<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:thales_group:sconnect:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3athales_groupsconnect/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 16:31:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3athales_groupsconnect/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical RCE Vulnerability in Thales SConnect Middleware</title><link>https://feed.craftedsignal.io/briefs/2026-10-swift-middleware-rce/</link><pubDate>Fri, 02 Oct 2026 16:31:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-swift-middleware-rce/</guid><description>A critical buffer overflow vulnerability (CVE-2026-18397) in the Thales SConnect browser extension allows unauthenticated attackers to achieve remote code execution through malicious drive-by web pages.</description><content:encoded><![CDATA[<p>Researchers have identified a critical vulnerability, tracked as CVE-2026-18397, in the SConnect browser extension developed by Thales Group. SConnect is widely used as authentication middleware for hardware-based MFA tokens (e.g., 3SKey) in highly sensitive financial and government environments, including the SWIFT banking system. The vulnerability stems from an insecure, custom-implemented RSA signature verification process within the extension.</p>
<p>Attackers can trigger this vulnerability via a drive-by attack by hosting a malicious website that forces the SConnect extension to process an oversized, invalid signature. Due to a failure in validating the success of the cryptographic operation, the native host component of SConnect reads from a stale memory buffer. An attacker can leverage this memory corruption, combined with heap spraying techniques, to load and execute an arbitrary dynamic link library (DLL) on the victim's machine. Successful exploitation grants the attacker remote code execution (RCE) with the privileges of the logged-in user, potentially enabling session theft, document signing, or unauthorized financial transactions. Thales Group patched the extension in August 2026 and removed it from Microsoft Edge in September 2026.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker hosts a malicious website containing an iframe designed to interact with the SConnect extension.</li>
<li>The victim navigates to the malicious website while SConnect is active in their browser.</li>
<li>The website sends a crafted, oversized RSA signature payload to the SConnect browser extension.</li>
<li>The SConnect extension initiates an insecure custom cryptographic check, which fails due to the oversized input.</li>
<li>The application fails to check the status of the operation, leading to a heap-based buffer vulnerability in the native host.</li>
<li>The attacker performs heap spraying with specific byte patterns to manipulate the memory layout.</li>
<li>The SConnect native host is triggered to load a malicious DLL provided by the attacker.</li>
<li>Arbitrary code is executed on the endpoint, leading to full system compromise or session theft.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full remote code execution on the target system. Given SConnect's role in the SWIFT banking ecosystem and national identity providers (such as Qatar’s Tawtheeq and the Swedish Tax Agency), this vulnerability poses an extreme risk to financial integrity and national security. It enables attackers to bypass hardware MFA protections, potentially allowing for the unauthorized signing of banking documents or the exfiltration of sensitive session data. Organizations relying on SConnect as a fallback for the newer &quot;Web Connect&quot; are at high risk if they have not yet migrated to the latest supported infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately transition all SConnect users to the newer &quot;Web Connect&quot; platform as recommended by SWIFT.</li>
<li>Uninstall the SConnect browser extension and its associated desktop native host component from all managed endpoints.</li>
<li>Conduct an audit for the presence of SConnect binaries and associated extension IDs across the enterprise environment to ensure total removal.</li>
<li>Review endpoints that previously utilized SConnect for any signs of post-exploitation activity, focusing on the native host process behavior.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>banking</category><category>authentication</category></item></channel></rss>