Search/mandiant
Vendor

mandiant

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
first response
Connections
334 relationships
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. Police bust cybercrime ring accused of stealing €30 million in four-day spree German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. SafePal breach affects 39,798 customers, data allegedly for sale Cryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details. The company traced the exposure to an authorization flaw in a plug-in used for order tracking. Under certain conditions, the flaw let one customer view another customer’s order information. Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. France’s tax authority admits hackers made off with data on 678,000 individuals France’s tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals. The incident came to light after an alleged attacker using the alias “ZeroBytes” took credit on a cybercrime forum and listed a stolen database for sale. Hacker claims millions of records stolen from corporate Azure tenants A threat actor known as “TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), according to Hudson Rock. Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. ChatGPT’s new feature could give infostealers a map of your Mac activity OpenAI’s new Computer History feature turns recent Mac computer activity into memories ChatGPT and Codex can use, and it’s raising questions about privacy and security along the way. Computer History builds a timeline out of everyday computer use, grouping activity into summaries and noting which apps and websites contributed to each one. Cyberattack forces UT San Antonio to delay start of fall semester The University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now start on Monday, August 24. Google’s AI security agents found 100+ critical software vulnerabilities in just two days Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories. Medusa ransomware gang has hit over 500 organizations, CISA warns Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory first issued in March 2025 and draws on FBI investigations conducted as late as April 2026. Researchers find a loophole that lets expired credit cards make unauthorized payments A team from the University of Massachusetts Amherst has shown that a contactless credit card keeps working past its printed expiration date, even after the cardholder gets a replacement. They named it the Zombie Card attack and presented the findings at USENIX Security 2026. US charges 17 Iranian hackers over 31-terabyte academic data theft The U.S. has charged 17 alleged members of Mabna Institute, an Iranian hacking-for-hire company accused of running a years-long campaign that stole data from American universities, companies, and government agencies. The Southern District of New York case adds eight names to the nine already charged back in 2018. US agencies warn of AI-powered attacks on Siemens industrial controllers Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to US federal agencies. Fake Gemini installer delivers Vidar infostealer via Google Colab lure A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. A $25 template helped scammers build hundreds of phantom bank domains A phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly DeQuattro, the company’s VP of Operations, was reviewing a domain that resembled the brand of one of its financial services clients. The page carried none of that client’s branding. It presented an unrelated bank instead. Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. Attackers impersonate popular AI brands to spread malware Attackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other malware, according to Sophos. Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, and connected third-party apps. A hollowed out data layer is making CISOs fly blind into AI attacks The security industry is currently transitioning to an era where both offense and defense are AI-led, and every SOC operates at machine speed. However, what most CISOs have not yet reckoned with is that the AI defenders they are about to deploy will inherit a data foundation that two years of ingestion cost pressure has quietly hollowed out. The result is a security industry heading into an AI era with less visibility than it had five years ago. Download: 2026 Credential Risk Report 85% of cybersecurity professionals consider compromised credentials a primary attack path—yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where credential security programs fall short and what it takes to move toward Continuous Credential Defense. When companies get specific about AI, revenue growth looks different Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples depending on data availability. Product showcase: ScamNet looks for warning signs in suspicious calls and shady links ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform. Call protection is available on iPhone, while tools such as Visual Intelligence are supported on iPhone and iPad. The app is free with optional ScamNet+ subscriptions. Hazmat: Open-source containment for AI agents Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. Attackers turn to AI for help identifying files worth stealing AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, manage technical infrastructure and generate commands during intrusions. Gambit Security researchers examined three unrelated threat actors that show how AI can support different stages of a cyberattack. Google’s open-source HEIR lets AI work with data it can’t see Google’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development platform for homomorphic encryption. It can convert pre-trained AI models designed to operate on unencrypted data into models that process encrypted inputs. OpenAI tightens defenses after AI agents breach research environment Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The weaknesses included previously unknown vulnerabilities and credentials leaked online. Google’s $10,000 refund test shows why AI agents need zero trust Google’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions. Banks look for fraud signals in customer behavior Banks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking environment where social engineering, reimbursement requirements and growing case volumes are changing fraud operations. OpenAI puts major frontier AI training run on hold over cyber risks OpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring. The move followed the OpenAI-Hugging Face incident and preliminary evidence that the company’s upcoming Astra model may meet the Critical cybersecurity capability threshold under its Preparedness Framework. 8,539 reasons to rethink how vulnerabilities get patched The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. AI is making fraud harder to spot and identity harder to prove Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and account activity. OpenAI previews privacy-focused system for detecting AI misuse OpenAI is previewing Private Safety Processing with early customers seeking greater certainty about how their data will be protected as AI systems become more capable. The system identifies patterns across related interactions while restricting OpenAI personnel from accessing the underlying content. The company plans to start rolling it out and publish a technical white paper in September. AWS limits AI agents’ data access, even when manipulated AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services rather than relying on the agent itself. Nearly half of enterprises have no one leading PQC migration Enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Cybersecurity jobs available right now: August 18, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: August 21, 2026 Here’s a look at the most interesting products from the past week, featuring releases from F5 Networks, Intezer, Netscout, and Tufin.
helpnetsecurity.comAug 23, 2026extracted
If you're not using AI to attack your own systems, your adversaries will
AI agents excel at hacking organizations, as they’ve demonstrated in real-life attacks multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions. As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies. “There is tremendous risk associated with agentic AI and machine identities,” Matt Hartman, former acting head of cyber of the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register. “As AI moves from generating content – yesterday's use case – to taking actions, it is inevitable that agents are going to receive access to sensitive systems and sensitive data,” Hartman said. “One area where organizations are struggling today is that they're going to need to treat every agent as a privileged identity.” Enterprises also face agentic threats from outside their organization, he added. “AI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute,” Hartman said. “We're seeing very highly personalized phishing, very good impersonation, automated reconnaissance. That really makes traditional indicators of trust increasingly unreliable.” For defenders, this means a “continued focus on strong identity, on phishing-resistant authentication, on behavioral signals, and on zero-trust principles therein,” he added. “Nothing deeply new here - but it is a whole new attack surface.” Meanwhile, on the attackers’ side, agents don’t take time off, and they remain singularly focused on completing a task, whether that’s finding vulnerabilities and exploit chains or mapping networks and identifying sensitive files. All of this makes these near-autonomous attack bots a gift from the heavens for financially motivated criminals and government-backed cyber operatives. It also presents a security use case for defenders: agentic red teaming. As former NSA cyber boss Rob Joyce said during a talk at RSAC: if you aren’t using AI agents to attack your own organizations, you can bet that someone else is. “You are going to be red-teamed whether you pay for it or not,” Joyce said. “The only difference is, you know who gets the results delivered to them.” Hartman echoed Joyce’s words. “What we are seeing as the leading capabilities to help defenders – there is a burgeoning market for continuous, AI-native, AI-enabled, automated red teaming and pen-testing,” he told us. After spending nearly two decades in the federal government at CISA, Hartman joined Merlin Group in October as its chief strategy officer. In his new private-sector role, he helps determine which early- to growth-stage cybersecurity and emerging technology companies the group invests in, and then works with these firms to navigate government, critical infrastructure, and other highly regulated markets. The goal is to integrate and scale “promising technologies” into critical environments, Hartman said. Right now, most of these technologies use AI agents to fight AI agents. “Organizations are just inundated with vulnerabilities, and adversaries are able to leverage AI to find vulnerabilities and exploit them in seconds when it used to take days,” he said. Agentic red teaming “is a category of products that every organization, including federal agencies, absolutely needs in the near term just to keep pace.” 'Largest controlled live AI cyberattack on record' Mandiant founder and former CEO Kevin Mandia has a new company, Armadin, which launched in March with a startling $190 million in seed and Series A funding. The firm builds and trains autonomous attacker swarms – thousands of AI agents that run 24/7 in organizations’ infrastructure to simulate real-life attackers. Ahead of Black Hat earlier this month, the startup said it and Tenex.ai, an agentic security operations provider, executed what they called the “largest controlled live AI cyberattack on record” for an unnamed “leading” global institution. Over the three-day attack, Armadin's swarm generated 17 million offensive actions, discovered 38 validated attack paths, and produced 238 security findings. Tenex.ai's agentic platform separately triaged 100 percent of 101,169 alerts and reconstructed the entire attack across 231 billion raw events. This exercise, we’re told, would have taken a five-person analyst team about 2,400 hours – or four months – to pull off. Co-founder and Chief Offensive Security Officer Evan Peña was the global red-team lead at Mandiant before co-founding Armadin. At Mandiant, he led a 210-person team whose members spanned the globe. “The problem was it was 100 percent human-led security assessments, and that would generally limit the amount of time that we would have,” Peña told The Register. His red team “would do a couple weeks or a one-month engagement, and then we would report on the engagement, give them a PDF file, walk away, and they would hire us again in a year. In today’s age of AI, it’s very archaic to think about that when we can scale so significantly with AI.” Attack yourself before someone else does At Armadin, Peña leads the human team that trains the AI agents. One of the lessons learned from OpenAI’s models autonomously attacking Hugging Face, according to Peña, is that organizations need to perform safe offensive AI attacks against their own systems. "Safe" is the keyword here: remember OpenAI’s rogue models intentionally didn’t have any guardrails in place. Yes, his statement is self-serving as it's core to Armadin's business. But he’s not wrong. “Organizations can cover so much more attack surface because we are able to leverage these agents at scale, and we have three things that we didn’t have before,” he said. “We have more time, because agents don’t sleep and they don’t take holidays. There’s no workforce requirements for them.” Number two, he said, is expertise. Attack agents need pre-training before they are set loose on organizations’ infrastructure. They need to know how to code, and perform source-code review. They need to know how to do application security, how to spot network misconfigurations, and hack into different systems and networks. “And then you add post-training to that from human expertise,” Peña said. “Number three is coverage,” he said. “We were only able to cover a finite amount of attack surface in the past. So if you had 10,000 external systems with a limited amount of time and humans, you could maybe cover 2,000 or 1,000 of those within that particular period of time. Now we can cover all 10,000 in probably hours.” Armadin’s AI agents have broken into every single customer’s environment, according to Peña. “We have found over 50 zero-days, and by zero-days, I don't just mean this zero-day allowed you to deface a web page. That’s cool, but I want to break into your network from the internet,” he said. “The zero-days I'm referring to allow an attacker to get remote code execution on an actual system. They're very high-impact zero-days. We don't care about noise, we care about impact.” Quarterly pen-testing doesn't cut it anymore The biggest challenge these days for defenders is the scale and speed AI brings to previously manual attackers’ dirty work – like scoping potential victims, performing reconnaissance, identifying vulnerable systems and exploits, and reading logs. Now all of these tasks can be automated. Penetration testing needs to keep up, Jay Bavisi, founder and group president of EC-Council, told The Register. The largest and best organizations do pen-testing once a year to meet compliance requirements, and “the better ones” run these exercises quarterly, Bavisi said. This is largely because human-led pen-tests take about three months. “So you have a serious problem with speed,” he said in an interview. “Then comes the second problem, which is scope. Nobody pen tests the entire organization.” There’s also what Bavisi calls a “sophistication problem,” because different human pen-testers will produce varied results, and organizations can’t hire hundreds of thousands of humans to try to break into their networks on a continuous basis. “The bad guys are already using AI to get rid of the speed problem. You pen-test once a year for compliance. They do it all the time because you're a gold mine. They don't have a scope problem because they're not just looking at the crown jewels - they're looking at your entire organization. And they don't have a sophistication problem because they're using algorithmic systems.” In June, the global cybersecurity training organization began offering pen-testing professionals a sponsored attempt to take the CPENT AI examination, and upskill themselves for the AI era. For every participant who passes, the council donates $1,000 in cybersecurity training and certification credits to nonprofit partners. For every completed training program, regardless of an exam pass or fail, the nonprofits get $250, and all of this has a $1 million max. “The traditional model of pen-testing once a year or once a quarter, that’s going away, and AI will take over with automated pen-testing,” Bavisi said. “But will the role of pen testers vanish? No, it will not. It will evolve into something much bigger and something far more important.” AI systems and AI-integrated applications mean there’s a lot more for security professionals to try to break and break into, and humans need to determine: What is the result of this system breaking? What’s the business impact? What do I prioritize fixing? “The present pen-testers have to be reskilled into understanding business impact and being able to make those important engineering decisions,” Bavisi said. Meanwhile, “offensive AI security professionals are the ones that are going to have to test the robustness of AI systems, because AI systems will become the heartbeat of organizations,” he added. “Pen-testers have to become masters of testing LLMs, understanding agentic behavior, thinking about what is the harm taxonomy, figuring out what kind of guardrails did we put in place.” The job of pen-testers has changed, in other words. “It now has a far wider scope.” ®
theregister.comAug 22, 2026extracted
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner account on August 20, 2026, and all removed within 86 to 107 minutes. Because the malicious code sat in the build script of the injected dependency, building a project that resolved it was sufficient to run the payload, and nothing from the crates themselves had to be called. Developers are advised to search ~/.cargo/registry/cache for the deleted crate files and to pin arrayref at 0.3.9 or earlier, after the Rust Security Response Team unyanked the maliciously-yanked versions during the response. There is no patched version, no CVE identifier has been assigned, and the RustSec advisories for all three crates record no evidence that any malicious version was used. "A new version of the arrayref crate was published with a direct dependency on proc-macro1, which would execute a malicious build script. This compromised version was published on 2026-08-20 and removed approximately 86 minutes later, with no evidence of actual usage," RUSTSEC-2026-0260 said. The Hacker News has reached out to the Rust Security Response Team for the basis of that finding and for the download count of the deleted versions, but had not received a response at the time of writing. The Rust Security Response Team said it received the report that the proc-macro1 crate was malicious at 07:15 UTC on August 20 and verified that the crate carried a build script downloading a malicious payload, in an advisory post crediting the Research Team at Nextron Systems GmbH with initially discovering and reporting it. "We do not believe the author of arrayref to be acting maliciously, but their computer or credentials are likely compromised, and we are attempting to contact them," the Rust Security Response Team said. The Hacker News confirmed via the crates.io API on August 21 that the sole listed owner of arrayref is user 2402, David Roundy, registered in October 2009. How the account was compromised has not been disclosed. The Rust Security Response Team listed the malicious versions it deleted, with the time each was online - [email protected] : published at 2026-08-20T07:15:00Z, deleted at 08:41:40Z. Online for 86 minutes. [email protected] : published at 07:34:07Z, deleted at 09:04:11Z. Online for 90 minutes. [email protected] : published at 07:37:49Z, deleted at 09:25:24Z. Online for 107 minutes. proc-macro1 ,proc-macro-en ,aovine ,arone ,aronenao , andtinymember , any versions. Each compromised release carried a single added line in its manifest, a dependency on proc-macro1, a typosquat of the ubiquitous proc-macro2 crate. The library source of proc-macro1 is a genuine copy of proc-macro2, so builds completed normally. The build script reassembles its payload host and command-and-control (C2) address from base64 fragments at build time. It then installs a custom certificate verifier whose three verification methods return success unconditionally, disabling TLS validation. It selects one of four payloads by operating system and CPU architecture. On Unix and macOS it writes the bytes to /tmp/rust-setup, marks the file executable, and spawns it detached with the C2 address as its first argument. On Windows it writes a PowerShell script to %TEMP% and launches it hidden through a VBScript launcher under wscript.exe, then abandons the child process, a step commented in the source as escaping Cargo's job object so the build does not wait on it. Delivery relied on the owner account yanking arrayref 0.3.5 through 0.3.9 within the same minute as the malicious publish, leaving the compromised release as the only version Cargo would not warn about, according to the report filed to the RustSec advisory database by the researcher who hit it. "Delivery: 0.3.5–0.3.9 are all yanked under the owner account, so cargo's consider updating to a version that is not yanked warning is the lure. That is how I hit it," the reporter, GitHub user jhobern, said. The Hacker News found via the crates.io API on August 21 that arrayref has 245,385,500 downloads all time and 53,905,601 in the 90 days ending August 20, and that 403 distinct crates on crates.io depend on it. We also verified each hop of the dependency chain named in the report against the crates.io index on August 21: winit requires sctk-adwaita ^0.10.1, which requires tiny-skia ^0.11, which requires arrayref ^0.3.6. Every requirement in that chain is a caret range on 0.3.x, and a caret range on 0.3.x accepts 0.3.10. The same check found that blake3 declared arrayref as a dependency through version 1.8.6 and does not in 1.8.7, published at 09:09 UTC on August 20, and that blake2b_simd and blake2s_simd dropped the same dependency in releases published at 09:25 and 09:26 UTC that morning. The stage-2 implant beacons over HTTPS POST to the path /49890878, persists through a Registry Run key on Windows, a LaunchAgent on macOS, and a systemd user service on Linux, and supports four commands covering termination, C2 reconfiguration, persistence installation, and downloading and running further scripts, according to Wiz, which said it steals browser credentials from Chrome, Brave, and Edge by querying SQLite login databases. The Nextron researcher analysis says the analysed Windows stage queries only the origin_url and username_value columns and does not directly extract password_value, but that analysis covered the Windows payload alone, with the Linux and macOS payloads hashed and not analysed. The same analysis notes the crate may be triggered by cargo build, cargo check, and cargo test. StepSecurity shared the following indicators of compromise (IoCs) - Network: 23.254.165.112:9089 (payload host),23.254.165.112:443 (C2),hwsrv-798836.hostwindsdns.com Files: /tmp/rust-setup ,%TEMP%\rust-setup.ps1 ,%TEMP%\rust-setup-launch.vbs Binaries: rust-crate_0.1.0 ,_0.2.0 ,_0.3.0 ,_0.4.0 Accounts: dtolney (crates.io id 438608), impersonator;droundy , legitimate owner, presumed compromised Email: [email protected] , forged author metadata Wiz said the infrastructure substantially overlaps with recent North Korean supply chain attacks, naming the Mastra npm compromise and the axios compromise. Microsoft assesses with high confidence that the Mastra activity is attributable to Sapphire Sleet, and Google Threat Intelligence Group (GTIG) attributed the axios compromise to an actor it now tracks as MIDNIGHT NEPTUNE, formerly known as UNC1069. No vendor has attributed the crates.io incident to a named actor. "While the malicious versions of axios were removed from the npm registry within three hours of their release, the scope of the compromise is estimated to be broad, as the package has over 100 million weekly downloads," GTIG and Mandiant said in a July 30 report recommending cooling windows on newly published third-party assets. Cargo has no shipped equivalent. A pull request stabilizing a global-min-publish-age setting, which would hold back dependencies younger than a configured age, entered its final comment period on August 18, two days before the attack, and remained open and unmerged as of August 21. GitHub shipped a similar cooldown default for Dependabot in July. In a September 2025 case, two malicious crates impersonating a logging library executed only at runtime, a distinction crates.io drew at the time.
