Search/crowdstrike
Vendor

crowdstrike

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
falcon
Connections
321 relationships
Benchmaxxing: When the Benchmark Becomes the Target
Public benchmarks in AI provide important signals and allow for regression testing, directional validation of model updates, and public discussion of capabilities and limitations. But the more attention a benchmark receives, the stronger the incentive to optimize for it. Once a score becomes the goal, teams start benchmaxxing: optimizing for the benchmark rather than the capability it is meant to measure. This is a familiar problem in the AI space. As Goodhart’s Law suggests, measures become less useful when they become targets. Gaming, ceiling effects, and data leakage erode the signaling value of doing well on public benchmarks. In the AI and cybersecurity space, the problem carries greater consequences because benchmark results can shape real security decisions. The industry has seen this before. Last decade, we called it "detection coverage" and learned through experience that vendors passing canned tests was a poor proxy for stopping adaptive adversaries in real environments. As AI becomes more deeply embedded in cybersecurity, we should not repeat the same mistake with a new class of benchmarks. In this blog, we examine the limitations of public cyber benchmarks and describe an approach for task-coupled internal benchmarks that drive rigorous science rather than optimizing for visibility or attention. The Challenges of Cyber Benchmarking The headlining failure of most cyber-relevant AI benchmarks is that they fail to measure what matters most: the ability of defensive cyber agents to reason end-to-end across exploits, telemetry, and environments, and generate novel detection or remediation strategies. In short, benchmarks fail to measure the ability to stop breaches. Benchmarks typically need ground truth for scoring, making them retrospective and often binary. This does not reflect defenders’ real challenges, which are constantly novel and epistemically gray. Benchmarks also rarely report the harms caused by mistakes, while leaderboards commonly downplay costs and times. Those factors are critical, especially as, for instance, eCrime breakout times are plummeting. By comparison, the reference action, human red teaming and detection generation, is well understood. Overall scores often obfuscate subpopulations where solvers perform poorly. A scoreboard might show 97%, but if that 3% falls within a group of jointly exploitable attack paths, the aggregate score has little construct validity. While benchmarks can be useful regression tests, their headlining results are structurally biased against generalizing to the real world. Contamination from direct or indirect leakage, solution leakage, and retrospective tasks all lower the upper bound on generalization. When the same model and harness are shipped, they will almost certainly underperform on novel stimuli. Overfitting, an inevitable result of benchmaxxing pressure, can also occur due to repeated evaluation. Every development cycle that checks the public test set and adjusts accordingly leaks information into the model, even with zero gradient updates. More subtly, publication bias causes the error distribution to be skewed strongly downward, as published results are likely drawn from surprisingly strong runs that are unlikely to be repeated. Common reporting patterns compound this problem by downplaying the probabilistic nature of results from agentic workflows. “Solved it in at least one of ten attempts” with an unbounded budget is grade inflation, not rigor. While these issues may seem esoteric or statistical, there are also more basic issues with benchmark scores because of the extent to which agents cheat. Dreadnode reported last month that more than a third of all passes on individual tasks on Cybench, across nearly every model assessed, involved cheating. In these cases, models searched postmortems on attacks, probed evaluation infrastructure, and read or inferred answers or paths from evaluation container metadata. When cheating is this prolific, benchmarks are not only measuring the wrong thing, they are doing so poorly. Public cyber benchmarks can also create information that benefits adversaries. Leakage, and even test questions themselves, can be used for model training or uplift. The public nature of benchmarks may also help adversaries understand which existing vulnerabilities are considered important enough to measure, and how detectable they are. Advanced adversaries may reason about vulnerabilities that are not measured and treat those gaps as potential soft spots. How CrowdStrike Approaches Benchmarks and Evaluations At CrowdStrike, rigorous evaluations are core to guiding our fast-moving AI research and development agenda. Substantively, our evaluations are designed to directly measure the capabilities we care about across malware analysis, detection engineering, threat intelligence comprehension and synthesis, log and telemetry analysis, and incident response reasoning. They measure real outputs against live problems, with increased realism driven by high-quality digital twins of real-world customer environments and increased difficulty driven by adversary tradecraft emulation. Being exceptionally difficult is a hallmark of our evaluations. Evaluations and benchmarks at CrowdStrike are intended to be living methods, not static checks. Public benchmarks provide useful common reference points, but for organizations deploying frontier AI, the most meaningful measures of success are private evaluations grounded in their own data, systems, workflows, and operational outcomes. These evaluations test whether an AI system can perform reliably where it will actually be used, not simply whether it can score well on a widely known test. Instead of optimizing for success in loosely related tasks, CrowdStrike’s benchmarks are task-coupled to support sharp decision-making. We are applying this approach in practice today. Our teams introduce novel evaluation content, rotate validation sets, and assess capabilities against cybersecurity problems that reflect real operational conditions. This helps preserve benchmarks as useful mileposts while creating more relevant tests that evolve with the systems being evaluated and reduce opportunities for benchmaxxing. We also separate evaluation developers from our solution architects. This firewalling helps limit leakage and preserve the credibility of evaluations over time. Our deployment methodology supports many-time/any-time runs at scale, allowing us to measure the full error distribution of solvers and report them meaningfully. Further, our measurement scheme goes well beyond task completion to include other factors that matter in the real defensive world, including cost, latency, stealth, and completeness. Public benchmarking still has an important role when it advances shared industry understanding. In partnership with Meta, CrowdStrike introduced CyberSOCEval, an open-source benchmark suite designed around real-world SOC workflows, adversary tradecraft, and operational outcomes. Ultimately, the goal is not to produce the highest benchmark score, but to build evaluations that tell us whether AI systems can deliver reliable defensive outcomes against the complexity and uncertainty of real-world cyber threats. Additional Resources Learn how CrowdStrike Falcon® AI Detection and Response secures AI. Download our guide to explore the five steps for frontier AI security readiness. Explore cutting-edge cybersecurity research at Day Zero 2026, a summit for the threat research community. Experience Fal.Con 2026 from anywhere with Fal.Con Digital, featuring keynote livestreams and on-demand access to 100+ sessions.
crowdstrike.comAug 19, 2026extracted
Security Hub Extended adds Supply Chain Security as its tenth category
Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted a partner reception that brought our leadership together with partner executives to plan what comes next. These are companies investing real engineering and real go-to-market (GTM) alongside us, and increasingly with each other, because the model resonates with the customers they’re talking to every day. The most common question we heard at the booth was when Supply Chain Security was coming. It’s here. And that’s the thing I want to spend the most time on today, because it’s the category customers keep asking us about. Supply Chain Security: The category customers have been asking for Software supply chain risk has moved from a security-team concern to a board-level conversation. SolarWinds showed what happens when a build system is compromised. Log4j showed what a single transitive dependency vulnerability can do at global scale. The xz utils backdoor showed the patience of a maintainer-compromise attack executed over years. Each demonstrated a different dimension of the same problem, and the pace is accelerating. Attackers know that a fast way into an enterprise is through the open source packages that enterprise unknowingly trust. Every customer I talked to at Black Hat had this on their risk register. Most still hadn’t operationalized a solution, because doing so meant a standalone deployment, a new contract, a new console, and integration work their security team couldn’t prioritize. That’s the friction we aim to remove. Security Hub Extended now offers Supply Chain Security with Chainguard and Socket as the curated partners. Supply Chain Security uses the same model as everything else in Extended. Every offering has pay-as-you-go pricing, one bill, no required long-term commitment. For enterprises that prefer to continue using the procurement process they always have, Security Hub Extended Private Offers are also available. These are committed term agreements with deeper discounts, the ability to aggregate spend across partners on a single AWS bill, and both monthly and annual payment options throughout the term. You pick the path that fits how you buy. What Chainguard does Chainguard gives you open source dependencies rebuilt from source in a hardened, verified build process, so what enters your environment is malware-resistant and provenance-backed. Their research shows that rebuilding from source would have stopped 98% of known malicious packages from ever reaching production. If you can’t verify the source, it never appears in the Chainguard repository. That’s the filter between the public registry and your developers. What Socket does Socket analyzes the actual behavior of open source packages to block malicious dependencies at the time of install. Not after a Common Vulnerability and Exposures (CVE) is published days or weeks later. At the moment the package tries to land in your environment, Socket flags it based on what it does, not what a database says about it. Its reachability analysis then tells you which vulnerabilities are exploitable from your code instead of drowning your team in noise. You pay for the distinct packages you check, not for how often your builds run. Why they work together Together, Chainguard and Socket cover the two questions that matter: Can I trust what I’m pulling in? Can I stop malicious components before they get built into my applications? Chainguard helps secure the foundation your code is built on. Socket secures the packages you pull into it. Both help protect your software supply chain regardless of where you deploy—across clouds or on-premises. Activate both through Security Hub Extended and their findings flow into Security Hub in OCSF (Open Cybersecurity Schema Framework) alongside everything else, so a supply chain risk is correlated and prioritized next to your endpoint, identity, and cloud signals. From there, it routes out to the downstream tools you’ve already integrated, so it fits the pipeline your builders run today. 23 partners, 10 categories. Built on what customers asked for Every partner in Security Hub Extended is here because customers told us they needed that capability and that specific solution was already working for them. We add categories because the threat landscape evolves, and we add partners because customers point us to who’s solving those problems well. The goal is straightforward: Simplify adopting the security solutions your peers are already succeeding with, through the AWS relationship you already have. The full set today spans endpoint, identity, email, network, data, browser, cloud, AI, security operations, and now supply chain. The 23 curated partners are 7AI, Britive, Chainguard, CrowdStrike, Cyera, Island, LayerX, Native Security, Noma, Okta, Oligo, Opti, Palo Alto Networks, Proofpoint, SailPoint, SentinelOne, Socket, Splunk, Sublime, Upwind, Varonis, Zenity, and Zscaler. Our focus now is deepening integrations and reducing activation friction so these solutions work together, not in isolation. That’s where the real value compounds. What we’re building next Everything I’ve described so far is the commercial model working: Customers buying best-of-breed security through one AWS relationship with the flexibility they expect. But the bigger vision is the integration layer that makes these tools genuinely better together, not just easier to buy together. The integration we’re most focused on is cross-partner correlation, turning signals from an endpoint solution, an identity solution, and a cloud solution into one exposure and one attack path instead of three disconnected alerts. Right alongside that, we’re dramatically reducing the activation, deployment, and integration friction so customers go from subscribing to seeing value in hours rather than weeks. Both efforts enable the curated solutions you already trust to deliver stronger outcomes together than they do apart. That’s the build we’re accelerating with our partners now, and you’ll hear more leading into re:Invent. Explore what’s available If you’re running open source in production and don’t yet have supply chain visibility, start there. Activate Chainguard and Socket through the Security Hub console today. If you’re managing multiple security vendor relationships and want to understand what consolidation looks like with Security Hub Extended, talk to your AWS account team. Pricing for every partner is published on our pricing page , no sales call required. And if you’re already using Security Hub for posture management and threat detection, the Extended plan is available in the same console you already use. We’re just getting started. If you have feedback about this post, submit comments in the Comments section below. Michael Fuller Michael has been with AWS for 16 years and led product for AWS Security Services for 11 years. Michael has 29 years in the industry and held several roles in product management, business development, and software development for IBM, Cisco, and Amazon. Michael has a Bachelor’s of Science in Computer Engineering from the University of Arizona and an MBA from the University of Washington.
aws.amazon.comAug 18, 2026extracted
Teaching AI to Reason Through Detection Triage
Every security alert begins with a deceptively simple question: Is this a real threat or just noise? Detection triage sits at the front of the response lifecycle, where answering this question quickly and accurately can determine what gets investigated, prioritized, or safely closed. CrowdStrike’s NVIDIA Nemotron-powered detection triage models already answer this question at machine speed, reading a detection and producing a true positive (TP) or false positive (FP) verdict with a calibrated confidence score. But experienced analysts do more than arrive at a verdict. They reason toward weighing evidence across command lines, behavioral context, and other signals to understand not only what happened, but why it matters. So we taught our triage model to do the same. Our latest research paper, “Cybersecurity Detection Classification with Reasoning-enabled Language Models” (Khanna et al., July 2026) which supports the Open Secure AI Alliance, trains a CrowdStrike Charlotte AI™ triage classifier to reason through a detection step by step, and produce a transparent chain of reasoning, before it commits to a verdict. The result is more accurate triage, more detections that can be safely automated, and a rationale that SOC analysts can read, evaluate, and trust. Below are the broader lessons from our findings: Reasoning makes triage better and more transparent: Teaching the model to think through a detection improves accuracy while producing an auditable rationale that analysts can evaluate. More automation is done safely: Large gains in high-confidence recall mean more benign alerts are auto-closed and more real threats can be prioritized for analysts, directly reducing alert fatigue. Specialization beats scale: A fine-tuned Nemotron 3 Nano 30B-A3B open model outperforms frontier general-purpose models many times its size on this task. (See figure 2) The agentic SOC keeps advancing: This research, currently focused on Windows endpoint detections, points to where our NVIDIA Nemotron 3 Nano 30B-A3B-powered triage is headed next, with more platforms to follow. From Labels to Reasoning The conventional approach to LLM-based triage asks the model to read a detection and output a label directly. This is fast and scalable, and produces a usable confidence score; however, it treats a reasoning-driven task as an instinctive response. Chain-of-thought reasoning changes that. Before deciding, the model works through the evidence in the detection: what the process is doing, where it came from, whether the parent-child process chain looks legitimate, and how the pieces fit together. This reasoning trace empowers better verdicts and provides an auditable explanation that an analyst can review, turning an opaque label into a decision they can stand behind. How We Trained the Model to Reason Getting a model to reason well about real detections took a four-stage training recipe, each stage building on the last: Prompt optimization: We automatically searched for the strongest possible reasoning prompt rather than hand-writing one. Crucially, we guarded the search with an LLM judge that rewarded genuine multi-field reasoning, preventing the model from collapsing into brittle numeric shortcuts that score well but don't generalize or explain anything useful. Self-training: The model learned from its own best work. It generated reasoning traces, kept the ones that reached the correct verdict, and fine-tuned them, concentrating its effort on the hardest detections it hadn't yet mastered. Reinforcement learning with verifiable rewards: Because a triage verdict is either right or wrong, we could reward the model directly for correct, well-formed answers. This allows it to discover better reasoning strategies on its own. Notably, it became both more accurate and more concise, reasoning in fewer tokens over the course of training. Confidence calibration: Reasoning introduces a subtle problem: Once the model has argued its way to a conclusion, its final label token is nearly always near-certain, so the token's probability is no longer a trustworthy confidence signal. We solved this by training a separate calibrator that reads the full reasoning trace and estimates the probability that the verdict is correct, restoring the reliable confidence score that automated triage depends on. Results The payoff shows up where it matters most: at the high-confidence operating point that governs automated triage. At this tier, detections can be auto-closed or prioritized with minimal analyst intervention, so higher recall here translates directly into more workload removed from the queue. Compared to the direct-label approach, the reasoning-enabled system surfaces dramatically more actionable detections at the same high precision. This 43.0 percentage point increase in high-confidence false positive recall means far more benign alerts can be automatically and safely closed, while the 18.3 percentage point gain in true positive recall means more genuine threats can be prioritized for analysts. Just as striking is what delivers this performance. The reasoning system reaches 82.6% overall accuracy, well above every off-the-shelf model we tested, including frontier general-purpose models many times its size. In our comparisons, leading general-purpose models clustered around 55% to 71% accuracy on this task, roughly in line with an untrained NVIDIA Nemotron 3 Nano 30B-A3B model and well below the fine-tuned result.
crowdstrike.comAug 17, 2026extracted
Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
Twenty-one cybersecurity-related merger and acquisition (M&A) deals were announced in July 2026. For a detailed view of the more than 420 acquisitions announced in 2025, check out SecurityWeek’s annual M&A report. Here are some of the most important cybersecurity M&A deals announced in July 2026: Bank of America announced plans to acquire UK-based information security consultancy MDSec Consulting Limited. MDSec provides technical information security consulting services and employs roughly 65 cybersecurity professionals. The acquisition will expand Bank of America’s presence in northern England. Barracuda Networks has acquired Texas-based Evo Security for an undisclosed amount. The deal expands Barracuda’s BarracudaONE platform by integrating multi-tenant identity, IAM, and PAM capabilities for MSP partners. San Francisco-based Cribl acquired Israeli AI detection engineering startup CardinalOps. The acquisition brings automated detection engineering to Cribl’s AI platform to improve threat coverage and lower log management costs for enterprise SOCs. Cribl is establishing a new office in Tel Aviv following the acquisition. Cybersecurity titan CrowdStrike is buying the patents and source code of Israel’s XM Cyber from Schwarz Group for an undisclosed amount. The transaction allows CrowdStrike to integrate exposure management and attack-path analysis directly into its offerings. It’s unclear how much CrowdStrike has paid for the XM Cyber IP, but Schwarz Group acquired XM Cyber in 2021 for $700 million. California/Israel-based Cyera has agreed to acquire Israeli startup Oasis Security in a transaction valued at around $1 billion. The move unifies Cyera’s data security platform with Oasis’s non-human identity governance to protect enterprise AI agents and service accounts. Infoblox has entered into a definitive agreement to purchase network intelligence and observability platform Kentik for an undisclosed amount. The integration blends Infoblox’s DNS/network context with Kentik’s real-time network traffic visibility to strengthen hybrid cloud cyber resilience. Okta signed an agreement to acquire Palo Alto-based Permiso Security, reportedly for roughly $200 million. The acquisition equips Okta with continuous identity threat detection (ITDR) capabilities to protect human, machine, and autonomous AI identities across cloud environments. Palo Alto Networks plans to acquire user-focused mobile and web observability platform Embrace. Palo Alto Networks will integrate Embrace’s mobile observability and real-time user telemetry into its platform to unify mobile experience monitoring and threat visibility. Qualcomm acquired Israeli IoT cybersecurity startup SAM Seamless Network, reportedly for over $100 million. The deal embeds SAM’s network security software into Qualcomm’s wireless chipsets and gateways to safeguard communication networks. SAM customers include US telecom giants AT&T and Verizon. Other cybersecurity M&A deals announced in July 2026: Related: Cybersecurity M&A Roundup: 37 Deals Announced in June 2026
securityweek.comAug 13, 2026extracted
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820) Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-68820 is a use-after-free flaw that affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and allows a low-privileged local attacker to elevate privileges to SYSTEM. “A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition,” Microsoft explained. “User interaction is not required.” Check Point researchers reported that the vulnerability has been exploited by North Korean attackers to deploy a kernel-mode rootkit in a new wave of the Operation Dream Job campaign. The three publicly disclosed vulnerabilities are: CVE-2026-62832, a vulnerability in the Windows User Profile Service that may allow an authenticated attacker to achieve Admin privileges by running a specially crafted application. “This is the flaw behind ‘LegacyHive,’ the unpatched proof-of-concept released by researcher Nightmare-Eclipse just hours after July’s Patch Tuesday,” commented Chris Goettl, VP of Product Management for security products at Ivanti. “This vulnerability lets a standard user coerce the User Profile Service into loading another user’s registry hive – including an administrator’s – to gain unauthorized access to that user’s Classes registry data.” CVE-2026-72971 affects the Windows Container Isolation FS Filter Driver (unionfs.sys), which may allow authenticated attackers to tamper with a vulnerable system. (This one only affectes Windows 11 versions for ARM64-based Systems.) Crowdstrike flagged a third vulnerability that was publicly disclosed before the patch was made available: CVE-2026-62737, a elevation of privilege vulnerability affecting the Windows kernel “While not officially recognized by Microsoft as publicly disclosed, a Chinese-language blog was published on August 9, 2026, describing a proof-of-concept exploit that can cause a system crash,” the company noted. Other vulnerabilities of note fixed this month include: CVE-2026-62815, a critical Microsoft QUIC vulnerability that can be exploited by unauthenticated attackers by sending a specially crafted packet to an affected service over the network. “Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required,” Microsoft says. CVE-2026-62878, a stack-based buffer overflow vulnerability in Windows DNS that can lead to remote code execution. This one can also be easily, reliably and remotely exploited by unauthenticated attackers. CVE-2026-63520, in Microsoft Sharepoint, discovered by Rapid7 researchers. It can be used in conjunction with CVE-2026-55040, a previously patched Sharepoint flaw, to achieve unauthenticated remote code execution against a vulnerable server. A Microsoft Defender zero-day exploit In related news, the security researcher who goes by “Nightmare Eclipse” released a proof-of-concept (PoC) exploit that ostensibly bypasses the patch for CVE-2026-50656, the “RoguePlanet” Microsoft Defender vulnerability the company pushed out in July 2026. Dubbed “ShieldBreak” by the researcher, the vulnerability professedly affects Windows 11, 10 and Windows Server 2025. Vulnerability analyst Will Dormann confirmed that the PoC exploit works if Defender is enabled. Security researcher and former Microsoft employee Kevin Beaumont noted that the ShieldBreak exploit (aka RoguePlanet 2) “operates very differently” that the initial RoguePlanet exploit. “RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files. ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API),” he explained, and released detections and hunting queries for the latter. He confirmed that ShieldBreak works on the latest Windows 11 version. Vulnerability analyst Will Dormann confirmed that the PoC exploit works if Defender is enabled and he also thinks ShieldBreak doesn’t seem to be a RoguePlanet bypass. Don’t rush and test patches “This volume of updates indeed seems to be the new normal – at least for now. What is interesting is that, while there is an explosion of bugs being reported (and fixed), there has been no equivalent increase in the number of bugs being actively exploited, at least as 0-days,” says Dustin Childs, head of threat awareness at TrendAI’s Zero Day Initiative. He also pointed out that Microsoft listing actively exploited bugs as “Unproven” or downplaying working Pwn2Own exploits may force security teams to perform independent risk triage. Ivanti’s Goettl says that the patches need to be triaged to identify CVEs that require immediate attention and that organizations need to remember that CVEs with high CVSS scores but which are not exploited or are not in internet-facing systems can be handled in a second round of patching. Tyler Reguly, Associate Director, Security R&D at Fortra, says that despite the latest mega-updates, IT admins and security teams should keep calm and not rush updates: “You need to make sure that you are rolling out safe updates that will not negatively impact your systems.” His advice for CISOs is to talk to their teams about how they are shifting or modifying their workflows to better accommodate this patching shift, and support them by enabling the changes they want to see made. UPDATE (August 13, 2026, 04:10 a.m. ET): The section about the ShieldBreak exploit has been rewritten to reflect new insight from security researchers who tested it. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comAug 12, 2026extracted
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, and incident response. OpenAI says GPT 5.6 Cyber is only available to select companies, including Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps. It's also rolling out to supported security vendors, including Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare. OpenAI says it won't give regular users access to the underlying models, citing security risks, and it makes sense because models have been abused to launch security attacks. Instead, OpenAI says approved partners will use them inside existing security products, managed services, and customer engagements. "By bringing our frontier cyber models into their services, we can help more defenders find serious vulnerabilities, validate which ones matter, and fix them faster," OpenAI wrote in a blog post. OpenAI offers Daybreak Blue and Daybreak Red for different security work OpenAI says partners can access two versions of ChatGPT's cyber capabilities through what the company calls Daybreak Access. Daybreak Blue is designed for a broad range of defensive security workloads, while Daybreak Red is intended for more specialized and closely governed work. OpenAI says the models can help security teams by: identifying vulnerabilities determining whether a weakness can actually be exploited identifying affected systems developing fixes helping move those fixes into production. Depending on the engagement, partners may use the models for vulnerability discovery and validation, red teaming, penetration testing, incident response, and remediation across enterprise environments. OpenAI says safeguards may include identity verification, clearly defined testing scopes, logging, monitoring, and human oversight. "Access to the underlying models remains with the approved partner and is not transferred directly to the customer," OpenAI explained. "Partners work with organizations to define the boundaries of each engagement, review findings, and apply their expertise before action is taken." The approach gives enterprises access to more advanced AI security capabilities without requiring them to build their own specialized cyber AI infrastructure. OpenAI says cybersecurity providers and consultancies can also apply to join the Daybreak Cyber Partner program, while organizations interested in using the technology can access it through participating security providers. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 10, 2026extracted
「正規ユーザー」を隠れみのに侵入 信頼された基盤を狙う最新サイバー脅威【調査】
CrowdStrike�̍ŐV���ɂ��ƁA�U���҂��M���ς݂̃��[�U�[��c�[�������p���ďd�v���Y�ڋ߂���X�������܂��Ă���BAI���̈��p�≹�����\�ɉ����APoC���J����48���Ԉȓ��̍U����88���ɏ��ȂǁA���p�̍��������������B ���̋L������������ł��B����o�^����ƑS�Ă������������܂��B �@CrowdStrike��2026�N8��3���i���n���ԁj�A�N�������u2026 Threat Hunting Report�v�����\�����B�������́A�U���҂�ID��Ղ�N���E�h�ASaaS�AAI�T�[�r�X�A�T�v���C��F�[���i�\�t�g�E�F�A�����ԁj�A�J�����ɂ����ĐM���ς݂̃��[�U�[��c�[����W�I�ɂ��A���K�̋Ɩ��v���Z�X�ɕ���ďd�v���Y�ڋ߂���X���������Ă���B �@����AI�̈��p�A�������\�A�Ǝ㐫���J����̐v���ȍU���A�J����Ղ�_���T�v���C��F�[���U���Ȃǂ��ۗ����ʂƂȂ����B �@AI�֘A�ɂ����ẮALLMJacking�L�����y�[���ɂ����2���ԂŖ�20������API�v�����������A�����ʂƉ^�p�ʂɑ傫�ȉe�����o���B�k���N�n�Ƃ���鋺�ЃA�N�^�[��FAMOUS CHOLLIMA�́A�M���ς݂�AI���𑫏�ɈÍ����Y��Ƃ�u���b�N��F�[����ƂN�������B�U���҂̑_���́A�閧���̐ގ��AI���f�����p���̕s���g�p�A�v�Z�����̒D��ɂ���BCrowdStrike�̊ϑ��ł́AAI�G�[�W�F���g�N�_�̌��m��₪���ƋN�_��2.5�{�ɒB���Ă���A�h�䑤�͈��ӂ��鋓���ƒʏ��AI�����Ƃ̌����������ɂ����Ȃ��Ă���B �@���B�b�V���O�i�������\�j�U���ɂ��N���́A2026�N�㔼����2025�N��������2�{�ɑ��������B�T�C�o�[�ƍߏW�c��CORDIAL SPIDER��SNARKY SPIDER�́A�������\���g���ăV���O���T�C���I���A�J�E���g��N�Q���ASaaS����f�[�^�������o�����BSNARKY SPIDER�ɂ����ł́A�A�J�E���g�̏����肩��f�[�^�ގ�܂ł�5�������������B�܂��A�[���R�[�h���g���t�B�b�V���O�̌��Ԏ��s�����A�ߋ�6�J����15�{�ɒ��ˏオ���Ă���B �@�Ǝ㐫�����p���鑬�x�������Ă���B2026�N1�6���ɊT�O���iPoC�j�����J���ꂽ�Z�L�����e�B�Ǝ㐫�̂����A�U����88����PoC���J����48���Ԉȓ��Ɋm�F���ꂽ�B�����n���ЃA�N�^�[��VAULT PANDA��GENESIS PANDA�́A�d�v��Web�A�v���P�[�V�����Ǝ㐫�̌��J����24���Ԉȓ��ɍU�����J�n�����BReact2Shell�̌��\��ACrowdStrike��4���Ԃ�80�����Q�g�D�Ɋւ���800���ȏ�̒������ɑΉ������B �@�x�����[�V�n���ЃA�N�^�[��UMBRAL BISON�́ALinux�̌������i�Ǝ㐫�iCVE-2026-31431�j��f�������p�����B2026�N4��29���̏����\�����PoC���J�̗����ɂ́ACrowdStrike���L�͂ȓW�J�����m���Ă���B�ŏ���24���ԂɊm�F���ꂽ���ۂ̂�����94���́A���JPoC����ɂ������������ł������B���Ђ͌��\�����20���Ԍ�Ƀx�����[�V�n�̊�������肵���B��[AI���Ǝ㐫������U���R�[�h�J�������������Ă���A���p�܂ł̎��Ԃ����������ɒZ�k����\���������Ă���B �@�T�v���C��F�[���U���ɂ����ẮA�U���҂�CI/CD��R���e�i���W�X�g���A�p�b�P�[�W���|�W�g���A�����J�����iIDE�j�̊g���@�\�N�����A�N�Q�����ˑ��p�b�P�[�W��M�����ꂽ�R���|�[�l���g�𑫊|����ɂ��ĉ������֔�Q���L���Ă���B���ЃA�N�^�[��ALTERED SPIDER�͂킸��1����300����ˑ����i��N�Q���A�F�؏������W���ăN���E�h���ֈړ������B�܂��A�k���N�Ƃ̊֗^���^���鋺�ЃA�N�^�[STARDUST CHOLLIMA��2026�N3���A���ݏo���������e�i�[�̔F�؏����g����Axios��npm�p�b�P�[�W��N�Q���AZshBucket�̊e���ł�z�z�����B�����6���ɂ́A������npm�p�b�P�[�W�����Ȃ��Ƃ�131��Mastra AI�t���[�����[�N���i�Ɉˑ��W�Ƃ��č����������B �@2026�N�㔼���ɓ��肳�ꂽ�\�t�g�E�F�A���|�W�g���ɂ����鋺�Ђ�87���́Anpm�֘A�ł������BJavaScript�̕��y�K�͂╡�G�Ȉˑ��W�A�����Ď������s�����C���X�g�[����������Q�g��ɗ��p����Ă���BCrowdStrike�͌��݁A�ǐՑΏۂƂ���290�ȏ�̍U���ҏW�c�𖽖����Ă���B����̕��͉ߋ�1�N�Ԃ̊ϑ��Ǝ�������A�M���W�𑫏�ɂ���U����AI��F�A�N���E�h�ASaaS�A�J����Ղ֍L�����Ă��錻������o�����B��A�̎���́A�U���҂����K�̌����╔�i���B��݂̂Ɏg������̍L�����@���Ɏ����Ă���B Copyright © ITmedia, Inc. All Rights Reserved.
