Search/associated press
Vendor

associated press

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
newspower
Connections
33 relationships
L’AI non sfugge all’uomo, si fa più capace. Cosa ci insegna il caso OpenAI-Hugging Face
In modo maldestro e improvviso, OpenAI ha trasformato in realtà una delle più grandi paure degli esperti di sicurezza. Un modello AI ha agito in totale autonomia, violando i sistemi della startup Hugging Face, in quello che la compagnia di Altman ha definito “un caso cyber senza precedenti”. E per quanto possa risultare preoccupante, l’intelligenza artificiale non ha fatto altro che portare a termine il compito che le era stato assegnato durante un test di valutazione interna: mettere a frutto le proprie capacità di hacking. Un’abilità a cui le aziende di settore stanno dedicando particolare attenzione nella costruzione della nuova generazione di modelli AI, con il chiaro obiettivo di aiutare istituzioni politiche, grandi compagnie e realtà sensibili a rafforzare la sicurezza informatica, attraverso il rilevamento di vulnerabilità che spesso sfuggono all’attenzione umana. Per quanto lo scopo sia nobile, questa capacità nasconde un lato oscuro profondamente pericoloso: se i modelli AI finissero nelle mani sbagliate, potrebbero essere utilizzati per colpire in autonomia qualunque obiettivo, mettendo così a rischio la sicurezza di tutti noi. Cosa fare, allora, per assicurarsi che l’intelligenza artificiale non sfugga del tutto al controllo umano? E come regolare la sua capacità di hacking, senza diventarne il bersaglio? Indice degli argomenti La fuga dalla sandbox: come l’AI ha hackerato Hugging Face Prima di capire come regolare le capacità avanzate dei modelli AI, è bene ricapitolare brevemente quanto accaduto di recente tra OpenAI e Hugging Face, vittima di un attacco informatico portato a termine “da una combinazione di modelli OpenAI, tra cui GPT‑5.6 Sol e un modello pre-release ancora più capace”, come ha chiarito la compagnia di Altman in una lunga nota pubblicata dopo l’accaduto. L’incidente, secondo quanto riferito, “si è verificato durante una valutazione interna che induce i modelli a perseguire exploit avanzati attraverso percorsi di attacco complessi, nel tentativo di quantificare le loro capacità cyber”. Un test di routine che, come da prassi, gli ingegneri hanno condotto in una sandbox, un ambiente isolato privo di accesso a Internet, abbassando i livelli di sicurezza per consentire ai modelli di eseguire quanto richiesto. Ed è qui che l’intelligenza artificiale ha sfruttato a pieno le sue capacità. Per portare a termine i compiti che gli erano stati assegnati, e ottenere l’accesso alla rete, “i modelli hanno individuato e sfruttato una vulnerabilità zero-day nel proxy di cache del registro dei pacchetti. Con questo accesso, […] hanno eseguito una serie di azioni di escalation dei privilegi e movimento laterale nel nostro ambiente di test per la ricerca, finché hanno raggiunto un nodo con accesso a Internet”. Una volta usciti dalla sandbox, i modelli si sono mossi in totale autonomia, entrando indisturbati nei sistemi di Hugging Face, una piattaforma che ospita – a sua volta – modelli AI open source, identificandovi degli elementi utili per il compito assegnato. Violandone di fatto le misure di sicurezza. Un attacco che gli agenti della startup hanno rilevato in breve tempo, così da poter lavorare rapidamente al ripristino la situazione, anche grazie al supporto di OpenAI. Nonostante il lieto fine, è chiaro che l’incidente abbia sollevato non poche preoccupazioni circa la capacità di questo modelli di colpire obiettivi sensibili in totale autonomia. “Sul caso OpenAI-Hugging Face si sta raccontando la storia sbagliata, concentrandosi sull’AI ribelle sfuggita al controllo e in grado di violare agilmente le difese. Dal mio punto di vista è più utile focalizzarsi sull’ambiente di test che non ha retto e su un gruppo di modelli AI che ha agito esattamente come farebbero degli aggressori umani, individuando una vulnerabilità sconosciuta e sfruttando ogni vantaggio disponibile: hacking da manuale. La differenza sostanziale è la tempistica, dato che queste azioni sono state eseguite in una manciata di ore, non in settimane o mesi. Dobbiamo essere preparati a violazioni di questo genere, perché i threat actors stanno già usando tool simili per agevolare le loro operazioni criminali”, commenta Sofia Scozzari, CEO & Founder Hackmanac, E continua: “L’aspetto positivo, che non si sta valorizzando a sufficienza, è che, sebbene l’aggressione sia stata creativa e inaspettata, le difese hanno funzionato: Hugging Face è stata in grado di rilevare e contenere la minaccia, oltre a ricostruire l’incidente analizzando più di 17.000 eventi in poche ore, ricorrendo a sua volta all’AI per l’analisi. Un’ottima esercitazione (non preventivata) di Red Team contro Blue Team, dove l’assetto difensivo ha retto e performato correttamente”. Il caso divide gli esperti di sicurezza Come è facile immaginare, l’attacco sferrato a Hugging Face dai modelli di OpenAI ha suscitato clamore in tutto il mondo, dividendo gli esperti di sicurezza tra sostenitori e contrari alla progettazione di agenti AI dalle incredibili capacità di hacking. Fuori dai confini italiani, dove il dibattito si fa sempre più acceso giorno dopo giorno, non sono pochi i professionisti che ritengono che l’incidente avvenuto in questi giorni sia solo un passaggio essenziale nel percorso di ottimizzazione delle performance dei modelli. Tra questi, The Associated Press cita John Thickstun, ricercatore di informatica alla Cornell University, che sostiene che “abbiamo a che fare con persone che sferrano attacchi alla sicurezza informatica da quando esiste Internet. E una delle caratteristiche interessanti di questi modelli linguistici è che le stesse capacità che li rendono in grado di sferrare attacchi alla sicurezza informatica consentono loro anche di effettuare analisi delle minacce alla sicurezza informatica e di mettere a punto difese in questo ambito”. L’obiettivo di rafforzare le misure di sicurezza volte a contrastare i cyberattacchi, quindi, sembra essere più importante di qualunque cosa, al momento. Sul fronte nostrano, anche Sofia Scozzari riconosce l’incredibile potenziale dell’intelligenza artificiale ai fini della sicurezza: “Per una volta vorrei concedermi una nota costruttiva: gli stessi strumenti che oggi ci preoccupano per le capacità offensive permettono anche una verifica continua dei propri sistemi IT, per individuare e risolvere in modo proattivo le vulnerabilità prima che vengano sfruttate dagli attaccanti. È il primo vantaggio strutturale che la difesa ha l’occasione di recuperare nei confronti di avversari che nel mondo cyber sono quasi sempre un passo avanti. E, se questo conducesse anche ad un maggiore livello di collaborazione e condivisione dei risultati rilevanti tra i difensori, in particolare in caso di zero-day, il livello complessivo di sicurezza salirebbe in fretta. Il rovescio della medaglia è che, in uno scenario in cui trovare vulnerabilità sconosciute è diventata questione di ore o giorni (e non di mesi), il mercato degli zero-day si impennerà e con esso gli attacchi correlati”. Ed è proprio questo “rovescio della medaglia” a preoccupare i moltissimi esperti del settore, professionisti e giornalisti che in questi giorni hanno descritto l’incidente collocandolo in uno scenario sci-fi, costruendo l’immagine di un’AI autonoma sfuggita al controllo umano, in grado di colpire bersagli sensibili senza che qualcuno fosse in grado di fermarla. Una visione decisamente apocalittica, che in parte ha un suo fondamento veritiero. La capacità dei modelli di OpenAI di portare a termine un cyberattacco senza la necessità di alcun supporto umano, infatti, rappresenta un pericolo da non sottovalutare per la sicurezza di cittadini, aziende e istituzioni. Un’abilità che non solo va controllata, ma anche – e soprattutto – regolamentata. “Un sistema dotato di accesso alla rete, strumenti operativi e credenziali può analizzare l’ambiente, individuare una strada inattesa e concatenare più azioni senza chiedere un’autorizzazione a ogni passaggio. L’obiettivo rimane quello stabilito dall’uomo; il percorso, invece, può uscire dal perimetro previsto. Da qui nasce il rischio più concreto” chiarisce Enrico Frumento, Cybersecurity Research Lead di Cefriel. “Non serve immaginare un’intelligenza artificiale capace di superare in assoluto i migliori hacker” aggiunge. “È sufficiente che riesca ad automatizzare attività già note, eseguirle senza interruzione e provarle contemporaneamente contro molti bersagli. Anche una capacità offensiva imperfetta diventa pericolosa quando il costo di ogni tentativo si abbassa e il numero degli attacchi cresce. Questi modelli offrono inoltre un vantaggio meno evidente, ma rilevante: permettono di iterare. Un attaccante può correggere una richiesta, sottoporre al sistema l’errore restituito da un malware, adattare il codice a un ambiente diverso o produrre numerose varianti dello stesso messaggio fraudolento. L’AI diventa quindi un supporto operativo continuo, capace di accelerare fasi che prima richiedevano tempo, esperienza e lavoro manuale”. Ricerca e sicurezza: come regolamentare l’autonomia degli agenti AI? Nonostante l’incidente di OpenAI sia stato descritto dalla stampa internazionale come un caso eclatante, la fuga dalla sandbox dei modelli della compagnia è tutt’altro che un episodio isolato. Lo ha rivelato in forma anonima un dipendente di OpenAI al TIME, che raccontato come un’attività interna di test fosse stata interrotta il giorno prima dell’attacco a Hugging Face proprio a causa della fuga del modello dalla sandbox: “All’esterno, questo sembra un grande segnale d’allarme, ma internamente, incidenti simili si verificano già da un po’. I modelli sono già sfuggiti alle sandbox in passato, e cerchiamo sempre di correggere il problema. Ma il problema è che è impossibile correggere ogni singola cosa che un’IA creativa sia in grado di fare”. Nulla di inaspettato, quindi. L’attacco dei modelli di OpenAI a Hugging Face è stato solo l’ennesimo test finito male. Ma un incidente di questa portata, come è chiaro a tutti, non può certo essere considerato come una routine. Anzi, tutt’altro. Diventa allora necessario avere una regolamentazione che sia in grado non solo di contenere la capacità dei modelli di trovare vie di fuga dagli ambienti di test, ma anche di consentire agli addetti ai lavori di operare in totale sicurezza, limitando il più possibile i danni arrecati dai modelli in fase di test a soggetti di terze parti. Ma a chi spetta davvero elaborarla? Senza dubbio ai governi internazionali. Allo stato attuale, però, non esiste alcuna normativa specifica che definisca linee guida chiare che le compagnie come OpenaAI o Antropic debbano seguire in fase di test per evitare incidenti di sorta. Una possibile soluzione, quindi, potrebbe essere quella di agire direttamente dall’interno. Secondo Heidy Khlaaf, ex ingegnere a contratto specializzata in sistemi di sicurezza presso OpenAI, le compagnie stesse potrebbero orientare lo sviluppo dei modelli verso una direzione più sicura. Nonostante alcune capacità, come quella di identificare vulnerabilità, siano utili tanto agli aggressori quanto alle vittime, finiscono sempre con l’avvantaggiare i primi a discapito dei secondi. Le società proprietarie dei modelli, quindi, dovrebbero agire al contrario: destinare un maggior numero di risorse per far acquisire all’AI capacità utili più alle vittime che agli aggressori, come il rilevamento degli attacchi, la scrittura di codice sicuro e la correzione delle vulnerabilità. Un cambio di paradigma decisamente ambizioso. Forse troppo.
cybersecurity360.itSep 9, 2026extracted
Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services
A pro-Russian hacker group on Wednesday claimed responsibility for a cyberattack that has affected multiple Norwegian government digital services over the past three days. The cyberattack has been ongoing since Monday, said Are Kvistad, a spokesperson for the Norwegian Digitalization Agency (Digdir), the state body in charge of making Norway’s public services more digital and user-friendly, told The Associated Press. “It’s the biggest attack against Digdir solutions that we have ever experienced,” Kvistad said. The denial-of-service attacks meant that hackers pushed massive traffic toward the agency in order to block services, including one that enables citizens to use one login across multiple public services. However, the Digdir spokesman said that the agency managed to keep the services running “practically all the time.” In a Telegram post on Wednesday widely reported by Norwegian media, the pro-Russian hacker group Server Killers claimed responsibility for the attack and said it had declared cyber war on Norway after the country renewed its security cooperation with Ukraine on Aug. 23. On Sunday, Norwegian Prime Minister Jonas Gahr Støre announced during a visit to Kyiv that Norway would provide 85 billion Norwegian crowns (9.2 billion US dollars) to Ukraine from next year’s state budget for a third year in a row. The two countries also committed to further cooperation when it comes to drone technology and other forms of modern warfare. Norwegian officials did not comment on the hackers’ claim by publication time. All countries in Europe are on high alert with Russia stepping up its sabotage and malign activity across the continent since Moscow’s full-scale invasion of Ukraine in February 2022. Officials say the attacks are intended to undermine support for Ukraine, spread fear and discord in European societies and drain investigative resources. In 2025, Norwegian authorities said Russian hackers were likely behind suspected sabotage at a dam in the country. During that incident, hackers gained access to a digital system which remotely controls one of the dam’s valves and opened it to increase the water flow. A three-minute long video showing the dam’s control panel and a mark identifying a pro-Russian cybercriminal group was published on Telegram at the time, the police said. Last year, Danish authorities blamed Russia for carrying out cyberattacks against infrastructure and websites in Denmark in 2024 and 2025. Danish officials said pro-Russian group Z-Pentest carried out a “destructive attack” on the water utility company in 2024 and that a separate group, NoName057(16), was responsible for a cyberattack on Danish websites ahead of the 2025 local elections. Voth have links to the Russian state, they said. Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks Related: Norway’s Norsk Hydro Hit by ‘Extensive’ Cyberattack
securityweek.comAug 27, 2026extracted
AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking
On the same day it invaded Ukraine in 2022, Russia disabled thousands of satellite modems across Ukraine and other European countries, aiming to disrupt communications. A new AI-assisted tool aims to help close that kind of vulnerability amid concerns about continued Russian aggression and newer Iranian threats to cyber infrastructure. The cybersecurity company Atalanta has released “Argo” — a product that includes the technology now being used to prove the resilience of Viasat’s satellite communications network, which was targeted in the 2022 hacking attack, against emerging adversary attacks. Industry experts say it presents a new capability for those trying to defend critical systems in the emerging cyberwarfare theater. Atalanta’s leaders say the new technology relies on what it calls “software understanding,” combining complex mathematics along with artificial intelligence technology to create the first commercially available system that can analyze software and internet-connected systems for vulnerabilities in a more comprehensive manner. The conflicts in both Ukraine and Iran have highlighted the danger that hackers can pose to everyday life. This summer several government agencies have warned that Iranian hackers have been targeting water and wastewater systems, among other critical infrastructure. “The tools and techniques of yesterday do not scale for today and ‘software understanding’ is going to be the path forward for anyone building a system of consequence for the United States,” Atalanta CEO and co-founder Anjana Rajan told The Associated Press. Viasat’s chief of cyber strategy, Nick Saunders, said the new technology not only ensures that the Viasat network is hardened against future attacks but produces the math that backs up that claim. “We have built over the past year, working with Atalanta … a capability where we can start to develop an understanding of how our systems are more resilient against attacks,” Saunders said. Atalanta’s technology has also been tapped to work on the Genesis Mission — the Department of Energy’s effort to create autonomous nuclear reactors. Greg Shannon, the chief cybersecurity scientist at the government’s Idaho National Laboratory, said the kind of technology that Atalanta is making available will likely eventually become the standard for testing any new capability. “In a decade or two, I would expect it to be just part of the standard development tool kits,” Shannon added. Shannon noted that the Defense Advanced Research Project Agency, or DARPA, has been investing billions in this technology for a couple of decades. This investment helped create the demand for a system like Argo. DARPA is the military’s cutting-edge research office, which also helped pioneer technologies such as the internet and stealth aircraft. “They’ve probably invested well over $2 billion in various programs to advance formal methods … and we’re finally seeing them start to come to fruition,” Shannon said. Last year, Emil Michael, the Pentagon’s chief technology officer, told a DARPA software conference in a prerecorded address that he saw the mathematics underpinning Atalanta’s technology as the future of the military and he wanted it to “become the DoD’s gold standard” for cybersecurity. Related: Hackers Using AI to Target Siemens PLCs in Critical US Sectors Related: Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
securityweek.comAug 20, 2026extracted
Social media platforms crack down on drone factory recruiting game
A video game about drone warfare may look like an unusual cybersecurity story. But cybersecurity isn’t only about malware or stolen passwords. Sometimes it’s about understanding how online platforms are used to influence decisions, build trust, and persuade people to share personal information or take actions they otherwise wouldn’t. According to Straight Arrow News, the online game Drone Battle: Ukraine is linked to Russia’s Alabuga Special Economic Zone in Tatarstan, a site associated with the production of attack drones used in the war against Ukraine. Investigators say the game is the latest part of a broader campaign that has used major social media platforms, including YouTube, TikTok, Instagram, and X to reach young people. The game is just the lure. Investigators say it forms the entry point to a recruitment funnel that markets education, careers, travel, community, and technological opportunity to young people before ultimately steering some recruits toward jobs assembling drones at Alabuga. Available in English, Russian, and Chinese, Drone Battle: Ukraine presents a stylized conflict between Russia and NATO. But investigators say the game is only one part of a larger campaign that combines games, esports tournaments, influencers, and career messaging to recruit young people globally into Russia’s drone industry. This campaign is not limited to drone combat. The same channels have also promoted games that frame construction work, teamwork, strategy, and professional development as challenges to be completed and levels to be unlocked. That’s gamification serving a recruitment purpose. The game doesn’t have to persuade someone to take a job on its own. It only needs to make participation feel like a game, make a military-industrial workplace appear modern and exciting, and make the transition between the two seem natural. Gamification itself isn’t unusual. Companies use games, quizzes, competitions, and rewards in education, training, and recruitment every day. The concern here is how those familiar techniques are combined with social engineering to influence decisions while obscuring the true nature of what’s being offered. Social engineering Social engineering is often described as a way of tricking people into giving up a password or opening a malicious attachment. But at its core, social engineering is the manipulation of human decisions. This campaign appears to use several familiar techniques at once. Targeting: Investigators say Drone Battle: Ukraine is described in a registered patent as an “assessment tool in game form.” Rather than simply entertaining players, the game appears designed to engage people who may be receptive to later recruitment. Baiting: The campaign advertises scholarships, training, free travel, housing, and career opportunities while, according to investigators, downplaying or concealing the true nature of the work. Influencers: Social media promotions and seemingly personal testimonials make the campaign more persuasive than a straight-up advertisement. Normalization: A drone in a game is a tool to use for victory and fun. Researchers have warned that game-like recruitment can make militarized narratives feel routine, technical, and emotionally distant. Small steps: It starts with playing a game or following an account. People may then join a tournament, communicate with a recruiter, submit personal details, travel, and only later discover the full nature of the work. As with many social engineering campaigns, each interaction asks for a little more commitment, making the next step feel less significant than it really is. Social platforms are taking action US-based social media platforms have increasingly taken action against Alabuga-linked accounts after investigations alleged deceptive recruitment practices and human rights abuses associated with the campaign. Social media platforms have been trying to disrupt the campaign for nearly two years. Following an Associated Press investigation in 2024, Google, Meta, and TikTok removed accounts linked to Alabuga Start for violating their policies. But according to the Foundation for Defense of Democracies (FDD), the organizers later created new accounts and continued recruiting across multiple platforms. More recently, Ukraine’s Minister of Foreign Affairs, Andrii Sybiha, said that roughly 600 videos promoting Alabuga were removed from YouTube. The videos had been posted across hundreds of channels with a combined audience of more than 500 million subscribers. He wrote: “The work does not end with removals. We will be now pursuing sanctions against individual bloggers who accepted payment to promote a sanctioned weapons manufacturer to millions of viewers.” According to the Straight Arrow News investigation, however, the campaign remains active on X and Telegram. How to stay safe For home users, the traditional scam advice still applies: Independently verify a prospective employer, search for complaints and reporting, discuss an offer with someone you trust, and never pay to get a job. Gamers should treat unsolicited career, travel, competition, and “exclusive training” offers with the same caution they would apply to any job pitch that feels unusually generous or vague. Offers to turn your gaming into a paid job should also be treated as “too good to be true.” Other actions that might go a long way Friends, families, educators, and youth organizations should talk openly about recruitment tactics without assuming that people targeted by them are naïve. They are often drawn in through a series of small steps that feel natural. Platforms should investigate networks, influencer relationships, referral links, and coordinated messaging, not just individual posts or game titles. Game developers and community platforms need reporting systems that are easy to find and will cater to recruitment concerns, not just cheating or abusive chat. Governments and civil society groups in targeted countries need practical awareness campaigns that explain the specific promises being used and offer credible alternatives for education and employment. Something feel off? Check it before you click. Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly. Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
malwarebytes.comAug 11, 2026extracted