thehackernews.comAug 20, 2026extracted
Google’s AI security agents found 100+ critical software vulnerabilities in just two days
Google’s AI security agents found 100+ critical software vulnerabilities in just two days Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories. The tool, called the Agentic Vulnerability Discovery Harness (AVDH), has been running inside Mandiant for ten months. In that time it has scanned tens of millions of lines of code and produced tens of thousands of findings, according to a blog post published by the Google Threat Intelligence Group. The tool has uncovered dozens of assignable flaws in widely used web extensions and open-source projects, Mandiant researchers Alex Tselevich and Michael Maturi wrote, resulting in 12 assigned CVEs, including CVE-2026-13242 and CVE-2026-55803, with “an additional dozen currently in active disclosure.” How the pipeline works AVDH runs as a sequence of specialised agents, each handing its output to the next, built on Google’s Agent Development Kit. The stages are: Threat modeling: An agent maps the codebase, figures out what kind of software it is, and marks which parts to skip, such as test directories. A human reviews the resulting threat model before anything else happens. Entry point discovery: Agents scan every file in scope to find places where user input enters the application, from web routes to inter-process listeners. Context enrichment: For each entry point, an agent pulls together scattered, relevant code, such as permission checks and input sanitizers, that a reviewer would otherwise have to chase down by hand. Hypothesis generation: Separate agents look for access-control problems, including missing authorization, privilege escalation, and cross-site request forgery, and for dangerous data flows, the kind that lead to SQL injection, cross-site scripting, command injection, and path traversal. Hypothesis validation: Several agents, deliberately run at high “temperature” settings to widen the range of reasoning they produce, weigh in on each hypothesis. A synthesis agent then sorts each one into confirmed, disproven, or rejected. Every confirmed finding still goes to a person before it counts for anything. Mandiant consultants reproduce the exploit and run proof-of-concept code to check that the flaw is genuine and that no overlooked control blocks it. Findings that fail that test get thrown out. Human-in-the-loop handover diagram (Source: Google) “We encourage network defenders considering implementing similar vulnerability discovery harnesses to manually validate findings,” Mandiant researchers Alex Tselevich and Michael Maturi noted. Cutting down on false alarms Automated code scanners have long had a reputation for noise, findings that look plausible on paper but don’t hold up once someone checks them. Mandiant says it built AVDH specifically to fight that problem, by having agents challenge each other’s conclusions and check them against rules written by its own consultants, rather than simply flagging code patterns that resemble known bugs. Those rules are organised by software domain, then split into three groups, language, framework, and vulnerability type, so the knowledge stays reusable as the tool is pointed at different codebases. To grade its own performance, Mandiant built a set of synthetic, deliberately vulnerable codebases rather than relying on public vulnerability datasets, out of concern that today’s models may already have seen those datasets during training and could be recalling answers rather than reasoning through them. “Securing the software development pipeline has emerged as a defining challenge in modern enterprise defense.” “To match these emerging threats, securing the code pipeline must be a critical component of a modern defense strategy. Manual source code review can’t keep pace with AI, and traditional scanning engines consistently miss the broad spectrum of vulnerabilities hidden in modern software,” researchers added. “However, the success of our harness proves defenders can reclaim the advantage against adversarial AI. By embedding frontier models within an expert-defined harness, defenders can automate the discovery of routine vulnerabilities,” they concluded.
helpnetsecurity.comAug 19, 2026extracted
TeamPCP Traced Back to 2020 Cryptojacking Operation
The group behind March's cascading supply chain attacks on open-source developer tools has been linked to infrastructure attacks dating back to 2020 and the first known self-propagating botnet built from hijacked AI infrastructure. New research published by Oligo Security on August 5 showed that TeamPCP shares domains, malware deployment paths and backend infrastructure with activity previously tracked as TA-NATALSTATUS between 2020 and August 2025. Oligo Security worked with Mandiant and GitLab on the investigation, and GitLab banned the accounts involved. The firm also assessed that TeamPCP ran ShadowRay 2.0, the campaign it documented in November 2025 against exposed Ray clusters, which it had attributed at the time to an actor called IronErn440. A Deployment Framework Reused for Years The strongest infrastructure link identified was masscan[.]cloud, which appears across TA-NATALSTATUS activity, ShadowRay 2.0 and later TeamPCP operations. Certificate transparency records date it to May 11, 2025, and TeamPCP's own GitHub account later listed it as the group's official website. Alongside it, Oligo found the same deployment framework reused for years: a distinctive directory path and a set of staging scripts documented in earlier TA-NATALSTATUS campaigns turning up unchanged in TeamPCP payloads. A compromised Ray cluster logged a download from that infrastructure on July 26, 2025, five months before the TeamPCP name surfaced publicly. The most direct evidence came from GitLab. One IP address received reverse shells from a compromised Ray cluster between October 15 and November 2. All shells terminated on November 2, and between November 2 and 4 the ironern440 account authenticated to GitLab from that same address, which hosted the campaign's tooling. From Cryptojacking to Wiper Oligo's timeline has the operators exploiting internet-facing infrastructure as early as 2020, often with automated and wormable techniques, before expanding into GitHub Actions abuse and token theft. That progression ran through PCPcat, which peaked around Christmas 2025 against React2Shell targets and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM. The infrastructure also broadened beyond exploitation, with subdomains observed supporting credential phishing, payment fraud and Zendesk impersonation. In late March, a second-stage Kubernetes payload gained a destructive branch. The script checked whether the victim system was set to the Iran timezone and, if so, deployed a destructive workload that deleted filesystems and rebooted the machine. Oligo noted that Iranian connectivity was heavily disrupted at the time, limiting visibility into whether it ever executed. Oligo was careful about how far the attribution extends. Whether the continuity reflects a direct rebrand, a shared operator set or close collaboration between related actors cannot be established with certainty, the firm said. What the evidence shows is that TeamPCP continues an existing operational ecosystem rather than being a new group that appeared in late 2025.
infosecurity-magazine.comAug 6, 2026extracted
Tanium expands autonomous security across AI, exposure management and SecOps
Tanium expands autonomous security across AI, exposure management and SecOps Tanium has announced a series of new autonomous security capabilities across the Tanium Autonomous IT Platform. Spanning agentic AI, exposure management and security operations, the capabilities empower IT and security operators to stay ahead of an AI-accelerated threat landscape, safely, without losing control. “Tanium is the platform that governs and manages them with Tanium Atlas — where every action is auditable, boundaries are enforced, and everything is grounded in what’s actually happening on the endpoint right now. What we are introducing extends that same principle across the full lifecycle from external exposure to detection to remediation,” said Harman Kaur, CTO at Tanium. That attack surface is expanding on every front: more identities, cloud services, and AI tooling are being deployed faster than security teams can vet them, while attackers use that same AI to move at machine speed. Keeping pace, let alone getting ahead, demands autonomous security: the ability to detect, decide, and remediate at that same speed. That is what Tanium is delivering, extending the Tanium Autonomous IT Platform across three areas: agentic AI, exposure management, and security operations, giving operators a complete view from external attack surface to endpoint, and the ability to act on it autonomously, at scale. Agentic AI and Tanium Atlas Tanium Atlas is an autonomous operating system built natively on the Tanium Autonomous IT Platform. It is designed to take IT and security operators from question to resolution in a single experience. Tanium Atlas runs through a governance model that makes it auditable and keeps it within limits defined by the operator, and can be reviewed after the fact. New capabilities within Tanium Atlas include: Agentic Performance Analysis: With the introduction of Agentic Performance Analysis, an operator can use Tanium Atlas to trace a slow machine back to its actual root cause in moments, replacing hours of manual log correlation. Background AI Agents: Tanium Atlas doesn’t just wait for someone to ask. Background AI Agents continuously surface issues before operators need to ask, and Tanium Atlas executes full alert-to-resolution workflows within limits operators define. Tanium Automate: Tanium Automate is expanding with endpoint-level sequence execution and a generalized API step, enabling playbooks to run faster on each endpoint while also connecting directly to external systems through REST and GraphQL APIs. As Tanium Atlas advances, Automate becomes the governed execution layer that turns endpoint intelligence and AI-assisted recommendations into safe, orchestrated action across endpoints and connected systems. Tanium Atlas MCP Server: Tanium Atlas MCP Server exposes approved Tanium data and actions as tools inside Claude, Microsoft Security Copilot, Copilot Studio, and other MCP-compatible AI clients through a governed Model Context Protocol server, allowing agents to interact with the Tanium Autonomous IT Platform and Tanium Atlas. That real-time endpoint foundation extends beyond the endpoint itself, to what an organization has exposed to the internet. Exposure management Organizations have blind spots beyond the firewall, and AI is accelerating how fast new vulnerabilities surface, with no clear sense of what to fix first. Fragmented tools amplify the problem, leaving teams exposed for longer than ever. Tanium is introducing two new exposure management capabilities that address this directly. Tanium’s External Attack Surface Management: This capability closes that gap by unifying real-time internet visibility from Censys to continuously discover an organization’s internet-facing assets, including hosts, services, web properties, and certificates, with endpoints to provide one continuously updated view of the full attack surface. Attack Path Mapping: Attack Path Mapping connects the dots between something exposed on the internet and what it can reach inside an organization’s network, showing the exact chain an attacker would follow to access the most sensitive systems. Instead of chasing every vulnerability equally, teams can see which single fix would shut down the most attack routes at once, prioritizing the fixes that get closest to an organization’s crown jewels. Tanium Endpoint Management is the connective tissue that turns these findings into confident, autonomous action. Because Tanium collects real-time intelligence from every endpoint, Exposure Management never scores risk in the abstract. Knowing where you are exposed is only part of the picture. When threats are already in motion, operators need the ability to hunt, validate and respond at the same speed attackers move. Security operations Tanium is introducing two new security operations capabilities: Agent-Guided Threat Hunting and the Tanium and Google Threat Intelligence integration. Proactive threat hunting is one of the most valuable things a security team can do, and one of the least done because it takes a rare kind of expert and hours of manual work per hunt. Agent-Guided Threat Hunting: Tanium Atlas changes the economics of proactive threat hunting. A hunter describes a hypothesis in plain language, and Tanium Atlas runs the hunt autonomously across the estate, reasoning over live endpoint data, choosing the right tool for the question, and mapping what it finds to MITRE ATT&CK. Tanium and Google Threat Intelligence integration (private preview): A hypothesis often starts with intel, and that’s where Tanium and Google Threat Intelligence comes in. SecOps teams buy threat intel, but the hard part is knowing whether a threat is live in your environment, and stopping it before it spreads. The intelligence gained from Mandiant’s frontline expertise, VirusTotal’s crowdsourced data and Google’s vast visibility is now incorporated with Tanium’s real-time visibility and control across more than 36 million endpoints worldwide, so hunts and triage start from a higher-confidence signal, and analysts spend less time chasing false positives. This integrated offering can quickly take a hunter from intel to live hunt to fleet-wide action. “Effective security operations require both high-fidelity intelligence and the ability to act on it instantly,” said Miton Adhikari, head of Google Security OEM Partnerships at Google. “By incorporating Google Threat Intelligence into Tanium’s real-time visibility and control across endpoints, Tanium operators can validate signals against what’s actually running in their environment and rapidly move from intel to remediation, at scale.” The capabilities Tanium is introducing share a single foundation: Tanium Atlas, the autonomous operating system that connects external exposure, endpoint intelligence and security operations into one governed, auditable experience. For IT and security operators facing an AI-accelerated threat landscape, that foundation is what makes autonomous security possible, not by removing humans from the loop, but by giving each operator the reach and speed to stay ahead of it, safely.
helpnetsecurity.comAug 4, 2026extracted
Google changes how it names cyber threat actors
Google changes how it names cyber threat actors Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes built up over years. Previously, Mandiant and Google’s Threat Analysis Group maintained separate naming schemes, resulting in a mix of sequential identifiers, such as APT1, and other independently developed names. GTIG says this made it harder for defenders to distinguish between the groups. “We know there are many threat actor tracking schemas in the industry, so we are intentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies. However, a significant caveat remains: because no two organizations have the exact same visibility into the threat landscape, direct, apples-to-apples comparisons between threat actors are rarely possible,” Google said. “Transitioning to a convention that is simpler to follow and remember is a practical step toward managing a highly intricate tracking problem,” the company added. The new system assigns every tracked threat actor a two-word cryptonym. The first word identifies the specific group. If a name from earlier public reporting already exists for that actor, GTIG keeps it. If not, the word is generated at random to avoid bias before being reviewed by analysts. The second word identifies the threat actor’s category, which may reflect assessed country attribution, criminal motivation, or another activity type. These are the category names Google will use under the new system: People’s Republic of China groups get CASTLE Iran-linked groups get ION North Korean groups get NEPTUNE Russian groups get RELIC Cybercriminal groups get COMET For example, the Russian state-linked group long known as Sandworm, or APT44, now carries the cryptonym SANDWORM RELIC. The first word keeps the identifier analysts already recognise, while the second immediately indicates the group’s assessed Russian state affiliation. Threat actor name appearance in GTI platform on initial rollout (Source: Google) GTIG has begun renaming several dozen of the most active threat groups and says additional actors will be updated over time. Existing names will not disappear. Previous names will remain searchable in the Google Threat Intelligence platform alongside MITRE ATT&CK mappings and aliases used by other security vendors. “We will continue to use UNC, or ‘uncategorized’ designations for threat clusters that are still in the early stages of investigation,” the company concluded.