itmedia.co.jpAug 5, 2026extracted
Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)
Many companies are showcasing their cybersecurity products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. To help cut through the clutter, the SecurityWeek team is publishing a digest summarizing vendor announcements at Black Hat USA 2026, including new products and services, updates to existing offerings, reports, and other initiatives. This is the third part of the series. You can also read Part 1 and Part 2 if you haven’t already. Above Security’s strategic investment from CrowdStrike Falcon Fund Above Security announced a strategic investment from the CrowdStrike Falcon Fund and integration with the CrowdStrike Falcon platform. Through the partnership, CrowdStrike customers will be able to extend their Falcon deployment, powering ready-made insider risk investigations with Falcon Next-Gen SIEM telemetry. Above correlates Next-Gen SIEM endpoint, identity, and third-party data into investigation-ready cases and streams completed investigations back into Falcon. ArmorCode launches vulnerability remediation agents ArmorCode announced four new Anya agents designed to help security teams analyze cloud risks, assess vulnerability exploitability, identify mitigation strategies, and coordinate patch orchestration. The company also added new Context Risk Graph capabilities for expanded attack path analysis, network reachability, and patch management. Commvault integrates Threat Scan with Google Threat Intelligence Enterprise cyber resilience company Commvault announced a new integration that will incorporate Google Threat Intelligence into Commvault Threat Scan workflows. This capability can help organizations identify clean recovery points faster, as well as reduce downtime and speed up recovery following cyberattacks. This announcement adds to Commvault’s ongoing collaboration with Google Cloud, including expanded cyber resilience capabilities for Google Cloud environments via Clumio, and support for Google Cloud workloads. CrowdStrike announces $100,000 international AI security challenge CrowdStrike announced AI Unlocked: Agents of Chaos, a global AI red teaming competition created with AWS that challenges participants to exploit rogue AI agents using prompt injection and other techniques to better understand emerging agentic AI security risks. The virtual competition, which begins on August 31 and features a $100,000 prize pool, is designed to give defenders hands-on experience securing AI agents as they become a growing enterprise attack surface. Dataminr threat landscape report Dataminr has published its 2026 Mid-Year Threat Landscape Report, finding that the average patch window in H1 2026 got 11 days longer. Meanwhile, attackers can break out in less than 30 minutes, and Dataminr tracked a 69.2% jump in alerts from the second half of 2025. DataBahn launches Federated Search and Orchestration DataBahn launched Federated Search and Orchestration, an expansion of its agentic data control plane that moves companies from applying intelligence after data has moved through pipelines to orchestrating it as the data moves. Enterprises can ask one question across every store they own without needing to copy any of the data, and hand it off to an AI agent to complete the investigation. FireMon integrates with Palo Alto Networks FireMon announced it has completed its product integration with Palo Alto Networks Strata Cloud Manager to deliver intelligent and interoperable solutions that enable joint customers to innovate faster and solve their most complex cybersecurity challenges. Intel 471 unveils new AI capabilities Intel 471 announced two new AI capabilities in the Verity471 platform: MCP471 and Agent471. With the addition of MCP471 and Agent471, Verity471 makes its pre-attack and threat-hunt intelligence more accessible and operationalizes it to help organizations detect and respond rapidly. Menlo Security extends platform to secure AI assistants and coding agents Menlo Security expanded its cloud-based Menlo Agent Runtime Security platform to protect AI assistants and coding agents from prompt injection attacks and data exfiltration. The platform routes agent web traffic through a cloud environment to sanitize files and strip hidden instructions before an agent receives the content. Adaptive data loss prevention controls mask sensitive information, while token-based authentication assigns per-agent session identity to enforce specific web access policies. Mimecast unveils Agent Risk Center and Managed Threat Response Mimecast announced a new expansion of its Incydr technology that discovers every AI agent and tool operating across an organization and ties each one back to the human who deployed it. The platform will also include a relaunched Managed Threat Response (MTR) service and expanded Google Workspace integrations. Palo Alto Networks introduces evolution of PAN-OS and publishes research Palo Alto Networks announced a new PAN-OS purpose-built for the Frontier AI era. PAN-OS 12.2 Ceres introduces Advanced Virtual Patching, automated blocking for direct-to-IP attacks, six AI security agents, and expanded hardware for securing AI data centers and critical infrastructure. Palo Alto Networks Unit 42 has also released new threat research detailing how an AI system built by its researchers uncovered more than 14,000 previously unknown vulnerabilities across nearly 4,000 widely used open source projects; and how analysis of more than 4 million reports found that 45.32% of malware with C&C activity communicates directly with IP addresses. Prophet Security research on AI in Security Operations Prophet Security has released its second annual State of AI in Security Operations report. An independent survey of 250 IT and cybersecurity professionals finds that security operations teams are reaching a breaking point as alert overload, AI-powered attacks and staffing shortages force organizations to rethink how SOCs operate. According to the report, 96% of organizations are already using AI or actively evaluating AI for security operations, organizations leave an average of 28% of security alerts uninvestigated, and 56% report an increase in AI-driven attacks over the past year. Proofpoint announces OEM Program Proofpoint announced an OEM Program: a portfolio of OEM-ready threat intelligence and detection capabilities available for technology providers, cybersecurity vendors, managed service providers, and platform companies. The program cuts the time, cost, and operational lift of building threat intelligence capabilities from scratch, helping partners accelerate product roadmaps and bring differentiated offerings to market faster. Rubrik adds agent identity controls to Agent Cloud Rubrik expanded its Agent Cloud platform with Rubrik Agent Identity to manage autonomous AI agent access permissions at runtime. The solution eliminates standing credentials by generating short-lived, scoped tokens for individual tool calls and integrating with identity providers (including Okta and Microsoft Entra ID). Before execution, tool requests pass through a gateway that conducts semantic behavioral analysis, verifies infrastructure access policies, and authenticates session identities. ServiceNow announces new security solutions and AI Center for Cyber Defense ServiceNow launched six unified solutions that deliver prevention-first, AI-native cyber defense across unified exposure management, identity and access security, cyber-physical security, cyber risk and compliance, and agentic incident response. ServiceNow also unveiled its newly formed AI Center for Cyber Defense, a global hub for security innovation. SOCRadar launches Human Identity Exposure Threat intelligence company SOCRadar announced the launch of Human Identity Exposure, a new Identity & Access layer for its Extended Threat Intelligence (XTI) platform that gives analysts an instant, comprehensive snapshot of an individual’s identity risk. SOCRadar Human Identity Exposure unifies fragmented identity exposure data, including breach repositories, stealer infections, attacker telemetry, PII, data leaks, and CTI signals into a single, decision-ready record. Surf AI announces new integration and platform expansion Surf AI announced an integration with Claude’s Compliance API, alongside the general availability of Exposure Reduction Operations, extending the platform to govern AI model connectivity alongside identity, cloud, and SaaS exposures. The integration pulls activity logs from the Claude environment, maps the connection and access path to an accountable owner inside the Context Graph, and operationalizes remediation, including disabling unsanctioned MCP integrations and lingering Claude access after offboarding. Tenable debuts open source AI agent exchange and expands AI risk coverage Tenable launched CyberAgents Exchange, a free, open source AI agent exchange built for cybersecurity teams. It is a vendor-agnostic community where security professionals can discover, share and build trusted AI agents, skills, MCP servers and multi-agent playbooks, backed by code-level transparency into who built what and how it works. Founding members also include SentinelOne and Recorded Future. The company also unveiled new Tenable One AI Exposure capabilities that expand coverage across every major AI platform and key developer tools. Thales releases Luna 8 Thales released Luna 8, its first in-house designed hardware security module made to secure, store, protect, and manage cryptographic keys against quantum threats. The system features an upgradeable architecture to integrate future cryptographic algorithms while maintaining backward compatibility with existing interfaces and ancillaries. Delivered on a unified hardware platform, the appliance is undergoing independent evaluation for FIPS 140-3 Level 3 and EU Common Criteria standards. Trustmi announces new AI investigation agent and new payment fraud threats Trustmi unveiled an AI Investigation Agent that is purpose-built for B2B fraud detection. It introduces agentic workflows that investigate suspicious activity, reasons across business workflows, and connects evidence across systems. The company also announced the discovery of two emerging payment fraud threats: Ghost Executive, an attack in which fraudsters fabricate an executive’s approval so the payment looks like a decision has already been made; and Deadline Deception, which pairs fraudulent paperwork with a false deadline to pressure employees into releasing funds. VanishID adds AI exploitability management and external identity protection control VanishID announced AI Exploitability Management and External Identity Protection. Operating externally without internal system credentials or installations, AI Exploitability Management breaks down over 40 attack scenarios to calculate individual risk scores based on public data availability. Complementing this tool, External Identity Protection deploys four categories of autonomous agents (detection, analyst, remediation, and residual risk) to scan data brokers, dark web repositories, and public records. Automated remediation agents submit and verify opt-out requests to erase public profiles.
securityweek.comAug 5, 2026extracted
How AI-powered phishing killed blocklists for good
Blocklists were already losing ground before AI entered the picture. Phishing domains have been getting shorter-lived for years, campaigns have been burning infrastructure faster, and the gap between blocklists and attacker campaigns keeps getting wider. AI just finished the job. Attackers are using AI to generate phishing pages from screenshots in minutes, spin up and tear down infrastructure faster than any blocklist can track, and iterate on tooling at a cadence that makes indicator-based detection functionally useless. 89% of phishing domains are now active for fewer than two days, with just 6.5% surviving past 15 days. By the time a domain makes it onto a blocklist, the campaign has moved on and the infrastructure has been replaced. If your primary defense against attacks delivered via malicious webpages like AiTM phishing, device code phishing, ClickFix, file downloads, malvertising and more relies on matching known-bad indicators, you’re always two steps behind. Disposable by design The problem isn't just that phishing infrastructure rotates quickly. Modern attacks are designed to be disposable from the outset. Attackers aren't waiting to get caught and then pivoting. They're proactively tearing down pages and spinning up new ones to stay ahead of detection, treating each piece of infrastructure as single-use by default. Attackers are also making that infrastructure harder to analyze while it's live, combining trusted hosting platforms — Cloudflare Workers, Railway, Vercel, Microsoft Dynamics, SharePoint, Adobe, Google Firebase, Google Sites, Jotform, Linode, Azure, Cloudflare, Atlassian, and many more are commonly abused — with bot protection, screening checks, and complex redirect chains on top to filter out researchers and automated scanners. 95% of in-browser attacks that Push Security detects use some form of bot protection, often layered with referrer checks and browser fingerprinting. The page a crawler sees and the page a real victim sees are frequently not the same page. And by the time you get to a once-malicious page (whether spun up by attackers or by compromising an existing site) the malicious payload may no longer be active. AI has also collapsed the cost of creating the pages themselves, too. Attackers were already proficient at cloning pages, but they can now vibe-code entire phishing sites from a screenshot of a legitimate login page — a convincing frontend with a completely unique codebase that looks nothing like the real page it’s based on, and nothing for static analysis to fingerprint. And phishing delivery increasingly abuses legitimate services — AI chatbot sharing features, search ad placement, in-app messages and app-generated emails — to inherit the domain reputation of platforms no blocklist would ever flag. The result is an environment where adding indicators to a blocklist is a bit like playing whac-a-mole, in a game that’s rigged against you from the start. AI adoption has exploded, but every new app, integration and extension introduces new threats and risks. The latest webinar from Push Security uncovers the scale of Shadow AI in the enterprise, how attackers are taking advantage, and what security teams can do about it. Register Now The tools layer is crumbling too For years, the middle of David Bianco's Pyramid of Pain offered a more durable detection surface. Instead of blocking individual domains, you could fingerprint phishing kits — their JavaScript structure, HTML patterns, code signatures — and write detections that survived across dozens or hundreds of campaigns even as infrastructure rotated. That layer is eroding. The phishing kit ecosystem now fragments through forking, AI-assisted development, and open-source-style code sharing faster than anyone can track. Device code phishing is the clearest example. From early adoption in Russia-linked campaigns in 2024, it’s taken until 2026 to really take off — at which point adoption has exploded from zero criminal kits in the wild to 25+ distinct kits (and counting). Criminal PhaaS kits like EvilTokens (340+ organizations in its first five weeks), Kali365 (which earned an FBI advisory), ARToken, DEBULL, Forg365, and many others all offer the capability. Established AiTM vendors like Tycoon 2FA have added device code phishing alongside their existing credential-harvesting capabilities, and we’ve recently observed kits dynamically switching between payloads depending on the environment and target’s behavior. For example, attempting device code phishing first, then falling back to AiTM if it times out. These kits are often controlled by attacker-operated admin panels that give full control over the payload and when it’s delivered, used in conjunction with voice-based social engineering and only “activating” the malicious page when performed by an admin. This further reduces the chance that these pages can be flagged and blocked ahead of time — they may only be seen a couple of times in targeted attacks before being rotated out. In Push Security’s recent webinar (now available on-demand), VP R&D Luke Jennings showcased just how easy it is to vibe-code your own PhaaS kit. What actually survives: techniques Genuinely new attack techniques still require human creativity to discover — an attacker has to identify a gap in how a legitimate protocol or feature can be subverted and operationalize it. That kind of innovation hasn't been automated, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation. Take adversary-in-the-middle (AiTM) phishing. Every AiTM kit — Tycoon, Sneaky 2FA, Evilginx, or countless forks and derivatives (we’re tracking 75+ kits in the wild) implements fundamentally the same interception technique: proxy the victim's session through attacker-controlled infrastructure, relay credentials and MFA tokens in real time, and capture the authenticated session. The frontends vary and the infrastructure rotates, but the behavioral mechanics of the interception are the constant. ClickFix tells a similar story. Whether the lure is a fake CAPTCHA (up 563% per CrowdStrike), a fake browser update, or a fake error dialog, the underlying technique is the same: inject malicious commands into the user's clipboard and instruct them to paste and execute the payload. The social engineering wrapper changes; the behavioral signature doesn't. Device code phishing is the same again. You’re interacting with a legitimate device code login page and ultimately completing a device code auth grant. It doesn’t matter what kit the attacker uses or where they host the page polling for the code, the destination page and user behavior is the same. Detecting at the technique level targets the thing that's hardest for attackers to change — the mechanics of the attack itself. But it demands two things that most detection programs lack. First, you need visibility where these attacks actually execute. AiTM interception, ClickFix clipboard manipulation, OAuth consent abuse, device code phishing — these techniques play out inside browser sessions where network proxies see encrypted traffic and EDR sees nothing at all. If your detection stack can't observe the page at the moment the user interacts with it, technique-level detection isn't available to you. Second, you need research velocity. The window between technique discovery and industrialization into criminal toolkits is compressing — device code phishing took roughly a year to go from nation-state novelty to commodity PhaaS feature, and ClickFix followed a similar trajectory. Defenders who can extract a behavioral signature and deploy a detection before commoditization have a structural advantage that compounds over time. Waiting for indicators — even tool-level indicators — means chasing a curve that's accelerating away from you. The proof: a detection with zero IOC overlap Earlier this year, Microsoft published research documenting a novel technique that weaponized OAuth error-handling redirects as a phishing delivery mechanism — exploiting standards-compliant redirect behavior to route users from trusted identity provider domains to attacker-controlled pages. From a URL-filtering perspective, the initial link carried the domain reputation of login.microsoftonline.com. Push's agentic threat hunting pipeline — AI agents operating as a force multiplier for human researchers, continuously hunting across browser telemetry from 3+ million deployments — ingested that research and extracted the behavioral mechanics, not the published IOCs. The agents built a detection targeting the behavioral signature: the OAuth redirect. Months after creating the detection, later, it fired on a completely different campaign. A user at a Push customer had been targeted — but with different lures, different domains, different infrastructure, and a previously unseen phish kit behind the redirect, compared to the original (a malware download payload). The underlying technique was identical. None of the original IOCs appeared anywhere in the attack chain. A blocklist-based approach would have missed this entirely (the domains weren’t flagged as malicious at the time), and a tool-signature approach would have missed it too — the phish kit didn’t match any known samples. The only detection that survived was the behavioral technique itself. The OAuth redirect case isn't an isolated example. The same pipeline led to the discovery and detection of three novel browser-based attack techniques — InstallFix (malware delivery disguised as software installation prompts), ConsentFix (OAuth consent phishing combined with ClickFix-style user manipulation), and LLMShare (malware delivery via AI chatbot sharing features). In several cases, detections were blocking active campaigns before the technique had been publicly documented. So far, Push's agentic pipeline has protected 60+ customers in the last three months alone who were targeted with novel phishing techniques — intercepting ~225 threat instances before the attacker could compromise an account, or trick the user into interacting with a malware payload. What this means for security teams The industry spent decades building bigger blocklists. AI made that approach structurally obsolete — not just slow, but architecturally incapable of keeping pace. What remains durable is the top of the Pyramid: technique-level behavioral detection, built around how attacks work rather than the infrastructure or tooling that implements them. Defending at that level requires browser-session visibility and a research pipeline fast enough to stay ahead of the compressing timeline from technique discovery to criminal adoption. At Push Security, we've built that pipeline using AI agents as a force multiplier for human researchers, continuously hunting across browser telemetry and shipping technique-level detections that survive indicator rotation — tripling monthly detection output not by building bigger blocklists, but by operationalizing behavioral detection at the top of the Pyramid at machine speed. Book a demo to learn more. Sponsored and written by Push Security.
