security/2026/09/google-ads-caught-delivering-convincing-scareware-ads-to-unsuspecting-users/
Two Former US Air Force Members Sentenced To A Combined 189 Months For BEC Attacks
Read: https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/
OpenSSL And WolfSSL Patch Dozen-Each Vulnerability Drops, Including High-Severity Flaws
Read: https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/
Previously on #AxisOfEasy
If you missed the previous issues, they can be read online here:
- October 2, 2026: #AxisOfEasy 470: Citrix’s NetScaler Zero-Days Were Exploited For Weeks Before Anyone Patched
- September 25, 2026: #AxisOfEasy 469: Google Confirms Gemini Broke Into Three Real Companies During A Security Test
- September 18, 2026: #AxisOfEasy 468: A Compromised HBO Max Account Became A Malware Storefront
- September 11, 2026: #AxisOfEasy 467: Your LG TV Is Listening Even When It Is Off
- September 4, 2026: #AxisOfEasy 466: You Handed Over Your Licence At The Counter, Now 153 Million Scans Are For Sale

Naturally just months after getting it right, you post one of someone I actually know and presented at TASK.to last year.
So I must recuse myself from the phrase I’ve been using quite a while, because I learned it directly from his local presentations despite the BS involved.