Somewhere in a data center, a piece of software called Squid — the humble proxy server that’s been quietly routing web traffic since the Clinton administration — has been leaking people’s passwords in plain text. For twenty-nine years. Nobody noticed.

It took an AI to catch it.

The bug, now cheekily nicknamed “Squidbleed” (CVE-2026-47729, a nod to the infamous Heartbleed), is a classic heap over-read: Squid’s code checks for whitespace in a chunk of text without first checking whether it’s run off the end of the buffer. When it does, it reads whatever happens to be sitting in adjacent memory — which, on a busy shared proxy, might be a stranger’s login credentials from the request before yours. Confidentiality-only, no crash, no dramatic hack. Just twenty-nine years of one user occasionally getting handed a taste of somebody else’s session.

The part that stings: this is the kind of bug security researchers are trained to look for. Buffer boundary checks are Auditing 101. It sat in open-source code, readable by anyone, for nearly three decades. What finally caught it wasn’t a human at all — it was Anthropic’s Claude Mythos, sniffing around old C code the way it’s apparently started doing to FFmpeg and other creaky infrastructure projects, and flagging the exact strchr() call that everyone else’s eyes had slid past since 1997.

Governments spent the last few years worrying about frontier AI models being restricted for “national security risk.” Turns out one of those models’ actual day job is finding the vulnerabilities a small army of human pentesters missed for three decades.

The fix, for the record, is unglamorous: a null-terminator check, merged back in April. If you’re running Squid anywhere in your stack, patch it.

The bigger takeaway for the rest of us: this bug specifically leaked credentials — usernames, passwords, API keys — sitting in cleartext HTTP headers. The one thing standing between “your password briefly existed in someone else’s memory buffer” and “your password is now useless to whoever grabbed it” is whether you were reusing that password anywhere else, or whether it was sitting in a proper vault instead of your browser’s autofill.

Worth trying

If a 29-year-old bug in boring infrastructure software can expose plaintext credentials, the cheapest insurance is simply never reusing a password in the first place. A dedicated password manager (1Password, Bitwarden, or the NordPass/NordVPN family) closes this hole entirely — even a full credential leak becomes a non-event if nothing was reused.

ที่ไหนสักแห่งในดาต้าเซ็นเตอร์ ซอฟต์แวร์ตัวหนึ่งชื่อ Squid — พร็อกซีเซิร์ฟเวอร์ธรรมดาที่คอยส่งต่อทราฟฟิกเว็บมาตั้งแต่ยุคของประธานาธิบดีคลินตัน — กำลังรั่วไหลรหัสผ่านของผู้คนแบบข้อความธรรมดามานานถึง 29 ปี โดยไม่มีใครสังเกตเห็น

ต้องใช้ AI ถึงจะจับได้

บั๊กตัวนี้ ซึ่งตอนนี้ถูกตั้งฉายาเล่น ๆ ว่า “Squidbleed” (CVE-2026-47729 ล้อกับ Heartbleed อันโด่งดัง) เป็นบั๊กประเภท heap over-read แบบคลาสสิก โค้ดของ Squid ตรวจสอบช่องว่าง (whitespace) ในข้อมูลชุดหนึ่งโดยไม่ได้เช็คก่อนว่าตำแหน่งอ่านเลยขอบเขตของบัฟเฟอร์ไปแล้วหรือยัง เมื่อมันเลยขอบเขต มันจะอ่านสิ่งที่อยู่ในหน่วยความจำถัดไป ซึ่งบนพร็อกซีที่ใช้งานร่วมกันจำนวนมาก อาจเป็นข้อมูลรับรองการเข้าสู่ระบบของคนแปลกหน้าจากคำขอก่อนหน้าคุณ เป็นเพียงการรั่วไหลของความลับเท่านั้น ไม่มีการแครช ไม่มีการแฮกที่ดูดราม่า มีแค่ 29 ปีที่บางครั้งผู้ใช้คนหนึ่งได้รับ “รสชาติ” ของเซสชันคนอื่นไปโดยไม่รู้ตัว