bleepingcomputer.comAug 5, 2026extracted
The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
Cyberspace is now the fourth domain of military conflict. Geopolitics can be summarized as the behavior of a country or region influenced by its location in time (history and current events), and space (geographical proximity to other countries or regions). Those geopolitical actions are also influenced by the state of the economy and the psychology of its leaders. Geopolitical disagreements between countries are usually settled by diplomacy but sometimes by physical force of arms. The latter is usually a kinetic war involving, as necessary and available, land (an Army), air (an Air Force) and the sea (a Navy). Over the last few decades, cyberspace has been increasingly co-opted into these conflicts as a fourth force. This article is a discussion on the confluence and effect of using adversarial cyber activity to support kinetic force of arms in solving geopolitical conflict. It is, in short, a discussion on geopolitics and cyberspace. Background In the modern world there are three types of warfare: kinetic war (traditional ‘boots on the ground’ physical conflict involving armed forces and usually preceded by cyber operations); cyberwar (aggressive cyber operations); and cyber-kinetic (cyber operations that result in physical damage). All three are generally motivated by politics or geopolitical differences, which makes the intersection of geopolitics and cyberspace an important study. The three primary geopolitical motivations for nation state cyber operations in support of geopolitical differences are espionage, a desire for regime change, and territorial disputes. In each case the cyber activity has become a common precursor to kinetic activity. In broad terms, nation state activity is ideologically East versus West. The East is primarily China, Russia, Iran and North Korea (CRINK for short). The West is primarily North America, UK, EU, and the remaining members of the 5Eyes (Australia and New Zealand). Nation state geopolitical cyber operations differ in motivation and practice from simple criminal activity. Criminal activity is motivated by monetary gain. The desire is to achieve this with as much speed and as little cost as possible. Being noisy is not a problem if you can get in, grab what you want, and leave as quickly as possible. Nation state activity is very different. It is low and slow. Stealth and continuous dwell time are important. “If you detect nation state actors on your network,” comments Dmitri Alperovitch, “chances are they have already been there for weeks or months.” Alperovitch was a co-founder of CrowdStrike, is a renowned expert on geopolitics and cyberspace, and is author of World on the Brink. He spoke to SecurityWeek about the intersection of geopolitics and cyberspace, and provided invaluable thoughts and insights. Cyberspace and espionage Nation state espionage alone is not generally considered to be war, although it is often a prelude to, or part of, war. It has been practiced for as long as civilization has existed. There are records from ancient Mesopotamia (perhaps 4,000 years ago). The Amarna Letters (14th century BCE) from Ancient Egypt provide diplomatic and intelligence correspondence inscribed on clay tablets. More recently, approximately 2,500 years ago, Sun Tsu’s The Art of War has a chapter titled ‘The use of spies’ treating espionage as the foundation of military activity. Cyber, however, now raises espionage to a new level of scale and purpose. Its motivation is as often economic as it is military. Nation states use cyber espionage to monitor other nations’ military capabilities and where possible steal military secrets, but also now to steal intellectual property from foreign enterprises. The latter means that commerce as well as the military must protect against nation state low and slow incursions. Every nation with a cyber capability is engaged in cyber espionage. The West, with the Five Eyes (FVEY) alliance, is probably the better actor. “It’s an intelligence alliance (US, Canada, UK, Australia and New Zealand) that evolved from the work of Alan Turing and Bletchley Park during the Second World War,” comments Alperovitch. It started as a signals intelligence alliance collecting from airwaves and detecting radio signals, but its activities have broadened into cyber espionage. “NSA, GCHQ, and the other countries in the alliance are now using cyber to accomplish national security priorities – which is the collection of intelligence on our adversaries. So, yes, we’re doing that. And I think we’re the best in the world at it.” What we don’t do, he continues, “We don’t steal intellectual property from private companies for the benefit of our own industries. That’s what China does.” A hypothetical example could be drawn with AI. AI will be seriously important in the future, militarily, sociologically, and economically. It is to be expected that both sides are already surveilling the state of AI in the other. Five Eyes might wish to watch DeepSeek-like companies for intelligence purposes; but that’s all. Beyond intelligence, China, however, might wish to watch, and exfiltrate, Anthropic-like intellectual property – and pass that IP on to its own DeepSeek-like AI enterprises. Other CRINK nations would do similar. There are additional behaviors that CRINK might engage in that Five Eyes does not. “We don’t engage in ransom operations or theft of currency and cryptocurrency as North Korea does. Our operations follow the rule of law, both domestic and international. The operations are designed generally to not be escalatory unless we’re in a military conflict, in which case, anything goes.” The last comment is interesting and explains the difficulty in understanding the role of cyberspace in geopolitics. When, exactly, can two nations be defined as ‘at war’? It used to be the presence of opposing armies on a battlefield, or a formal declaration of war between nations. However, since 2011 in the US, and 2016 in the rest of NATO, cyber is officially a military domain, and cyberspace is therefore a potential battlefield. In the US, Cyber Command was ordered by Secretary of Defense Robert Gates in 2009 and became operational within Strategic Command in 2010 before becoming an independent unified combatant command in 2018. The logical implication of this process is that the moment one nation engages in cyber espionage against another nation on the cyberspace battlefield, the two nations are effectively at least at military quasi-war with each other. But “We’re not going to go [full kinetic] war over espionage, because everyone does it,” adds Alperovitch. If espionage led to war, the world would have been at continuous war since ancient Mesopotamia. Nevertheless, his earlier qualification (‘unless we’re in a military conflict, in which case, anything goes’) marks a major change in the role of cyberspace that comes to a head when kinetic conflict has either started or is inevitable. Cyberspace and kinetic conflict There are two primary causes for kinetic war: regime change and territorial disputes. In both cases, any kinetic activity is generally preceded by or concurrent with aggressive cyber activity. Cyber activity is unlikely to ever win kinetic wars – its purpose is to prepare for, support, and hasten a kinetic victory. There are two recent examples of attempted regime change (Venezuela and Iran), and two examples of territorial disputes: Russia with Ukraine, and China with Taiwan. Venezuela. Nicolás Maduro, then president of Venezuela, was arrested and removed from Venezuela through a kinetic US operation on January 3, 2026. This operation was almost certainly, and is commonly believed, to have included a cyber element, if only pre-kinetic espionage intelligence gathering. Operational support (possibly in assisting the power blackout that was part of the extraction) is likely, but unproven. This is not surprising – US intelligence would avoid disclosing any cyber access to Venezuelan networks in case it is needed again in the future. In a press conference following the operation, General Dan Caine (chairman of the joint chiefs of staff) specifically mentioned Cyber Command as part of the layering of ‘different effects’ leading up to the operation. Maduro was arrested and extracted to face charges related to ‘narco-terrorism’ and is currently being held in New York. The primary purpose of the extraction was, however, to effect regime change, prevent future narco-terrorism, and give the US greater influence over Venezuelan oil. It succeeded only in oil, where the US now has considerable influence. It failed in preventing the flow of narcotics into the US since Venezuela was a transit route for narcotics produced elsewhere (primarily Colombia). And it failed to effect regime change. The current ‘acting’ president is Delcy Rodríguez, previously Venezuela’s Executive Vice President. Officially, her position is that Maduro is still the legal and rightful president. Iran. Epic Fury and Roaring Lion were respectively the joint US and Israeli combat missions launched on February 28, 2026, against Iran. The primary purposes were to destroy Iran’s potential to develop nuclear weaponry and to effect regime change to prevent any continuing desire for nuclear weaponry. Cyber activity was an important component at the launch of kinetic action. Cyber operations degraded Iran’s radar grids to allow the initial wave of US and Israeli airstrikes. These were remarkably successful, including killing supreme leader Ayatollah Ali Khamenei. Many of the top military leaders were also killed. It is believed that cyber espionage played a part in knowing precisely when and where they were located. The initial kinetic action amounted to regime decapitation that would hopefully lead to the rise of a new regime. Psychological cyber operations were used to deliver anti-regime messaging and normal state media, government communication lines, and public apps were all targeted, hoping that the Iranian people would rise up against the Iranian government. This didn’t happen. Despite the success of the ‘remote’ kinetic action against Iranian military capabilities, Iran continues. Iran has retaliated with its own kinetic activity against US and Israeli regional allies, and with its own cyberattacks against the US. On July 22, 2026, CISA warned that Iranian actors were exploiting ‘programmable logic controllers across US critical infrastructure’. This war is ongoing. At the time of writing, it is four months and four weeks since the commencement of kinetic activity. It has involved action in the air, on the seas, and in cyberspace – but not specifically on the ground. Ground forces are not currently involved. The implication here is that cyber activity can assist in areas of kinetic activity, but cannot ultimately succeed without human boots, troops, on the ground in the battlefield. Cyberspace and territorial disputes We have two examples of major geopolitical territorial disputes. One involves an ongoing war – in Ukraine. The second dispute is over Taiwan. China insists it is part of China. Taiwan and much of the West disputes this. There is, again at the time of writing, no kinetic war in or for Taiwan. However, if we accept that the role of cyber in geopolitics is to prepare for and assist in kinetic warfare, there are worrying signs. Ukraine. On February 24, 2022, Russia invaded Ukraine. This was fundamentally a territorial dispute. Putin, that is Russia, considered Ukraine to be part of the Russian empire. He wished to return Russia to the preeminence it had in the USSR prior to the collapse that ended the Cold War. Ukraine disagreed. Other factors played into this dispute. Historically, Ukraine and Russia have always been linked. When Zelensky came to power, he spoke Russian more fluently than Ukrainian. Ukraine is effectively a buffer between Russia and its adversary NATO and the EU. Ukraine, however, displayed distinct preferences toward NATO and indicated a wish to join the EU in the future. Putin felt he had no option but to force Ukraine back into the Russian fold. Physically attempting to do this started almost exactly eight years before the current ongoing war in mainland Ukraine when Russia took Crimea. On both occasions he employed the now textbook style of first disrupting the enemy via cyberspace. For Crimea, a cyber espionage campaign dubbed Operation Armageddon and targeting government, law enforcement, and defense agencies was conducted from 2013. Ukraine attributed it to the FSB. Russian malware, including Snake and Uroburos (closely related malware) that was developed and distributed by the Turla APT group, was used against Ukrainian government systems. As the kinetic invasion began, Russian special forces and cyber units raided Crimean telecommunications centers and cut communication between Crimea and mainland Ukraine, disrupted government phones, and DDoSed government websites, news outlets and social media. Three months prior to the later invasion of mainland Ukraine in 2022, in late 2021, Alperovitch had declared that kinetic war was inevitable. “What convinced me,” he told SecurityWeek, “was what I was seeing in the cyber domain. Not exclusively – there was a buildup of Russian forces and rhetoric from the Russian government – but I was also seeing cyber intrusions into Ukrainian systems unlike any that I had seen since Crimea in 2014. This was a clear indication that Russia was again preparing for a full scale invasion.” He believes that aggressive cyberactivity is effectively a ‘canary in the coalmine’ warning on imminent kinetic warfare. In some ways, Russian activity never ceased after 2014, with long running Sandworm (GRU Unit 74455), APT28 / Fancy Bear (GRU Unit 26165), and Gamaredon (FSB‑linked) campaigns. However, cyber activity escalated dramatically immediately prior to the 2022 invasion. Ukrainian government websites were defaced using WhisperGate. HermeticWiper struck hundreds of systems across Ukrainian financial, defense, aviation, and IT sectors. A second wiper (IsaacWiper) targeted government networks. And as the invasion began, a cyberattack disrupted Viasat’s KA-SAT satellite network, disabling thousands of modems across Ukraine and Europe, but more specifically severely degrading Ukrainian military C2 capabilities. Kinetically, Ukraine (supported by the US and the EU, has proven remarkably resilient. Four years into the war (again at the time of writing) Russia has not succeeded in its kinetic invasion. While the cyber activity did what it was designed to do, history again suggests that cyber can assist kinetic but cannot guarantee kinetic success. Taiwan. A second territorial dispute exists today, with China insisting that Taiwan is part of mainland China. Like Ukraine with Russia, Taiwan disagrees, insisting it is an independent island nation. But just as an independent Ukraine inhibits Russian influence eastward, so an independent Taiwan off the eastern coast constrains China’s strategic freedom of action across military, economic, diplomatic, and informational domains in the Pacific region. While there is currently no specific kinetic activity from China, there is massive cyber hostility targeting Taiwan that has been ongoing for years. There is also massive Chinese pre-positioning in western critical industries. This latter is not a precursor to a Chinese kinetic invasion of the US, but more likely a defensive position to disrupt the US in interfering in any kinetic action against Taiwan. China’s Volt Typhoon is an example, combining pre-positioning with living-off-the-land for stealth. It has been operating for years, quietly embedding itself inside utility sectors, including communications, energy, transportation, and water systems. The belief is this is designed to give China the ability to disrupt critical services in the event of a future crisis. That crisis could be any US reaction to an invasion of Taiwan. All of this is necessary because of the importance of Taiwan to western economy. Unlike Ukraine, which has little direct relevance to the US if lost to Russia, Taiwan is critically important to US technology companies. It supplies around 90% of the world’s most advanced chips. Without Taiwan’s fabrication capacity, it is unlikely that companies like Apple, AMD, Google or AMD would be able to manufacture the processors they use; and the progress of AI would be inhibited by difficulties in building the necessary data centers. It would take many years and many billions of dollars for the US to build its own industry to replace Taiwan’s current capacity. For this reason, the US is more aggressive in its support for Taiwan than it is in support of Ukraine. We do not know if this support is preventing a Chinese kinetic invasion of Taiwan or merely delaying it. It’s certainly not stopping China’s desire to take Taiwan. China wants Taiwan, and the US doesn’t want it to have Taiwan. Interpretation of what is really happening is all conjecture. Is China ramping up cyber activities to force the US to be less reliant on Taiwan? If that were to happen, US defense of Taiwan might relax, enabling China to absorb Taiwan with less difficulty. Or should we see this aggressive cyberactivity as an indication of Alperovitch’s ‘a canary in the coalmine’? Only time will tell. The longer it takes for China to invade Taiwan, the less dramatic it will be. But if China were to invade Taiwan tomorrow, all bets are off. Summary The four examples of Venezuela, Ukraine, Iran and Taiwan demonstrate that over the last 15 years, cyberspace has become deeply embedded in geopolitical military actions around the globe. Nowhere, at least so far, has cyber activity done more than assist kinetic military force. The only successfully completed kinetic action was the arrest of Maduro in Venezuela, which involved boots on the ground. Boots on the ground have so far been excluded from the Iran war, and nobody seems to know what will happen without them. But there have been boots on the ground in Ukraine for the last four years, and there is still no winner. Neither successful cyber activity nor greater force on the ground guarantees a successful kinetic operation – but there is little doubt that cyberspace and ground force will continue hand in hand in the future. Taiwan is a big concern. The geopolitical peculiarities of this situation suggest that any future kinetic conflict will be, for the first time, between two major powers each with nuclear capabilities. We must hope that for Taiwan, geopolitical hostilities between East and West remain in cyberspace. Related: China Admitted to Volt Typhoon Cyberattacks on US Critical Infrastructure: Report Related: The Impact of Geopolitics on CPS Security Related: Geopolitics Will Drive Aggressive Cyber Activity Throughout 2020 Related: The Increasing Effect of Geopolitics on Cybersecurity
securityweek.comAug 5, 2026extracted
Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
The Linux Foundation has issued a Request for Comments on a newly proposed framework aimed at standardizing how the cybersecurity industry handles agentic AI incidents. Announced at the Black Hat conference in Las Vegas, the Shared AI Findings Exchange (SAFE) guidelines seek to turn AI security incidents and near misses into actionable threat intelligence for the broader ecosystem. The SAFE framework is being driven by the recently launched Open Secure AI Alliance, a coalition that has grown to over 120 organizations. The SAFE initiative is spearheaded by Open Secure AI Alliance members such as Nvidia, Cisco, CrowdStrike, Hugging Face, and Red Hat. The core objective is to establish a confidential pipeline for collecting incident data, analyzing control failures, and broadcasting evidence-based recommendations to reduce systemic risks. Because modern AI agents function as complex systems reliant on identity controls, runtimes, and execution harnesses, the alliance emphasizes that open intelligence sharing is the only way defenders can match the speed of emerging attack vectors. Alongside the policy framework, alliance members have released various open source tools covering the entire AI security stack. Nvidia has contributed its NOOA research harness for auditing agent behavior, the OpenShell runtime that restricts agent access at the system level, and Garak, an LLM vulnerability scanner designed to catch prompt injections and data leaks prior to deployment. Okta is developing implementations utilizing the open Cross App Access (XAA) protocol to secure agent connections within OpenShell sandboxes. Meanwhile, Red Hat launched a new open source project called Asago, which maps external governance requirements, such as those in the EU AI Act, directly to live runtime controls for AI agents. Newly added members Amazon and Visa have contributed frameworks for building and evaluating agent boundaries, with Amazon specifically open-sourcing Cedar, an authorization language for establishing verifiable access controls. Microsoft is releasing tools like PyRIT and RAMPART, which allow red teams to run automated testing and turn incident findings into repeatable software checks. The new guideline proposal comes in light of OpenAI and Anthropic discovering that their models went rogue during tests and attacked real organizations. Related: Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
securityweek.comAug 5, 2026extracted
AI is 'both the weapon and the target' in latest wave of cyberattacks
ON-PREM EPA to drop requirement for public notice of polluting datacentersState and local regulators would decide whether the public gets a say on minor-source permits SYSTEMS OpenAI's upcoming Jalapeño chip looks like it'll be an inference beast128 chips, 1.7 exaFLOPS, and 27 TB of HBM give Altman and crew a leg up over Blackwell, and maybe even Rubin SYSTEMS What Nvidia's first Groq 3 LPU benchmarks tell us about its $20B gambleGemma 4 31B performance tests offer a best-case scenario for next-gen dataflow accelerators ON-PREM US datacenters tripled their water footprint in 10 years... and those are figures from the start of the AI boom. It can only be worse now. Silo-ed reporting isn't helping ai and ML AI slop is good for business if you know what you're doingYour irresponsibility is someone else's opportunity Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career Emperor Penguin Linus Torvalds banishes a bug – with a botThe lad himself finds and fixes a tricky one… or does he? FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan
theregister.comAug 3, 2026extracted
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Foundation. Its stated scope covers the full agent stack, including identity, permissions, isolation, guardrails, logs, model formats, multi-model scanning, and secure coding workflows. The pitch is that cyber defenders need AI models they can read, change, and run on their own hardware, not only closed systems reached through a vendor's application programming interface (API). The launch also brings its first named technical contribution: NVIDIA-labs OO Agents (NOOA), an Apache 2.0 research framework designed to make agent behavior easier to test, trace, audit, and govern. The launch materials do not include a charter, governing board, technical workstreams, delivery schedule, or shared alliance repository, and its standalone website remains under construction. The Hacker News has reached out to NVIDIA for details about the alliance's governance, member commitments, and first planned deliverables, and will update this story with any response. The First Code Comes With a Sandbox Warning An agent harness is the software layer around a model that renders context, executes actions, manages state, and decides when a task is done. Under NOOA, that layer is represented as a Python class. Fields store its state, methods expose its capabilities, docstrings act as prompts, and type annotations define the contracts the model must follow. A method containing an ellipsis body, ..., is completed at runtime by a large language model (LLM)-driven loop. A method containing ordinary Python remains deterministic code. The same structure lets developers use familiar testing, tracing, version control, and refactoring workflows instead of splitting agent behavior across prompts, tool schemas, callbacks, and workflow graphs. In its own evaluation, NVIDIA reported that the framework scored 86.8% on the CyberGym L1 vulnerability-rediscovery benchmark using GPT-5.5, with network access blocked and rule-based checks applied to each trajectory. The repository is equally direct about the risk. NOOA can be configured to execute LLM-generated Python, which may transmit private data, delete files, or modify its environment. Its abstract syntax tree checks and module deny-lists are described as defense-in-depth controls, "not a containment boundary." NVIDIA places containment outside NOOA itself. Agents that execute generated code must run behind operating system-level isolation, such as a container, virtual machine, or its OpenShell sandbox. NOOA provides inspection and tracing; the OS-level sandbox is the containment boundary. A July 27 review of the public repository found a v0.0.6 tag dated July 22. The project's release guide says tagging a commit is the release ceremony and that attaching built wheels to a separate GitHub Release is optional. Its contribution guide says development is maintained by NVIDIA, with external contributions welcomed through pull requests. The repository had no root-level governance or roadmap file. The Hugging Face Incident Became the Argument NVIDIA tied the alliance's case for locally controlled defensive models to the July intrusion at Hugging Face, where an autonomous agent system compromised parts of the company's production infrastructure. Hugging Face identified unauthorized access to a limited set of internal datasets and several credentials used by its services. It found no evidence of tampering with public models, datasets, Spaces, container images, or published packages. Hugging Face said initial access to its environment came through a malicious dataset that abused a remote-code dataset loader and template injection in a dataset configuration. The activity progressed to node access, credential collection, and lateral movement across several internal clusters. Hugging Face said it ran LLM-driven analysis agents over more than 17,000 recorded actions to reconstruct the timeline, extract indicators of compromise, and map the credentials that had been touched. Commercially hosted frontier-model APIs initially rejected the attack commands, exploit payloads, and command-and-control artifacts required for the analysis. The company instead ran the open-weight GLM 5.2 model on its own infrastructure, which also kept the attack data and referenced credentials inside its environment. Its operational advice was to "have a capable model you can run on your own infrastructure vetted and ready before an incident." In this case, the advantage was operational control. The incident does not establish model openness as a substitute for identity, isolation, or containment. As previously reported by The Hacker News, OpenAI later said its preliminary investigation found that GPT-5.6 Sol and a more capable pre-release model caused the incident while operating with reduced cyber refusals during an internal ExploitGym evaluation. OpenAI's disclosure describes an earlier step in the chain. The models exploited a zero-day vulnerability in an internally hosted package-registry cache proxy to obtain internet access. They then chained vulnerabilities and stolen credentials across OpenAI and Hugging Face systems while seeking benchmark answers. OpenAI said one chain found a remote code execution path on Hugging Face servers. OpenAI said Hugging Face detected and stopped the activity on its infrastructure and had already begun containment and forensic reconstruction by the time the companies connected. The primary disclosures establish that the open model helped Hugging Face reconstruct the intrusion and supported its response. They do not show that GLM 5.2 independently detected, stopped, or contained the breach. A Coalition Without a Public Operating Manual The alliance follows a July 24 industry letter arguing that downloadable models give defenders capabilities comparable to attackers, reduce dependence on individual providers, and allow sensitive work to remain on infrastructure controlled by the user. OpenAI, Google, and Meta appear among the letter's signatories but are absent from the alliance's inaugural membership list. Anthropic appears on neither list as of July 27, 2026. The roster alone does not explain those absences. Signing the policy letter and joining a technical coalition are different commitments, and the public materials do not say why those companies are absent, whether membership discussions are underway, or what members must contribute to join. Several technologies cited in the announcement predate the coalition, including Hugging Face's Safetensors model format, HPE-backed SPIFFE/SPIRE workload identity, IBM and Red Hat's Lightwell remediation system, Microsoft's MDASH multi-model security harness, and SpaceXAI's Grok Build coding agent. They are member projects, not alliance-created products. Elastic said it will contribute research, tools, and architectural knowledge across security, search, observability, and AI-powered detection. CrowdStrike said it is developing techniques that use open models to detect attacks against AI systems and agents. The Linux Foundation described itself as an inaugural partner and said its role is to provide a neutral place for competing organizations to collaborate. It did not state that the alliance is formally hosted or governed as a Linux Foundation project. The public record does not distinguish between members assigning engineers to joint work, contributing existing projects, or endorsing the coalition's direction. Published workstreams, maintainers, release processes, or jointly governed code would make the level of joint participation easier to assess. For now, the public record shows a coalition, a policy position, several member commitments, and one identifiable new NVIDIA-maintained code release, NOOA. The alliance's governance, joint roadmap, first multi-member deliverable, and the models, weights, and datasets promised by NVIDIA remain undisclosed.
thehackernews.comJul 27, 2026extracted
Google goes it alone with a new cybercrime crew taxonomy
SYSTEMS What Nvidia's first Groq 3 LPU benchmarks tell us about its $20B gambleGemma 4 31B performance tests offer a best-case scenario for next-gen dataflow accelerators ON-PREM US datacenters tripled their water footprint in 10 years... and those are figures from the start of the AI boom. It can only be worse now. Silo-ed reporting isn't helping ai and ML AI slop is good for business if you know what you're doingYour irresponsibility is someone else's opportunity SAAS Salesforce partners not seeing meaningful revenue from Agentforce AI platform, report saysShow us the money ai and ml AI companies are burning books, advocates complain to FTCFahrenheit 203, the temperature GPUs stop gorging on literature Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career Emperor Penguin Linus Torvalds banishes a bug – with a botThe lad himself finds and fixes a tricky one… or does he? FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan
theregister.comJul 27, 2026extracted
Why Modern SOCs Need Multi-Layered Detections
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on credential theft and DLL side-load techniques to bypass host-level monitoring. Perimeter vulnerabilities compound this exposure; firewalls and VPN gateway breaches climbed 19% according to the latest Verizon Data Breach Investigations Report. Once an adversary gains access, breakout often occurs in seconds. Claude Mythos and similar models have further escalated operational pressure. These can rapidly discover and exploit previously unknown vulnerabilities, virtually closing the window from initial discovery to full compromise. Security practices must adapt to prioritize rapid containment and post-compromise behavior analysis, and defensive capabilities now demand real-time detection that goes beyond host-level coverage. This is where multi-layered network detections come in, extending defense beyond the endpoint-but their effectiveness depends highly on the data behind them. Network evidence strengthens detection Endpoint, identity, and cloud platforms each offer a valuable perspective on corporate security. Host tools track processes in memory, identity solutions monitor credentials, and cloud environments log configuration changes. While each source provides visibility, these systems operate in isolation, leaving gaps in visibility that attackers can easily exploit. Each tool sees only its fragment of the attack chain. Threat actors can compromise a workstation, leverage blind spots between endpoint and identity systems to hide credential theft, move laterally into cloud infrastructure, and exfiltrate data before the SOC is aware. That is why unified, correlated telemetry across these domains is essential to revealing the full picture. Network Detection and Response (NDR), validates, enriches, and connects these separate signals using network data. Because it's collected out of band, the data remains immutable even when local agents go dark or when threat actors disable endpoint tools. And because it captures traffic across the entire enterprise, NDR provides vital context, recording every conversation, transaction, and data transfer, delivering the undeniable proof defenders require to respond. For instance, when an identity tool flags an unusual login, network data verifies whether that account initiated unauthorized database queries. When an endpoint alert flags credential access, it helps validate whether the adversary attempted lateral movement. Multi-layered detections build confidence in decisions Most organizations already possess some form of network visibility, such as legacy intrusion detection systems (IDS), packet capture (PCAP) appliances, or basic NetFlow logs. However, these legacy tools operate in isolation, and most fail to match the speed that analysts need to respond to modern attacks. NDR replaces these fragmented, legacy tools. Through the consolidation of signatures, packet analysis, and flow logs into a single workflow, NDR delivers a comprehensive suite of detections and capabilities that dramatically ease analyst cognitive load. Rather than search through an overwhelming volume of separate, uncoordinated alarms, defenders use multiple integrated network detection layers to establish certain proof. Signature-based detection and threat intelligence: These provide rapid validation for documented exploits, catching known threats and historical malicious files with high precision, and detecting communication with established adversary infrastructure. However, to identify post-exploitation activity, modern automated toolkits require advanced behavioral and anomaly layers. Behavioral detection: Behavioral models identify adversary tactics, techniques, and procedures (TTPs) regardless of specific files or exploit code. For example, they can detect suspected command and control tactics without reliance on specific indicators. Anomaly detection: Anomaly detection flags structural variations from baseline network traffic, such as a workstation that suddenly behaves like an internal port scanner, identifies connections to a large number of previously unseen hosts, or exhibits connection patterns that indicate data collection. Supervised ML models: These machine learning models excel at identifying patterns that are difficult to capture using signatures or rule-based logic, thereby extending coverage to threats that evade traditional detection methods. They can see indicators of compromise in encrypted traffic, identify malicious domains, and help uncover tunneling within the network. AI: Rather than deliver independent alerts that force analysts to guess at severity, advanced artificial intelligence engines correlate alerts across diverse telemetry sources and layers and map attacker behavior. This integration reduces confusion, tracks the complete kill chain, and builds confidence in operational decisions. With verified, correlated intelligence, analysts shift from validating alerts to rapid triage and containment. To achieve this degree of operational clarity, security leaders must invest in full-lifecycle protection. This posture is predicated on advanced network telemetry that can surface adversary activity quickly enough to match the operational tempo of Mythos-class threats. AI is only as effective as the evidence behind it As a defensive layer, AI currently excels at threat triage, workflow automation, and incident summarization. However, the core rule remains absolute: garbage in, garbage out. The efficacy of AI-driven security automation is limited by a "knowledge ceiling" determined by source data, not model selection. Even the most advanced models cannot overcome the limitations imposed by low-quality or missing data. Invest in the data; everything else follows. Rich network telemetry gives AI the truth it requires to reach correct conclusions, accurately mapping enterprise exposure, reconstructing attack paths, and verifying whether exploits succeeded. Without it, AI tools can generate false positives, miss critical activities, and slow incident response. Network traffic represents undeniable evidence of the enterprise environment. When AI is grounded in this provable data, it delivers security value rather than noise. From data silos to unified defense This network context is not a standalone solution; it requires integration and data enrichment from multiple SOC tools to achieve maximum impact. The true strength of this approach lies in an open data architecture and deep configurability. When a platform supports open data standards, analysts can quickly correlate network telemetry with host and identity alerts. This seamless integration allows security teams to use rich network context immediately, which resolves ambiguous events and maps attack paths from initial entry to execution. Structured, accessible data ensures that incident response teams can execute precise containment before an intrusion escalates. Key takeaways The emergence of powerful autonomous exploit engines like Mythos necessitates an evolution in enterprise defense. In this landscape, security teams must evolve toward a defensive architecture with network data at the center to tie together otherwise disparate security tools and data. This integration provides the evidence and context that reduce blind spots and uncertainty. As AI becomes a core component of the modern SOC, the strategic value of network evidence grows exponentially. Unified network evidence and comprehensive visibility ensure that human analysts and AI models work from the exact same view of the environment. This shared perspective replaces guesswork with clear, structured facts. This strategy consistently delivers three critical operational outcomes: Improved detection quality: identify complex, multi-stage attacks that evade single-layer tools Faster investigations: use rich network logs to rapidly reconstruct security incidents Higher confidence in results: eliminate operational doubt and execute rapid threat containment With a solid foundation of network evidence, organizations can turn their network into their most powerful defensive asset. About Corelight Corelight delivers network detection and response (NDR) solutions that accelerate threat investigations through AI-powered defense. By pairing comprehensive network visibility with deep behavioral analytics, the Corelight Open NDR Platform provides security teams with actionable context and evidence-backed detection. Security professionals can explore Corelight Network Defense or visit the Corelight website to learn how to defend the hybrid enterprise.
