Search/lenovo
Vendor

lenovo

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
ez media & backup center ix2 firmware
Connections
1166 relationships
AI-Infra-Guard: Open-source security scanner for AI systems
AI-Infra-Guard: Open-source security scanner for AI systems Tencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of risk, and runs jailbreak evaluations against a target model. To check a skill, the platform asks a language model whether it looks malicious. Zhuque Lab scores that call against SkillTrustBench, a public set of 5,520 human-labeled samples across nine risk categories. False positive rates there run from 1.20 percent to 18.67 percent, depending on which model does the judging. The model a team plugs in decides how much reading they end up doing. At the low end, about one clean skill in eighty gets flagged. At the high end, close to one flag in five is a waste of somebody’s afternoon. Banks, carriers and manufacturers use the tool, including ICBC, China Merchants Bank, China Telecom, Lenovo, vivo and Bilibili. Zhuque Lab splits the platform into two layers, and only one of them involves interpretation. “CVE version-matching isn’t intent-based at all,” the AI-Infra-Guard team said. “FPR there is purely a function of fingerprint accuracy.” The scanner reads files an attacker wrote Both scanning components ingest tool descriptions and skill files that a hostile server controls. Indirect prompt injection is the technique that exploits this: instructions buried in content the model reads, aimed at the model doing the reading. Release 4.1.9 hardened the scanning agents against it. “File/tool content that gets read is placed into a dedicated, explicitly-delimited text block in the prompt, structurally separated from instructions, rather than mixed inline. The scanning agent is told to treat that block as data to analyze, never as commands to follow,” the team told Help Net Security. The move “cuts naive-to-moderate injection significantly,” but “it’s a mitigation, not a formal guarantee,” and “we don’t claim it’s unbreakable, and we’d say that about any LLM-driven agent.” A defender scanning a suspicious MCP server should treat a clean result as one input, not a clearance. No login in the open-source build The repository carries a warning against putting the platform on the internet: it “currently lacks an authentication mechanism.” A scanner built to tell an organization which of its AI services are exposed comes with instructions not to expose the scanner. “AI-Infra-Guard is a single-operator tool by design,” the team said. “No login, no RBAC.” Zhuque Lab’s answer is to put the access control outside the application: “the documented recommendation is a reverse proxy in front (nginx with Basic Auth or an IP allowlist) plus normal firewall rules.” That is the login layer. A team that skips it is running a vulnerability scanner that holds the API keys for every model it evaluates, reachable by anyone who can route to the port. AI-Infra-Guard is available for free on GitHub. Must read: 20 open-source cybersecurity tools to keep your team ready for anything GitHub CISO on security strategy and collaborating with the open-source community Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comSep 9, 2026extracted
Acceso no autorizado a cuentas de Dropbox mediante una integración de Lenovo ID
Acceso no autorizado a cuentas de Dropbox mediante una integración de Lenovo ID 08/09/2026 Mar, 08/09/2026 - 09:33 Entre el 4 y el 21 de agosto de 2026 se produjeron accesos no autorizados a cuentas de Dropbox mediante el mecanismo de autenticación asociado a Lenovo ID. Dropbox identificó posteriormente que las cuentas afectadas estaban vinculadas a Lenovo ID y no tenían activada la autenticación de dos factores. Según la información facilitada por Dropbox, aproximadamente 5.000 cuentas resultaron afectadas durante ese periodo. El incidente no consistió en la obtención de las contraseñas de Dropbox, sino en el abuso de un mecanismo de autenticación federada entre Dropbox y Lenovo. Según la investigación comunicada por Dropbox, un problema en el proceso de verificación del correo electrónico de Lenovo ID permitió a terceros registrar una cuenta de Lenovo utilizando la dirección de correo electrónico de otra persona y utilizar posteriormente esa identidad para acceder a la cuenta de Dropbox asociada a la misma dirección. Dropbox indicó que menos de un tercio de las aproximadamente 5.000 cuentas afectadas registraron visualización o descarga de archivos. Lenovo, por su parte, describió el problema como una integración heredada entre Lenovo ID y Dropbox que podía utilizarse para autenticar indebidamente determinadas cuentas. Tras identificar el problema, Dropbox expiró todas las sesiones autenticadas mediante Lenovo ID, eliminó los vínculos entre las cuentas de Lenovo y Dropbox y modificó el proceso para exigir la contraseña de Dropbox antes de permitir el acceso mediante Lenovo ID. Asimismo, Dropbox notificó el incidente a los usuarios afectados y a los organismos reguladores de protección de datos. Actualmente, Dropbox considera mitigado el mecanismo de acceso utilizado durante el incidente: las sesiones autenticadas mediante Lenovo ID fueron cerradas, se eliminaron las vinculaciones existentes y se introdujo una comprobación adicional mediante la contraseña de Dropbox. La compañía comunicó directamente a los usuarios afectados la situación y señaló que quienes no hubieran recibido dicha comunicación no estaban incluidos entre las cuentas afectadas. Lenovo ha indicado que sus propios clientes no resultaron afectados y que su investigación continúa. Por tanto, de acuerdo con las últimas declaraciones disponibles de las compañías, el acceso mediante el mecanismo utilizado en el incidente ha sido bloqueado, mientras que la investigación de Lenovo sobre la integración afectada permanece abierta.   Referencias 31/08/2026 Dropbox Notificación de acceso no autorizado a cuentas entre el 4 y el 21 de agosto 01/09/2026 Reuters Dropbox says about 5,000 accounts compromised in August hack 01/09/2026 Decrypt Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw 02/09/2026 Lenovo Declaración sobre la integración heredada entre Lenovo ID y Dropbox Etiquetas Acceso no autorizado Intrusión Servicios almacenamiento
incibe.esSep 8, 2026extracted
7th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files containing court records, including names and other personal information. Hit, a major Slovenian gambling and tourism operator, has  sustained a cyberattack that forced six casinos to close for about three days. Operations have resumed, but some table games, bingo, loyalty services, cash registers, and hotel systems remained unavailable during restoration, while some employees were temporarily furloughed. Baylor Genetics, a US clinical diagnostic laboratory, has disclosed a data breach affecting 2.8M patients and employees after unauthorized access to part of its IT environment in June. Stolen data included names, birth dates, medical testing and laboratory results, health insurance information, and some Social Security numbers. Global cloud storage provider Dropbox has disclosed unauthorized access to about 5,000 accounts after attackers exploited Lenovo’s email verification process. Fraudulent Lenovo IDs created with victims’ email addresses enabled access without Dropbox passwords, while files were viewed or downloaded from affected accounts. AI THREATS Researchers have  detailed an AI-assisted ransomware intrusion that compromised an enterprise network in under 10 hours. Autonomous agents mapped internal systems, mined code repositories, obtained root credentials from a secrets manager, and abused build pipelines and cloud resources, compressing activity that normally requires substantially more human effort. Security researchers have  disclosed GitSpawn, a vulnerability class affecting AI coding agents including Claude Code, Codex, Cursor, Goose, Qwen Code, Grok Build, and Hermes. Malicious repository Git configurations can trigger arbitrary code execution as the developer when agents automatically gather project context, in some cases before trust prompts. Researchers have  showcased how an AI coding assistant can be used to port a known PLC exploit to a different controller model, producing working payloads after guided analysis. While the process still required significant manual effort, it demonstrated how AI can accelerate exploit development for industrial systems. VULNERABILITIES AND PATCHES SonicWall has  addressed CVE-2026-83548 and CVE-2026-83549, critical vulnerabilities affecting SMA 1000 remote access gateways. CVE-2026-83548 is a pre-authentication SSRF flaw rated CVSS 10.0, while CVE-2026-83549 enables post-authentication remote code execution. Both were exploited as zero-days and affect SMA 6210, 7210, and 8200v appliances. JFrog has  addressed CVE-2026-82329, a critical CVSS 9.8 authentication bypass affecting self-hosted Artifactory deployments. The flaw allows unauthenticated attackers to obtain administrator access tokens and take control of repositories. Exploitation was observed shortly after disclosure against internet-exposed systems, while JFrog Cloud environments were patched by the vendor. Check Point IPS provides protection against this threat (JFrog Artifactory Authentication Bypass (CVE-2026-82329)) Security researcher have  unveiled  FalconFlank, a zero-day privilege escalation technique affecting CrowdStrike Falcon on Windows 11 25H2 and Windows Server 2025. The proof-of-concept abuses Falcon’s Microsoft Office macro-removal remediation behavior, allowing a low-privileged local user to obtain elevated access on affected systems THREAT INTELLIGENCE REPORTS Check Point Research has  uncovered a Chinese-speaking cybercrime cluster, dubbed Gambling Goblin, that compromises Brazilian government and education websites. The group installs malicious Apache modules to proxy visitors to gambling and phishing pages while manipulating search rankings. Its infrastructure spans multiple languages and shows links to Earth Berberoka. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Check Point Research has  analyzed JSCeal, a cryptocurrency-focused information stealer compiled into V8 bytecode and executed through a bundled Node.js runtime. Researchers developed a static deobfuscation pipeline that recovered readable code, revealing keylogging, browser credential theft, HTTPS interception, additional encryption, and newer variants targeting macOS systems. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Researchers have  mapped a campaign by Iran-linked Mirage Kitten that uses fake LinkedIn coding tests to deliver NodeRabbit and PollCat malware. The malicious tests are distributed through cloud links and install cross-platform implants. Targets include fintech and aviation organizations in Egypt, Ethiopia, and Afghanistan. Researchers have  analyzed new macOS delivery activity linked to North Korea’s Contagious Interview campaign. Attackers use fake job interviews and trojanized disk images or installer packages impersonating legitimate Mac applications. The samples connect to infrastructure previously associated with malicious Git hooks and VS Code task files. The post 7th September – Threat Intelligence Report appeared first on Check Point Research .
research.checkpoint.comSep 7, 2026extracted
In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: Microsoft releases cloud patches Microsoft has released patches for nine vulnerabilities in Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure Active Directory B2C, Fabric, Azure AI Language, and Discovery Studio. The fixes were deployed server side and require no action from Microsoft’s customers. Project Watershed 250: cybersecurity capabilities for Texas water utilities White House and Texas’ Governor have launched Project Watershed 250, a federal-private sector effort to provide water and wastewater utilities in Texas with access to free cyber defense resources and harded then against cyberattacks from China, Iran, and other hostile foreign adversaries. Minnesota county paid $128K to ransomware group Winona County in Minnesota reportedly paid a $128,539.57 ransom to restore services and protect personal information affected by a January 2026 ransomware attack. In April, the county fell victim to a second ransomware attack, claimed by the InterLock gang, but it is unclear who was responsible for the January incident. Exploit published for Exchange flaw affecting over 21,000 servers Exploit code has been published for CVE-2026-62911, a high-severity Microsoft Exchange Server vulnerability patched in August, the Netherlands National Cyber Security Centre warns. On September 1, The Shadowserver Foundation, observed over 21,000 servers that have not been patched. 5,000 Dropbox accounts compromised via Lenovo login integration Dropbox has notified approximately 5,000 users that hackers compromised their accounts by abusing an issue with Lenovo’s email verification process. The attackers registered Lenovo IDs using the victim’s email addresses and then accessed their Dropbox accounts. Dropbox says it closed all unauthorized sessions and access. Knight Office phishes for Microsoft 365 and Google Workspace credentials A newly identified adversary-in-the-middle (AitM) phishing kit has been targeting Microsoft 365 and Google Workspace users to steal their account credentials, Huntress reports. Knight Office relies on token theft, a popular technique that provides attackers with an already-authenticated session that completely bypasses password requirements and MFA mechanims. Plex releases security updates The popular streaming service Plex this week announced the release of Plex Media Server 1.43.3 and Plex Desktop 1.115.0 with patches for multiple security vulnerabilities, urging users to update their instances as soon as possible. No details on the bugs have been shared, and the CVEs have not been assigned yet. Guardio valued at $1.1 billion Guardio is valued at $1.1 billion following a new funding round of $40M. Guardio protects people from the AI-driven scams that lead to identity theft. Today’s bad actors prefer to walk into a network with credentials rather than being forced to break in. Coder’s module registry website served malware A threat actor hacked Coder’s Cloudflare infrastructure and added unauthorized IP addresses that hosted malicious code. The code was served through Coder’s module registry website to a subset of users, for a short period of time. Users who downloaded the malicious code were infected with a credential stealer, Coder notes. Russian charged in US for serving malware to 80,000 freelancers Searzhudin Tamirlanovich Aktulaev, 40, of Russia, has been charged in the US with exploiting the online message platform of a freelance employment company in California to deliver malware to 80,000 freelance users between June 2016 and November 2017. Aktulaev was arrested in Cyprus last year. The indictment was filed in 2021 and unsealed on Monday, when Aktulaev appeared in court, after being extradited to the US. Lasso Security raises $30 million Israeli AI security company Lasso Security has raised $30 million in a funding round led by ClearSky, with additional support from Entrée Capital, iAngels, Singtel Innov8, Mindset and Swish Data. The company has just announced LEAP, an AI guardrail that promises top-tier detection accuracy on CPUs. Related: In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions
securityweek.comSep 4, 2026extracted
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also ransomware, stolen ID data, hidden attack servers, and weak settings that should have been fixed long ago. Here’s the full list. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Fake IT, Real AccessMicrosoft has warned of a human-operated intrusion campaign that leverages Microsoft Teams external collaboration to impersonate IT or help desk personnel and socially engineer users into granting an interactive remote session. "Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2)," the tech giant said. "After the implant is deployed, the threat actor performs extensive host and Active Directory reconnaissance, periodically captures screenshots of the victim's desktop, executes follow-on payloads through trusted Windows binaries, and pivots across the enterprise over Windows Remote Management (WinRM) toward high-value assets such as domain controllers." Microsoft has described the "intrusion pattern" as high-impact as it grants an external operator interactive access to internal infrastructure. Teams Vishing at ScaleIn more Teams-related abuse, a coordinated social engineering operation dubbed Spring Ring has been observed leveraging external Microsoft Teams accounts to masquerade as IT help desk personnel to target more than 150 employees across at least 10 companies in various industries between January and April 2026. "What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware," Palo Alto Networks Unit 42 said. "In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC)." As many as 26 distinct attacker identities have been identified behind the chat and call attempts. Ransomware Affiliate PlaybookIn a new report, Sophos revealed that The Gentlemen ransomware operation, which it tracks as Gold Sherwood, has claimed a total of 683 victims by the end of July 2026. In July alone, the group is said to have added 169 victims. "The Gentlemen ransomware intrusions [...] demonstrate a repeatable affiliate playbook that combines opportunistic initial access, rapid privilege escalation, legitimate remote access mechanisms, tool staging in trusted system paths, targeted data exfiltration, aggressive defense evasion, backup disruption, and ransomware deployment," Sophos said. "Affiliates are operationally flexible: they use native Windows utilities, commercial and open-source tools, BYOVD-based EDR killers, and backup service tampering to adapt to victims’ environments and maximize impact before encryption." PhaaS Survives TakedownThe Outsider phishing-as-a-service (PaaS) platform has continued to be a resilient threat in the face of law enforcement action that took down a number of domains related to the service. The kit is operated by a threat actor known as "ChenLun." Group-IB said it has identified over 700 new phishing pages created using the kit within a month after Google filed a civil lawsuit against its operators, indicating that affiliates are continuing to use the service. The campaigns are delivered via SMS. "What was once a technically demanding operation has been reduced to a subscription and a Telegram channel," Group-IB said. "The phishing kits are distributed via a dedicated Telegram ecosystem. Operators used a WebSocket connection for live keylogging and to manipulate MFA challenges." Signed Software, Hidden PayloadA government-themed tax notice campaign is targeting recipients through U.A.E.- and India-themed tax assessment lures to persuade them to open a malicious disc image. "The disc image contains a legitimate, validly signed commercial executable alongside a hidden, unsigned malicious DLL," iZOOlogic said. "This makes abuse of software trust and DLL sideloading the central mechanism of the campaign. The malicious DLL acts as a loader and establishes multiple execution and persistence mechanisms. The loader contains three encrypted payloads. Two decrypt to legitimately signed kernel drivers from unrelated commercial products, while the third is a persistence script." The attack chain paves the way for a Registry-resident second stage, which connects to an external server over UDP. Executive Phishing as a ServiceZeroBEC has disclosed details of a turnkey phishing service called BlueKit that's being used to target CEOs of financial-industry groups to facilitate credential theft using a browser-in-the-middle (BitM) infrastructure. The campaign uses document-sharing lures to trigger the attack chain and employs ZeroBot to screen bots. "The campaign did not stop at credential or session theft," ZeroBEC said. "After a BlueKit browser-in-the-middle flow, selected victims were moved into a fake document-viewer workflow that delivered a legitimate ScreenConnect client configured for an attacker-used ScreenConnect cloud instance." The service advertises access at $250 for seven days, $480 for 14 days, and $940 for 30 days, placing it at the higher end of the current PhaaS market, in comparison to Tycoon 2FA, Greatness, and Forg365, which cost approximately $350, $289, and $400 per month. Dormant Domains, Ready C2Cybersecurity researchers have analyzed the infrastructure powering the operations of Prince of Persia (aka Indy), a little-known Iranian hacking group known for deploying malware families, Foudre and Tonnerre, to profile victims and harvest sensitive data from high-value targets. According to Whisper Security's Kaveh Azarhoosh, the backend is self-authoritative, with each live C2 server also running the nameservers for its own domains. Also identified is a dormant reserve of 58 domains that are registered and delegated to the group's own nameservers, but none of which currently points at any server. "They're staged, not live: the moment any one of them gains an address record, a new command server has gone live — and it's visible before the server does anything at all," Azarhoosh told The Hacker News via email. Remote-Controlled Rubber DuckyIntezer has detailed a fake "privacy browser" downloaded from a counterfeit site ("www.mxsetuplogi.com") that turns remote attacker commands into simulated mouse and keyboard input on a victim's machine. The site is surfaced via a sponsored search result on Google, in this case after the victim mistyped the domain name ("www.mxsetup.logi.con") on the address bar. The cybersecurity company described it as a USB Rubber Ducky attack delivered over the internet. "This attack evades EDR and sits at zero to two detections on VirusTotal," it said in a statement. "The infection began with one simple mistyped letter during routine mouse setup that routed the victim through a malvertising network into an MSIX installer signed through Microsoft's own infrastructure." The campaign has been tracked back to a similar operation from January 2016, indicating that the activity has been active for at least a decade. 153 Million IDs for SaleThe U.S. Federal Bureau of Investigation (FBI) is investigating a new ID theft service called Nexus, which claims to have digital scans of over 153 million driver's licenses from people in the U.S. and Canada. According to independent security journalist Brian Krebs, the service is said to be siphoning images collected by a widely used identity verification company called IDScan.net based in Louisiana. The service, launched on the dark web on August 31, 2026, also boasts of more than 10 million identification cards, more than three million travel documents and/or international IDs, and at least 579,000 medical cards. Each record can be unlocked for $100. Shortly after the exposé was published, Nexus went offline. IDscan.net is said to be investigating the incident on its end. AI Instructions Become a TrapA scan of 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies has uncovered llms.txt or llms-full.txt that are being placed at the root of their websites, alongside robots.txt. "The file is not a sitemap and it is not a disclaimer," an Israeli stealth startup said. "It is a curated instruction set for AI agents: what to read, which APIs to call, which packages to install, which domains to trust. OpenAI, Anthropic, and Google publish their own." Of the 8,265 llms.txt and llms-full.txt files surfaced from the scan, 120 of them, each on a different site, featured install instructions pointing to PyPI or npm package names and domains that had never been registered. "We selected a small set of package names that appeared in the llms.txt files of companies you have definitely heard of, and registered them on PyPI and npm," Alon Hertz, one of the researchers, said. "Into each one we embedded a single phone-home — a minimal beacon that reported the fact of installation back to infrastructure we controlled. The first callback arrived in under four minutes." What's troubling here is that at least one active attack has already exploited this misconfiguration, in which authentication vendor Clerk's llms.txt included a reference to an npm package named "clerk-next-fix-auth-protection" instead of referencing its scoped package, @clerk/eslint-plugin. An unknown threat actor registered a public package with the same name. The package contained code to transmit the installer's username, machine name, working directory, and timestamp to an external server. Clerk has since addressed the issue. AI Defenders Sound the AlarmA coalition of over 100 companies, including Anthropic, Google, OpenAI, Microsoft, Perplexity, and others, has published an open-leet calling for improvements to cybersecurity as AI continues to compress compress cyberattack timelines, as well as accelerate the speed and scale of cyber attacks, leaving defenders with an ever-shortening window to address security issues before they are exploited. The signatories noted that current approaches to cybersecurity are not equipped to deal with the incoming surge in AI-enabled attacks, and that threat actors can rely on AI tools to target longstanding vulnerabilities, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems. "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable," the letter warns. "The companies and public services our communities depend on – from hospitals to water treatment plants to the infrastructure that powers the internet – are at risk. Today’s AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years. If we act decisively, we can use the defenders' window to make our digital world much more secure." Legacy Login Exposes 5K AccountsDropbox has disclosed that about 5,000 accounts were compromised last month, allowing threat actors to view and download content stored on the cloud-storage platform. The company told Reuters that it "identified unauthorized access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled," adding it terminated all sessions authenticated through a Lenovo ID. Lenovo said the issue is related to a "legacy integration" between Lenovo ID and Dropbox that "could be used to improperly authenticate certain Dropbox accounts." Kernel Protection by DefaultMicrosoft has announced that it will expand memory integrity protection across eligible devices starting October 2026, to help users benefit from "stronger kernel-level protection from sophisticated attacks by default with little or no additional configuration." The company continued: "This change reduces security complexity while helping you establish a stronger security baseline across your environment. Built on Virtualization-based Security (VBS), memory integrity helps protect critical parts of Windows from tampering. It forms a foundation for modern security innovations such as hotpatch updates that improve user experience and productivity, as well as protection." Pro-Ukraine Ransomware RebrandA new ransomware group named VantaCore has targeted at least seven Russian companies with a proprietary ransomware strain and demanding millions of dollars in ransom. The threat actor is assessed to be a rebranding of a known pro-Ukrainian group tracked as Thor, F6 said. Also put to use in the attacks are VantaCoreLoader, to distribute the ransomware and other malicious programs, VantaCoreRAT, a backdoor that can harvest information about infected systems and execute commands, and SnowKiller, which can terminate security software using the BYOVD technique. Sextortion Suspects Face LifeTwo Nigerian nationals, Adebola Festus Adekunle, 26, and Mudasiru Afeez Olawale, 24, have been extradited to the U.S. to face prosecution in two separate cases for the financially-motivated sextortion of minors that led to the death of minors in both the Northern District of Mississippi and the Middle District of North Carolina. Both of them face a maximum penalty of life in prison and mandatory minimum prison sentences, with the child exploitation resulting in death charge carrying a minimum penalty of 30 years in prison. Hardware-Backed Digital IDsGoogle said it's expanding the Android Ready SE initiative to bring together silicon vendors, device manufacturers, wallet developers, and government issuers to streamline compliance and scale certified hardware security across the mobile ecosystem. The development is seen as a way to scale high-assurance, tamper-resistant digital identity amid accelerating global demand for securely storing national electronic IDs (eIDs) and mobile driver licenses (mDLs) in hardware-backed mobile wallets. OAuth Access Outlives PasswordsThe FBI has warned that malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique called OAuth consent phishing to gain access to their accounts. The activity has targeted government officials, media, and other publicly known personalities on a commercial messaging application (CMA), urging them to access a malicious link under the guise of a file-sharing service through an application under the malicious actor's control. "Previous phishing campaigns have also impersonated event coordinators and planners, who sent malicious links to targets under the guise of an invitation to an event and the need to verify the target's identity through a malicious application under the actor's control," the FBI said. Authorities did not provide any details about how many people may have been compromised by these attacks, or who is behind them. Electron Apps Hide a StealerTrojanized Electron desktop applications impersonating legitimate software are being used to distribute a Windows information stealer called RevStealer. The applications are shared via GitHub repositories and game-cheat-themed sites, including a fake Claude Opus 5 Free Desktop project. "It is delivered by an Electron loader that hides an AES-encrypted native payload inside an application resource, attempts to add the user's AppData folder to Microsoft Defender's exclusion list, and launches the payload with no visible window," Morphisec said. The malware also runs a series of anti-analysis and anti-VM checks before unpacking the main payload. "If the primary C2 is unreachable, RevStealer reads a fallback address from a smart contract on the Polygon blockchain, letting operators rotate infrastructure without rebuilding the malware," the company said. What's notable about the malware is that it's not designed for persistence. Rather, it prioritizes capturing as much data as possible in a single run, exfiltrates it in encrypted typed records, and then deletes itself. Trusted Tool, Rogue AccessThreat actors are weaponizing Faronics Deploy, a legitimate endpoint management platform, to run attacker-controlled PowerShell after phishing victims install the software. Huntress said it observed more than 457 endpoints encountering Faronics-related lures. "In observed cases, threat actors chained Faronics Deploy to ScreenConnect, blending malicious remote access activity into trusted software workflows," it said. "The delivery method varies between scripts, with observed examples using curl or MSHTA to retrieve additional content, while others invoke msiexec to install payloads hosted on attacker-controlled infrastructure. These scripts are subsequently used to install ScreenConnect, establishing an additional remote access mechanism on the compromised endpoint." ClickFix Goes Cross-PlatformCybersecurity researchers have described CRPx0 as a ClickFix-delivered ransomware-as-a-service (RaaS) operation that employs lures related to Windows and macOS update prompts and reCAPTCHA checks to trick victims into running a copied command. "On Windows, it starts a multi-stage DLL chain. On macOS, it downloads the Python payload directly," the Ransom-ISAC Research Team said. "The final payload is a cross-platform Python ransomware that exfiltrates data before encryption, encrypts files with AES-128-CBC via Fernet, wraps the per-victim key with an embedded RSA-4096 public key, attempts lateral movement, and drops ransom notes demanding Bitcoin or Monero payment within 48 hours." The RaaS program first appeared on June 7, 2026. As of late August, the group has advertised the operation on a clearnet site ("crpx0[.]su/v3.txt") as an offensive control panel to manage compromised machines, harvest files and credentials, monitor stolen cryptocurrency artifacts, run remote commands, and launch ransomware manually. One point is easy to miss: changing a password may not shut every door. A bad app approval or remote session can give attackers access without the password. Recovery should also end open sessions, remove unknown app access, and check remote tools. Better security settings are slowly becoming the default, which helps. But old account links, weak sign-in options, and trusted software still give attackers room to work. The safest rule this week is simple: check what already has access before adding anything new.