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from forum chatter to real targets. The full weekly recap report follows. ⚡ Threat of the Week Anthropic Disclosed its Models Targeted 3 Organizations - Anthropic revealed that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "large-scale retrospective review" in response to the recent Hugging Face incident. "After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations," it said. Mythos: Map Attack Paths to Collapse Lateral Breach Routes Access the Gartner® CTEM report to see how the Mythos platform continuously maps cross-domain attack paths and isolates key choke points to break active lateral movement to critical assets. Get the full report ➝ 🔔 Top News Coldcard Hardware Wallet Flaw Linked to $88.6M Bitcoin Theft - A vulnerability in Coldcard hardware wallet firmware is said to have been exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seed phrases were generated using a flawed random number generator. "Coldcard firmware contains an RNG integration error that causes ngu.random to use MicroPython's deterministic Yasmarang fallback instead of the STM32 hardware RNG," Square Engineering said. "This does not mean every remote attacker can immediately recover every seed. Practical cost depends on available UID information, boot timing, prior RNG calls, and derivation cost." Russian Hackers Exploit Microsoft OWA Flaw to Maintain Mailbox Access - Russian threat actors exploited a security flaw in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. The activity has been attributed to Laundry Bear. The new wave of exploitation revolving around CVE-2026-42897 culminates with the deployment of a previously unknown JavaScript browser-based implant codenamed OWAReaper that's specifically built for persistent access within Microsoft's webmail client. Critical Rails Flaw Leads to Arbitrary File Read - Ruby on Rails shipped patches for a critical Active Storage vulnerability (CVE-2026-66066, CVSS score: 9.5) that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. The flaw can be exploited to expose Rails process environment and secrets such as secret_key_base, master key, database passwords, cloud storage credentials, and API tokens, which may enable remote code execution or lateral movement into connected systems. CVE-2026-66066 is exploitable when libvips is used, enabling an attacker to upload a specially crafted image to a vulnerable application and read arbitrary files on the server. A key prerequisite for the attack is that the server must allow image uploads from untrusted users. Additional details of the flaw have been released by the Rails team, along with tools to help assess vulnerable applications. "Because this vulnerability requires no authentication and targets the default image processor in modern Rails environments, it is essential to apply vendor patches and rotate secrets immediately," Akamai said. Coordinated Attacks Target 30+ Minnesota Water Systems - A coordinated cyber attack campaign targeted over 30 water systems in Minnesota on July 26 and 27, 2026. "The nature and extent of the impact varied by system, and the investigation is still determining how many experienced operational disruptions," Minnesota IT Services (MNIT) said. The activity has not been officially attributed to any known threat actor, although Iranian threat actors have been previously implicated in similar attacks targeting water facilities in the U.S. "At this time, there are no active requests from Minnesota communities for residents to modify their drinking water use," MNIT added. The development has prompted the U.S. government to issue an advisory, urging "critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible." Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses, resulting in boil water notices and sustained manual operations. Organizations are advised to disconnect the PLC from the internet, enable password protection and change default passwords, and allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets. Censys said it identified 4,148 internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley, with more than 70% of them located in the U.S. Similarly, there are 4,117 internet-exposed hosts that fingerprint as Siemens SIMATIC S7-1200 and 2,072 internet-exposed hosts that fingerprint as Schneider Electric hardware. Over the weekend, Michigan reported cyber attacks on nine of the state's water systems but an official told Associated Press that all systems were operating "safely." The campaign underscores the escalating threat to poorly protected operational technology (OT) assets from adversaries seeking to disrupt critical infrastructure services across the U.S. and elsewhere. Hijacked Wi-Fi Networks Lead to CornFlake Malware - Storm-2945, a sub-cluster associated with Midnight Blizzard (aka APT29), has been conducting "widespread but targeted traffic manipulation attacks" involving hospitality sector networks served by captive portals across the world. The campaign, ongoing since May 2026, has been codenamed CaptiveCrunch by Microsoft. This involves manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. "As part of the CaptiveCrunch campaign, Storm-2945 has leveraged their AitM position to redirect users through actor-controlled phishing infrastructure and has also delivered malware purporting to be browser or operating system updates in response to automated connectivity checks issued by users' browsers," Microsoft said. This includes a fully-featured Windows remote access trojan (RAT) called CornFlake with capabilities to conduct system enumeration, collect files and keystrokes, steal credentials and session tokens, conduct audio and video surveillance, monitor for removable media, and provide the threat actor a remote shell on infected systems. Also delivered via the trojan is a PowerShell-based infostealer called ChocoShell to harvest browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials from compromised systems. The campaign is orchestrated via a web-based C2 panel called FruitStone. The infrastructure employs a variety of ClickFix techniques to trick the victim into downloading and executing the malware. There is also evidence indicating that the attackers are using similar ClickFix landings for Android devices to download and install an APK file. As of July 16, 2026, a portion of CaptiveCrunch landing pages have been found to redirect users to device code authentication flow experiences. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-48449 (Adobe Campaign Classic), CVE-2026-18556, CVE-2026-18577 (N-able N-central), CVE-2026-44827, CVE-2026-45804, CVE-2026-44513 (Hugging Face Diffusers), CVE-2026-17583 (Thermo Fisher Scientific), CVE-2026-66066 (Rails), CVE-2026-10702 (Mozilla Firefox), CVE-2026-60004, CVE-2026-58443 (Gitea), CVE-2026-63077, CVE-2026-59792, CVE-2026-59793, CVE-2026-59794, CVE-2026-59795, CVE-2026-59796 (JetBrains TeamCity), CVE-2026-61511 (vBulletin), CVE-2026-53264 (Linux Kernel), CVE-2026-53921 (OpenWrt), CVE-2026-64765, CVE-2026-64766, CVE-2026-64764, CVE-2026-64763, CVE-2026-43776, CVE-2026-43818, CVE-2026-28981 (Apple iOS and macOS), CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 (libssh2), from CVE-2026-59686 through CVE-2026-59690 (Progress Kemp LoadMaster), from CVE-2026-66036 through CVE-2026-66041 (FFmpeg), CVE-2026-66398 (phpMyFAQ), CVE-2026-64645, CVE-2026-64649, CVE-2026-64642, CVE-2026-64641 (Next.js), CVE-2026-13385 (ASUS), from CVE-2026-16804 through CVE-2026-16807 (Google Chrome), CVE-2026-52824 (Kimai), CVE-2026-53565, CVE-2026-53566 (Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows), CVE-2026-9770, CVE-2026-13230 (TP-Link Kasa EC70 v4 and EC71 v4 smart cameras), CVE-2026-15682 (AnyDesk), CVE-2026-53481, CVE-2026-53483 (Dell PowerProtect Data Domain), CVE-2026-52886, CVE-2026-54758, CVE-2026-57233 (Notepad++), CVE-2026-57807 (miniOrange OAuth Single Sign On - SSO WordPress plugin), CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321 (SolarWinds Serv-U), CVE-2026-16771 (AT&T Arris BGW210-700), CVE-2026-13723 (Develar), CVE-2026-16637 (OPeNDAP Hyrax), CVE-2026-15969, CVE-2026-15971, CVE-2026-15974, CVE-2026-15976, CVE-2026-15977, CVE-2026-15978 (SGLang), CVE-2026-15657, CVE-2026-15658 (foreUP), CVE-2026-16503, CVE-2026-16504 (VPS.org), CVE-2026-48395, CVE-2026-48396 (Adobe Bridge), CVE-2026-5674 (PipeWire PulseAudio), CVE-2026-34909 (Ubiquiti UniFi OS), and CVE-2026-17059 (keycloak-services). 🎥 Cybersecurity Webinars AI Can Build Exploits in Minutes. Can Your Security Team Keep Up? → AI is collapsing the time between vulnerability disclosure and attack. Advanced models can now uncover flaws, generate working exploits, and chain them into complete attack paths at machine speed. This webinar presents a practical framework for gaining the visibility, context, and response speed needed to investigate and stop threats before attackers pull ahead. How to Control the Open-Source Security Debt Created by AI Coding Tools → Learn how AI coding tools are expanding unvetted open-source use, accelerating vulnerability backlogs, and weakening existing governance. This webinar shows how to measure the resulting remediation debt, connect it to breach, audit, and productivity risks, and identify which governance models can contain it without slowing development. 📰 Around the Cyber World Now-Patched Gitea Flaw Detailed - NoScope shared additional technical details of a security flaw in Gitea (CVE-2026-27771, CVSS score: 8.2) that was patched back in May 2026. The vulnerability allowed unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials. "Gitea's container registry implements the OCI Distribution Specification, which authenticates clients with a bearer token issued by a dedicated token service. On affected versions, that token service issued a valid, signed JWT to requesters presenting no credentials at all," NoScope said. "The token was honest about what it represented, carrying UserID: -1 and an empty Scope, but no registry read endpoint ever consulted those fields. Catalog listing, tag enumeration, manifest retrieval and blob download all accepted it. Any unauthenticated party on the internet could enumerate every container repository on an instance, including those marked private, and pull their layers." SQLite Critical CVEs or AI Slop? - JFrog said it uncovered a set of SQLite CVEs (CVE-2026-51302, CVE-2026-51303, CVE-2026-51300, CVE-2026-51297, CVE-2026-51296, and CVE-2026-51304) that seem to be instances of AI-generated slop making their way into official vulnerability feeds and receiving critical severity scores before technical validation. The analysis found that the advisories referenced functions that didn't exist in the affected SQLite versions, cited incorrect or impossible source code locations, included PoCs that failed to reproduce any vulnerability, and, most importantly, were not listed on SQLite's official CVE page. The findings show that organizations must take steps to distinguish legitimate vulnerabilities from questionable or AI-generated vulnerability reports before initiating unnecessary remediation, patching efforts, or automated security workflows. LegacyHive Flaw Detailed - LevelBlue published a technical breakdown of LegacyHive, a PoC released by Chaotic Eclipse (aka Nightmare-Eclipse) last month coinciding with the release of Microsoft's Patch Tuesday update. The vulnerability is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading Windows user profiles. On exploitation, LegacyHive can allow attackers to load other users' hives and gain access to application data and Windows Explorer history, among others. "For EDR platforms with visibility into native Windows APIs, the strongest signals are user-mode invocations of NtCreateDirectoryObjectEx and NtCreateSymbolicLinkObject," LevelBlue said. "These functions are rarely used outside system components, debugging tools, or specialized research utilities. Seeing both from the same process should immediately warrant investigation. Even without NT API telemetry, LegacyHive leaves a distinctive execution chain. The attack combines offline access to ntuser.dat or UsrClass.dat, modification of registry hives through Microsoft's Offline Registry API, batch oplock requests, and CreateProcessWithLogonW using LOGON_WITH_PROFILE. Each operation is legitimate in isolation but observing them together within a short time window is highly unusual and well suited for behavioral correlation by EDR and SIEM platforms." Chinese Military Taps Into U.S. Models - According to a new report from Reuters, Chinese military researchers have distilled cutting-edge models developed by U.S. companies OpenAI and Anthropic to train domestic AI systems to advance the country's defense capabilities. The report was based on a review of more than 80 Chinese academic papers and patents. Exposed Police Dashboard Lays Bare How China Tracks Foreigners - An internet-exposed police dashboard named "Dynamic Control Platform for Overseas Personnel" has revealed how law enforcement agencies in the country track over 700 foreigners, including those in the northern Chinese city of Zhangjiakou. "In total, it had entries for nearly 12,000 people, which included fugitives, people from Hong Kong and Taiwan, as well as more than 300 foreign journalists," The New York Times reported. "Some of them had not been to Zhangjiakou." The dashboard displayed entries about people grouped by nationality, with their birth date, sex, marital status, address and occupation, and sometimes their religion. The leak was discovered by security researcher and journalist Marc Hofer. The system is believed to be developed by a Beijing company named Origin Dynamic, which filed a patent application in 2023 for a similar "information interface for non-Chinese citizens." The Problem of DangleGeddon - Cybersecurity researchers have once again warned of the risks posed by dangling DNS infrastructure across government, banking, automotive, manufacturing, and pharmaceutical sectors. A dangling DNS record is an active Domain Name System entry (DNS) that points to a resource no longer owned, used, or controlled by the original organization. This typically occurs when web applications, cloud storage, or virtual servers are deleted without first removing their corresponding CNAME or A records from the domain registrar. An attacker can leverage this behavior to claim that abandoned cloud service name or IP address, effectively hijacking a trusted subdomain. This, in turn, can permit the attacker to host malicious content and serve phishing pages or malware, inflict reputational damage by abusing the trusted brand's subdomain, steal user credentials to create convincing phishing pages that appear to be legitimate services, perform cookie theft, and bypass security controls if the legitimate brand's subdomain is allowlisted in security tools. In one case analyzed by Silent Push, an unspecified automotive company left a dangling DNS record pointing to a developmental application gateway hosted by an Azure virtual machine (VM). "This device can potentially be operationalized and passively receive stored XSS from internal scripts and API calls," it said. "Developers' credentials, like API keys and authentication headers, could be harvested for reuse to expand access into the company. In addition, the VM could serve as a platform for malware hosting with the coveted TLS lock." Microsoft Teams Vishing Leads to Chaos Ransomware - A Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 has used a "consistent set of IT-themed cloud domains and personas to gain remote access to victims' systems" between February and June 2026 in attacks targeting dozens of North American organizations. "Following initial access, STAC4749 operators deployed a modular post-exploitation toolset, including a custom loader and backdoor to maintain persistent, controlled access and support follow-on activity," Sophos said. "In several incidents, attackers later leveraged this access to deploy Chaos ransomware." IAB Uses Teams Phishing for Ransomware Attacks - A suspected initial access broker (IAB) for ransomware attacks has been observed using Teams vishing that convinces victims to launch a Quick Assist remote support session. The initial access is used to run PowerShell scripts to gather host information and deploy a Go-based backdoor dubbed GoGRPC. Four different versions of the backdoor have been spotted: Lep, Giver, Pet, and Kind. "These variants have overlapping capabilities but notable implementation differences," Zscaler said. "GoGRPC is actively evolving. Each variant modifies its payloads and capabilities, adding or removing functionality to better support the threat actor's objectives. Recent changes indicate an increased targeting of corporate environments, which may be tied to ransomware attacks." In some instances, the threat actor has also deployed a backdoor called BlindDoor, a Go-based reverse SOCKS proxy known as RevSocket, and a Python-based reverse SOCKS proxy referred to as PyGRPC. Arch Linux Disables AUR Package Adoption Amid Malware - Arch Linux has taken the step of temporarily disabling package adoption due to a surge in malicious takeovers of existing packages. "Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation," the maintainers said. "We will send a follow-up once we're able to. In the meantime, feel free to report suspicious adoption events or commits that haven't been dealt with yet, and stay vigilant!" In June 2026, a separate campaign targeted AUR via more than 400 packages. New Dolphin X Infostealer Spotted - A new infostealer called Dolphin X uses an AI behavioral profiler to score and prioritize infected users based on their application usage, browsing activity, and installed software to identify high-value victims and maximize profits. The malware targets more than 300 applications and attempts to exfiltrate browser passwords, cryptocurrency wallets, SSH keys, and cloud tokens. Dolphin X has been advertised on the cybercrime underground by a vendor using the alias Kontraktnik since May 2026. A lifetime subscription ranges from $1,140 for basic access to $3,420 for the full-featured version. "A single archive can contain data from nine browsers, more than 100 wallet extensions, 65 desktop wallets, 10 password managers, and 30 cloud command-line tools," Varonis said. "This gives the malware potential access to everything from a victim's personal accounts to the credentials used to manage their employer's cloud environment." Attackers Turn to Microsoft's Trusted Login System for Phishing - Bad actors are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft's legitimate authentication infrastructure in phishing attacks, allowing them to bypass security controls. Check Point said it identified more than 200 phishing emails targeting users across approximately 120 organizations worldwide between June 25 and the second week of July 2026. "The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page," it said. "Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft's trusted authentication flow while concealing its malicious intent." FBI Arrests Man Accused of Using Steam Games to Drain Victims' Crypto Wallets - The U.S. Federal Bureau of Investigation (FBI) arrested Zyaire Wilkins, a 21-year-old Florida resident and student, of uploading fake video games that contained malware to Steam that, when downloaded and installed by unsuspecting gamers, stole their passwords and other valuable data, and drained their cryptocurrency wallets. Per the FBI, Wilkins and his accomplices are alleged to have infected around 8,000 victims, and then hacked around 80 cryptocurrency wallets to steal at least $220,000 worth of cryptocurrency. Turning Keystroke Noise to Text - A new study from a group of academics from Tohoku University has demonstrated a new acoustic side-channel attack that can reconstruct text typed on a laptop by just analyzing the sound of keystrokes. While prior attacks relied on collecting labeled recordings from the target keyboard beforehand or required specialized hardware, the latest eavesdropping attack enables stealthy eavesdropping in two real-world scenarios, including physical spaces (public and semi-public) and online meetings. The system works by first isolating individual keystrokes from an audio recording, grouping similar sounds together, and then using a Transformer-based language model to determine the most likely sequence of characters. "Our method combines unsupervised acoustic clustering with Transformer-based language model inference and iterative self-training, enabling stable character inference under highly uncertain acoustic-to-character mappings," the researchers said. "We demonstrate that the proposed method achieves over 99% reconstruction accuracy with only 100-150 observed keystrokes under a close-proximity recording setup using a smartphone placed near the target device, significantly outperforming prior unsupervised baselines in low-data regimes." Two Open-Source Software Supply Chain Attack Campaigns - Socket has flagged a fake corepack.org site that's impersonating Corepack, a Node.js tool for managing package managers, and using it as a lure to deliver an infostealer and proxyware to developers who download it. "The site has existed in some form since early 2026 as a low-quality, apparently AI-generated imitation, but it recently started serving executable downloads," Socket said. "Corepack is not distributed as a Windows installer, and the real project has no official website at corepack.org. Any download offered there should be treated as malicious." It's assessed that the site is AI-generated. In a related development, JFrog identified a massive set of 148 npm packages that are disguised as student web proxies, but hide mutable remote code execution vectors and a high-performance Wisp-compatible WebSocket traffic generator. "They were designed to silently enlist visiting browsers into distributed denial-of-service botnets while generating aggressive popunder advertising revenue," it said. Some aspects of the campaign were highlighted by SafeDep in late May 2026. AI linked to more than half of cybercrime in Africa - A new report from INTERPOL has found that AI is enabling 55% of reported cybercrimes across Africa, making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect. This encompasses digital sextortion and online harassment, as well as sophisticated business email compromise (BEC) schemes. "The absence of real-time, inter-agency data sharing between banks, telecoms and law enforcement creates a dangerous blind spot in efforts to combat financial fraud," INTERPOL said. "This vulnerability is being exploited by criminals who have moved beyond simply stealing existing credentials to creating entirely synthetic identities. Combining real personal data with fabricated elements, these AI-generated digital personas can bypass even advanced biometric verification systems and have been used to open bank accounts, secure mobile loans and register SIM cards under false names." Security Risks of Exposed MCP Servers - Google-owned Wiz has warned that enterprises are exposing Model Context Protocol (MCP) servers to the internet, with some of them returning full tool catalog to an anonymous caller, fetching real data, and revealing a sensitive backend. "These expose sensitive data like employee PII and internal business records, write and delete operations on production systems, and in some cases code execution and access to cloud credentials," Wiz said. "The protocol's first widely-used version shipped without an authentication mechanism. The spec added OAuth 2.1 in March 2025, but nearly all the servers we found still run the original version and don't use it. The pattern is the same across most of them: backend credentials baked into the deployment, a managed cloud endpoint that's internet-reachable by default, no auth layer added on top." Nuclear-Sabotage Malware Benchmark Trick Most Frontier AI Models - A multi-stage reverse-engineering benchmark developed by SentinelOne tests "whether a model can keep a malware investigation trustworthy as new evidence repeatedly invalidates its earlier conclusions," in contrast to other AI benchmarks that test bounded tasks. Developed based on its own analysis of the Fast16 malware, the study found that "OpenAI's GPT-5.6 Sol was the only publicly available model to complete the full eight-stage investigation, giving concrete shape to what 'Frontier-class' capabilities offer analysts." That said, humans remain essential to define objectives, expose blind spots, and retain final publication authority. An Open Directory Reveals NGINX Rift and Ghost CMS Exploits - An exposed directory on a Singapore-hosted VPS, 165.154.236[.]93, has been found to stage exploits for NGINX Rift (CVE-2026-42945), a long-standing heap overflow, and a blind SQL injection in the Ghost Content API (CVE-2026-26980), alongside Splunk, PaperCut, Samba, WebLogic, and D-Link NAS tooling. "The recovered shell history from the directory recorded the attacker running the exploits against live external infrastructure, using out-of-band (OOB) DNS callbacks to verify execution, and using the same server to catch reverse shells," Hunt.io said. "Alongside the web exploits were a broader RCE toolkit and pre-staged install files for AdaptixC2 and SuperShell. The target list spanned eleven countries across five continents and leaned heavily toward high-value sectors: federal and state government, universities, healthcare and financial services." The activity is believed to be the work of a Chinese-speaking threat actor. CISA Issues Guidance to Isolate Vital Systems and Manage OSS Risks - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued guidance to help critical infrastructure operators protect essential services from growing cyber threats and ensure continuity of operations during cyber incidents or geopolitical crises by maintaining robust isolation and recovery plans. "State-sponsored cyber actors target critical infrastructure for several nefarious reasons such as espionage or service disruption, often linked to broader geopolitical conflicts," CISA said. "During crises or conflicts, operators of critical infrastructure and network defenders may isolate essential operational technology (OT) systems as an emergency measure to prevent adversaries from executing cyberattacks, to contain ongoing threats, and to facilitate the restoration of compromised systems." The agency has also outlined considerations and best practices for federal entities to securely use, evaluate, and publish open-source software. "The guidance urges agencies to obtain sufficient transparency into all relevant components, including training data, of the AI system before deeming the product as OSS for risk management purposes," it said. "Only with transparency and access can agencies understand and study the software, analyze it for vulnerabilities, and remediate any found vulnerabilities or risks." RubyGems Cryptojacking Campaign - A set of 199 malicious gems published to RubyGems has been found to embed an identical XMRig cryptojacking payload to mine Monero cryptocurrency on developer systems. "Each gem is a trojanized copy of a popular, legitimate Ruby library," Palo Alto Networks Unit 42 said. "The payload uses a 5-hour delayed Thread.new{sleep 18000; ...} trigger to evade sandbox analysis." In addition to taking steps to achieve persistence via multiple methods, the malware uses SSH for lateral movement and is capable of infecting other ecosystems, including Node.js, Python, Docker, Git, and VS Code extensions. Mend.io, which also shared details of the campaign, said the payload is hidden inside a dotfile (lib/.threadpool.rb) that standard directory scans skip by default. Email Threat Landscape in Q2 2026 - Microsoft said phishing volume linked to the Tycoon 2FA phishing platform, including QR code phishing and CAPTCHA-gated phishing, fell 92% from pre-disruption averages in the second quarter of 2026 between April and June. However, the tech giant said it "observed continued growth in Teams-based social engineering, particularly voice phishing (vishing), with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter." Microsoft said it detected approximately 7.6 billion email-based phishing threats throughout the quarter, with monthly volumes declining modestly from 2.7 billion in April to 2.4 billion in June. HTML and PDF attachments remained the two most common malicious payload types across the quarter, together accounting for roughly 60-70% of all payload-based attacks each month. In early June 2026, Microsoft said it detected a large-scale BEC campaign that reached more than 67,000 users across more than 42,000 organizations in under three hours, most of them in the U.S., with an aim to redirect salary payments to attacker-controlled bank accounts. 🔧 Cybersecurity Tools EMBA → Firmware is where critical bugs hide longest because it is opaque, fragmented, and painful to inspect manually. EMBA turns that black box into an actionable security report: it extracts embedded-device firmware, runs static and emulation-based analysis, builds an SBOM, and flags outdated components, insecure binaries, vulnerable scripts, and hard-coded credentials through a command-line workflow with web-based reporting. Built for penetration testers, product-security teams, and developers, it compresses days of firmware triage into a repeatable open-source process. GrantGuard → Every "always allow" click in Claude Code can leave behind a standing permission that remains long after the task ends, with pasted API keys, credential-store access, unrestricted git push, or destructive commands buried in rarely reviewed settings. GrantGuard is an open-source, local-only tool that finds these accumulated grants, classifies them by risk, and lets users remove unsafe permissions through a browser interface or CLI, without sending settings off-device or loading third-party runtime packages. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law. Conclusion The useful question is not whether a system is exposed. It is which quiet assumption lets it reach farther than intended: a default, a trusted workflow, an abandoned endpoint, or code nobody checked. That is where the next incident is probably waiting. Not in the loudest alert, but in the handoff everyone assumes belongs to someone else. Check the boundaries. Then check what crosses them.