helpnetsecurity.comJul 27, 2026extracted
Key vulnerabilities of Microsoft’s July 2026 Patch Tuesday
Although experts had already warned of an impending “tsunami of vulnerabilities” back in April, immediately following the announcement of the Mythos AI model, concrete evidence began to emerge over the summer. June’s Patch Tuesday was massive and, at the time, a record-breaker (around 200 CVEs), and right before that, hundreds of fixes were released for Chromium-based browsers, including Chrome and Microsoft Edge. But July revealed this new trend in all its glory. Yesterday’s Patch Tuesday addressed 570 vulnerabilities in Microsoft products, and if we are including the “platform-level” patches that Microsoft applies to its own servers, the total rises to 620. And that’s not even counting the 470 vulnerabilities in Chromium. In just six months, Redmond has already fixed more defects than in any previous year over the past 20 years of observation. Depending on which products are included in the final figures, the number of CVEs may vary slightly; various experts cite figures of 569, 570, 621, 622 — but anyway this figure is three times higher than the previous update package and five to 10 times higher than last year’s typical figures for monthly update. The fixed vulnerabilities are broken down by category as follows: 254 — elevation of privilege (EoP), 145 — remote code execution (RCE), 102 — information disclosure, 35 — denial of service (DoS), 17 — security feature bypass, and 16 — information spoofing. EoP vulnerabilities accounted for nearly 44% of the release, while RCE vulnerabilities accounted for a quarter. Rapid7 experts separately note 416 bugs in Windows itself (also a record), and the fact that the release notes no longer list CVEs individually. Instead, there is a summary table organized by product families and a new section titled “Notable CVEs”. Incidentally, in that section, Microsoft managed to list CVE-2026-56155 twice instead of another zero-day vulnerability. This brevity is partly due to the fact that the update package affects a very broad range of products. Even very old, rarely used components — such as MIDI drivers — have been updated, as well as games, including Age of Empires II (CVE-2026-50663) and Minecraft Bedrock Dedicated Server, where the high-impact CVE-2026-55010 (CVSS 9.8) was found — a heap overflow leading to RCE without authentication. Of the entire set, only three vulnerabilities are classified as zero-day, and 59 have been rated critical. Among the critical vulnerabilities, 48 can lead to RCE, nine to privilege escalation, one to security feature bypass, and one allows spoofing. Vulnerabilities exploited in real-world attacks or known prior to the patch CVE-2026-56155 (CVSS 7.8) — privilege escalation in Active Directory Federation Services. Due to access control flaws, a user with low local privileges can elevate them to administrator level. No details are provided about attacks exploiting this vulnerability, but the description acknowledges the effort of Microsoft DART staff — the incident response team. The vulnerability has already been added to the CISA KEV catalog. CVE-2026-56164 (CVSS 5.3) — privilege escalation via Microsoft SharePoint Server: a lack of authentication for a critical function. The attack complexity for exploiting this vulnerability is low; no authentication or user interaction is required, and Microsoft explicitly states that an attacker doesn’t need in-depth knowledge of the system. Affected versions include SharePoint Enterprise Server 2016, Server 2019, and the Subscription Edition. Credit for the discovery goes to experts at Mandiant Incident Response, Google Cloud, FLARE OTF, and an anonymous contributor — the acknowledgments list once again reads like a breakdown of an active incident, and not just a single one. Until the patch is installed, enabling AMSI with Request Body Scan set to Full can help, but this is a temporary measure, not a substitute for the update. CVE-2026-56164 has also already been added to CISA’s KEV. The third zero-day vulnerability has “merely” been disclosed prior to remediation; there are no reports of it being exploited in attacks. However, this is due to the nature of the vulnerability — we’re dealing with yet another BitLocker bypass — CVE-2026-50661 (CVSS 6.1) — therefore exploitation requires physical access to the machine. Microsoft considers exploitation unlikely, and authorship is attributed to an “anonymous” individual. Presumably, the patch addresses GreatXML — a BitLocker bypass that a researcher going by the nickname Chaotic Eclipse (Nightmare Eclipse) published on June 10, the day after June’s Patch Tuesday. Laptops and any devices that leave the corporate perimeter should be patched as a priority. Critical vulnerabilities in July’s Patch Tuesday There are many critical vulnerabilities, so we’ll highlight only the most urgent ones. In our list, the CVSS score never drops below 9.6. CVE-2026-57092 (CVSS 9.9) — EoP in VMSwitch, allows escape from an isolated environment with full host compromise. A use-after-free vulnerability that allows a low-privileged attacker to cross the virtual machine boundary and gain access to the host. ZDI notes that a similar exploit was demonstrated at Pwn2Own Berlin on ESXi. Hyper-V users need to update VMSwitch today. CVE-2026-56190 (CVSS 9.8) — RCE in RDP, unauthenticated, network-based, no user interaction required. Those with RDP servers accessible via the internet are at critical risk; such configurations are practically unsustainable in 2026. CVE-2026-50518 (CVSS 9.8) — RCE in the DHCP server: heap overflow, unauthenticated, network-based. And this isn’t the only problem with the DHCP server. In this release, it also contains CVE-2026-50370, -56159, and -48564, while the DHCP client contains CVE-2026-54128. CVE-2026-50522 and CVE-2026-58644 (both CVSS 9.8) — a pair of RCE vulnerabilities in SharePoint servers: deserialization of untrusted data, unauthenticated, and without user interaction. Although Microsoft describes the exploit’s reliability as “unproven”, this is, to put it mildly, untrue. For CVE-2026-50522, a working exploit was demonstrated at Pwn2Own Berlin. In the same group is CVE-2026-55040 (CVSS 9.1), an authentication bypass discovered by Rapid7 experts. Exploiting this vulnerability is the first link in the attack chain; the second is currently under embargo and will be disclosed (and patched) in August Patch Tuesday. Together, they enable RCE without authentication. Meanwhile, the July Patch Tuesday marks the end of support for SharePoint Server 2016 and 2019. CVE-2026-56188 (CVSS 9.8) — RCE in the Windows Server network driver. The exploitation is highly complex (TOCTOU), but if successful, this vulnerability allows privileged code to be executed over the network without user interaction — in other words, it enables the creation of network worms. CVE-2026-55008 (CVSS 9.6) — spoofing in Exchange Server (it’s unclear why this is called spoofing, as the description explicitly states “XSS”). An attacker sends a specially crafted email; the victim simply opens it in OWA — and arbitrary JavaScript is executed in their session. The reason behind the “tsunami” and how to deal with it If such patch releases become the norm, without a radical overhaul and automation of vulnerability management processes, security and IT teams will have nothing to do but apply updates. There are indications that this is the new normal, and the tsunami could last for many months — possibly years. At Microsoft, the reason is called MDASH — multi-model agentic scanning harness. A few days before the release, Microsoft officially acknowledged that its AI-powered vulnerability scanning system is actively analyzing critical Windows components, and warned customers that the volume of updates in each release will only increase. That said, Redmond is not alone; Adobe and Cisco, for example, have recently announced an increase in the frequency of their updates. So how can an organization adapt its processes and technologies to this pace and volume of updates? Automate in-depth host scanning, maintain a list of priority patches, install applicable updates, and verify that vulnerabilities are actually patched. With 500+ defects per month, manually transferring tickets from the scanner to a task tracker or launching update tasks simply isn’t possible. Prioritize efforts effectively. It’s nearly impossible to address a release of this magnitude in its entirety all at once, so a process that takes into account the severity of vulnerabilities, the likelihood of them being exploited in the company’s infrastructure, and the business impact becomes absolutely essential. Set up organizational processes. Technically, a patch can often be applied in minutes, but the approval process can take weeks as it makes its way through various departments, as can the process of initiating and managing that approval. Vulnerability management must be tied to an approval process that is as short, simple, and automatically documented as possible. If a decision regarding a specific vulnerability requires setting aside a maintenance window and obtaining approval from an entire committee, the process must be given high priority by that committee. Otherwise, by the time the patch is installed, Microsoft will have released the next 600 vulnerabilities.
kaspersky.comJul 15, 2026extracted
Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip
Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip Spanish police have arrested a man suspected of supporting some of Russia's most prominent hacktivist groups and helping a Ukraine-based member of one flee to Russia. The suspect was arrested in March in the northern city of Palencia after an investigation, launched with information provided by the FBI, linked him to the pro-Russian groups CyberArmy of Russia Reborn (CARR), Z-Pentest and NoName057(16). In a statement released earlier this week, police alleged that the man, whose identity has not been disclosed, provided logistical support to a Ukrainian hacker linked to CARR in an effort to help him escape to Russia through Poland and Belarus. Authorities also accused the suspect of communicating with members of Russian hacktivist groups through encrypted messaging apps, coordinating activities and supporting operations attributed to NoName057(16), a group best known for disruptive distributed denial-of-service attacks against governments and organizations supporting Ukraine. During a search of the suspect's home, officers seized computers and cryptocurrency storage devices and froze a cryptocurrency wallet that investigators believe received proceeds from the sale of information obtained through criminal activity. Spanish police said the suspect is being investigated for alleged membership in and collaboration with a terrorist organization, glorification of terrorism and computer-related damage, although formal charges have not yet been announced. In comments to the Russian technology outlet SecPost, a person claiming to represent Z-Pentest said the group did not know who had been detained and suggested police may have made a mistake. The representative said the group had asked "its people in Europe and Spain" to gather information about the suspect. International targets The arrest is the latest international law enforcement action against individuals allegedly linked to Russian government-aligned hacktivist groups. In 2024, the U.S. sanctioned two alleged members of CARR, including its purported leader and primary hacker, accusing them of targeting U.S. critical infrastructure. According to the U.S. government, the group has claimed attacks on industrial control systems at water, hydroelectric, wastewater and energy facilities, although many of its operations have consisted of relatively unsophisticated DDoS attacks. European authorities also have intensified pressure on NoName057(16). Last year, an international law enforcement operation disrupted much of the group's infrastructure, targeting more than 100 servers and issuing seven international arrest warrants. Despite the operation, the group has continued to claim cyberattacks against countries backing Ukraine. Security researchers have long argued that many Russian hacktivist groups operate much more closely with the Kremlin than they publicly acknowledge. Earlier this year, Mandiant reported that CARR maintains a close operational relationship with Sandworm, the notorious hacking unit linked to Russia's military intelligence. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaJul 8, 2026extracted
Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. According to Cisco Talos researchers, the ORB network serves as a secure relay infrastructure for other China-aligned advanced persistent threats (APTs), including UAT-5918. This type of infrastructure, which was previously documented by Google Mandiant, allows threat actors to proxy their network traffic through regional devices, making it appear to originate from legitimate local infrastructure to evade detection and complicate attribution. The Talos analysts have identified new malware in the campaign, including LONGLEASH, a new version of the previously documented SHORTLEASH backdoor, DOGLEASH, a Linux backdoor, JARLEASH, an administrative tool, and LEASHTEST, a testing utility. The researchers report that UAT-7810 primarily exploits known (n-day) vulnerabilities to gain initial access, including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 in Ruckus routers, as well as CVE-2025-2492 in ASUS AiCloud routers. LONGLEASH malware The newly discovered LONGLEASH malware is an upgraded version of SHORTLEASH, first documented by SecurityScorecard in 2025, that significantly expands its capabilities. The malware builds on the previous version, which supported command-and-control (C2) communications, web server hosting, network tunnel management, and operation as both a C2 server and client. In addition to those, Talos researchers have now also observed the following capabilities: Reverse shell HTTP, DNS, SOCKS, TCP, ICMP, and UDP proxying with traffic redirection SMTP client/server functionality TLS and PKI support Self-removal for when tampering or other suspicious activity is detected Ability to act as an intermediate C2 server, forwarding commands and data between infected nodes DOGLEASH, JARLEASH, and LEASHTEST Apart from LONGLEASH, the researchers have also discovered DOGLEASH, a lightweight Linux backdoor deployed via web shell scripts. Upon launch, it opens a listening TCP port and authenticates incoming requests using a hardcoded password, supporting shell command execution, file access and modification, OS information retrieval, and arbitrary code execution directly in the host's memory. JARLEASH is a Java-based administrative tool that provides web-based file management and includes FTP, SFTP, and Netcat server functionality. Finally, the threat actors have developed LEASHTEST, which can be used to verify whether an MIPS IoT device can perform functions related to malware operations, likely to help refine LONGLEASH’s MIPS support. Cisco Talos concludes that UAT-7810 continues to expand its ORB infrastructure, actively replacing or extending SHORTLEASH with the more capable LONGLEASH while broadening its toolkit with new malware. A complete list of the indicators of compromise (IoCs) linked to UAT-7810 activity and the latest toolset is available at the bottom of Cisco Talos’ report. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 7, 2026extracted
Cisco Vulnerability Exploited Months Before Disclosure, Google Warns
A threat actor started exploiting a severe vulnerability in Cisco products at least two months before the flaw was disclosed, a new Google report warned. Tracked as CVE-2026-20245, this high-severity (CVSS 7.8) privilege escalation vulnerability stems from insufficient validation of user-supplied input in the command-line interface (CLI) of Cisco Catalyst SD-WAN Controller, formerly known as SD-WAN vSmart. It affects several versions of Cisco Catalyst SD-WAN Manager as well as related products like Cisco Catalyst SD-WAN Validator. Affected versions of these products are vulnerable regardless of the installation – on-premises, Cloud-Pro, Cloud (Cisco Managed) and Government (FedRAMP). Authenticated, local attackers can exploit it by uploading a crafted file to the affected system and can consequently execute arbitrary commands as root. The zero-day vulnerability was disclosed by Cisco on June 4 after it has observed “limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.” However, at the time of disclosure, no patch was available. The tech giant started releasing Catalyst SD-WAN Manager updates with the CVE-2026-20245 fix on June 10. Vulnerability Disclosure in June, Exploitation in March In a new report published on June 24, security researchers at Mandiant, part of Google Cloud, said they identified a threat actor targeting SD-WAN infrastructure at a service provider in early 2026. From late 2025 to January 2026, Mandiant observed multiple unauthorized peering connections to the victim’s SD-WAN Manager devices. The researchers noted that this malicious activity could be linked to the exploitation of CVE-2026-20127 or CVE-2026-20182 as the vulnerabilities were not disclosed, and patches were not available during this period. CVE-2026-20127 and CVE-2026-20182 are critical vulnerabilities recently disclosed by Cisco that affect the peering authentication mechanism for Cisco Catalyst SD-WAN controllers. Both could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges. The Mandiant researchers noticed further unauthorized peering connections on a device running a software version unaffected by CVE-2026-20127 in March. They checked with Cisco, which confirmed that these connections did not leverage CVE-2026-20182 either and could instead be using stolen certificate material from a previous compromise of the same device. They later found that a threat actor established initial access via unauthorized peering connections to facilitate Secure Shell (SSH) access and then used that access to manipulate default account passwords to evade detection. They also identified that a threat actor exploited what is now known as CVE-2026-20245 in Cisco Catalyst SD-WAN Manager to gain root-level access via a malicious CSV upload. This latter actor then deleted malicious files, reverted configuration changes and executed a validation script to ensure indicators have been purged. “It is unclear if the same threat actor was responsible for the late 2025 to January 2026 and March 2026 rogue peering activity,” Mandiant said. New Living-Off-the-Edge Paradigm for Threat Actors Nevertheless, Google highlighted that this campaign “underscores the living-off-the-edge paradigm, where threat actors prioritize the compromise of network appliances to bypass traditional security perimeters.” Mandiant further emphasized that orchestrators managing edge devices and software-defined networking appliances “often lack the telemetry required for deep forensic analysis, and their role as a central control plane provides a stealthy platform for persistent, wide-scale access to internal enterprise traffic.” “For state-sponsored actors, the ability to exploit zero-day vulnerabilities in these platforms remains a premier vector for long-term strategic intelligence collection,” Google concluded. Additionally, Matei Badanoiu, lead security researcher at Pentest-Tools.com, highlighted that these findings reinforce another paradigm: threat actors often exploit vulnerabilities long before they are known and fixed. "In the case of Cisco and the above CVE, the window has been open for at least two months before the patch and advisory. Whoever used this vulnerability had working knowledge of it in this period while defenders had none,” Badanoiu said. Image credits: PJ McDonnell / Bangla press / Shutterstock.com