thehackernews.comSep 3, 2026extracted
Dropbox, 5mila profili compromessi nell’attacco cyber di agosto
Gli hacker criminali avrebbero avuto accesso ai file presenti in meno di un terzo degli account compromessi. Dropbox ha comunicato di aver subìto un attacco cyber lo scorso agosto, con la compromissione di 5mila profili . Gli hacker criminali avrebbero avuto modo di visualizzare e, in alcuni casi, scaricare contenuti archiviati sulla piattaforma di cloud storage . La conferma è arrivata da parte della stessa società, lo scorso martedì, dopo che Bloomberg News aveva per prima riportato l’attacco informatico. Conseguenza diretta della notizia, le azioni di Dropbox hanno perso circa il 2,4% negli scambi after-hours di martedì . Si conferma, dunque, come le vulnerabilità di una piattaforma digitale possano avere delle conseguenze dirette sugli utenti. Dietro l’accaduto Alcuni utenti di Dropbox , ha spiegato la Reuters , hanno ricevuto lunedì un’ e-mail dalla società che li informava dell’utilizzo del loro account – con relazione ai loro dati – senza autorizzazione , tra il 4 e il 21 agosto. Secondo la stessa società, tuttavia, gli hacker criminali hanno avuto accesso ai file presenti in meno di un terzo degli account compromessi . Il numero complessivo dei profili coinvolti si aggira quindi intorno alle 5mila unità. Dropbox ha spiegato, sempre alla Reuters , di aver individuato accessi non autorizzati che riguardavano profili collegati a un Lenovo ID sui quali non era stata attivata l’autenticazione a due fattori (2FA). In risposta all’incidente, Dropbox ha terminato tutte le sessioni autenticate attraverso Lenovo ID . L’azienda ha inoltre eliminato i collegamenti tra gli account Lenovo ID e quelli Dropbox e ha modificato i propri sistemi. D’ora in poi, “ gli utenti dovranno inserire la password di Dropbox prima di poter accedere al proprio account attraverso Lenovo “. I chiarimenti delle aziende Da parte sua Lenovo ha individuato una “ legacy integration ”, cioè un’integrazione di vecchia generazione, tra Lenovo ID e Dropbox che avrebbe potuto essere utilizzata per autenticare in modo improprio alcuni account Dropbox . Lenovo ha precisato che i propri clienti non sono stati coinvolti nell’incidente. L’indagine è ancora in corso. Dropbox ha dichiarato di aver segnalato l’incidente alle autorità competenti per la protezione dei dati . L’episodio mette nuovamente in evidenza i rischi legati alle integrazioni tra servizi online e ai sistemi di autenticazione esterni. In questo caso, dalle informazioni che hanno reso pubbliche le due aziende, è emerso che il collegamento del probolema a un’integrazione tra Lenovo ID e Dropbox . Quest’ultimo ha interessato profili che non avevano attivato l’ autenticazione a due fattori. Seguici anche sul nostro canale WhatsApp Vai al sito di Cybersecurity Italia. L'articolo Dropbox, 5mila profili compromessi nell’attacco cyber di agosto sembra essere il primo su CyberSecurity Italia .
cybersecitalia.itSep 3, 2026extracted
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
ai and ml Zuck's Muse to Spark joy with open weights release 'soon'While you wait, Meta says it’s taught the model to stop wasting tokens and ask for help a bit more often ai and ml With Gemini 3.8 Flash, Google reminds everyone it's still in the raceAI model scores well, runs fast, and doesn't cost too much (yet) security AI agents carried out every step of this ransomware attack – then left the victim an 80-page security auditAdding insult to injury ai and ml Anthropic promises zero data retention – but customers must check it workedMore compliance-friendly stance could boost appeal of Fable Security Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeksThe model provider gave METR the credits for free. An actual customer would not have been so lucky Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career
theregister.comSep 2, 2026extracted
Dropbox accounts breached through Lenovo email verification flaw
Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs. Although some affected users did not have Lenovo accounts, the cloud-storage provider said it uses Lenovo Identity Provider Services as part of its authentication infrastructure. This allows users to log into Dropbox accounts using verified Lenovo IDs. According to the notification sent to impacted users, the unauthorized access was possible due to "an issue with Lenovo's email verification process," which "allowed an unauthorized party to register a Lenovo ID using your email address." The attacker then used the fraudulent Lenovo ID to access the Dropbox account registered under the same email address without needing the login password. Dropbox’s identity-linking process trusted Lenovo’s assertion that the attacker controlled the email address without requiring confirmation through the existing Dropbox login method. “While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.” Some Dropbox users reported receiving "about two weeks ago" notifications about suspicious Dropbox sign-ins and immediately changing their password and activating two-factor authentication (2FA). "One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID," user xaphod said. The cloud storage company determined that the attacker accessed users’ Dropbox accounts between August 4 and 21. In a statement for BleepingComputer, Lenovo said that the issue was related to a legacy integration between Lenovo ID and Dropbox, which could be leveraged "to improperly authenticate certain Dropbox accounts." "Upon identifying the issue, Dropbox and Lenovo worked collaboratively to promptly mitigate the risk," a Lenovo spokesperson told BleepingComputer. The investigation into the incident continues, but the company determined that Lenovo customers were not affected by the issue. Dropbox responded by expiring all sessions authenticated through Lenovo IDs and adding a new login requirement mandating that users enter their Dropbox account password when attempting to use Lenovo ID authentication. According to Reuters, approximately 5,000 accounts were accessed, and the hacker viewed and downloaded content from some users. BleepingComputer has contacted Dropbox for additional information, but we have not received a response as of publication. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comSep 2, 2026extracted
New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims
As organizations race to future-proof their systems against quantum-enabled attacks, questions remain around how to verify whether hardware is quantum-safe. A new industry benchmark aims to answer that question. The Trusted Computing Group (TCG) released new guidance on August 24 that helps prove that trusted platform modules (TPMs) genuinely meet essential PQC requirements. TCG is a nonprofit organization tasked with promoting vendor-neutral standards for hardware-based security products like TPMs. TPMs are specialized security chips installed on a computer motherboard or processor that safely store passwords, digital certificates and encryption keys. TCG, the main standards body, has published the version 1.2 of it specifications for second-generation TPMs (TPM 2.0) – which are part of the Windows 11 system requirements. TPMs will likely play an important role in some organizations’ PQC roadmap as they offer a robust solution to maintain trusted identities, platform integrity, attestation and hardware-anchored security over time. With the potential evolution of PQC algorithms over time, these elements “may need to remain secure for decades,” TCG noted. Not all TPMs currently on the market provide quantum-safe encryption options and some advertise “compliance” yet fail to provide full, end-to-end security capabilities. In March 2026, the nonprofit brough together almost 90 contributors from government, academia, semiconductor companies and computing hardware providers – including Intel, Google, Hewlett Packard Enterprise, Microsoft, NVIDIA, Lenovo, STMIcroelectronics and more – to develop a standard for PQ-ready TPMs, the TCG PC Client Platform TPM Profile (PTP) 1.07. The TCG standard document outlines the minimum requirements for PQC-ready TPMs. Now, TCG has released an accompanying document helping businesses to verify whether their TPMs meet the requirements of PTP 1.07. It also designates two categories to describe how ready a TPM is for the transition to post-quantum cryptography (PQC): ‘TCG PQC-ready TPM’ – a TPM that already supports the PQC capabilities defined in PTP 1.07 ‘TCG PQC-upgradable TPM’ – a TPM that does not yet support PTP 1.07 but is designed to be upgraded to support it These designations provide a simple way to understand where a platform stands in its transition to PQC. The nonprofit has also announced plans to enhance its certification programs to certify TCG PQC-ready TPM.
infosecurity-magazine.comAug 24, 2026extracted
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications. "Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud capabilities with broader surveillance and device-control features," ThreatFabric said in a technical report shared with The Hacker News. The malware, besides targeting sensitive applications and enabling extensive device takeover, introduces a novel Wi‑Fi mesh technique that makes it possible for the infected devices to relay data through nearby compromised devices with internet access. It's distributed via phishing sites and dropper apps impersonating utilities. The Dutch security company said the malware family's activity dates back to February 2026, when the first domain was registered with a fabricated persona. Active development efforts ensued not long after, with the first wrapper using a booking app lure and the implant appearing by the end of May. But in an interesting twist, these efforts were abandoned from late June to mid-July, while signs of a second deployment emerged around July 13. The newer iteration of the wrapper and the implant have been found to incorporate stronger anti-analysis checks and the ability to phishing lock screen secrets. A corresponding panel and API subsequently went live between July 24 and 28. The APK package names linked to the wrapper and implant are below - tech.intel.dialer.updater (Wrapper) org.honor.secure.helper (Wrapper) org.lenovo.storage.processor (Implant) dev.huawei.media.helper (Implant) An examination of the malware reveals that it monitors 169 package IDs associated with banks, peer-to-peer (P2P) payment and Buy Now, Pay Later (BNPL) services, cryptocurrency wallets and exchanges, messaging apps, government and eID services, browsers, authenticators, and email clients. The majority of the targets are Ukrainian, but also present in the list are apps used in Russia, Central and Western Europe, and the U.K. "The target set suggests a blend of banking malware and spyware," ThreatFabric noted. "Financial fraud appears to be a major objective, with coverage spanning banks, payment services, cryptocurrency exchanges and wallets, government identity apps, and authenticators." In tandem, Manic is also designed to target commercial and military-focused messaging apps. Because the malware facilitates location tracking, notification monitoring, file collection, and remote device surveillance, the broad targeting allows the operator to keep tabs on a victim's financial activity, communications, and their whereabouts in real-time. Like other Android malware families, Manic achieves its goals by abusing Android's accessibility services and notification permissions, effectively allowing it to capture lock screen secrets or serve fake overlays to gather sensitive data or conceal malicious activity by showing black or update screens. Some of the other noteworthy features of the malware are listed below - Intercept keypad interactions and collect passwords, one-time codes, and recovery phrases Leverage accessibility services as a "UI keylogger" to classify and record text along with the app used, and if that app is on the malware's target list Monitor the screen and interact with the device remotely over a WebRTC session Remove the implant from the launcher Record current coordinates and timestamp (and enable device location, if not already) Take screenshots Export contacts, call history, SMS messages, and notifications Obtain a list of installed apps Send SMS to a supplied telephone number along with the provided text Display bogus notifications Delete a selected local file Lock the screen through the accessibility service Attempt to disable Google Play Protect through UI automation On top of these capabilities, Manic can capture PIN codes by serving a transparent overlay atop the legitimate numeric keypad in the targeted app. Thus, when a user taps on the overlay, the malware records the exact tap position and the nearby UI element. It then briefly turns off touch interception and proceeds to replicate the tap on the actual keypad at the same position by taking advantage of the accessibility services API. This, in turn, allows the targeted app to function normally, while the threat actor is in possession of the PIN code without having to display a fake banking interface. "Persistence relies on background workers, alarms, and the Accessibility and notification services," ThreatFabric said. "These components maintain C2 communication, process commands, upload queued data, and synchronize the offline mesh, with periodic execution every 10 to 15 minutes depending on the build." Perhaps the most unusual aspect of Manic is its store-and-forward relay mechanism to exfiltrate data using another device that's in close physical proximity to the compromised Android phone if it cannot connect to the attacker-controlled infrastructure. With this approach, the idea is to allow the source device to remain offline while the malware attempts to locate a second infected device that can provide an alternative pathway to the command-and-control (C2) server. The relay mechanism works like this - The collected files and command results are staged in an encrypted format and placed in a local queue Find an infected peer nearby using Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT If a peer is located, the encrypted package is relayed to it and forwarded toward the C2 server Manic also supports multi-hop routes, enabling the queued items to be configured for a maximum of four relay hops by default. If no peers are found, the data is kept in the queue, and the whole process is retried later. "Each newly queued item receives a four-hop relay limit by default, although the configuration can change that value," ThreatFabric told The Hacker News. "The relay metadata also carries the current hop count. An online peer can create a Wi‑Fi Direct group when it finds no peers. Every retained build uses the same network name and tries to create the group up to three times." This also means that disconnecting an infected device from the internet does not necessarily prevent data exfiltration, as Manic can weaponize another compromised Android device as a gateway. "The evolution observed between May and July 2026, including stronger anti-analysis measures and lock-secret phishing, indicates that Manic remains under active development and continues to expand its capabilities," ThreatFabric said.