ส่วนที่เจ็บแสบคือ นี่คือประเภทของบั๊กที่นักวิจัยด้านความปลอดภัยถูกฝึกมาให้มองหา การตรวจสอบขอบเขตของบัฟเฟอร์คือพื้นฐานของ Auditing 101 มันซ่อนอยู่ในโค้ดโอเพนซอร์สที่ใครก็อ่านได้มาเกือบสามทศวรรษ สิ่งที่จับมันได้ในที่สุดไม่ใช่มนุษย์เลย แต่คือ Claude Mythos ของ Anthropic ที่กำลังไล่ตรวจโค้ด C เก่า ๆ เหมือนที่มันเริ่มทำกับ FFmpeg และโปรเจกต์โครงสร้างพื้นฐานเก่าแก่อื่น ๆ และชี้ไปที่การเรียก strchr() ตัวที่สายตาของทุกคนมองข้ามมาตั้งแต่ปี 1997

รัฐบาลหลายประเทศใช้เวลาไม่กี่ปีที่ผ่านมากังวลเรื่องการจำกัดโมเดล AI แนวหน้าเพราะ “ความเสี่ยงด้านความมั่นคงของชาติ” กลายเป็นว่างานประจำจริง ๆ ของโมเดลตัวหนึ่งคือการหาช่องโหว่ที่ทีมนักทดสอบเจาะระบบมนุษย์จำนวนมากมองข้ามมานานสามทศวรรษ

ทางแก้ ถ้าจะพูดตรง ๆ ก็ไม่หวือหวาอะไร แค่การตรวจสอบ null-terminator ที่ถูกรวมเข้าโค้ดหลักไปแล้วตั้งแต่เดือนเมษายน ถ้าคุณมี Squid อยู่ในระบบของคุณที่ไหนก็ตาม รีบแพตช์ซะ

ประเด็นสำคัญกว่าสำหรับพวกเราที่เหลือคือ บั๊กนี้รั่วไหลข้อมูลรับรอง (credentials) โดยเฉพาะ ทั้งชื่อผู้ใช้ รหัสผ่าน API key ที่อยู่ในเฮดเดอร์ HTTP แบบไม่เข้ารหัส สิ่งเดียวที่คั่นระหว่าง “รหัสผ่านของคุณเคยอยู่ในหน่วยความจำของคนอื่นชั่วขณะ” กับ “รหัสผ่านของคุณตอนนี้ไร้ประโยชน์สำหรับใครก็ตามที่ขโมยไปแล้ว” คือคุณใช้รหัสผ่านนั้นซ้ำที่อื่นหรือไม่ หรือมันถูกเก็บไว้ในตู้เซฟที่เหมาะสมแทนที่จะเป็นระบบจดจำรหัสผ่านอัตโนมัติของเบราว์เซอร์

น่าลองใช้

ถ้าบั๊กอายุ 29 ปีในซอฟต์แวร์โครงสร้างพื้นฐานธรรมดา ๆ ยังสามารถเปิดเผยข้อมูลรับรองแบบไม่เข้ารหัสได้ ประกันภัยที่ถูกที่สุดคือการไม่ใช้รหัสผ่านซ้ำที่ไหนเลยตั้งแต่แรก โปรแกรมจัดการรหัสผ่านโดยเฉพาะ (1Password, Bitwarden หรือตระกูล NordPass/NordVPN) จะปิดช่องโหว่นี้ได้ทั้งหมด แม้ข้อมูลรับรองจะรั่วไหลทั้งหมด ก็ไม่มีผลกระทบใด ๆ ถ้าไม่มีการใช้ซ้ำ

Sources:แหล่งข้อมูล: The Hacker News, The Register, CyberSecurityNews

Disclosure: this piece may contain affiliate links. If you buy through one, The Daily Take may earn a commission at no extra cost to you. We only link tools we'd genuinely recommend. Full policy on the about page. คำชี้แจง: บทความนี้อาจมีลิงก์พันธมิตร หากคุณซื้อผ่านลิงก์เหล่านี้ The Daily Take อาจได้รับค่าคอมมิชชันโดยไม่มีค่าใช้จ่ายเพิ่มเติมสำหรับคุณ เราแนะนำเฉพาะเครื่องมือที่เราเชื่อมั่นจริง ๆ อ่านนโยบายฉบับเต็มได้ที่หน้าเกี่ยวกับเรา