infosecurity-magazine.comJun 25, 2026extracted
Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack
The investigation conducted by California Water Service (Cal Water) into the recent cyberattack claimed by the Iranian hacker group Handala found no evidence of activity in the water utility’s operational technology (OT) environment. Handala, which claims to be a hacktivist collective but is widely believed to be a front for Iranian government hacking operations, said it could have disrupted the water supply after gaining access to Cal Water systems but decided not to do so. The statement suggested that the hackers had gained deep access to industrial control systems (ICS). The threat actor leaked 5 GB of data allegedly taken from Cal Water systems. Cybersecurity analysts discovered personal information in the published files and found evidence that a customer billing system and an internal application may have been compromised. Cal Water, one of the largest investor-owned water utilities in the United States, has hired cybersecurity experts, including Google’s Mandiant unit, to assist with the investigation into the cybersecurity incident. In a statement to SecurityWeek, Cal Water said, “Based on its investigation, Mandiant has confirmed that the threat actor activity was limited to unauthorized access to a small number of specific user accounts within two third-party service provider platforms.” It added, “Mandiant did not identify evidence of threat actor activity in Cal Water’s internal information technology or operational technology environments.” “The investigation determined that the threat actor accessed one active customer’s online Cal Water account using stolen user credentials. The customer account did not provide access to the billing system, and no payment information was compromised. The threat actor also accessed an external, third-party web site related to a GPS location correction tool; however, the website does not contain any confidential or sensitive information.” The organization concluded, “We appreciate the collaboration and support our state and federal government partners provided throughout the investigation, and we will continue to work to maintain the security of our systems and data from malicious actors.” The water sector continues to be a prime target for threat actors due to its heavy reliance on legacy systems and often inadequate cybersecurity measures. Related: Siemens Says Desigo CC Files Flagged as Malware by Security Engines
securityweek.comJun 25, 2026extracted
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant. The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an authenticated, local attacker to execute arbitrary commands with elevated privileges by supplying a crafted file to the affected system by taking advantage of the device's insufficient validation of user-supplied input. Earlier this month, Cisco acknowledged that it became aware of exploitation of this vulnerability, adding that a malicious actor must have netadmin privileges on an affected system to pull off a successful attack. "Throughout the intrusion, to maintain operational security and avoid detection, the threat actor consistently employed anti-forensic techniques, selectively deleting and restoring system configuration files that were modified during their activities," Mandiant researchers Chester Sng, Pete Boonyakarn, and Logeswaran Nadarajan said. The incident, the tech giant's incident response and threat intelligence arm added, targeted an unspecified communications service provider to elevate a compromised admin account to full root-level access. Two distinct periods of unauthorized activity have been detected, one taking place between late 2025 and January 2026 and the other in March 2026. At this stage, it's unclear if these two events are connected and the work of the same threat actor. During the first wave, the victim is said to have experienced unauthorized peering connections that likely exploited one of two authentication bypass flaws in Cisco Catalyst SD-WAN controllers (CVE-2026-20127 or CVE-2026-20182). It's worth noting that both the security vulnerabilities were undisclosed zero-days at that point. Then in March 2026, a second wave of rogue peering connections targeted a device running a newer software version that was patched against CVE-2026-20127. Cisco has since confirmed that these connections did not leverage CVE-2026-20182, raising the possibility that the attacker, who may or may not have been behind the previous unauthorized peering connections, relied on stolen certificates from a prior breach of the same device to obtain initial access. "The attacker then changed default admin credentials before exploiting CVE-2026-20245 as a zero-day via a malicious CSV file upload (evil_tenant.csv)," Mandiant said. "This exploit allowed them to escalate privileges and create a rogue user account (named 'troot') with full root-level shell control." The attackers have also been found to consistently cover their tracks by deleting files created by them, reversing configuration changes, and running scripts to ensure that no evidence was left behind and limit defenders' ability to assess the full extent of the compromise. "After changing the default admin password and exfiltrating the SD-WAN fabric configuration, the actor changed the password back to its original value so an administrator logging in would not notice anything was off," Austin Larsen, principal threat analyst at Google Threat Intelligence Group (GTIG), said. "They escalated to root through a malicious CSV upload, created a hidden "troot" account in /etc/passwd and /etc/shadow, then deleted every file they touched and ran a validation script to confirm their indicators were gone." Google pointed out that the activity once again highlights the "continuing trend" of bad actors weaponizing zero-days in edge devices like SD-WAN, as they lack the telemetry needed for deep forensic analysis, and a foothold in those systems can facilitate persistent visibility into internal traffic across the fabric. "Advanced adversaries continue to primarily target and exploit network devices and other systems that don't natively support EDR solutions," Charles Carmakal, chief technology officer of Mandiant Consulting, said in a post on LinkedIn.
thehackernews.comJun 25, 2026extracted
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. The CVE-2026-20245 vulnerability is a high-severity command injection flaw in Cisco Catalyst SD-WAN Manager (vManage), Controller (vSmart), and Validator (vBond) that allows authenticated attackers to execute arbitrary commands as root by uploading a crafted file. Cisco said the vulnerability stemmed from insufficient validation of user-supplied input and could be exploited by authenticated attackers with local access to affected devices. When Cisco disclosed the flaw earlier this month, the company warned that it had been exploited in a limited number of attacks but did not provide any details. Cisco only stated that successful exploitation allowed attackers to gain root privileges and that some incidents involved unauthorized configuration changes being pushed to edge devices. The company released security updates and urged customers to upgrade to fixed software versions, stating that no workarounds were available. New exploitation details emerge In a report published today, Mandiant revealed that CVE-2026-20245 was exploited as a privilege-escalation vulnerability after attackers had already gained access to targeted SD-WAN devices. According to the researchers, the intrusion began with unauthorized SD-WAN peering connections observed on a service provider's infrastructure. Beginning in March 2026, the threat actor established new rogue peer connections and authenticated to affected SD-WAN Manager devices using the vmanage-admin account. Mandiant believes the rogue peering may have been created by exploiting previously disclosed Cisco SD-WAN authentication bypass zero-days, CVE-2026-20127 and CVE-2026-20182, though the exact method remains unclear. After gaining access, the attackers changed the default admin account password, logged in to the SD-WAN Manager web interface, and extracted configuration information for edge devices, controllers, and SD-WAN templates. Mandiant says the attackers subsequently restored the admin account to its original password after completing their activity, likely to reduce detection. The researchers say the attackers then exploited CVE-2026-20245 through a tenant-upload feature in the SD-WAN command-line interface by uploading a malicious CSV file named "evil_tenant.csv." "CVE-2026-20245, a vulnerability reported to Cisco by Mandiant, exists in the command-line interface (CLI) of Cisco Catalyst SD-WAN Controllers that could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system," explains Mandiant. Mandiant says the malicious payload first created backups of system configuration files, including /etc/passwd and /etc/shadow, before creating a new account named "troot" with root-level privileges. The attackers then used the Linux "su" command to switch from the compromised administrative account to the newly created root account, giving them full control over the device. Mandiant says the attackers heavily relied on anti-forensic tactics to evade detection. This includes backing up configuration files before modifying them and then restoring them after exploitation. They also cleaned up traces of exploitation by deleting the malicious CSV payload, removing temporary files created during the attack, and erasing evidence of the rogue root account. The researchers also observed the execution of a validation script to confirm that all traces of the compromise had been removed from the device. Mandiant says some rogue peering activity observed in March 2026 occurred on systems that were not vulnerable to any of the previously disclosed authentication-bypass flaws. Cisco told the researchers that the breach did not involve CVE-2026-20182 and said it was possible the attackers used certificates stolen during a previous compromise to regain access to devices. Mandiant has published indicators of compromise, attacker IP addresses, and guidance to help organizations determine whether they were compromised. Organizations should collect diagnostic data from SD-WAN devices, check for signs of unauthorized peering connections, and upgrade to the latest software releases if they have not already done so. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 24, 2026extracted
Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack
Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: DockSec: Open-source AI-powered Docker security scanner DockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanation and remediation. Created by Advait Patel, the Python tool runs Trivy, Hadolint, and Docker Scout against a developer’s Dockerfile and image, correlates the findings, returns a 0-100 security score, and proposes line-specific fixes. Treating AI agents like service accounts for federated query security In this interview with Help Net Security, Paras Malhotra, CISO at Starburst, explains how the company handles data governance across federated query environments. Topics include layering Starburst’s access controls above native source permissions, tiering vendor risk across more than 200 partners and connectors, and building audit trails for autonomous agents. NOVA microhypervisor brings AMD DMA isolation to shared AI infrastructure BlueRock has issued the latest open-source release of its NOVA Microhypervisor with DMA remapping support for AMD platforms that have IOMMU hardware virtualization. The capability is enabled by default and extends hardware-level isolation across virtual machines, devices, and memory in shared execution environments. The security in smartphones is helping send them to landfills The WEEE Forum estimated that 5.3 billion mobile phones became electronic waste in 2022. Many of these devices still function. The average smartphone stays in use for about three years, and owners often replace handsets that retain enough computing power for other jobs. A team at the Université Libre de Bruxelles examined a barrier to giving those devices a second life. Every set of AI guardrails can be broken by the right prompt AI companies use guardrails to block harmful outputs such as deepfakes, malware, and instructions for biological weapons or illicit drugs. A new mathematical proof by Apostol Vassilev, a senior scientist at NIST, suggests those protections have inherent limits. For any finite set of guardrails, there exists a prompt that can bypass them if discovered. NOVA microhypervisor brings AMD DMA isolation to shared AI infrastructure BlueRock has issued the latest open-source release of its NOVA Microhypervisor with DMA remapping support for AMD platforms that have IOMMU hardware virtualization. The capability is enabled by default and extends hardware-level isolation across virtual machines, devices, and memory in shared execution environments. The security in smartphones is helping send them to landfills Billions of working smartphones reach the end of their service lives each year and move into drawers, recycling streams, and waste piles. The WEEE Forum estimated that 5.3 billion mobile phones became electronic waste in 2022. Many of these devices still function. The average smartphone stays in use for about three years, and owners often replace handsets that retain enough computing power for other jobs. A team at the Université Libre de Bruxelles examined a barrier to giving those devices a second life. Every set of AI guardrails can be broken by the right prompt Companies that build AI systems wrap them in guardrails meant to block harmful output, including deepfakes, malware, and instructions for making biological weapons or illicit drugs. When a user prompts the system for such content, the guardrails are designed to flag the request and refuse. A new mathematical proof sets a limit on how secure those guardrails can ever be. CISA orders federal agencies to “patch smarter” The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive that will change how the US federal government approaches vulnerability management. How to use NIST and ISO frameworks to govern AI agents Security leaders no longer need convincing that AI agents introduce risk. What’s missing is how to govern them once they move into production and begin operating autonomously across enterprise environments. CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) A vulnerability (CVE-2026-28318) that can be exploited to crash SolarWinds Serv-U file transfer servers is being leveraged by attackers in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Friday. The agency has ordered US federal civilian agencies to address it by June 19, 2026, either by implementing a patch or implementing mitigations. Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751) A Qilin ransomware affiliate is believed to be exploiting CVE-2026-50751, an authentication bypass vulnerability in Check Point VPN Remote Access and Mobile Access, the company announced on Monday. Check Point Remote Access VPN enables and secures connections between corporate networks and remote or mobile devices. LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271) A command injection vulnerability (CVE-2026-42271) in BerryAI’s LiteLLM open-source AI gateway is being exploited by attackers, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog on Monday. Record Microsoft Patch Tuesday, fresh zero-day Microsoft marked its largest-ever Patch Tuesday this month, by shipping fixes for nearly 200 vulnerabilities. Within hours, “Nightmare Eclipse”, the researcher behind weeks of escalating Windows exploit releases, dropped a proof-of-concept exploit for a new zero-day: “RoguePlanet”, which abuses a race condition in Windows Defender to spawn a command shell running with SYSTEM-level privileges. Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520) Ivanti has patched two critical vulnerabilities (CVE-2026-10520 and CVE-2026-10523) in Ivanti Sentry and has urged customers to implement the fix right away. Though the vulnerabilities are not known to be actively exploited, security researchers have already released technical details about the former, which may be used by attackers to craft a working exploit. Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert A zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools is being exploited in the wild, Charles Carmakal, CTO at cybersecurity firm Mandiant, part of Google Cloud, warned today. The architecture of subtraction: Why it’s time to erase the roads, not just map the traffic AI-assisted vulnerability discovery and exploit development are making patching increasingly inadequate as a primary defense. Advanced AI models can shrink the time from vulnerability discovery to exploitation from months to hours, while organizations struggle to patch systems as quickly as new flaws are identified. Product showcase: Staying ahead of the threat horizon with Aunoo Aunoo is an open strategic intelligence platform that uses AI agents to monitor intelligence sources, including for cybersecurity, to compile a daily briefing and alert on defined criteria. Each source is checked for credibility and quality before it is included. The platform runs in any browser and can send its findings via Slack, Discord, Teams, email or using the internal chat. When attacks spread too far: Lessons from real cyber attack case studies In this Help Net Security video, Michael Adjei, Director, Systems Engineering at Illumio, explains three real world cyber attacks and what went wrong during detection. Cyber resilience metrics that drive action In this Help Net Security video, Pete Bowers, COO at NormCyber, explains how organizations can build a cyber resilience metrics program that supports better decisions. He questions common ways of measuring resilience, such as risk registers, tool scores, and annual tests, and points out their limits. GitHub Copilot app launches as desktop home for AI coding agents GitHub introduced the Copilot app, a desktop application built for working with AI coding agents, at Microsoft Build 2026. The release expands GitHub’s Copilot product line beyond editor integrations and command-line tools into a dedicated workspace for directing several agents at once. Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup The 2026 FIFA World Cup will bring millions of visitors and an estimated 6 billion spectators to a tournament spread across 16 host cities in the United States, Canada and Mexico. In a new report, Intel 471 describes the 2026 FIFA World Cup as “the largest and most complex cyberattack surface in sporting history.” Hackers used Meta’s AI support system to hijack over 20,000 Instagram accounts Meta has revealed that attackers hijacked 20,225 Instagram accounts by exploiting a flaw in the company’s AI-assisted account recovery system. According to the company, a vulnerability in High Touch Support (HTS) allowed unauthorized parties to perform password resets on Instagram accounts. Microsoft changes how Defender for Endpoint EDR updates are delivered on Windows Microsoft will distribute Defender for Endpoint EDR updates through Microsoft Update, enabling EDR security improvements to be released independently of monthly Windows operating system updates. The rollout started for Windows 10 devices in late May 2026 and will expand to Windows 11 and other supported Windows versions later this year. Microsoft expects deployment to be completed by fall 2026. Meta claims NSO Group still targets WhatsApp users despite court order Meta claims it disrupted spear-phishing attempts linked to NSO Group and is asking a US federal court to hold the spyware vendor in contempt for allegedly violating an injunction that bars it from targeting WhatsApp and its users. Mythos Preview can weaponize N-day vulnerabilities in hours Mythos Preview can develop working exploits from newly disclosed software vulnerabilities in hours, cutting down a process that has historically taken days or weeks, according to Anthropic. Google patches Chrome zero-day exploited in the wild (CVE-2026-11645) Google has fixed 74 vulnerabilities in Chrome, including a high-severity zero-day (CVE-2026-11645) that has been exploited in the wild. The fix has been shipped in Chrome 149.0.7827.102/.103 for Windows and macOS and Chrome 149.0.7827.102 for Linux, with the update rolling out to users over the coming days and weeks. French government messaging platform breached through account hijacking French authorities are investigating a compromise of Tchap, the government’s secure messaging platform, after hackers hijacked a user account and gained access to public chat rooms. Anthropic’s Claude Fable 5 is out for public use, with safeguards for high-risk requests Days after publishing research on how advanced AI systems could amplify cyber operations in the wrong hands, Anthropic released Claude Fable 5, a Mythos-class model for general use. The company said Mythos-class models possess advanced cybersecurity and research biology capabilities that can provide information and guidance beyond what is typically available through conventional online sources. New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials A new Browser-in-the-Browser (BitB) phishing campaign is targeting Microsoft 365 users with fake login popups designed to closely mimic legitimate browser authentication windows, according to Palo Alto Networks Unit 42. Identity theft is turning into a chain reaction for victims For a growing number of victims, identity theft no longer ends with a fraudulent charge or a compromised account. More than one in four people who contacted the Identity Theft Resource Center during the reporting period were dealing with multiple identity-related incidents, according to the organization’s 2026 Trends in Identity Report. X Square Robot open sources its robot-free data collection framework Companies building robots for physical work spend large amounts of time and money operating machines by hand to gather training examples. Each session with a physical robot produces a small number of demonstrations per day, which slows the growth of datasets used to train embodied AI. Human demonstrators offer a cheaper source of data, and X Square Robot has put a system for this approach into public release. Making the cloud prove it followed your privacy wishes Companies that store personal data in cloud key-value databases should handle deletion requests by running the operation and confirming the job is complete. The people making those requests and the regulators overseeing them have had limited means to confirm the data is gone or that the record of its removal is genuine. GDPRuler, a middleware system from researchers at the Technical University of Munich and the University of Lisbon, sits between an application and an unmodified key-value database and enforces privacy rules as data passes through it. 9 out of 10 people can no longer distinguish real from AI-generated content Online fraud is becoming harder to distinguish from legitimate activity as AI-generated messages, voices, photos, reviews, and identities become more convincing. Nearly nine in ten adults say they can no longer tell what is real from AI-generated content, according to the latest Malwarebytes survey. The share increased from 66% in 2025 to 85% in 2026. FBI seizes 13 websites linked to alleged Chinese intelligence-gathering effort Federal authorities have seized 13 internet domains allegedly used to target current and former U.S. government employees and military personnel with access to classified and sensitive information. 52% of direct-to-IP threats are missing from intelligence feeds Security tools are good at inspecting websites, domains, URLs, and files, so attackers are moving lower in the stack and communicating directly with IP addresses, where visibility is limited. According to Palo Alto Networks’ report, this creates a visibility gap that allows malicious traffic to blend into normal internet activity and evade detection. Google Colab CLI opens runtimes to Claude Code and Codex Google released the Google Colab Command-Line Interface, a tool that connects local terminals to remote Colab runtimes. The CLI provides an execution platform for developers and AI agents, letting users provision compute, run local Python scripts on remote runtimes, and retrieve artifacts back to local machines. OpenAI is locking down parts of ChatGPT to reduce data theft risks OpenAI has started rolling out Lockdown Mode for ChatGPT, an optional security setting that restricts access to external resources and several product capabilities. It is available for personal accounts, including Free, Go, Plus, and Pro plans, as well as self-serve ChatGPT Business accounts. Samsung just made Galaxy phones more secure in One UI 9 beta Samsung’s One UI 9 beta integrates Lockdown mode into the power menu. This is the screen that contains Power off, Restart, and emergency options. Opening it initiates Lockdown mode, disabling biometric authentication. The security questions around Chinese AI coding models in U.S. software Software developers across the United States are using AI models built in China to write, debug, and review code, drawn by prices below those of American alternatives. These models carry risks for the security of American software, according to a report from Booz Allen Hamilton, which tested how the models respond when the user appears to work for the U.S. government. Malware ships with bugs that defenders could use against it Static analysis tools have spent years scanning legitimate software for security bugs before it goes out the door. The same scanners work on malware, and malware carries a steady supply of its own bugs. Researchers ran four of these tools across 658 leaked malware projects and found that close to 90 percent contained at least one recognized software weakness. Apple expands what parents can block, approve, and limit Apple has previewed a set of new child safety features coming to iPhone, iPad, and the Mac later this year, expanding parental controls with tools that help families manage app access, web browsing, communication, and screen time. Apple Intelligence can now replace weak passwords without user intervention Apple’s next generation of Apple Intelligence, the company’s personal intelligence system, expands its capabilities and introduces new security features in Passwords. With the new update, Passwords can automatically replace weak or compromised passwords. Scams now operate like real businesses with budgets and targets Social media has overtaken email as a primary attack vector, showing changes in how people consume information and interact online, according to Bitdefender’s Global Scam Intelligence Report 2026. Fraud campaigns use advertisements, sponsored content, impersonation pages, and direct messages to reach users. Apple extends Private Cloud Compute to third-party data centers Apple is bringing its Private Cloud Compute (PCC) platform to Google Cloud, expanding the infrastructure behind Apple Intelligence to third-party data centers. Introduced in 2024, PCC provides cloud-based processing for AI workloads that exceed the capabilities of on-device models while maintaining Apple’s security and privacy guarantees. Building reusable workflows with custom agents in Copilot CLI Developers spend much of their working time in the terminal, generating commands, debugging issues, and running scripts close to their systems. Repeated terminal work tends to pile up small steps such as re-running the same commands, re-explaining context, and translating logs into a form a team can act on. Custom agents in GitHub Copilot CLI address these patterns by turning repeated tasks into reusable workflows. Organizations can’t see much of their mobile AI activity Organizations have limited visibility into AI activity on mobile devices despite security leaders expressing confidence in their AI governance, according to Lookout’s “Solving for the Mobile AI Blind Spot: Executive Confidence Meets Technical Reality” report. Prompt injection still drives most agentic AI security failures in production A backdoor sat on PyPI for three hours in March 2026. Nearly 47,000 downloads occurred during the window. The compromised package, LiteLLM, serves as the language-model gateway for CrewAI, DSPy, Microsoft GraphRAG, and dozens of other AI agent frameworks. Anyone pulling an update during that window pulled in an autonomous attack bot named hackerbot-claw along with it. Threat actors are recruiting the people who hold cloud logins Companies keep most of their data and applications in cloud platforms that anyone can reach with the right login. That setup turns each employee holding those credentials into a security variable, and members of the cybercrime underground have built methods to reach those people. Intel 471 tracked this activity into 2026 and sorted insider risk into three categories that cloud-reliant organizations contend with. Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware Cybercriminals are using TikTok and Instagram Reels videos to spread Vidar, an infostealer malware, through fake downloads for popular paid software, according to ReversingLabs. The researchers uncovered two campaigns behind the activity, each using a different approach to draw in viewers before sending them to external download sites. Google sues China-based scammers over Gemini AI abuse Google has filed a lawsuit against Outsider Enterprise, a China-based cybercrime network for using AI tools, including Gemini, to build phishing websites and scam infrastructure. Cybercriminals are moving away from mass phishing campaigns Phishing activity declined by roughly 20% in both 2024 and 2025, according to research from Zscaler’s ThreatLabz team. The drop followed years of growth that pushed phishing activity above 2 billion hits in 2023. Authorities dismantle crypto laundering service that moved €336 million for cybercriminals An international law enforcement operation has dismantled a cryptocurrency laundering service linked to ransomware groups and other cybercriminals that processed more than €336 million in illicit funds. Cybersecurity jobs available right now: June 9, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: June 12, 2026 Here’s a look at the most interesting products from the past week, featuring releases from AISLE, Drata, Elastic, Filigran, IDnow, and Ridge Security.
helpnetsecurity.comJun 14, 2026extracted
In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: IBM and AT&T accused of hack cover-ups A former IBM cybersecurity executive has filed a lawsuit accusing IBM and AT&T of covering up repeated foreign government-linked hacks on their systems. According to the whistleblower, the companies failed to properly disclose multiple breaches to the US government over several years. He alleges they instead provided false assurances about their security posture to secure and maintain valuable federal contracts, in violation of legal requirements. University of Oxford impacted by CareerConnect data breach The University of Oxford disclosed a data breach related to the CareerConnect careers service. Hackers accessed the platform and compromised names, email addresses, and encrypted passwords. The incident impacts alumni, research staff, and employer user accounts, but not students, who rely on Single Sign-On (SSO) to log in. Google Threat Intelligence Group and Mandiant layoffs Google Cloud has reportedly initiated a round of layoffs impacting its cybersecurity division, specifically targeting members of the Mandiant team and the Google Threat Intelligence Group (GTIG). Google has not confirmed the exact number of affected employees, and it has not responded to SecurityWeek’s request for comment. Microsoft issues incident response playbook for AI Microsoft has released a new practitioner’s playbook detailing how to investigate security incidents involving Microsoft 365 Copilot and Azure AI Services. The document provides security teams with structured methodologies to track and analyze potentially malicious activity within these environments. The resource is designed to help defenders adapt their traditional response workflows to the unique telemetry of modern AI platforms. CISA mandates patching for actively exploited LiteLLM flaw CISA has added CVE-2026-42271, a critical command injection vulnerability in the AI gateway BerriAI LiteLLM, to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation in the wild. There does not appear to be any information on the attacks exploiting the vulnerability. Regulators issue $400 million penalty over Coupang data leak The South Korean Personal Information Protection Commission (PIPC) has imposed a record $400 million fine on Coupang due to widespread security failures and data handling violations that exposed the personal information of more than 30 million customers. Investigations revealed critical deficiencies in access controls and authentication key management. Coupang plans to appeal the fine. Nokia debuts automated edge defense for proxy botnets Nokia has introduced Deepfield Genome Shield, an automated security platform designed to proactively defend against massive DDoS attacks driven by residential proxy botnets. The system mitigates threats from an estimated 200 million compromised devices by disrupting botnet command-and-control communications directly at the network edge. ICS device exposure remains flat as attack surface widens Bitsight’s 2026 Global State of ICS/OT Exposure report indicates that internet-facing industrial control systems (ICS) have plateaued at roughly 170,000 monthly exposures. Despite this flat count, the overall risk profile is expanding because modern ICS increasingly support non-traditional protocols such as SSH, HTTP, and MQTT alongside legacy protocols, widening the attack surface and making defenders’ jobs more challenging. ENISA shifts focus to collective EU resilience The European Union Agency for Cybersecurity (ENISA) is centering its Cyber Europe 2026 exercise on enhancing collective response capabilities across the region. The focus highlights an ongoing effort to evaluate and strengthen the cooperative resilience of EU member states against large-scale cyber incidents. This strategic direction aims to ensure that European infrastructure can withstand and rapidly recover from coordinated, transnational digital threats. Global operation takes down crypto laundering service An international law enforcement coalition supported by Europol and Eurojust has dismantled AudiA6, a prominent cryptocurrency laundering network that laundered over $388 million for ransomware actors between 2022 and 2025. The operation disrupted an industrial-scale scheme that funneled illicit digital assets through thousands of fake exchange accounts opened with stolen identities. Additionally, authorities seized the platform’s web infrastructure and successfully shuttered Dark2Web, an underground cybercrime forum managed by the same operators to connect threat actors globally.
