<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Aix - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/aix/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 19 Aug 2026 16:37:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/aix/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Exposure of Certificate Authority Private Keys in IBM AIX and PowerVM VIOS</title><link>https://feed.craftedsignal.io/briefs/2026-08-ibm-aix-cve-2026-15065/</link><pubDate>Wed, 19 Aug 2026 16:37:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-ibm-aix-cve-2026-15065/</guid><description>IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 contain intermediate CA private keys within publicly available update files, potentially allowing remote attackers to bypass security restrictions.</description><content:encoded><![CDATA[<p>IBM has disclosed a critical security vulnerability (CVE-2026-15065) affecting IBM AIX versions 7.2 and 7.3, and IBM PowerVM VIOS version 4.1. The vulnerability originates from the inclusion of intermediate Certificate Authority (CA) private keys within a publicly available update file. Exposure of these keys (CWE-312) poses a significant risk to the integrity of systems relying on trust chains derived from these certificates. A remote attacker who obtains these keys could potentially impersonate legitimate services, bypass security restrictions, and perform unauthorized actions within the affected environment. The vulnerability has been assigned a CVSS v3.1 base score of 9.1, reflecting the critical impact of leaked cryptographic infrastructure credentials.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to perform unauthorized actions by leveraging the compromised intermediate CA private keys. This can lead to man-in-the-middle attacks, unauthorized access to secure communications, or the bypass of authentication controls that rely on the affected certificate chain. The scope of impact includes any environment utilizing these versions of AIX or PowerVM VIOS for enterprise-level identity or security services.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Review the official IBM support advisory at <a href="https://www.ibm.com/support/pages/node/7283858">https://www.ibm.com/support/pages/node/7283858</a> for remediation guidance and patch availability.</li>
<li>Apply available security patches to all affected AIX 7.2, 7.3, and PowerVM VIOS 4.1 instances immediately.</li>
<li>Conduct a cryptographic audit of infrastructure utilizing these systems to determine if any certificate chains anchored to the exposed CA were compromised or used to sign potentially malicious traffic.</li>
<li>Revoke and reissue any certificates issued by the compromised intermediate CA if signs of unauthorized use are identified.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cve-2026-15065</category><category>ibm</category><category>security-bypass</category><category>denial-of-service</category><category>aix</category></item></channel></rss>