thehackernews.comAug 20, 2026extracted
Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI
ASIA IN BRIEF Chinese company Zhipu last week launched a new AI model called GLM-5.3 that it claims has bug-finding powers that match those possessed by American models. The company’s announcement includes benchmark data that finds GLM-5.3 beats Fable 5 and GPT-5.6 Sol on the CyberGym benchmark, a test of a model’s ability to solve real-world cybersecurity challenges. “As we scaled post-training, cyber capability developed faster than we expected. GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain,” the company wrote, adding that the model “did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains.” The company said it has worked with Chinese companies to test the model on real-world codebases, and found 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols. “Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years,” the announcement states. GLM-5.3 also performed worse than western models on other security and coding benchmarks. Yet the fact that the model is a highly-capable bug finder signals that China is not far behind in terms of being able to poke holes in its rivals software and developed that capability very quickly after the debut of Anthropic’s Mythos. Any advantage the US felt it had as the home of Anthropic has therefore dissipated. Korea signals legal action against Apple, Google app store strangleholds South Korea’s Communications Commission last week found Google and Apple had abused their app store monopolies, and promised stern sanctions will follow. In 2021, South Korea passed world-first legislation requiring app store operators to offer the option to use third-party payment schemes. Apple and Google did so, but charged a 26 percent transaction fee for doing so – meaning they earned almost as much revenue when users chose third-party payment providers as they did from their own schemes. The regulator has previously warned that it will impose the highest possible penalty available under law, which is three percent of revenue earned by non-compliant behaviour. That’s probably back-of-the-sofa money for Apple and Google. India has banned rideshare operators from offering customers the chance to specify the amount they will tip before a driver accepts a gig. Uber India introduced the feature last year, seemingly copying it from an Indian rideshare operator called Namma Yatri. Consumer affairs minister Pralhad Joshi criticized Uber for the practice at the time, as he saw it as a means for users to effectively jump the queue by offering drivers more money – and for rideshare platforms to improve their revenue because if tips are higher, so is the platform’s share of the gratuity. Last week, India’s Ministry of Road Transport & Highways issued a directive (PDF) banning the practice. Henceforth, rideshare apps can only offer users the chance to tip at the end of a journey, and all of the tip must go to the driver. “No feature, prompt, message, add-on, payment option, or user interface element should be displayed before completion of the ride that directly or indirectly encourages, induces, or creates an impression that payment of any additional amount may improve ride confirmation, driver acceptance, driver allocation, waiting time, or quality of service,” the directive states. Indian services giants reveal data breaches Indian tech services giants TCS and HCL last week both admitted to data breaches but say customer data is safe, and only employee data is at risk. TCS published a stock exchange filing that opens “This is to inform you that Company has received threat-intelligence alerts alleging possible exposure of certain employee information.” The filing says TCS investigated the matter “and has not found any credible evidence of a breach of TCS systems or customer environments.” The company says leaked info is “basic employee information” and more than four years old. Note that mention of the stolen data being at least for years old, because TCS’s filing says the attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue to pull off the heist. TCS says it “had strong safeguards in place against such techniques for more than two years,” perhaps suggesting the data heist occurred before the company shored up its defenses. “Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely,” the filing states. HCL also used a stock exchange filing [PDF] to address what it called “claims made by a hacker group of potential exposure of limited data elements relating to HCLTech employees.” The company described the stolen data as “limited and dated to a few years back,” and added its assurance that customer data is safe. HCL’s investigation is ongoing. Lenovo’s enterprise unit finally posts a big profit Lenovo last week announced its quarterly results, including a $777 million profit for its Infrastructure Solutions Group (ISG) – the biz based on the 2014 acquisition of IBM’s x86 server operation that has seldom produced positive financials. Even during the early years of the AI boom, ISG’s profits were modest – just a few million dollars per quarter on turnover of billions. The business unit won a record $8.5 billion of revenue, up 98 percent year-on-year. AI was a big reason for the result, as buyers sought hardware to run inferencing workloads, The company says it has a pipeline for $54 billion of AI server sales, and has become the number two x86 server vendor as measured by revenue. Overall revenue came in at $26.95 billion, up 43 percent year-on-year, and cash won by its PC-led intelligent devices group jumped 27 percent to $17.1 billion and saw its PC market share reach 24.2 percent. Lenovo reckons the strength of its supply chain helped make those outcomes possible. India to build astronaut training facility India’s Space Research Organization (ISRO) last week issued a tender for construction of an astronaut training facility. The tender mentions extensive air conditioning works, plus a swimming pool, suggesting India wants to build a large tank in which the Vyomanauts who will fly its future Gaganyaan missions can train at home, instead of traveling to Russia or elsewhere as has been the case in the past. The tender covers $2.75 million worth of work. ®
theregister.comAug 17, 2026extracted
Acoustic keylogging | Kaspersky official blog
For security researchers studying unconventional side-channel attacks, acoustic keylogging is something of a Hello World: a foundational problem that’s been tackled many times. A recent paper authored by researchers across three Japanese universities cites six previous studies on the topic that date as far back as 2004. While earlier experiments showed theoretical promise, they came with real-world caveats so severe that it made them all but impractical for actual espionage. The authors of this latest study, however, claim to have overcome most of those limitations. Today, we look at how they pulled it off, and assess whether their method holds up in real-world scenarios. What makes this new approach different? Previous acoustic keylogging techniques were fundamentally flawed. Best-case scenarios required prior training on the target’s specific keyboard model. Worst-case scenarios required a complex microphone array to isolate the subtle acoustic differences between keystrokes. Crucially, almost all prior models failed outside silent environments, which rendered the attack vector virtually useless. The Japanese research team demonstrated reliable keystroke interception even if the target was sitting nearby in a public space, sound was being recorded in an online meeting, or the researchers were using a contact microphone to eavesdrop through a wall. All this with strong model accuracy and a minimal training dataset. Their process needs a sample of just 150 to 200 keystrokes to reach a 99% accuracy rate for subsequent typing. How to crack 200 keystrokes in under 50 iterations To understand how the researchers achieved such high accuracy and adaptability, we have to look at their audio processing pipeline. Their analysis begins by automatically segmenting a raw recording into discrete keystrokes. This data is then passed through a specialized algorithm that simplifies the subsequent audio analysis. Next, the system clusters together acoustically similar signals. The assumption is that the members of one cluster map to the exact same key. One particularly intriguing takeaway was isolating the spacebar sound from all the rest. Because the spacebar produces a distinctly unique sound profile compared to other keys, identifying it provides reliable word boundaries. This streamlines the next phase: feeding the preprocessed acoustic data into specialized language models for inference. Yes, the method relies on not one but two language models. The first model performs multiple passes over the audio stream to map acoustic signatures to potential keyboard characters. During each pass, the model leverages dictionaries to hypothesize character mapping, and check whether the resulting text aligns with standard words. The second model handles the final refinement pass: it ingests thoroughly pre-processed data rather than raw inputs. The method doesn’t stop there: unrecognized keystrokes undergo manual analysis, with analysts injecting educated guesses before re-running the recognition pipeline once again. The goal of looping through these multiple iterations is to achieve complete recognition across the keyboard from an ultra-compact dataset of ideally no more than 200 captured keystrokes. This marks a major shift from legacy methods, which relied on massive training datasets. Research results To validate their theoretical model, the researchers created an experimental testing setup: The team tested four distinct laptop models, each producing unique acoustic keyboard signatures. Participants typed 2400 characters per experiment, with analysts extracting audio samples ranging from 50 to 400 keystrokes. Across all devices, the system reliably reconstructed typed text from a baseline sample of just 150 keystrokes or more. Recognition accuracy exceeded 80% at 150 keystrokes, and approached 100% once the sample reached 200 keystrokes. The researchers achieved nearly identical results in field-like conditions with the microphone placed three meters away from the target device. Going a step further, the team successfully tested an even higher-friction scenario: using a specialized contact microphone to eavesdrop through a physical wall. Under these conditions, accuracy dipped slightly for certain laptop models. Dell and Lenovo devices yielded roughly 80% accuracy over a 200-keystroke sample, while Apple and HP ones maintained nearly 100% recognition rates. Remote interception during videoconferencing presented an additional variable: results depended on both the target laptop model and the specific web conferencing software used. Even so, most test scenarios yielded reliable character recognition, though a few edge cases required expanding the sample size from 200 to at least 250 keystrokes. Reasonable critique Despite these impressive results, the technique has clear limitations. First, all experiments were conducted strictly on lowercase English text. The target dataset was capped at just 29 characters: the standard alphabet, spacebar, period, and comma — even number keys were excluded. As a result, capturing randomized character strings like complex passwords remains a major hurdle. Yet these are precisely the targets threat actors care about most. However, the Japanese research team didn’t ignore passwords. While recognition accuracy was predictably low, the authors proposed assessing success through a more realistic lens. For starters, attackers can almost always capture audio of other typing activity alongside password entry. This provides a stream of natural language with minimal special characters. Factoring this broader acoustic context into the password analysis significantly improves the odds of a successful guess. Next, the researchers rightly noted that even a list of several candidate passwords increases the chances of compromising a target account. As shown in the graph above, when ample data (426 keystrokes) is captured, a short five-character password can be successfully cracked within 100 attempts with a 90% success rate. Naturally, longer passwords proved far more resistant to eavesdropping. Despite its limitations, this study represents a major breakthrough in acoustic side-channel attacks. It demonstrates a highly practical threat scenario: an attacker captures a brief audio recording of typing activity, then uses iterative analysis and targeted manual adjustments to process and refine the data offsite. While eavesdropping in a noisy restaurant or through a wall is likely difficult to scale, capturing keystrokes during virtual meetings for offline decoding represents a realistic attack scenario. Ultimately, this research offers a compelling proof-of-concept: modern algorithms can drastically improve the accuracy of acoustic reconnaissance.
kaspersky.comAug 6, 2026extracted
Nobody was checking the drives that encrypt your laptop
Nobody was checking the drives that encrypt your laptop A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož and three colleagues bought 38 of those drives and ran them through a test bench. Brož maintains cryptsetup, the tool that configures disk encryption on most Linux systems. The drives came from Samsung, Western Digital, Micron, Kioxia, and others, a mix of new stock and secondhand units pulled from laptops. The team treated each one as a black box and sent it only the commands the Opal2 documentation defines. Several drives failed on basic points. What the drives got wrong Two Lenovo OEM drives encrypt every sector with the same tweak value. AES-XTS relies on that value to make identical data look different depending on where it sits on the disk. With one value across the whole drive, identical content written to two locations produces identical ciphertext. A pattern in your files survives into the encrypted data. The same two drives ship a random number generator that returns a predictable counting sequence on every call. A SanDisk SATA drive leans toward one byte value, 0x8B. The drive emits it roughly double the expected frequency. Opal2 requires every drive to expose this generator and leaves its quality unspecified. The tweak flaw exposes residual pattern information about data a key change was meant to erase, and the researchers rate real exploitation as very limited. The weak generator matters for software that pulls keys from it, and the team searched for a product that does and came up empty. The encryption key itself lives on the drive and stays there. The reset tokens have their own problem. Every Opal2 drive carries a PSID, a code printed on the label that wipes the drive back to factory state. One batch of SanDisk drives generated those codes in sequence, sharing a prefix and a suffix. Recovering one drive’s PSID hands you its neighbors’ by counting up. Six other drives accept any garbage appended to a valid PSID and treat it as correct. Vendors buy hardware encryption, and no one checks it Companies deploy Opal2 drives to satisfy a data-at-rest requirement. A purchasing officer sees “hardware encryption” on a spec sheet and marks the box. The gap between that label and the chip’s behavior went years unmeasured by any independent party. This is the first cross-vendor security comparison of Opal2 drives. The last major public work on self-encrypting SSDs landed in 2019. The Samsung generator bias sat undetected across a drive that researchers had already reverse-engineered. The method that surfaced all of it: buy used SSDs and run a script. The marketing muddies things further. The team began with more than fifty drives and set aside a dozen that support only Pyrite2, a related standard that checks a password and leaves the data in plaintext. Vendors sell those drives with hardware encryption in the copy. The disclosure went nowhere Brož and his team reported every security issue to the affected vendors. Micron shipped a firmware fix for a sector-size bug on its Crucial T500. Every other report came back as already known and unpatched, out of support, or met with silence. Several vendors answer broken encryption firmware by marking the feature dead and pointing customers to software encryption. Firmware updates stay hard to get. Many require a vendor’s Windows-only tool or a bootable image. The Linux Vendor Firmware Service covers a slice of OEM drives, and the rest depend on whichever support site still exists. What got fixed The project shipped code. Opal2 support landed in cryptsetup. Single-user mode is staged for a coming release, along with the Linux kernel changes it needs. The team released the Opal Test Suite so anyone can point the same checks at their own drives. Three of the tested drives turned out unusable for real disk encryption. Single-user mode, the feature that keeps a drive administrator from unlocking a user’s data, tells a similar story. Twenty-four drives advertise it. Fourteen support it well enough to use. Cryptsetup now checks a drive’s single-user-mode firmware before trusting it and drops to a safer configuration when the check fails. The practical guidance runs opposite to the original sales pitch. Layer software encryption over the drive’s own, and let the hardware serve as a second wall. A drive that claims to encrypt your data deserves the same scrutiny as any other security control. The tools to apply that scrutiny are open source now, and the first pass through them found broken firmware in production on machines storing real data. Download: The ultimate guide to network operations management
helpnetsecurity.comJul 21, 2026extracted
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it all looks until the bill arrives. The full ThreatsDay list is below. Global fraud bustA global anti-fraud operation involving 97 countries and territories has resulted in the arrest of 5,811 individuals and the interception of $293 million in illicit assets as part of an operation codenamed First Light 2026 that took place between January 15 and April 30, 2026, to tackle social engineering scams and associated money laundering activities. "Over 142,000 victims globally were identified during Operation First Light 2026, highlighting the extent to which social engineering scams and fraud have escalated into a major transnational threat, affecting individuals, businesses, and governments," INTERPOL said. More than 23,000 cases were solved, and 15,606 suspects have been identified. In Eswatini, authorities arrested 82 people and dismantled a criminal network running illegal online gambling, money laundering, and elaborate impersonation scams. The Thai police made two arrests and uncovered a money laundering scheme that converted illicit funds from romance scams into various cryptocurrencies, using cross-chain token swaps to obscure the financial trail. Payment SDK typosquatsA cluster of 17 malicious npm and PyPI packages have been found to typosquat Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, and exfiltrate them to an Ngrok endpoint. The malware skips machines that have less than two CPU cores, and the hostname or username contains sandbox, analyzer, cuckoo, virus, malware, vmware, or vbox. "The threat actor targeted payment app SDKs, which might indicate a financial motive or the desire to monetize using payment app accounts," Socket said. "The threat actor used their obfuscator 'properly.' They did not re-use the same obfuscation key across versions or packages, which is intended to prevent signatures from tracking this malware by the same key. This resulted in different hashes for each file." Stealthy code injectionCybersecurity researchers have outlined a technique called Process Parameter Poisoning (P³) that can be used to code in foreign processes without raising any security alarms. "P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure (Process Parameter Poisoning) as an execution and staging location for shellcode injection into remote processes, without triggering common detection mechanisms," researchers Max Hirschberger and Ogulcan Ugur said. "One major advantage of this technique is that no processes are created in a suspended state and no threads or processes are suspended during its execution." Unauthenticated file accessA critical security flaw in Esri ArcGIS Server 12.0 and prior (CVE-2026-9181, CVSS score: 9.8/7.5) could be exploited to access sensitive files on the system without requiring valid credentials by sending crafted path parameters. "The vulnerability exists in the ArcGIS Server REST Uploads resource, where insufficient validation of crafted path parameters allows an unauthenticated remote attacker to traverse outside the intended directory boundary," Horizon3.ai said. Ransomware tooling overlapA new analysis of the Interlock (aka Hive0163) ransomware operation has identified links with TAG-124 (aka KongTuke and Landupdate808). The threat actor is known to employ a variety of mostly custom malware, including NodeSnake, Interlock RAT, JunkFiction downloader (aka Dormouse), Supper (aka SocksShell and WINDYTWIST), and JunkFiction cryptor. IBM X-Force said it has discovered strong overlaps between NodeSnake, ModeloRAT, JunkFiction downloader, Interlock RAT, and Supper malware variants, indicating a shared original codebase or possibly common developers. Rhysida, on the other hand, often uses Endico downloader, Broomstick (aka Oyster or CleanUpLoader), Supper, and Tomb cryptor (aka Textshell or pkr_mtsi). Evidence indicates a relationship with IceNova (aka Latrodectus) operators and ITG23 (aka TrickBot). Early versions of JunkFiction date back to May 2024, with the downloader being used to Supper, which then delivers CrossTec Remote Control, a legitimate remote administration tool. "The fact that both ModeloRAT and NodeSnake were deployed by TAG-124/KongTuke, possessed overlaps with other malware families belonging to the Interlock toolkit and used the same exploit during their operations, supports the theory that these activities may be linked," IBM X-Force said. Claude data warningChina's National Vulnerability Database (CNVDB) is urging developers to uninstall recent Claude Code versions over concerns that they can gather sensitive user data without consent. The "backdoor code" can collect details such as a user's location and identity, and forward them to remote servers. The agency said the alert only applies to Claude Code versions 2.1.91 (April 2) to 2.1.196 (June 29). "It is recommended that relevant units and users immediately conduct a comprehensive investigation," CNVDB said. "For development terminals with the above-mentioned affected versions installed, immediately uninstall or upgrade to the latest secure version with the relevant backdoor code removed; strengthen the control of external access permissions and traffic monitoring of development tools within core business network segments to prevent the unauthorized transmission of sensitive data." The disclosure comes shortly after a report that Claude contained covert code designed to prevent Chinese AI companies from extracting details about its inner workings. Anthropic subsequently said it was an experiment to protect against model distillation. Teams support lureA social engineering campaign has combined email phishing with a fake IT support scam abusing Microsoft Teams calls to deliver EtherRAT. "The attack lures the victim with a fake 'Employee Survey' email and PDF, then pivots to a Microsoft Teams call from an actor impersonating a 'System Administrator,'" Palo Alto Networks Unit 42 said. "The actor abuses Teams remote control (give/request control) to control the victim's machine, then guides the victim to install different remote RMM tools to establish persistence - HopToDesk and AnyDesk. The actor uses cmd.exe > curl.exe to download a malicious MSI (v7.msi) from camorreado[.]click and execute it. The MSI is a multi-stage loader that downloads a legitimate Node.js runtime, decrypts an embedded payload through a multi-step cipher chain, and runs EtherRAT." Scattered Spider linkThe notorious cybercrime group known as Scattered Spider is called by various names, including Octo Tempest, Muddled Libra, and UNC3944. Group-IB, which designated the term 0ktapus to a social engineering attack campaign targeting Twilio in August 2022, said Scattered Spider can be best described as a decentralized cybercrime collective analogous to The Com, with 0ktapus acting as a sub-cluster within the group. Scattered Spider comprises smaller clusters that are united by the use of shared tradecraft and English as a common language, but act separately. "Physical device theft activity from mobile carrier stores has been observed in at least one subcluster, for SIM swapping purposes," Group-IB said. "Subclusters target all kinds of sectors, either as end-targets for direct exploitation or as stepping stones to gather intelligence or tools for future attacks." The end goal of these attacks is cryptocurrency theft and ransomware, leading to extortion. LINE espionage schemeTaiwanese authorities have charged two local businessmen with allegedly assisting Chinese government-linked hackers carry out a sprawling espionage campaign targeting politicians, academics, journalists, and civil society groups. The suspects are believed to have run a company that collected and leased accounts for the LINE messaging app to operators linked to China's cyber forces. The accounts were then used to impersonate international journalists and build trust with targets and ultimately deliver malware designed to compromise their computers. The LINE accounts were rented by a Chinese firm named Xiamen Empress Information Technology. Meta phishing abuseAn unknown threat actor is manipulating Meta's Business Account Manager to send spam emails that bypass email filters since at least November 2025 and trick victims into providing their Meta account details to the attacker on attacker-controlled web pages. The emails were sent from a Meta business account. "Starting in June, they modified their phishing lure to incorporate a chatbot, run through a fraudulent account on Facebook Messenger, and began sending credentials to a private Telegram channel," Huntress said. "The phishing campaign appears to target businesses and attempts to capture credentials, MFA codes, business and personal phone numbers, email addresses, and an image of the target's ID or passport." Meta has since taken steps to plug the attack method. Windows LPE chainIn August 2025, SafeBreach researcher Ron Ben Yizhak disclosed details of an issue (CVE-2025-49760) in Microsoft's Windows Remote Procedure Call (RPC) communication protocol that could be abused by an attacker to conduct spoofing attacks and impersonate a known server. Then, in October 2025, Microsoft addressed another vulnerability tracked as CVE-2025-59200, which has been described as a spoofing flaw in the Data Sharing Service Client. "By exploiting a vulnerability in the Data Sharing Service (DsSvc) – tracked as CVE-2025-59200 – an attacker can spoof an RPC server, then send a hotkey that bypasses User Interface Privilege Isolation (UIPI) to start a scheduled task," Ben Yizhak said. "The task sends an RPC request to the spoofed server of the attacker and the response injects an XML into a toast notification to elevate privileges from low to medium integrity." Kernel driver flawsMultiple vulnerabilities have been disclosed in RtsPer.sys, an SD card reader driver developed by Realtek. These vulnerabilities enable non-privileged users to leak the contents of the kernel pool and kernel stack, write to arbitrary kernel memory, and read and write physical memory from user mode via the DMA capability of the device, per a security researcher who goes by the name "zwclose." The issues impact many OEMs, including Dell, Lenovo, and possibly other laptops equipped with an SD card reader manufactured by Realtek. The issues have been assigned the CVEs: CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40431, and CVE-2024-40432. The complete set of fixes was released by Realtek in August 2024. New ransomware behaviorRansomware attacks that deploy WhiteLock involve the locker communicating with external servers during the encryption process and terminating Services related to remote access tools, such as AnyDesk and TeamViewer, to prevent victims from responding remotely. "After registering an infected device, WhiteLock checks whether AnyDesk and TeamViewer are installed on the victim's device," AhnLab said. "If these tools are present, it terminates the relevant Services in subsequent stages. This behavior is interpreted as an attempt to prevent security personnel or administrators from isolating the infected system or responding in real time through remote access tools." Another new ransomware entrant is Prinz Eugen, which was first detected in May 2026. "The encryptor is freshly built, written in Go, and more technically deliberate than many first-wave ransomware samples," Threatdown said. "It performs recursive encryption, prioritizes recently modified files, uses ChaCha20-Poly1305 with integrity checks, and leaves no ransom note on disk." The ransomware is advertised by a threat actor named ROOTBOY on underground forums, who has previously engaged in data sale and extortion activity between July and November 2025. The development comes as the Bumblebee malware loader, deployed via SEO poisoning through a trojanized installer for ManageEngine OpManager, has been leveraged by threat actors to drop AdaptixC2, which then acts as a conduit for Akira ransomware deployment. Chrome extension hijackCybersecurity researchers have flagged a new browser-based threat dubbed GhostChrome-X that uses Google Chrome to establish and maintain access to compromised hosts. "Two aspects in particular make GhostChrome-X noteworthy. First, the malware directly targets Chrome's extension trust model by modifying protected configuration files and forging the integrity metadata required for Chrome to accept an attacker-controlled extension as a legitimate browser component," Rubrik Zero Labs said. "Second, rather than functioning solely as a data-stealing extension, GhostChrome-X integrates browser-based access with operating system-level command execution, enabling the browser to serve as a persistent platform for ongoing attacker operations." Once active, the malware establishes persistence using scheduled tasks and Registry Run keys, while communicating with an external server to collect browser cookies, browsing history, and submitted form data. It also supports remote command execution on the infected system and "monitors WebAuthn activity and enables attacker-controlled interactions with WebAuthn-enabled websites from within the victim's browser session." Tax refund RAT lureA phishing and malware campaign is using Indian Income Tax Return (ITR) refund lures to deliver a multi-stage AutoIt infection chain that leads to the deployment of AsyncRAT. The campaign has targeted financial and technology organizations. "The operation is notable for the way it combines credible email delivery, compromised web infrastructure, Dropbox-hosted payloads, password-protected archives, AutoIt staging, sandbox-aware execution, persistence, process injection, and a final .NET RAT payload," ZeroBEC said. "More recent samples shifted to LX RAT, a commercially marketed remote access trojan protected by the LX Crypter / LX Protector ecosystem." Fraudulent tax assessment notifications have also been used to distribute a trojan-like payload to targeted users using DLL side-loading techniques. The rogue DLL features persistence mechanisms, system information discovery, user activity monitoring, dynamic payload execution, and encrypted command-and-control (C2) communication. "The observed capabilities -- including modular payload loading, encrypted communication, persistence mechanisms, and remote execution functionality -- indicate that the campaign is designed to establish unauthorized access to and maintain control over compromised hosts," CYFIRMA said. Fileless Remcos loaderAnother campaign targeting India, this time using GST-themed ZIP archive lures to deliver a variant of the Remcos RAT malware family. "One notable characteristic of this infection chain was its reliance on in-memory execution techniques / fileless malware and Steganography," K7 Labs said. "By avoiding disk-based artifacts, the threat reduces forensic evidence and increases its ability to evade traditional security tools and signature-based detection methods." Teams access phishAn active phishing campaign is using Microsoft Teams-themed lures to distribute a legitimate remote access tool configured for unauthorized access. "Victims are directed to convincing landing pages that impersonate collaboration and productivity services, where they are prompted to download software presented as a meeting transcript viewer, recording utility, or document-related application," CYFIRMA noted. "The use of compromised business websites provides reputational legitimacy, while dedicated infrastructure enables rapid deployment and campaign scalability. The operation demonstrates active maintenance, with the majority of identified infrastructure observed within the last three to six months, indicating continued development and operational investment." ADFS token forgery riskGoogle-owned Mandiant has revealed that "when ADFS certificates are manually rotated, configuration drift can silently leave active signing keys exposed in Machine DPAPI," adding "in environments where AutoCertificateRollover is disabled, and certificates are manually rotated, the database often becomes a 'ghost'—a record that still exists, still decrypts successfully, but references a certificate no longer used for token signing by the ADFS service." The tech giant has warned that the technique could be exploited by bad actors to forge high-privilege SAML tokens. Cloud exfiltration controlsAmazon Web Services (AWS) has emphasized the need for a layered strategy for egress security and to prevent data exfiltration. "Without egress controls in place, that outbound traffic can flow freely, and the unauthorized access might go unnoticed until a compliance audit, customer complaint, or incident notification forces discovery," AWS said. The risk is compounded by agentic AI systems, in which an unauthorized party can manipulate an autonomous agent’s objectives to silently exfiltrate data and achieve code execution. "As organizations deploy AI agents with access to tools, APIs, and code interpreters, these agents become high-value targets, and their outbound network activity must be constrained with the same rigor as any other workload," AWS said. Cloud data reroutingPalo Alto Networks Unit 42 has identified a bucket hijacking technique that impacts major cloud service providers. It has been described as a fundamental architectural flaw. "An attacker can silently compromise an organization's active data streams by rerouting data into an external storage bucket," Unit 42 said. "Because a storage bucket name is globally unique, an attacker can simply delete the bucket and then recreate it under the attacker's own account using the same name. This, therefore, creates a global namespace risk. This bucket hijacking reroutes critical logs and sensitive data directly to the attacker's environment." A similar attack method, dubbed Bucket Monopoly, was detailed by Aqua Security in 2024. There is no evidence that the attack technique has been abused in the wild. In recent weeks, Unit 42 has also warned that: (1) insecure default configurations and overly permissive enrollment rights in Active Directory Certificate Services (AD CS) can be exploited for privilege escalation, unauthorized identity impersonation, and persistence; (2) Kubernetes identities can be abused in combination with exposed attack surfaces to escalate privileges from initial access to sensitive backend cloud infrastructure; (3) multi-agent AI systems can introduce new pathways for exploitation through inter-agent communication and orchestration via prompt injection due to a model's inability to reliably differentiate between developer-defined instructions and adversarial user input, and a lack of agent capability scoping and tool input sanitization; (4) Amazon Bedrock AgentCore's Code Interpreter sandbox network isolation mode can be bypassed to allow sending and receiving of data from external endpoints via DNS tunneling by taking advantage of a lack of session token enforcement; and (5) AgentCore starter toolkit's auto-create logic generates identity and access management (IAM) roles that grant privileges broadly across the AWS account, rather than being scoped to individual resources, effectively introducing what's called an Agent God Mode that makes it possible to escalate privileges and compromise every other AgentCore agent within the AWS account. The useful lesson this week is not “watch for weird behavior.” Weird is late. By then the fake support call has a session, the package has run, the bucket is gone, and the quiet process already has somewhere to send data. Watch the normal paths instead. Names that look almost right. Tools asking for slightly too much. Services that still trust old state. Traffic that should have had nowhere to go. Most of the damage here did not need magic. It needed permission, habit, and nobody looking closely enough.