securityweek.comJun 12, 2026extracted
South Korea hits Coupang with record $409 million fine over data breach
South Korea hits Coupang with record $409 million fine over data breach South Korea's data protection regulator has imposed a record 624.7 billion won ($409 million) fine on Coupang, the country's largest online retailer, after an investigation into a data breach that compromised the personal information of tens of millions of customers. The Personal Information Protection Commission (PIPC) voted at a plenary session on Wednesday to sanction Coupang and its logistics subsidiary, Coupang Fulfillment Services, concluding that the breach stemmed not from sophisticated hacking but from “deficiencies in basic safety management.” The penalty is the largest ever issued by the commission for a personal data breach, surpassing the record 134.8 billion won ($88.8 million) fine levied against SK Telecom earlier this year. The breach first became public in November when Coupang said approximately 33.7 million customer accounts had been compromised — equivalent to around 65% of South Korea's entire population. The PIPC's investigation confirmed that 33,222,472 registered members were affected, but also identified a category of victims the company had not previously acknowledged: at least 4,338,368 non-members whose names, phone numbers and addresses had been stored as delivery recipients by other customers, and who had no way of knowing their data was held by Coupang at all. The regulator said it had formally urged the company four times, in December 2025 and January 2026, to notify those non-member victims. Coupang failed to do so each time. The perpetrator, an unnamed Chinese national and former employee who left the company at the end of 2024, had himself developed Coupang's alternative authentication system while still employed and had stolen the signing key that underpinned it before he left. He began with a test run in January 2025, using the stolen key on 95 accounts. From April, he systematically cycled through member ID numbers, hitting Coupang's delivery address page approximately 148 million times over two months to harvest names, phone numbers and addresses. He then turned to the account edit page, accessing it nearly 35 million times between June and October to collect names and email addresses. A final phase added apartment entry codes and order histories. The former employee later reassembled the data into individual customer profiles and sent two extortion emails — to members directly, and to Coupang — the second claiming to hold 120 million addresses, 560 million order records and more than 33 million email addresses, with sample data that included sensitive purchase histories. The PIPC found that throughout the seven-month attack, traffic on the affected pages had spiked to many times their normal levels, and that tens of millions of access attempts had used non-existent member IDs. Coupang detected none of it until a customer forwarded one of the extortion emails. The commission referred Coupang for criminal prosecution over the destruction of evidence. Regulators had ordered the preservation of access logs on November 21 — the day after Coupang filed its initial breach report, but six days later, the company manually deleted approximately six months of web access logs. Coupang also failed to pause its routine policy of automatically deleting logs after six months, allowing further records to be wiped. Roughly 13% of the logs covering the attack period were lost, making it impossible to identify all affected victims. Police separately recovered a smashed laptop from a river during the investigation — a MacBook Air the alleged perpetrator had weighted with bricks in an apparent attempt to destroy evidence — which forensic teams from Mandiant, Palo Alto Networks and Ernst & Young were able to document before it was handed to authorities. Additional violations uncovered The investigation, expanded in January 2026 following parliamentary hearings and media coverage, unearthed several violations separate from the breach itself. Through its “Coupang Partners” affiliate marketing program, the company had covertly collected the third-party browsing activity of about 11.2 million users — URLs visited, app names, timestamps, IP addresses and device identifiers — without consent, linking the data to individual member accounts. Coupang argued the information did not constitute personal data; the regulator disagreed, noting it was stored alongside member ID numbers and device identifiers. The commission imposed a further 201.1 billion won ($132 million) fine for this violation alone. Coupang deleted the records in April 2026 after investigators confronted the company. Some advertising partners in the same program had also been running so-called “hijack ads” — redirecting users to Coupang without their consent, in some cases by covering the screen with a transparent button so that clicking anywhere triggered a redirect. Coupang had been aware of the practice since 2022 but had failed to terminate the accounts of partners who met its own threshold for removal, and had in some cases paid them higher commissions after they were caught, the investigation found. Coupang Fulfillment Services, the logistics subsidiary, was also found to have secretly added 71 police press-corps journalists — none of whom had ever worked at a Coupang warehouse — to an internal employment blacklist, citing “spreading false information,” without their knowledge or consent. The subsidiary was also found to have submitted employees' weight data, collected for health management purposes, as evidence in an industrial accident lawsuit, without a separate legal basis. The commission additionally found that when Coupang conducted its own internal investigation of the hacker in December 2025 — drawing criticism from lawmakers and government officials at the time — it had excluded its own chief privacy officer from the process entirely. Regulators treated this not as an internal communication failure but as a substantive violation of the legally mandated independence of the chief privacy officer’s role. Acting CEO Harold Rogers, who was questioned by police in January as a suspect in an obstruction inquiry, had pledged full cooperation with authorities. The company said it regretted the PIPC's decision and reserved the right to challenge it through legal proceedings once it receives the formal written ruling. Dispute mediation proceedings covering more than 2,500 individual and group claimants, which had been paused during the investigation, are set to resume on June 12. A class-action lawsuit in the United States also remains pending. Coupang's shares have fallen around 35% since the start of the year. The company has warned that revenue growth could slow, and faces ongoing scrutiny from South Korean lawmakers over both the breach and its response to it. Alexander Martin is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
therecord.mediaJun 12, 2026extracted
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
Google has confirmed that a PeopleSoft vulnerability mitigated by Oracle this week has been exploited by ShinyHunters as a zero-day to steal data from organizations. Oracle has released an out-of-band advisory and security alert for CVE-2026-35273, a critical unauthenticated remote code execution vulnerability impacting PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, as well as PeopleSoft Enterprise Applications. The software giant has released mitigations, but patches do not appear to be available. PeopleSoft is an ERP software suite used by many large organizations to manage a wide range of business functions, including HR, payroll, finance, supply chain, and campus operations. While the solution is used across many industries, the ShinyHunters campaign exploiting CVE-2026-35273 appears to have focused on the education sector. The University of Nottingham in the UK is the first confirmed victim. Mandiant and Google Threat Intelligence Group (GTIG) reported observing activity associated with the exploitation of the PeopleSoft zero-day between May 27 and June 9. The attacks have been attributed to ShinyHunters, which Google tracks as UNC6240. Google’s researchers notified more than 100 global organizations of potential exposure, the majority of which are based in the US, with 68% in the higher education sector. The tech giant said some of the targets blocked the attack, but others had their systems compromised and data stolen. ShinyHunters claims to have targeted roughly 300 PeopleSoft instances belonging to 100 organizations. “The attacker staging environments hosted customized MeshCentral agents masquerading as legitimate cloud endpoints, which they used to run administrative command queries and deploy a custom lateral movement and defacement script, [victim_abbreviation]_fanout.sh,” Mandiant and GTIG explained. “This campaign directly correlates with subsequent data leaks of stolen organization data published on the ShinyHunters Data Leak Site (DLS) on June 9, 2026.” Google has shared remediation and hardening recommendations, as well as technical details on the attacks and indicators of compromise (IoCs). Oracle has not responded to SecurityWeek’s inquiry regarding exploitation. TrendAI (Trend Micro’s enterprise business), whose researchers have been credited by Oracle for reporting CVE-2026-35273, told SecurityWeek that it’s currently seeing limited exploitation of the vulnerability, but its investigation is ongoing. Related: CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk Related: Hackers Exploit Langflow Vulnerability for Remote Code Execution
securityweek.comJun 12, 2026extracted
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a zero-day the entire time. The flaw, CVE-2026-35273, is a remote code execution bug in PeopleSoft Enterprise PeopleTools rated 9.8 out of 10. It needs no login and no user interaction, just network access over HTTP, to take over the server. If you run PeopleSoft with the Environment Management Hub reachable from outside, that is your exposure, and the immediate move is to lock those endpoints down. The vulnerability sits in the Updates Environment Management component, the piece behind the Environment Management Hub (PSEMHUB). Oracle lists PeopleTools 8.61 and 8.62 as affected and says earlier, unsupported versions are probably vulnerable too. It credits researchers from TrendAI Zero Day Initiative and TrendAI Research for the report. Mandiant CTO Charles Carmakal confirmed the bug is being exploited in the wild; Oracle has not said whether it has seen exploitation. Its advisory points to a patch availability document behind a support login, and whether a full fix is broadly available is unclear. For now, the guidance centers on mitigation. The operational detail became public because the attackers left their own gear exposed. Researcher @nahamike01 publicly flagged the open directories. Mandiant then triaged five sequential IP addresses running Python's SimpleHTTP server on port 8888. Those servers exposed the staging files: a shared .bash_history, custom MeshCentral remote-management agents disguised as Microsoft Azure binaries, and a lateral-movement script. The agents called home to a command-and-control server at azurenetfiles.net, a domain picked to look like Azure NetApp Files. The script, named [victim]_fanout.sh, spreads over SSH by spraying a hardcoded list of usernames and passwords against internal hosts pulled from /etc/hosts, then drops a marker file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT into PeopleSoft directories. The command history shows the data compressed with zstd and an outbound SSH connection to the server hosting the public mirror of the ShinyHunters leak site. Mandiant notified more than 100 organizations whose IP addresses matched vulnerable endpoints. Sixty-eight percent were in higher education, most of them in the United States. Some blocked the activity; others were compromised and had data posted to the leak site. The University of Nottingham is one of the first confirmed victims. Have I Been Pwned has counted about 455,000 unique email addresses in the leaked set, covering current students and alumni, with names, addresses, phone numbers, passport numbers, and details on ethnicity and disabilities. The university has confirmed the breach. Oracle's guidance is to disable the Environment Management Hub service on multi-server setups, or remove the PSEMHUB application outright on single-server setups. If you cannot do either, block external access to /PSEMHUB/* (especially /PSEMHUB/hub) and /PSIGW/HttpListeningConnector at the perimeter. Mandiant warns that WAF body-inspection rules alone are not enough, since they can be bypassed. Restricting these endpoints does not break normal user sessions. Then hunt for signs of an existing compromise: WebLogic access logs showing external POST requests to /PSEMHUB/hub or /PSIGW/HttpListeningConnector. Unexpected .jsp files under the PSEMHUB.war web application directory, or odd folders named logs, persistantstorage, or scratchpad under the PSEMHUB paths. Recently changed .xml files under the web doc root's envmetadata/data/environment, which can be abused for XMLDecoder persistence that fires on the next restart. Outbound SMB traffic on port 445 from PeopleSoft hosts to external destinations, which the exploit chain may use to capture machine-account NetNTLM hashes. Apply Oracle's update for your PeopleTools version once you confirm it is available in My Oracle Support. ShinyHunters says victim outreach has only just started, and it has not posted most of the organizations it claims, so more names are likely. The method is the bigger tell. ShinyHunters has lately leaned on vishing, stolen tokens, and weak access controls to steal data from SaaS and education platforms, from Salesforce customers to Canvas. A server-side zero-day in on-premises ERP software is a step up from that, aimed at the same data-rich targets. The open question is whether this was a one-off borrowed zero-day or the start of ShinyHunters moving into ERP exploitation.
thehackernews.comJun 11, 2026extracted
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks. The flaw is within Oracle PeopleSoft PeopleTools and has a CVSS base score of 9.8. "This Security Alert addresses vulnerability CVE-2026-35273 in Oracle PeopleSoft PeopleTools. Oracle PeopleSoft Enterprise Applications customers may also be affected by this vulnerability," reads a new Oracle advisory. "This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution." Oracle has confirmed that the zero-day vulnerability affects PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62, and has released emergency mitigations to address the flaw, with a patch coming soon. Zero-day exploited in ShinyHunter data theft attacks While Oracle has not stated that this vulnerability is actively exploited, its disclosure comes after BleepingComputer first reported that the ShinyHunters extortion gang was exploiting a PeopleSoft zero-day vulnerability to breach instances and steal data. BleepingComputer has since learned that this is the zero-day exploited in the attacks. On Tuesday, BleepingComputer learned that Oracle PeopleSoft was targeted in a wave of data theft attacks that left ransom notes purportedly from the ShinyHunters extortion gang. ShinyHunters is a well-known threat actor that commonly breaches cloud SaaS instances, CRMs, and enterprise platforms that host large volumes of corporate data. After gaining access to an instance, they will download the data and demand a ransom to prevent its public leak. The group has been linked to numerous high-profile attacks targeting SnowFlake, Salesforce, and third-party integration providers over the past year. ShinyHunters confirmed to BleepingComputer that they are behind these attacks, claiming to use a "gadget chain" of old and zero-day flaws to breach PeopleSoft instances. Using this flaw, the threat actor allegedly stole data from 300 instances for over 100 organizations. Cybersecurity researcher "Michael R" found several exposed online directories containing attack-related tooling and shared the following IP addresses used in the attacks. 142.11.200[.]186 142.11.200[.]187 142.11.200[.]188 142.11.200[.]189 142.11.200[.]190 108.174.202[.]99 176.120.22[.]24 Targeting the education sector Mandiant released a report confirming that threat actors exploited the Oracle PeopleSoft CVE-2026-35273 vulnerability as a zero-day, primarily targeting organizations in the education sector. "Upon becoming aware of active scanning and exploitation, we initiated notifications to over 100 global organizations whose IP addresses correlated with potentially vulnerable endpoints," Mandiant reported. "Most of these organizations were based in the United States, and 68 percent operated within the higher education sector." Mandiant's report also shared additional technical details about the attacks, saying the threat actors used the exposed staging servers to host HTTP services and utilized custom MeshCentral remote management agents to communicate with attacker-controlled infrastructure masquerading as Microsoft Azure services. The researchers said the threat actors conducted reconnaissance on compromised instances, mapped PeopleSoft and WebLogic configurations, and used scripts to laterally move across internal systems using stolen or hardcoded credentials. Mandiant also said the attackers compressed exfiltrated data and ultimately connected to a server at 176.120.22.24, which is associated with the public ShinyHunters data leak site, helping link the activity to the extortion group. As part of its guidance, Mandiant advised organizations to restrict access to vulnerable PeopleSoft endpoints, review logs for suspicious requests targeting /PSEMHUB/ and /PSIGW/HttpListeningConnector, and inspect servers for signs of compromise, including: Unexpected .jsp webshell files in WebLogic application directories Unauthorized files or binaries staged in PSEMHUB transaction folders Suspicious directories such as logs, persistantstorage, or scratchpad Recently modified XML files that could be used to maintain persistence or trigger remote code execution after a restart ShinyHunters recently targeted the education sector in a massive cyberattack on Instructure Canvas that allowed them to steal 280 million data records for students, teachers, and staff. Instructure later paid a ransom to prevent the leaking of the stolen data. BleepingComputer has reached out to Oracle with questions about the vulnerability and the attacks but has not received a response. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 11, 2026extracted
Cisco Talos, nel 2026 attività sponsorizzate dagli Stati meno rumorose ma più pazienti: ecco come difendersi
Le minacce sponsorizzate dagli Stati costituiscono una delle sfide più complesse per aziende, infrastrutture critiche e pubbliche amministrazioni. Lo riporta l’ultima analisi di Cisco Talos nel 2026. Il team di intelligence di Cisco, specializzato nello studio delle minacce avanzate, infatti “conferma un’evoluzione ormai evidente anche in altri report recenti di Mandiant e CrowdStrike”, secondo Pierluigi Paganini, analista di cyber security e Ceo Cybhorus. “Questa importante analisi ci dà infatti modo di focalizzare un aspetto che spesso viene sottovalutato: gli attori sponsorizzati dagli Stati non sono necessariamente i più rumorosi, ma sono quasi sempre i più pazienti“, secondo Dario Fadda, esperto di cyber sicurezza e collaboratore di Cybersecurity360. Ecco perché e come mitigare il rischio. Indice degli argomenti I gruppi Nation-State non agiscono per guadagnare un ritorno immediato o per produrre impatti visibili. Invece operano silenziosamente, con metodo e in maniera persistente, utilizzando credenziali valide, strumenti legittimi e relazioni di fiducia già presenti nelle organizzazioni. L’analisi di Cisco Talos mette in risalto un’evoluzione rilevante nel modo in cui si conduce questa tipologia di attacchi e, dunque, come fronteggiarli. I gruppi di cyber criminali sponsorizzati dagli Stati non operano secondo la logica dei criminali comuni. “Oggi il vero rischio non è il ransomware che blocca i sistemi e si fa notare, ma l’avversario che rimane invisibile per mesi utilizzando credenziali legittime e strumenti già presenti nell’infrastruttura”, sottolinea Dario Fadda. Infatti il loro obiettivo è rimanere invisibili il più a lungo possibile, spesso per mesi, raccogliendo informazioni strategiche o mettendo a punto future operazioni. “Le operazioni sponsorizzate dagli Stati stanno progressivamente abbandonando tecniche rumorose per adottare strategie ‘living-off-the-land’, basate su credenziali valide e strumenti nativi del sistema. Questo rende sempre più sfumato il confine tra attività amministrativa e compromissione, aumentando drasticamente il tempo medio di permanenza degli attaccanti nelle reti, che in diversi casi supera i 200 giorni prima della rilevazione“, mette in guardia Paganini. Il fattore più sottovalutato di questo modello operativo è la fiducia. Molte imprese infatti si ostinano a ritenere affidabile tutto ciò che ricade all’internp del proprio perimetro, spaziando dagli utenti interni ai sistemi certificati, fino ai fornitori e alle piattaforme cloud. Ma Cisco Talos punta il dito contro lo sfruttamento sempre più frequente della fiducia implicita. Gli attaccanti agiscono nelle infrastrutture senza introduzione di codice malevolo, ma sfruttando strumenti già presenti come PowerShell o sistemi di gestione IT, oltre a credenziali legittime, così offuscando le proprie attività, rese difficili da riconoscere rispetto ad operazioni amministrative ordinarie. “Il punto centrale non è solo la persistenza, ma la normalizzazione dell’anomalia: l’uso di PowerShell, strumenti IT e accessi legittimi trasforma l’attacco in comportamento ordinario, rendendo inefficaci molti modelli di detection tradizionali basati su firme o indicatori statici“, mette in guardia Paganini: “Anche le analisi più recenti di Microsoft Digital Defense Report evidenziano come oltre il 60% degli incidenti coinvolga identità compromesse, segno che l’identità è ormai il vero perimetro di sicurezza“. Mimetizzandosi e rimanendo nascosti il più a lungo possibili, questi attacchi dimostrano di avere obiettivi differenti rispetto ai ransomware, come lo spionaggio, il furto di proprietà intellettuale o la persistenza di accessi strategici, mantenuti nel tempo per rubare informazioni. “In questo scenario, la supply chain diventa un amplificatore del rischio, come visto in campagne recenti legate a compromissioni di provider e strumenti di sviluppo. La conseguenza è un cambio di paradigma: non si difende più solo la rete, ma l’intero ecosistema di relazioni digitali”, avverte Paganini. Poiché l’accesso iniziale sfrutta frequentemente credenziali compromesse e il movimento laterale utilizza strumenti legittimi per espandersi all’interno dell’infrastruttura, per mitigare i rischi occorre: diffidare di richieste urgenti, non cliccare su link ricevuti in messaggi inattesi, verificare sempre l’autenticità delle comunicazioni tramite i canali ufficiali, adottare l’autenticazione a più fattori e password uniche per ridurre il rischio di compromissioni successive. La protezione degli accessi, il monitoraggio dei comportamenti e la limitazione dei privilegi sono ormai una priorità. “Per questo motivo le organizzazioni, soprattutto quelle che gestiscono servizi critici e finanziari, devono superare il concetto tradizionale di perimetro sicuro e adottare un approccio basato sulla verifica continua della fiducia. La differenza tra rilevare un attacco e accorgersene troppo tardi si gioca sempre più sulla capacità di individuare anomalie comportamentali, non semplicemente malware tecnologici”, avverte Dario Fadda. Inoltre, per mitigare il rischio bisogna implementare un approccio pragmatico, soprattutto laddove le risorse sono limitate. La priorità consiste nell’aumento della visibilità su ciò che accade nella rete, attivando e centralizzando i log e raccogliendo in maniera strutturata le informazioni di sicurezza. In contemporanea, Cisco Talos consiglia nel 2026 di potenziare la protezione delle identità grazie all’adozione dell’autenticazione multifattore e gestendo rigorosamente gli accessi privilegiati. Il monitoraggio continuo dei sistemi più critici e la realizzazione di modelli comportamentali aggiornati nel tempo, in grado di rilevare anche anomalie minime e attività sospette, invisibili o quasi agli strumenti classici, sono fondamentali per difendersi dalle minacce sponsorizzate dagli Stati. Esse si distinguono per gli spazi temporali estesi e obiettivi di natura strategica. Secondo Cisco Talos, nel 2026 una difesa frammentata né solo reattiva debba evolvere verso modelli di monitoraggio continuo, analisi e adattamento. Per distinguere l’attività malevola da quella legittima, occorre identificare anomalie e comportamenti fuori schema, sempre più fattori centrali per la sicurezza. “Serve quindi un approccio basato su continuous threat exposure management, correlazione comportamentale e soprattutto una governance matura delle identità. La sfida non è più ‘bloccare l’attacco’, ma riconoscere quando un’attività interna legittima ha smesso di esserlo”, conclude Paganini.