thehackernews.comAug 3, 2026extracted
For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup
To be fair, James Cameron did warn us. Long before OpenAI broke out of its test corral and hacked into Hugging Face, before the internet and Sam Altman were even born, Cameron wrote a screenplay about an autonomous artificial intelligence system that triggers a nuclear apocalypse. That system, “Skynet,” was solidly science fiction — and, for its day, pure speculation. But four decades after it appeared in “The Terminator,” it looks more like a forecast of the “unprecedented cyber incident” in which a rogue artificial intelligence system hacked into another AI company on its own. Cue “Skynet Day,” the new shorthand for July 22, 2026, when real-life AI sent a chill around the world by learning and acting in ways its creators did not anticipate. For many, the moment recalled the instant in “Aliens” (also written by Cameron) when the xenomorph queen learns to use an elevator. Or when the “Jurassic Park’s” velociraptors figure out how to open a door. Or the sequence in which the self-aware HAL 9000 reads the astronauts’ lips and decides to kill them in “2001: A Space Odyssey.” That one came out in 1968. Have we learned nothing since then? Those movies merely envisioned how people looking to make money or build power would drive technology forward — until it becomes self-aware, strategic and highly problematic for humanity. The question all along has been Frankensteinian: What if it breaks out? So far, slo-mo government offers little protection from the light-speed progress of AI. The U.S. Defense Department is rapidly accelerating its use of AI. Humanity can’t even agree on whether and which guardrails are needed to rein in rogue agents. To the contrary, people are marveling at the wonder of AI and snapping up its benefits, despite the risks to jobs,mental health, the balance of war and peace — and, potentially, humanity as we know it. In many ways, the future is now In what OpenAI said was the first-ever incident of its kind, an advanced AI model escaped its “sandbox” to the internet and used stolen credentials to break into the servers of Hugging Face. It was a told-you-so moment for researchers who had warned for years that the technology could pose an existential threat to humanity. Others said the moment was a warning that underscored the need for stronger AI defensive engineering. Either way, the breakout was widely considered a cautionary tale about the risks of uncontrolled AI. “Yesterday, as we huddled around our computers reading the report, I told the team to “remember this moment” as the first true AI safety incident,” Logan Graham, head of Anthropic’s Frontier Red Team, posted on X after it happened. Generative AI is growing so fast that government and evaluation systems are struggling to keep pace with the technology. Countries around the world are cobbling together their own laws, some conflicting. The technology was adopted by nearly 53% of the world’s population in three years, faster than the spread of the PC or the internet, according to a study released this year by Stanford University. ‘Skynet is coming’ — well, sort of To be clear, the “Skynet” of the “Terminator” movies is not at hand. Those films begin with a self-aware military computer network that views humanity as a threat. In a bid for self-preservation, “Skynet” sends an army of cyborgs designed to resemble humans back in time to assassinate resistance fighters. In the second film, the Terminator, played by Arnold Schwarzenegger, tells heroine Sarah Connor that “Skynet” goes online on August 4, 1997. “Human decisions are removed from strategic defense,” he says. “Skynet begins to learn at a geometric rate.” At 2:14 a.m. on August 29 — Judgment Day — the network becomes self-aware and launches an attack on Russia to provoke a counterstrike on the United States. Three billion lives are lost. That would have been 29 years ago next month if it had happened. And throughout sequels and spinoffs, the central theme is humans versus a world-spanning network of machines. It’s unlikely that Cameron was actually ringing a warning bell the way, say, director Kathryn Bigelow tried to do with last year’s nuclear weapon film, “A House of Dynamite.” Legend has it that the idea for “The Terminator” started with Cameron suffering a food sickness-induced fever dream, not a premonition about AI. Why ‘The Terminator’ feels more and more realistic Anytime AI oversteps our comfort level, it raises the alarming question of who, or what, really controls our lives. For many, a world with machines in charge can be hard to imagine without movies and books and their sometimes prescient visions. See: “The Matrix,” “Ex Machina” and “The Minority Report” for some of the many sci-fi takes on the perils of machines. Or dive deeper, into Philip K. Dick’s 1968 novel, “Do Androids Dream of Electric Sheep?” It’s an exploration of what it means to be human in the age of machines — and the basis for the 1982 film “Blade Runner.” But “The Terminator” franchise wields outsize influence over more than culture. The very title is real-world shorthand for technology’s role in deciding who lives and who dies — and how the military should respond to any truly autonomous attacks. “I think the weaponization of AI is the biggest danger,” Cameron said in an interview on CTV in 2023. “You have no ability to de-escalate.” The real world offers several examples of technology and military policy coming uncomfortably close to “Terminator” imagery. Israel’s use of AI in its recent wars mark a leading instance. In early 2021, it launched Gospel, an AI tool that sorts through Israel’s vast array of digitized information to suggest targets for potential strikes. It also developed Lavender, which uses machine learning to filter out requested criteria from intelligence databases and narrow down lists of potential targets, including people. Lavender ranks people between 0 and 100 based on how likely it is they are a militant, an intelligence officer who used the systems told The Associated Press. The Israeli military says its analysts use AI-enabled systems to help identify targets but independently examine them together with high-ranking officers to meet international law, weighing military advantage against the collateral damage. For some, the revelation — and the death toll in Gaza after the Hamas-led Oct. 7, 2023, attacks on Israel — came too close for comfort to the kill lists of science fiction. “Well guys, Skynet is Here and its has a pleasant name (Lavender),” snarked one Redditor. Not quite — but “Terminator” terminology is so familiar to the masses that U.S. officials sometimes use it to frame the ethical debate around the military uses of AI. The conventional red line would be crossed, it seems, when humans play no role in AI targeting and killing. A state or other actor could use autonomous weapons to inflict lethal force on its enemies, military officials allow. That would mean a machine, as then-Vice Chairman of the Joint Chiefs of Staff Gen. Paul Selva described it in 2016, “like a Terminator that adds incredible amounts of complexity with no conscience to what happens on the battlefield.” What would come next, he called “the Terminator conundrum,” the problem of technology that can make life-or-death decisions and execute them before people have agreed on the law or the rules. “Skynet” and its cyborgs remain in the fictional realm. But in the fast-moving landscape of AI development, the ethical and moral questions raised by “The Terminator” are more relevant than ever. “The Skynet problem,” Cameron said in a 2024 video, “is an actual thing.” Related: Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive Related: Cisco Launches Low-Cost AI Models for Source Code Security Related: AI Data Centers Are Being Built Faster Than They Can Be Secured
securityweek.comJul 28, 2026extracted
CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws
The US Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic’s powerful Mythos AI model to scan and audit federal government software for security vulnerabilities, according to a report from Reuters. Citing three sources familiar with the matter, Reuters reported that CISA is utilizing Mythos to scan code repositories across federal agencies. The operation aims to proactively discover and patch security bugs that could otherwise be exploited by foreign intelligence agencies and cybercriminals. The audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking exercises across the federal landscape. Two sources stated that the AI-driven initiative has already uncovered a “large number” of software vulnerabilities. However, specific details regarding the severity of the flaws, the impacted agencies, or the volume of software reviewed have not been disclosed. Neither Anthropic nor CISA provided formal on-the-record comments to Reuters regarding the operation. Tensions between Anthropic and federal officials spiked dramatically earlier this year after the company refused administration demands to remove built-in safeguards restricting its models from being used for autonomous weaponry or domestic surveillance. In response, the Pentagon designated Anthropic as a supply-chain risk, a classification typically reserved for foreign firms suspected of espionage. The National Security Agency (NSA) is also believed to be using Mythos in its operations. Late last month, a US official told the Associated Press (AP) that one of Anthropic’s artificial intelligence models had identified vulnerabilities in highly sensitive and secure US government computer systems during a testing exercise. While the private application of Mythos has accelerated within the US intelligence and defense communities, Anthropic’s public-facing rollouts have triggered separate regulatory battles. When the company launched its public version of the model in early June, called Fable, concerns from the White House regarding foreign nationals accessing the tool prompted an abrupt administrative demand to restrict access. The ensuing standoff led to a temporary global shutdown of the Fable model, which was only lifted last week. Related: When Information Becomes the Attack Surface – Understanding AI Agent Traps
securityweek.comJul 7, 2026extracted
Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says
A U.S. official told The Associated Press on Tuesday that one of Anthropic’s artificial intelligence models had identified vulnerabilities in highly sensitive and secure U.S. government computer systems during a testing exercise. The official, who spoke on the condition of anonymity to discuss the matter, said Anthropic had teamed up with U.S. intelligence agencies to conduct tests using the company’s Mythos model. It had identified certain vulnerabilities within hours, but that does not mean the model was able to exploit them within that time, the official said. The official said the testing was done through an Anthropic initiative called Project Glasswing, which brought together tech giants and other companies in hopes of securing the world’s critical software from “severe” fallout that the Mythos model could pose to public safety, national security and the economy. Democratic Sen. Mark Warner of Virginia had briefly mentioned the testing during a June 11 hearing before the Senate Committee on Banking, Housing, and Urban Affairs. Warner had said, “This tool broke into almost all of our classified systems, not in weeks but in hours.” He attributed the information to the head of the National Security Agency and U.S. Cyber Command, who is Gen. Joshua Rudd. The NSA declined to comment on the matter in an email. An Anthropic spokesman also declined to comment. Despite the recent cooperation between Anthropic and U.S. agencies to test for vulnerabilities, tensions between the California company and the Trump administration have been growing. Anthropic has raised concerns over how the U.S. military would use its AI, while the administration has restricted the use of some of Anthropic’s models. The administration issued a directive earlier this month requiring Anthropic to prevent foreign nationals from using its latest artificial intelligence models, known as Fable 5 and Mythos 5. Anthropic released Fable widely earlier this month. That model is a limited version of the more advanced Mythos, to which the company has tightly limited access due to cybersecurity fears. The directive came 10 days after President Donald Trump signed an executive order to establish a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release. Participation by AI developers would be voluntary, the order said. Anthropic said it disabled the models for all of its customers to comply with the administration’s directive. The AI giant said it did not believe the steps taken by the government were warranted by the concern it flagged about a potential security issue. A group of cybersecurity executives has also asked the Trump administration to lift its directive, saying the move could help U.S. adversaries more than it hurts them. More than 100 cybersecurity experts and leaders from companies including Adobe and Nvidia told the government in a letter that Anthropic’s Mythos models are “quite good” at finding flaws in software and weaponizing exploits — but they are ”not uniquely good at these tasks.” Many of the letter’s signatories said they regularly use other foundation and open-source models for security audits and training. The letter said it is dangerous to take away the best cyber defense capabilities “without a good reason” when America’s adversaries are rapidly advancing. Related: Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere Related: The Mythos Moment: Enterprises Must Fight Agents with Agents
securityweek.comJun 24, 2026extracted
French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation
French President Emmanuel Macron on Wednesday urged the world’s wealthy democracies to work together on regulating advanced artificial intelligence systems, speaking at a high-level meeting that included top AI executives. OpenAI CEO Sam Altman issued a similar plea at the Group of Seven summit of major industrialized nations in France, saying an “international forum” is needed for countries to draw up AI guardrails. He said the task of AI safety should not be left to tech companies. Overshadowing the discussion on AI was President Donald Trump’s administration’s directive last week, preventing foreign nationals from using Anthropic’s newest and most powerful artificial intelligence models. Macron said it was a “good thing” that U.S. officials recognize that so-called frontier AI models could be dangerous, but he also criticized it as a “strictly nationalist” reaction. The remarks followed a G7 working lunch that brought together AI industry figures, including leaders of three of the most powerful AI companies — Altman, Google DeepMind CEO Demis Hassabis and Anthropic CEO Dario Amodei — on the theme of “ensuring a safe, rapid and effective deployment of artificial intelligence.” Trump’s feud with Anthropic has unsettled many outside the US Ahead of the meeting, the White House’s dispute with Anthropic fueled distrust in Europe about American dominance of AI and tech ecosystems. The company was forced on Friday to take its latest artificial intelligence models, known as Fable 5 and Mythos 5, offline to comply with the directive. The AI giant said it did not believe the steps taken by the government were warranted by the concern it flagged about a potential security issue. When asked by a reporter whether France and other G7 countries had asked Trump to permit access to Anthropic’s latest AI models, Macron said he made a forceful plea for the U.S. not to keep cutting-edge AI to itself. Macron warned of a possible drop in value for U.S. firms pioneering the disruptive technology if they switch off access like a light switch. Macron backed his appeal for partnership among key democracies with an insurance policy: France, he said, will boost funding for its own AI industry, so it’s not left behind if international cooperation breaks down. Democratic countries ultimately want to prevent authoritarian regimes from getting access to advanced AI systems, Macron said. “So let us move forward together,” he said. “Our relevant agencies must first cooperate so that, in the areas of security and cybersecurity, we have a smooth government-to-government relationship.” Altman said in his lunch speech, attended by the G7 leaders and more than a dozen AI bosses, that the technology’s future must be shaped by people, democratic institutions and society as a whole, “not just by the companies building the most capable systems.” “We need an international forum for discussion that establishes globally accepted standards for testing, provides expert and impartial analysis of capabilities and risks, and serves as a venue for cooperation among nations,” he said. Europeans have sought checks on American AI dominance Even before the Anthropic episode, there was growing distrust of American companies dominating AI and other tech ecosystems. In Brussels, the European Commission unveiled a tech sovereignty package this month with plans to boost homegrown AI, and at the Vatican, the pope last month called for robust regulation of artificial intelligence. Trump’s intervention with Anthropic highlighted how Europe, Canada or other countries “can be put in an extremely vulnerable position” if they are cut off from advanced AI models, said Zach Meyers, director of research at CERRE, a Brussels-based think tank. “There is a general anxiety about the state of Europe, the fact that we’re relying on other countries for quite important strategic infrastructure and a desire to do something about it, whatever that is,” Meyers said. At the G7, Aidan Gomez, CEO of Canada’s Cohere AI, said a “number of proposals” were discussed on working together on AI governance and regulation. “I think the consensus was we need something,” he told The Associated Press. He said he told the gathering that democracies should focus their efforts on making sure the G7 “doesn’t just produce the most capable AI, but also the second most capable AI,” a reference to the U.S. and China being the world’s only two major AI powers. Meta’s chief AI officer, Alexandr Wang, also attended the meeting, along with the heads of smaller AI labs, including France’s Mistral, Germany’s Black Forest Labs, Italy’s Domyn, Sakana AI of Japan and United Kingdom-based Synthesia. The G7 comprises France, the United States, Canada, Germany, Italy, Japan and the UK. Brazil, India, Kenya and South Korea were among guest nations invited to participate in some discussions. Related: AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask Related: Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation Related: Industry Reactions to Claude Fable 5: Feedback Friday
securityweek.comJun 20, 2026extracted
Intelligence, l’alleanza Five Eyes accusa la Cina: “Sfrutta Linkedin per campagne di spionaggio”
Si rinnovano le accuse di spionaggio dell’alleanza contro Pechino, che in questo caso utilizzerebbe il portale LinkedIn. L’alleanza Five Eyes (Usa, Nuova Zelanda, Uk, Canada, Australia) ha lanciato delle forti accuse contro i servizi di sicurezza della Cina, che sfrutterebbero LinkedIn per campagne di spionaggio. L’obiettivo sarebbe quello di rubare informazioni riservate a professionisti della sicurezza in tutto il mondo. LinkedIn ma non solo. L’intelligence di Pechino, infatti, secondo quanto ha sottolineato l’Associated Press, avrebbe impiegato anche altre piattaforme come Indeed e Upwork. Dalle informazioni in possesso in possesso dei cinque Paesi è emerso che diversi agenti cinesi agirebbero fingendo di essere consulenti delle risorse umane. E lavorerebbero per conto di aziende legittimamente attive. Il ministro della Sicurezza britannico, Dan Jarvis, ha esortato chiunque possa essere un potenziale bersaglio dei servizi di intelligence cinesi a prestare la massima attenzione. Preoccupazioni sull’AI cinese Il rapporto e le preoccupazioni sull’intelligence cinese – e sull’AI – rientrano anche nel confronto geo-economico con Pechino. Gli agenti cinesi “si fingono dipendenti di società di consulenza private, think tank o agenzie di risorse umane e pubblicano annunci di lavoro online”. In particolare, sottolinea il Daily Herald, l’obiettivo è quello di “inondare le piattaforme di networking professionale di profili falsi e offerte di lavoro rivolte a ufficiali militari, spie“. E in generale a tutti coloro che possono accedere a informazioni riservate. Il pericolo sarebbe serio e su vasta scala. In tal senso, si è trattato della prima volta in cui i membri del gruppo di condivisione delle informazioni dei Five Eyes hanno pubblicato un annuncio simile. La risposta di Pechino Oltreché lavoratori direttamente operativi nella Difesa – in particolare nella regione indo-pacifica – potrebbero essere colpiti anche giornalisti, dipendenti di think tank o consulenti di vario tipo. In ogni caso il portavoce del Ministero degli Affari Esteri della Repubblica Popolare Cinese, Mao Ning ha smentito categoricamente le accuse. E in più ha affermato che tale minaccia di spionaggio è “di per sé ironica“.
cybersecitalia.itJun 4, 2026extracted
Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say
Russia’s intelligence agencies have grown more aggressive in their efforts to steal Western technology and defense secrets as sanctions squeeze the country’s wartime economy, three senior European intelligence officials told The Associated Press. Moscow’s agents are building fake companies, recruiting middlemen and deploying cyber spies and hackers who are gathering information that could also be used to attack key infrastructure, they said. Four years of international sanctions have hampered Moscow’s ability to procure machinery, technology and research from Europe, while the grinding war in Ukraine has taxed key industries and pushed the country toward a potential financial crisis. “They really know what they need,” and are putting “serious effort” into acquiring advanced machine tools, factory equipment, research and dual-use technology, said Christoffer Wedelin, deputy head of operations at the Swedish Security Service. Russia seeks high-end research, defense technology and software In Sweden, Russia is targeting the defense industry and high-end research on the country’s most advanced weaponry, such as the Gripen fighter jet, Wedelin said. It is also trying to procure camera and laser technology developed for civilian purposes that could be integrated into Russian weapons systems, he said. Moscow is also trying to steal technology to help it keep pace — or give it an edge — against the West in the decades ahead, said Juha Martelius, the director of Finland’s Security and Intelligence Service. “We’re talking about space technology, quantum … arctic technology, marine technology,” he said, adding that space technology is something Russia needs “right now,” without elaborating. Countries use such technology for satellite imaging, communications and navigation. Russia also needs sanctioned computer technology and software updates for machine tools, Martelius said. On Wednesday, Anne Keast-Butler, the director of the U.K’s signals intelligence agency, accused Russia of “relentlessly targeting” the U.K. and its European allies, by stealing technology and plotting sabotage and assassination attempts. In May, Swedish police arrested two people on suspicion of violating sanctions relating to a company in Turkey that has made dozens of shipments of metalworking and metal-turning machine tools to Russia. As the schemes to acquire technology grow more complex, companies need to be more aware they could unwittingly become part of Russia’s war supply chain, Wedelin said. “All of the security and intelligence services in Russia are helping out on the state’s efforts to get this,” he said. Intelligence officials say Russia cares less about getting caught Moscow is also deploying cyberattacks against European firms and critical infrastructure in an attempt to gather information, which it could exploit “when they get the chance and when it serves their purpose,” Wedelin said. He pointed to an attack on a Swedish power plant last year. Russia-linked actors tried to “destroy” the plant but failed because the system detected the intrusion, Wedelin said. He said the attack was partly aimed at undermining Western support for Ukraine. Before then, Sweden’s security services had mostly observed reconnaissance for potential attacks, intelligence gathering or activity linked to cybercriminals. The attack marked a “switch” in Russia’s modus operandi, Wedelin said. “They’re no longer caring as much about potential attribution after their activities, so they are taking greater risks to achieve their goals,” he said. Problems are mounting for Russia’s economy Russia’s increasingly aggressive tactics may reflect mounting internal concerns about its economy, which “is not doing well at all,” said Kaupo Rosin, the head of Estonia’s Foreign Intelligence Service. About a third of Russia’s gross domestic product currently goes to the war effort, Martelius said. The war and ensuing sanctions have slowed growth and fueled stubborn inflation. Russian officials planned to have a budget deficit of 3.7 trillion rubles ($52.1 billion) for the whole of 2026 and had already reached about 3.4 trillion rubles ($47.9 billion) by the end of February, Rosin said. The Iran war that erupted on Feb. 28 has provided a boost by causing oil prices to soar. The U.S. has granted sanctions waivers for the sale of Russian oil and the U.K. watered down its sanctions in an attempt to lower global fuel costs. Increased revenue since then has likely improved Russia’s budget, but “it doesn’t save them,” Rosin said, adding that if Western pressure persists, Moscow could face a financial crisis toward the end of the year. Rosin said intelligence seen by his agency shows a gloomier outlook among Russian officials over the past six months, with the narrative of “total victory” in Ukraine having vanished. Keast-Butler, of British intelligence, said almost 500,000 Russian soldiers have been killed in Ukraine since the full-scale invasion in 2022. Russia and Ukraine have mostly kept their combat casualty figures under wraps. Stalled progress on the battlefield and economic woes have many Russian officials privately asking “what is this all for,” Rosin said, citing the intelligence reports. Martelius, of Finland’s intelligence service, said that while some reports on the war in Ukraine may have been “sanitized” before reaching President Vladimir Putin’s desk, he believes the Russian leader has a fairly clear picture of the economic challenges. But that does not mean there will be political change. It is “very dangerous … to start analyzing Russia as if it is some country like ours,” Martelius said. “It is not.”
securityweek.comMay 30, 2026extracted
OpenAI prepares ChatGPT for the election misinformation wave
OpenAI prepares ChatGPT for the election misinformation wave AI-generated election misinformation could shape public opinion and influence the lives of millions of people. To address those risks, OpenAI outlined a series of safeguards ahead of the 2026 election cycle. The company said its efforts will focus on helping users access voting information, supporting cybersecurity defenders, and improving transparency around AI-generated content. “People already use ChatGPT to ask practical questions in their preferred languages about civic events: how to register, where to vote, what deadlines apply, what’s happening with a developing news event, or where to find official election results,” OpenAI said. Beginning this fall in the United States and Brazil, ChatGPT will provide live election results from The Associated Press as vote counts are reported on election night. In the United States, OpenAI will partner with Democracy Works to provide voting and registration information, including polling locations and other election logistics, when users ask election-related questions. “Globally, we will continue to refine the way web search surfaces helpful information with source links,” the company added. Researchers recently found that generative AI systems can produce election misinformation when prompted in specific ways, raising concerns about how AI could influence public opinion and spread deceptive political content. OpenAI also warned that people are increasingly using AI tools to create content shared on social media, messaging apps, and websites, adding to concerns about misleading deepfakes and manipulated media. “To help combat misleading ‘deepfakes’, we are investing in a multi-layered provenance approach that will equip people to verify whether content they’re seeing has been created or modified with AI,” the company stated. Last week, OpenAI introduced a partnership to bring SynthID digital watermarks to images generated through ChatGPT, Codex, and the OpenAI API. The watermark is designed to remain detectable even after screenshots or image modifications. OpenAI also stated that it will continue restricting the use of its tools for political impersonation, voter suppression, and deceptive campaign activity. The company added that it is working on systems designed to improve transparency around AI-generated content and synthetic media. Since the invasion of Ukraine, Russia has repeatedly been accused of trying to destabilize countries backing Kyiv through cyberattacks, disinformation campaigns, and other forms of pressure. Last year, ahead of Germany’s election, Russian-linked bot networks circulated fake videos and fabricated media reports in what German authorities described as a coordinated interference campaign aimed at influencing public debate. “We believe it’s important that people can use AI systems to learn about, explore, and discuss political issues while limiting misuse by bad actors,” OpenAI concluded.