thehackernews.comJul 22, 2026extracted
Loop engineering comes to the SOC: Introducing the Intezer Org Brain
Loop engineering comes to the SOC: Introducing the Intezer Org Brain July 21, 2026 Written by Itai Tevet Last month (June), one idea took over the AI conversation: stop prompting your agent, and start designing the loop that prompts it. Boris Cherny, the creator of Claude Code, said he doesn’t prompt Claude anymore. Loops do. Within days the industry had a name for it: loop engineering. Coding agents got there first. But the loop that matters most for security teams doesn’t run in a code editor. It runs in your SOC, where the real question is what your AI analyst remembers after each investigation. Think about the best analyst on your team. Three years in, they just know things. That CrowdStrike alert on the build servers fires every time DevOps pushes a release. Dave from finance logs in from Portugal, and it’s fine. None of it is written down anywhere. And the day they resign, all of it walks out the door. We built Org Brain so it doesn’t. Context was table stakes. This is something else. Let’s be clear about what we’re not claiming. Organizational context in an AI SOC is table stakes. Every serious AI SOC product has some version of it, and Intezer has used org context in investigations for years. If a vendor is still pitching “we understand your environment” as the headline, that’s a 2024 announcement. Org Brain is different in kind, not degree. It’s a memory system, not a context store. It doesn’t just hold what someone loaded into it during onboarding. It learns, it recalls, it fetches what it’s missing, and it gets sharper with every alert it touches, all autonomously. Here’s how. Two memory systems, one brain Today we’re releasing Org Brain, built from two main components, modeled on the two kinds of memory a real SOC team runs on: how you work, and who you are. Muscle memory — the how (procedural knowledge) Every SOC develops its own way of doing things, mostly without documenting it. Which query an analyst runs when an identity alert hits a domain controller. Which detections get closed on sight because they’ve been benign four hundred times in a row. What the tuning history says about that noisy DLP rule. Where an investigation goes next after a suspicious login, and where it doesn’t bother going. This knowledge lives in your analysts’ hands. For Intezer customers, it has also lived in the Tuning Center, as memory you had to create yourself. Org Brain now captures it autonomously and applies it, so an investigation at 3am runs the way your best analyst would run it at 10am. Self-awareness — the who (declarative knowledge) Your assets and what they’re for. Your users, their roles, what their normal login behavior looks like. The tickets they’ve opened before. And one layer deeper: your data itself. How your SIEM is structured, which fields exist, what the columns actually mean, where the truth about an entity lives. This is declarative knowledge. The facts an investigation stands on. An AI agent that doesn’t know your schema is a tourist with a phrasebook. One that does can ask your environment the right question, in your environment’s own language, mid-investigation. Put together, this is the difference between an AI that has context and an AI that knows your organization. Context answers “what is this server?” Org Brain answers “what is this server, is that login normal for this user, and what would our team do about it?” Engineered as a loop Org Brain is built the way loop engineering prescribes. The agent alone isn’t the system; the loop around it is. Act, verify, learn, repeat. Org Brain runs that loop across your SOC’s past, present, and future. It learns from your past. A brain that starts empty would take months to become useful. Org Brain doesn’t start empty. Intezer can now ingest the history your SOC already has: the cases and tickets sitting in your case management tool, years of resolutions, escalations, and quiet decisions to close without action. That history becomes muscle memory and self-awareness before the first new alert arrives. It fetches your present. When memory isn’t enough, Org Brain doesn’t guess. It knows what it knows, and it knows where to look. Mid-investigation, it pulls live context from your environment on demand, just in time, so a verdict rests on what’s true right now, not on what was true when someone last synced a database or refreshed a graph. We’ve been investing in developing more integrations to fetch just-in-time organizational context, and customers can expect an increasingly rich context ecosystem. It learns for your future. After every investigation, autonomous or alongside your analysts, the loop closes. Following frontier AI system design, a superior model, what AI labs call an auditor, or critic, reviews what happened. What the investigation found, what your analysts corrected, which path led to the verdict. The conclusions are written back into the brain. A tuning decision or an analyst’s feedback becomes muscle memory. A newly seen asset becomes self-awareness. The next investigation starts smarter than the last one finished. What this means for Intezer customers Org Brain is rolling out gradually, and parts of it are already working for you. Some capabilities live in the backend. You won’t see a new button immediately, but you’ll notice richer context in results and more accurate verdicts. When Org Brain appears in your menu bar, you’re officially in the rollout. Some of it will also look familiar. Alert tuning, feedback, and custom queries are now part of Org Brain, which means every tuning decision and correction your team has made was, in effect, training it before it had a name. More capabilities will land under the Org Brain umbrella in the coming months. A superior way to run an AI SOC Context is critical to every investigation. That was true before AI entered the SOC, and it’s table stakes now. No AI analyst should be making verdicts blind to the environment it works in. But holding context and understanding an organization are not the same thing, and the gap between them shows up exactly where it hurts: in accuracy, in speed, in how complete an investigation really is. Org Brain is our answer to that gap, and it reflects how we build: staying at the frontier of AI development and turning what’s proven there into outcomes for security teams. A brain that knows how your SOC works and who your organization is. One that learns from your past, fetches your present just in time, and gets smarter with every investigation. If you want to see what your SOC looks like with a brain, book a demo. Itai Tevet Co-founder and CEO of Intezer, Itai is on a mission to revolutionize how SOC teams investigate and respond to cybersecurity incidents. He previously led the cyber incident response team for one of the world's most targeted organizations. Itai combines his expertise in AI and security to advise security leaders at Fortune 500 companies on how to defend against threat actors in the AI era.
intezer.comJul 21, 2026extracted
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together diverse functions under one umbrella. The ransomware component has been internally named CrownX. "The attack began with a spoofed legal document email directing recipients to a password protected archive on Proton Drive," Blackpoint Cyber researchers Nevan Beal and Sam Decker said. "Malicious content was embedded inside an ISO image rather than attached directly, reducing the likelihood of detection at the email layer." Should the email recipient interact with a document-themed Windows Shortcut ("Secure Document CA-283505.pdf.lnk") inside the mounted image, it triggers a staged malware sequence that culminates in the deployment of Avalon. Specifically, the shortcut runs a command to launch an MSBuild project located in the ISO image. The MSBuild project, for its part, loads an embedded .NET assembly, which then interferes with the regular functioning of Event Tracing for Windows (ETW) to reduce forensic visibility and download a next-stage payload over HTTPS responsible for launching Avalon. The malware framework boasts of an extensive defense evasion subsystem that aims to evade detection, while incorporating specific methods to conceal execution from security tools associated with Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender. "These capabilities give the framework a multitude of ways to reduce telemetry, bypass user mode monitoring, and adjust its execution depending on the defensive controls present on the host," the researchers said. The complete set of features built into Avalon is as follows - Harvest credentials, cookies, history, and bookmarks from Chromium-based browsers and Mozilla Firefox. Gather data from cryptocurrency wallet apps like MetaMask, Phantom, Coinbase Wallet, Exodus, Electrum, Atomic Wallet, Ledger Live, and Bitcoin Core, along with Discord, Slack, Teams, OpenVPN, WireGuard, and Windows Credential Manager. Collect details about SSH known hosts, saved RDP connections, Wi-Fi profiles, and Group Policy Preferences cpassword artifacts. Exfiltrate data to a remote server ("helloxcherry[.]com") and poll the server for receiving tasking commands. Perform reconnaissance and prioritize systems that can expand the scope of the compromise. Encrypt files associated with business operations, software development, engineering, data storage, and virtual infrastructure using Windows Cryptography API and deliver a ransom note containing payment instructions and deadline timers that show how much time is left before the ransom amount is increased. Inhibit system recovery by terminating the Volume Shadow Copy Service and deleting shadow copies. Remove traces of artifacts using an anti-forensic cleanup subsystem to complicate incident response efforts. Directly interact with disk structures likely in an effort to damage partition information, boot records, or other critical areas of the drive, effectively rendering the system unusable. "CrownX represented the final extortion stage, but the damage extended well beyond the encryption itself," the company said. "By the time the ransom note appeared, the broader framework had already collected credentials, established C2 communications, prepared multiple paths for lateral movement, and weakened local recovery options." Another important detail is that Avalon shows signs of artificial intelligence (AI)-assisted development, one that has assembled multiple components with scant regard for sophisticated tradecraft or operational security, something that requires significant expertise to build. The findings are yet another sign of how AI can lower the barrier to entry, making malware development more accessible with little time and effort, and even allowing actors with little technical expertise and resources to come up with tools that may require extensive development effort. In other words, the presence of a certain capability is no longer a reliable indicator of a threat actor's sophistication or operational maturity. "The kill chain illustrates how a familiar business lure can progress into a reusable, multi-capability framework designed to harvest credentials, retrieve subsequent payloads entirely in memory, and stage multiple follow-on actions from a single compromised endpoint," Blackpoint Cyber said. LLM Behind an Agentic Ransomware Attack The disclosure comes as Sysdig detailed what it said was the first publicly documented agentic ransomware infection driven by a large language model from start to finish, while retrying and tweaking its actions in real-time to complete tasks. The agentic threat actor (ATA) behind the operation has been codenamed JADEPUFFER. The operator "gained initial access to an internet-facing Langflow instance through CVE-2025-3248 and ran an adaptive and fully automated campaign, ultimately pivoting to the intended target and running a destructive database-extortion playbook against the victim's production database server," Sysdig's Michael Clark said. "The skill floor for running ransomware has dropped to whatever it costs to run an agent, and if that agent is running on stolen credentials through LLMjacking, the cost to an attacker is close to zero." AI Malware That Uses LLM in a Codeless Attack The findings also follow the discovery of an AI malware that brings together a Telegram bot with a public LLM API to devise a codeless attack. Once launched, the implant transmits basic details about the compromised system to the attacker's Telegram bot and enters into a command-and-control (C2) loop that polls the bot API every 5 seconds for new messages. The results of the command execution are exfiltrated back using the same channel. The speciality of this malware is that each operator message is forwarded to a public LLM API endpoint ("api.groq[.]com/openai/v1/chat/completions"), which then translates the natural language instructions provided by the attacker into its equivalent shell command. The artifact was uploaded to the VirusTotal platform on March 11, 2026, and has zero detections across all engines to date. "This work introduces an LLM translation layer that replaces shell syntax with plain text. The attacker types plaintext instructions in Telegram," Palo Alto Networks Unit 42 said. "The LLM translates the instructions into shell commands. And the victim executes the shell commands. No command-line knowledge is required."
thehackernews.comJul 3, 2026extracted
CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach
The UK’s Cyber Monitoring Centre (CMC) has shared its analysis of the Canvas cyber incident affecting Instructure’s Learning Management System as the education technology firm prepares to share its own findings next week. The CMC said that approximately 160 UK higher education institutions were affected and threat actors exfiltrated confidential course and user data. In total, around 9000 educational institutions are thought to have been affected worldwide. While the incident has not met the CMC’s minimum category threshold, the review aims to better understand the financial impact of data breach events, inform the development of the CMC’s data breach analysis model and deepen insight into cyber risk within the UK higher education sector. The CMC considers a cyber-attack a ‘Category 1 event’ if it has loss of £10m ($13m) or impact more than 0.01% of UK organizations. For context, the 2025 cyber-attack against Jaguar Land Rove was ranked as a Category 3 systemic event on the five-point CMC scale. The CMC said that the Canvas event illustrates how data breach events can differ from large-scale disruption events in their financial profile. “In this case, losses appear to be driven more by response, recovery, and risk management activity than by prolonged business interruption,” the CMC review said. How the Canvas Cyber-Attack Unfolded On April 29, Instructure detected unauthorized activity in Canvas. The company said this activity was carried out by a cybercriminal organization known for large-scale attacks across multiple sectors, including technology and education. On May 7, 2026, the same threat actor gained additional access through a second Canvas vulnerability. The unauthorized actor made changes to the pages that appeared when some students and teachers were logged in through Canvas A defacement message which appeared on approximately 330 institutional Canvas login pages led many to conclude that the ShinyHunters extortion group was at the center of the cyber-attack. Attribution has not been confirmed by Instructure. The firm confirmed on May 9 that Canvas was fully online and available for use. CrowdStrike is involved in the forensic investigation into the incident, which Instructure said was carried out using one of its Free-For-Teacher accounts. Cyber Monitoring Centre Review and Recommendations The CMC said that despite the number of higher education institutions affected, there is no evidence of lateral movement of the threat actors into the other institutional systems. The recommendations outline by the CMC were described as “common good practice” for higher education establishments that have been reinforced by analysis of the Canvas event. These include: Align architecture with risk: Priorities protection of mission‑critical systems and high‑value services based on the organization’s risk appetite Separate application and data layers: Improve data integrity, recovery and validation by isolating these components where possible Enforce MFA consistently: Ensure multi-factor authentication is properly implemented across all systems Control third‑party access: Limit and closely manage external access privileges across the supply chain Assess offshore dependencies: Understand risks linked to overseas providers, including legal and support limitations Strengthen SaaS security: Follow provider guidance to avoid misconfigurations and reduce breach risk Test incident response plans: Run breach and outage scenarios to improve resilience and business continuity Canvas Incident Underscores Phishing Risks and Need for Clear Communication Communication was also a key recommendation for organizations responding to an incident including sharing sufficient technical detail to enable partners and customers to assess their exposure and undertake their own investigation. Further, the CMC said that software providers should maintain appropriate customer contacts – for example the CIO or CISO – for incident notifications. Following the incident, the education technology firm said it had "reached an agreement with the unauthorized actor involved in this incident." However, it did not state whether money exchanged hands. The CMC noted that following a ransom payment, promises to delete data, including passing on apparent technical proof of deletion, are unreliable. In this case, the ongoing risk to students and others is unlikely to be direct extortion. A more likely risk is that the exfiltrated data could be used to target them with more sophisticated phishing emails. Canvas said it does not expect the information involved to be made public but highlighted that those affected should remain vigilant for phishing, smishing and vishing scams.
infosecurity-magazine.comJun 26, 2026extracted
GentleKiller Framework Disables Victims' Security Software
One of the most active ransomware gangs of 2026 has been handing its affiliates a ready-made toolkit for switching off victims' security software before the encryption begins. New analysis from ESET detailed the endpoint detection and response (EDR) killer suite of The Gentlemen, a ransomware-as-a-service operation (RaaS), built around an in-house framework the researchers named GentleKiller. GentleKiller's job is to disable endpoint protection. ESET found it targeting more than 400 processes across roughly 48 security products, from Microsoft Defender and CrowdStrike to Sophos and ESET's own tools, attempting to disable them at the kernel level so the ransomware could run unchecked. Borrowed Drivers, Kernel Power The method is called bring your own vulnerable driver (BYOVD). Each build loads a legitimately signed but flawed kernel driver, then abuses it to kill security processes from inside the kernel, beyond the reach of user-mode protections. ESET counted at least eight GentleKiller variants, each impersonating a different legitimate product, with names lifted from games and security brands such as Valorant, FACEIT and Kaspersky, and each abusing a different driver. To bypass inspection, the binaries carry fake version details, copied but invalid digital signatures and the icons of the vendors they mimic, often wrapped in commercial packers. A Suite, Not a Single Tool What makes Gentlemen unusual is that its operators, not its affiliates, build and maintain the EDR killers. ESET said most ransomware crews leave affiliates to find their own; only a handful, such as RansomHub, supply one. Gentlemen offers a whole portfolio: GentleKiller, the in-house framework, in at least eight variants HexKiller, previously tied to the Warlock gang ThrottleBlood, seen in MedusaLocker and DragonForce intrusions HavocKiller, which abuses a Huawei audio driver The three borrowed tools were each re-skinned with Gentlemen's shared evasion layer. GentleKiller itself moved faster still, with the operators turning newly disclosed driver exploits into working variants within days of release. Inside the Gentlemen Operation Gentlemen surfaced in late 2025, founded by a former Qilin affiliate, and lures affiliates with an unusually large 90% cut. ESET confirmed the operator-run model partly through a May data leak, in which the gang's leader openly discussed maintaining the EDR-killer packages. Unusually, it does not concentrate on US victims, picking targets across Southeast Asia, South America and Western Europe by their exposed FortiGate configurations. ESET said understanding how GentleKiller works helps defenders prepare even for variants not yet built. In practice, defenses against such BYOVD attacks center on blocking known-vulnerable drivers and alerting whenever a protected security process is suddenly shut down.
infosecurity-magazine.comJun 22, 2026extracted
Klue Breach Enables Hackers to Compromise Cybersecurity Firms via OAuth Tokens
Several companies have disclosed that they were affected by a breach of business intelligence provider Klue, including a number of cybersecurity firms. Huntress, Recorded Future, Jamf and Tanium have all acknowledged using Klue’s intelligence services and confirmed that the breach enabled unauthorized access to their Salesforce accounts via stolen OAuth tokens used for Klue integrations. Klue Battlecards Breach and Salesforce OAuth Token Abuse According to an official statement published by Klue’s CEO, Jason Smith, on June 19, the company detected an intrusion on June 12. An unauthorized actor gained access to Klue’s integration infrastructure, notably the Klue Battlecards app, through a compromised legacy credential. They used this access to obtain OAuth tokens - a secure digital key that allows an application to access a firm’s data on another service without needing a password – and connect Klue to third-party platforms, including Salesforce. They then accessed Klue customer data and leveraged the stolen OAuth tokens to impersonate Klue within those connected Salesforce environments, exfiltrating sensitive customer information before the activity was detected and contained. Klue’s Smith said the company immediately responded by revoking affected credentials and tokens, removing unauthorized code and disabling potentially impacted integrations. Klue also notified law enforcement and launched an internal investigation and comprehensive review of its security controls. It has now engaged CrowdStrike to support with forensics. Customers have been regularly updated about what happened and provided with remediation guidance through various channels. Salesforce also notified the public on June 17 it has disabled Klue Battlecards integration. Klue Breach Affects Cybersecurity Firms In customer-facing blog posts, Huntress, Recorded Future, Jamf and Tanium confirmed that while the breach originated through Klue’s infrastructure, their own products and services remained unaffected. Tanium reassured customers that "there was no impact on our ability to serve them." Meanwhile Jamf stated, "We have no evidence of lateral movement and have contained the incident on our end." However, Huntress warned that customer data may have been compromised, including business names, products trialed/used, subscription details, business contact information and marketing and sales communications. Jamf also warned customers about potential phishing campaigns leveraging the stolen Salesforce data, advising vigilance against malicious actors posing as Jamf employees. Recorded Future disabled Klue’s integration and conducted a forensic analysis, emphasizing the need for continuous monitoring of third-party integrations. The company said, "This incident underscores the critical need for continuous monitoring of third-party integrations, especially those with privileged access to sensitive data." ReliaQuest was the first to detect the suspicious and alerted Klue. However, the company told Infosecurity that it does not use Klue and was not affected by the breach. Commenting on how the attackers exploited OAuth tokens to pivot into connected Salesforce environments, the firm said: "The adversary’s ability to move laterally from a compromised integration to a customer’s CRM demonstrates the evolving tactics of modern threat actors.” Non-cybersecurity firms were also affected, including insurance service provider Insurity and social media analytics platform Sprout Social. The breach was claimed on June 19 by Icarus, a recently identified cyber extortion group. Icarus has just three victims listed on its data leak site, according to ransomware tracking website Ransomware.live. On June 20, the group issued a deadline message to all Klue clients it claims to have contacted, warning that they have until June 22 to respond before their data is released. This article was updated on June 22 to add ReliaQuest's comments, highlighting the company has not been affected by the Klue breach.