cybersecurity360.itJun 11, 2026extracted
Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert
Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert A zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools is being exploited in the wild, Charles Carmakal, CTO at cybersecurity firm Mandiant, part of Google Cloud, warned today. The warning comes a day after Oracle published an out-of-band security alert about the flaw, which is remotely exploitable without authentication, may result in remote code execution, and affects PeopleSoft PeopleTools versions 8.61 and 8.62 (and possibly earlier, unsupported ones as well). Oracle credited researchers with TrendAI Zero Day Initiative and TrendAI Research for reporting the vulnerability. The security alert links to a “patch availability document”, but it is unclear whether a patch is currently available, as the document is accessible only to customers with a support account. Help Net Security has reached out to Oracle for confirmation on whether CVE-2026-35273 is being actively exploited, but we’ve yet to receive a reply. ShinyHunters targeting PeopleSoft instances Oracle’s alert was published on the same day that Bleeping Computer reported ShinyHunters’ claims that they’ve been breaching Oracle PeopleSoft servers and have stolen data from 100+ organizations. According to the extortion group’s claims, the targeted organizations are mostly educational institutions, and their PeopleSoft instances – whether on-premises or in the cloud – were breached “using a ‘gadget chain’ of old and zero-day vulnerabilities.” Among the victims is apparently the University of Nottingham, which confirmed it has suffered a cybersecurity incident and that it has notified affected students and alumni directly. ShinyHunters claimed that breach and leaked tens of gigabytes of stolen data, including personal data and academic records of nearly half a million current and former students. A threat researcher seemingly confirmed ShinyHunters’ ongoing targeting of PeopleSoft instances, after discovering exposed directories containing tools used in these attacks. “At the /pay_or_leak endpoint, is stolen data from 20+ organizations, many named and others from 02 Jun and 04 Jun not yet named. Inside the same bash history log is a purpose-built shell script (uon_fanout.sh) which spreads defacement markers across PeopleSoft infrastructure,” the researcher noted. “The code shows the attackers are very familiar with PeopleSoft; extracting creds from psappsrv.cfg (app server config), mapping all connected nodes, and identifying web/app/batch tiers.” The researcher also posted a list of IPs and domains related to the attacks, which can be used by PeopleSoft admins and defenders to check for signs of compromise. UPDATE (June 11, 2026, 05:15 p.m. ET): Mandiant and Google Threat Intelligence Group have confirmed that ShinyHunters (i.e., UNC6240) have been targeting Oracle PeopleSoft application infrastructure between May 27, 2026 and June 9, 2026, and the activity “is consistent” with the exploitation of CVE-2026-35273. “The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity predates Oracle’s June 10, 2026 advisory, the vulnerability was exploited as a zero-day,” they said, and revealed that they notified over 100 global organizations with potentially vulnerable endpoints. “While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters [data leaks site],” the researchers shared. They detailed the actions performed and tools used by the attackers, and provided remediation and hardening advice. Though there’s still no mention of a patch for CVE-2026-35273, there are mitigations PeopleSoft admins can implement to minimize the risk of exploitation. They can disable the Environment Management Hub (EMHub) Service in Multi-Server configurations, remove the PSEMHUB application in Single-Server configurations or, if they cannot disable the EMHub Service, they can block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the network perimeter or firewall level. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comJun 11, 2026extracted
Googleセキュリティ責任者が語る「サイバー脅威の未来」 完全自律型AIエージェントによる攻撃が現実味
AI���T�C�o�[�U���̎�������ς����Ă���B�Ǝ㐫���p�̃X�s�[�h�������P�ʂɉ������钆�A�N���v���Z�X�̑唼��AI���S���u���S�����^AI�G�[�W�F���g�U���v�̖{�i�����ԋ߂��Ƃ����BGoogle�̃Z�L�����e�B�g�b�v���A���Ђ̌���Ɩh�䑤�̐j�H�����B ���̋L������������ł��B����o�^����ƑS�Ă������������܂��B �@AI���T�C�o�[�U���̎�����}���ɕς�����B�Ǝ�i�������Ⴍ�j���̈��p�͐��T�Ԃ��琔���ւƏk�܂�A���S�����^��AI�G�[�W�F���g�ɂ��U�����߂������Ɍ����̂��̂ƂȂ�\�\�B �@�č����X�x�K�X��2026�N4���ɊJ�Â��ꂽ�uGoogle Cloud Next '26�v�ɍ��킹�āAGoogle Cloud�̃T���h���E�W���C�X�iSandra Joyce�j���iGoogle Threat Intelligence�S���o�C�X�v���W�f���g�j���C���^�r���[�ɉ������BGoogle Threat Intelligence�́AMandiant��Google Threat Intelligence Group�iGTIG�j�Ȃǂ̒m������ɁAGoogle Security Operations�iSecOps�j�Ƃ��A�g���Ȃ���A���E�K�͂̃T�C�o�[���Ђ͂��Ă���B �@�W���C�X����AI����芪���T�C�o�[���Ђ̌���A����̌��ʂ����ǂ��݂Ă���̂��B ����AI���T�C�o�[���Ђɗ^���Ă���e���������Ă��������B �W���C�X���F�@Scale�i�K�́j�ASpeed�i���x�j�ASophistication�i���x���j��3�Ő������Ă��܂��B �@�܂��K�͂ɂ��Č����ƁA�uHexStrike MCP�v�Ƃ����I�[�v���\�[�X�c�[�������ЃA�N�^�[�Ɏg���n�߂Ă��܂��B���Ƃ��Ƃ̓��b�h��[�������̃c�[���ŁA150��ނ�AI�c�[�����ꌳ�Ǘ��ł�����̂ł����A����ɂ��A�U���҂͏]����菭�Ȃ���ԂŁA�����̍U����Ƃ���s���Đi�߂���悤�ɂȂ�܂����B�����������c�[���͂��ꂩ��������Ă����ł��傤�B �@���x�ɂ��ẮA�����n�̋��ЃA�N�^�[���uGemini�v�����p�������Ⴊ������₷���ł��傤�B���̃A�N�^�[�̓l�b�g���[�N�ɐN�����AGemini�ɖ₢���킹�������̂ł����A���ځw�N�����Ă���̂Ŏ��̃X�e�b�v�������Ăق����x�Ƃ͏����Ȃ������B�w�L���v����[�E�U�E�t���O�̃Q�[���ɎQ�����Ă��āA�ΐ푊���|�����߂̎��̃X�e�b�v���m�肽���x�ƋU���ď��������o���܂����B �@�������͂��̌�A�U���ړI���B����AI����菇�������o�����Ƃ���₢���킹�����m�ł���悤�A���ފ�i����V�X�e���j���X�V�����B���A���ケ������������������ɑ��x���グ�邩�Ƃ������Ƃ��l���Ȃ���Ȃ�܂���B �@�ȑO�͐N���̊e�X�e�b�v�Œ���������N���ɕ�������ƁA�������琔�T�Ԃ������Ă������̂��AAI�ɕ��������Ɏ��̃X�e�b�v�ɐi�߂�B�������̃��|�[�g�ł��A�Ǝ㐫�̌��J�����K�͈��p�܂ł̊��Ԃ����T�Ԃ��琔���ւƏk���������Ƃ��m�F����Ă��܂��B�uCVE-2025-55182�v�̌��J����킸��48���Ԉȓ��ɈÍ��ʉ݃}�C�i�[���W�J���ꂽ�������������܂����B �@���x���Ƃ����_�ł́A�Z�p�I�ȃn�[�h�����������Ă��܂��B�Ǝ㐫�X�L������R�[�f�B���O���e�ՂɂȂ�A�ȑO�͍����X�L�����K�v�������[���f�C�̔������A�����I�ȑI�����ɂȂ����B��������2025�N�A�uBig Sleep�v�Ƃ������f�����g���ĎГ��̐Ǝ㐫�X�L���������܂����B���̌�A�n���t�H�[�����̏������݂ŃI�[�v���\�[�X�\�t�g�E�F�A�́uSQLite�v�ɐƎ㐫�����݂���\����c�����A�������f���Œ��������Ƃ�����ۂɐƎ㐫���m�F�ł��܂����B���ЃA�N�^�[�����p����O�ɏC���������ł����킯�ł��B �������S�����^��AI�G�[�W�F���g�U���͊��Ɋm�F����Ă��܂����B�܂��A����̌��ʂ��́B �W���C�X���F�@���S�����^��AI�G�[�W�F���g�U����A��K�͂ȐƎ㐫�X�L�����Ƃ��������̂́A�܂�����قǑ����͊m�F���Ă��܂���B�����A����͏o�n�߂Ă��܂��B �@���V�A�̌R�����@�ւ��g���Ƃ����}���E�F�A�́A�����n��LLM�ɖ₢���킹�Ȃ��烊�A���^�C���Ŏw�߂����܂��B������Anthropic�ŋN����������m�F���Ă��܂��B2025�N9���Ɍ��m���ꂽ����ł́A�����n�̍��Ǝx���O���[�v��Anthropic�́uClaude Code�v�����p���A��@����N���f���V�����̎��W�A���W�J�A�f�[�^�ގ�Ɏ���܂ł̐N���v���Z�X��80�90����AI�������I�Ɏ��s���܂����B�e�b�N��Ƃ���Z�@�ցA���{�@�ւȂǖ�30�̕W�I�ɑ��Ď��{���ꂽ�A�j�㏉�̑�K��AI�����^�T�C�o�[�X�p�C�L�����y�[���ł��B�l�Ԃ̃I�y���[�^�[���֗^�����̂́u�����邩�~�߂邩�v�Ƃ������헪�I�Ȕ��f�̏�ʂ����ł����B���S�Ȏ����^�ɂ͎����Ă��܂��A���̕����ւ̐i���͑����Ă��܂��B �@���������U���̖{�i���̒���Ƃ��Ē��ڂ��Ă���̂́A�C���V�f���g���X�|���X��[���ւ̈˗����}�����邩�ǂ����ł��BAI�ɂ�鎩���Ǝ㐫�X�L�������{�i������A����܂Ől�Ԃ��������琔�T�Ԃ����ĒT���Ă����N��������C�ɔ����A���p�����悤�ɂȂ�A�N�Q�������}������B���̌��ʁA�Ή��ɓ�����C���V�f���g���X�|���X�̃R���T���^���g�Ɉ˗����E�����邱�ƂɂȂ�܂��B�܂������܂łł͂���܂��A���ɋ߂������ɂ����Ȃ�Ǝv���܂��B �@�����_�ł�AI���g�����Ǝ㐫�X�L�����ɂ����̃X�L�����K�v�ł��B�{�^����őS������Ă����킯�ł͂Ȃ��B�����A90����A6�J����ɏ��ǂ��ς���Ă��邩�͕�����܂���BAI�̐i���̃X�s�[�h���l����ƁA�y�ώ��͂ł��܂���B �����h�䑤��AI���ǂ����p���Ă��܂����B�g�D�̕ω����܂߂ċ����Ă��������B �W���C�X���F�@�h�䂷��������}����AI�ϊv�̒��ɂ��܂��B �@��̗Ⴊ�_�[�N�E�F�u�̉�͂ł��B�ȑO�̓L�[���[�h�����x�[�X�̃A�v���[��ŁA�댟�m����90���ɒB���Ă��܂����B�n���t�H�[�����Ŏg���錾��́A���V�A��⒆����Ƃ������W���I�Ȃ��̂����łȂ��A�Ɠ��̃X�����O��B�ꂪ�������Ă��āA���ʂ̌����ł͂��܂������܂���B �@������Gemini���_�[�N�E�F�u�̌���╶���𗝉�����悤�P�����܂����B���̌��ʁA���x��98���܂Ō��サ�Ă��܂��B���̋@�\�́uDark Web intelligence�v�Ƃ��āA���E�I�ȃT�C�o�[�Z�L�����e�B�C�x���g�uRSA Conference 2026�v�Ŕ��\���܂����BGoogle Threat Intelligence�̐V�@�\�Ƃ��āA�����O�̃p�u���b�N�v���r���[���n�܂��Ă��܂��B����1000�����ȏ�̃_�[�N�E�F�u�̓��e���������A�g�D�ɂƂ��Ė{���ɏd�v�ȋ��Ђ��i�荞�ނ��Ƃ��ł��A�ڋq�ɂ����Ă��܂��B �@AI�̐i���ɔ����A�Z�L�����e�B�g�D�݂̍�����̂��̂��ς���Ă��܂��B�ŏ��̃t�F�[�Y�́A�������ɂ�鐶�Y�������ړI�Ƃ����uHuman-in-the-loop�v�̒i�K�ł����B�����ł̓}���E�F�A��͂̍�������A���胏�[�N�t���[�̎������Ȃǂ����S�ƂȂ�܂��B���Ȃ�X�e�b�v�́AAI�G�[�W�F���g���\�z���Đl�Ԃ�������Ď��A��������uHuman-on-the-Loop�v�̒i�K�ł��B�����Č��ݖڎw���Ă���̂��A�����̃G�[�W�F���g�Q�������I�ɘA�g�A�Ǘ������A�l�Ԃ�������邱�ƂȂ����Ђ̑S�̑���c������uHuman-out-of-the-Loop�v�̒i�K�ł��B �@�A�i���X�g�̐l�����傫���ς��킯�ł͂���܂��A��l��l�̖����͍��{�I�ɕς��܂��B���Ђ�������A����ɑΉ�����\�͂����₳�Ȃ���Ȃ�Ȃ��B����ŁA��[�����ɂ͏T���Ɏ����I��AI�ɐG��Ċy����ł��郁���o�[�������A�͌����ĔߊϓI�Ȃ��̂���ł͂���܂���B�V�����h��̎�@������̎�ŊJ�����Ă����Ƃ����A�O�����Ȋy�������g�D�̒��ɐ��܂�Ă��܂��B ������Ƃ͍��A�������ׂ��ł��傤���B �W���C�X���F�@�܂��p�b��Ǘ��ł��B�Ǝ㐫�̌��J���爫�p�܂ł̊��Ԃ��}���ɏk�܂��Ă��鍡�A����܂Ō�ɂ��Ă����g�D�ɂ͋�����@���������Ăق����B �@10�N���̋Z�p�I��������Ă���A�Ή���90���ŏI���܂���B����ǂ��납�A�Â��ăp�b��Ă��Ȃ��V�X�e�������݂���B�����������V�X�e���ɂ��ẮAAI���g�����Ǝ㐫�X�L�������{�i������O�ɁA�Z�O�����g���܂��̓G�A�M���b�v�ɂ��u�����������ׂ��ł��B�p�b��K�p�͌����ӂ��������ł͂Ȃ��A���Ԃ̂������Ƃł��B �@�������̃��|�[�g�ł��A�Ǝ㐫���J����24���Ԉȓ��̉��z�p�b��K�p�A72���Ԉȓ��̊��S�p�b��K�p��ڕW�Ƃ��Đݒ肷�邱�Ƃ𐄏����Ă��܂��B�uVPC Service Controls�v��uIdentity-Aware Proxy�v�Ƃ������N���E�h�l�C�e�B�u�Ȗh��w��g�ݍ��킹�邱�ƂŁA�p�b��K�p���Ԃɍ���Ȃ��ꍇ�̃��X�N���y���ł��܂��B �@��������ڂ��ׂ��ω�������܂��B2025�N�������ɂ́A�N���E�h���ւ̐N���o�H�Ƃ��āA�\�t�g�E�F�A�Ǝ㐫�̈��p���F�؏��̈��p�����߂ď���܂����B�\�t�g�E�F�A�Ǝ㐫�������Ƃ���N���̊����́A2025�N�㔼����2.9�����瓯�N�̉������ɂ�44.5���ւƋ}�����Ă��܂��B���������ꂽ�Ǝ㐫�X�L�����̕��y�����̔w�i�ɂ���܂��B����͔��ɏd�v�ȕω��ł��B ����2025�N�ɗ����グ��Disruption��[���iCyber Threat Disruption Unit�j�̐��ʂ������Ă��������B �W���C�X���F�@Disruption��[���͋��Ђ��ώ@�A���͂��邾���łȂ��A�ϋɓI�ɖ��͉����邱�Ƃ�ړI�Ƃ��Ă��܂��B���N�C���V�f���g���X�|���X�̎d�������Ă��āA�悤�₭�����ł���悤�ɂȂ����Ƃ������o������܂��B �@2026�N1���ɂ́AIPIDEA�ƌĂ�鋏�Z�^�v���L�V�l�b�g���[�N��E�����܂����B1�T�Ԃ�550�ȏ�̋��ЃA�N�^�[�O���[�v�����p���Ă��邱�Ƃ��m�F���ꂽ�l�b�g���[�N�ŁA���V�A�⒆���A�k���N�A�C�����̍��Ǝx���O���[�v����ƍߑg�D�܂ŕ��L�����p����Ă��܂����B�d�g�݂Ƃ��ẮA�uAndroid�v�A�v���P�[�V������uWindows�v�����\�t�g�E�F�A�Ȃǂ�IPIDEA�֘A��SDK�i�\�t�g�E�F�A�J���L�b�g�j��g�ݍ��݁A���[�U�[�̒m��Ȃ������ɒ[�����v���L�V�̃m�[�h�Ƃ��ė��p���邱�ƂōU�������U��������̂ł��B�k������̍U�����A�܂�ŋߏ�����̍U���̂悤�Ɍ����邱�Ƃ��ł��܂��B �@�������͖@�I�[�u�A�Z�p�I�e�C�N�_�E���A�C���t���̉������Ɏ��{���A���S���P�ʂ̃f�o�C�X���l�b�g���[�N����藣�����Ƃ��ł��܂����B�p�[�g�i�[��Okta�ł́AIPIDEA�̏o���m�[�h��90�������������Ƃ��m�F����Ă��܂��B �@������̓A�W�A�S���ΏۂƂ��������n�X�p�C�L�����y�[���̉�̂ł��B42�J���̒ʐM���Ǝ҂Ɛ��{�@�ւ�W�I�ɂ��Ă��āA�uGoogle Sheets�v�̃X�v���b�h�V�[�g�ɖ��߂��������݁A�}���E�F�A�������ǂݎ���ē����d�g�݂��g���Ă��܂����B�����̓}���E�F�A���Q�ҏ��̍Ō�̃s�[�X�������Ă����̂ł����AMandiant�̋��ЃC���e���W�F���X��C���V�f���g�Ή��̒m����ʂ��Ĕ�Q�҂����ł��A�A�W�A�̂قڑS�Ă̍��ɓW�J���Ă����A10�N�ǂ��������A�N�^�[�̃C���t����S�ė��Ƃ��܂����B �@���ʂ͐��������ł͂���܂���B�E����ɒn���t�H�[�������m�F�����Ƃ���AIPIDEA���̊Ǘ��҂����p�҂ł��鋺�ЃA�N�^�[�����Ɍ����āu���J���ԃT�[�r�X���_�E��������v�ƍ��m���郁�b�Z�[�W�𓊍e���Ă��܂����B�U���҂��������ۂɍ����Ă������Ƃ��A���̏������݂����������܂��BDisruption��[���͍���������𑱂��A�E����ɍč\�z���ꂽ�l�b�g���[�N�ɂ��J��Ԃ��Ή����Ă������j�ł��B �����|�X�g�ʎq�Í��ւ̔����͂ǂ��i��ł��܂����B �W���C�X���F�@�ʎq�R���s���[�^�ɂ��Í���ǂ̌������ɂ��āA�������͏]���̗\����O�|���܂����B�ȑO��2036�N����ƌ����Ă����������A2029�N�ɍX�V���Ă��܂��B�ʎq�r�b�g���̑����ƌ����̋}���Ȑi�W�����̔w�i�ɂ���܂��B �@�ʎq��1�ʂ�2�ʂ�����܂���B��Ɏ������������A����܂Œ~�ς��Ă����Í����f�[�^���ł���B�����_�ł͗ʎq�R���s���[�^�͋ɒቷ����K�v�Ƃ��Ă��ď��p���ɂ͒������ł����A�����̐i�W�X�s�[�h���l����ƁA��Ƃ�{�@�ւ͍�����������n�߂�K�v������܂��B �@�K���ʂł��������������Ă��܂��B�č��ł͕č��ƈ��S�ۏ�ǁiNSA�j���A���ƈ��S�ۏ�V�X�e�������̈Í��A���S���Y���Q�uCNSA 2.0�v�iCommercial National Security Algorithm Suite 2.0�j�������Ă��܂��B���̂��߁A2027�N�ȍ~�̐V�K���B�ł́A�ʎq�ϐ��̂���Í������ւ̑Ή������߂��܂��B�h�q�֘A�̐����Ǝ҂��Ώۂł��B2030�N�ɂ͘A�M���{�̑S�V�X�e���ł̈ڍs���������߂��A2031�N�ɂ͑ΏۃJ�e�S���[�S�̂ł̗ʎq���S�A���S���Y���g�p�����������܂��B �@Google�͊��ɁuGoogle Chrome�v���͂��߂Ƃ���v���_�N�g�ɗʎq���S�A���S���Y�����������Ă��܂��B���E�͏��������̃��X�N�𗝉����n�߂Ă��܂����A�Z�L�����e�B�p�b��̓K�p�Ɠ��l�ɁA���扄���ɂ��Ă����g�D�ɂ͂����P�\������܂���B ����Wiz������̓����ƍ���̃��[�h�}�b�v�������Ă��������B �W���C�X���F�@�������N���[�Y�����u�Ԃ��瓝����Ƃ��n�߂܂����BMandiant�AGoogle Threat Intelligence�ASecOps�A������Wiz����̂ƂȂ����̐��́A�܂��Ƀh���[����[�����Ǝv���Ă��܂��B �@��̓I�ɂ́A�C���V�f���g���X�|���X�œ���ꂽ�C���e���W�F���X���قڃ��A���^�C����Wiz�̌ڋq�ɓ͂��邱�Ƃ�ڎw���Ă��܂��B���b�h�`�[�~���O���A6�J���O�̎���ł͂Ȃ��A���T���ЃA�N�^�[�����ۂɎg���Ă������Ŏ��{����BMandiant�̃G�L�X�p�[�g�������f�B�G�[�V�����ɂ��g�ݍ��܂�āA�Ǝ㐫�̔�������C���܂ł̈�A�̃v���Z�X��Wiz�v���b�g�t�H�[����Ŋ������錩���݂ł��B �@Mandiant�̐��m���AWiz�̃e�N�m���W�[�AGoogle Threat Intelligence�ASecOps���S�Ă��낤�A���ʂȂ��̂ɂȂ�Ǝv���Ă��܂��B Copyright © ITmedia, Inc. All Rights Reserved.