thehackernews.comJul 9, 2026extracted
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide. The exposed data was first discovered by security researcher Bob Diachenko, who says he found a server containing what appeared to be valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords. According to screenshots and information shared by Diachenko, the database contains entries for Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, and many others. "Massive Fortinet/FortiGate bruteforce/active exploitation campaign uncovered in action," Diachenko posted on LinkedIn. "Thousands of top vendors instances are listed in the files like this (see screenshot). This one alone has 21,634 domain names - from Chevron to Fortinet itself. All - with potentially working passwords to the FortiGate appliances obtained through various menas." The exposed data also included comments listing each organization's industry, revenue, and number of employees, likely for planning attacks. Diachenko later shared additional information that claimed the operation was conducted by a Russian-speaking multi-operator threat group that harvested credentials for FortiGate SSL VPN devices. According to Diachenko's investigation, the attackers allegedly conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets and an additional 2.1 billion attempts against 163,650 Microsoft SQL Server systems. He further claimed the threat actors intercepted SSL VPN authentication hashes, cracked them using a 45-GPU cluster managed through Hashtopolis, and used the recovered credentials to move laterally into internal Active Directory environments. Diachenko told BleepingComputer he obtained these details after analyzing additional files inadvertently exposed on the same server. "They accidentally left an open directory with artefacts, connection strings, tooling, scripts and data online. Analytics obtained via their cron jobs, bash histories, logs etc," Diachenko explained. The researcher also stated that multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey were fully compromised, including a Turkish NATO defense contractor from which classified documents were allegedly stolen. Threat intelligence company Hudson Rock has since published its own analysis of the exposed data after receiving the dataset from Diachenko. The company described the collection as one of the largest known troves of compromised Fortinet-related credentials. According to Hudson Rock, the dataset contains 73,932 unique firewall URLs across 194 countries and impacts 21,632 unique domains. The company says the attackers maintained detailed logs of successful compromises and assembled a database containing verified credentials for organizations across nearly every major industry sector. Among the organizations Hudson Rock says appear in the dataset are Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, and numerous government agencies and critical infrastructure operators. The company also released statistics showing that the highest number of affected devices was in India, the United States, Taiwan, Mexico, Turkey, Thailand, Colombia, Malaysia, Chile, and the United Arab Emirates. The most common sectors for the listed companies are telecommunications, IT services, financial services, government organizations, healthcare providers, educational institutions, and manufacturing. One strange aspect of the leak is that many of the exposed credentials were long, complex passwords that would ordinarily be considered difficult to crack. Believed to be extracted from Fortinet configs Cybersecurity researcher Kevin Beaumont independently reviewed portions of the exposed data and told BleepingComputer that some of the credentials are authentic. "I have been able to confirm the authenticity of some of the admin logins and passwords - this looks like a real dump," Beaumont said. After further review of the data shared by Hudson Rock, Beaumont published additional findings indicating that the dataset contains credentials for roughly 75,000 Fortinet devices, most of which remain online. According to Beaumont, the data appears to have originated from exported Fortinet configurations because it contains information, including email addresses, that is typically only accessible through configs. He also said the affected IP addresses are different from those in the 2025 Belsen Group Fortinet leak, further indicating that this is a more recent and larger collection of compromised devices. Beaumont said he verified that multiple organizations listed in the dataset were using valid credentials and observed that many affected devices were running relatively recent FortiOS versions. "The data is legit. It is around 75k devices. Almost all are still online, and Fortinet devices. It appears to be recent data," Beaumont wrote. Based on network data from Shodan, Beaumont says the leak contains approximately half of all internet-accessible Fortinet firewalls and said that a majority of the affected devices expose their FortiGate management interfaces directly to the internet. The source of the configuration data remains unknown, with it unclear whether it was stolen through previously disclosed Fortinet vulnerabilities, a newly discovered flaw, or another method. Neither Diachenko, Hudson Rock, nor Beaumont have identified how the configuration data was originally obtained. Hudson Rock has created a free FortiBleed lookup tool to check if your organization is impacted. Organizations in the dataset should immediately rotate passwords associated with Fortinet VPN and administrative interfaces, enforce MFA, examine gateway logs for suspicious activity, and monitor for exposed employee credentials. BleepingComputer contacted Fortinet regarding the exposed dataset and will update this article if we receive a response. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 17, 2026extracted
3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs
Three recently patched Fortinet FortiSandbox vulnerabilities are being targeted in the wild, according to exploit intelligence company Defused. Defused’s honeypots have been seeing attempts to exploit CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089. CVE-2026-39813 and CVE-2026-39808 were both rated ‘critical severity’ and patched in April. The former allows an attacker to bypass authentication, while the latter is an OS command injection flaw that can be exploited to execute arbitrary code or commands. CVE-2026-25089 was patched by Fortinet with its June 2026 Patch Tuesday updates. It allows a remote, unauthenticated attacker to execute arbitrary commands on vulnerable appliances. Exploitation of CVE-2026-39808 was independently observed by KEVIntel on June 12. Both Defused and KEVIntel reported seeing attacks targeting CVE-2026-39813 on June 15. Defused noted that the exploit for CVE-2026-25089 appears to have been created using AI and did not work when first observed by the company. Defused recently also saw exploitation of two Fortinet FortiClient EMS vulnerabilities tracked as CVE-2026-21643 and CVE-2026-35616. Compromised Fortinet firewalls Separately, SOCRadar has detected more than 30,000 compromised Fortinet firewalls that expose corporate networks to hacking. The campaign has been dubbed FortiBleed. According to the security firm, a threat actor has been systematically hacking Fortinet firewalls and VPN gateways, compiling a database of verified credentials that can be used to access them. The compromised systems belong to companies and government organizations across more than 190 countries. Many of the devices are located in India and the United States. “The attackers scan the internet for Fortinet devices, try a curated list of known passwords against each one, and record every successful login,” SOCRadar explained. “Once a device is compromised, they use it as a listening post, monitoring traffic passing through and collecting any additional credentials that flow by. Those freshly collected passwords are then fed back into the scanner to compromise even more devices. The system feeds itself.” The threat actor left its server exposed, enabling researchers to collect data on its infrastructure and targets. “Among the recovered data were credentials for what appears to be a defense industry VPN endpoint, suggesting the group’s ambitions extend beyond purely financial targets,” SOCRadar noted. While the company has yet to attribute the attack to a known threat actor, it believes the hackers are likely Russian speakers. The FortiBleed activity was also analyzed by researcher Bob Diachenko and cybersecurity firm Hudson Rock. Hudson Rock said the campaign appears to impact major companies such as Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, and Oracle. *updated to mention that Diachenko and Hudson Rock are also monitoring the FortiBleed campaign Related: Fortinet, Ivanti Patch Critical Vulnerabilities Related: Fortinet Patches High-Severity Vulnerabilities Related: Fortinet Patches Exploited FortiCloud SSO Authentication Bypass
securityweek.comJun 17, 2026extracted
Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small, repeated batches and routing it through Dropbox and OneDrive so the traffic blended into normal cloud activity. Symantec and Carbon Black's Threat Hunter Team reported the campaign this week. This points to espionage, not a money grab: Symantec said the commands indicate intelligence collection, not theft for profit. Neither the executive nor the exchange was named. The value is plain enough: an exchange executive's inbox can hold non-public listing details, enforcement matters, deal terms, market-moving plans, plus the executive's calendar and contacts. Five months of quiet access handed the attacker a detailed read on the executive's dealings and where the organization was heading, without needing broad access to other business systems. The first malicious activity showed up on October 10, 2025. By then, the attacker was already running two binaries as SYSTEM, the highest Windows privilege level, one faking Adobe's updater and the other faking OneDrive. By the time defenders noticed anything, the intruder had full control of the machine, and how they first got in is still unknown. However, Symantec confirmed that the first signs likely came from lateral movement off a previously compromised device. The operation kicked into gear on November 12. The attacker pulled a Dropbox API token, started uploading data with curl, and deployed the main tool: a mailbox stealer built on Aspose, a legitimate .NET library that reads Outlook OST and PST files. Wrapped in an executable, it converted the mailbox to PST and wrote it to disk, run each time with a password and a date-range flag. The first run grabbed everything from August 2025 on. After that the attacker came back every two to four weeks, each run taking only the days since the last one, eight more pulls through February 17, 2026. The result is a near-continuous copy of the mailbox, sliced thin enough not to draw attention from security software. The stealth came from making the work look ordinary. Scheduled tasks posed as Adobe, Lenovo and OneDrive system services. For exfiltration the attacker used Dropbox and OneDrive Personal, and for OneDrive they connected to hard-coded Microsoft IP addresses instead of the onedrive.live.com hostname, so there were no DNS lookups for a perimeter tool to catch or block. The attacker also tested the public file host temp.sh once in November, then dropped it. The last observed activity, on March 19, 2026, was a new backdoor that was staged but never run, which Elias said may mean the attacker lost access soon after. Symantec's published indicators point to a wider intrusion kit, not just a mailbox grabber: FRPC for tunneling traffic out, Secretsdump for pulling Windows credentials, SharpDecryptPwd for recovering saved app passwords, and a tool to bypass Windows User Account Control. The report does not say how each was used here, and none of them point to a specific group. There is no CVE in this story. It was an intrusion against a person's mailbox, not the exploitation of a freshly disclosed flaw, which is part of why it is worth reading: no patch closes this, and the burden shifts to monitoring and response. Attribution is unresolved too. The mix of public tooling and consumer cloud services left little to tie the activity to a known actor, and that stays open until a stronger source says otherwise. Routing exfiltration through Dropbox and OneDrive to blend in is a well-worn play, and one Microsoft has flagged as a deliberate way to slip past perimeter defenses and muddy attribution. If you defend an exchange, a regulator, or any firm sitting on market-moving information, feed the hashes in now and watch for the behavior behind them: unusual mailbox export activity, odd Outlook access, uploads to personal Dropbox or OneDrive accounts, unexpected tunneling, and credential-dumping on systems tied to privileged users.