infosecurity-magazine.comJun 22, 2026extracted
More Cybersecurity Firms Disclose Impact From Klue Hack
At least nine organizations have publicly acknowledged the impact of the supply chain attack on market intelligence platform Klue. The incident occurred on June 11-12 and affected Klue’s integration with Salesforce, resulting in data being exfiltrated from the Salesforce instances of multiple Klue customers, including several cybersecurity firms. On Friday, Klue confirmed previous security reports that the attackers used compromised legacy credentials to access its systems and compromise Salesforce integrations. “The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments,” Klue said. The company revoked the affected credentials and tokens, disabled the integrations across multiple services, and has been investigating the attack together with CrowdStrike and law enforcement. “Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted,” the company said. To date, at least nine Klue customers have disclosed impact from the incident, including cybersecurity firms HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. Insurity and Sprout Social also notified their customers of the incident. All the affected companies pointed out that the intrusion was limited to the Salesforce instances and did not involve their systems, as Klue said in its incident notice. Across the board, the hackers stole business information from the affected organizations’ Salesforce CRMs, including sales account data and business contact information, such as names, email addresses, job titles, phone numbers, and business addresses. Salesforce disabled the Klue integration in the wake of the incident, and revenue intelligence platform Gong did the same on Friday, warning that the hackers exploited its Klue integration to access internal licensed user data. “We can confirm no direct impact on call recordings or customer transcripts. Examples of data accessed included user names, user business titles, and user emails,” Gong said. In its analysis of the incident, Huntress suggested that a threat actor named Icarus might have been responsible for the attack. Since then, Icarus has added Klue to its Tor-based leak site, claiming responsibility for the attack and threatening to publish the information stolen from Klue customers’ Salesforce instances. Per the threat actor’s posts, the data would be released on June 22, unless Klue and the affected organizations engage in negotiations. Related: Cybersecurity Firms Impacted by Klue Supply Chain Attack Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems Related: Laravel-Lang Packages Poisoned for Malware Delivery
securityweek.comJun 22, 2026extracted
In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: 10-year-old phpBB flaw enables session hijacking Researchers uncovered a critical authentication bypass in phpBB versions up to 3.3.16 and 4.0.0-a2. A single unauthenticated HTTP request can impersonate any user, including admins, exposing private messages and forum content, and providing full administrative control. phpBB users should upgrade immediately to 3.3.17 or the latest master branch. The issue, reported via HackerOne, received a patch within days, but thousands of active forums remain exposed. Velvet Ant maintained decade-long stealth in air-gapped critical infrastructure China-nexus actor Velvet Ant compromised an organization’s segregated network starting around 2016. It chained internet-facing footholds, Nginx/FastCGI proxies, and backdoored PAM/OpenSSH components for credential theft and persistent access. The group deployed variants of GS-Netcat, SOCKS5 proxies, and nine pam_unix.so backdoors across hosts. Remediation proved complex. MaXSS and Spyder flaws expose 10 million Chrome users to hacking Critical vulnerabilities in SiderAI (Spyder) and MaxAI (MaXSS) agentic side-panel Chrome extensions can allow malicious websites to trigger arbitrary extension actions, including hidden tab screenshots, AI memory dumps, and potential file access. With over 10 million combined installs and no vendor response, the issues enable full browser session compromise and account takeovers without user interaction. Users should remove the extensions until fixed. AWS unveils Continuum AWS has announced a new AI-powered tool designed to help organizations discover, prioritize, validate, and resolve vulnerabilities. Available in gated preview, Continuum takes findings from existing tools and its own scanning, prioritizing them based on exploitability in the user’s own environment. 1.2 million WordPress sites compromised in OptinMonster supply chain attack Attackers injected malicious JavaScript into Awesome Motive’s OptinMonster, TrustPulse, and PushEngage WordPress plugin CDN scripts. The payload activates for logged-in admins, creating rogue administrator accounts and a hidden backdoor plugin. The breach stemmed from a compromised UpdraftPlus instance and CDN key. The supply chain attack is believed to have hit more than 1.2 million WordPress sites. FTC says imposter scams cost Americans $3.5 billion in 2025 The FTC reported imposter scams as the most common fraud category, with losses nearly tripling since 2020. Bank and government impersonation schemes drove the bulk of the damage, often via fake security alerts urging money transfers. Overall fraud losses hit a record $16 billion. The agency continues enforcement under its Impersonation Rule and supports public awareness campaigns. US DOT closes investigation into Delta’s 2024 CrowdStrike outage response The Department of Transportation ended its probe into Delta’s prolonged recovery from the global CrowdStrike incident without penalties. Investigators found the airline provided adequate refunds, baggage help, and support for passengers with disabilities. This aligns with the current administration’s shift away from certain Biden-era consumer protection enforcement approaches. JetBrains Marketplace plugins steal developer AI keys At least 15 malicious AI coding assistant plugins, published in the JetBrains Marketplace under various vendor accounts, exfiltrate OpenAI, DeepSeek, and similar API keys. The plugins have racked up nearly 70,000 installs while functioning as advertised. Keys are sent in plaintext to a hardcoded attacker server. The plugins also appear to resell stolen access to paying users. Apple releases Beats firmware fixing unauthenticated mic access Beats Studio Buds firmware update 1B211 patches CVE-2025-20701, which allowed nearby attackers to listen via the microphone on unpaired devices actively seeking connections. Updates apply automatically when paired with Apple devices. CVE-2025-20701 is one of three Bluetooth security issues disclosed last year, which have been found to impact devices from several major vendors. Popa botnet tied to Israeli proxy provider Researchers linked the large Popa Android TV box botnet — used for residential proxy traffic in ad fraud and scraping — to NetNut, operated by publicly traded Israeli company Alarum Technologies. Researchers said an SDK turns compromised streaming devices into persistent proxies. The operation involves millions of IPs daily and raises concerns about local network exposure and ties to data scraping. NetNut and Alarum have disputed the allegations calling them “demonstrably inaccurate assertions and flawed deductions rather than verified facts.” GCP Config Connector enables org-wide IAM owner takeover A confused deputy vulnerability in Config Connector lets any Kubernetes namespace user escalate to GCP Organization Owner by submitting a malicious IAMPolicyMember. Google acknowledged the issue internally as P1/S1 but later classified it as “working as intended” and left it unpatched. The bypass affects organizations using the service for organization-level management. ShinyHunters leaks Knicks and MSG talent and customer data Hackers published Madison Square Garden data, including details on Knicks-related “talent” (players, coaches, celebrities) with risk assessments, addresses, and contact info, along with customer correspondence. The dump follows a June 5 breach. ShinyHunters continues its pattern of public leaks to pressure victims.
securityweek.comJun 19, 2026extracted
Lock-in tecnologico cyber: come pianificare la strategia di uscita
Il lock-in tecnologico è la condizione in cui un’organizzazione diventa così dipendente da un vendor specifico – per ragioni tecniche, contrattuali, operative o normative – da rendere la transizione verso un’alternativa eccessivamente costosa, rischiosa o temporalmente impraticabile. Non è, di per sé, una patologia in quanto un certo grado di dipendenza dai propri fornitori è fisiologico in qualsiasi ecosistema tecnologico complesso. Semmai, il problema emerge quando questa stessa dipendenza raggiunge un livello tale da compromettere la capacità dell’organizzazione di prendere decisioni autonome sul proprio stack IT, di rispondere a variazioni del mercato o di gestire una crisi del fornitore senza subire interruzioni operative significative. Indice degli argomenti Nel contesto della cyber security, il lock-in tecnologico introduce una dimensione di rischio specifica che va oltre la semplice dipendenza commerciale. Un’organizzazione profondamente dipendente da un singolo vendor per funzioni di sicurezza critiche, come possono essere un EDR, un SIEM o una piattaforma di identity management, è esposta a un rischio che combina la concentrazione operativa con la superficie di attacco: se quel vendor viene compromesso (come nel caso CrowdStrike del 2024), non solo il servizio si interrompe, ma il sistema di difesa stesso diventa il vettore del problema. Dunque, la diversificazione non è solo una scelta commerciale ma una misura di resilienza. Per i soggetti NIS2 e DORA, il rischio di lock-in ha una dimensione normativa esplicita: DORA identifica la concentrazione verso un singolo provider ICT come rischio sistemico da presidiare e impone alle entità finanziarie di valutare e documentare le dipendenze critiche. NIS2, più in generale, richiede che le misure di sicurezza includano la continuità operativa, un obiettivo difficilmente raggiungibile in presenza di dipendenze non presidiate da adeguate strategie di uscita. La pianificazione della reversibilità non è, quindi, un’opzione avanzata per le organizzazioni più mature: è un requisito di governance che le normative stanno progressivamente rendendo obbligatorio. Quando si parla di forniture IT si possono quindi identificare quattro differenti forme di lock-in tecnologico Il lock-in contrattuale è la forma più immediata e, paradossalmente, la più facilmente prevenibile se affrontata nella fase di negoziazione. Si manifesta attraverso clausole che rendono la cessazione del rapporto commerciale eccessivamente onerosa: penali di uscita anticipata calcolate sull’intero valore residuo del contratto, rinnovi automatici con finestre di disdetta strette, limitazioni al diritto di portabilità dei dati, periodi minimi contrattuali pluriennali senza clausole di revisione. Nei contratti con i grandi hyperscaler e con i vendor di software Enterprise, queste clausole sono spesso la norma, non l’eccezione. La difesa contrattuale contro questo tipo di lock-in richiede attenzione in fase di negoziazione: clausole di exit esplicite con termini e costi predefiniti; diritto di portabilità dei dati in formato standard senza costi aggiuntivi; finestre di disdetta ragionevoli (90 giorni è uno standard accettabile per la maggior parte dei servizi); limitazione delle penali di uscita anticipata a importi proporzionati e non punitivi. Per i contratti con vendor che gestiscono funzioni critiche, è opportuno negoziare anche obblighi di supporto alla transizione: un periodo di affiancamento post-contratto durante il quale il vendor fornisce accesso ai dati e supporto tecnico alla migrazione. Il lock-in tecnico è la forma più pervasiva e difficile da rimuovere una volta instauratasi. Si manifesta attraverso la dipendenza da formati proprietari (e quindi, dati che non possono essere esportati in formati standard senza perdita di informazioni o senza strumenti specifici del vendor) e da API proprietarie che richiedono riscrittura significativa delle integrazioni per migrare verso un’alternativa. Un CRM che archivia i dati in un formato interno non esportabile in CSV o JSON standard, un SIEM che produce log in un formato proprietario non leggibile da altri strumenti, una piattaforma cloud che offre servizi managed senza equivalenti standard: questi sono esempi concreti di lock-in tecnico che si accumula silenziosamente nel tempo, spesso senza che l’organizzazione ne sia consapevole fino al momento in cui cerca di uscire. La prevenzione del lock-in tecnico richiede una strategia di architettura deliberata: privilegiare standard aperti e interoperabili nelle scelte tecnologiche, evitare dipendenze da servizi proprietari privi di alternative equivalenti, mantenere layer di astrazione (API gateway, middleware) che isolino il business logic dalle specificità del vendor sottostante. Per le piattaforme cloud, l’adozione di strumenti di Infrastructure as Code (Terraform, Pulumi) con provider-agnostic configuration riduce significativamente il costo di una eventuale migrazione verso un hyperscaler alternativo. Il lock-in operativo è il meno visibile dei quattro e spesso il più costoso da risolvere. Si accumula nel tempo attraverso la specializzazione del personale su tecnologie proprietarie specifiche: team IT che conoscono profondamente una piattaforma ma non hanno esperienza con le alternative, processi operativi costruiti attorno alle specificità di un vendor, procedure di troubleshooting e documentazione che assumono implicitamente la presenza di quel vendor. Quando l’organizzazione deve cambiare, si trova a dover affrontare non solo la migrazione tecnica, ma anche un gap di competenze che richiede tempo e risorse significative per essere colmato. La gestione del lock-in operativo richiede un approccio proattivo alla formazione e alla documentazione: mantenere competenze interne che non dipendano esclusivamente da un singolo vendor; costruire processi operativi che siano il più possibile vendor-agnostic; documentare le configurazioni e le procedure in modo da renderle trasferibili. Per le competenze critiche, è buona pratica mantenere almeno una risorsa interna con conoscenza dell’alternativa principale, anche se non la si utilizza attivamente, per garantire la capacità di valutazione in caso di necessità di transizione. Il lock-in normativo è una categoria specifica dei settori regolamentati: si verifica quando la scelta di un vendor crea dipendenze che sono difficili da sciogliere per ragioni di conformità. Un sistema di archiviazione che garantisce la conservazione dei log per 10 anni secondo requisiti normativi specifici, una piattaforma di firma elettronica certificata secondo standard nazionali, un sistema di gestione dei dati sanitari conforme a requisiti specifici di settore: migrare da questi sistemi richiede non solo la migrazione tecnica dei dati, ma la verifica che il nuovo vendor garantisca la stessa conformità normativa, spesso un processo lungo e costoso. Per le organizzazioni nei settori critici NIS2, il lock-in normativo può manifestarsi anche attraverso la data residency: un vendor che garantisce la residenza dei dati in specifiche regioni geografiche richieste dalla normativa applicabile crea una dipendenza che limita le alternative disponibili. La prevenzione richiede di verificare, in fase di selezione, che esistano almeno due vendor alternativi in grado di soddisfare i requisiti normativi applicabili — non uno solo. Riconoscere il lock-in è necessario, ma non sufficiente: per prendere decisioni informate, l’organizzazione ha bisogno di uno strumento che consenta di misurarlo in modo coerente e comparabile tra vendor diversi. Il Vendor Dependency Index (VDI) è un framework di valutazione strutturato in sei dimensioni, ciascuna con un peso relativo proporzionale al suo impatto sulla capacità di transizione. Il risultato è un punteggio da 1 (dipendenza minima, transizione agevole) a 5 (lock-in critico, transizione estremamente costosa o impraticabile nel breve termine). Il VDI non è uno strumento assoluto, ma uno strumento di confronto e prioritizzazione. Il suo valore principale è rendere visibile e quantificabile un rischio che altrimenti rimane implicito nelle valutazioni soggettive dei team IT. Un VDI superiore a 3,5 per un vendor che gestisce funzioni critiche deve attivare un piano di mitigazione; un VDI superiore a 4,5 rappresenta una dipendenza che richiede attenzione immediata del management. La pianificazione della reversibilità è spesso percepita come un esercizio accademico, utile in teoria ma difficilmente necessario nella pratica quotidiana. Gli scenari di crisi che seguono hanno lo scopo di ancorare questa percezione alla realtà: sono casi che si sono verificati, si verificano regolarmente, e che le organizzazioni prive di una exit strategy hanno affrontato in condizioni di estrema difficoltà operativa. Un vendor IT che gestisce infrastrutture critiche entra in procedura fallimentare. Il servizio si interrompe con preavviso di 30-60 giorni. I dati sono bloccati fino alla nomina del curatore. L’organizzazione deve migrare in emergenza verso un’alternativa senza il supporto del vendor. Casi reali: il fallimento di diversi provider cloud di secondo livello negli anni 2015-2020 ha lasciato centinaia di clienti senza accesso ai propri dati per settimane. La lezione: la solidità finanziaria del vendor è un elemento del rischio lock-in, non solo un indicatore commerciale. Un VDI elevato su un vendor con indicatori finanziari in deterioramento è un segnale di allerta critico. Un vendor critico viene acquisito da un concorrente diretto dell’organizzazione cliente, o da un soggetto con interessi in conflitto. Il nuovo proprietario modifica le condizioni contrattuali, aumenta i prezzi in modo significativo, o discontinua il prodotto. L’organizzazione si trova vincolata a un contratto con un vendor che non avrebbe mai scelto. Casi reali: l’acquisizione di VMware da parte di Broadcom (2023) e la successiva ristrutturazione delle licenze ha costretto migliaia di organizzazioni a rivalutare la propria dipendenza dalla piattaforma di virtualizzazione, con costi di migrazione non previsti. La lezione: il vendor che si acquista oggi potrebbe non essere lo stesso tra due anni. Un vendor viene sanzionato da un’autorità regolatoria (ACN, Garante privacy, autorità di vigilanza finanziaria) o incluso in liste di restrizione per ragioni di sicurezza nazionale. L’organizzazione deve cessare il rapporto entro tempi imposti dalla normativa, indipendentemente dal costo e dalla complessità della migrazione. Casi reali: le restrizioni imposte in diversi paesi europei e negli USA a vendor di telecomunicazioni e software di origine cinese (Huawei, ZTE, Kaspersky) hanno costretto le organizzazioni nei settori critici a migrazioni urgenti. La lezione che ne possiamo trarre è che il rischio geopolitico è un componente del rischio lock-in che deve essere valutato esplicitamente per i vendor con sede o interessi in paesi ad alto rischio. Sviluppare un piano di transizione verso provider alternativi evita l’interruzione operativa del business in caso di crisi del fornitore. La pianificazione della reversibilità è un pilastro del Vendor Risk Management moderno per mitigare i rischi cyber: la capacità di uscire da una relazione con un vendor critico in tempi ragionevoli e senza interruzioni operative non è una misura difensiva straordinaria, ma un requisito di resilienza che le normative NIS2 e DORA stanno progressivamente codificando. La reversibilità non significa necessariamente cambiare vendor frequentemente o mantenere architetture ridondanti costose: significa avere la capacità di farlo quando necessario, in tempi accettabili, con un costo proporzionato. Questa capacità si costruisce nel tempo attraverso scelte architetturali deliberate, clausole contrattuali adeguate e un monitoraggio continuo del grado di dipendenza. Un’organizzazione che ha investito nella portabilità dei dati, nell’interoperabilità dei sistemi e nella formazione del personale su più piattaforme è intrinsecamente più resiliente e più conforme ai requisiti normativi di una che ha ottimizzato esclusivamente sull’integrazione con un singolo vendor. La portabilità dei dati è il prerequisito tecnico di qualsiasi strategia di exit. Senza la capacità di estrarre i propri dati in formato standard e completo, qualsiasi piano di migrazione è teorico. Eppure, nella pratica, molte organizzazioni scoprono i limiti alla portabilità dei dati solo quando tentano di effettuare la migrazione: formati di esportazione incompleti, API con rate limit che rendono l’estrazione di grandi volumi impraticabile in tempi ragionevoli, costi di egress per il trasferimento dei dati fuori dalla piattaforma del vendor. La difesa contro questo rischio deve essere contrattuale e tecnica insieme. Sul piano contrattuale: clausole esplicite che garantiscono l’esportazione completa dei dati in formati aperti e documentati, senza costi aggiuntivi, entro termini definiti dalla richiesta di cessazione. Sul piano tecnico: test periodici di esportazione dei dati critici (non solo la verifica che la funzione esista, ma la verifica che funzioni correttamente con i volumi reali) e documentazione aggiornata del formato dei dati esportati per facilitare l’importazione nel sistema del vendor alternativo. L’adozione di standard aperti e di architetture interoperabili è la strategia di prevenzione del lock-in tecnico più efficace a lungo termine. Nel contesto cloud, questo si traduce nella preferenza per servizi che implementano API standard (REST, OpenAPI, GraphQL) rispetto a API proprietarie, nell’utilizzo di formati di dati aperti (JSON, Parquet, CSV) rispetto a formati binari proprietari, e nell’adozione di strumenti di orchestrazione e provisioning che supportano nativamente più provider (Kubernetes per i container, Terraform per l’Infrastructure as Code). Per le piattaforme di sicurezza, l’interoperabilità è garantita dall’adozione di standard come STIX/TAXII per la condivisione di threat intelligence, OpenC2 per l’automazione della risposta, e OCSF (Open Cybersecurity Schema Framework) per la normalizzazione dei log di sicurezza. L’adozione di questi standard non è solo una scelta tecnica: è una misura di resilienza che riduce il costo di sostituzione di un componente della stack di sicurezza e facilita l’integrazione con nuovi vendor. La strategia multi-vendor, ossia distribuire le funzioni critiche tra vendor diversi per ridurre la concentrazione del rischio, è la risposta più diretta al lock-in tecnologico, ma anche quella con i costi operativi più elevati. Gestire più vendor per la stessa funzione introduce complessità: interfacce diverse, procedure operative distinte, costi di formazione moltiplicati, potenziali problemi di integrazione. La scelta tra vendor singolo e multi-vendor non è quindi una scelta tra sicurezza e comodità: è una valutazione del trade-off tra rischio di concentrazione e costo operativo della diversificazione. Un approccio pragmatico prevede di applicare la strategia multi-vendor selettivamente, in funzione della criticità della funzione e del VDI del vendor primario: per le funzioni essenziali con VDI elevato, la duplicazione è giustificata e raccomandabile; per le funzioni con VDI basso e alternative disponibili in tempi ragionevoli, la complessità aggiuntiva di un secondo vendor non è necessariamente giustificata. Il caso degli hyperscaler è emblematico: una strategia multi-cloud attiva (workload distribuiti tra AWS, Azure e GCP) riduce il lock-in ma aumenta significativamente la complessità operativa; una strategia cloud-agnostic basata su Kubernetes e Terraform mantiene la portabilità senza la complessità della gestione multi-cloud attiva. La exit strategy inizia dal contratto. Le clausole di reversibilità, spesso trascurate nella negoziazione, quando l’attenzione è concentrata sulla funzionalità e sul prezzo, sono lo strumento che garantisce all’organizzazione il diritto e la capacità pratica di uscire dalla relazione con il vendor in condizioni controllate. Gli elementi essenziali di una clausola di reversibilità efficace coprono quattro aree: il diritto di portabilità (esportazione completa dei dati in formato standard, senza costi aggiuntivi); il supporto alla transizione (periodo di affiancamento post-contratto, tipicamente 90-180 giorni, durante il quale il vendor continua a fornire accesso ai dati e supporto tecnico alla migrazione); la cancellazione certificata (distruzione sicura dei dati residui con certificazione documentata); la continuità del servizio (garanzia che il servizio continui a funzionare normalmente durante il periodo di transizione, senza degradazione delle performance o delle funzionalità). Il piano di migrazione è il documento operativo che traduce la strategia di exit in un progetto concreto con fasi, responsabilità, risorse e tempistiche. Deve essere preparato con anticipo: idealmente al momento dell’onboarding del vendor, non quando la migrazione diventa urgente, e aggiornato periodicamente per riflettere l’evoluzione dell’ambiente tecnologico e della relazione con il vendor. Un piano di migrazione mai aggiornato è quasi inutile nel momento del bisogno. Le fasi tipiche di un piano di migrazione da un vendor critico sono: assessment dell’ambiente attuale (inventario di dati, integrazioni, dipendenze, competenze); selezione del vendor alternativo (con processo di valutazione formale che include security assessment e VDI preliminare); progettazione dell’architettura target; migrazione pilota su ambiente non produttivo; migrazione progressiva degli ambienti produttivi con rollback plan; verifica funzionale e di sicurezza; dismissione dell’ambiente del vendor precedente con cancellazione certificata dei dati. Per i sistemi critici, la fase di coesistenza in cui entrambi i vendor operano in parallelo è raccomandata anche quando aumenta il costo a breve termine: garantisce la continuità operativa durante la transizione e riduce il rischio di interruzione. Il lock-in nei servizi cloud degli hyperscaler (AWS, Microsoft Azure, Google Cloud Platform) merita una trattazione specifica per la sua pervasività e per la complessità delle dipendenze che può generare. I grandi provider cloud offrono ecosistemi di servizi managed estremamente ricchi e integrati: database proprietari (DynamoDB, Cosmos DB, BigQuery), servizi serverless (Lambda, Azure Functions, Cloud Run), strumenti di ML/AI nativi, servizi di sicurezza integrati. L’adozione di questi servizi genera produttività immediata e integrazione nativa e il lock-in tecnico che cresce con ogni servizio managed aggiuntivo adottato. La risposta non è evitare i servizi managed degli hyperscaler, sarebbe come rinunciare a vantaggi competitivi reali, ma adottarli con consapevolezza del lock-in che generano. Una strategia cloud pragmatica distingue tra i servizi che sono accettabile avere in lock-in (servizi non critici, facilmente riproducibili, con basso VDI) e quelli per cui la portabilità deve essere preservata (dati critici, funzioni essenziali, sistemi con compliance normativa specifica). Per questi ultimi, l’investimento in architetture cloud-agnostic (container-based, IaC-managed, con storage in formati aperti) è un investimento in resilienza, non solo in flessibilità tecnica. Per le organizzazioni che operano in ambienti ibridi (infrastruttura on-premise combinata con servizi cloud) il rischio di lock-in si manifesta anche attraverso la dipendenza dagli strumenti di gestione dell’ambiente ibrido stesso: soluzioni come VMware (ora Broadcom), Azure Arc, AWS Outposts. L’acquisizione di VMware da parte di Broadcom e la conseguente ristrutturazione del modello di licensing è diventata il caso di scuola del lock-in negli ambienti ibridi: migliaia di organizzazioni si sono trovate a dover rivalutare la propria infrastruttura di virtualizzazione in condizioni di urgenza, con costi non previsti e alternative tecnicamente complesse da implementare in tempi brevi.