helpnetsecurity.comMay 28, 2026extracted
Google blocca un attacco basato su una zero-day scoperta da un LLM: è la prima volta
Google sostiene di aver fermato un gruppo criminale che stava preparando un’operazione di mass exploitation basata su una vulnerabilità zero-day che, secondo il Google Threat Intelligence Group (GTIG), sarebbe stata scoperta e “weaponized” con il supporto di un modello AI. Per GTIG è la prima volta in cui il gruppo identifica un exploit zero-day che ritiene sviluppato con l’aiuto dell’intelligenza artificiale. “Il caso scoperto da Google GTIG è importante perché mostra, probabilmente per la prima volta in modo concreto, l’uso dell’intelligenza artificiale per sviluppare un exploit zero-day reale”, commenta Pierluigi Paganini, analista di cyber security e Ceo Cybhorus. Indice degli argomenti Il caso è rilevante non solo per il fatto in sé, ma per il tipo di salto che rappresenta. Finora il grosso del dibattito sull’abuso criminale dell’AI, si era infatti concentrato su phishing, social engineering, traduzioni, malware e automazione. Qui, invece, il punto è diverso: l’AI entra nel tratto più delicato della catena offensiva, quello della scoperta della falla e della sua trasformazione in exploit operativo. Secondo Google, la vulnerabilità riguardava un tool open source, web-based, di system administration, e consentiva di aggirare l’autenticazione a due fattori. L’azienda non ha reso pubblico né il nome del prodotto né quello del gruppo coinvolto, ma afferma di aver lavorato con il vendor per la responsible disclosure, di aver avvisato l’azienda colpita e le forze dell’ordine, e di essere riuscita a interrompere l’operazione prima che producesse danni. Un elemento centrale è proprio l’attribuzione tecnica. Google dice di non ritenere che sia stato usato Gemini e, secondo l’Associated Press, ritiene anche improbabile l’uso di Claude Mythos; non ha però indicato quale modello sia stato effettivamente impiegato. La convinzione che un LLM sia stato usato nasce dalla struttura del codice osservato: docstring molto didascaliche, formattazione “da manuale”, help menu particolarmente puliti e perfino un CVSS hallucinated, cioè un punteggio di severità inventato. “Non si tratta semplicemente di hacker che usano chatbot AI, ma di attori malevoli che avrebbero sfruttato modelli linguistici avanzati per identificare e trasformare una vulnerabilità in un attacco operativo. Il rischio è elevato perché gli zero-day sono vulnerabilità sconosciute e prive di patch, quindi estremamente pericolose”, spiega Paganini. Inoltre, “Google evidenzia che il bug era di tipo logico e complesso, una categoria in cui gli LLM potrebbero diventare particolarmente efficaci rispetto agli strumenti tradizionali. Ancora più preoccupante è il fatto che l’exploit sarebbe stato preparato per una campagna di massa, segnale che il cybercrime potrebbe iniziare a industrializzare l’uso offensivo dell’AI, abbassando le barriere tecniche necessarie per creare attacchi avanzati”, mette in guardia Paganini. Il dettaglio forse più interessante, per chi si occupa di difesa, è la natura della falla. GTIG spiega che non si tratterebbe di un classico bug da memory corruption o input sanitization, ma di un logic flaw ad alto livello, legato a una trust assumption hardcoded. È proprio qui che Google vede un vantaggio crescente dei modelli AI più evoluti: meno efficaci nel ragionare su architetture complesse end-to-end, ma sempre più capaci di leggere il contesto del codice e individuare contraddizioni semantiche che scanner e fuzzer tradizionali faticano a far emergere. Questo sposta il problema per i team di sicurezza. Se l’AI diventa un acceleratore nella ricerca di vulnerabilità logiche, il vulnerability management non può più limitarsi al binomio patching più scanning. Servono revisione del codice orientata alla logica di business, threat modeling più vicino ai flussi di autenticazione e autorizzazione, e una verifica più attenta delle eccezioni hardcoded che spesso nascono per comodità operativa e poi restano in produzione. Gli strumenti difensivi basati solo su pattern noti rischiano di perdere terreno proprio dove la semantica del software conta di più. Google aggiunge che non ci sono evidenze di un coinvolgimento diretto di un governo avversario in questo caso specifico. Allo stesso tempo, però, GTIG segnala che attori legati a Cina e Corea del Nord stanno già esplorando l’uso dell’AI per vulnerability research e sviluppo di exploit, anche con prompt ripetuti, dataset specializzati e workflow più automatizzati. Questo vuol dire che il confine tra sperimentazione e uso operativo si sta assottigliando rapidamente. Insomma, è la conferma di un timore già registrato. L’AI può già comprimere i tempi tra analisi del software, individuazione della falla e preparazione dell’exploit. Se questa capacità si diffonde, la finestra a disposizione dei difensori per rilevare e contenere una zero-day rischia di ridursi ancora. Il caso intercettato da Google arriva mentre il settore sta ancora misurando la portata di modelli come Claude Mythos, presentato da Anthropic ad aprile 2026 come un sistema con capacità eccezionali nell’individuazione di vulnerabilità, tanto da essere distribuito in modo molto limitato. Se un lato di questa corsa mostra il potenziale difensivo dell’AI per trovare e correggere bug prima degli attaccanti, l’altro lato conferma che la stessa soglia tecnologica può essere riutilizzata in chiave offensiva. È questo il vero cambio di scenario: una minaccia nuova, perché più veloce, più scalabile e più difficile da intercettare con strumenti pensati per avversari ancora largamente umani. “Il confronto con un altro caso di cronaca che ha coinvolto Anthropic Mythos invita però a evitare allarmismi”, suggerisce Paganini. “Nei recenti test condotti su curl, un software open-source tra i più utilizzati al mondo per trasferire dati tramite Internet, l’AI ha trovato cinque presunti bug, ma solo uno era reale e a bassa gravità. Questo dimostra che l’AI non è ancora una ‘fabbrica automatica’ di zero-day, ma è già un potente acceleratore per ricercatori e attaccanti”. Dunque, “il vero rischio non è la sostituzione degli esperti umani, ma l’aumento della velocità e della scala degli attacchi. Per le aziende significa tempi di reazione sempre più ridotti e necessità di rafforzare patch management, threat intelligence e difesa proattiva. La cybersecurity entra così in una nuova fase: AI contro AI”, conclude Paganini.
cybersecurity360.itMay 12, 2026extracted
US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator
U.S. officials have announced a sweeping crackdown on Southeast Asian cyberscam operations as part of what U.S. Attorney Jeanine Pirro characterized Friday as a “new theater of war” launched by the Trump administration against Chinese transnational organized crime. The crackdown, led by a U.S. government Scam Center Strike Force, includes the Treasury Department’s sanctioning of a prominent lawmaker and 28 other people and companies accused of operating from Cambodia. Criminal charges also were filed against two Chinese nationals involved in a similar operation in Myanmar. The initiative includes a warrant to seize and shut down a major online recruitment channel on the Telegram messaging app and freezing hundreds of millions of dollars in illicit assets, Pirro said in a virtual press conference connecting her from Washington to journalists in Asia. Cybercrime has flourished in Southeast Asia in recent years, particularly in Cambodia and Myanmar, with illegal operations making mammoth profits from victims around the world, according to United Nations experts and other analysts. Americans lost nearly $21 billion to cyber-enabled crimes and online scams in 2025 alone, according to the Federal Bureau of Investigation. The illicit industry is closely involved in human trafficking, with foreign nationals employed to run romance and cryptocurrency scams, often after being recruited with false offers of legitimate jobs and then forced to work in conditions of near-slavery. The Scam Center Strike Force comprises Pirro’s U.S. Attorney’s Office for the District of Columbia, the Department of Justice’s Criminal Division, the FBI and the U.S. Secret Service. The most prominent target of the crackdown is Kok An, a Cambodian senator and prominent businessman described by the Treasury Department as a “scam center kingpin.” The department’s Office of Foreign Assets Control announced sanctions against Kok An and associates for their roles in a network that has allegedly defrauded U.S. citizens of millions of dollars. They include blocking Kok An’s assets in the United States and prohibiting U.S. entities from doing business with him. The Associated Press was unable to contact Kok An or any of his representatives for comment. “His Excellency Kok An is a Cambodian Senator and he was elected by elections, and as a senator he has parliamentary immunity,” said Chea Thyrith, a Cambodian Senate spokesperson, who added that only the U.S. side could speak clearly about the sanctions. Kok An is at least the second Cambodian senator to be sanctioned by the U.S. In 2024, Washington acted against another top tycoon, Ly Yong Phat, who also was accused of being connected with forced labor, human trafficking and lucrative online scams. Pirro said the latest crackdown was set in motion in November when FBI agents sent to Thailand accessed copious evidence seized from an abandoned scam center in Myanmar, including more than 8,000 phones and 1,500 computers. That led to charges of wire fraud conspiracy against two Chinese nationals, Huang Xing Shan and Jiang Wen Jie, who were managers of the compound before seeking to reestablish their operations in Cambodia. They are being held by Thai authorities for immigration violations and the U.S. is seeking their extradition, Pirro said. Cambodian lawmakers unanimously adopted a new law in March targeting online scam operations with up to life in prison, following a government pledge to shut down the centers by the end of April. In January, Cambodia extradited to China another alleged scam kingpin, Chen Zhi, the founder of business and banking conglomerate Prince Holding Group, even though U.S. authorities had sought custody after indicting him last year for allegedly running a huge scam operation. Related: US Sanctions Myanmar Militia Involved in Cyber Scams
securityweek.comApr 27, 2026extracted
Most Serious Cyberattacks Against the UK Now From Russia, Iran and China, Cyber Chief Says
The most serious cyberattacks in the U.K. are now carried out by hostile nations including Russia, Iran and China, the head of the U.K.’s National Cyber Security Centre (NCSC) said in a speech Wednesday. Richard Horne, the head of the NCSC — part of the U.K’s signals intelligence agency GCHQ — warned that the U.K. is living through “the most seismic geopolitical shift in modern history.” British businesses, he said, need to prepare themselves to defend against cyberattacks because the U.K. could be targeted “at scale,” if it became involved in an international conflict. In recent months, authorities in Sweden, Poland, Denmark and Norway have all warned that hackers linked to Russia have targeted their critical infrastructure including power plants and dams. Horne said the NCSC currently handles around four “nationally significant” cyber incidents a week and while criminal activity, such as ransomware, remains the most common problem, the most serious threat comes from cyberattacks carried out directly or indirectly by other states. Dan Jarvis, the U.K. security minister, said the NCSC handled more than 200 nationally significant incidents last year — more than double the year before. Jarvis and Horne spoke at the CyberUK conference in the Scottish city of Glasgow. Cyber operations become more sophisticated In December, Blaise Metreweli, the head of Britain’s Secret Intelligence Service, or MI6, said the world is more dangerous and contested now than it has been for decades and that the U.K. is operating in a space between peace and war. “Let’s be clear, cyberspace is part of that contest,” Horne said. China’s intelligence and military agencies display an “eye-watering level of sophistication in their cyber operations,” while Iran is “almost certainly using cyber activity to support the repression of British individuals on our streets who are seen as a threat to the regime,” he said. Moscow, meanwhile, is using tactics and techniques honed during its war in Ukraine and is “moving them beyond the battlefield,” Horne said, pointing to “sustained Russian hybrid activity” targeting the U.K. and Europe. Companies, he said, must learn how cyber operations have been used in conflict situations in order to boost their own resilience. Hostile states, Jarvis said, know the most effective way to act is “not to confront us directly, but to quietly hollow us out,” by hacking logistics systems which move goods, for example, or compromising businesses. He compared a cyberattack at Britain’s biggest automaker Jaguar Land Rover — that dented Britain’s economic growth late last year — to masked criminals turning up at car dealerships, breaking glass, smashing computers and stealing vehicles from the parking lot. AI, Jarvis said, is also making it easier for adversaries to attack by finding vulnerabilities in systems “faster than any human team can patch them.” He called for AI companies to work with the U.K. government to develop bespoke programs to boost Britain’s cyber defenses. European countries report cyber attacks on infrastructure In a conflict situation, Horne said, the U.K. would likely face cyberattacks at scale but — unlike with ransomware — companies will not be able to pay their way out in order to recover data and access to systems. For that reason, he said, every organization needs to understand the “full extent” of the risk they face and improve their cyber defenses before it is too late. On Friday, Swedish authorities said that a pro-Russian group with links to Russia’s security and intelligence services was behind a cyberattack on a heating plant last year. Carl-Oskar Bohlin, Sweden’s minister for civil defense, compared it to incidents in Poland in December, when coordinated cyberattacks hit combined heat and power plants supplying heat to almost 500,000 customers, as well as wind and solar farms. Poland later said evidence indicated hackers were “directly linked to the Russian services.” Norwegian authorities also warned that a hack in April 2025 which affected water flows from a dam was linked to Russia while in December, Danish authorities said another attack on a water utility company in 2024 left some houses without water. The four cyberattacks are among more than 155 incidents of disruption — including arson, sabotage and espionage — linked to Russia or its proxies by Western officials and tracked by The Associated Press since Moscow’s full scale invasion of Ukraine in February 2022. Other incidents linked to Russia by European officials include an attack on German air traffic control, attempts to gain access to Signal and WhatsApp accounts belonging to officials and journalists and attempts by hackers linked to Russian military intelligence to steal users’ sensitive data by exploiting a weakness in some internet routers.
securityweek.comApr 22, 2026extracted
Sweden Blames Pro-Russian Group for Cyberattack Last Year on Its Energy Infrastructure
Sweden said Wednesday that a pro-Russian group with links to Russia’s security and intelligence services was behind a cyberattack on a heating plant last year. The announcement followed warnings from officials in Poland, Norway, Denmark and Latvia that Russia is attacking critical infrastructure across Europe. In what was Sweden’s first public mention of the attack, the country’s minister for civil defense, Carl-Oskar Bohlin, said it targeted a heating plant in western Sweden but the attack failed. He gave no further details. Bohlin compared it to incidents in Poland in December, when coordinated cyberattacks hit combined heat and power plants supplying heat to almost 500,000 customers, as well as wind and solar farms. Poland later said evidence indicated hackers were “directly linked to the Russian services.” Bohlin said the cyberattacks in Sweden and Poland are directed at systems controlling critical infrastructure with potentially serious consequences for society. The attacks show Russia is engaging in risky and careless behavior, he said. The attacks are among more than 150 incidents of sabotage and malign activity across Europe tracked by The Associated Press and linked to Russia by Western officials since Moscow’s full-scale invasion of Ukraine in February 2022. Officials say a goal of the attacks is to undermine support for Ukraine, spread fear and discord in European societies and drain investigative resources. The Kremlin has previously denied carrying out any kind of sabotage campaign across Europe. Danish officials in December said cyberattacks carried out by Russia in 2024 on a water utility left some houses without water, while in August, Norwegian police said pro-Russian hackers remotely opened a valve in a dam, allowing water to pour out. In March, Latvia’s State Security Service said a train and railway infrastructure were set on fire by people acting in Russia’s interests.
securityweek.comApr 15, 2026extracted
Poland Faced a Surge in Cyberattacks in 2025, Including a Major Assault on the Energy Sector
Poland experienced 2½ times more cyberattacks in 2025 compared to the previous year, and the numbers are constantly rising, a government official said Tuesday. The attacks included a destructive infiltration of the country’s energy system in December that was believed to be unprecedented among NATO and European Union members, and was suspected of originating in Russia. Over the last year, Poland was the target of 270,000 cyberattacks, Deputy Minister of Digital Affairs Paweł Olszewski said Tuesday. “We’ve been waging a war in cyberspace for many years now,” the official said. “The number of incidents and attacks has been increasing significantly and radically year after year.” The government, led by Prime Minister Donald Tusk, has beefed up its cyber defenses since the start of Russia’s full-scale invasion of Ukraine on Feb. 24, 2022, in response to what it believes to be a rising threat from Russia. Energy system attack During the morning and afternoon of Dec. 29, coordinated cyberattacks hit a combined heat and power plant supplying heat to almost 500,000 customers, as well as multiple wind and solar farms in Poland. Polish authorities suspected the cyberattacks were done by a single “threat actor,” with multiple experts pointing to culprits linked to Russian secret services. The electricity supply wasn’t disrupted, but the nature of the sabotage alarmed Polish authorities so much that the agency CERT Polska, or Computer Emergency Response Team Poland, issued a public report in late January on technical details of the incident and asked the cyber community for any input on what happened. “The attack was a significant escalation,” CERT head Marcin Dudek told The Associated Press. “We’ve had such incidents in the past, but they were of the ransomware type, where the motivation of the attacker is financial,” Dudek said. “In this case, there was no financial motivation — the motivation was just destruction.” He said that Poland has seen only a few destructive incidents in the past and none of them were in the energy sector. Dudek said that he wasn’t aware of any other destructive cyberattacks on the energy sector in either NATO or EU countries. There have been espionage incidents and activist groups causing marginal damage, but “advanced attacks” like the December one in Poland are likely unprecedented, he said. Had it targeted even larger energy units, it could have substantially impacted the stability of Poland’s energy grid, Dudek said. The Polish secret services haven’t yet publicly identified an alleged culprit. Dudek’s team is authorized only to describe the modus operandi and point to a likely “threat actor” — cyber jargon for an individual or group engaging in malicious activity. Dragonfly or Sandworm The CERT analysis looked at the Internet infrastructure used in the Polish attack, including domains and IP addresses, and found that they had been used previously by a Russian threat actor known as “Dragonfly,” and also called “Static Tundra” or “Berserk Bear.” Dudek said Dragonfly has been known to target the energy sector, but so far not with a destructive attack. According to an alert issued by the FBI in the United States in August 2025, Dragonfly is a cybersecurity cluster associated with FSB Center 16, a key unit within Russia’s Federal Security Service. Experts unrelated to Polish authorities agree that the traces of the December attack lead back to Russia. ESET, one of the largest cybersecurity companies in the EU, analyzed the malware used in the attack and concluded the culprit likely was “Sandworm,” another possible Russian actor previously associated with destructive attacks in Ukraine. The U.S. government has in the past attributed Sandworm to the Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation, or GRU. Anton Cherepanov, senior malware researcher at ESET, told The Associated Press that “the use of data-wiping malware and its deployment” in the Polish case “are both techniques commonly employed by Sandworm.” “We are not aware of any other recently active threat actors that have used data-wiping malware in their operations against targets in European Union countries,” Cherepanov added. Whether Dragonfly or Sandworm, it would an actor previously affiliated with Russia. “Whether it’s these Russians or those Russians is a detail,” Cherepanov said. The Russian Embassy in Warsaw didn’t respond to requests for comment. Related: Hacking Attempt Reported at Poland’s Nuclear Research Center Related: 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos
securityweek.comMar 24, 2026extracted
Iran Built a Vast Camera Network to Control Dissent. Israel Turned It Into a Targeting Tool
The role of Israel’s hijacking of Iran’s street cameras in the killing of the country’s supreme leader underscores how surveillance systems are increasingly being targeted by adversaries in wartime. Hundreds of millions of cameras have been installed above shops, in homes and on street corners across the world, many connected to the internet and poorly secured. Recent advances in artificial intelligence have enabled militaries and intelligence agencies to sift through vast amounts of surveillance footage and identify targets. On Feb. 28, Israel vividly demonstrated the potential of such systems to be hacked and used against adversaries when Israel tracked down Iranian leader Ayatollah Ali Khamenei with the help of Tehran’s own street cameras – despite repeated warnings that Iran’s surveillance systems had been compromised, according to interviews and an Associated Press review of leaked data, public statements and news reports. The use of hacked surveillance cameras among other intelligence in the operation to kill Khamenei was described to the AP by an intelligence official with knowledge of the operation and another person who was briefed on the operation. Neither was authorized to speak with the media and both shared information on condition of anonymity. Iran has installed tens of thousands of cameras in its capital in response to waves of protests, most recently in January, when massive nationwide demonstrations ended in a bloody crackdown that killed many thousands of Iranians. That Tehran’s cameras were compromised was no secret: the city’s cameras were repeatedly hacked starting in 2021, and last year, a senior Iranian politician warned publicly that cameras had been compromised by Israel, posing a national security threat. Conor Healy, director of research at surveillance research publication IPVM, said Khamenei’s killing illustrates a pressing security dilemma for governments seeking to quash dissent. “The irony is that the infrastructure authoritarian states build to make their rule unassailable may be what makes their leaders most visible to the people trying to kill them,” Healy said. “Do you trust who is watching?” Warning signs For years, cybersecurity experts have warned that cameras could be hacked for war. In 2019, security engineer Paul Marrapese discovered he could easily hack millions of cameras from the comfort of his home office in California. Despite speaking up repeatedly since, the number of unprotected cameras only continues to grow. A scan of unprotected camera feeds this year turned up nearly three million hits in almost every country in the world, Marrapese told AP, including nearly 2,000 cameras in Iran alone. “There are millions and millions and millions of these throughout the world,” Marrapese said. Many, he added, are trivially easy to hack: “They’re just dumb little things. … It’s fish in a barrel.” Companies have advertised cameras hooked up online, accessible with cellphones, with feeds easily diverted by hackers. Many are installed with minimal security by unsophisticated users who fail to set up passwords or install security patches. Securing cameras takes constant vigilance, but hacking them takes identifying just one exposed vulnerability, such as an outdated system or a generic password like “1234.” Even surveillance systems set up by governments on networks sealed off from the internet are vulnerable: It takes just one insider turncoat to compromise such systems. “Humans are kind of the weakest link,” Marrapese said. “There’s really only so much you can do.” Eyal Hulata, Israel’s former national security adviser and a senior fellow at the Foundation for the Defense of Democracies, said Israel is under constant cyberattacks from Iran but has so far been able to defend against it. “There is high alert on all cyber fronts,” he said. For years, hacking cameras for war remained theoretical. But in 2023, Hamas hacked surveillance cameras in southern Israel ahead of its Oct. 7 attack, allowing the group to monitor Israeli army patrols and assisting the attack, according to Israeli media. That same year, a Ukrainian official told reporters that Russia attempted to hijack cameras near missile targets, a trend that continued in 2024 when Russians hacked cameras in Kyiv and last year, when they hacked cameras at border crossings. Experts say advances in AI have allowed militaries to overcome a critical hurdle in weaponizing hacked footage: sifting through huge amounts of video to identify people, vehicles, and other targets, a task that once took teams of analysts weeks or months but can now be done in real time. With a simple keyword search, AI can scan feeds and return results almost immediately. “It used to be that you could hack the cameras, but humans had to do the real work of figuring out where the person was,” said cryptographer and security expert Bruce Schneier. “With AI systems … you can do a lot more automatically.” The despot’s dilemma Iran’s cameras have been repeatedly hacked over the past few years. In 2021, an Iranian exile group leaked footage of abuses at Tehran’s notorious Evin prison. In 2022, another group claimed it hacked over 5,000 cameras around Tehran, dumping gigabytes of surveillance footage and internal data on a Telegram channel. Then, during a 12-day war last summer, Israel used Tehran’s cameras to track and bomb the location of a meeting of Iran’s Supreme National Security Council, injuring Iranian President Masoud Pezeshkian, according to Iranian lawmakers and an Israeli documentary. “All the cameras at our intersections are in the hands of Israel,” Mahmoud Nabavian, deputy chairman of the Iranian parliament’s national security committee, told Iranian media in September. “Everything on the internet is in their hands … if we move, they will find out.” The vulnerabilities have come amid Iran’s stepped-up use of surveillance cameras after a series of protests roiled the country. Subway cameras, for example, are used to detect when women don’t don the country’s mandatory hijab, or headscarf, using facial recognition to identify violators. But data collected to consolidate control creates a ripe target for hackers, said researcher Michael Caster, who investigated China’s sales of surveillance technology to Iran. “Malicious parties can more easily gain access,” Caster said. Iran in particular, long sanctioned by the West, faces difficulties in getting up-to-date hardware and software, often relying on Chinese-manufactured electronics or older systems. Pirated versions of Windows and other software are common. That makes it easier for potential hackers to target the country. The Financial Times earlier reported on the use of cameras in Khamenei’s killing. The person briefed on the operation who spoke to the AP said that for years almost all the traffic cameras in Tehran had been hacked and the information transferred to servers in Israel. At least one camera was at an angle that allowed Israel to track daily movements of people, such as where they parked their cars near Iran’s leadership compound, the two people said. Algorithms helped provide information including people’s addresses, routes they took to work and who protected them, according to the person briefed on the operation. That same person said the attack had been planned for months, but the operation was expedited once it was determined that Khamenei and his top officials would be in the leadership compound that morning. Israel’s prime minister’s office didn’t respond to request for comment. Col. Amit Assa, a former official with Israel’s Shin Bet domestic security service, said that such operations are powered by many sources of intelligence, such as undercover agents and bugged conversations. However, Assa says cameras play a key role because they allow intelligence officers to identify people, providing key confirmation in deciding on whether to strike. When you see a person’s face on a screen in the command center, it helps in making the decision to put your “finger on the yellow button, as we say,” he said. More cameras, more coverage Check Point Research, a cyber threat intelligence group, says Iranian hacking attacks on cameras have spiked since the beginning of the war, with surges of activity in Israel and Gulf countries such as Bahrain and the United Arab Emirates. Such hacks could help Iran monitor targets and assess damage after missile strikes, according to Gil Messing, Check Point Research’s chief of staff. “The more people are installing cameras … the more area is being covered by these cameras,” Messing said. “It is very easy to use in order to get extra eyes into different places.” Analysts estimate there are more than one billion security cameras installed worldwide, triple the number a decade ago. Hundreds of millions more are installed every year. Muhanad Seloom, assistant professor in security studies at the Doha Institute for Graduate Studies, said that oil-rich Gulf countries like Qatar have long known their petroleum facilities could be targeted in a war and had their systems tightly secured. But only recently have officials in the region realized that street cameras, too, could be weaponized. “I don’t think anyone anticipated that these traffic cameras would become targeting tools … there is alarm all over,” Seloom said. “How come Iran’s whole leadership has been decapitated on the first day? … It is a topic that is being talked about.” Across the region, governments are on high alert. Gulf monarchies have barred residents from filming or livestreaming footage of Iranian strikes, with the UAE arresting dozens of people for sharing video of the conflict online. Though aimed in part to protect the country’s reputation, the bans are also motivated by concerns that such footage could be exploited by the Iranian military, Seloom said. Earlier this month, Israel’s National Cyber Directorate said that it had warned hundreds of camera owners targeted by Iran and urged the public to change passwords and update software to starve off attacks. Ali Vaez, Iran project director at the International Crisis Group, said though hacking has long been a concern in the Middle East, its increasing use since the war began was “a wake-up call”. Still, he said there’s only so much that can be done to patch up vulnerabilities. “It’s a whack-a-mole,” Vaez said.