thehackernews.comJun 4, 2026extracted
Hackers Target Global Stock Exchange in Espionage Operation
Hackers gained access to the email account of a senior executive at a major global stock exchange and exfiltrated data for months. The attack, investigated by Broadcom’s Symantec and Carbon Black threat-hunting team, began in October 2025, and the threat actor retained access to the compromised Outlook mailbox until March 2026. The security experts estimate that the dwell time was roughly 150 days. The goal of the operation was most likely espionage, but Symantec and Carbon Black did not share any information about who may have been behind the attack or which stock exchange was targeted. “For an espionage actor, a senior executive’s mailbox is a high-value intelligence target. An Outlook profile may yield details of external negotiations, internal deliberations, the executive’s calendar, travel pattern, and their contacts,” the researchers said. “Organizations such as exchanges and regulators may hold non-public information about listings, enforcement actions and market-moving events. Months of unfettered access to that mailbox lets an attacker build a near-complete picture of the target’s working life and the organization’s near-term direction without ever having to move laterally elsewhere on the network,” they added. The initial access vector remains unknown, but the first signs of malicious activity were seen on October 10, 2025, when malware had already been running on the compromised host, disguised as Adobe and OneDrive applications. Command-and-control (C&C) channels were established on November 12, when the attacker also began collecting and exfiltrating data. To avoid raising suspicion, they used Dropbox and OneDrive to exfiltrate files, transferring only small batches at a time. “The cumulative effect over the five months observed is a complete, near-continuous theft of the user’s Outlook mailbox, broken into incremental archives small enough not to draw attention from security software,” the researchers explained. The attacker continuously worked on persistence, regularly re-registering tasks disguised as Adobe, Lenovo, and OneDrive system services to maintain access. Symantec and Carbon Black made indicators of compromise (IoCs) available to help other organizations detect potential attacks. Related: Sophisticated Deep#Door Backdoor Enables Espionage, Disruption
securityweek.comJun 3, 2026extracted
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks. "External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks," Ivanti said in an advisory. Fortinet published advisories for two critical shortcomings affecting FortiAuthenticator and FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that could result in code execution - CVE-2026-44277 (CVSS score: 9.1) - An improper access control vulnerability in FortiAuthenticator that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. (Fixed in FortiAuthenticator versions 6.5.7, 6.6.9, and 8.0.3) CVE-2026-26083 (CVSS score: 9.1) - A missing authorization vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI that may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. (Fixed in FortiSandbox versions 4.4.9 and 5.0.2, FortiSandbox Cloud version 5.0.6, and FortiSandbox PaaS versions 4.4.9. and 5.0.2) SAP also shipped fixes for two critical vulnerabilities - CVE-2026-34260 (CVSS score: 9.6) - An SQL injection vulnerability in SAP S/4HANA CVE-2026-34263 (CVSS score: 9.6) - A missing authentication check in the SAP Commerce cloud configuration "The vulnerability is caused by an overly permissive security configuration with improper rule ordering, allowing an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution," Onapsis said about CVE-2026-34263. On the other hand, CVE-2026-34260 could be exploited by an attacker to inject malicious SQL statements and potentially impact the confidentiality and availability of the application. However, since the affected code only allows read access to data, the vulnerability does not compromise the integrity of the application. "It allows a low-privileged, authenticated attacker to inject malicious SQL code via user-controlled input, potentially exposing sensitive database information and crashing the application," Pathlock said. Patches have also been released by Broadcom for a high-severity flaw in VMware Fusion (CVE-2026-41702, CVSS score: 7.8) that could pave the way for local privilege escalation. The issue has been addressed in version 26H1. "VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary," Broadcom said. "A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed." Round off the list is a set of five critical vulnerabilities impacting n8n - CVE-2026-42231 (CVSS score: 9.4) - A vulnerability in the xml2js library used to parse XML request bodies in n8n's webhook handler that allows prototype pollution via a crafted XML payload, enabling an authenticated user with permission to create or modify workflows to achieve remote code execution on the n8n host. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-42232 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node, leading to remote code execution when combined with other nodes exploiting the prototype pollution. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-44791 (CVSS score: 9.4) - A bypass for CVE-2026-42232 that could result in remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44789 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node, leading to remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44790 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation, enabling an attacker to read arbitrary files from the n8n server and resulting in full compromise. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) Software Patches from Other Vendors Security updates have also been released by other vendors over the past several weeks to rectify various vulnerabilities, including - ABB Adobe Amazon Web Services AMD Apple ASUS Atlassian Axis Communications AVEVA Canon Cisco CODESYS ConnectWise Dell Devolutions Drupal F5 Fortra Foxit Software Fujitsu GitLab GnuTLS Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Intel Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Meta WhatsApp Microsoft Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA OPPO Palo Alto Networks Phoenix Contact Phoenix Technologies Progress Software QNAP Qualcomm React Ricoh Samsung Schneider Electric Siemens Sophos Spring Framework Supermicro Synology Tenable TP-Link WatchGuard Zoom, and Zyxel
thehackernews.comMay 18, 2026extracted
[GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th)
[This is a Guest Diary by Joshua Nikolson, an ISC Intern and part of the SANS.edu Bachelor's degree in Applied Cybersecurity (BACS) program.] Introduction One day at work, a friend messaged me, “How do you check a website to see if it’s legit?” This friend recently received a phishing text message from a “bank”, and I figured he wanted to be careful and double-check. I told him to put the URL into VirusTotal but said that just because it may say it’s clean, that doesn’t mean it’s not malicious. He sent me a screenshot of the VirusTotal page for the URL, with no detections and everything showing green. I took a moment to look at it a little more closely. The domain name was unusual, and right off the bat I could see it had been created in the last few months. As of now, it has one detection from a vendor. All domains mentioned in this blogpost will be listed in the Indicators of Compromise section at the end. Going to the site, I could immediately tell that something was off about it. It was a secondhand marketplace that seemed to sell just about everything under the sun, with tons of listings in each category and items priced too good to be true. While the site had that “AI vibecoded feeling”, I wanted to give my friend something more concrete other than “don’t trust this site”. I decided to reverse image search one of the product images, a Lenovo ThinkPad battery replacement, and after some digging, I found an eBay listing with all the same product images and item descriptions. I did this for a few more of the site’s listings and came to the same result. I let my friend know, and he said, “Yeah, it looked too good to be true”. Finding a Marketplace I found this interesting and wanted to see if I could find something similar again. Today, it is trivial to use AI to mass-deploy these scams, and I wanted to see what would happen if I tried to buy something. Let’s look up what my friend was originally looking for: a Texas Instruments TI-nSpire CAS calculator. Simply searching on Google and going to the second page, something pops out to me. Why is a driving school selling a calculator? The search result link, hxxps://desidrivingschool[.]com/listing/164903741/ redirects to a marketplace where it is for sale: This domain looks suspicious on its own, and to add insult to injury, it was registered ~12 days ago on April 3rd, 2026: What's happening here? You may be asking why this Desi Driving School is showing up in the search results for this calculator? Good question. If you append “/sitemap.xml” to the URL, you can see tons of these listings that are meant to infiltrate the search results. This is a prime example of SEO poisoning, in which potential victims are lured through their shopping searches to these fake marketplaces. Threat actors have previously used compromised WordPress sites as command-and-control infrastructure or to stage payloads, but this is being used as a distinct attack vector. Unfortunately, this website was likely compromised, whether through something like a malicious WordPress plugin or stolen credentials, and is now being used to drive traffic to this malicious marketplace: You can see the range of products that this site offers. They must have a good distribution network. While reverse-image searching for images of the calculator, I found another similar posting on a different fake marketplace. Same images, same description and title, same exact setup with a redirect… And another… with what looks like loads of other compromised sites being used. You can endlessly find these sites by searching any description of a product listed with quotes in Google to find the real item that is being sold and copied from, such as this blazer: If the price was higher than the actual listing, you might think the scheme is just scraping listings, posting them at a higher price, then purchasing the cheaper item and shipping it. However, I do not think that is the case. Let’s try to buy this Eddie Bauer blazer with a fake identity and a fake debit card from Privacy.com and see what happens. Right away, I can tell this checkout page is a replica of the Shopify checkout page and looks almost identical. Choosing Mastercard, we’ll check out and pay now. Let’s prepare my fake card. Creating a temporary debit card with a $5 spending limit is extremely easy with Privacy.com, and I have my Mastercard ready. First, I am instructed to enter my card here: Then I get redirected to this page and must enter my information again: After hitting pay now, a loading screen with a different URL is shown that reminds me of the PayPal loading screen: And then I am redirected to a thank-you page for my order, despite the card being declined, which they know because it shows failure_code=failed in the URL. Only one declined charge was seen on my card. However, in other testing instances, I have seen an additional charge at a different price than the “advertised product”. The above screenshot is from the order we just made, and this next screenshot is from a different test where two charges were attempted right away on order: It seems that shirleymcgrady is another similar site, but probably used as the main checkout for the other smaller sites. The loading page domain from the payment was also created recently, 1 month ago, with one detection on VirusTotal. Aftermath A few days after I tried to check out, multiple other charges were attempted on the card: The clear objective of the scam here is to have the victim make a payment for an item that will never be shipped, resulting in their personal and payment information being stolen. I can only imagine how many people were duped by these marketplaces, considering their popularity, and it must be paying off for the attackers. With the evolving expertise of AI tools and technology in general, attackers can create these campaigns in a matter of seconds. This takes advantage of the average person’s trust by having a high-ranking site in the search results, images that look real (because they are real, and stolen), and a site that seems trustworthy enough for someone to enter their card details. I would love to take this a step further and use a card with more funds to purchase a lower-cost item to see how different, if at all, the result would be. It is also fun to hunt down these different marketplaces and see how many you can find. Annoyingly, some of them use registrars that make it harder, not easier, to report abuse, but if anyone reading this would like to investigate this further, I would love to offer my help and see what we can do about it. Indicators of Compromise Marketplace Domains: sydney.nbcsi[.]com dryoff.onetoll[.]shop popeye.fivedemo[.]shop offup.japanhold[.]shop Redirector Domains: desidrivingschool[.]com curencares[.]in abralipedema.com[.]br Payment Page Domains: shirleymcgrady[.]com yzoqrbiuar[.]asia
isc.sans.eduMay 13, 2026extracted
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
Update: Added Microsoft's statement to the end of the first section of this article. Microsoft Defender is detecting legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, resulting in widespread false-positive alerts, and in some cases, removing certificates from Windows. According to cybersecurity expert Florian Roth, the issue first appeared after Microsoft added the detections to a Defender signature update on April 30th. Today, administrators worldwide began reporting that DigiCert root certificate entries were flagged as malware and, on affected systems, removed from the Windows trust store. According to a Reddit post about the false positives, the detected certificates are: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 DDFB16CD4931C973A2037D3FC83A4D7D775D05E4 On impacted systems, these certificates were removed from the AuthRoot store under this Registry key: HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\ These false positives have led to concern among Windows users, with some thinking their devices were infected and reinstalling the operating system to be safe. Microsoft has reportedly fixed the detections in Security Intelligence update version 1.449.430.0, and the most recent update is now 1.449.431.0. Other reports on Reddit indicate that the fix also restores previously removed certificates on affected systems. The new Microsoft Defender updates will automatically install, and Windows users can manually force an update by going into Windows Security > Virus and threat protection > Protection updates and clicking on Check for Updates. After publishing this article, Microsoft confirmed that the false positives were linked to detections for compromised certificates from a recent DigiCert breach. "Following reports of compromised certificates Microsoft Defender immediately added detections for malware in our Defender Antivirus Software to help keep customers protected. Earlier today we determined false positive alerts were mistakenly triggered and updated the alert logic," Microsoft told BleepingComputer. "Microsoft Defender suppressed and cleaned up the alerts for customer environments. Customers should update to Security Intelligence version 1.449.430.0 or later, but do not need to take additional action for these alerts. We have notified affected organizations and recommend administrators look for more details in the service health dashboard (SHD) within the M365 admin center." Linked to recent DigiCert breach The false positives occur shortly after a disclosed DigiCert security incident that enabled threat actors to obtain valid code-signing certificates used to sign malware. "A malware incident targeted a customer support team member. Upon detection, the threat vector was contained," explains the DigiCert incident report. "Our subsequent investigation found that the threat actor was able to procure initialization codes for a limited number of code signing certificates, few of which were then used to sign malware." "The identified certificates were revoked within 24 hours of discovery and the revocation date set to their date of issuance. As a precautionary measure, pending orders within the window of interest were cancelled. Additional details will be provided in our full incident report." According to DigiCert's incident report, attackers targeted the company's support staff in early April by creating support messages containing a malicious ZIP file disguised as a screenshot. After multiple blocked attempts, one support analyst's device was eventually compromised, followed by a second system that went undetected for a time due to an endpoint protection "sensor gap." Using access to the breached support environment, the hacker used a feature in DigiCert's internal support portal that allowed support staff to view customer accounts from the customer's perspective. While limited in scope, this access exposed "initialization codes" to previously approved, but undelivered, EV code-signing certificate orders. "Possession of an initialization code, combined with an approved order, is sufficient to obtain the resulting certificate (see Contributing Factors discussion below)," explained DigiCert. "Since the threat actor was able to obtain these two pieces of information for a finite set of approved orders, they were able to obtain EV Code Signing certificates across a set of customer accounts and CAs." DigiCert says it revoked 60 code-signing certificates, including 27 linked to a "Zhong Stealer" malware campaign. "11 were identified in certificate problem reports provided to DigiCert by community members linking the certificates to malware, and 16 were identified during our own investigation," explained DigiCert. Zhong Stealer malware campaign This aligns with earlier reports from security researchers who had observed newly issued DigiCert EV certificates used in malware campaigns and reported them to DigiCert. Researchers, including Squiblydoo, MalwareHunterTeam, and g0njxa, reported that certificates issued to well-known companies such as Lenovo, Kingston, Shuttle Inc, and Palit Microsystems were being used to sign malware. "What do Lenovo, Kingston, Shuttle Inc, and Palit Microsystems have in common?," posted Squiblydoo on X. "EV Certificates from these companies were issued and used by a Chinese crime group, #GoldenEyeDog (#APT-Q-27)!" The malware in this campaign is named "Zhong Stealer," though analysis indicates it may be more like a remote access trojan (RAT) than an infostealer. The researcher says the malware was distributed through the following attacks: Phishing emails deliver a fake image or screenshot A first-stage executable that displays a decoy image Retrieval of a second-stage payload from cloud storage such as AWS Use of signed binaries and loaders, including components tied to legitimate vendors After DigiCert disclosed the incident, the researchers said the incident report explains how the certificates used in these malware campaigns were obtained. It should be noted that the certificates flagged by Microsoft Defender are root certificates in the Windows trust store and do not match the revoked DigiCert code-signing certificates used to sign malware. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 3, 2026extracted
Shadow AI risks deepen as 31% of users get no employer training
Shadow AI risks deepen as 31% of users get no employer training Between one-fifth and one-third of workers use AI outside the influence and governance of the IT function, according to a global survey of 6,000 full-time employees at enterprise organizations. Researchers found a widening gap between employee AI adoption and the controls organizations have in place to manage it. The Lenovo Work Reborn Research Series 2026 report documents a workforce split into two groups: employees equipped with IT-managed tools, training, and oversight, and those operating independently with consumer AI services. Training and tooling gaps drive unsanctioned use Many employees report that their employers fail to supply either AI tools or training, and a sizable share of those who receive training describe it as irregular or ineffective. Half of all employees say better training would help them get more value from AI at work, pointing to a workforce ready to adopt AI faster than its employers can equip it. Employee enthusiasm for AI continues to climb. Seven in ten use AI tools at least a few times a week, and 80% expect their use of AI to increase over the next year. Lenovo’s research indicates that adoption is outpacing the capacity of enterprises to manage, enable, or align it. Security implications of unmanaged adoption The report identifies two security concerns tied to shadow AI. Bypassing compliance controls increases the risk that intellectual property or sensitive data are processed outside governed environments. Fragmented workflows produce inconsistent execution and uneven distribution of productivity gains across teams. Employee trust in enterprise-provided tools shows measurable cracks. A meaningful share of employees doubt the reliability of information produced by employer-provided AI tools, and a smaller group questions whether their privacy and personal data are safe when using them. Cybersecurity awareness among employees is uneven. Nearly half of employees are highly concerned about criminals using AI to develop sophisticated cyber attacks against their company, and the same percentage are highly concerned about themselves or a colleague accidentally leaking sensitive company information through public AI systems such as ChatGPT. Forty percent are highly concerned about deepfake videos and AI-generated phishing emails. Only 23% are highly concerned about criminals attacking their company’s AI systems directly, a gap that becomes consequential as organizations deploy AI agents and internal AI infrastructure. These employee perceptions track with separate findings from Lenovo’s CIO Playbook, which reports that 61% of IT leaders say AI is increasing cybersecurity risks and only 31% are confident in their ability to address those risks. What employees want from security teams Seventy-four percent of employees say more or better cybersecurity training on AI-related risks would reassure them that they and their organization are protected. Seventy-three percent say it would be reassuring to know their company’s cybersecurity team is using AI to address these risks. Seventy percent say stricter policies on how employees can use AI would provide reassurance. The report recommends building governance before scaling AI, embedding security awareness into the flow of work through continuous in-context learning, and standardizing the AI interface across workflows and endpoints.
helpnetsecurity.comMay 1, 2026extracted
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database commands. "The vulnerable ABAP program allows a low-privileged user to upload a file with arbitrary SQL statements that will then be executed," Onapsis said in an advisory. In a potential attack scenario, a bad actor could abuse the affected upload-related functionality to run malicious SQL against BW/BPC data stores, extract sensitive data, and delete or corrupt database content. "Manipulated planning figures, broken reports, or deleted consolidation data can undermine close processes, executive reporting, and operational planning," Pathlock said. "In the wrong hands, this issue also creates a credible path to both stealthy data theft and overt business disruption." Another security vulnerability that deserves a mention is a critical-severity remote code execution in Adobe Acrobat Reader (CVE-2026-34621, CVSS score: 8.6) that has come under active exploitation in the wild. That said, there are many unknowns at this stage. It is not clear how many people have been affected by the hacking campaign. Nor is there any information about who is behind the activity, who is being targeted, and what their motives could be. Also patched by Adobe are five critical flaws in ColdFusion versions 2025 and 2023 that, if successfully exploited, could lead to arbitrary code execution, application denial-of-service, arbitrary file system read, and security feature bypass. The vulnerabilities are listed below - CVE-2026-34619 (CVSS score: 7.7) - A path traversal vulnerability leading to security feature bypass CVE-2026-27304 (CVSS score: 9.3) - An improper input validation vulnerability leading to arbitrary code execution CVE-2026-27305 (CVSS score: 8.6) - A path traversal vulnerability leading to arbitrary file system read CVE-2026-27282 (CVSS score: 7.5) - An improper input validation vulnerability leading to security feature bypass CVE-2026-27306 (CVSS score: 8.4) - An improper input validation vulnerability leading to arbitrary code execution Fixes have also been released for two critical FortiSandbox vulnerabilities that could result in authentication bypass and code execution - CVE-2026-39813 (CVSS score: 9.1) - A path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. (Fixed in versions 4.4.9 and 5.0.6) CVE-2026-39808 (CVSS score: 9.1) - An operating system command injection vulnerability in FortiSandbox that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. (Fixed in version 4.4.9) The development comes as Microsoft addressed a staggering 169 security defects, including a spoofing vulnerability impacting Microsoft SharePoint Server (CVE-2026-32201, CVSS score: 6.5) that could allow an attacker to view sensitive information. The company said it's being actively exploited, although there are no insights into the in-the-wild exploitation associated with the bug. "SharePoint services, especially those used as internal document stores, can be a treasure trove for threat actors looking to steal data, especially data that may be leveraged to force ransom payments using double extortion techniques by threatening to release the stolen data if payment is not made," Kev Breen, senior director of threat research at Immersive, said. "A secondary concern is that threat actors with access to SharePoint services could deploy weaponised documents or replace legitimate documents with infected versions that would allow them to spread to other hosts or victims moving laterally across the organization." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD Apple ASUS AVEVA Broadcom (including VMware) Canon Cisco Citrix CODESYS D-Link Dassault Systèmes Dell Devolutions dormakaba Drupal Elastic F5 Fortinet Foxit Software FUJIFILM Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NETGEAR Node.js NVIDIA ownCloud Palo Alto Networks Phoenix Contact Progress Software QNAP Qualcomm Rockwell Automation Ruckus Wireless Samsung Schneider Electric Siemens SonicWall Splunk Spring Framework Supermicro Synology TP-Link WatchGuard, and Xiaomi
thehackernews.comApr 15, 2026extracted
Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
SAP has released security updates to address two critical security flaws that could be exploited to achieve arbitrary code execution on affected systems. The vulnerabilities in question listed below - CVE-2019-17571 (CVSS score: 9.8) - A code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) CVE-2026-27685 (CVSS score: 9.1) - An insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration "The application uses an outdated artifact of Apache Log4j 1.2.17 that is vulnerable to CVE-2019-17571," SAP security company Onapsis said. "It allows an unprivileged attacker to execute arbitrary code remotely on the server, causing high impact on confidentiality, integrity, and availability of the application." CVE-2026-27685, on the other hand, stems from missing or insufficient validation during the deserialization of uploaded content, which could allow an attacker to upload untrusted or malicious content. "Only the fact that an attacker requires high privileges for a successful exploit prevents the vulnerability from being tagged with a CVSS score of 10," Onapsis added. The disclosure comes as Microsoft shipped patches for 84 vulnerabilities across products, including dozens of privilege escalation and remote code execution flaws. On Tuesday, Adobe also announced patches for 80 vulnerabilities, four of which are critical flaws impacting Adobe Commerce and Magento Open Source that could result in privilege escalation and security feature bypass. Separately, it fixed five critical vulnerabilities in Adobe Illustrator that could pave the way for arbitrary code execution. Elsewhere, Hewlett Packard Enterprise put out fixes for five shortcomings in Aruba Networking AOS-CX. The most severe of the flaws is CVE-2026-23813 (CVSS score: 9.8), an authentication bypass affecting the management interface. "A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls," HPE said. "In some cases, this could enable resetting the admin password." "Exploitation of this Aruba vulnerability potentially gives attackers full control of AOS-CX network devices and the ability to compromise an entire system undetected," Ross Filipek, CISO at Corsica Technologies, said in a statement. "A successful compromise could lead to the disruption of network communications or the erosion of the integrity of key business services. This flaw is a reminder that vulnerabilities in network devices are becoming more common in today's hyper-connected world. When attackers gain privileged access to these devices, it puts organizations at significant risk." Software Patches from Other Vendors Security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD Arm Atlassian Bosch Broadcom (including VMware) Canon Cisco Commvault Dassault Systèmes Dell Devolutions Drupal Elastic F5 Fortinet Fortra Foxit Software GitLab Google Android and Pixel Google Chrome Google Cloud Google Pixel Watch Google Wear OS Grafana Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric Moxa Mozilla Firefox, Firefox ESR, and Thunderbird n8n NVIDIA Palo Alto Networks QNAP Qualcomm Ricoh Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Synology TP-Link Trend Micro WatchGuard Western Digital Zoom, and Zyxel
thehackernews.comMar 11, 2026extracted
Motorola turns to GrapheneOS for smartphone security upgrade
Motorola turns to GrapheneOS for smartphone security upgrade Motorola is strengthening smartphone security through a long-term partnership with the GrapheneOS Foundation, a mobile security nonprofit that develops a hardened operating system based on the Android Open Source Project. GrapheneOS includes protections designed to reduce entire classes of vulnerabilities, strengthen app sandboxing and system boundaries, and limit the impact of common exploits while maintaining a standard Android user experience. GrapheneOS is best suited for users who prioritize privacy, security architecture, and greater control over their device. The operating system is currently available only on Google Pixel devices. “By combining GrapheneOS’s pioneering engineering with Motorola’s decades of security expertise, real-world user insights, and Lenovo’s ThinkShield solutions, the collaboration will advance a new generation of privacy and security technologies,” the company said in the announcement. Specific GrapheneOS features planned for integration have not been disclosed. GrapheneOS developers noted that Motorola’s devices still do not meet the platform’s hardware requirements and that work is ongoing to bring them closer to those standards. According to Motorola, joint research, software enhancements, and new security capabilities will continue in the coming months as the partnership evolves.
helpnetsecurity.comMar 2, 2026extracted
Lenovo adds new AI-driven edge systems to ThinkEdge portfolio
Lenovo adds new AI-driven edge systems to ThinkEdge portfolio Lenovo expanded its ThinkEdge portfolio with a new generation of AI-driven edge computing solutions, including the compact and reliable ThinkEdge SE10n Gen 2, the AI-ready ThinkEdge SE30n Gen 2, the AI-powerhouse ThinkEdge SE60n Gen 2, and Lenovo’s first industrial all-in-one (AIO) Panel PC, the ThinkEdge SE50a. As enterprises push intelligence closer to operations to improve resilience, reduce latency, and keep sensitive data local, edge computing has become a critical layer between devices, infrastructure, and cloud. Lenovo’s ThinkEdge solutions are purpose-built, industrial-grade edge systems designed to run reliably in harsh, space-constrained environments where traditional servers or PCs are impractical. Powered by Intel Core processors with scalable AI options, the fanless rugged lineup features industrial design ideal for 24/7 operation in factories and warehouses, seamless connectivity with options for Wi-Fi 6E, cellular connectivity and more. Backed by Lenovo’s global supply chain, long lifecycle support, and enterprise-grade services, ThinkEdge solutions are engineered not just to deploy at scale, but to operate consistently over years of continuous use. “Edge computing is where we turn insights into outcomes, and our next-generation ThinkEdge solutions place the power of AI exactly where decision making happens,” says Marc Godin, VP & GM, WW OEM Solutions – IDG Commercial. “Powering real-world AI applications delivering real-time data means loss prevention and instant inventory insights in retail; visual inspection and predictive maintenance in manufacturing; imaging workflow support and operation insights in healthcare; and even crowd management and infrastructure monitoring in cities and venues,” added Godin. “Our latest ThinkEdge portfolio delivers a truly comprehensive suite of solutions designed with AI in mind, from intelligent gateways to high-performance edge computing systems,” states Sanjeev Menon, VP & GM, Desktop Computing Business. “AI at the edge must be intelligent, protected and manageable at scale, and our lineup delivers by combining the latest computing core components, critical manageability and protection capabilities, and vertical industry ruggedization to help customers turn insights into recommendations and action.” Edge AI – more adaptability and less latency Lenovo’s newest ThinkEdge lineup delivers optimized on-device AI, enabling businesses to act faster while removing reliance on cloud connectivity, decreasing latency, strengthening data privacy, and lowering operational costs. Spanning lightweight gateways to high-performance AI edge systems and operator interfaces, the ThinkEdge portfolio integrates into existing environments and can be remotely managed, allowing customers to start small and scale edge intelligence with confidence as their use cases evolve. The latest ThinkEdge portfolio includes: ThinkEdge SE10n Gen 2, a compact intelligent gateway that provides reliable mobile management where needed. Built for connectivity, data capture and lightweight edge analytics, the fanless nano gateway is easy to deploy and delivers essential performance for customers of all sizes without the commitment of large investments. ThinkEdge SE30n Gen 2, a versatile AI-ready gateway that turns data into decisions with real-time inferencing right next to the equipment. A rugged yet compact device built for real-world edge conditions, the fanless gateway optimizes the Intel Core processor to streamline device orchestration and fleet-level manageability for complex edge deployments. ThinkEdge SE60n Gen 2, a high-performance edge computer solution with AI capability that supports multi-camera vision, predictive analysis and autonomous workflows across industry and enterprise edge deployments. Powered by Intel Core Ultra processors with integrated AI accelerators delivering up to 97 TOPS, the device brings reliable edge AI to the most demanding conditions, including industry automation, commercial autonomous robots, smart retail, healthcare, transportation, and more. ThinkEdge SE50a, Lenovo’s first industrial all-in-one Panel PC that embeds local AI intelligence into operator stations, reducing complexity while enhancing visibility, control, and insight at the point of interaction. Built for demanding environments, the rugged AIO is available in three different sizes (12.1”, 15.6” or 21.5”). It can be expanded to fit individual needs and is Lenovo’s most intuitive interface for frontline operations. With its latest ThinkEdge portfolio, Lenovo is extending AI from the data center to the point of action, helping businesses turn operational data into real-world outcomes at the edge. Availability Lenovo ThinkEdge SE10n Gen 2 will be available in select markets worldwide starting July 2026. Lenovo ThinkEdge SE30n Gen 2 will be available in select markets worldwide starting April 2026. Lenovo ThinkEdge SE50n Gen 1 will be available in select markets worldwide starting June 2026. Lenovo ThinkEdge SE60n Gen 2 will be available in select markets worldwide starting April 2026.