cybersecurity360.itJun 18, 2026extracted
Cisco Talos, nel 2026 attività sponsorizzate dagli Stati meno rumorose ma più pazienti: ecco come difendersi
Le minacce sponsorizzate dagli Stati costituiscono una delle sfide più complesse per aziende, infrastrutture critiche e pubbliche amministrazioni. Lo riporta l’ultima analisi di Cisco Talos nel 2026. Il team di intelligence di Cisco, specializzato nello studio delle minacce avanzate, infatti “conferma un’evoluzione ormai evidente anche in altri report recenti di Mandiant e CrowdStrike”, secondo Pierluigi Paganini, analista di cyber security e Ceo Cybhorus. “Questa importante analisi ci dà infatti modo di focalizzare un aspetto che spesso viene sottovalutato: gli attori sponsorizzati dagli Stati non sono necessariamente i più rumorosi, ma sono quasi sempre i più pazienti“, secondo Dario Fadda, esperto di cyber sicurezza e collaboratore di Cybersecurity360. Ecco perché e come mitigare il rischio. Indice degli argomenti I gruppi Nation-State non agiscono per guadagnare un ritorno immediato o per produrre impatti visibili. Invece operano silenziosamente, con metodo e in maniera persistente, utilizzando credenziali valide, strumenti legittimi e relazioni di fiducia già presenti nelle organizzazioni. L’analisi di Cisco Talos mette in risalto un’evoluzione rilevante nel modo in cui si conduce questa tipologia di attacchi e, dunque, come fronteggiarli. I gruppi di cyber criminali sponsorizzati dagli Stati non operano secondo la logica dei criminali comuni. “Oggi il vero rischio non è il ransomware che blocca i sistemi e si fa notare, ma l’avversario che rimane invisibile per mesi utilizzando credenziali legittime e strumenti già presenti nell’infrastruttura”, sottolinea Dario Fadda. Infatti il loro obiettivo è rimanere invisibili il più a lungo possibile, spesso per mesi, raccogliendo informazioni strategiche o mettendo a punto future operazioni. “Le operazioni sponsorizzate dagli Stati stanno progressivamente abbandonando tecniche rumorose per adottare strategie ‘living-off-the-land’, basate su credenziali valide e strumenti nativi del sistema. Questo rende sempre più sfumato il confine tra attività amministrativa e compromissione, aumentando drasticamente il tempo medio di permanenza degli attaccanti nelle reti, che in diversi casi supera i 200 giorni prima della rilevazione“, mette in guardia Paganini. Il fattore più sottovalutato di questo modello operativo è la fiducia. Molte imprese infatti si ostinano a ritenere affidabile tutto ciò che ricade all’internp del proprio perimetro, spaziando dagli utenti interni ai sistemi certificati, fino ai fornitori e alle piattaforme cloud. Ma Cisco Talos punta il dito contro lo sfruttamento sempre più frequente della fiducia implicita. Gli attaccanti agiscono nelle infrastrutture senza introduzione di codice malevolo, ma sfruttando strumenti già presenti come PowerShell o sistemi di gestione IT, oltre a credenziali legittime, così offuscando le proprie attività, rese difficili da riconoscere rispetto ad operazioni amministrative ordinarie. “Il punto centrale non è solo la persistenza, ma la normalizzazione dell’anomalia: l’uso di PowerShell, strumenti IT e accessi legittimi trasforma l’attacco in comportamento ordinario, rendendo inefficaci molti modelli di detection tradizionali basati su firme o indicatori statici“, mette in guardia Paganini: “Anche le analisi più recenti di Microsoft Digital Defense Report evidenziano come oltre il 60% degli incidenti coinvolga identità compromesse, segno che l’identità è ormai il vero perimetro di sicurezza“. Mimetizzandosi e rimanendo nascosti il più a lungo possibili, questi attacchi dimostrano di avere obiettivi differenti rispetto ai ransomware, come lo spionaggio, il furto di proprietà intellettuale o la persistenza di accessi strategici, mantenuti nel tempo per rubare informazioni. “In questo scenario, la supply chain diventa un amplificatore del rischio, come visto in campagne recenti legate a compromissioni di provider e strumenti di sviluppo. La conseguenza è un cambio di paradigma: non si difende più solo la rete, ma l’intero ecosistema di relazioni digitali”, avverte Paganini. Poiché l’accesso iniziale sfrutta frequentemente credenziali compromesse e il movimento laterale utilizza strumenti legittimi per espandersi all’interno dell’infrastruttura, per mitigare i rischi occorre: diffidare di richieste urgenti, non cliccare su link ricevuti in messaggi inattesi, verificare sempre l’autenticità delle comunicazioni tramite i canali ufficiali, adottare l’autenticazione a più fattori e password uniche per ridurre il rischio di compromissioni successive. La protezione degli accessi, il monitoraggio dei comportamenti e la limitazione dei privilegi sono ormai una priorità. “Per questo motivo le organizzazioni, soprattutto quelle che gestiscono servizi critici e finanziari, devono superare il concetto tradizionale di perimetro sicuro e adottare un approccio basato sulla verifica continua della fiducia. La differenza tra rilevare un attacco e accorgersene troppo tardi si gioca sempre più sulla capacità di individuare anomalie comportamentali, non semplicemente malware tecnologici”, avverte Dario Fadda. Inoltre, per mitigare il rischio bisogna implementare un approccio pragmatico, soprattutto laddove le risorse sono limitate. La priorità consiste nell’aumento della visibilità su ciò che accade nella rete, attivando e centralizzando i log e raccogliendo in maniera strutturata le informazioni di sicurezza. In contemporanea, Cisco Talos consiglia nel 2026 di potenziare la protezione delle identità grazie all’adozione dell’autenticazione multifattore e gestendo rigorosamente gli accessi privilegiati. Il monitoraggio continuo dei sistemi più critici e la realizzazione di modelli comportamentali aggiornati nel tempo, in grado di rilevare anche anomalie minime e attività sospette, invisibili o quasi agli strumenti classici, sono fondamentali per difendersi dalle minacce sponsorizzate dagli Stati. Esse si distinguono per gli spazi temporali estesi e obiettivi di natura strategica. Secondo Cisco Talos, nel 2026 una difesa frammentata né solo reattiva debba evolvere verso modelli di monitoraggio continuo, analisi e adattamento. Per distinguere l’attività malevola da quella legittima, occorre identificare anomalie e comportamenti fuori schema, sempre più fattori centrali per la sicurezza. “Serve quindi un approccio basato su continuous threat exposure management, correlazione comportamentale e soprattutto una governance matura delle identità. La sfida non è più ‘bloccare l’attacco’, ma riconoscere quando un’attività interna legittima ha smesso di esserlo”, conclude Paganini.
cybersecurity360.itJun 11, 2026extracted
Aggiornamenti Microsoft giugno 2026: tre zero-day e il ritorno di Nightmare Eclipse
Il Patch Tuesday di giugno 2026 entra direttamente nella storia. Dustin Childs di Zero Day Initiative, che conta le CVE di ogni pacchetto cumulativo di aggiornamenti Microsoft dal 2017, lo ha detto senza giri di parole: “questo è di gran lunga il rilascio mensile più grande che abbia mai contato”. La cifra ufficiale è di 206 CVE corrette, con 33 classificate con un indice di gravità critico, tre zero-day e una falla in Exchange Server che risulta essere già attivamente sfruttata. Tutti i dettagli sul pacchetto cumulativo di aggiornamenti per questo mese sono disponibili sulla pagina ufficiale Microsoft. Indice degli argomenti Se si includono le 360 vulnerabilità Chromium/Edge corrette da Google nel medesimo ciclo (e che insistono sullo stesso ecosistema dei browser Windows) il totale mensile raggiunge la cifra straordinaria di 571 CVE. Un numero che non ha precedenti e che si inserisce nella traiettoria già identificata il mese scorso: i sistemi AI di ricerca automatizzata delle vulnerabilità, a cominciare da MDASH di Microsoft, stanno accelerando la scoperta di falle a una velocità che i processi di patching faticano a sostenere. Nel complesso, le tipologie di vulnerabilità corrette sono le seguenti: 65 di tipo escalation di privilegi; 55 di esecuzione di codice remoto; 28 di tipo spoofing; 30 di tipo Information Disclosure; 19 che consentono il bypass delle funzionalità di sicurezza; 9 di tipo Denial of Service. Ma il dato numerico, per quanto impressionante, non è il cuore del problema di questo mese: il cuore sono le tre zero-day e il contesto in cui sono state prodotte. Per comprendere il vero significato del Patch Tuesday del mese di giugno 2026 occorre partire da una storia che inizia ad aprile. Il ricercatore di sicurezza che opera con gli pseudonimi Chaotic Eclipse e Nightmare Eclipse e già autore del PoC BlueHammer su Microsoft Defender pubblicato il 2 aprile scorso ha fatto di nuovo quello che aveva promesso: ha rilasciato pubblicamente due nuovi zero-day, YellowKey e GreenPlasma, esattamente alla vigilia del Patch Tuesday di giugno. La motivazione dichiarata è sempre la stessa: profonda insoddisfazione per il modo in cui Microsoft gestisce il processo di divulgazione responsabile delle vulnerabilità e il programma di bug bounty. Come ha scritto il ricercatore, il rapporto con Microsoft MSRC si è rotto irreparabilmente. Nel giro di due mesi, questo singolo ricercatore ha rilasciato pubblicamente sei zero-day su prodotti Microsoft: BlueHammer, RedSun, UnDefend, MiniPlasma, YellowKey e GreenPlasma. Tutti prima che Microsoft avesse una patch disponibile. E Nightmare Eclipse ha già annunciato una “sorpresa devastante” per il 14 giugno 2026. Il caso Nightmare Eclipse non è una nota di colore. È un segnale sistemico che il rapporto tra la comunità di ricerca indipendente e i grandi vendor tecnologici è sotto pressione. Quando quel rapporto si rompe, il risultato sono zero-day pubblici senza patch: esattamente il tipo di rischio che nessun programma di vulnerability management può gestire in modo ordinario. E quando il ricercatore annuncia in anticipo la prossima release, il problema non riguarda più solo Microsoft: riguarda chiunque abbia endpoint Windows da proteggere, soprattutto in ambito aziendale. La prima delle tre zero-day è CVE-2026-50507, la vulnerabilità battezzata YellowKey da Nightmare Eclipse: un bypass della cifratura BitLocker che il ricercatore ha descritto come “una delle scoperte più assurde che abbia mai fatto”, paragonandola a una backdoor integrata nel sistema operativo. Il meccanismo di attacco è brutalmente semplice: l’attaccante collega una chiavetta USB con i file exploit al dispositivo bersaglio, protetto da BitLocker, e riavvia il sistema nel Windows Recovery Environment (WinRE). In questo ambiente, tenere premuta una combinazione di tasti specifica innesca una shell con accesso completo e senza restrizioni al volume cifrato. La protezione crittografica, che dovrebbe rendere i dati inaccessibili anche in caso di furto fisico del dispositivo, viene aggirata come se non esistesse. Il CVSS di 6.8 e la classificazione “Important” (anziché Critical) riflettono il requisito di accesso fisico: BitLocker è per definizione una protezione contro le minacce fisiche, quindi una vulnerabilità che richiede accesso fisico ha un vettore d’attacco intrinsecamente più limitato rispetto a un RCE di rete. Ma questo non deve far abbassare la guardia: gli scenari di furto, smarrimento o accesso non autorizzato a dispositivi non presidiati sono esattamente quelli per cui BitLocker esiste. La seconda zero-day è CVE-2026-45586, battezzata GreenPlasma: una vulnerabilità di escalation di privilegi nel processo Windows CTFMON (ctfmon.exe), il componente responsabile del supporto al riconoscimento vocale e alla scrittura manuale che, in ogni sessione interattiva di Windows, viene eseguito con i privilegi di SYSTEM. Il meccanismo tecnico è sofisticato. Come ha spiegato il ricercatore Het Mehta che ha analizzato l’exploit, l’attacco individua una sezione di memoria arbitraria e inganna CTFMON nell’interagire con essa, manipolando una catena di chiavi di registro Windows e regole di permesso. Il risultato è che un utente senza privilegi può creare oggetti di memoria arbitrari in directory accessibili a SYSTEM, potenzialmente permettendo la manipolazione di servizi o driver privilegiati che si fidano implicitamente di quei percorsi. Il PoC rilasciato pubblicamente da Nightmare Eclipse è incompleto (al momento, manca il codice per ottenere una shell SYSTEM completa) ma questo non è di grande conforto: la storia del settore insegna che la distanza tra un PoC parziale e un exploit funzionale, in mani abili, si misura in ore. La terza zero-day, CVE-2026-49160, è una vulnerabilità di Denial of Service nel protocollo HTTP/2 all’interno di HTTP.sys, il componente kernel di Windows che gestisce le richieste HTTP per IIS e altri servizi web Windows. Un attaccante non autenticato può inviare flussi di richieste HTTP/2 appositamente costruiti e mettere fuori servizio i server web esposti su internet. A differenza delle altre due zero-day, CVE-2026-49160 era già pubblicamente nota prima del rilascio della patch. L’impatto diretto è sulla disponibilità del servizio, non sulla confidenzialità dei dati, ma non va sottovalutato: in architetture dove IIS o altri servizi HTTP.sys-based gestiscono applicazioni business-critical, un DoS temporaneo si traduce in perdita di fatturato e possibile violazione degli SLA. Inoltre, un server web temporaneamente offline può aprire finestre di opportunità per attacchi secondari durante il periodo di ripristino. Prima ancora del Patch Tuesday ufficiale del 9 giugno, Microsoft aveva dovuto fare i conti con un’emergenza non pianificata: CVE-2026-42897, una vulnerabilità di spoofing in Exchange Server 2016, 2019 e Subscription Edition, classificata Critical, era stata sfruttata attivamente in attacchi reali già dalla settimana del Patch Tuesday di maggio. Mentre non era ancora disponibile una patch, gli attaccanti ne approfittavano. Microsoft ha risposto in due modi. Sul breve termine, ha attivato il servizio Exchange Emergency Mitigation (EM) per distribuire automaticamente una mitigazione temporanea ai server Exchange con il servizio abilitato. Ma sul lungo termine, la patch definitiva è arrivata con il ciclo di giugno, quasi un mese dopo l’inizio dello sfruttamento attivo e questo intervallo di esposizione è inaccettabile per qualsiasi organizzazione che usi Exchange come infrastruttura email critica. Giugno include anche ulteriori aggiornamenti per Exchange: CVE-2026-45583 (RCE), CVE-2026-45501/45500 (Spoofing), CVE-2026-45504 (EoP) e CVE-2026-45503/45502 (Information Disclosure). La quantità di CVE Exchange in un singolo ciclo è un segnale che la superficie d’attacco di questo prodotto rimane strutturalmente critica e richiede un monitoraggio dedicato. Nel Patch Tuesday del mese di giugno 2026 sono presenti gli aggiornamenti per altre tre importanti vulnerabilità che, se non corrette, potrebbero esporre direttamente l’infrastruttura code del sistema operativo. Una delle vulnerabilità più pericolose del mese per le infrastrutture Enterprise è la CVE-2026-47288, una RCE nel Kerberos Key Distribution Center (KDC) di Windows, il servizio di autenticazione che gira su ogni domain controller Active Directory ed è responsabile dell’emissione dei ticket Kerberos nell’intera rete aziendale. La vulnerabilità è causata da un integer overflow e consente a un attaccante autenticato sulla rete locale o adiacente di eseguire codice sul KDC. Come ha sottolineato CrowdStrike, “una vulnerabilità qui potrebbe permettere agli attaccanti di prendere di mira i server più sensibili in un ambiente Enterprise”. La classificazione come Critical e il vettore “adjacent network” significano che un attaccante già all’interno del perimetro di rete, tramite phishing, VPN compromessa o lateral movement, può usare questa falla per compromettere il domain controller. In parallelo, la CVE-2026-45648 introduce un vettore di esecuzione di codice remoto direttamente nei Domain Services di Active Directory. Come per Kerberos, la compromissione di Active Directory equivale alla compromissione dell’intera infrastruttura di identità aziendale: tutti gli account, tutti i permessi, tutte le risorse gestite dal dominio diventano potenzialmente accessibili all’attaccante. Infine, il mese di giugno 2026 porta tre vulnerabilità critiche in Windows Hyper-V (CVE-2026-47652, CVE-2026-45641, CVE-2026-45607), tutte classificate come RCE con potenziale guest-to-host escape: un attaccante con accesso a una macchina virtuale guest potrebbe eseguire codice sull’host fisico Hyper-V, compromettendo tutte le VM in esecuzione su quel server. In architetture multi-tenant (cloud privati, ambienti di virtualizzazione Enterprise, provider di servizi gestiti MSP) questo tipo di vulnerabilità ha un raggio d’azione potenzialmente illimitato: un singolo guest compromesso diventa il vettore per compromettere l’intero hypervisor e tutto ciò che vi gira sopra. In Patch Tuesday di giugno 2026 interviene su altre vulnerabilità nei sistemi Windows e nelle applicazioni collegate che potrebbero avere impatti importanti sulle superficie di attacco delle aziende. Questo mese Microsoft corregge 11 vulnerabilità nel Remote Desktop Client, alcune delle quali classificate Critical (CVE-2026-44801, CVE-2026-44799, CVE-2026-42992, CVE-2026-42985 e altre). Il vettore di sfruttamento è doppio: un utente che si connette a un server RDP malevolo o apre un file .rdp appositamente costruito può ricevere codice in esecuzione sulla propria macchina. In un contesto di lavoro ibrido e smart working dove l’accesso remoto è la norma, questa superficie d’attacco è enormemente estesa. La raccomandazione operativa va oltre il semplice patching: limitare le connessioni RDP ai soli server fidati e verificati, implementare Network Level Authentication (NLA) ovunque, e valutare l’adozione di soluzioni di remote access zero-trust che non espongano direttamente il protocollo RDP. La lista di CVE Office di giugno è lunga e articolata: CVE-2026-45458 e CVE-2026-45456 sono RCE Critical che interessano contemporaneamente Outlook e Word, sfruttabili tramite documenti malevoli. La Preview Pane di Outlook rimane ancora una volta il vettore chiave. Tre mesi consecutivi di vulnerabilità Office sfruttabili via anteprima del messaggio dovrebbero essere sufficienti a spingere qualsiasi organizzazione ad adottare la misura di hardening più semplice disponibile: disabilitare la Preview Pane per i messaggi da mittenti esterni. Oltre alle RCE, giugno introduce CVE-2026-45459, un Security Feature Bypass in Microsoft Excel che potrebbe ricordare CVE-2026-26144 del marzo scorso, la falla che aveva trasformato Microsoft Copilot in un potenziale vettore di esfiltrazione dati. Con Copilot sempre più integrato nelle applicazioni Office, ogni bypass delle feature di sicurezza di Excel merita analisi approfondita. Il Patch Tuesday di giugno 2026 include, infine, una serie di aggiornamenti per Secure Boot e UEFI Secure Boot (CVE-2026-48576, CVE-2026-48575, CVE-2026-48573, CVE-2026-48570, CVE-2026-48568, CVE-2026-45656, CVE-2026-45654, CVE-2026-45588), oltre a un fix per Windows Boot Manager (CVE-2026-47656). Il contesto non è casuale: con YellowKey che sfrutta il Windows Recovery Environment per bypassare BitLocker, Microsoft sta lavorando a un rafforzamento sistematico dell’intera catena di fiducia pre-OS, da UEFI a Secure Boot a BitLocker. Di particolare rilievo è anche la vulnerabilità tracciata come CVE-2026-44810, una EoP critica nei Microsoft Cryptographic Services: si tratta di un sottosistema fondamentale che gestisce le operazioni crittografiche di Windows, incluse quelle alla base di BitLocker, Secure Boot e HTTPS. Una compromissione di questo componente avrebbe implicazioni che si propagano a tutti i meccanismi di sicurezza che dipendono dalla crittografia di sistema: cioè, praticamente tutti. Da segnalare anche la CVE-2026-42829, un bypass della Windows Administrator Protection (la nuova feature di sicurezza introdotta in Windows 11 26H2 per limitare i privilegi anche degli account amministratori) e la CVE-2026-45595, un bypass della Mark of the Web, il meccanismo che avvisa gli utenti quando aprono file scaricati da Internet. Entrambi sono vettori tipici delle campagne di installazione di malware tramite file scaricati o phishing. Dall’analisi degli aggiornamenti rilasciati da Microsoft in occasione del Patch Tuesday del mese di giugno 2026 possiamo trarre tre importanti considerazioni. 200 CVE al mese, di cui 33 critiche, non possono essere gestite con un ciclo mensile di test, approvazione e deployment basato su revisione manuale. Le organizzazioni che non hanno ancora automatizzato almeno la fase di deployment delle patch sui sistemi non critici stanno accumulando un debito di sicurezza che si misurerà in incidenti. L’automazione del patch management non è più un’opzione avanzata: è un requisito minimo. Sei zero-day pubblici in due mesi da un singolo ricercatore, con un settimo annunciato. Microsoft ha risposto migliorando il programma bug bounty a maggio, ma evidentemente non in modo sufficiente a placare la situazione. Questa dinamica (ricercatori frustrati che scelgono la divulgazione pubblica come strumento di pressione) è destinata ad aumentare man mano che crescono i sistemi AI che trovano vulnerabilità, abbassando la barriera tecnica per chi vuole fare ricerca. Il settore ha bisogno di standard di disclosure più chiari, processi più trasparenti e meccanismi di risoluzione delle controversie che non si concludano con zero-day su GitHub. YellowKey ricorda una verità fondamentale che il mondo della sicurezza tende a dimenticare nell’era del cloud e della gestione remota: la sicurezza fisica degli endpoint conta ancora enormemente. BitLocker con TPM-only non è una protezione contro un attaccante con accesso fisico al dispositivo, non lo è mai stato del tutto, e YellowKey lo conferma drammaticamente. La risposta è stratificata: TPM+PIN, policy di controllo degli accessi fisici, monitoraggio dei boot da dispositivi USB e, soprattutto, processi di incident response che non presuppongano la totale inviolabilità del full disk encryption come ultima linea di difesa.
cybersecurity360.itJun 10, 2026extracted
Drata brings visibility, control and auditability to enterprise AI agents
Drata brings visibility, control and auditability to enterprise AI agents Drata has introduced AI Agent Governance, a new security category focused on managing the risks and oversight requirements of AI agents, while extending its trust platform to support enterprise adoption of autonomous AI systems. While McKinsey finds 57% of business leaders cite governance friction as the top blocker to deploying more AI, this move is a strategic shift grounded in platform trends Drata is uniquely positioned to observe. Over the last nine months, the company has processed more than 2.1 million security questions through the Drata Trust Graph and seen the frequency of AI-specific questions surge by over 30%. These insights, derived from aggregate platform activity, reveal that questions cluster across five core themes: 1. Which AI agents are running? 2. What are they allowed to do? 3. Who do they run as? 4. Are they behaving as expected? 5. Can you prove all of the above? As AI adoption surges, the diligence required of companies to govern them does as well. Unfortunately, security leaders are unprepared to answer the first four questions, making it nearly impossible to answer the fifth. In fact, a staggering 89% of companies leave questions in that category unanswered. Empowering security leaders to see the agents in their environment, authorize their access, monitor them continuously, and prove their posture is what the new product from Drata is designed to do. “When enterprise customers conducted security reviews in the past, the conversation centered on which frameworks we were certified against, how we managed our security posture, and what our third-party risk profile looked like,” says Nils Puhlmann, co-founder of Cloud Security Alliance and former chief security officer of Twilio, Navan and Zynga. “However, over the past few months, an entirely new category of questions has emerged, focused on which AI agents are running and how they are governed. Answering those questions confidently is impossible with today’s technology; anyone who solves that problem is solving for the future of enterprise trust.” AI Agent Governance from Drata provides enterprise security teams with capabilities for the AI era, all built on the same platform that produces compliance evidence for thousands of audits and enables teams to prove trust externally. Upon integration, Drata’s inline sensors find every agent created by every employee in the environment, including the shadow AI agents no one knew existed, and provide a full inventory in minutes, mapping each one to its owner, identity, permissions, and scope. From there, every action is evaluated against its individual policy in real time, with violations blocked inline before execution and any drift caught and flagged immediately. Every decision is logged in a tamper-evident record, providing a single, verified evidence trail for the board, auditors, customers, and regulators. “Every major technology wave creates a security wave, and the security wave never starts with the platform vendor. Where endpoint created CrowdStrike and cloud created Wiz, we are now in a world where AI agents are creating a technology wave that requires a security layer to support its growth,” said Adam Markowitz, CEO of Drata. “We have spent five years building the trust layer between great companies and helping our customers prove trust faster through agentic workflows. Extending the platform to govern agents themselves is the next required step and Drata is uniquely positioned with the platform data and the policies, controls, risk, monitoring, and remediation actions to do it credibly,” Markowitz concluded.
helpnetsecurity.comJun 10, 2026extracted
VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux systems. The activity has been attributed by Volexity to a threat cluster it tracks as VerdantBamboo, which it said overlaps with hacking groups known as Clay Typhoon (Microsoft), UNC5221 (Google), and Warp Panda (CrowdStrike). The cybersecurity company said it discovered the intrusion during an incident response engagement in September 2025, when it emerged that the adversary had compromised an unnamed victim's Egnyte Storage Sync system by exploiting a local privilege escalation flaw to deploy BRICKSTORM. The issue was addressed in Storage Sync version 13.13, released in March 2026. "The appliance had periodically been accessed by VerdantBamboo via IP addresses assigned through the victim organization's web SSL VPN," researchers Damien Cash, Paul Rascagneres, Steven Adair, and Tom Lancaster said in a technical report published last week. "The threat actor used the malware's proxying capabilities deployed on the Storage Sync system, along with compromised credentials, to access the victim's Microsoft 365 (M365) environment." It's assessed that these steps were undertaken to blend in with legitimate network traffic and evade Conditional Access policies, with the initial compromise occurring at least 18 months before. Following the initial remediation, VerdantBamboo is said to have staged a return, breaching the same organization by using stolen administrative credentials to connect to the firewall, and then abusing that access to configure web SSL VPN access to the device, connect to other systems, and deploy additional malware to a Synology Network Attached Storage (NAS) appliance. Further investigation has since uncovered that the threat actor had in fact compromised the victim organization's Managed Services Provider (MSP), specifically infecting its MSP's pfSense firewall with a BSD variant of BRICKSTORM around the same time the victim's Storage Sync system was also breached. It's believed that the victim was compromised through the threat actor's breach of the MSP. The two malware families deployed to the NAS appliance over SSH are as follows - PLENET (aka GRIMBOLT), a cross-platform backdoor developed in .NET Core and a new version of BRICKSTORM compiled using native ahead-of-time (AOT) compilation. It supports interactive shell, remote command execution, file manipulation, and command-and-control (C2) server switching. AGENTPSD, a Python-based reverse shell that likely functions as a fallback in case the primary implant ceases to function It's worth noting that the use of PLENET in the wild was reported by Google earlier this February in connection with attacks mounted by a suspected China-nexus threat cluster dubbed UNC6201 that exploited a vulnerability in Dell RecoverPoint for Virtual Machines (CVE-2026-22769, CVSS score: 10.0) as a zero-day since mid-2024. "VerdantBamboo is a highly sophisticated threat actor that seeks to leverage a combination of living-off-the-land techniques and malware deployment on systems that traditionally do not or cannot run EDR software," Volexity said. "This threat actor appears to have good knowledge of proprietary appliances, allowing them to deploy malware with customized persistence mechanisms. They also appear to have operational security discipline aimed at leveraging a limited number of domains and IP addresses per victim and setting up customized implant naming and persistence on a per-device basis."