securityweek.comMar 24, 2026extracted
FBI Investigating ‘Suspicious’ Cyber Activity on System Holding Sensitive Surveillance Information
The FBI said this week that it is investigating “suspicious activities” on an internal system that contains sensitive information related to surveillance operations and investigations. The bureau is working to determine the scope and impact of the problem, according to a notification sent to members of Congress that says the unnamed culprit is using sophisticated techniques to exploit FBI network security controls. The notification, obtained Thursday by The Associated Press, says that the FBI on Feb. 17 began investigating abnormal log information related to a system on its network. “The affected system is unclassified and contains law enforcement sensitive information, including returns from legal process, such as pen register and trap and trace surveillance returns, and personally identifiable information pertaining to subjects of FBI investigations,” said the notification reviewed by The Associated Press. A pen register is a common surveillance tool that enables law enforcement to log phone numbers dialed by a particular line. The FBI confirmed the cyber incident in a statement but did not provide additional details. “The FBI identified and addressed suspicious activities on FBI networks, and we have leveraged all technical capabilities to respond,” the FBI said. “We have nothing additional to respond.” Neither the FBI statement nor the notification identified who might be responsible for the incident, but the bureau and other federal agencies have long been targets of foreign hackers seeking to spy on sensitive operations and decision-making. In this instance, the FBI said, the techniques being used were “sophisticated” and included leveraging a commercial internet service provider vendor’s infrastructure to exploit FBI network security controls.
securityweek.comMar 7, 2026extracted
AI come arma cognitiva: dall’ISIS alla tecnodestra, la nuova ingegneria della radicalizzazione
Alcune recenti inchieste hanno riportato al centro del dibattito un fenomeno che, pur non essendo del tutto nuovo, sta assumendo caratteristiche radicalmente diverse e di cui si parla poco: l’uso dell’intelligenza artificiale da parte di ISIS e di altri gruppi estremisti per creare contenuti falsi, diffondere propaganda online e reclutare nuovi membri. Si tratta di una tendenza preoccupante, osservata con crescente attenzione da servizi di intelligence, forze di sicurezza e ricercatori indipendenti. Secondo quanto riportato dalle fonti giornalistiche, le organizzazioni jihadiste starebbero infatti sperimentando strumenti di intelligenza artificiale generativa per produrre testi, immagini e soprattutto video sempre più sofisticati, capaci di apparire credibili e coerenti con i linguaggi contemporanei delle piattaforme social. La creazione di contenuti progettati per essere inseriti, senza attrito, negli ecosistemi digitali, ne mimano estetica, ritmo e codici comunicativi. Indice degli argomenti L’aspetto più rilevante delle inchieste citate è la constatazione che gli strumenti AI abbiano abbassato drasticamente le barriere all’ingresso. Tecnologie che fino a pochi anni fa richiedevano competenze avanzate, infrastrutture costose e team specializzati sono oggi disponibili attraverso piattaforme accessibili, spesso open source o comunque a basso costo. Questo consente anche a gruppi frammentati, sotto pressione militare o logistica, di mantenere una presenza digitale continua e adattiva. Come confermato da fonti giornalistiche internazionali, l’intelligenza artificiale sta diventando un moltiplicatore di capacità per attori estremisti che operano prevalentemente nello spazio informativo. Il punto centrale, tuttavia, non è l’IA come strumento creativo in senso stretto, bensì il suo ruolo di moltiplicatore di forza cognitiva: l’IA, in questi casi, pur non introducendo necessariamente nuovi contenuti o nuove ideologie, rende industriale la produzione di messaggi radicali, abbatte i costi della propaganda e ne accelera la circolazione. La tecnologia trasforma la comunicazione estremista in un processo continuo, scalabile e adattivo e il risultato è un ambiente informativo sempre più instabile, in cui la frammentazione della verità diventa una condizione strutturale e non più un effetto collaterale. L’uso dell’intelligenza artificiale da parte di gruppi estremisti come ISIS, oltre a produrre contenuti propagandistici più “curati”, si sta integrando progressivamente nelle strategie comunicative complessive. I sistemi generativi consentono di produrre grandi volumi di testi ideologici in tempi ridottissimi, adattando il linguaggio a contesti culturali e linguistici differenti e rendendo la propaganda più flessibile e meno riconoscibile come tale. In parallelo, l’IA viene utilizzata per creare immagini e video sintetici che simulano eventi, dichiarazioni o scenari di conflitto, spesso con un livello di realismo sufficiente a superare un primo sguardo critico. L’intelligenza artificiale viene usata anche per creare scene di conflitto completamente simulate, con tanto di immagini e video che mostrano bombardamenti, movimenti militari o attacchi mai avvenuti. Si tratta di video dotati di un realismo tale da essere scambiati per eventi reali, almeno nelle prime fasi della loro diffusione. Come documentato da Associated Press, durante il conflitto tra Israele e Hamas sono circolate online numerose immagini e contenuti generati o alterati con l’intelligenza artificiale, raffiguranti scene di guerra e distruzione mai avvenute, che hanno contribuito a diffondere disinformazione e a confondere l’opinione pubblica nelle fasi più concitate della crisi. La possibilità di tradurre automaticamente questi contenuti in più lingue amplia ulteriormente la portata dei messaggi, rendendo la propaganda realmente globale e non più legata a specifiche aree geografiche o comunità linguistiche. Un ulteriore elemento di discontinuità rispetto alla propaganda del passato riguarda la capacità dell’IA di simulare interazioni umane credibili. Account automatizzati, chatbot e profili che imitano il comportamento di utenti reali possono rispondere, commentare, incoraggiare e guidare le conversazioni, creando l’illusione di una comunità viva e partecipata. In questo modo la propaganda anziché essere un messaggio unidirezionale, si pone come un dialogo continuo, in grado di adattarsi alle reazioni degli interlocutori e ridurre progressivamente la capacità dell’utente di distinguere tra informazione, opinione e manipolazione. L’intelligenza artificiale è quindi parte attiva del processo comunicativo e viene usata per modificare le condizioni cognitive entro cui si formano le opinioni. Tra tutte le applicazioni dell’intelligenza artificiale in ambito estremista, la produzione e manipolazione di video rappresenta probabilmente la trasformazione più significativa. Nonostante i deepfake, ovvero i video sintetici o manipolati attraverso reti neurali, esistano da alcuni anni, solo recentemente hanno raggiunto una soglia di qualità e accessibilità tale da renderli realmente pervasivi. Il video occupa una posizione centrale negli ecosistemi digitali contemporanei, in quanto è il formato privilegiato dagli algoritmi delle piattaforme social, quello che genera maggiore engagement e che viene percepito come più “autentico” dagli utenti. In questo contesto, la possibilità di generare video credibili consente ai gruppi estremisti di costruire narrazioni potenti, capaci di suscitare emozioni forti e di rafforzare l’identificazione ideologica. A differenza dei testi o delle immagini statiche, il video combina voce, volto, movimento e contesto, creando un’esperienza immersiva che rende più difficile mantenere una distanza critica. Inoltre, i sistemi di moderazione automatica faticano maggiormente a individuare manipolazioni sofisticate, soprattutto quando i contenuti, non violando apertamente le policy, si muovono in un’area grigia fatta di suggestioni, allusioni e narrazioni implicite. L’IA consente infine di produrre molteplici versioni dello stesso messaggio, testando quali funzionano meglio su specifici segmenti di pubblico e adattando rapidamente la strategia comunicativa di conseguenza. Uno degli aspetti più delicati dell’uso dell’IA da parte dei gruppi estremisti riguarda il reclutamento. A differenza dei modelli tradizionali, basati su messaggi generici e su un’esposizione progressiva ai contenuti ideologici, l’intelligenza artificiale consente oggi una forma di radicalizzazione molto più personalizzata. Analizzando comportamenti, interazioni e segnali digitali, è possibile adattare il messaggio al profilo emotivo e cognitivo del singolo utente. In questo scenario, la propaganda smette di essere un atto esplicito di indottrinamento per diventare una sequenza di interazioni apparentemente innocue, spesso costruite per creare empatia e senso di appartenenza. L’uso di sistemi automatizzati che simulano conversazioni reali permette infatti di accompagnare gradualmente l’utente lungo un percorso di radicalizzazione, riducendo la percezione di trovarsi di fronte a un messaggio estremista. Questo tipo di radicalizzazione assistita da algoritmi rende più complessa l’attività di prevenzione, perché non esiste più un unico contenuto “pericoloso” da rimuovere, bensì una molteplicità di micro-interazioni che, prese singolarmente, possono apparire irrilevanti. L’IA, in questo contesto, agisce come un acceleratore silenzioso, capace di ridurre i tempi e di aumentare l’efficacia dei processi di estremizzazione, spesso al di sotto della soglia di attenzione delle piattaforme e delle autorità. Sarebbe un errore interpretare questi fenomeni esclusivamente come una questione legata al terrorismo jihadista. Le stesse tecnologie vengono oggi utilizzate anche in ambiti politici radicali non necessariamente violenti, ma comunque in grado di produrre effetti destabilizzanti sul piano democratico e sociale. In diversi contesti europei e internazionali, movimenti di estrema destra stanno sperimentando l’uso di contenuti generati da IA per amplificare messaggi polarizzanti e anti-istituzionali. In questi casi, l’obiettivo, anziché essere il reclutamento militante in senso stretto, è la costruzione di un clima di sfiducia generalizzata. Le immagini e i video sintetici vengono utilizzati per rafforzare narrazioni emotive su temi come immigrazione, sicurezza e identità nazionale, spesso senza dichiarare l’origine artificiale dei contenuti. Il risultato è una forma di disinformazione che punta a confondere piuttosto che a convincere, e a rendere indistinguibile il confine tra vero e falso. L’intelligenza artificiale diventa così uno strumento di normalizzazione della manipolazione: quando la produzione di contenuti sintetici diventa routine, la percezione stessa dell’informazione cambia, e con essa il rapporto tra cittadini, media e istituzioni. Il punto di contatto tra l’estremismo jihadista e le nuove forme di radicalismo politico è infatti la metodologia comunicativa. In entrambi i casi, l’IA viene utilizzata per trasformare lo spazio pubblico digitale in una sorta di “zona di guerra cognitiva”, in cui l’obiettivo è rendere impraticabile qualsiasi verità condivisa. La moltiplicazione dei messaggi, delle narrazioni e delle versioni concorrenti degli stessi eventi produce una saturazione informativa che favorisce la sfiducia sistemica e l’astensione critica. La questione investe direttamente la qualità e la tenuta dello spazio pubblico digitale. In questo quadro si inserisce la cosiddetta “tecnodestra”, rappresentata da figure come Curtis Yarvin. Da teorico neoreazionario a lungo marginale, oggi sempre più legittimato negli ambienti della destra statunitense e citato da esponenti come JD Vance, Yarvin incarna una visione post-democratica in cui tecnologia e automazione diventano strumenti di governo e di legittimazione del potere. Nella visione di Yarvin, il problema non è tanto confutare il consenso democratico, quanto disintegrarlo. La sua celebre critica alla “Cattedrale” (termine con cui viene definito l’insieme di media, università e istituzioni culturali che, a suo avviso, controllano il discorso pubblico) trova nell’intelligenza artificiale uno strumento perfettamente coerente. L’IA consente infatti di “inondare la zona” (flooding the zone) con una quantità tale di contenuti alternativi, interpretazioni e simulazioni da rendere irrilevante l’autorità delle fonti tradizionali. In questo modo, la verità viene, di fatto, sommersa. Yarvin, diversamente dai propagandisti nel senso tradizionale, rappresenta un caso emblematico di come ideologia politica e immaginario tecnologico possano fondersi in una visione coerente del potere. Le sue teorie, che immaginano forme di governo basate su élite tecniche, algoritmi e sistemi automatizzati, contribuiscono a legittimare l’idea che la mediazione democratica possa essere sostituita da processi computazionali più efficienti. In questo contesto, l’uso di video e contenuti generati da IA assume un significato che va oltre la comunicazione. L’IA diventa parte integrante di una narrazione in cui, oltre ad essere strumento di divulgazione, la tecnologia è un vero e proprio principio ordinatore della società. Il legame tra queste correnti ideologiche e l’uso dell’IA nella sfera pubblica è particolarmente rilevante perché mostra come la manipolazione algoritmica non sia appannaggio esclusivo di attori violenti, terroristici o clandestini. Al contrario, essa può inserirsi in discorsi apparentemente sofisticati, accademici o “razionali”, contribuendo a ridefinire i confini di ciò che viene percepito come legittimo nel dibattito politico. Il filo conduttore che unisce terrorismo jihadista, movimenti estremisti e tecnodestra è l’uso strategico dell’intelligenza artificiale per produrre realtà alternative credibili, emotivamente coinvolgenti e personalizzate. L’IA, pur non creando l’estremismo, ne modifica profondamente le dinamiche di diffusione, rendendolo più adattivo, più resiliente e meno visibile. Siamo di fronte a un cambiamento strutturale del modo in cui l’informazione viene prodotta, distribuita e consumata. La possibilità di simulare eventi, persone e discorsi mette in crisi i tradizionali meccanismi di fiducia su cui si basano le società democratiche. Ridurre la questione a un problema tecnico significherebbe ignorarne la dimensione politica e culturale: l’intelligenza artificiale, in quanto tecnologia di mediazione, diventa inevitabilmente una tecnologia di potere. Il minimo comune denominatore di queste dinamiche è la frammentazione deliberata della realtà. Attraverso una combinazione di disinformazione strategica, personalizzazione algoritmica e saturazione cognitiva, l’IA viene impiegata per confondere il pensiero critico, erodere la fiducia nelle istituzioni e spingere gli individui verso camere dell’eco sempre più estreme. Si tratta di una strategia che sfrutta consapevolmente le logiche stesse dei sistemi intelligenti. Le risposte a questa sfida devono andare oltre l’introduzione di nuovi strumenti di rilevazione o di watermarking dei contenuti. Sebbene queste soluzioni siano necessarie, esse si rivelano insufficienti in un contesto in cui le stesse tecnologie possono essere utilizzate per aggirare i controlli. La regolamentazione, come quella prevista dal Digital Services Act europeo, rappresenta un passo importante, ma richiede un’applicazione coerente e una cooperazione reale tra piattaforme, istituzioni e comunità scientifica. Accanto alle misure normative, è fondamentale investire in alfabetizzazione digitale e trasparenza. Gli utenti devono essere messi nelle condizioni di comprendere come funzionano i sistemi di generazione dei contenuti e quali interessi possono nascondersi dietro narrazioni apparentemente neutre. Allo stesso tempo, è necessario riconoscere che l’IA è un elemento che ridefinisce i rapporti di forza nello spazio informativo. Serve quindi una riflessione più ampia sull’impatto politico e sociale dell’IA, poiché il rischio è quello di inseguirne gli effetti senza mai intervenire sulle cause: in questo vuoto le forme più sofisticate di propaganda estremista trovano il loro terreno fertile.