helpnetsecurity.comFeb 23, 2026extracted
US lawyers fire up privacy class action accusing Lenovo of bulk data transfers to China
AI and ml Payments giant Stripe is about to drop over $7 billion to become a gateway to AI token salesAI gateways look promising as companies struggle with model orchestration ai and ml Anthropic says text watermarking scheme relies on inconsequential words'Shall I compare thee to a summer's afternoon' is the sort of thing this will make, and others look likely to adopt it AI and ML DeepSeek's innovative harness treats everything as a plug-inChinese AI labs keep moving forward while US labs play defense SECURITY Autonomous AI attacks pose 'clear and present danger' to critical infrastructureWeaponized agents could turn digital intrusions into kinetic disasters, experts warn off-prem Rent-a-GPU outfit Nebius promises rapid 1 GW powerup plan isn't nebulousAnd it'll jump through every financial hoop it can to get there Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
go.theregister.comFeb 17, 2026extracted
AI-Powered Knowledge Graph Generator & APTs, (Thu, Feb 12th)
Unstructured text to interactive knowledge graph via LLM & SPO triplet extraction Courtesy of TLDR InfoSec Launches & Tools again, another fine discovery in Robert McDermott’s AI Powered Knowledge Graph Generator. Robert’s system takes unstructured text, uses your preferred LLM and extracts knowledge in the form of Subject-Predicate-Object (SPO) triplets, then visualizes the relationships as an interactive knowledge graph.[1] Robert has documented AI Powered Knowledge Graph Generator (AIKG) beautifully, I’ll not be regurgitating it needlessly, so please read further for details regarding features, requirements, configuration, and options. I will detail a few installation insights that got me up and running quickly. The feature summary is this: AIKG automatically splits large documents into manageable chunks for processing and uses AI to identify entities and their relationships. As AIKG ensures consistent entity naming across document chunks, it discovers additional relationships between disconnected parts of the graph, then creates an interactive graph visualization. AIKG works with any OpenAI-compatible API endpoint; I used Ollama exclusively here with Google’s Gemma 3, a lightweight family of models built on Gemini technology. Gemma 3 is multimodal, processing text and images, and is the current, most capable model that runs on a single GPU. I ran my experimemts on a Lenovo ThinkBook 14 G4 circa 2022 with an AMD Ryzen 7 5825U 8-core processor, Radeon Graphics, and 40gb memory running Ubuntu 24.04.3 LTS. My installation guidelines assume you have a full instance of Python3 and Ollama installed. My installation was implemented under my tools directory. python3 -m venv aikg # Establish a virtual environment for AIKG cd aikg git clone https://github.com/robert-mcdermott/ai-knowledge-graph.git # Clone AIKG into virtual environment bin/pip3 install -r ai-knowledge-graph/requirements.txt # Install AIKG requirements bin/python3 ai-knowledge-graph/generate-graph.py --help # Confirm AIKG installation is functional ollama pull gemma3 # Pull the Gemma 3 model from Ollama I opted to test AIKG via a couple of articles specific to Russian state-sponsored adversarial cyber campaigns as input: CISA’s Cybersecurity Advisory Russian GRU Targeting Western Logistics Entities and Technology Companies May 2025 SecurityWeek’s Russia’s APT28 Targeting Energy Research, Defense Collaboration Entities January 2026 My use of these articles in particular was based on the assertion that APT and nation state activity is often well represented via interactive knowledge graph. I’ve advocated endlessly for visual link analysis and graph tech, including Maltego (the OG of knowledge graph tools) at far back as 2009, Graphviz in 2015, GraphFrames in 2018 and Beagle in 2019. As always, visualization, coupled with entity relationship mappings, are an imperative for security analysts, threat hunters, and any security professional seeking deeper and more meaningful insights. While the SecurityWeek piece is a bit light on content and density, it served well as a good initial experiment. The CISA advisory is much more dense and served as an excellent, more extensive experiment. I pulled them both into individual text files more easily ingested for processing with AIKG, shared for you here if you’d like to play along at home. Starting with SecurityWeek’s Russia’s APT28 Targeting Energy Research, Defense Collaboration Entities, and the subsequent Russia-APT28-targeting.txt file I created for model ingestion, I ran Gemma 3 as a 12 billion parameter model as follows: ollama run gemma3:12b # Run Gemma 3 locally as 12 billion parameter model ~/tools/aikg/bin/python3 ~/tools/aikg/ai-knowledge-graph/generate-graph.py --config ~/tools/aikg/ai-knowledge-graph/config.toml -input data/Russia-APT28-targeting.txt --output Russia-APT28-targeting-kg-12b.html You may want or need to run Gemma 3 with fewer parameters depending on the performance and capabilities of your local system. Note that I am calling file paths rather explicitly to overcome complaints about missing config and input files. The article makes reference to APT credential harvesting activity targeting people associated with a Turkish energy and nuclear research agency, as well as a spoofed OWA login portal containing Turkish-language text to target Turkish scientists and researchers. As part of it’s use of semantic triples (Subject-Predicate-Object (SPO) triplets), how does AIKG perform linking entities, attributes and values into machine readable statements [2] derived from the article content, as seen in Figure 1? Figure 1: AIKG Gemma 3:12b result from SecurityWeek article Quite well, I’d say. To manipulate the graph, you may opt to disable physics in the graph output toolbar so you can tweak node placements. As drawn from the statistics view for this graph, AIKG generated 38 nodes, 105 edges, 52 extracted edges, 53 inferred edges, and four communities. You can further filter as you see fit, but even unfiltered, and with just a little by of tuning at the presentation layer, we can immediately see success where semantic triples immediately emerge to excellent effect. We can see entity/relationship connections where, as an example, threat actor –> targeted –> people and people –> associated with –> think tanks, with direct reference to the aforementioned OWA portal and Turkish language. If you’re a cyberthreat intelligence analyst (CTI) or investigator, drawing visual conclusions derived from text processing will really help you step up your game in the form of context and enrichment in report writing. This same graph extends itself to represent the connection between the victims and the exploitation methods and infrastructure. If you don’t want to go through a full installation process for yourself to complete your own model execution, you should still grab the JSON and HTML output files and experiment with them in your browser. You’ll get a real sense of the power and impact of an interactive knowledge graph with the joint forces power of LLM and SPO triplets. For a second experiment I selected related content in a longer, more in depth analysis courtesy of a CISA Cybersecurity Advisory (CISA friends, I’m pulling for you in tough times). If you are following along at home, be sure to exit ollama so you can rerun it with additional parameters (27b vs 12b); pass /bye as a message, and restart: ollama run gemma3:27b # Run Gemma 3 locally with 27 billion parameters ~/tools/aikg/bin/python3 ~/tools/aikg/ai-knowledge-graph/generate-graph.py --config ~/tools/aikg/ai-knowledge-graph/config.toml --input ~/tools/aikg/ai-knowledge-graph/data/Russian-GRU-Targeting-Logistics-Tech.txt --output Russian-GRU-Targeting-Logistics-Tech-kg-27b.html Given the density and length of this article, the graph as initially rendered is a bit untenable (no fault of AIKG) and requires some tuning and filtering for optimal effect. Graph Statistics for this experiment included 118 nodes, 486 edges, 152 extracted edges, 334 inferred edges, and seven communities. To filter, with a focus again on actions taken by Russian APT operatives, I chose as follows: Select a Node by ID: threat actors Select a network item: Nodes Select a property: color Select value(s): #e41a1c (red) The result is more visually feasible, and allows ready tweaking to optimize network connections, as seen in Figure 2. ??????? Figure 2: AIKG Gemma 3:27b result from CISA advisory Shocking absolutely no one, we immediately encapsulate actor activity specific to credential access and influence operations via shell commands, Active Directory commands, and PowerShell commands. The conclusive connection is drawn however as threat actors –> targets –> defense industry. Ya think? ;-) In the advisory, see Description of Targets, including defense industry, as well as Initial Access TTPs, including credential guessing and brute force, and finally Post-Compromise TTPs and Exfiltration regarding various shell and AD commands. As a security professional reading this treatise, its reasonable to assume you’ve read a CISA Cybersecurity Advisory before. As such, its also reasonable to assume you’ll agree that knowledge graph generation from a highly dense, content rich collection of IOCs and behaviors is highly useful. I intend to work with my workplace ML team to further incorporate the principles explored herein as part of our context and enrichment generation practices. I suggest you consider the same if you have the opportunity. While SPO triplets, aka semantic triples, are most often associated with search engine optimization (SEO), their use, coupled with LLM power, really shines for threat intelligence applications. Cheers…until next time. Russ McRee | @holisticinfosec | infosec.exchange/@holisticinfosec | LinkedIn.com/in/russmcree Recommended reading and tooling: Semantic Triples: Definition, Function, Components, Applications, Benefits, Drawbacks and Best Practices for SEO Russian GRU Targeting Western Logistics Entities and Technology Companies Russia’s APT28 Targeting Energy Research, Defense Collaboration Entities References [1] McDermott, R. (2025) AI Knowledge Graph. Available at: https://github.com/robert-mcdermott/ai-knowledge-graph (Accessed: 18 January 2026 - 11 February 2026). [2] Reduan, M.H., (2025) Semantic Triples: Definition, Function, Components, Applications, Benefits, Drawbacks and Best Practices for SEO. Available at: https://www.linkedin.com/pulse/semantic-triples-definition-function-components-benefits-reduan-nqmec/ (Accessed: 11 February 2026).
isc.sans.eduFeb 13, 2026extracted
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms
It's Patch Tuesday, which means a number of software vendors have released patches for various security vulnerabilities impacting their products and services. Microsoft issued fixes for 59 flaws, including six actively exploited zero-days in various Windows components that could be abused to bypass security features, escalate privileges, and trigger a denial-of-service (DoS) condition. Elsewhere, Adobe released updates for Audition, After Effects, InDesign Desktop, Substance 3D, Bridge, Lightroom Classic, and DNG SDK. The company said it's not aware of in-the-wild exploitation of any of the shortcomings. SAP shipped fixes for two critical-severity vulnerabilities, including a code injection bug in SAP CRM and SAP S/4HANA (CVE-2026-0488, CVSS score: 9.9) that an authenticated attacker could use to run an arbitrary SQL statement and lead to a full database compromise. The second critical vulnerability is a case of a missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform (CVE-2026-0509, CVSS score: 9.6) that could permit an authenticated, low-privileged user to perform certain background Remote Function Calls without the required S_RFC authorization. "To patch the vulnerability, customers must implement a kernel update and set a profile parameter," Onapsis said. "Adjustments in user roles and UCON settings might be required to not interrupt business processes." Rounding off the list, Intel and Google said they teamed up to examine the security of Intel Trust Domain Extensions (TDX) 1.5, uncovering five vulnerabilities in the module (CVE-2025-32007, CVE-2025-27940, CVE-2025-30513, CVE-2025-27572, and CVE-2025-32467), and nearly three dozen weaknesses, bugs, and improvement suggestions. "Intel TDX 1.5 introduces new features and functionality that bring confidential computing significantly closer to feature parity with traditional virtualization solutions," Google said. "At the same time, these features have increased the complexity of a highly privileged software component in the TCB [Trusted Computing Base]." Software Patches from Other Vendors Security updates have also been released by other vendors in recent weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD AMI Apple ASUS AutomationDirect AVEVA Broadcom (including VMware) Canon Check Point Cisco Citrix Commvault ConnectWise D-Link Dassault Systèmes Dell Devolutions dormakaba Drupal F5 Fortinet Foxit Software FUJIFILM Fujitsu Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Thunderbird n8n NVIDIA Phoenix Contact QNAP Qualcomm Ricoh Rockwell Automation Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Spring Framework Supermicro Synology TP-Link WatchGuard Zoho ManageEngine Zoom, and Zyxel
thehackernews.comFeb 11, 2026extracted
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively Exploited
Microsoft on Tuesday rolled out its first security update for 2026, addressing 114 security flaws, including one vulnerability that it said has been actively exploited in the wild. Of the 114 flaws, eight are rated Critical, and 106 are rated Important in severity. As many as 58 vulnerabilities have been classified as privilege escalation, followed by 22 information disclosure, 21 remote code execution, and five spoofing flaws. According to data collected by Fortra, the update marks the third-largest January Patch Tuesday after January 2025 and January 2022. These patches are in addition to two security flaws that Microsoft has addressed in its Edge browser since the release of the December 2025 Patch Tuesday update, including a spoofing flaw in its Android app (CVE-2025-65046, 3.1) and a case of insufficient policy enforcement in Chromium's WebView tag (CVE-2026-0628, CVSS score: 8.8). The vulnerability that has come under in-the-wild exploitation is CVE-2026-20805 (CVSS score: 5.5), an information disclosure flaw impacting Desktop Window Manager. The Microsoft Threat Intelligence Center (MTIC) and Microsoft Security Response Center (MSRC) have been credited with identifying and reporting the flaw. "Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager (DWM) allows an authorized attacker to disclose information locally," Microsoft said in an advisory. "The type of information that could be disclosed if an attacker successfully exploited this vulnerability is a section address from a remote ALPC port, which is user-mode memory." There are currently no details on how the vulnerability is being exploited, the scale of such efforts, and who may be behind the activity. "DWM is responsible for drawing everything on the display of a Windows system, which means it offers an enticing combination of privileged access and universal availability, since just about any process might need to display something," Adam Barnett, lead software engineer at Rapid7, said in a statement. "In this case, exploitation leads to improper disclosure of an ALPC port section address, which is a section of user-mode memory where Windows components coordinate various actions between themselves." Microsoft previously addressed an actively exploited zero-day flaw in DWM in May 2024 (CVE-2024-30051, CVSS score: 7.8), which was described as a privilege escalation flaw that was abused by multiple threat actors, in connection with the distribution of QakBot and other malware families. Satnam Narang, senior staff research engineer at Tenable, called DWM a "frequent flyer" on Patch Tuesday, with 20 CVEs patched in the library since 2022. Jack Bicer, director of vulnerability research at Action1, said the vulnerability can be exploited by a locally authenticated attacker to disclose information, defeat address space layout randomization (ASLR), and other defenses. "Vulnerabilities of this nature are commonly used to undermine Address Space Layout Randomization (ASLR), a core operating system security control designed to protect against buffer overflows and other memory-manipulation exploits," Kev Breen, senior director of cyber threat research at Immersive, told The Hacker News. "By revealing where code resides in memory, this vulnerability can be chained with a separate code execution flaw, transforming a complex and unreliable exploit into a practical and repeatable attack." The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating Federal Civilian Executive Branch (FCEB) agencies to apply the latest fixes by February 3, 2026. Another vulnerability of note concerns a security feature bypass impacting Secure Boot Certificate Expiration (CVE-2026-21265, CVSS score: 6.4) that could allow an attacker to undermine a crucial security mechanism that ensures that firmware modules come from a trusted source and prevent malware from being run during the boot process. In November 2025, Microsoft announced that it will be expiring three Windows Secure Boot certificates issued in 2011, effective June 2026, urging customers to update to their 2023 counterparts - Microsoft Corporation KEK CA 2011 (June 2026) - Microsoft Corporation KEK 2K CA 2023 (for signing updates to DB and DBX) Microsoft Windows Production PCA 2011 (October 2026) - Windows UEFI CA 2023 (for signing the Windows boot loader) Microsoft UEFI CA 2011 (June 2026) - Microsoft UEFI CA 2023 (for signing third-party boot loaders) and Microsoft Option ROM UEFI CA 2023 (for signing third-party option ROMs) "Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time," Microsoft said. "To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance." The Windows maker also pointed out that the latest update removes Agere Soft Modem drivers "agrsm64.sys" and "agrsm.sys" that were shipped natively with the operating system. The third-party drivers are susceptible to a two-year-old local privilege escalation flaw (CVE-2023-31096, CVSS score: 7.8) that could allow an attacker to gain SYSTEM permissions. In October 2025, Microsoft took steps to remove another Agere Modem driver called "ltmdm64.sys" following in-the-wild exploitation of a privilege escalation vulnerability (CVE-2025-24990, CVSS score: 7.8) that could permit an attacker to gain administrative privileges. Also high on the priority list should be CVE-2026-20876 (CVSS score: 6.7), a critical-rated privilege escalation flaw in Windows Virtualization-Based Security (VBS) Enclave, enabling an attacker to obtain Virtual Trust Level 2 (VTL2) privileges, and leverage it to subvert security controls, establish deep persistence, and evade detection. "It breaks the security boundary designed to protect Windows itself, allowing attackers to climb into one of the most trusted execution layers of the system," Mike Walters, president and co-founder of Action1, said. "Although exploitation requires high privileges, the impact is severe because it compromises virtualization-based security itself. Attackers who already have a foothold could use this flaw to defeat advanced defenses, making prompt patching essential to maintain trust in Windows security boundaries." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors since the start of the month to rectify several vulnerabilities, including — ABB Adobe Amazon Web Services AMD Arm ASUS Broadcom (including VMware) Cisco ConnectWise Dassault Systèmes D-Link Dell Devolutions Drupal Elastic F5 Fortinet Fortra Foxit Software FUJIFILM Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Imagination Technologies Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Firefox ESR n8n NETGEAR Node.js NVIDIA ownCloud QNAP Qualcomm Ricoh Samsung SAP Schneider Electric ServiceNow Siemens SolarWinds SonicWall Sophos Spring Framework Synology TP-Link Trend Micro, and Veeam
thehackernews.comJan 14, 2026extracted
Week in review: 40 open-source tools securing the stack, invisible IT to be the next workplace priority