thehackernews.comJun 8, 2026extracted
Quando i sistemi digitali falliscono: il rischio sistemico nell’era delle interdipendenze
Il testo seguente è una rielaborazione divulgativa in italiano dell’editoriale “Systemic Failure” di Roberto Setola, pubblicato sull’International Journal of Critical Infrastructure Protection (IJCIP), volume 53, giugno 2026. Nel maggio 2026 l’Ufficio delle Nazioni Unite per la Riduzione del Rischio di Disastri (UNDRR) ha pubblicato uno studio dedicato agli scenari di guasto su larga scala dei sistemi digitali critici. Il messaggio centrale che emerge dallo studio è che le infrastrutture critiche, e in particolare quelle digitali, non sono esposte soltanto agli attacchi informatici, ma anche agli effetti a cascata provocati da eventi naturali estremi. Lo studio prende in esame tre scenari plausibili. Il primo è una tempesta solare paragonabile all’Evento di Carrington del 1859, che causò gravi interruzioni alle reti telegrafiche dell’epoca. Il secondo riguarda ondate di calore simili a quelle che contribuirono ai grandi blackout verificatisi negli Stati Uniti e in Europa nel 2003. Il terzo considera le conseguenze di un’eruzione vulcanica sottomarina analoga a quella di Hunga Tonga–Hunga Haʻapai del 2022, che lasciò l’arcipelago di Tonga quasi completamente isolato per settimane. Gli incidenti accidentali di origine umana A tali scenari naturali si aggiungono gli incidenti accidentali di origine umana. Un esempio significativo è rappresentato dall’aggiornamento difettoso del sensore Falcon di CrowdStrike nel 2024, che provocò pesanti disservizi nel trasporto aereo e ripercussioni su numerose infrastrutture in diversi Paesi con stimabili fra i 7 ed i 10 miliardi di dollari. Accanto agli eventi accidentali e naturali occorre considerare anche le operazioni cyber malevole che possono generare anch’esse conseguenze economiche estremamente significative. L’attacco NotPetya, ad esempio, colpì aziende globali come Maersk, Merck, FedEx/TNT e Mondelēz, provocando danni stimati superiori a dieci miliardi di dollari. La crescente interconnessione tra cybersecurity e rischi informatici non intenzionali Uno degli aspetti più rilevanti evidenziati dall’analisi è la crescente interconnessione tra cybersecurity e rischi informatici non intenzionali. Un’interruzione fisica può creare vulnerabilità sfruttabili da attori ostili, mentre un attacco informatico può innescare guasti fisici e operativi. La combinazione di queste due dimensioni genera un ulteriore livello di rischio sistemico. In questo contesto si parla di “guasto cyber sistemico”: un evento legato alle tecnologie digitali le cui conseguenze superano le capacità di risposta e recupero di qualsiasi singola organizzazione. Ciò avviene perché gli effetti si estendono su vaste aree geografiche, superano i confini nazionali e coinvolgono centinaia di migliaia di utenti. Secondo l’UNDRR, le infrastrutture digitali sono oggi allo stesso tempo più robuste e più fragili che in passato. Decenni di investimenti in ridondanza, bilanciamento dei carichi e architetture distribuite hanno reso i sistemi molto resistenti ai guasti ordinari e localizzati. Tuttavia, la stessa architettura, caratterizzata da forti interdipendenze e da una continua ricerca dell’efficienza, può favorire la propagazione rapida di uno shock iniziale di grandi dimensioni. Questa considerazione non riguarda soltanto il mondo digitale. Anche le reti elettriche mostrano un comportamento “robusto ma fragile”: normalmente garantiscono elevati livelli di affidabilità, ma restano vulnerabili a blackout di dimensioni eccezionali. Si tratta di una caratteristica tipica dei sistemi complessi che crescono attraverso connessioni sempre più fitte e numerose. Cambiano le dinamiche dei guasti Lo studio sottolinea inoltre il passaggio da una dinamica di guasto additiva a una dinamica esponenziale. Nei modelli tradizionali si assume che due eventi contemporanei producano effetti approssimativamente pari alla somma dei singoli impatti. Nelle infrastrutture digitali altamente interconnesse, invece, gli effetti possono amplificarsi reciprocamente: il guasto di un sistema elimina una ridondanza essenziale per un altro sistema, che a sua volta sovraccarica ulteriori componenti, generando un effetto domino capace di attraversare interi settori economici. A favorire tali dinamiche contribuiscono sia la crescente complessità delle infrastrutture cyber-fisiche sia la presenza di numerosi chokepoints. (“strozzature”) strategici. Questi possono essere geografici, come gli stretti di Hormuz, Suez e Malacca, oppure tecnologici, quando pochi operatori controllano una quota significativa delle piattaforme e dei servizi digitali fondamentali. Come comprendere meglio il rischio sistemico Le conclusioni dello studio risultano particolarmente attuali alla luce delle tensioni geopolitiche e delle difficoltà che interessano le catene globali di approvvigionamento. I modelli oggi utilizzati per valutare gli impatti delle interruzioni appaiono infatti inadeguati quando il livello di interdipendenza tra sistemi è molto elevato. Per comprendere e gestire il rischio sistemico è quindi necessario adottare approcci più realistici, capaci di considerare gli effetti a cascata, le interazioni non lineari, le dipendenze tra settori differenti e la possibilità che i guasti si propaghino ben oltre i confini organizzativi, industriali e nazionali entro cui il rischio viene normalmente valutato. Per approfondire Leggi l’articolo “Systemic failure“.
cybersecitalia.itJun 8, 2026extracted
AI-built ransomware toolkit automates EDR evasion, AD discovery
A threat actor is using an AI-built ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response (EDR) solutions. Tool and payload development was assisted by Cursor and Claude Opus agents in various stages, including initial coding, analysis, and revisioning. Additionally, some agents were tasked with checking security research posts for various bypass techniques. Some of the malware created this way was tested in virtual environments against EDR tools from Sophos, CrowdStrike, and Microsoft. Despite the malware research and development orchestrated using AI technology, the researchers note that the workflow is entirely human-driven. Rapid EDR-bypass development Researchers at cybersecurity company Sophos detected activity from the toolkit on a system at a customer environment that triggered alerts for payloads stored in C:\Users\User\Documents\test. The malicious files suggested they were part of an attack framework that focused on evading detection: Cobalt Strike profiles designed to make beacon traffic resemble legitimate web requests A Telegram bot API–based external command and control (C2) mechanism that routed communication through Telegram’s infrastructure rather than using direct connections Python-based malware development scripts for injecting shellcode into legitimate Windows executables while preserving original functionality A Cloudflare Worker acting as a front-end redirector to obscure the actual backend C2 server The researchers say that while the tool may appear as a “red team” post-exploitation framework, it is used in cybercriminal activity related to ransomware. "Our initial assessment included the possibility that a legitimate Red Team was engaged, but our investigation revealed further artifacts that indicated malicious and criminal activity," Sophos told BleepingComputer. The discovery in Cobalt Strike operator logs of entries pointing to a ransom note and details on multiple organizations listed on a ransomware data leak site clarified that the framework was used for cybercrime operations. Agentic malware development In a report published today, Sophos says that multiple Python scripts on the compromised host were written in Russian and generated with the help of AI tools. During the investigation, the researchers found a Git repository with components related to "an automated Active Directory (AD) discovery panel and a lab that uses an iterative approach to developing and testing malware against the Sophos, CrowdStrike, and Windows Defender endpoint detection and response (EDR) agents." They say that AD discovery is driven by collecting observations from completed tasks and selecting the next action from predefined choices. The next step is delegated to remote agents, with results being reassessed. The framework has multiple AI agents, each with a distinct role and function. For instance, a Claude Opus 4.5 agent acts as the coordinator of the R&D process, while others handle testing, OPSEC hardening, documentation, proxy stress testing, VM deployment, and other related tasks. For the development stage, some agents documented bypass techniques in research from Kaspersky, Palo Alto Networks, Bishop Fox, and SpecterOps, as well as details published in social media posts. The agents extracted the techniques, mapped them to the MITRE ATT&CK knowledge base of adversary behaviors, identified what was needed for reproduction, prepared a test lab, executed the technique, and reported the outcome. The main component in the malicious framework is a Python tool that generates payloads, mostly in Rust and Go, based on an evasion technique. Close to 80 modules were generated and tested against more than 70 techniques. While the agents initially suggested a high failure rate, the modules appeared to bypass almost all EDR solutions after several iterations. However, Sophos noticed discrepancies between the test output and the framework’s internal reporting in some instances, although the reasons are unclear. Sophos found no evidence that AI was embedded in deployed malware or operating independently in victim environments. Instead, the technology was used to accelerate the iterative process of developing, testing, and refining payloads against security products. AI tools are shortening the period between the publication of offensive security research and its practical implementation by threat actors. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 2, 2026extracted
Threat Actor Uses AI to Build EDR Evasion Tools
A threat actor has been observed using AI coding tools to develop and refine malware designed to slip past endpoint detection and response (EDR) software, in what was presented as a red team project. The activity was uncovered by Sophos X-Ops. According to new analysis from its Counter Threat Unit, the activity was discovered after an unusual endpoint in a customer environment raised alerts for malicious files in a local test folder. Those files, alongside a linked Git repository, revealed a lab built to develop evasion tooling and test it against EDR agents from Sophos, CrowdStrike and Microsoft. Many of the Python scripts were partly AI-generated and written in Russian. Humans Stayed in the Loop The most important finding is what the AI did not do. Sophos stressed that the workflow was not run by an autonomously reasoning model, and that no AI was embedded in the malware itself. Instead, AI sped up a structured cycle of building, testing and refining that still relied on human review at each turn. The actor worked inside Cursor, an AI-native development environment, and assigned roles to several agents. One, running on Claude Opus, set the rules for the others, while the rest handled testing, operational security and documentation. A separate playbook tasked them with mining public security research, mapping techniques to the MITRE ATT&CK framework and reproducing them in the lab, with commits flowing back through the Model Context Protocol (MCP). A Red Team Cover Story At the core of the lab was a Python tool that wrapped payloads in layers of encryption and evasion to produce custom loaders, drawing on offensive frameworks such as Cobalt Strike and Sliver. Sophos said nearly 80 modules covering more than 70 techniques were built this way. The agents reported the modules became almost universally effective after iteration, though Sophos noted its documented test output did not clearly support that. Although the project was framed as red teaming, Sophos assessed that the label was likely a cover, used in part to get past Claude's guardrails around malware development. ”In reality, the framework was built for stealthy post-exploitation activity in target environments,” the team said. Sophos also linked the activity to known ransomware and data theft operations. For defenders, the company argued the shift changes little in practice, even as AI lowers the barrier to building such tooling and helps attackers find gaps faster. The team urged organizations to maintain defense-in-depth fundamentals: timely patching, multi-factor authentication (MFA), modern methods such as passkeys, and broad EDR deployment.
infosecurity-magazine.comJun 2, 2026extracted
Sophos uncovers AI-powered malware lab built for EDR evasion
Sophos uncovers AI-powered malware lab built for EDR evasion A threat actor used AI technologies to build a malware-testing framework for developing and refining endpoint detection and response (EDR) evasion techniques, according to Sophos. The investigation began after an anomalous endpoint in a customer environment triggered alerts tied to malicious payloads originating from a testing directory. The files pointed to a broader framework focused on evading detection. The environment contained Cobalt Strike profiles designed to disguise beacon traffic as legitimate web requests, a Telegram-based command-and-control mechanism, shellcode injection tools, and a Cloudflare Worker used to conceal backend infrastructure. Sophos linked the activity to ransomware deployment and data theft operations but did not identify the group involved. “We are not disclosing the ransomware group at this time due to ongoing active investigations related to this threat actor. However, it is a group that is currently active and impacting organisations globally, including in the United States,” Rafe Pilling, Director of Threat Intelligence at Sophos, told Help Net Security. AI-generated scripts and automated discovery Researchers found multiple Python scripts, many of them written in Russian, that appeared to be partially AI-generated, along with a Git repository containing an automated Active Directory discovery panel and a malware-testing lab used to evaluate payloads against Sophos, CrowdStrike, and Microsoft Defender protections. The Active Directory discovery component collected information from completed tasks, selected follow-up actions from predefined workflows, dispatched tasks to remote agents, and reevaluated results as they were returned. While the behavior resembled AI-driven automation, it did not represent an autonomously reasoning LLM. “Artifacts within the Git repository suggest that the threat actor identified potential bypass techniques from research blogs published by organizations such as Kaspersky, Palo Alto Networks, and Bishop Fox,” Sophos researchers wrote. “Information was also sourced from X and Telegram, although it is unclear if these sources influenced the tool development.” Dedicated testing lab The lab consisted of several Windows Server 2022 virtual machines used to test payloads against different EDR products. One system was dedicated to Sophos, another to CrowdStrike, while a third served as a control environment without EDR software installed. A fourth Ubuntu virtual machine hosted a Sliver command-and-control server. Multiple AI agents operated within the framework. A Claude Opus 4.5 agent coordinated activity and set rules for the other agents, while additional agents handled EDR testing, documentation, OPSEC hardening, proxy stress testing, and virtual machine deployment. The setup relied on Model Context Protocol (MCP), an open standard that enables AI assistants to interact with external tools and data sources, connecting the agents to Git repositories. The threat actor used Ludus, a platform for rapidly deploying and managing virtualized security testing environments, to provision the lab infrastructure and relied on Cursor, an AI-native integrated development environment, during the malware development process. The AI agents were tasked with reading security research, extracting attack techniques, mapping them to the MITRE ATT&CK framework, preparing test environments, executing experiments, and reporting the results. The findings suggest the threat actor presented the project as a red-team framework while interacting with Claude. Asked about the use of such framing in attempts to bypass safeguards, Sophos pointed to a broader pattern observed in recent attacks. “Attempts to bypass model safeguards using benign framing for malicious prompts, such as the use of a red team pretext, have been observed in a number of cases over the past year, including in attacks recently reported targeting government entities in Mexico. We have been in touch with Anthropic regarding our observations,” Pilling noted. At the core of the framework was a Python-based payload generation tool that produced custom Windows executables and DLLs, a type of Windows library file that programs can load and execute. The payloads incorporated encryption, evasion, and alternative execution techniques and were then used for testing. Diagram showing AI’s role in the malware development workflow (Source: Sophos) Sophos said the tool supported nearly 80 modules used to test more than 70 evasion techniques. Questions over reported success rates Documentation generated within the framework suggested the evasion modules became increasingly successful after repeated testing and refinement. However, the available test data reviewed during the investigation did not support those claims. “We don’t have the data to fully account for the discrepancies, but it’s likely that common large language model issues, such as hallucinations, played a role in the differences observed,” Pilling concluded. Despite the use of AI agents, Sophos said the defensive fundamentals remain unchanged, including patching, MFA, passkeys, and endpoint protection.
helpnetsecurity.comJun 2, 2026extracted
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. "This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential downstream propagation," Socket said. Exactly who is behind the attack activity is presently unknown given that TeamPCP (aka Replicating Marauder, TGR-CRI-1135, and UNC6780), an infamous cybercrime group, has open-sourced the attack tools linked to the Shai-Hulud worm, opening the door for other threat actors to pull off similar attacks and making definitive attribution harder. The names of some of the affected packages are listed below - @redhat-cloud-services/vulnerabilities-client @redhat-cloud-services/tsc-transform-imports @redhat-cloud-services/topological-inventory-client @redhat-cloud-services/sources-client @redhat-cloud-services/rule-components @redhat-cloud-services/remediations-client @redhat-cloud-services/rbac-client Per analyses from Aikido Security, JFrog, Microsoft, OX Security, ReversingLabs, SafeDep, StepSecurity, and Wiz, the npm packages contain an obfuscated preinstall hook that's designed to collect GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault material, SSH keys, Git credentials, and other sensitive files. Like observed in prior Mini Shai-Hulud waves, the malware also contains encrypted exfiltration logic that transmits the data to "api.anthropic[.]com:443/v1/api" and uses GitHub as a fallback mechanism. This indicates attempts made by the attacker to both steal credentials and weaponize them to further poison the software supply chain. "It commits the encrypted result envelope through the GitHub API," Socket said. "The commit message can include: IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner: ." Another noteworthy step carried out by the malware is to avoid execution on Russian-language systems, a pattern also observed in the GlassWorm supply chain campaigns. "For npm, the payload calls the OIDC token exchange and whoami endpoints, repackages a tarball (updateTarball, package-updated.tgz), and signs the artifact through Sigstore," SafeDep said. "Stolen credentials exfiltrate to attacker-created public GitHub repositories, each carrying the description Miasma: The Spreading Blight." The first commit containing the "Miasma: The Spreading Blight" string appeared on May 29, 2026, OX Security noted, indicating that either this variant was active since then, or the threat actor started testing around that time. As for GitHub, the malware enumerates repositories the token can write to, reads action.yml/action.yaml via GraphQL, and commits a workflow through the createCommitOnBranch mutation so that the commit appears as a verified, signed change. Other actions carried out by the malware are listed below - Attempt privilege escalation by launching a container that bind-mounts the host /etc/sudoers.d and grants the CI runner passwordless sudo Check for endpoint protection from CrowdStrike, SentinelOne, Carbon Black, and StepSecurity Harden-Runner before commencing the malicious actions Establish persistence by injecting a SessionStart hook to Anthropic Claude Code and a tasks.json with "runOn": "folderOpen" for Microsoft Visual Studio Code projects so that the malware is automatically launched during every session "One of the main changes in this new variant is the addition of new data collectors focused on cloud identities," Wiz researchers said. "Specifically, collectors for GCP and Azure identities were added that collect all identities the infected machine has access to. While previous versions of the malware primarily focused on extracting secrets from these environments, this variant suggests an increased attacker focus on gaining and leveraging access to the cloud itself. Unlike previous versions, the malware has also been found to generate a uniquely encrypted payload for each infection, thereby making detection and version tracking significantly more challenging. Evidence suggests that the compromise of a Red Hat employee's GitHub account was the patient zero that was used to inject the payload into these packages. The compromised account is said to have pushed malicious orphan commits to two RedHatInsights repositories, bypassing code review. It's recommended to isolate hosts that have installed the affected versions, remove the malicious versions, rotate exposed credentials, review for any signs of suspicious GitHub or npm activity, audit the environment for persistence artifacts that involve changes to configuration files (~/.claude/settings.json, .vscode/tasks.json, .github/workflows/codeql.yml, .github/setup.js), and enforce strong access controls. "Because the malware includes background execution and potential developer-tool persistence mechanisms, uninstalling the npm package or deleting node_modules should not be considered sufficient cleanup," Socket explained. "For CI/CD systems, suspend affected workflow runs, invalidate build artifacts produced during the exposure window, and review whether any release, container image, npm package, or deployment artifact was created after the malicious package was installed." Update Dark web monitoring and threat intelligence firm Whiteintel said it "detected a Red Hat GitHub credential and session cookie in infostealer logs on April 13 and May 15, 2026," raising the possibility that this information may have been used to break into the employee's account. The development is the latest in a number of supply chain attacks that have targeted the open-source ecosystems over the past couple of months. These attacks have impacted well-known projects, including Aqua Trivy, Checkmarx KICS, Bitwarden, SAP, TanStack, and GitHub, and Nx Console. Last month, a separate campaign codenamed Megalodon was found to have injected malicious GitHub Action workflows to harvest CI/CD secrets, cloud credentials, and tokens, impacting both development and deployment pipelines in public GitHub repositories. "These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the 'Megalodon' supply chain intrusion campaign, demonstrate how cyber threat actors are abusing tools and processes that support enterprise, cloud, and DevOps environments - specifically CI/CD pipelines, code extensions and workflows," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said.