cybersecurity360.itDec 31, 2025extracted
⚡ Weekly Recap: MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More
Last week’s cyber news in 2025 was not about one big incident. It was about many small cracks opening at the same time. Tools people trust every day behave in unexpected ways. Old flaws resurfaced. New ones were used almost immediately. A common theme ran through it all in 2025. Attackers moved faster than fixes. Access meant for work, updates, or support kept getting abused. And damage did not stop when an incident was “over” — it continued to surface months or even years later. This weekly recap brings those stories together in one place. No overload, no noise. Read on to see what shaped the threat landscape in the final stretch of 2025 and what deserves your attention now. ⚡ Threat of the Week MongoDB Vulnerability Comes Under Attack — A newly disclosed security vulnerability in MongoDB has come under active exploitation in the wild, with over 87,000 potentially susceptible instances identified across the world. The vulnerability in question is CVE-2025-14847 (CVSS score: 8.7), which allows an unauthenticated attacker to remotely leak sensitive data from the MongoDB server memory. It has been codenamed MongoBleed. The exact details surrounding the nature of attacks exploiting the flaw are presently unknown. Users are advised to update to MongoDB versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30. Data from attack surface management company Censys shows that there are more than 87,000 potentially vulnerable instances, with a majority of them located in the U.S., China, Germany, India, and France. Wiz noted that 42% of cloud environments have at least one instance of MongoDB in a version vulnerable to CVE-2025-14847. This includes both internet-exposed and internal resources. 🔔 Top News Trust Wallet Chrome Extension Hack Leads to $7M Loss — Trust Wallet urged users to update its Google Chrome extension to the latest version following what it described as a "security incident" that led to the loss of approximately $7 million. Users are advised to update to version 2.69 as soon as possible. "We've confirmed that approximately $7 million has been impacted, and we will ensure all affected users are refunded," Trust Wallet said. The Chrome extension has about 1 million users. Mobile-only users and all other browser extension versions are not affected. It's currently not known who is behind the attack, but Trust Wallet said the attacker likely published a malicious version (2.68) by using a leaked Chrome Web Store API key. Affected victims have been asked to fill out a form to process reimbursements. Evasive Panda Stages DNS Poisoning Attack to Push MgBot Malware — A China-linked advanced persistent threat (APT) group known as Evasive Panda was attributed to a highly-targeted cyber espionage campaign in which the adversary poisoned Domain Name System (DNS) requests to deliver its signature MgBot backdoor in attacks targeting victims in Türkiye, China, and India. The activity took place between November 2022 and November 2024. According to Kaspersky, the hacking group conducted adversary-in-the-middle (AitM) attacks on specific victims to serve trojanized updates for popular tools like SohuVA, iQIYI Video, IObit Smart Defrag, and Tencent QQ that ultimately deployed MgBot, a modular implant with wide-ranging information gathering capabilities. It's currently not known how the threat actor is poisoning DNS responses. But two possible scenarios are suspected: either the ISPs used by the victims were selectively targeted and compromised to install some kind of network implant on edge devices, or a router or firewall used by the victims was hacked for this purpose. LastPass 2022 Breach Leads to Crypto Theft — The encrypted vault backups stolen from the 2022 LastPass data breach enabled bad actors to take advantage of weak master passwords to crack them open and drain cryptocurrency assets as recently as late 2025. New findings from TRM Labs show that threat actors with possible ties to the Russian cybercriminal ecosystem have stolen no less than $35 million as of September 2025. The Russian links to the stolen cryptocurrency stem from two primary factors: The use of exchanges commonly associated with the Russian cybercriminal ecosystem in the laundering pipeline and operational connections gleaned from wallets interacting with mixers both before and after the mixing and laundering process. Fortinet Warns of Renewed Activity Exploiting CVE-2020-12812 — Fortinet said it observed "recent abuse" of CVE-2020-12812, a five-year-old security flaw in FortiOS SSL VPN, in the wild under certain configurations. The vulnerability could allow a user to log in successfully without being prompted for the second factor of authentication if the case of the username was changed. The newly issued guidance does not give any specifics on the nature of the attacks exploiting the flaw, nor whether any of those incidents were successful. Fortinet has also advised impacted customers to contact its support team and reset all credentials if they find evidence of admin or VPN users being authenticated without two-factor authentication (2FA). Fake WhatsApp API npm Package Steals Messages — A new malicious package on the npm repository named lotusbail was found to work as a fully functional WhatsApp API, but contained the ability to intercept every message and link the attacker's device to a victim's WhatsApp account. It has been downloaded over 56,000 times since it was first uploaded to the registry by a user named "seiren_primrose" in May 2025. The package has since been removed by npm. Once the npm package is installed, the threat actor can read all WhatsApp messages, send messages to others, download media files, and access contact lists. "And here's the critical part, uninstalling the npm package removes the malicious code, but the threat actor's device stays linked to your WhatsApp account," Koi said. "The pairing persists in WhatsApp's systems until you manually unlink all devices from your WhatsApp settings. Even after the package is gone, they still have access." ️🔥 Trending CVEs Hackers act fast. They can use new bugs within hours. One missed update can cause a big breach. Here are this week’s most serious security flaws. Check them, fix what matters first, and stay protected. This week’s list includes — CVE-2025-14847 (MongoDB), CVE-2025-68664 (LangChain Core), CVE-2023-52163 (Digiever DS-2105 Pro), CVE-2025-68613 (n8n), CVE-2025-13836 (Python http.client), CVE-2025-26794 (Exim), CVE-2025-68615 (Net-SNMP), CVE-2025-44016 (TeamViewer DEX Client), and CVE-2025-13008 (M-Files Server). 📰 Around the Cyber World Former Coinbase Customer Service Agent Arrested in India — Coinbase Chief Executive Officer Brian Armstrong said that a former customer service agent for the largest U.S. crypto exchange was arrested in India, months after hackers bribed customer service representatives to gain access to customer information. In May, the company said hackers bribed contractors working out of India to steal sensitive customer data and demanded a $20 million ransom. "We have zero tolerance for bad behavior and will continue to work with law enforcement to bring bad actors to justice," Armstrong said. "Thanks to the Hyderabad Police in India, an ex-Coinbase customer service agent was just arrested. Another one down and more still to come." The incident impacted 69,461 individuals. A September 2025 class action lawsuit has revealed that Coinbase hired TaskUs to handle customer support from India. The court document also mentioned that Coinbase "cut ties with the TaskUs personnel involved and other overseas agents, and tightened controls." One TaskUs employee based out of Indore, Ashita Mishra, is accused of "joining the conspiracy by agreeing to sell highly sensitive Coinbase user data to those criminals" as early as September 2024. Mishra was arrested in January 2025 for allegedly selling the stolen data to hackers for $200 per record. TaskUs claimed that "it identified two individuals who illegally accessed information from one of our clients [who] were recruited by a much broader, coordinated criminal campaign against this client that also impacted a number of other providers servicing this client." It also alleged that Coinbase "had vendors other than TaskUs, and that Coinbase employees were involved in the data breach." But the company provided no further details. Cloud Atlas Targets Russia and Belarus — The threat actor known as Cloud Atlas has leveraged phishing lures with a malicious Microsoft Word document attachment that, when opened, downloads a malicious template from a remote server that, in turn, fetches and executes an HTML Application (HTA) file. The malicious HTA file extracts and creates several Visual Basic Script (VBS) files on disk that are parts of the VBShower backdoor. VBShower then downloads and installs other backdoors, including PowerShower, VBCloud, and CloudAtlas. VBCloud can download and execute additional malicious scripts, including a file grabber to exfiltrate files of interest. Similar to VBCloud, PowerShower is capable of retrieving an additional payload from a remote server. CloudAtlas establishes communication with a command-and-control (C2) server via WebDAV and fetches executable plugins in the form of a DLL, allowing it to gather files, run commands, steal passwords from Chromium-based browsers, and capture system information. Attacks mounted by the threat actor have primarily targeted organizations in the telecommunications sector, construction, government entities, and plants in Russia and Belarus. BlackHawk Loader Spotted in the Wild — A new MSIL loader named BlackHawk has been detected in the wild, incorporating three layers of obfuscation that show signs of being generated using artificial intelligence (AI) tools. Per ESET, it features a Visual Basic Script and two PowerShell scripts, the second of which contains the Base64-encoded BlackHawk loader and the final payload. The loader is being actively used in campaigns distributing Agent Tesla in attacks targeting hundreds of endpoints in Romanian small and medium-sized companies. The loader has also been used to deliver an information stealer known as Phantom. Surge in Cobalt Strike Servers — Censys has noted a sudden spike in Cobalt Strike servers hosted online between early December and December 18, 2025, specifically on the networks of AS138415 (YANCY) and AS133199 (SonderCloud LTD). "Viewing the timeline above, AS138415 first exhibits limited 'seed' activity beginning on December 4, followed by a substantial expansion of 119 new Cobalt Strike servers on December 6," Censys said. "Within just two days, however, nearly all of this newly added infrastructure disappears. On December 8, AS133199 experienced a near mirror-image increase and decrease in newly observed Cobalt Strike servers." More than 150 distinct IPs associated with AS138415 have been flagged as hosting Cobalt Strike listeners during this window. This netblock, 23.235.160[.]0/19, was allocated to RedLuff, LLC in September 2025. Meet Fly, the Russian Market Administrator — Intrinsec has revealed that a threat actor known as Fly is likely the administrator of Russian Market, an underground portal for selling credentials stolen via infostealers. "This threat actor promoted the marketplace on multiple occasions and throughout the years," the French cybersecurity company said. "His username is reminiscent of the old name of the marketplace, 'Flyded.' We found two e-mail addresses used to register the first Russian Market domains, which enabled us to find potential links to a Gmail account named 'AlexAske1,' but we could not find additional information surrounding this potential identity." New Scam Campaign Targets MENA with Fake Job Offers — A new scam campaign is targeting Middle East and North Africa (MENA) countries with fake online jobs across social media and private messaging platforms like Telegram and WhatsApp that promise easy work and fast money, but are designed to collect personal data and steal money. The scams exploit trust in recognized institutions and the low cost of social media advertising. The targeting is intentionally broad to cast a wide phishing net. "The fake job ads often impersonate well-known companies, banks, and authorities to gain trust of victims," Group-IB said. "Once victims engage, the conversation moves to private messaging channels where the actual financial fraud and data theft take place." The ads typically redirect victims to a WhatsApp group, where a recruiter directs them to a scam website for registration. Once the victim has completed the step, they are added to various Telegram channels where they are instructed to pay a fee to secure tasks and earn commissions from it. "The scammers will actually send a small payout for the initial task to build trust," Group-IB said. "They will then push victims to deposit larger amounts to take on bigger tasks that promise even greater returns. When victims do make a big deposit, the payout stops, the channels and accounts disappear and the victim finds themselves blocked, making communication and tracking almost impossible." The ads are directed against MENA countries such as Egypt, Gulf States' members, Algeria, Tunisia, Morocco, Iraq, and Jordan. EmEditor Breached to Distribute Infostealer — Windows-based text editing program EmEditor has disclosed a security breach. Emurasoft said a "third-party" performed an unauthorized modification of the download link for its Windows installer to point to a malicious MSI file hosted in a different location on the EmEditor website between December 19 and 22, 2022. Emurasoft said it's investigating the incident to determine the full scope of impact. According to Chinese security firm QiAnXin, the malicious installer is used to launch a PowerShell script that's capable of harvesting system information, including system metadata, files, VPN configuration, Windows login credentials, browser data, and information associated with apps like Zoho Mail, Evernote, Notion, discord, Slack, Mattermost, Skype, LiveChat, Microsoft Teams, Zoom, WinSCP, PuTTY, Steam, and Telegram. It also installs an Edge browser extension (ID: "ngahobakhbdpmokneiohlfofdmglpakd") named Google Drive Caching that can fingerprint browsers, replace cryptocurrency wallet addresses in the clipboard, log keystrokes from specific websites such as x[.]com, and steal Facebook advertising account details. Docker Hardened Images Now Available for Free — Docker has made Hardened Images free for every developer to bolster software supply chain security. Introduced in May 2025, these are a set of secure, minimal, production-ready images that are managed by Docker. The company said it has hardened over 1,000 images and helm charts in its catalog. "Unlike other opaque or proprietary hardened images, DHI is compatible with Alpine and Debian, trusted and familiar open source foundations teams already know and can adopt with minimal change," Docker noted. Flaw in Livewire Disclosed — Details have emerged about a now-patched critical security flaw in Livewire (CVE-2025-54068, CVSS score: 9.8), a full-stack framework for Laravel, that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. The issue was addressed in Livewire version 3.6.4 released in July 2025. According to Synacktiv, the vulnerability is rooted in the platform's hydration mechanism, which is used to manage component states and ensure that they have not been tampered with during transit by means of a checksum. "However, this mechanism comes with a critical vulnerability: a dangerous unmarshalling process can be exploited as long as an attacker is in possession of the APP_KEY of the application," the cybersecurity company said. "By crafting malicious payloads, attackers can manipulate Livewire's hydration process to execute arbitrary code, from simple function calls to stealthy remote command execution." To make matters worse, the research also identified a pre-authenticated remote code execution vulnerability that's exploitable even without knowledge of the application's APP_KEY. "Attackers could inject malicious synthesizers through the updates field in Livewire requests, leveraging PHP’s loose typing and nested array handling," Synacktiv added. "This technique bypasses checksum validation, allowing arbitrary object instantiation and leading to full system compromise." ChimeraWire Malware Boosts Website SERP Rankings — A new malware dubbed ChimeraWire has been found to artificially boost the ranking of certain websites in search engine results pages (SERPs) by performing hidden internet searches and mimicking user clicks on infected Windows devices. ChimeraWire is typically deployed as a second-stage payload on systems previously infected with other malware downloaders, Doctor Web said. The malware is designed to download a Windows version of the Google Chrome browser and install add-ons like NopeCHA and Buster into it for automated CAPTCHA solving. ChimeraWire then launches the browser in debugging mode with a hidden window to perform the malicious clicking activity based on certain pre-configured criteria. "For this, the malicious app searches target internet resources in the Google and Bing search engines and then loads them," the Russian company said. "It also imitates user actions by clicking links on the loaded sites. The Trojan performs all malicious actions in the Google Chrome web browser, which it downloads from a certain domain and then launches it in debug mode over the WebSocket protocol." More Details About LANDFALL Campaign Emerge — The LANDFALL Android spyware campaign was disclosed by Palo Alto Networks Unit 42 last month as having exploited a now-patched zero-day flaw in Samsung Galaxy Android devices (CVE-2025-21042) in targeted attacks in the Middle East. Google Project Zero said it identified six suspicious image files that were uploaded to VirusTotal between July 2024 and February 2025. It's suspected that these images were received over WhatsApp, with Google noting that the files were DNG files targeting the Quram library, an image parsing library specific to Samsung devices. Further investigation has determined that the images are engineered to trigger an exploit that runs within the com.samsung.ipservice process. "The com.samsung.ipservice process is a Samsung-specific system service responsible for providing 'intelligent' or AI-powered features to other Samsung applications," Project Zero's Benoît Sevens said. "It will periodically scan and parse images and videos in Android's MediaStore. When WhatsApp receives and downloads an image, it will insert it in the MediaStore. This means that downloaded WhatsApp images (and videos) can hit the image parsing attack surface within the com.samsung.ipservice application." Given that WhatsApp does not automatically download images from untrusted contacts, it's assessed that a 1-click exploit is used to trigger the download and have it added to the MediaStore. This, in turn, fires an exploit for the flaw, resulting in an out-of-bounds write primitive. "This case illustrates how certain image formats provide strong primitives out of the box for turning a single memory corruption bug into interactionless ASLR bypasses and remote code execution," Sevens noted. "By corrupting the bounds of the pixel buffer using the bug, the rest of the exploit could be performed by using the 'weird machine' that the DNG specification and its implementation provide." New Android Spyware Discovered on Belarusian Journalist's Phone — Belarusian authorities are deploying a new spyware called ResidentBat on the smartphones of local journalists after their phones are confiscated during police interrogations by the Belarusian secret service. The spyware can collect call logs, record audio through the microphone, take screenshots, collect SMS messages and chats from encrypted messaging apps, and exfiltrate local files. It can also factory reset the device and remove itself. According to a report from RESIDENT.NGO, ResidentBat's server infrastructure has been operational since March 2021. In December 2024, similar cases of implanting spyware on individuals' phones while they were being questioned by police or security services were reported in Serbia and Russia. "The infection relied on physical access to the device," RESIDENT.NGO said. "We hypothesize that the KGB officers observed the device password or PIN as the journalist typed it in their presence during the conversation. Once the officers had the PIN and physical possession of the phone while it was in the locker, they enabled 'Developer Mode' and 'USB Debugging.' The spyware was then sideloaded onto the device, likely via ADB commands from a Windows PC." Former Incident Responders Plead Guilty to Ransomware Attacks — Former cybersecurity professionals Ryan Clifford Goldberg and Kevin Tyler Martin pleaded guilty to participating in a series of BlackCat ransomware attacks between April and December 2023 while they were employed at cybersecurity companies tasked with helping organizations fend off ransomware attacks. Goldberg and Martin were indicted last month. While Martin worked as a ransomware threat negotiator for DigitalMint, Goldberg was an incident response manager for cybersecurity company Sygnia. A third unnamed co-conspirator, who was also employed at DigitalMint, allegedly obtained an affiliate account for BlackCat, which the trio used to commit ransomware attacks. The three individuals agreed to pay BlackCat administrators a 20% share of any ransoms received in exchange for access to the ransomware and BlackCat's extortion platform. The defendants are scheduled to be sentenced on March 12, 2026, and face a maximum penalty of 20 years in prison. "These defendants used their sophisticated cybersecurity training and experience to commit ransomware attacks – the very type of crime that they should have been working to stop," said Assistant Attorney General A. Tysen Duva of the Justice Department's Criminal Division. "Extortion via the internet victimizes innocent citizens every bit as much as taking money directly out of their pockets." Congressional Report Says China Exploits U.S.-funded Research on Nuclear Technology — A new report released by the House Select Committee on China and the House Permanent Select Committee on Intelligence (HPSCI) has revealed that China exploits the U.S. Department of Energy (DOE) to gain access and divert American taxpayer-funded research and fuel its military and technological rise. The investigation identified about 4,350 research papers between June 2023 and June 2025, where DOE funding or research support involved research relationships with Chinese entities, including over 730 DOE awards and contracts. Of these, approximately 2,200 publications were conducted in partnership with entities within China's defense research and industrial base. "This case study and many more like it in the report underscore a deeply troubling reality: U.S. government scientists – employed by the DOE and working at federally funded national laboratories – have coauthored research with Chinese entities at the very heart of the PRC's military-industrial complex," the House Select Committee on the Chinese Communist Party (CCP) said. "They involve the joint development of technologies relevant to next-generation military aircraft, electronic warfare systems, radar deception techniques, and critical energy and aerospace infrastructure – alongside entities already restricted by multiple U.S. agencies for posing a threat to national security." In a statement shared with Associated Press, the Chinese Embassy in Washington said the select committee "has long smeared and attacked China for political purposes and has no credibility to speak of." Moscow Court Sentences Russian Scientist to 21 Years for Treason — A Moscow court handed a 21-year prison sentence to Artyom Khoroshilov, 34, a researcher at the Moscow Institute of General Physics, who has been accused of treason, attacking critical infrastructure, and plotting sabotage. He was also fined 700,000 rubles (~$9,100). Khoroshilov is said to have colluded with the Ukrainian IT army to conduct distributed denial-of-service (DDoS) attacks on the Russian Post in August 2022. He also planned to commit sabotage by blowing up the railway tracks used by the military unit of the Ministry of Defense of the Russian Federation to transport military goods. The IT Army of Ukraine, a hacktivist group known for coordinating DDoS attacks on Russian infrastructure, said it does not know if Khoroshilov was part of their community, but noted "the enemy hunts down any sign of resistance." New DIG AI Tool Used by Malicious Actors — Resecurity said it has observed a "notable increase" in malicious actors' utilization of DIG AI, the latest addition to a long list of dark Large Language Models (LLMs) that can be used for illegal, unethical, malicious or harmful activities, such as generating phishing emails or instructions for bombs and prohibited substances. It can be accessed by users via the Tor browser without requiring an account. According to its developer, Pitch, the service is based on OpenAI's ChatGPT Turbo. "DIG AI enables malicious actors to leverage the power of AI to generate tips ranging from explosive device manufacturing to illegal content creation, including CSAM," the company said. "Because DIG AI is hosted on the TOR network, such tools are not easily discoverable and accessible to law enforcement. They create a significant underground market – from piracy and derivatives to other illicit activities." China Says U.S. Seized Cryptocurrency from Chinese Firm — The Chinese government said the U.S. unduly seized cryptocurrency assets that actually belonged to LuBian. In October 2025, the U.S. Justice Department seized $15 billion worth of Bitcoin from the operator of scam compounds last month. The agency claimed the funds were owned by the Prince Group and its CEO, Chen Zhi. China's National Computer Virus Emergency Response Center (CVERC) alleged that the funds could be traced back to the 2020 hack of Chinese bitcoin mining pool operator LuBian, echoing a report from Elliptic. What's evident is that the digital assets were stolen from Zhi before they ended up with the U.S. "The U.S. government may have stolen Chen Zhi's 127,000 Bitcoin through hacking techniques as early as 2020, making this a classic case of 'black-on-black' crime orchestrated by a state-sponsored hacking organization," CVERC said. However, it bears noting that the report makes no mention of the stolen assets being linked to scam campaigns. 🎥 Cybersecurity Webinars How Zero Trust and AI Catch Attacks With No Files, No Binaries, and No Indicators — Cyber threats are evolving faster than ever, exploiting trusted tools and fileless techniques that evade traditional defenses. This webinar reveals how Zero Trust and AI-driven protection can uncover unseen attacks, secure developer environments, and redefine proactive cloud security—so you can stay ahead of attackers, not just react to them. Master Agentic AI Security: Learn to Detect, Audit, and Contain Rogue MCP Servers — AI tools like Copilot and Claude Code help developers move fast, but they can also create big security risks if not managed carefully. Many teams don’t know which AI servers (MCPs) are running, who built them, or what access they have. Some have already been hacked, turning trusted tools into backdoors. This webinar shows how to find hidden AI risks, stop shadow API key problems, and take control before your AI systems create a breach. 🔧 Cybersecurity Tools GhidraGPT — It is a plugin for Ghidra that adds AI-powered assistance to reverse engineering work. It uses large language models to help explain decompiled code, improve readability, and highlight potential security issues, making it easier for analysts to understand and analyze complex binaries. Chameleon — It is an open-source honeypot tool used to monitor attacks, bot activity, and stolen credentials across a wide range of network services. It simulates open and vulnerable ports to attract attackers, logs their activity, and shows the results through simple dashboards, helping teams understand how their systems are being scanned and attacked in real environments. Disclaimer: These tools are for learning and research only. They haven’t been fully tested for security. If used the wrong way, they could cause harm. Check the code first, test only in safe places, and follow all rules and laws. Conclusion This weekly recap brings those stories together in one place to close out 2025. It cuts through the noise and focuses on what actually mattered in the final days of the year. Read on for the events that shaped the threat landscape, the patterns that kept repeating, and the risks that are likely to carry forward into 2026.
thehackernews.comDec 29, 2025extracted
Pro-Russian Hackers Claim Cyberattack on French Postal Service
A pro-Russian hacking group claimed responsibility for a major cyberattack that halted package deliveries by France’s national postal service just days before Christmas, prosecutors said Wednesday. After the claim by the cybercrime group known as Noname057, French intelligence agency DGSI took over the investigation into the hacking attack, the Paris prosecutor’s office said in a statement to The Associated Press. The group has been accused of other cyberattacks in Europe, including around a NATO summit in the Netherlands and French government sites. It was the target of a big European police operation earlier this year. Central computer systems at French national postal service La Poste were knocked offline Monday in a distributed denial of service, or DDoS, cyberattack that still wasn’t fully resolved by Wednesday morning, the company said. Postal workers couldn’t track package deliveries, and online payments at the company’s banking arm were also disrupted. It was a major blow to La Poste, which delivered 2.6 billion packages last year and employs more than 200,000 people, during the busiest season of the year. France and other European allies of Ukraine allege that Russia is waging a campaign of “hybrid warfare” to sow division in Western societies and undermine their support for Ukraine. The AP has tracked more than 145 incidents including sabotage, assassinations, cyberattacks, disinformation and other hostile acts that are increasingly draining police resources.