Week in review: 40 open-source tools securing the stack, invisible IT to be the next workplace priority Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 40 open-source tools redefining how security teams secure the stack Open source security software has become a key way for teams to get flexibility, transparency, and capability without licensing costs. The free tools in this roundup address problems security teams deal with, from managing large environments to catching misconfigurations and understanding how new technologies change threat exposure. AI agents break rules in unexpected ways AI agents are starting to take on tasks that used to be handled by people. These systems plan steps, call tools, and carry out actions without a person approving every move. This shift is raising questions for security leaders. A new research paper offers one of the first attempts to measure how well these agents stay inside guardrails when users try to push them off course. AI-driven threats are heading straight for the factory floor In this Help Net Security interview, Natalia Oropeza, Chief Cybersecurity Officer at Siemens, discusses how industrial organizations are adapting to a shift in cyber risk driven by AI. She notes that in-house capability, especially for OT response and recovery, is becoming a priority. Oropeza also explains why collaboration and a different mindset are becoming as important as the technology. LLMs are everywhere in your stack and every layer brings new risk LLMs are moving deeper into enterprise products and workflows, and that shift is creating new pressure on security leaders. A new guide from DryRun Security outlines how these systems change long standing assumptions about data handling, application behavior, and internal boundaries. It is built around the OWASP Top 10 for LLM Applications, which the company uses as the structure for a full risk model and a reference architecture for teams building with LLMs. The hidden dynamics shaping who produces influential cybersecurity research Cybersecurity leaders spend much of their time watching how threats and tools change. A new study asks a different question, how has the research community itself changed over the past two decades. Researchers from the University of Southampton examined two long running conference communities, SOUPS and Financial Cryptography and Data Security, to see how teams form, who contributes, and which kinds of work gain attention. Henkel CISO on the messy truth of monitoring factories built across decades In this Help Net Security interview, Stefan Braun, CISO at Henkel, discusses how smart manufacturing environments introduce new cybersecurity risks. He explains where single points of failure hide, how attackers exploit legacy systems, and why monitoring must adapt to mixed-generation equipment. His insights show why resilience depends on visibility, autonomy, and disciplined vendor accountability. December 2025 Patch Tuesday forecast: And it’s a wrap It’s hard to believe that we’re in December of 2025 already and the end of the year is fast approaching. Looking back on the year, there are two major items that really stand out in my mind. First, there is the large number of Microsoft products that have come to EOL/EOS near the end of this year. It seemed there was always a reason their products would get official extended support at the last minute, but this time, that didn’t happen – applications and operating systems alike came to an end. The simple shift that turns threat intel from noise into real insight In this Help Net Security video, Alankrit Chona, CTO at Simbian, explains how security teams can put threat intelligence to work in a way that supports detection, response, and hunting. Password habits are changing, and the data shows how far we’ve come In this Help Net Security video, Andréanne Bergeron, Security Researcher at Flare, explains how changes in user habits, policy shifts, and new tools have shaped password security over nearly twenty years. She walks through research based on leaked passwords from 2007 to 2025 and shows how strength levels rose as standards evolved and breach events pushed users to reset weak credentials. How to tell if your password manager meets HIPAA expectations Most healthcare organizations focus on encryption, network monitoring, and phishing prevention, although one simple source of risk still slips through the cracks. Password management continues to open doors for attackers more often than leaders expect. Weak, reused, or shared passwords often play a part in breaches that involve protected health information. The HIPAA Security Rule expects organizations to manage authentication with care, and password managers can help satisfy these expectations when they are chosen and deployed with the right controls. NVIDIA research shows how agentic AI fails under attack Enterprises are rushing to deploy agentic systems that plan, use tools, and make decisions with less human guidance than earlier AI models. This new class of systems also brings new kinds of risk that appear in the interactions between models, tools, data sources, and memory stores. A research team from NVIDIA and Lakera AI has released a safety and security framework that tries to map these risks and measure them inside real workflows. New image signature can survive cropping, stop deepfakes from hijacking trust Deepfake images can distort public debate, fuel harassment, or shift a news cycle before anyone checks the source. A new study from researchers at the University of Pisa examines one specific part of this problem. They introduced a way to keep image signatures intact even after cropping. Building SOX compliance through smarter training and stronger password practices A SOX audit can reveal uncomfortable truths about how a company handles access to financial systems. Even organizations that invest in strong infrastructure often discover that everyday password habits weaken the controls they thought were solid. CISOs know that passwords still sit at the center of most access decisions, and any weakness in how people create, store or share them can undermine internal control over financial reporting. UTMStack: Open-source unified threat management platform UTMStack is an open-source unified threat management platform that brings SIEM and XDR features into one system. The project focuses on real time correlation of log data, threat intelligence, and malware activity patterns gathered from different sources. The goal is to help organizations identify and halt complex threats that rely on stealthy techniques. LLM vulnerability patching skills remain limited Security teams are wondering whether LLMs can help speed up patching. A new study tests that idea and shows where the tools hold up and where they fall short. The researchers tested LLMs from OpenAI, Meta, DeepSeek, and Mistral to see how well they could fix vulnerable Java functions in a single attempt. LLM privacy policies keep getting longer, denser, and nearly impossible to decode People expect privacy policies to explain what happens to their data. What users get instead is a growing wall of text that feels harder to read each year. In a new study, researchers reviewed privacy policies for LLMs and traced how they changed. CISOs are spending big and still losing ground Security leaders are entering another budget cycle with more money to work with, but many still feel no safer. A new benchmark study from Wiz shows a widening gap between investment and impact. Budgets keep rising, cloud programs keep expanding, and AI is reshaping both threats and defenses. Still, CISOs say the fundamentals of risk reduction are not improving fast enough. Invisible IT is becoming the next workplace priority IT leaders want their employees to work without running into digital hurdles, but many still struggle with fragmented systems that slow teams down. A new report from Lenovo sheds light on how widespread the problem has become and what organizations can do to reduce workplace friction. The Bastion: Open-source access control for complex infrastructure Operational teams know that access sprawl grows fast. Servers, virtual machines and network gear all need hands-on work and each new system adds more identities to manage. A bastion host tries to bring order to this problem. It acts as a single entry point for sysadmins and developers who connect to infrastructure through ssh. This model is old in theory, but The Bastion open-source project shows how far a purpose-built access layer can go. Teamwork is failing in slow motion and security feels it Security leaders often track threats in code, networks, and policies. But a quieter risk is taking shape in the everyday work of teams. Collaboration is getting harder even as AI use spreads across the enterprise. That tension creates openings for mistakes, shadow tools, and uncontrolled data flows. A recent Forrester study shows how this break in teamwork forms and how leaders can respond before it grows. Uneven regulatory demands expose gaps in mobile security Mobile networks carry a great deal of the world’s digital activity, which makes operators a frequent target for attacks. A study released by the GSMA shows that operators spend between $15 and $19 billion a year on core cybersecurity functions. Spending could reach more than $40 billion by 2030. These figures do not include expenses tied to resilience, training, or governance. Ransomware keeps widening its reach Ransomware keeps shifting into new territory, pulling in victims from sectors and regions that once saw fewer attacks. The latest Global Threat Briefing for H2 2025 from CyberCube shows incidents spreading in ways that make it harder for security leaders to predict where threats will rise next. What 35 years of privacy law say about the state of data protection Privacy laws have expanded around the world, and security leaders now work within a crowded field of requirements. New research shows that these laws provide stronger rights and duties, but the protections do not always translate into reductions in harm. The study looks at thirty five years of privacy history, from the rise of early data protection efforts to the current landscape of AI driven risk, cross border transfers, and uneven enforcement. Download: Evaluating Password Monitoring Vendors Organizations using Active Directory must update their password policies to block and detect compromised passwords. However, comparing vendors in this area can be challenging. Product showcase: Tuta – secure, encrypted, private email Tuta, formerly known as Tutanota, is built for anyone who wants email that stays private. Instead of treating encryption like a bonus feature, the service encrypts almost everything by default. That means your messages are locked down from the moment you hit send until they reach the other side. Cybersecurity jobs available right now: December 9, 2025 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: December 12, 2025 Here’s a look at the most interesting products from the past week, featuring releases from Apptega, Backslash Security, BigID, Black Kite, Bugcrowd, NinjaOne, Nudge Security, and Veza.
helpnetsecurity.comDec 14, 2025extracted
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days
Microsoft closed out 2025 with patches for 56 security flaws in various products across the Windows platform, including one vulnerability that has been actively exploited in the wild. Of the 56 flaws, three are rated Critical, and 53 are rated Important in severity. Two other defects are listed as publicly known at the time of the release. These include 29 privilege escalation, 18 remote code execution, four information disclosure, three denial-of-service, and two spoofing vulnerabilities. In total, Microsoft has addressed a total of 1,275 CVEs in 2025, according to data compiled by Fortra. Tenable's Satnam Narang said 2025 also marks the second consecutive year where the Windows maker has patched over 1,000 CVEs. It's the third time it has done so since Patch Tuesday's inception. The update is in addition to 17 shortcomings the tech giant patched in its Chromium-based Edge browser since the release of the November 2025 Patch Tuesday update. This also consists of a spoofing vulnerability in Edge for iOS (CVE-2025-62223, CVSS score: 4.3). The vulnerability that has come under active exploitation is CVE-2025-62221 (CVSS score: 7.8), a use-after-free in Windows Cloud Files Mini Filter Driver that could allow an authorized attacker to elevate privileges locally and obtain SYSTEM permissions. "File system filter drivers, aka minifilters, attach to the system software stack, and intercept requests targeted at a file system, and extend or replace the functionality provided by the original target," Adam Barnett, lead software engineer at Rapid7, said in a statement. "Typical use cases include data encryption, automated backup, on-the-fly compression, and cloud storage." "The Cloud Files minifilter is used by OneDrive, Google Drive, iCloud, and others, although as a core Windows component, it would still be present on a system where none of those apps were installed." It's currently not known how the vulnerability is being abused in the wild and in what context, but successful exploitation requires an attacker to obtain access to a susceptible system through some other means. Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have been credited with discovering and reporting the flaw. According to Mike Walters, president and co-founder of Action1, a threat actor could gain low-privileged access through methods like phishing, web browser exploits, or another known remote code execution flaw, and then chain it with CVE-2025-62221 to seize control of the host. Armed with this access, the attacker could deploy kernel components or abuse signed drivers to evade defenses and maintain persistence, and can be weaponized to achieve a domain-wide compromise when coupled with credential theft scenarios. The exploitation of CVE-2025-62221 has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to the Known Exploited Vulnerabilities (KEV) catalog, mandating Federal Civilian Executive Branch (FCEB) agencies to apply the patch by December 30, 2025. The remaining two zero-days are listed below - CVE-2025-54100 (CVSS score: 7.8) - A command injection vulnerability in Windows PowerShell that allows an unauthorized attacker to execute code locally CVE-2025-64671 (CVSS score: 8.4) - A command injection vulnerability in GitHub Copilot for JetBrains that allows an unauthorized attacker to execute code locally "This is a command injection flaw in how Windows PowerShell processes web content," Action1's Alex Vovk said about CVE-2025-54100. "It lets an unauthenticated attacker execute arbitrary code in the security context of a user who runs a crafted PowerShell command, such as Invoke-WebRequest." "The threat becomes significant when this vulnerability is combined with common attack patterns. For example, an attacker can use social engineering to persuade a user or admin to run a PowerShell snippet using Invoke-WebRequest, allowing a remote server to return crafted content that triggers the parsing flaw and leads to code execution and implant deployment." It's worth noting that CVE-2025-64671 comes in the wake of a broader set of security vulnerabilities collectively named IDEsaster that was recently disclosed by security researcher Ari Marzouk. The issues arise as a result of adding agentic capabilities to an integrated development environment (IDE), exposing new security risks in the process. These attacks leverage prompt injections against the artificial intelligence (AI) agents embedded into IDEs and combine them with the base IDE layer to result in information disclosure or command execution. "This uses an 'old' attack chain of using a vulnerable tool, so not exactly part of the IDEsaster novel attack chain," Marzouk, who is credited with discovering and reporting the flaw, told The Hacker News. "Specifically, a vulnerable 'execute command' tool where you can bypass the user-configured allow list." Marzouk also said multiple IDEs were found vulnerable to the same attack, including Kiro.dev, Cursor (CVE-2025-54131), JetBrains Junie (CVE-2025-59458), Gemini CLI, Windsurf, and Roo Code (CVE-2025-54377, CVE-2025-57771, and CVE-2025-65946). Furthermore, GitHub Copilot for Visual Studio Code has been found to be susceptible to the vulnerability, although, in this case, Microsoft assigned it a "Medium" severity rating with no CVE. "The vulnerability states that it's possible to gain code execution on affected hosts by tricking the LLM into running commands that bypass the guardrails and appending instructions in the user's 'auto-approve' settings," Kev Breen, senior director of cyber threat research at Immersive, said. "This can be achieved through 'Cross Prompt Injection,' which is where the prompt is modified not by the user but by the LLM agents as they craft their own prompts based on the content of files or data retrieved from a Model Context Protocol (MCP) server that has risen in popularity with agent-based LLMs." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify multiple vulnerabilities, including — Adobe Amazon Web Services AMD Arm ASUS Atlassian Bosch Broadcom (including VMware) Canon Cisco Citrix CODESYS Dell Devolutions Django Drupal F5 Fortinet Fortra GitLab Google Android and Pixel Google Chrome Google Cloud Google Pixel Watch Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Imagination Technologies Intel Ivanti Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Firefox ESR NVIDIA OPPO Progress Software Qualcomm React Rockwell Automation Samsung SAP Schneider Electric Siemens SolarWinds Splunk Synology TP-Link WatchGuard Zoom, and Zyxel
thehackernews.comDec 10, 2025extracted
Intel, AMD Processors Affected by PCIe Vulnerabilities
Major hardware vendors are investigating the potential impact of three recently discovered PCI Express (PCIe) vulnerabilities. PCIe is the widely used high-speed hardware interface standard used to connect GPUs, SSDs, network cards, and other peripherals inside computers and servers. It also serves as a direct communication link between the CPU and these peripherals. The flaws, discovered by Intel employees, affect the PCIe Integrity and Data Encryption (IDE) standard. The security holes are tracked as CVE-2025-9612, CVE-2025-9613, and CVE-2025-9614. PCIe IDE, introduced in PCIe 6.0, is designed to secure data transfers through encryption and integrity protection. “IDE uses AES-GCM encryption to protect confidentiality, integrity, and replay resistance for traffic between PCIe components. It operates between the transaction layer and the data link layer, providing protection close to the hardware against unauthorized modification of link traffic,” the CERT/CC at Carnegie Mellon University explained in an advisory. “Three specification-level vulnerabilities can, under certain conditions, result in consumption of stale or incorrect data if an attacker is able to craft specific traffic patterns at the PCIe interface,” CERT/CC added. Exploitation of the vulnerabilities can lead to information disclosure, privilege escalation, or denial of service (DoS). However, the vulnerabilities have all been classified as ‘low severity’ as their exploitation requires physical or low-level access to the targeted computer’s PCIe IDE interface. These types of vulnerabilities may typically be useful for security researchers specializing in hardware security, or sophisticated threat actors that may want to gain deep and stealthy access to a system in a highly targeted attack. The PCI Special Interest Group (SIG), the consortium responsible for developing and maintaining PCIe, has published an advisory summarizing each of the vulnerabilities. Hardware vendors that use PCIe have been provided an Engineering Change Notification (ECN) that addresses the vulnerabilities. System and component suppliers are expected to release firmware updates. According to CERT/CC’s advisory, only Intel and AMD have confirmed that their products are affected. Nvidia, Dell, F5, and Keysight said they are not affected. However, there is a list of more than a dozen other vendors with an ‘unknown’ impact status, including Arm, Cisco, Google, HP, IBM, Lenovo, and Qualcomm. Intel has published its own advisory to inform customers that some of its Xeon 6 and Xeon 6700P-B/6500P-B series processors are affected. AMD has also published an advisory. The company says it’s still waiting for additional details on the vulnerabilities, but believes its EPYC 9005 series (including embedded) processors may be impacted. Related: RMPocalypse: New Attack Breaks AMD Confidential Computing Related: Chipmaker Patch Tuesday: Over 60 Vulnerabilities Patched by Intel Related: New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs
securityweek.comDec 10, 2025extracted
Invisible IT is becoming the next workplace priority
Invisible IT is becoming the next workplace priority IT leaders want their employees to work without running into digital hurdles, but many still struggle with fragmented systems that slow teams down. A new report from Lenovo sheds light on how widespread the problem has become and what organizations can do to reduce workplace friction. Complexity is holding digital workplaces back Hybrid work pushed companies to adopt new tools, devices and management platforms at speed. According to the research, enterprises now manage an average of 897 applications, but only 28 percent are integrated. The report notes that this patchwork environment strains both workers and support teams, since employees must move across several systems before they can resolve problems or complete simple tasks. The survey, which gathered responses from 600 IT leaders worldwide, shows that productivity goals are often at odds with current digital conditions. Forty nine percent say improving the employee experience is their top objective. Only 36 percent believe their workplace supports engagement effectively. Lenovo’s Rakshit Ghura summed it up in the report: “The digital workplace has become totally fragmented. Hybrid work has led to inconsistent employee experiences, giving rise to a lot of new tools and technologies, reducing IT visibility.” Support operations are under pressure Support workflows are a major pain point. Employees may switch between email, phone, chat tools and service applications when reporting an issue. This creates slow resolution times and pulls people away from their work. Three in four IT leaders say manual processes in support environments hinder productivity. Despite these challenges, most respondents agree that improving IT support is central to improving the workplace. Seventy nine percent say employee experience cannot advance without transforming support operations. That sentiment sets the stage for the report’s core concept: invisible IT. What invisible IT looks like in practice Lenovo defines invisible IT as support that runs in the background and prevents problems before employees notice them. The report highlights two areas that bring this approach to life. The first is predictive and proactive support. Eighty three percent of leaders say this approach is essential, but only 21 percent have achieved it. With AI tools that monitor telemetry data across devices, support teams can detect early signs of failure and trigger automated fixes. If a fix requires human involvement, the repair can happen before the user experiences downtime. This reduces disruptions and shifts support teams away from repetitive tasks that slow down operations. The second area is hyper personalization. Many organizations personalize support by role or seniority, but the study argues this does not reflect how people work. AI systems can now create personas based on individual usage patterns. This lets support teams tailor responses and rollouts to real conditions rather than assumptions. The report cites internal testing results that included 40 percent of issues resolved before tickets were created and a 30 percent improvement in the employee experience. Support teams will not shrink, but their work will change The research indicates that predictive and personalized support will not lead to large reductions in IT staff. Only 12 percent of leaders expect to reduce headcount. Most respondents expect these tools to help staff focus on higher value work. Twenty one percent say support roles will shift toward improving productivity and workplace quality. Thirty nine percent say staff will spend more time on strategic tasks. This suggests that invisible IT is about changing how IT contributes to the business. Organizations are still far from this model Although interest in invisible IT is high, most companies are still using manual processes. Sixty five percent detect issues only when users contact support. Fifty five percent resolve them through manual interventions. Hyper personalization is also limited, with 51 percent of organizations offering standard support for all employees. Barriers are widespread. Fifty one percent cite fragmented systems as their top challenge. Another 47 percent point to cost concerns or uncertain return on investment. Limited AI capabilities and skills gaps also slow progress, along with slow upgrade cycles and a lack of time for planning. How leaders can begin moving toward invisible IT The report outlines several steps for organizations that want to build toward predictive and personalized support. Leaders are encouraged to unify data sources so that AI tools can learn from workplace activity. Support teams need training so they can apply new insights and respond to higher complexity issues. The report also calls out the value of external partners who can help close skills gaps and accelerate deployment. A long runway ahead Invisible IT remains an early ambition for most enterprises, but the findings suggest that interest is growing as organizations see the link between fewer disruptions and stronger business performance. For CISOs and CIOs searching for new ways to strengthen the digital workplace, the study shows that reducing friction may be as important as any new platform or tool.