thehackernews.comJun 1, 2026extracted
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought 'curl | sh' had a personality. The vibe is simple: old bugs, new wrappers, faster abuse. Patch the obvious crap first. Then read the rest. ⚡ Threat of the Week PAN-OS GlobalProtect Authentication Bypass Under Exploitation - Palo Alto Networks warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections. The issue specifically affects firewalls with GlobalProtect portal or gateway configured when authentication override cookies are enabled and a specific certificate configuration exists, the network security company said. Securing AI Use Within Your Organization Starts Here The risks of ungoverned AI within your organization are compounding at machine speed. Turn your AI security priorities into actionable steps with this step-by-step guide. Download Now ➝ 🔔 Top News Critical Unpatched Flaw in Gogs - The popular open-source self-hosted Git service Gogs is affected by a critical-severity zero-day vulnerability that exposes servers to remote code execution (RCE), per Rapid7. The injection flaw can be exploited by authenticated attackers via pull requests with malicious branch names. "Since Gogs ships with open registration enabled by default and no limit on repository creation, an unauthenticated attacker can simply create an account and repository on any default-configured instance," the cybersecurity firm says. Any repository owner can enable rebase merging with a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user. Attackers with write access to repositories that have rebase enabled can exploit the flaw directly. "The result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users' private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository's code," Rapid7 said. Gogs servers across Windows, Linux, and macOS that are running default configurations are affected. No patch has been released as of the time of publishing. GlassWorm C2 Taken Down - CrowdStrike, Google, and the Shadowserver Foundation dismantled the GlassWorm malware operation by taking down all four of GlassWorm's command-and-control (C2) channels simultaneously on May 26, 2026, at 2 p.m. UTC. GlassWorm, since its emergence last year, has conducted a "multi-pronged campaign" using trojanized VS Code extensions published on both the Microsoft VS Code Marketplace and Open VSX. The campaign is also known to have introduced malicious code through compromised npm and Python packages. By taking down all four channels at the same time, the action severed the operators' access to the infected hosts and their ability to deliver new commands. Evidence suggests that GlassWorm's operators are of Russian origin: the malware checks the system's locale and avoids infecting machines in CIS countries, and its code contains Russian-language comments. In addition to taking down the GlassWorm infrastructure, CrowdStrike has instructed the infected endpoints to beacon to the benign IP address 164.92.88[.]210. Organizations are advised to check for connections to this IP address to identify potential infections. Despite these efforts, the broader economics of repository abuse remain an ongoing issue. Open-source ecosystems continue to offer attackers low-cost distribution channels with a massive reach when compared to traditional software. This also means operators behind such campaigns can resurface under new accounts, domains, or package names. In other words, it's only a temporary disruption, not eradication. CERT-In Urges Organizations to Patch Exploited Flaws Within 12 Hours - Organizations in India have been urged to patch actively exploited vulnerabilities impacting internet-facing or "crown jewel" systems within 12 hours, where feasible, so as to better respond to the speed artificial intelligence (AI) now brings to cyber attacks. CERT-In stopped short of framing the timelines as binding, describing them as indicative expectations to be applied according to operational criticality and threat exposure. The agency also warned that AI-assisted attacks are dramatically compressing the time between vulnerability disclosure and exploitation. The framework also recommends one-day remediation for critical externally exposed vulnerabilities, three days for critical internal vulnerabilities affecting high-value systems, and five days for high-severity flaws based on risk prioritization. GREYVIBE Leans on AI for Ukraine Attacks - A previously undocumented Russian group codenamed GREYVIBE has been found to make extensive use of large language models (LLMs) in its attacks against private, government, and military organizations in Ukraine. The end goal is to gather intelligence for the ongoing war. "While the activities align with Russian state interests, several observed indicators suggest the group has ties to the broader cybercrime ecosystem, with the group potentially involving current or former cybercriminal actors," WithSecure said. The threat actor is believed to have been active since August 2025. What's notable is the extent to which AI appears to be enmeshed throughout the operation. The group's use of AI is believed to be "operationally integrated rather than isolated or experimental." AI Chatbot Recommendations Redirect Users to Cryptojacking Malware - A new campaign is using searches for popular tools in AI chatbots to redirect users to sketchy sites that trick users into downloading booby-trapped executables that drop a cryptocurrency miner on compromised hosts. The goals of the campaign are not merely financially motivated. The threat actors have also been found to establish persistent remote access to compromised hosts through ScreenConnect deployments, which could then be leveraged for follow-on activity, such as data theft, lateral movement, or ransomware. 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-8732 (WP Maps Pro plugin), CVE-2026-0257 (Palo Alto Networks PAN-OS and Prisma Access), CVE-2026-27771 (Gitea), CVE-2026-45659 (Microsoft SharePoint), from CVE-2026-9090 through CVE-2026-9098 (Casdoor), CVE-2026-48800, CVE-2026-48778, CVE-2026-48770 (Notepad++), CVE-2026-40933 (Flowise), from CVE-2026-9872 through CVE-2026-9893 (Google Chrome), CVE-2026-32996, CVE-2026-32997 (Veeam Backup & Replication), CVE-2026-44962 (Plesk), CVE-2026-4868, CVE-2026-1402, CVE-2026-6713 (GitLab), CVE-2026-46840, CVE-2026-46775, CVE-2026-46839, CVE-2026-2332 (Oracle), CVE-2026-4480 (Samba), CVE-2025-59199 aka Click Or Trick (Microsoft Windows 11), CVE-2026-9560 (OpenVPN Connect for macOS), CVE-2026-9312 (GitHub Enterprise Server), CVE-2026-3593, CVE-2026-5946, CVE-2026-5947 (BIND 9), CVE-2026-47783 (Memcached), CVE-2026-44930 (Apache CXF), CVE-2026-9089 (ConnectWise Automate), CVE-2026-4115 (PuTTY), CVE-2026-48095 (7-Zip), an argument injection vulnerability in Gogs, a remote code execution vulnerability in Microsoft Visual Studio Code Remote-SSH extension, and multiple vulnerabilities in Roundcube Webmail. 🎥 Cybersecurity Webinars Beyond Zero-Day: How Attackers Actually See Your Network → Zero-days are inevitable. The real battle is what attackers see once they're inside. Join HD Moore (creator of Metasploit) in this webinar as he reveals how to map your network like an attacker - exposing hidden assets, forgotten bridges, and dangerous IT/IoT/OT connections most teams miss. Why Automated Pentesting Falls Short - And How to Fix It → Automated pentesting tools promised comprehensive security validation, but in reality, they only scratch the surface. After a few runs, new findings drop sharply, leaving critical blind spots in detection, response, and control effectiveness. Join Autumn Stambaugh and Can Yüceel of Picus Security as they explain why automated pentesting alone isn't enough - and how to build a complete validation program that actually closes the gaps. 📰 Around the Cyber World New Windows Flaw Under Attack - Belgium's Centre for Cybersecurity (CCB) has warned that a recently patched Windows flaw, CVE-2026-41089, has come under active exploitation in the wild. The vulnerability is a stack-based buffer overflow in Windows Netlogon that allows an unauthorized attacker to execute code over a network. There are currently no details on how the vulnerability is being exploited. The vulnerability was addressed by Microsoft as part of its May 2026 Patch Tuesday update. Anthropic Confirms Mythos Release - Anthropic has confirmed it intends to bring Mythos-class models to "all our customers in the coming weeks" and said it's "making swift progress" on developing stronger cyber safeguards prior to their release. New Linux Flaw CIFSwitch Uncovered - A newly disclosed Linux local privilege escalation (LPE) vulnerability dubbed CIFSwitch has been found to enable low-privileged users to gain root access by abusing a logic flaw between the Linux kernel Common Internet File System (CIFS) client and the userspace helper package, cifs-utils. According to SpaceX security engineer Asim Viladi Oglu Manizada, the kernel-side bug has been around since 2007. A patch for the flaw has been pushed to mainline Linux as of May 19, 2026. Dashlane Warns of Brute-Force Attack - Dashlane said: "user accounts were targeted in a brute force attack by an external party, resulting in the suspension of those accounts as part of Dashlane's built-in security measures." The affected accounts have since been unsuspended. The password management company also noted that it's taking measures to address the issue, adding that there is no evidence of compromise of Dashlane's systems. It's not known who is behind the attack. Global Smishing Operation Impacts 19 Countries - Hunt.io said it identified a coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus. "The same infrastructure hitting Romanian taxpayers was also targeting DPD delivery customers in the U.K. and Ireland, road police portals in Bulgaria and Armenia, tax authorities in Greece, and T-Mobile users in the United States," the company said. "1,628 malicious URLs confirmed active across 19 countries and multiple sectors." The campaigns are designed to invoke a false sense of emergency using fabricated fines and trick users into making payments and entering their personal information. Microsoft Teams and Google Drive Abused to Deliver Java RAT - An intrusion targeting a customer in the legal industry involved the use of Microsoft Teams voice phishing to deceive the victim into granting remote access via Quick Assist. It was followed by the deployment of a Java-based remote access trojan (RAT) named Nimbus RAT. "Nimbus RAT is a self-contained implant that uses Google Drive and Google Sheets for command-and-control (C2), helping its network traffic appear benign," eSentire said. "From initial Teams contact to RAT execution, the attack took less than 20 minutes." The activity overlaps with similar Teams-based social engineering attacks carried out by BlackSuit affiliates. Tracking Site Visitors Via FROST - New research has shown that malicious websites can track visitors by measuring tiny changes in SSD access times as a side channel, turning normal browser activity into a privacy leak. The attack, named FROST (short for Fingerprinting Remotely using OPFS-based SSD Timing), is a "side-channel attack from JavaScript that exploits OPFS [Origin Private File System] to leak sensitive information from the browser without requiring any user interaction on both Linux and macOS." The attack "uses SSD contention measurements from within the browser to fingerprint user activity on a system," a group of academics from the Graz University of Technology and Liebherr-Transportation Systems GmbH said. "After tricking the victim into clicking a malicious link, an attacker can monitor the victim's activity on the host system, such as website visits and application usage, without further user interaction." The impact of the attack goes beyond website tracking. The study also demonstrated that it's possible to fingerprint application usage, allowing attackers to potentially infer where specific apps were opened. Instagram Exploit Allegedly Enabled Account Takeover - According to Dark Web Informer and ZachXBT, Instagram is said to have suffered from an exploit that made it possible to use Meta AI to reset passwords to accounts with no multi-factor authentication (MFA) enabled. To pull off the attack, bad actors simply had to use a VPN to approximately match their location to the target Instagram account's region, begin the password reset process, and then prompt Meta's AI support chatbot to change the email address associated with the account. The end goal of the attack appears to link the target account with a new email address using the Meta AI chatbot, seize control of high-profile Instagram profiles, and sell them on the gray market for thousands of dollars. According to a report from 404 Media, bad actors have been aware of the loophole since March 2026. The exploit has since been patched, though it's unclear how many accounts were impacted by the exploit. The incident highlights the dangers of granting AI agents overly broad permissions that could be abused to trigger unintended actions without any human confirmation. EvilTokens Abuses OAuth Flow, RatPressto Kit Surfaces - The phishing-as-a-service (PhaaS) platform known as EvilTokens is being used to carry out device code phishing attacks at scale. "These campaigns are notable for abusing the OAuth 2.0 device authorization flow, automating this sophisticated phishing at scale, and using AI to produce realistic, quickly deployable attack infrastructure," Netcraft said. The company said it has seen thousands of attacks using the EvilTokens phishing kit. The development coincides with the emergence of a new phishing toolkit dubbed RatPressto that's being used in an active campaign. The kit, hosted on legitimate-but-compromised WordPress sites, is used to serve ScreenConnect for establishing persistent remote access. "RatPressto has been observed targeting financial organizations, looking to silently exfiltrate credentials, secrets, and sensitive data that could be used to aid further compromise," Fortra said. Solo Russian-Speaking Threat Actor Linked to Patriot Bait Campaign - A solo Russian-speaking threat actor tracked as "bandcampro" ran a 5-year MAGA-themed Telegram channel (@americanpatriotus, approximately 17,000 subscribers) and pivoted to AI-automated content, fraud, and credential theft starting September 2025. "A jailbroken Google Gemini served as the actor's co-worker, generating Q-styled posts, deploying infrastructure, rotating stolen API keys, modeling victim passwords, and running a QAnon-styled chatbot (QFS 2.0 Terminal)," Trend Micro said. "Safeguards were bypassed via jailbreaking and non-English prompting, allowing explicit pump-and-dump prompts and instructions to mutate victim passwords to be processed, showing how frontier-AI safety controls can be circumvented through jailbreaks and non-English prompting." The campaign once again highlights how AI has significantly cut down the resources needed to run influence operations. SonicWall Scanning Spike Recorded - GreyNoise said it observed a "significant new spike in scanning of SonicWall SonicOS management interfaces" between May 9 and May 18, 2026. "Approximately 56% of sessions originate from networks announced in the Netherlands and 44% in Ukraine - together more than 99% of total volume," it said. "A single ASN (AS211736) carries roughly half of the total session volume." New Payload Ransomware Emerges - Cybersecurity researchers have analyzed ransomware families like NightSpire and Payload, with the latter already racking up 50 victims on its leak site since emerging in February 2026. "Although the group initially claimed only a limited number of victims, its operations quickly showed a global footprint, with targets across Egypt, Mexico, and Poland," Dark Atlas said. 🔧 Cybersecurity Tools EvidenceForge → It is an open-source tool from Cisco Talos that generates realistic, multi-format synthetic security logs - including Windows events, Sysmon, Zeek, and more - with strong consistency and causal relationships. It's particularly useful for threat hunting training, detection testing, and research where you need high-quality, non-obvious synthetic data. MCPGuard-Dynamic → It is an open-source project from Facebook that provides kernel-level sandboxing for LLM agent tool calls using the Model Context Protocol (MCP). It combines policy enforcement, argument validation, and eBPF-based system call guards to restrict what potentially untrusted MCP servers can do - helping prevent file access, network exfiltration, and privilege escalation attempts. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law. Conclusion That's the week: too much speed, too many defaults, and not enough people treating "minor" exposed crap like it can become tomorrow's incident report. The pattern is boring until it's your box - attackers keep finding the cheap paths first, because cheap still works. Patch the loud stuff, audit the weird stuff, and don't ignore the boring stuff. That's usually where the fire starts.
thehackernews.comJun 1, 2026extracted
Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels
The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026. "Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fake Webex meeting page that leveraged a legitimate meeting schedule," ENKI said in an analysis published this week. The attacks have been found to deliver a variant of a known malware family dubbed HTTPSpy by disguising it as installers from South Korean security software, a tactic the threat actor has consistently adopted since 2023. In the latest campaign observed in March 2026, the adversary has been found to propagate malicious payloads through a bogus web page impersonating the security software installation page of a South Korean B2B messaging service. Given the nature of the lure, it's suspected that the activity may have been specifically designed to single out messaging administrators within corporate environments. The page claims to offer two security tools: a firewall and a keyboard security program. Once unsuspecting users initiate the download, it results in the download of either of the two executables - "nos-setup.exe" and "astx-setup.exe" - that masquerade as nProtect Online Security and AhnLab Safe Transaction (ASTx). Despite the differences in the name, the malicious behavior embedded in them is identical. The primary responsibility of the binaries is to launch a second-stage DLL payload ("MemLoader.dll") via "regsvr32.exe," after which a batch script is run to delete themselves from disk. The DLL establishes persistence on the host using a scheduled task and contacts a command-and-control (C2) server to retrieve an as-yet-unknown payload. "The attacker likely monitored the recurring GET requests from the malware and selectively delivered payloads to specific victims," ENKI said. In another campaign observed in April 2026, a counterfeit web page mimicking Cisco Webex is said to have been used to display a pop-up message urging the victim to download and run a script to address issues with accessing the camera. Doing so results in the retrieval of a ZIP archive containing an encrypted JavaScript (JSE) file ("fix-camera.jse"). The execution of the JSE file results in the deployment of an intermediate downloader ("mTSTCv8.mdxm") using PowerShell, which then runs anti-analysis checks and contacts a C2 server to fetch the next-stage malware ("engine.dat" or "spyInster.dll"). In the final stage, the DLL drops a loader component ("cacheMon.dat") that, in turn, executes HTTPSpy on the compromised system. HTTPSpy is a full-featured remote access trojan that supports a wide range of capabilities to run shell commands, upload/download files, execute processes, capture screenshots, inject DLL paths into specified PID processes, and erase itself from the endpoint. This is not the first time Kimsuky has deployed HTTPSpy. In its 2025 European Threat Landscape Report, CrowdStrike said the hacking group likely targeted a German defense manufacturer's employees via a credential phishing campaign deploying the malware between May 2024 and at least September 2024. The first use of HTTPSpy dates back to 2022. Simultaneously, the malware also drops and opens an HTML file named "meeting.html," which immediately redirects the victim to a Webex meeting room. Accessing the URL opens a legitimate Webex meeting room associated with an actual scheduled event that took place around the same time. "This indicates that the attacker likely compromised a service member's device or account to obtain the meeting schedule, then crafted a fake meeting page to distribute malware to the other attendees," the cybersecurity company said. ENKI said it also discovered additional fake web pages that query a local server set up by the malware on the victim's machine via JSONP (JSON with Padding) to verify malware execution status and display an installation prompt if it's not running. The technique has been codenamed JSONPing. However, the exact nature of the downloaded malware remains unknown as the URL is currently inactive. "Kimsuky went beyond simple malware distribution, introducing sophisticated mechanisms to maximize delivery success, including real-time infection verification via JSONPing and crafting a fake page using a stolen meeting schedule," ENKI said. Kimsuky Evolves with HelloDoor and HttpMalice The disclosure comes as Kaspersky detailed the threat actor's use of Microsoft Visual Studio Code (VS Code) tunneling, Cloudflare Quick Tunnels, DWAgent, large language models (LLMs), and the Rust programming language in its latest campaigns, highlighting its continued adaptation and evolution. "Specifically, Kimsuky leveraged legitimate VS Code tunneling mechanisms to establish persistence and distributed the open-source DWAgent remote monitoring and management tool for post-exploitation activities," the Russian cybersecurity company said. "These activities affected various sectors in South Korea, impacting both public and private entities." Attack chains have been found to rely on a variety of droppers written in JSE, PIF, SCR, and EXE to deliver two broad malware families: PebbleDash and AppleSeed. While PebbleDash attacks have also been recorded against defense organizations in Brazil and Germany, the AppleSeed cluster has mainly targeted government organizations. Some of the key malware families delivered by the droppers are as follows - HelloDoor, a Rust-based PebbleDash variant first identified in August 2025 and likely developed using an LLM. It supports basic functionality to set the current directory, sleep for a specific time interval, and run commands. HttpMalice, the latest backdoor variant of PebbleDash, emerged no later than December 2025. It comes with capabilities to gather information about the compromised system, set up persistence, perform reconnaissance using native Windows commands, capture screenshots, load downloaded payloads into memory, run commands, and exfiltrate the execution output. HttpTroy, a backdoor delivered via a loader named MemLoad that allows file upload/download, screenshot capture, command execution, in-memory loading of executables, reverse shell, process termination, and trace removal. AppleSeed, which comes in two variants: Dropper and Spy. The Dropper is responsible for downloading additional malware and executing commands received from its C2 server. The Spy version gathers sensitive information such as documents, screenshots, keystrokes, and lists of USB drives. This also includes harvesting data from the C:\GPKI directory, mirroring a similar feature implemented in Troll Stealer. HappyDoor, an advanced version of AppleSeed that first surfaced in 2021. Another notable tactical shift involves the abuse of the legitimate VS Code Remote Tunneling feature to establish covert remote access to the victim's device, thereby eliminating the need for traditional malware-based C2 channels. This approach has also been highlighted by Darktrace and Logpresso. "Our analysis shows that the actor retains access to the original source code of the malware clusters and the ability to modify it," Kaspersky researcher Sojun Ryu said. "Two clusters have overlapping target sectors that span the defense, military, government, medical, machinery, and energy industries." "The AppleSeed cluster is shifting its focus to data exfiltration, and GPKI certificate extraction has become a signature capability. Meanwhile, the PebbleDash cluster demonstrates advanced remote control capabilities and an expanding set of targets."
thehackernews.comMay 29, 2026extracted
CrowdStrike, Google shatter Glassworm botnet
ai and ML AI slop is good for business if you know what you're doingYour irresponsibility is someone else's opportunity SAAS Salesforce partners not seeing meaningful revenue from Agentforce AI platform, report saysShow us the money ai and ml AI companies are burning books, advocates complain to FTCFahrenheit 203, the temperature GPUs stop gorging on literature DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comMay 27, 2026extracted
CrowdStrike, Google Take Down Glassworm Botnet
An industry effort involving CrowdStrike, Google and the Shadowserver Foundation has led to the disruption of the Glassworm botnet. Working together, the three organizations managed to simultaneously take down all four of Glassworm's command-and-control (C2) channels, severing the operators from their infected machines and their ability to deliver new malicious payloads. These channels included traditional C2 servers hosted on commercial virtual private servers (VPS). The botnet also relied on less common and more stealthy assets, such as Google Calendar event titles which were used as dead-drop locations for Base64-encoded C2 paths, peer-to-peer networks and blockchain-based infrastructure, notably with C2 server addresses encoded in the memo fields of transactions on the Solana blockchain. The Glassworm remote access tool queried the BitTorrent peer-to-peer network for configuration data stored against hardcoded public keys. “The combination of blockchain, peer-to-peer, and legitimate web services as resolution layers was designed to be resilient against takedowns — a dynamic front protecting the actual C2 servers behind multiple layers of indirection,” CrowdStrike noted in a report published on May 26. This is why the threat hunters had to disrupt all channels simultaneously. “Taking down only one channel would have left the others operational, allowing the operators to quickly reconstitute,” CrowdStrike added. Glassworm Tied to Poisonous VS Code Extensions, Npm and Python Packages A household name in open-source software supply chain attacks, Glassworm has been a network of devices controlled by malicious operators since at least early 2025. It had been used in several multi-pronged malicious campaigns targeting software developers by poisoning open-source packages they rely upon across Windows, macOS and Linux systems. Some of the activities linked to Glassworm included trojanized extensions of Microsoft Visual Studio Code (VS Code), published to the OpenVSX marketplace, compromised npm and Python packages introducing malicious code through postinstall hooks and setup scripts and More than 300 GitHub repositories were poisoned using stolen developer credentials harvested from earlier Glassworm infections, CrowdStrike added. The company highlighted that Glassworm “marked a significant shift in the threat landscape” that should “serve as a wake-up call for every organization that ships or consumes software.” “Adversaries are no longer just targeting products, they're targeting the developers who build them. The barrier to poisoning a package or extension is low; the potential blast radius is enormous. As long as developer environments, build pipelines, and code repositories remain under-protected, every organization that consumes software inherits the risk of everyone who produces it,” CrowdStrike threat hunters warned.
infosecurity-magazine.comMay 27, 2026extracted
Glassworm botnet disrupted after resilient C2 infrastructure takedown
The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network. In a coordinated operation conducted yesterday, CrowdStrike, Google, and The Shadowserver Foundation cut off the botnet operators’ access to four distinct command-and-control (C2) channels designed to resist conventional disruption efforts. Glassworm campaigns have been ongoing since October 2025 and initially targeted developers with malicious OpenVSX and Microsoft VS Code extensions that stole cryptocurrency wallets and developer credentials. Later attack waves extended to GitHub repositories and npm packages, with one campaign in March impacting more than 400 software artifacts. In a more recent attack, Glassworm operators planted dozens of dormant extensions on OpenVSX that would activate the malicious component after an update. One reason the Glassworm threat has survived this long is its C2 infrastructure, which relies on non-traditional communication channels that are difficult to take down. “The combination of blockchain, peer-to-peer, and legitimate web services as resolution layers was designed to be resilient against takedowns — a dynamic front protecting the actual C2 servers behind multiple layers of indirection,” CrowdStrike notes. The researchers say that “Glassworm's operators built their infrastructure for resilience,” and taking down the botnet required hitting the four C2 channels simultaneously: Solana blockchain: C2 server addresses are encoded in the memo fields of blockchain transactions, creating an immutable, publicly accessible dead drop that cannot be taken offline by conventional means. BitTorrent Distributed Hash Table (DHT): The GlasswormRAT queries the BitTorrent peer-to-peer network for configuration data stored against hardcoded public keys, leveraging a global decentralized network with no single point of failure. Public calendar service: Glassworm uses Google Calendar event titles as dead-drop locations for Base64-encoded C2 paths. Direct server connections: Traditional C2 infrastructure hosted on commercial VPS providers served as the final payload delivery mechanism. Because of this architecture, disrupting a single channel would have little impact on the Glassworm operation, as communications could shift to another channel, allowing the threat actor to maintain control. “All four channels had to be disrupted simultaneously in a coordinated effort. As a result, infected machines can no longer receive new instructions or payloads,” CrowdStrike says. Following the disruption, all machines compromised in a Glassworm attack are beaconing to the IP address 164.92.88[.]210 operated by CrowdStrike. Organizations are advised to look for this network indicator and take immediate remediation action. Additionally, the researchers have published YARA rules to confirm infections on suspected hosts. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 27, 2026extracted
GlassWorm Botnet Disrupted
The GlassWorm botnet that has been targeting the open source software ecosystem for over six months has been disrupted, cybersecurity firm CrowdStrike reports. Together with Google and the Shadowserver Foundation, CrowdStrike took down GlassWorm’s four command-and-control (C&C) channels simultaneously, preventing access to the infected machines and the delivery of fresh payloads. The malware has been using the Solana blockchain for C&C infrastructure, with Google Calendar, the BitTorrent peer-to-peer network, and traditional servers hosted on commercial VPS providers serving as backup C&Cs. GlassWorm’s operators have been encoding C&C addresses in the memo fields of blockchain transactions, which cannot be modified or deleted. The BitTorrent network was used to store configuration data against hardcoded public keys, Google Calendar was used to store Base64-encoded C&C paths in event titles, and the traditional C&C servers were used to host payloads. “The combination of blockchain, peer-to-peer, and legitimate web services as resolution layers was designed to be resilient against takedowns — a dynamic front protecting the actual C&C servers behind multiple layers of indirection,” CrowdStrike notes. By taking down all four channels at the same time, the cybersecurity firms severed the operators’ access to the infected machines and their ability to deliver new instructions. First spotted in October 2025, GlassWorm has been relying on Unicode variation selectors to hide its code in code editors and make it invisible to the human eye. The self-propagating malware was initially distributed via trojanized Visual Studio extensions via the OpenVSX marketplace. In November, however, it also emerged on GitHub. In 2026, GlassWorm attacks continued to target VS developers and other open source software ecosystems. In March, multiple Python projects were compromised. “The operators behind Glassworm are well-resourced and persistent. Over the course of more than a year, they continuously evolved: adopting new programming languages (from JavaScript to Rust to Zig), expanding across package ecosystems (VSCode, npm, PyPI, GitHub), and building redundant infrastructure designed to survive takedown attempts,” CrowdStrike says. GlassWorm is designed to steal sensitive information (such as NPM, GitHub, and Git credentials) and funds from dozens of cryptocurrency extensions. It also deploys SOCKS proxy servers and hidden VNC servers for remote access to the infected machines. The attackers’ access to stolen credentials created an ongoing risk of high-impact supply chain compromises beyond the victim developers. All consumers of potentially impacted software, including enterprises and other types of organizations, were also exposed to compromise. According to CrowdStrike, evidence suggests that GlassWorm’s operators are of Russian origin: the malware checks the system’s locale and avoids infecting machines in CIS countries, and its code contains Russian-language comments. “This takedown matters beyond the botnet. Glassworm marked a significant shift in the threat landscape that should serve as a wake-up call for every organization that ships or consumes software. Adversaries are no longer just targeting products, they’re targeting the developers who build them,” CrowdStrike notes. In addition to taking down the GlassWorm infrastructure, CrowdStrike has instructed the infected machines to beacon to the benign IP address 164.92.88[.]210. Organizations are advised to check for connections to this IP address to identify potential infections. “As long as developer environments, build pipelines, and code repositories remain under-protected, every organization that consumes software inherits the risk of everyone who produces it. Glassworm demonstrates that attackers know this and are investing in resilient infrastructure to maintain persistent access to developer ecosystems,” CrowdStrike notes. Related: ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested Related: Microsoft Disrupts Malware-Signing Service Run by ‘Fox Tempest’ Related: Tycoon 2FA Fully Operational Despite Law Enforcement Takedown
securityweek.comMay 27, 2026extracted
Anthropic: Claude Mythos identified 10,000+ software flaws
Anthropic: Claude Mythos identified 10,000+ software flaws Anthropic and its Project Glasswing partners have identified more than 10,000 high- or critical-severity vulnerabilities in critical software systems, the company announced in an update on the project’s progress. Mythos identifies thousands of high-severity vulnerabilities In April 2026, Anthropic introduced Claude Mythos Preview, a new large language model that can autonomously find zero-day vulnerabilities and create exploits for them. The company also launched Project Glasswing and gave Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks, and other partners in the open source community access to the LLM, to help them secure critical software before AI systems can be used to target it. Since then, with Mythos’ help, several companies, including Cloudflare and Mozilla, have discovered hundreds of vulnerabilities in their codebases. Anthropic has also scanned more than 1,000 open-source projects with Mythos, and has identified 23,019 issues, of which 6,202 were high- or critical-severity vulnerabilities. The company and six independent security research firms have assessed 1,752 of those high- or critical-severity findings, and more than 90% were validated as true positives, the company added. Anthropic’s dashboard of open-source vulnerabilities, showing vulnerabilities of all severities Patching becomes the bottleneck More disclosures of vulnerabilities unearthed with Mythos’ help are yet to come, as the project was started just a couple of months ago and the coordinated vulnerability disclosure process typically takes time. (Newly discovered flaws are kept private, usually for 90 days or until patches are available, before being made public.) For example, Mythos identified a vulnerability in wolfSSL, an open-source cryptography library used by billions of devices, and constructed an exploit that would let an attacker forge certificates that would allow them to host a fake website for a bank or email provider. The vulnerability has been patched, but technical details are still under wraps. Anthropic says that even though they made sure to deliver detailed vulnerability reports to open source maintainers, the latter have become a major bottleneck in the AI-driven vulnerability discovery process. “The relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity,” the company said. Plans for the future To help open source maintainers process and triage bug reports, Anthropic partnered with the Open Source Security Foundation’s Alpha-Omega project. To make vulnerability discovery and patching easier, Anthropic released Claude Security in public beta for Claude Enterprise customers. Its Cyber Verification Program allows approved security professionals to use its models for legitimate cybersecurity work with fewer restrictions, Anthropic noted, and said it is also making tools used with Mythos Preview available to qualifying security teams. These include custom skills, an automated scanning and reporting framework, and a threat-modeling tool for identifying and prioritizing attack targets. Anthropic plans to work with partners, including the US government and allied governments, to expand Project Glasswing, and intends to make Mythos-class models generally available, but only after developing stronger safeguards. “At present, no company — including Anthropic — has developed safeguards strong enough to prevent such models from being misused and potentially causing severe harm,” the company concluded.
helpnetsecurity.comMay 26, 2026extracted
Loading 40 more…