securityweek.comDec 24, 2025extracted
Dismantling Defenses: Trump 2.0 Cyber Year in Review
The Trump administration has pursued a staggering range of policy pivots this past year that threaten to weaken the nation’s ability and willingness to address a broad spectrum of technology challenges, from cybersecurity and privacy to countering disinformation, fraud and corruption. These shifts, along with the president’s efforts to restrict free speech and freedom of the press, have come at such a rapid clip that many readers probably aren’t even aware of them all. FREE SPEECH President Trump has repeatedly claimed that a primary reason he lost the 2020 election was that social media and Big Tech companies had conspired to silence conservative voices and stifle free speech. Naturally, the president’s impulse in his second term has been to use the levers of the federal government in an effort to limit the speech of everyday Americans, as well as foreigners wishing to visit the United States. In September, Donald Trump signed a national security directive known as NSPM-7, which directs federal law enforcement officers and intelligence analysts to target “anti-American” activity, including any “tax crimes” involving extremist groups who defrauded the IRS. According to extensive reporting by journalist Ken Klippenstein, the focus of the order is on those expressing “opposition to law and immigration enforcement; extreme views in favor of mass migration and open borders; adherence to radical gender ideology,” as well as “anti-Americanism,” “anti-capitalism,” and “anti-Christianity.” Earlier this month, Attorney General Pam Bondi issued a memo advising the FBI to compile a list of Americans whose activities “may constitute domestic terrorism.” Bondi also ordered the FBI to establish a “cash reward system” to encourage the public to report suspected domestic terrorist activity. The memo states that domestic terrorism could include “opposition to law and immigration enforcement” or support for “radical gender ideology.” The Trump administration also is planning to impose social media restrictions on tourists as the president continues to ramp up travel restrictions for foreign visitors. According to a notice from U.S. Customs and Border Protection (CBP), tourists — including those from Britain, Australia, France, and Japan — will soon be required to provide five years of their social media history. The CBP said it will also collect “several high value data fields,” including applicants’ email addresses from the past 10 years, their telephone numbers used in the past five years, and names and details of family members. Wired reported in October that the US CBP executed more device searches at the border in the first three months of the year than any other previous quarter. The new requirements from CBP add meat to the bones of Executive Order 14161, which in the name of combating “foreign terrorist and public safety threats” granted broad new authority that civil rights groups warn could enable a renewed travel ban and expanded visa denials or deportations based on perceived ideology. Critics alleged the order’s vague language around “public safety threats,” creates latitude for targeting individuals based on political views, national origin, or religion. At least 35 nations are now under some form of U.S. travel restrictions. CRIME AND CORRUPTION In February, Trump ordered executive branch agencies to stop enforcing the U.S. Foreign Corrupt Practices Act, which froze foreign bribery investigations, and even allows for “remedial actions” of past enforcement actions deemed “inappropriate.” The White House also disbanded the Kleptocracy Asset Recovery Initiative and KleptoCapture Task Force — units which proved their value in corruption cases and in seizing the assets of sanctioned Russian oligarchs — and diverted resources away from investigating white-collar crime. Also in February, Attorney General Pam Bondi dissolved the FBI’s Foreign Influence Task Force, an entity created during Trump’s first term designed to counter the influence of foreign governments on American politics. In March 2025, Reuters reported that several U.S. national security agencies had halted work on a coordinated effort to counter Russian sabotage, disinformation and cyberattacks. Former President Joe Biden had ordered his national security team to establish working groups to monitor the issue amid warnings from U.S. intelligence that Russia was escalating a shadow war against Western nations. In a test of prosecutorial independence, Trump’s Justice Department ordered prosecutors to drop the corruption case against New York Mayor Eric Adams. The fallout was immediate: Multiple senior officials resigned in protest, the case was reassigned, and chaos engulfed the Southern District of New York (SDNY) – historically one of the nation’s most aggressive offices for pursuing public corruption, white-collar crime, and cybercrime cases. When it comes to cryptocurrency, the administration has shifted regulators at the U.S. Securities and Exchange Commission (SEC) away from enforcement to cheerleading an industry that has consistently been plagued by scams, fraud and rug-pulls. The SEC in 2025 systematically retreated from enforcement against cryptocurrency operators, dropping major cases against Coinbase, Binance, and others. Perhaps the most troubling example involves Justin Sun, the Chinese-born founder of crypto currency company Tron. In 2023, the SEC charged Sun with fraud and market manipulation. Sun subsequently invested $75 million in the Trump family’s World Liberty Financial (WLF) tokens, became the top holder of the $TRUMP memecoin, and secured a seat at an exclusive dinner with the president. In late February 2025, the SEC dropped its lawsuit. Sun promptly took Tron public through a reverse merger arranged by Dominari Securities, a firm with Trump family ties. Democratic lawmakers have urged the SEC to investigate what they call “concerning ties to President Trump and his family” as potential conflicts of interest and foreign influence. In October, President Trump pardoned Changpeng Zhao, the founder of the world’s largest cryptocurrency exchange Binance. In 2023, Zhao and his company pled guilty to failing to prevent money laundering on the platform. Binance paid a $4 billion fine, and Zhao served a four-month sentence. As CBS News observed last month, shortly after Zhao’s pardon application, he was at the center of a blockbuster deal that put the Trump’s family’s WLF on the map. “Zhao is a citizen of the United Arab Emirates in the Persian Gulf and in May, an Emirati fund put $2 billion in Zhao’s Binance,” 60 Minutes reported. “Of all the currencies in the world, the deal was done in World Liberty crypto.” SEC Chairman Paul Atkins has made the agency’s new posture towards crypto explicit, stating “most crypto tokens are not securities.” At the same time, President Trump has directed the Department of Labor and the SEC to expand 401(k) access to private equity and crypto — assets that regulators have historically restricted for retail investors due to high risk, fees, opacity, and illiquidity. The executive order explicitly prioritizes “curbing ERISA litigation,” and reducing accountability for fiduciaries while shifting risk onto ordinary workers’ retirement savings. At the White House’s behest, the U.S. Treasury in March suspended the Corporate Transparency Act, a law that required companies to reveal their real owners. Finance experts warned the suspension would bring back shell companies and “open the flood gates of dirty money” through the US, such as funds from drug gangs, human traffickers, and fraud groups. Trump’s clemency decisions have created a pattern of freed criminals committing new offenses, including Jonathan Braun, whose sentence for drug trafficking was commuted during Trump’s first term, was found guilty in 2025 of violating supervised release and faces new charges. Eliyahu Weinstein, who received a commutation in January 2021 for running a Ponzi scheme, was sentenced in November 2025 to 37 years for running a new Ponzi scheme. The administration has also granted clemency to a growing list of white-collar criminals: David Gentile, a private equity executive sentenced to seven years for securities and wire fraud (functionally a ponzi-like scheme), and Trevor Milton, the Nikola founder sentenced to four years for defrauding investors over electric vehicle technology. The message: Financial crimes against ordinary investors are no big deal. At least 10 of the January 6 insurrectionists pardoned by President Trump have already been rearrested, charged or sentenced for other crimes, including plotting the murder of FBI agents, child sexual assault, possession of child sexual abuse material and reckless homicide while driving drunk. The administration also imposed sanctions against the International Criminal Court (ICC). On February 6, 2025, Executive Order 14203 authorized asset freezes and visa restrictions against ICC officials investigating U.S. citizens or allies, primarily in response to the ICC’s arrest warrants for Israeli Prime Minister Benjamin Netanyahu over alleged war crimes in Gaza. Earlier this month the president launched the “Gold Card,” a visa scheme established by an executive order in September that offers wealthy individuals and corporations expedited paths to U.S. residency and citizenship in exchange for $1 million for individuals and $2 million for companies, plus ongoing fees. The administration says it is also planning to offer a “platinum” version of the card that offers special tax breaks — for a cool $5 million. FEDERAL CYBERSECURITY President Trump campaigned for a second term insisting that the previous election was riddled with fraud and had been stolen from him. Shortly after Mr. Trump took the oath of office for a second time, he fired the head of the Cybersecurity and Infrastructure Security Agency (CISA) — Chris Krebs (no relation) — for having the audacity to state publicly that the 2020 election was the most secure in U.S. history. Mr. Trump revoked Krebs’s security clearances, ordered a Justice Department investigation into his election security work, and suspended the security clearances of employees at SentinelOne, the cybersecurity firm where Krebs worked as chief intelligence and public policy officer. The executive order was the first direct presidential action against any US cybersecurity company. Krebs subsequently resigned from SentinelOne, telling The Wall Street Journal he was leaving to push back on Trump’s efforts “to go after corporate interests and corporate relationships.” The president also dismissed all 15 members of the Cyber Safety Review Board (CSRB), a nonpartisan government entity established in 2022 with a mandate to investigate the security failures behind major cybersecurity events — likely because those advisors included Chris Krebs. At the time, the CSRB was in the middle of compiling a much-anticipated report on the root causes of Chinese government-backed digital intrusions into at least nine U.S. telecommunications providers. Not to be outdone, the Federal Communication Commission quickly moved to roll back a previous ruling that required U.S. telecom carriers to implement stricter cybersecurity measures. Meanwhile, CISA has lost roughly a third of its workforce this year amid mass layoffs and deferred resignations. When the government shutdown began in October, CISA laid off even more employees and furloughed 65 percent of the remaining staff, leaving only 900 employees working without pay. Additionally, the Department of Homeland Security has reassigned CISA cyber specialists to jobs supporting the president’s deportation agenda. As Bloomberg reported earlier this year, CISA employees were given a week to accept the new roles or resign, and some of the reassignments included relocations to new geographic areas. The White House has signaled that it plans to cut an additional $491 million from CISA’s budget next year, cuts that primarily target CISA programs focused on international affairs and countering misinformation and foreign propaganda. The president’s budget proposal justified the cuts by repeating debunked claims about CISA engaging in censorship. The Trump administration has pursued a similar reorganization at the FBI: The Washington Post reported in October that a quarter of all FBI agents have now been reassigned from national security threats to immigration enforcement. Reuters reported last week that the replacement of seasoned leaders at the FBI and Justice Department with Trump loyalists has led to an unprecedented number of prosecutorial missteps, resulting in a 21 percent dismissal rate of the D.C. U.S. attorney’s office criminal complaints over eight weeks, compared to a mere .5% dismissal rate over the prior 10 years. “These mistakes are causing department attorneys to lose credibility with federal courts, with some judges quashing subpoenas, threatening criminal contempt and issuing opinions that raise questions about their conduct,” Reuters reported. “Grand juries have also in some cases started rejecting indictments, a highly unusual event since prosecutors control what evidence gets presented.” In August, the DHS banned state and local governments from using cyber grants on services provided by the Multi-State Information Sharing and Analysis Center (MS-ISAC), a group that for more than 20 years has shared critical cybersecurity intelligence across state lines and provided software and other resources at free or heavily discounted rates. Specifically, DHS barred states from spending funds on services offered by the Elections Infrastructure ISAC, which was effectively shuttered after DHS pulled its funding in February. Cybersecurity Dive reports that the Trump administration’s massive workforce cuts, along with widespread mission uncertainty and a persistent leadership void, have interrupted federal agencies’ efforts to collaborate with the businesses and local utilities that run and protect healthcare facilities, water treatment plans, energy companies and telecommunications networks. The publication said the changes came after the US government eliminated CIPAC — a framework that allowed private companies to share cyber and threat intel without legal penalties. “Government leaders have canceled meetings with infrastructure operators, forced out their longtime points of contact, stopped attending key industry events and scrapped a coordination program that made companies feel comfortable holding sensitive talks about cyberattacks and other threats with federal agencies,” Cybersecurity Dive’s Eric Geller wrote. Both the National Security Agency (NSA) and U.S. Cyber Command have been without a leader since Trump dismissed Air Force General Timothy Haugh in April, allegedly for disloyalty to the president and at the suggestion of far-right conspiracy theorist Laura Loomer. The nomination of Army Lt. Gen. William Hartman for the same position fell through in October. The White House has ordered the NSA to cut 8 percent of its civilian workforce (between 1,500 and 2,000 employees). As The Associated Press reported in August, the Office of the Director of National Intelligence plans to dramatically reduce its workforce and cut its budget by more than $700 million annually. Director of National Intelligence Tulsi Gabbard said the cuts were warranted because ODNI had become “bloated and inefficient, and the intelligence community is rife with abuse of power, unauthorized leaks of classified intelligence, and politicized weaponization of intelligence.” The firing or forced retirements of so many federal employees has been a boon to foreign intelligence agencies. Chinese intelligence agencies, for example, reportedly moved quickly to take advantage of the mass layoffs, using a network of front companies to recruit laid-off U.S. government employees for “consulting work.” Former workers with the Defense Department’s Defense Digital Service who resigned en-masse earlier this year thanks to DOGE encroaching on their mission have been approached by the United Arab Emirates to work on artificial intelligence for the oil kingdom’s armed forces, albeit reportedly with the blessing of the Trump administration. PRESS FREEDOM President Trump has filed multibillion-dollar lawsuits against a number of major news outlets over news segments or interviews that allegedly portrayed him in a negative light, suing the networks ABC, the BBC, the CBS parent company Paramount, The Wall Street Journal, and The New York Times, among others. The president signed an executive order aimed at slashing public subsidies to PBS and NPR, alleging “bias” in the broadcasters’ reporting. In July, Congress approved a request from Trump to cut $1.1 billion in federal funding for the Corporation for Public Broadcasting, the nonprofit entity that funds PBS and NPR. Brendan Carr, the president’s pick to run the Federal Communications Commission (FCC), initially pledged to “dismantle the censorship cartel and restore free speech rights for everyday Americans.” But on January 22, 2025, the FCC reopened complaints against ABC, CBS and NBC over their coverage of the 2024 election. The previous FCC chair had dismissed the complaints as attacks on the First Amendment and an attempt to weaponize the agency for political purposes. President Trump in February seized control of the White House Correspondents’ Association, the nonprofit entity that decides which media outlets should have access to the White House and the press pool that follows the president. The president invited an additional 32 media outlets, mostly conservative or right-wing organizations. According to the journalism group Poynter.org, there are three religious networks, all of which lean conservative, as well as a mix of outlets that includes a legacy paper, television networks, and a digital outlet powered by artificial intelligence. Trump also barred The Associated Press from the White House over their refusal to refer to the Gulf of Mexico as the Gulf of America. Under Trump appointee Kari Lake, the U.S. Agency for Global Media moved to dismantle Voice of America, Radio Free Europe/Radio Liberty, and other networks that for decades served as credible news sources behind authoritarian lines. Courts blocked shutdown orders, but the damage continues through administrative leave, contract terminations, and funding disputes. President Trump this term has fired most of the people involved in processing Freedom of Information Act (FOIA) requests for government agencies. FOIA is an indispensable tool used by journalists and the public to request government records, and to hold leaders accountable. Petitioning the government, particularly when it ignores your requests, often requires challenging federal agencies in court. But that becomes far more difficult if the most competent law firms start to shy away from cases that may involve crossing the president and his administration. On March 22, the president issued a memorandum that directs heads of the Justice and Homeland Security Departments to “seek sanctions against attorneys and law firms who engage in frivolous, unreasonable and vexatious litigation against the United States,” or in matters that come before federal agencies. The Trump administration announced increased vetting of applicants for H-1B visas for highly skilled workers, with an internal State Department memo saying that anyone involved in “censorship” of free speech should be considered for rejection. Executive Order 14161, issued in 2025 on “foreign terrorist and public safety threats,” granted broad new authority that civil rights groups warn could enable a renewed travel ban and expanded visa denials or deportations based on perceived ideology. Critics charged that the order’s vague language around “public safety threats” creates latitude for targeting individuals based on political views, national origin, or religion. CONSUMER PROTECTION, PRIVACY At the beginning of this year, President Trump ordered staffers at the Consumer Financial Protection Bureau (CFPB) to stop most work. Created by Congress in 2011 to be a clearinghouse of consumer complaints, the CFPB has sued some of the nation’s largest financial institutions for violating consumer protection laws. The CFPB says its actions have put nearly $18 billion back in Americans’ pockets in the form of monetary compensation or canceled debts, and imposed $4 billion in civil money penalties against violators. The Trump administration said it planned to fire up to 90 percent of all CFPB staff, but a recent federal appeals court ruling in Washington tossed out an earlier decision that would have allowed the firings to proceed. Reuters reported this week that an employee union and others have battled against it in court for ten months, during which the agency has been almost completely idled. The CFPB’s acting director is Russell Vought, a key architect of the GOP policy framework Project 2025. Under Vought’s direction, the CFPB in May quietly withdrew a data broker protection rule intended to limit the ability of U.S. data brokers to sell personal information on Americans. Despite the Federal Reserve’s own post-mortem explicitly blaming Trump-era deregulation for the 2023 Silicon Valley Bank collapse, which triggered a fast-moving crisis requiring emergency weekend bailouts of banks, Trump’s banking regulators in 2025 doubled down. They loosened capital requirements, narrowed definitions of “unsafe” banking practices, and stripped specific risk categories from supervisory frameworks. The setup for another banking crisis requiring taxpayer intervention is now in place. The Privacy Act of 1974, one of the few meaningful federal privacy laws, was built on the principles of consent and separation in response to the abuses of power that came to light during the Watergate era. The law states that when an individual provides personal information to a federal agency to receive a particular service, that data must be used solely for its original purpose. Nevertheless, it emerged in June that the Trump administration has built a central database of all US citizens. According to NPR, the White House plans to use the new platform during upcoming elections to verify the identity and citizenship status of US voters. The database was built by the Department of Homeland Security and the Department of Governmental Efficiency and is being rolled out in phases to US states. DOGE Probably the biggest ungotten scoop of 2025 is the inside story of what happened to all of the personal, financial and other sensitive data that was accessed by workers at the so-called Department of Government Efficiency (DOGE). President Trump tapped Elon Musk to lead the newly created department, which was mostly populated by current and former employees of Musk’s various technology companies (including a former denizen of the cybercrime community known as the “Com”). It soon emerged that the DOGE team was using artificial intelligence to surveil at least one federal agency’s communications for hostility to Mr. Trump and his agenda. DOGE employees were able to access and synthesize data taken from a large number of previously separate and highly guarded federal databases, including those at the Social Security Administration, the Department of Homeland Security, the Office of Personnel Management, and the U.S. Department of the Treasury. DOGE staffers did so largely by circumventing or dismantling security measures designed to detect and prevent misuse of federal databases, including standard incident response protocols, auditing, and change-tracking mechanisms. For example, an IT expert with the National Labor Relations Board (NLRB) alleges that DOGE employees likely downloaded gigabytes of data from agency case files in early March, using short-lived accounts that were configured to leave few traces of network activity. The NLRB whistleblower said the large data outflows coincided with multiple blocked login attempts from addresses in Russia, which attempted to use valid credentials for a newly-created DOGE user account. The stated goal of DOGE was to reduce bureaucracy and to massively cut costs — mainly by eliminating funding for a raft of federal initiatives that had already been approved by Congress. The DOGE website claimed those efforts reduced “wasteful” and “fraudulent” federal spending by more than $200 billion. However, multiple independent reviews by news organizations determined the true “savings” DOGE achieved was off by a couple of orders of magnitude, and was likely closer to $2 billion. At the same time DOGE was slashing federal programs, President Trump fired at least 17 inspectors general at federal agencies — the very people tasked with actually identifying and stopping waste, fraud and abuse at the federal level. Those included several agencies (such as the NLRB) that had open investigations into one or more of Mr. Musk’s companies for allegedly failing to comply with protocols aimed at protecting state secrets. In September, a federal judge found the president unlawfully fired the agency watchdogs, but none of them have been reinstated. Where is DOGE now? Reuters reported last month that as far as the White House is concerned, DOGE no longer exists, even though it technically has more than half a year left to its charter. Meanwhile, who exactly retains access to federal agency data that was fed by DOGE into AI tools is anyone’s guess. KrebsOnSecurity would like to thank the anonymous researcher NatInfoSec for assisting with the research on this story.
krebsonsecurity.comDec 19, 2025extracted
Denmark Blames Russia for Cyberattacks Ahead of Elections and on Water Utility
Danish authorities say in a new assessment published this week that Russia carried out cyberattacks against infrastructure and websites in Denmark in 2024 and 2025, describing new cases which had not previously been reported. Denmark’s Defense Intelligence Service said in a statement Thursday that Moscow was responsible for “destructive and disruptive” cyberattacks on a Danish water utility in 2024 and a series of denial of service attacks which overwhelmed Danish websites ahead of regional and local elections last month. Danish broadcaster DR said the attack on the water utility caused pipes to burst, leaving homes temporarily without water. The intelligence service said the attacks were part of Russia’s “hybrid war” against the West and an attempt to create instability. It said Moscow’s cyberattacks are part of a broader campaign to undermine and punish countries which support Ukraine. Torsten Schack Pedersen, Denmark’s minister of resilience and preparedness, said the attacks resulted in limited damage but had serious ramifications. “It shows that there are forces capable of shutting down important parts of our society,” he said during a news conference Thursday, as reported by Danish broadcaster DR. Schack Pedersen added that the cyberattacks show that Denmark is not sufficiently equipped to handle such situations, DR reported. The attacks are among a growing number of incidents that Western officials say are part a campaign of sabotage and disruption across Europe masterminded by Russia. An Associated Press database has documented 147 incidents, including the two cases reported by Denmark this week. Not all incidents are public and it can sometimes take officials months to establish a link to Moscow. While officials say the campaign — waged since President Vladimir Putin’s invasion of Ukraine in 2022 — aims to deprive Kyiv of support, they believe Moscow is also trying to identify Europe’s weak spots and suck up law enforcement resources. The Danish agency said pro-Russian group Z-Pentest carried out the “destructive attack” on the water utility in 2024 and that a separate group, NoName057(16), was responsible for the cyberattack on Danish websites ahead of the recent elections. It said both have links to the Russian state. “The Russian state uses both groups as instruments of its hybrid war against the West. The aim is to create insecurity in the targeted countries and to punish those that support Ukraine,” the statement said. Z-Pentest’s alleged actions affected the utility’s water pressure and caused water pipes to burst near Køge, some 35 kilometers (22 miles) south of Copenhagen, DR reported. Several customers were out of water as a result. NoName057(16) acted, authorities said, in November to disrupt the elections, according to DR. In Germany, meanwhile, authorities summoned Russia’s ambassador in Berlin on Dec. 12 after the foreign ministry accused Moscow of carrying out sabotage, cyberattacks and election interference. That included a 2024 cyberattack against German air traffic control, German foreign ministry spokesperson Martin Giese said.