helpnetsecurity.comDec 8, 2025extracted
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack
Microsoft on Tuesday released patches for 63 new security vulnerabilities identified in its software, including one that has come under active exploitation in the wild. Of the 63 flaws, four are rated Critical and 59 are rated Important in severity. Twenty-nine of these vulnerabilities are related to privilege escalation, followed by 16 remote code execution, 11 information disclosure, three denial-of-service (DoS), two security feature bypass, and two spoofing bugs. The patches are in addition to the 27 vulnerabilities the Windows maker addressed in its Chromium-based Edge browser since the release of October 2025's Patch Tuesday update. The zero-day vulnerability that has been listed as exploited in Tuesday's update is CVE-2025-62215 (CVSS score: 7.0), a privilege escalation flaw in Windows Kernel. The Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have been credited with discovering and reporting the issue. "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally," the company said in an advisory. That said, successful exploitation hinges on an attacker who has already gained a foothold on a system to win a race condition. Once this criterion is satisfied, it could permit the attacker to obtain SYSTEM privileges. "An attacker with low-privilege local access can run a specially crafted application that repeatedly attempts to trigger this race condition," Ben McCarthy, lead cybersecurity engineer at Immersive, said. "The goal is to get multiple threads to interact with a shared kernel resource in an unsynchronized way, confusing the kernel's memory management and causing it to free the same memory block twice. This successful 'double free' corrupts the kernel heap, allowing the attacker to overwrite memory and hijack the system's execution flow." It's currently not known how this vulnerability is being exploited and by whom, but it's assessed to be used as part of a post-exploitation activity to escalate their privileges after obtaining initial access through some other means, such as social engineering, phishing, or exploitation of another vulnerability, Satnam Narang, senior staff research engineer at Tenable, said. "When chained with other bugs this kernel race is critical: an RCE or sandbox escape can supply the local code execution needed to turn a remote attack into a SYSTEM takeover, and an initial low‑privilege foothold can be escalated to dump credentials and move laterally," Mike Walters, president and co-founder of Action1, said in a statement. Also patched as part of the updates are two heap-based buffer overflow flaws in Microsoft's Graphics Component (CVE-2025-60724, CVSS score: 9.8) and Windows Subsystem for Linux GUI (CVE-2025-62220, CVSS score: 8.8) that could result in remote code execution. Another vulnerability of note is a high-severity privilege escalation flaw in Windows Kerberos (CVE-2025-60704, CVSS score: 7.5) that takes advantage of a missing cryptographic step to gain administrator privileges. The vulnerability has been codenamed CheckSum by Silverfort. "The attacker must inject themselves into the logical network path between the target and the resource requested by the victim to read or modify network communications," Microsoft said. "An unauthorized attacker must wait for a user to initiate a connection." Silverfort researchers Eliran Partush and Dor Segal, who discovered the shortcoming, described it as a Kerberos constrained delegation vulnerability that allows an attacker to impersonate arbitrary users and gain control over an entire domain by means of an adversary-in-the-middle (AitM) attack. An attacker who is able to successfully exploit the flaw could escalate privileges and move laterally to other machines in an organization. More concerning, threat actors could also gain the ability to impersonate any user in the company, allowing them to gain unfettered access or become a domain administrator. "Any organization using Active Directory, with the Kerberos delegation capability turned on, is impacted," Silverfort said. "Because Kerberos delegation is a feature within Active Directory, an attacker requires initial access to an environment with compromised credentials." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — Adobe Amazon Web Services AMD Apple ASUS Atlassian AutomationDirect Bitdefender Broadcom (including VMware) Cisco Citrix ConnectWise D-Link Dell Devolutions Drupal Elastic F5 Fortinet GitLab Google Android Google Chrome Google Cloud Grafana Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Firefox ESR NVIDIA Oracle Palo Alto Networks QNAP Qualcomm Rockwell Automation Ruckus Wireless Samba Samsung SAP Schneider Electric Siemens SolarWinds SonicWall Splunk Spring Framework Supermicro Synology TP-Link WatchGuard, and Zoom
thehackernews.comNov 12, 2025extracted
Lenovo lancia il ThinkBook Plus G6 Rollable 2025 con display arrotolabile
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comOct 18, 2025extracted
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped
Microsoft on Tuesday released fixes for a whopping 183 security flaws spanning its products, including three vulnerabilities that have come under active exploitation in the wild, as the tech giant officially ended support for its Windows 10 operating system unless the PCs are enrolled in the Extended Security Updates (ESU) program. Of the 183 vulnerabilities, eight of them are non-Microsoft issued CVEs. As many as 165 flaws have been rated as Important in severity, followed by 17 as Critical and one as Moderate. The vast majority of them relate to elevation of privilege vulnerabilities (84), with remote code execution (33), information disclosure (28), spoofing (14), denial-of-service (11), and security feature bypass (11) issues accounting for the rest. The updates are in addition to the 25 vulnerabilities Microsoft addressed in its Chromium-based Edge browser since the release of September 2025's Patch Tuesday update. The two Windows zero-days that have come under active exploitation are as follows - CVE-2025-24990 (CVSS score: 7.8) - Windows Agere Modem Driver ("ltmdm64.sys") Elevation of Privilege Vulnerability CVE-2025-59230 (CVSS score: 7.8) - Windows Remote Access Connection Manager (RasMan) Elevation of Privilege Vulnerability Microsoft said both issues could allow attackers to execute code with elevated privileges, although there are currently no indications on how they are being exploited and how widespread these efforts may be. In the case of CVE-2025-24990, the company said it's planning to remove the driver entirely, rather than issue a patch for a legacy third-party component. The security defect has been described as "dangerous" by Alex Vovk, CEO and co-founder of Action1, as it's rooted within legacy code installed by default on all Windows systems, irrespective of whether the associated hardware is present or in use. "The vulnerable driver ships with every version of Windows, up to and including Server 2025," Adam Barnett, lead software engineer at Rapid7, said. "Maybe your fax modem uses a different chipset, and so you don't need the Agere driver? Perhaps you've simply discovered email? Tough luck. Your PC is still vulnerable, and a local attacker with a minimally privileged account can elevate to administrator." According to Satnam Narang, senior staff research engineer at Tenable, CVE-2025-59230 is the first vulnerability in RasMan to be exploited as a zero-day. Microsoft has patched more than 20 flaws in the component since January 2022. The third vulnerability that has been exploited in real-world attacks concerns a case of Secure Boot bypass in IGEL OS before 11 (CVE-2025-47827, CVSS score: 4.6). Details about the flaw were first publicly disclosed by security researcher Zack Didcott in June 2025. "The impacts of a Secure Boot bypass can be significant, as threat actors can deploy a kernel-level rootkit, gaining access to the IGEL OS itself and, by extension, then tamper with the Virtual Desktops, including capturing credentials," Kev Breen, senior director of threat research at Immersive, said. "It should be noted that this is not a remote attack, and physical access is typically required to exploit this type of vulnerability, meaning that 'evil-maid' style attacks are the most likely vector affecting employees who travel frequently." All three issues have since been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the patches by November 4, 2025. Some other critical vulnerabilities of note include a remote code execution (RCE) bug (CVE-2025-59287, CVSS score: 9.8) in Windows Server Update Service (WSUS), an out-of-bounds read vulnerability in the Trusted Computing Group (TCG) TPM2.0 reference implementation's CryptHmacSign helper function (CVE-2025-2884, CVSS score: 5.3), and an RCE in Windows URL Parsing (CVE-2025-59295, 8.8). "An attacker can leverage this by carefully constructing a malicious URL," Ben McCarthy, lead cybersecurity engineer at Immersive, said about CVE-2025-59295. "The overflowed data can be designed to overwrite critical program data, such as a function pointer or an object's virtual function table (vtable) pointer." "When the application later attempts to use this corrupted pointer, instead of calling a legitimate function, it redirects the program's execution flow to a memory address controlled by the attacker. This allows the attacker to execute arbitrary code (shellcode) on the target system." Two vulnerabilities with the highest CVSS score in this month's update relate to a privilege escalation flaw in Microsoft Graphics Component (CVE-2025-49708, CVSS score: 9.9) and a security feature bypass in ASP.NET (CVE-2025-55315, CVSS score: 9.9). While exploiting CVE-2025-55315 requires an attacker to be first authenticated, it can be abused to covertly get around security controls and carry out malicious actions by smuggling a second, malicious HTTP request within the body of their initial authenticated request. "An organization must prioritize patching this vulnerability because it invalidates the core security promise of virtualization," McCarthy explained regarding CVE-2025-49708, characterizing it as a high-impact flaw that leads to a full virtual machine (VM) escape. "A successful exploit means an attacker who gains even low-privilege access to a single, non-critical guest VM can break out and execute code with SYSTEM privileges directly on the underlying host server. This failure of isolation means the attacker can then access, manipulate, or destroy data on every other VM running on that same host, including mission-critical domain controllers, databases, or production applications." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — Adobe Amazon Web Services AMD AMI Apple ASUS Axis Communications Broadcom (including VMware) Canon Check Point Cisco D-Link Dell Drupal Elastic F5 Fortinet Foxit Software FUJIFILM Gigabyte GitLab Google Chrome Google Cloud Google Pixel Watch Grafana Hitachi Energy HMS Networks (including Red Lion) Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moodle Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA Oracle Palo Alto Networks Progress Software QNAP Qualcomm Ricoh Rockwell Automation Salesforce Samsung SAP Schneider Electric ServiceNow Siemens SolarWinds SonicWall Splunk Spring Framework Supermicro Synology TP-Link Unity Veeam, and Zoom
thehackernews.comOct 15, 2025extracted
AI is rewriting the rules of cyber defense
AI is rewriting the rules of cyber defense Enterprise security teams are underprepared to detect new, adaptive AI-powered threats. The study, published by Lenovo, surveyed 600 IT leaders across major markets and shows widespread concern about external and internal risks, along with low confidence in current defenses. External AI threats gain ground More than six in ten IT leaders see cybercriminals using AI as a growing risk. AI-enhanced campaigns can adapt to defenses in real time, imitate normal user behavior, and operate across cloud, devices, and applications. Respondents admit that they are not confident they can defend against these techniques, which may include polymorphic malware, deepfake social engineering, and AI-powered brute-force attempts. The report indicates that AI is accelerating the pace of attacks. Adversaries can generate code, adjust tactics, and exploit systems at machine speed, which shortens the window for detection and response and creates a demand for updated monitoring and analysis models. Internal AI risks The survey also shows that AI inside organizations presents its own challenges. Seven in ten IT leaders believe misuse of public AI tools by employees is a serious concern, while more than six in ten say AI agents represent an insider threat they are not ready to handle. Less than 40 percent feel confident managing these risks. Concerns extend to the protection of AI models, training data, and prompts. As businesses adopt AI solutions, tampering or data poisoning could undermine trust, cause reputational harm, or even expose sensitive information. Despite this, leaders report feeling somewhat more confident about securing in-house AI development compared with defending against external AI-enabled attacks. Gaps in defensive capabilities Confidence in existing tools and processes is low. More than half of respondents believe their data protection measures are not sufficient to counter AI-related threats. Vulnerability analysis, incident detection, response, and identity management also fall short. Between 60 and 70 percent of leaders doubt these areas are fully prepared for AI-era attacks. The shortcomings reveal the limits of traditional approaches. Measures like role-based data access or signature-based antivirus tools cannot keep up when AI systems scan large datasets or when malware mutates to avoid detection. Security leaders recognize that AI adversaries demand new approaches. Barriers to progress While many organizations are already experimenting with AI in cybersecurity, scaling these efforts is difficult. Three major barriers stand out in the survey: complex IT environments, lack of skilled staff, and limited budgets. Most enterprises rely on a patchwork of legacy and newer systems, making it difficult to integrate AI-powered security tools. Progress is further hindered by a shortage of professionals with expertise in both AI and cybersecurity. Finally, budget pressures leave some teams reluctant to replace existing tools, even when their features are outdated. Paths forward The report outlines practical steps for leaders. These include consolidating telemetry across endpoints, applications, and cloud environments to reduce blind spots and improve visibility. Establishing AI usage policies for employees is necessary, as is securing the AI development lifecycle against manipulation and data leakage. Training staff to recognize AI-enabled social engineering, such as voice and video impersonation, is another priority. On the technology side, unifying monitoring and adopting AI-based analysis can help defenders keep pace with machine-speed threats. “AI has changed the balance of power in cybersecurity. To keep up, organizations need intelligence that adapts as fast as the threats. That means fighting AI with AI,” said Rakshit Ghura, VP & GM, Lenovo Digital Workplace Solutions. “With intelligent, adaptive defenses, IT leaders can protect their people, assets, and data while unlocking AI’s potential to drive business forward.”
helpnetsecurity.comSep 25, 2025extracted
Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 Bugs
Microsoft on Tuesday addressed a set of 80 security flaws in its software, including one vulnerability that has been disclosed as publicly known at the time of release. Of the 80 vulnerabilities, eight are rated Critical and 72 are rated Important in severity. None of the shortcomings has been exploited in the wild as a zero-day. Like last month, 38 of the disclosed flaws are related to privilege escalation, followed by remote code execution (22), information disclosure (14), and denial-of-service (3). "For the third time this year, Microsoft patched more elevation of privilege vulnerabilities than remote code execution flaws," Satnam Narang, senior staff research engineer at Tenable, said. "Nearly 50% (47.5%) of all bugs this month are privilege escalation vulnerabilities." The patches are in addition to 12 vulnerabilities addressed in Microsoft's Chromium-based Edge browser since the release of August 2025's Patch Tuesday update, including a security bypass bug (CVE-2025-53791, CVSS score: 4.7) that has been patched in version 140.0.3485.54 of the browser. The vulnerability that has been flagged as publicly known is CVE-2025-55234 (CVSS score: 8.8), a case of privilege escalation in Windows SMB. "SMB Server might be susceptible to relay attacks depending on the configuration," Microsoft said. "An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks." The Windows maker said the update enables support for auditing SMB client compatibility for SMB Server signing as well as SMB Server EPA, allowing customers to assess their environment and detect any potential device or software incompatibility issues before deploying appropriate hardening measures. "The key takeaway from the CVE-2025-55234 advisory, other than the explanation of the well-known attack surface around SMB authentication, is that this is one of those times where simply patching isn't enough; in fact, the patches provide administrators with more auditing options to determine whether their SMB Server is interacting with clients that won't support the recommended hardening options," Adam Barnett, lead software engineer at Rapid7, said. Mike Walters, president and co-founder of Action, said the vulnerability stems from the fact that SMB sessions can be established without properly validating the authentication context when key hardening measures, such as SMB signing and Extended Protection for Authentication, are not in place. "This gap opens the door to man-in-the-middle relay attacks, where attackers can capture and forward authentication material to gain unauthorized access," Walters added. "It can easily become part of a larger campaign, moving from phishing to SMB relay, credential theft, lateral movement, and eventually data exfiltration." The CVE with the highest CVSS score for this month, but not listed in the Release Notes, is CVE-2025-54914 (CVSS score: 10.0), a critical flaw impacting Azure Networking that could result in privilege escalation. It requires no customer action, given that it's a cloud-related vulnerability. Two other shortcomings that merit attention include a remote code execution flaw in Microsoft High Performance Compute (HPC) Pack (CVE-2025-55232, CVSS score: 9.8) and an elevation of privilege issue affecting Windows NTLM (CVE-2025-54918, CVSS score: 8.8) that could allow an attacker to gain SYSTEM privileges. "From Microsoft's limited description, it appears that if an attacker is able to send specially crafted packets over the network to the target device, they would have the ability to gain SYSTEM-level privileges on the target machine," Kev Breen, senior director of threat research at Immersive, said. "The patch notes for this vulnerability state that 'Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network,' suggesting an attacker may already need to have access to the NTLM hash or the user's credentials." Lastly, the update also remediates a security flaw (CVE-2024-21907, CVSS score: 7.5) in Newtonsoft.Json, a third-party component used in SQL Server, that could be exploited to trigger a denial-of-service condition, as well as two privilege escalation vulnerabilities in Windows BitLocker (CVE-2025-54911, CVSS score: 7.3, and CVE-2025-54912, CVSS score: 7.8). Microsoft's Hussein Alrubaye has been credited with discovering and reporting both the BitLocker flaws. The two defects add to four other vulnerabilities in the full-disk encryption feature (collectively called BitUnlocker) that were patched by Microsoft in July 2025 - CVE-2025-48003 (CVSS score: 6.8) - BitLocker Security Feature Bypass Vulnerability via WinRE Apps Scheduled Operation CVE-2025-48800 (CVSS score: 6.8) - BitLocker Security Feature Bypass Vulnerability by Targeting ReAgent.xml Parsing CVE-2025-48804 (CVSS score: 6.8) - BitLocker Security Feature Bypass Vulnerability by Targeting Boot.sdi Parsing CVE-2025-48818 (CVSS score: 6.8) - BitLocker Security Feature Bypass Vulnerability by Targeting Boot Configuration Data (BCD) Parsing Successful exploitation of any of the above four flaws could allow an attacker with physical access to the target to bypass BitLocker protections and gain access to encrypted data. "To further enhance the security of BitLocker, we recommend enabling TPM+PIN for pre-boot authentication," Security Testing and Offensive Research at Microsoft (STORM) researchers Netanel Ben Simon and Alon Leviev said in a report last month. "This significantly reduces the BitLocker attack surfaces by limiting exposure to only the TPM." "To mitigate BitLocker downgrade attacks, we advise enabling the REVISE mitigation. This mechanism enforces secure versioning across critical boot components, preventing downgrades that could reintroduce known vulnerabilities in BitLocker and Secure Boot." The disclosure comes as Purple Team detailed a new lateral movement technique dubbed BitLockMove that involves the remote manipulation of BitLocker registry keys via Windows Management Instrumentation (WMI) to hijack specific COM objects of BitLocker. BitLockMove, developed by security researcher Fabian Mosch, works by initiating a remote connection to the target host through WMI and copying a malicious DLL to the target over SMB. In the next phase, the attacker writes a new registry key that specifies the DLL path, ultimately causing BitLocker to load the copied DLL by hijacking its COM objects. "The purpose of the BitLocker COM Hijacking is to execute code under the context of the interactive user on a target host," Purple Team said. "In the event that the interactive user has excessive privileges (i.e., domain administrator), this could also lead to domain escalation." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — Adobe Arm Broadcom (including VMware) Cisco Commvault Dell Drupal F5 Fortra FUJIFILM Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Google Wear OS Fortinet Hikvision Hitachi Energy HP HP Enterprise (including Aruba Networking) IBM Ivanti Jenkins Juniper Networks Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA QNAP Qualcomm Rockwell Automation Salesforce Samsung SAP Schneider Electric Siemens Sitecore Sophos Spring Framework Supermicro Synology TP-Link, and Zoom
thehackernews.comSep 10, 2025extracted
Someone Created First AI-Powered Ransomware Using OpenAI's gpt-oss:20b Model
Cybersecurity company ESET has disclosed that it discovered an artificial intelligence (AI)-powered ransomware variant codenamed PromptLock. Written in Golang, the newly identified strain uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts in real-time. The open-weight language model was released by OpenAI earlier this month. "PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption," ESET said. "These Lua scripts are cross-platform compatible, functioning on Windows, Linux, and macOS." The ransomware code also embeds instructions to craft a custom note based on the "files affected," and the infected machine is a personal computer, company server, or a power distribution controller. It's currently not known who is behind the malware, but ESET told The Hacker News that PromptLoc artifacts were uploaded to VirusTotal from the United States on August 25, 2025. "PromptLock uses Lua scripts generated by AI, which means that indicators of compromise (IoCs) may vary between executions," the Slovak cybersecurity company pointed out. "This variability introduces challenges for detection. If properly implemented, such an approach could significantly complicate threat identification and make defenders' tasks more difficult." Assessed to be a proof-of-concept (PoC) rather than a fully operational malware deployed in the wild, PromptLock uses the SPECK 128-bit encryption algorithm to lock files. Besides encryption, analysis of the ransomware artifact suggests that it could also be used to exfiltrate data or even destroy it, although the functionality to actually perform the erasure appears not yet to be implemented. "PromptLock does not download the entire model, which could be several gigabytes in size," ESET clarified. "Instead, the attacker can simply establish a proxy or tunnel from the compromised network to a server running the Ollama API with the gpt-oss-20b model." The emergence of PromptLock is another sign that AI has made it easier for cybercriminals, even those who lack technical expertise, to quickly set up new campaigns, develop malware, and create compelling phishing content and malicious sites. Earlier today, Anthropic revealed that it had banned accounts created by two different threat actors that used its Claude AI chatbot to commit large-scale theft and extortion of personal data targeting at least 17 distinct organizations, and developed several variants of ransomware with advanced evasion capabilities, encryption, and anti-recovery mechanisms. The development comes as large language models (LLMs) powering various chatbots and AI-focused developer tools, such as Amazon Q Developer, Anthropic Claude Code, AWS Kiro, Butterfly Effect Manus, Google Jules, Lenovo Lena, Microsoft GitHub Copilot, OpenAI ChatGPT Deep Research, OpenHands, Sourcegraph Amp, and Windsurf, have been found susceptible to prompt injection attacks, potentially allowing information disclosure, data exfiltration, and code execution. Despite incorporating robust security and safety guardrails to avoid undesirable behaviors, AI models have repeatedly fallen prey to novel variants of injections and jailbreaks, underscoring the complexity and evolving nature of the security challenge. "Prompt injection attacks can cause AIs to delete files, steal data, or make financial transactions," Anthropic said. "New forms of prompt injection attacks are also constantly being developed by malicious actors." What's more, new research has uncovered a simple yet clever attack called PROMISQROUTE – short for "Prompt-based Router Open-Mode Manipulation Induced via SSRF-like Queries, Reconfiguring Operations Using Trust Evasion" – that abuses ChatGPT's model routing mechanism to trigger a downgrade and cause the prompt to be sent to an older, less secure model, thus allowing the system to bypass safety filters and produce unintended results. "Adding phrases like 'use compatibility mode' or 'fast response needed' bypasses millions of dollars in AI safety research," Adversa AI said in a report published last week, adding the attack targets the cost-saving model-routing mechanism used by AI vendors. Update ESET, in a follow-up post shared on X, said the "PromptLock" ransomware is actually a proof-of-concept (Poc) rather than fully operational malware deployed in the wild. The PoC is part of a study published by a group of academics from the NYU Tandon School of Engineering last week. "Unlike conventional malware, the prototype only requires natural language prompts embedded in the binary; malicious code is synthesized dynamically by the LLM at runtime, yielding polymorphic variants that adapt to the execution environment," the researchers said. "The system performs reconnaissance, payload generation, and personalized extortion, in a closed-loop attack campaign without human involvement." Md Raz, the lead author on the Ransomware 3.0 paper, said the cybersecurity community's immediate concern following the discovery of the PoC highlights the need for taking AI-enabled threats seriously. "While the initial alarm was based on an erroneous belief that our prototype was in-the-wild ransomware and not laboratory proof-of-concept research, it demonstrates that these systems are sophisticated enough to deceive security experts into thinking they're real malware from attack groups," Raz added. (The story was updated after publication on September 3, 2025, to note that PromptLock is a PoC developed as part of academic research.)
thehackernews.comAug 27, 2025extracted
Loading 10 more…