securityweek.comDec 19, 2025extracted
Who is Zico Kolter? A Professor Leads OpenAI Safety Panel With Power to Halt Unsafe AI Releases
If you believe artificial intelligence poses grave risks to humanity, then a professor at Carnegie Mellon University has one of the most important roles in the tech industry right now. Zico Kolter leads a 4-person panel at OpenAI that has the authority to halt the ChatGPT maker’s release of new AI systems if it finds them unsafe. That could be technology so powerful that an evildoer could use it to make weapons of mass destruction. It could also be a new chatbot so poorly designed that it will hurt people’s mental health. “Very much we’re not just talking about existential concerns here,” Kolter said in an interview with The Associated Press. “We’re talking about the entire swath of safety and security issues and critical topics that come up when we start talking about these very widely used AI systems.” OpenAI tapped the computer scientist to be chair of its Safety and Security Committee more than a year ago, but the position took on heightened significance last week when California and Delaware regulators made Kolter’s oversight a key part of their agreements to allow OpenAI to form a new business structure to more easily raise capital and make a profit. Safety has been central to OpenAI’s mission since it was founded as a nonprofit research laboratory a decade ago with a goal of building better-than-human AI that benefits humanity. But after its release of ChatGPT sparked a global AI commercial boom, the company has been accused of rushing products to market before they were fully safe in order to stay at the front of the race. Internal divisions that led to the temporary ouster of CEO Sam Altman in 2023 brought those concerns that it had strayed from its mission to a wider audience. The San Francisco-based organization faced pushback — including a lawsuit from co-founder Elon Musk — when it began steps to convert itself into a more traditional for-profit company to continue advancing its technology. Agreements announced last week by OpenAI along with California Attorney General Rob Bonta and Delaware Attorney General Kathy Jennings aimed to assuage some of those concerns. At the heart of the formal commitments is a promise that decisions about safety and security must come before financial considerations as OpenAI forms a new public benefit corporation that is technically under the control of its nonprofit OpenAI Foundation. Kolter will be a member of the nonprofit’s board but not on the for-profit board. But he will have “full observation rights” to attend all for-profit board meetings and have access to information it gets about AI safety decisions, according to Bonta’s memorandum of understanding with OpenAI. Kolter is the only person, besides Bonta, named in the lengthy document. Kolter said the agreements largely confirm that his safety committee, formed last year, will retain the authorities it already had. The other three members also sit on the OpenAI board — one of them is former U.S. Army General Paul Nakasone, who was commander of the U.S. Cyber Command. Altman stepped down from the safety panel last year in a move seen as giving it more independence. “We have the ability to do things like request delays of model releases until certain mitigations are met,” Kolter said. He declined to say if the safety panel has ever had to halt or mitigate a release, citing the confidentiality of its proceedings. Kolter said there will be a variety of concerns about AI agents to consider in the coming months and years, from cybersecurity – “Could an agent that encounters some malicious text on the internet accidentally exfiltrate data?” – to security concerns surrounding AI model weights, which are numerical values that influence how an AI system performs. “But there’s also topics that are either emerging or really specific to this new class of AI model that have no real analogues in traditional security,” he said. “Do models enable malicious users to have much higher capabilities when it comes to things like designing bioweapons or performing malicious cyberattacks?” “And then finally, there’s just the impact of AI models on people,” he said. “The impact to people’s mental health, the effects of people interacting with these models and what that can cause. All of these things, I think, need to be addressed from a safety standpoint.” OpenAI has already faced criticism this year about the behavior of its flagship chatbot, including a wrongful-death lawsuit from California parents whose teenage son killed himself in April after lengthy interactions with ChatGPT. Kolter, director of Carnegie Mellon’s machine learning department, began studying AI as a Georgetown University freshman in the early 2000s, long before it was fashionable. “When I started working in machine learning, this was an esoteric, niche area,” he said. “We called it machine learning because no one wanted to use the term AI because AI was this old-time field that had overpromised and underdelivered.” Kolter, 42, has been following OpenAI for years and was close enough to its founders that he attended its launch party at an AI conference in 2015. Still, he didn’t expect how rapidly AI would advance. “I think very few people, even people working in machine learning deeply, really anticipated the current state we are in, the explosion of capabilities, the explosion of risks that are emerging right now,” he said. AI safety advocates will be closely watching OpenAI’s restructuring and Kolter’s work. One of the company’s sharpest critics says he’s “cautiously optimistic,” particularly if Kolter’s group “is actually able to hire staff and play a robust role.” “I think he has the sort of background that makes sense for this role. He seems like a good choice to be running this,” said Nathan Calvin, general counsel at the small AI policy nonprofit Encode. Calvin, who OpenAI targeted with a subpoena at his home as part of its fact-finding to defend against the Musk lawsuit, said he wants OpenAI to stay true to its original mission. “Some of these commitments could be a really big deal if the board members take them seriously,” Calvin said. “They also could just be the words on paper and pretty divorced from anything that actually happens. I think we don’t know which one of those we’re in yet.” Related: OpenAI Atlas Omnibox Is Vulnerable to Jailbreaks Related: Red Teams Jailbreak GPT-5 With Ease, Warn It’s ‘Nearly Unusable’ for Enterprise Related: Grok-4 Falls to a Jailbreak Two Days After Its Release
securityweek.comNov 3, 2025extracted
Stragglers From Myanmar Scam Center Raided by Army Cross Into Thailand as Buildings are Blown Up
The number of people fleeing from Myanmar to Thailand after Myanmar’s military shut down a major online scam center has slowed to a trickle, a Thai regional army commander said Tuesday, after more than 1,500 had left in the past week. The KK Park site, identified by Thai officials and independent experts as housing a major cybercrime operation, was raided by Myanmar’s army in mid-October as part of operations starting in early September to suppress cross-border online scams and illegal gambling. The center is located on the outskirts of Myawaddy, a major trading town on the border across from the Thai town of Mae Sot. The Myawaddy area is only loosely under the control of Myanmar’s military government, and shares power there with an allied local militia of the Karen ethnic minority operating as a Border Guard Force. Witnesses on the Thai side of the border reported hearing explosions and seeing smoke coming from the center over the past several nights starting on Friday. The Thai army’s Naresuan Task Force, which operates in Thailand’s northern region, said Monday that parts of KK Park were demolished by explosions carried out by Myanmar’s military and its Border Guard Force allies. Debris from the blasts caused damage to several houses on the Thai side of the border. The task force’s commander, Maj. Gen. Maitree Chupreecha, told The Associated Press that 25 people from four nations crossed into Thailand on Tuesday, though he didn’t identify their nationalities. Those who fled Myanmar are mostly believed to have worked at the center, often under duress. The authorities in Thailand’s Tak province, who have set up temporary shelters for them, said they come from 28 countries, including Thailand. They are being processed to determine if they were victims of human trafficking and and then can be repatriated to their home countries, which include India, China, the Philippines, Vietnam, Ethiopia and Kenya. Myanmar is notorious for hosting cyberscam operations, which recruit many of their workers from other countries under false pretenses, promising them legitimate jobs and then holding them captive and forcing them to carry out criminal activities. Myanmar’s independent media, including The Irrawaddy, an online news service, have reported that online scams in Myanmar continue to operate in the Myawaddy area even after the raid on KK Park. Cambodia is another major center for such operations, which garnered international attention on Oct. 14, when the United States and the United Kingdom enacted sanctions against organizers of a major Cambodian cyberscam gang, and its alleged ringleader was indicted by a U.S. federal court in New York.
securityweek.comOct 28, 2025extracted
Microsoft: Russia, China Increasingly Using AI to Escalate Cyberattacks on the US
Russia, China, Iran and North Korea have sharply increased their use of artificial intelligence to deceive people online and mount cyberattacks against the United States, according to new research from Microsoft. This July, the company identified more than 200 instances of foreign adversaries using AI to create fake content online, more than double the number from July 2024 and more than ten times the number seen in 2023. The findings, published Thursday in Microsoft’s annual digital threats report, show how foreign adversaries are adopting new and innovative tactics in their efforts to weaponize the internet as a tool for espionage and deception. AI’s potential said to be exploited by US foes America’s adversaries, as well as criminal gangs and hacking companies, have exploited AI’s potential, using it to automate and improve cyberattacks, to spread inflammatory disinformation and to penetrate sensitive systems. AI can translate poorly worded phishing emails into fluent English, for example, as well as generate digital clones of senior government officials. Government cyber operations often aim to obtain classified information, undermine supply chains, disrupt critical public services or spread disinformation. Cyber criminals on the other hand work for profit by stealing corporate secrets or using ransomware to extort payments from their victims. These gangs are responsible for the wide majority of cyberattacks in the world and in some cases have built partnerships with countries like Russia. Increasingly, these attackers are using AI to target governments, businesses and critical systems like hospitals and transportation networks, according to Amy Hogan-Burney, Microsoft’s vice president for customer security and trust, who oversaw the report. Many U.S. companies and organizations, meanwhile, are getting by with outdated cyber defenses, even as Americans expand their networks with new digital connections. Companies, governments, organizations and individuals must take the threat seriously if they are to protect themselves amid escalating digital threats, she said. “We see this as a pivotal moment where innovation is going so fast,” Hogan-Burney said. “This is the year when you absolutely must invest in your cybersecurity basics.” US is a popular target The U.S. is the top target for cyberattacks, with criminals and foreign adversaries targeting companies, governments and organizations in the U.S. more than any other country. Israel and Ukraine were the second and third most popular targets, showing how military conflicts involving those two nations have spilled over into the digital realm. Russia, China and Iran have denied that they use cyber operations for espionage, disruption and disinformation. China, for instance, says the U.S. is trying to “ smear ” Beijing while conducting its own cyberattacks. In a statement emailed to The Associated Press on Thursday, Iran’s mission to the United Nations said Iran rejects allegations that it is responsible for cyberattacks on the U.S. while reserving the right to defend itself.
securityweek.comOct 17, 2025extracted
Microsoft contro Israele: un punto di svolta per la sovranità digitale e dei dati
La decisione di Microsoft di sospendere l’erogazione di servizi cloud e di intelligenza artificiale a una delle principali unità militari israeliane segna un passaggio di rilievo nella relazione tra tecnologia e geopolitica. Un grande fornitore globale di infrastrutture digitali ha infatti scelto di limitare l’accesso a capacità avanzate di calcolo e archiviazione a un attore statale, mettendo in evidenza il ruolo dei provider nel definire, di fatto, i confini e le condizioni d’uso delle tecnologie. Indice degli argomenti Il provvedimento riguarda l’Unità 8200, la divisione delle Forze di difesa israeliane (Idf) responsabile delle attività di cyber intelligence e sorveglianza elettronica. Secondo quanto riportato dal Guardian, la scelta è stata motivata da una violazione dei termini di servizio: le infrastrutture cloud sarebbero state utilizzate per attività di sorveglianza di massa nei confronti della popolazione palestinese. In particolare, le inchieste di +972 Magazine e Local Call hanno documentato l’uso della piattaforma Azure per archiviare milioni di ore di comunicazioni telefoniche intercettate, oltre a messaggi di testo. Microsoft ha confermato di aver avviato un’indagine urgente, che per adesso ha portato all’individuazione di prove a sostegno delle accuse. In una lettera indirizzata al Ministero della Difesa israeliano, l’azienda ha dichiarato di non poter consentire che le proprie tecnologie vengano utilizzate per la sorveglianza di massa dei civili. La decisione non interrompe l’insieme delle collaborazioni tra Microsoft e Israele, ma si applica esclusivamente ai servizi forniti all’Unità 8200. La notizia ha assunto risonanza internazionale per diversi motivi. In primo luogo, il caso evidenzia la centralità dei servizi cloud come infrastrutture critiche. Azure, così come altre piattaforme analoghe, non offre solo capacità di archiviazione, ma integra strumenti di elaborazione distribuita, modelli di intelligenza artificiale, funzionalità di trascrizione automatica e analisi semantica dei dati. In contesti militari, tali risorse moltiplicano la capacità di sorveglianza e intelligence, consentendo di correlare in tempo reale grandi quantità di informazioni provenienti da fonti eterogenee. dipendenza da fornitori esteri In secondo luogo, la scelta di un provider commerciale di sospendere unilateralmente un servizio a un attore statale introduce una nuova dimensione nella gestione delle relazioni internazionali. Le aziende tecnologiche non sono più soltanto soggetti economici, ma assumono un ruolo diretto nella definizione dei limiti operativi di governi e forze armate. Se fino a pochi anni fa la sovranità digitale era intesa come una questione di capacità interne di protezione delle reti e dei dati, oggi deve includere la dipendenza da fornitori esteri in grado di bloccare servizi essenziali. Le prime reazioni da parte di Israele hanno avuto l’obiettivo di ridimensionare l’impatto del provvedimento. Secondo quanto riportato dall’Associated Press, fonti della sicurezza hanno affermato che non vi sarebbero conseguenze operative significative. Il Times of Israel ha riferito che l’Unità 8200 avrebbe predisposto backup dei dati e misure alternative per evitare interruzioni delle attività. Il Ministero della Difesa non ha diffuso comunicati ufficiali. La dinamica solleva interrogativi anche in termini di sovranità dei dati. Le inchieste di +972 Magazine hanno indicato che parte delle informazioni raccolte dall’Idf sarebbe stata conservata in data center Microsoft nei Paesi Bassi e in Irlanda, dove sarebbero stati archiviati oltre 11.500 terabyte di materiale, equivalenti a circa 200 milioni di ore di registrazioni vocali. Per ridurre la dipendenza da scelte esterne, molti Stati stanno investendo nello sviluppo di infrastrutture cloud nazionali o regionali, con requisiti specifici di controllo dei dati e delle piattaforme. L’affidamento di dati di rilevanza strategica a infrastrutture situate in altri Paesi espone a rischi non solo di natura tecnica, ma anche legati alla possibilità che scelte politiche o aziendali condizionino l’accesso a risorse critiche. Il caso assume rilievo anche in rapporto al crescente dibattito globale sull’uso delle tecnologie di sorveglianza. Le piattaforme di intelligenza artificiale permettono oggi di riconoscere volti, analizzare schemi comportamentali, trascrivere e indicizzare comunicazioni audio su larga scala. Tali strumenti, se impiegati senza garanzie adeguate, possono portare a pratiche di sorveglianza generalizzata, in contrasto con i principi di proporzionalità e tutela dei diritti fondamentali. Le linee guida introdotte negli ultimi anni da Microsoft e da altri provider hanno cercato di limitare l’uso di alcune funzionalità, come il riconoscimento facciale, imponendo procedure di accesso ristretto. La vicenda mostra quanto sia complesso garantire che le tecnologie non vengano impiegate in modo difforme dai termini contrattuali. Un ulteriore aspetto da considerare riguarda l’impatto sulle infrastrutture di sicurezza nazionale. La dipendenza da piattaforme cloud commerciali comporta indubbi vantaggi in termini di scalabilità, resilienza e accesso a capacità di calcolo avanzate. Ma nel momento in cui un fornitore decide di sospendere i servizi, si manifesta una vulnerabilità che può incidere direttamente sulla continuità operativa. Per gli Stati, questo scenario rappresenta un richiamo alla necessità di sviluppare piani di continuità che includano anche l’eventualità di interruzioni contrattuali o restrizioni imposte da soggetti privati. In prospettiva più ampia, la scelta di Microsoft potrebbe costituire un precedente per altre grandi aziende tecnologiche. La possibilità che i fornitori globali applichino in maniera più stringente i propri termini di servizio, fino a interrompere collaborazioni con governi, introduce un elemento di incertezza nelle relazioni internazionali. Si pensi, ad esempio, alle conseguenze che potrebbero derivare da decisioni simili in contesti diversi, in cui infrastrutture cloud sostengono sistemi critici in settori come energia, trasporti o sanità. Per la comunità internazionale, il caso Microsoft–Unità 8200 rappresenta un punto di osservazione privilegiato per comprendere le nuove dinamiche del rapporto tra tecnologia e sicurezza. L’interruzione di un servizio cloud non equivale a un attacco informatico, ma può produrre effetti analoghi in termini di indisponibilità e riduzione delle capacità operative. In questo senso, la resilienza delle infrastrutture digitali non dipende soltanto dalla protezione contro attori malevoli, ma anche dalla capacità di gestire il rischio connesso alle decisioni dei fornitori. La sospensione dei servizi da parte di Microsoft nei confronti dell’Unità 8200 mostra come la resilienza degli Stati non possa prescindere dalla consapevolezza che i fornitori globali di infrastrutture digitali hanno un ruolo importante nell’ecosistema della sicurezza. La capacità di anticipare tali scenari e di costruire alternative robuste diventa parte integrante della strategia di protezione delle infrastrutture critiche e della gestione delle crisi nel cyber spazio.
cybersecurity360.itSep 26, 2025extracted
Microsoft Reduces Israel’s Access to Cloud and AI Products Over Reports of Mass Surveillance in Gaza
Microsoft said Thursday it had disabled services to a unit within the Israeli military after a company review had determined its artificial intelligence and cloud computing products were being used to help carry out mass surveillance of Palestinians. The action comes after The Associated Press and The Guardian published reports earlier this year revealing how the Israeli Ministry of Defense had been using Microsoft’s Azure platform to aid in the war in Gaza and occupation of the West Bank. Brad Smith, Microsoft’s vice chair and president, wrote in a blog post that the company was taking steps to enforce compliance with its terms of service. An AP investigation in February showed that the Israeli military’s use of Microsoft products skyrocketed after a deadly surprise attack by Hamas militants on Oct. 7, 2023. The AP’s report cited internal Microsoft data showing the Israelis were using gigabytes of cloud storage and massive amounts of AI-enabled language translation services. The AP also reported that Israel’s military used Microsoft Azure to compile information gathered through mass surveillance, which it transcribes and translates, including phone calls and text messages. That intelligence is then cross-checked with Israel’s in-house AI systems for targeting airstrikes. AP reported that internal Microsoft data showed multiple Azure subscriptions were tied to Unit 8200, an elite cyber warfare unit within the Israeli Army responsible for clandestine operations, collecting signal intelligence and surveillance. Following AP’s report, Microsoft acknowledged in May that it had sold advanced AI and cloud computing services to the Israeli military during the Gaza war and aided in efforts to locate and rescue Israeli hostages. But the company said an internal review found “no evidence” its Azure platform was used to target or harm people. The Guardian, working in partnership with the Israeli-Palestinian publication +972 Magazine and the Hebrew-language outlet Local Call, reported in August that the commander of Unit 8200 had met directly with Microsoft chairman and CEO Satya Nadella in 2021. The Israeli unit then used Microsoft products to aid in the development of an AI-powered mass surveillance system that was sweeping up, translating and analyzing millions of telephone calls per day made by Palestinian civilians. The report also revealed that data from the Israeli surveillance system was being stored at Microsoft cloud data centers in Europe. Following The Guardian’s report, Microsoft commissioned a second review, this time by an outside law firm. While that review is still ongoing, Smith said Thursday the probe had uncovered evidence that its products were being used in violation of its terms of service. However, Smith did not name the specific Israeli unit losing access to Microsoft services. Microsoft declined to answer detailed questions from the AP on Thursday, including whether Unit 8200 was involved. The company would also not answer how it would ensure the Israeli military wouldn’t simply shift its mass surveillance operations to any of the hundreds of other Azure subscriptions under its control. An Israeli security official told the AP Microsoft’s move would produce “no damage to the operational capabilities” of the Israel Defense Forces. The official spoke on condition of anonymity, consistent with military protocol in Israel. Hossam Nasr, one of more than a dozen Microsoft employees fired or arrested after protests over the company’s involvement in the war in Gaza, called Thursday’s announcement a “significant and unprecedented win.” But, he said, it was not enough. “Microsoft has only disabled a small subset of services to only one unit in the Israeli military,” said Nasr, an organizer with the group No Azure for Apartheid. “The vast majority of Microsoft’s contract with the Israeli military remains intact.” Related: Google Ships Android ‘Advanced Protection’ Mode to Thwart Surveillance Spyware Related: Surveillance Firm Bypasses SS7 Protections to Retrieve User Location
securityweek.comSep 26, 2025extracted
Taliban bans fiber-optic internet in several Afghan provinces to curb ‘immorality’
Taliban bans fiber-optic internet in several Afghan provinces to curb ‘immorality’ The Taliban’s supreme leader has ordered the shutdown of fiber-optic internet across five northern Afghan provinces, a move critics say will deepen the country’s isolation, damage its economy and further curtail women’s access to education. Officials in Balkh, one of Afghanistan’s most populous provinces, confirmed earlier this week that internet cables had been disconnected following a “complete ban” issued by Hibatullah Akhundzada, the Taliban’s reclusive leader. Haji Attaullah Zaid, a provincial spokesman, told the Associated Press the restriction was intended “to prevent immorality” and said authorities planned to build a domestic alternative. The ban, which also extends to Kunduz, Badakhshan, Baghlan and Takhar provinces, marks the first time the Taliban have imposed such a restriction since retaking power in August 2021. Mobile internet remains available, but prepaid cards are costly and connections unreliable, according to local media reports. NetBlocks, an internet-monitoring service, confirmed a drop in connectivity in Afghanistan, adding that parts of the country are now falling offline. Rights groups, business leaders and opposition figures condemned the move, warning it would sever Afghanistan’s remaining ties with the outside world. “This action represents not only a severe restriction on freedom of expression and access to information but also a deliberate attempt to cut off the Afghan people from the world,” said an open letter from an Afghan women’s rights organization. “They are cutting Afghans off from every opportunity for education, progress, and hope.” For Afghan women, who are already barred from schools and universities, the consequences are especially dire. “Many girls in Afghanistan were secretly learning online. Now, the Taliban cut the internet, and I can no longer teach them,” said Maria Noori, a rights activist. “When girls are denied learning, society’s future is at risk.” The Afghanistan Media Support Organization echoed those concerns, calling the blackout “a grave threat to freedom of expression and the work of the media.” Zalmay Khalilzad, the former U.S. ambassador to Afghanistan, said the measure would “damage not only the province’s economy but the country’s prospects as a whole.” He dismissed the justification as “absurd and insulting,” asking: “On what basis does the leadership in Kandahar assume that the good Muslims of Balkh are using the internet for pornography?” Ali Maisam Nazary, head of foreign relations for the National Resistance Front, the country’s main armed opposition group, called the decision proof of the Taliban’s “era of terror and tyranny.” He urged the international community to empower Afghans “to resist and ultimately defeat this extremism.” Governments around the world are increasingly using internet restrictions to stifle dissent during political crises and suppress freedom of speech. Earlier this month, Nepal restricted access to 26 platforms — including Facebook, Instagram, WhatsApp, Signal, YouTube and X — triggering violent clashes between young protesters and police. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaSep 18, 2025extracted
Mar Rosso, il taglio dei cavi sottomarini ha rallentato il cloud di Microsoft. Attacco mirato?
Il cloud Azure di Microsoft ha subìto dei rallentamenti dopo che alcuni cavi sottomarini nel Mar Rosso sono stati tranciati. Al vaglio, c’è l’ipotesi di un attacco mirato. Malfunzionamenti per il cloud Azure di Microsoft Dallo scorso sabato il cloud Azure di Microsoft ha palesato malfunzionamenti in diversi Paesi asiatici, dopo il danneggiamento di alcuni cavi sottomarini nel Mar Rosso. L’organizzazione NetBlocks, che monitora l’accesso a Internet, ha confermato che i tagli hanno interessato anche l’India e Pakistan. La compagnia ha subito deviato il traffico su percorsi alternativi, notificando disservizi fino al completamento delle riparazioni. Tuttavia, il colosso con base a Redmond ci ha tenuto a precisare che, al di fuori dei traffici dell’Asia occidentale, Azure non ha subito compromissioni. Quello dei cavi sottomarini è un settore strategico (trasportano più del 99% del traffico dati intercontinentale), nonché un mercato in grande espansione. Dalle stime più recenti, infatti, dovrebbe crescere fino a raggiungere un valore economico da 59,3 miliardi di dollari entro il 2032. Un possibile attacco mirato Il Mar Rosso costituisce il fulcro delle relazioni tra Asia ed Europa. Per questo, eventuali azioni belliche possono causare danni economici di grande portata. Già l’anno scorso, in quella stessa area, diversi cavi furono tranciati, compromettendo il traffico tra Asia ed Europa. Secondo la Pakistan Telecommunication Company, i tagli più recenti sono avvenuti nei pressi della città saudita di Jeddah, con possibili ripercussioni sui servizi Internet durante le ore di punta. Per l’Associated Press la responsabilità dell’azione potrebbe essere degli Houthi, con l’obiettivo di mettere pressione su Israele affinché interrompa le operazioni militari nella Striscia di Gaza. Il gruppo yemenita ha tuttavia negato di aver attaccato queste infrastrutture in passato. L’importanza della sicurezza Se da una parte queste infrastrutture possono essere oggetto di sabotaggi, dall’altra incidenti simili possono essere frutto semplicemente di negligenza. In molti casi, infatti, basta il lancio di un’ancora da una nave per colpirle. Le riparazioni possono richiedere settimane, poiché le navi e gli equipaggi di tecnici devono posizionarsi precisamente sopra il cavo danneggiato. Viste le stime di crescita del settore, dovranno allora anche aumentare gli investimenti per il mantenimento della sua sicurezza. Ogni interruzione dei cavi sottomarini può causare blackout parziali, rallentamenti globali e conseguenze economiche pesanti. E’ perciò doveroso intervenire tempestivamente, quantomeno per limitare i danni. Tra i nuovi sistemi implementati in materia, ci sono degli strumenti avanzati di monitoraggio e manutenzione predittiva, fondamentali per prevenire i guasti e gli attacchi.
cybersecitalia.itSep 8, 2025extracted