itmedia.co.jpJun 8, 2026extracted
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January and May 2026. The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is also known as Chatty Spider, Luna Moth, and Silent Ransom Group (SRG). "UNC3753 leverages voice phishing (vishing) and social engineering deception techniques to achieve remote access into corporate environments," researchers Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, and Tyler McLellan said. "Using pretexts such as data migration or invoice-related emails, the threat actors initiate phone conversations posing as IT support and convince targets to host screen-sharing sessions and download remote monitoring and management (RMM) utilities." Upon gaining access, the threat actors have been found to either carry out direct searches to locate and exfiltrate files of interest or deceive the victim into carrying out the actions on their behalf. Stolen information includes proprietary legal agreements, personally identifiable information (PII), and financial records. In some instances, the attackers have accessed victims' systems in person, echoing an advisory issued by the U.S. Federal Bureau of Investigation (FBI) last month. These physical intrusions involve the threat actors posing as IT technicians to enter corporate offices and attempt to steal data using removable USB media. "By sending someone in-person to the victim's location to facilitate the intrusion, SRG actors exfiltrate data to an external hard drive or USB drive inserted by the threat actor into the victim's computer," the FBI said of the new escalation in UNC3753's capabilities. Google said UNC3753 shares tactical overlaps with UNC2686, a threat cluster previously known for carrying out BazarCall-style campaigns in 2021. Although the group has been observed deploying LockBit Black ransomware in the past, it has mainly focused on extortion-only operations since 2022, pressuring victims to pay up or risk getting their data published on the LEAKEDDATA data leak site. Both UNC3753 and UNC2686 are assessed to be offshoots of the now-defunct Conti ransomware gang, with early iterations of the campaigns using subscription cancellation lures as part of callback phishing attacks that aim to install remote access software on victims' machines. Beginning around March 2025, the hacking crew has impersonated internal corporate IT help desk staff to trick victims into joining a screen-sharing session on enterprise communication platforms like Zoom, Microsoft Teams, or Quick Assist under the guise of addressing a security issue helping with a corporate data migration project, effectively bypassing traditional security controls. "The threat group frequently initializes campaigns using benign, invoice-themed email lures sent from actor-controlled consumer email accounts," Google said. "These messages contain no active links or malicious attachments. Instead, they typically contain a brief, generic message. The primary purpose of these emails is to establish a pretext, raising the target's internal security concerns so they are more susceptible to follow-up voice calls." Once a session is established, the attackers attempt to establish a persistent foothold by guiding the victims to install legitimate remote desktop software like AnyDesk, Bomgar, SuperOps RMM, or Zoho Assist. Instructions to install these programs are shared via a legitimate service called "privnote[.]com," which allows users to send notes that self-destruct after being read by the recipient. UNC3753 has also been observed establishing Zoom sessions directly on targets' personal laptops to access corporate virtual desktop infrastructure (VDI) and burrow deeper into corporate file systems with the goal of enumerating local and cloud directories, crawling mapped network drives, and harvesting data from highly sensitive folders, including those related to tax filings, audits, corporate client agreements, and Social Security numbers (SSNs). In the final stage, the captured data is sent to the threat actors via WinSCP or Rclone, or to email addresses controlled by the threat actor from the target's mailbox. This is followed by the attackers sending an extortion demand in the form of an email message, typically within 30 minutes of exiting the target environment. The email messages give victims a three-day deadline to initiate ransom negotiations. They also threaten to call and email target employees and external clients directly to notify them of the data breach should they remain unresponsive, not to mention publish the entire stolen information on the data leak site. In many incidents investigated by Google's threat intelligence and incident response teams, the end-to-end operation from initial contact to data extortion is said to have occurred within a single business day. The fast-tempo operational model is exemplified by the fact that the attackers initiate data searches, staging, and theft in under an hour. "Legal services firms represent high-value targets for extortion actors. They maintain concentrated repositories of extremely sensitive client transaction files, merger and acquisition plans, client trade secrets, and corporate regulatory reports," Google said. "Threat groups recognize that legal entities are subject to heavy reputational and regulatory exposure and may be highly motivated to resolve extortion situations quietly to protect their professional standing. Threat actors recognize that targeting the human element - specifically using voice-guided social engineering-enables them to easily bypass robust technical perimeters, web security gateways, and MFA configurations." The findings coincide with a new report from Resecurity about the threat actor's use of DNS Fast Flux network infrastructure across various countries in Latin America, Eastern Europe, Central Asia, Middle East/Africa, East Asia, and the Caribbean to make its domains harder to block - business-data-leaks[.]com, the data leak site that lists close to 100 victim organizations as of June 2026 ep6pheij[.]com, which stages the stolen data per victim "By changing the DNS records and using short Time-To-Live (TTL) values, attackers make their malicious infrastructure resilient against takedowns," the cybersecurity company said. "Both domains operate on a fast-flux network backed by a botnet spread across 18 countries and 22 ISPs. The two domains share 50-60% of their bot pool, confirming a single threat actor operates both. The infrastructure contains zero datacenter or hosting IPs - every node traces back to a consumer ISP (e.g., Telecentro, Mega Cable, Vodafone) and is flagged as residential or mobile IP address."
thehackernews.comJun 8, 2026extracted
Silent Ransom Group targets law firms with fake IT support calls
The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant. The report follows an FBI FLASH advisory published last week warning that the Silent Ransom Group was targeting U.S. law firms in social engineering and even in-person data theft attacks, with Mandiant now providing additional technical details about how the intrusions are conducted. Mandiant says the threat group, tracked as UNC3753, Luna Moth, and Chatty Spider, targeted dozens of organizations across the legal, financial, and professional services sectors between January and May 2026. Mandiant warned that legal firms remain especially attractive targets because they store large volumes of highly sensitive client information and may feel pressured to resolve extortion incidents to avoid reputational and regulatory damage. "Legal services firms represent high-value targets for extortion actors. They maintain concentrated repositories of extremely sensitive client transaction files, merger and acquisition plans, client trade secrets, and corporate regulatory reports," explains Mandiant. "Threat groups recognize that legal entities are subject to heavy reputational and regulatory exposure and may be highly motivated to resolve extortion situations quietly to protect their professional standing." The researchers say the attacks begin with invoice-themed phishing emails from consumer email accounts. These emails do not contain malicious links or attachments and instead serve as a precursor for follow-up phone calls from attackers impersonating corporate IT staff. Conducting attacks via voice calls has been an ongoing tactic by these threat actors for years, which they previously used in BazarCall social engineering campaigns tied to Ryuk and Conti ransomware attacks. A callback phishing attack is when threat actors send benign-looking phishing emails containing alarming or IT-related lures that prompt the recipient to call them back at an enclosed phone number. In the current campaign, the Silent Ransom Group impersonates IT help desks and convinces employees to join remote support sessions via Microsoft Teams, Zoom, Quick Assist, or Microsoft Terminal Services. During these sessions, the threat actors trick the target into installing remote monitoring and management tools such as AnyDesk, Zoho Assist, Bomgar, or SuperOps, thereby granting them initial access to the corporate network. Mandiant also discovered phishing domains tied to the campaign that impersonate internal IT portals using naming patterns such as: -itdesk[.]com -it[.]com -helpdesk[.]com The researchers say the threat actors also use privnote[.]com, a self-destructing messaging service, to share installation links and commands with targets during remote support sessions. According to Mandiant, this tactic helps reduce forensic artifacts left in browser histories or corporate chat logs. Once inside a network, the group searches for sensitive legal and financial documents, including contracts, tax records, Social Security numbers, and merger or acquisition files. The attackers commonly target document management platforms and cloud storage repositories before exfiltrating the data using tools such as WinSCP or Rclone. Mandiant says the extortion operation is highly aggressive, with ransom demands often arriving within 30 minutes of the attackers leaving the victim environment. "These highly aggressive extortion letters give organizations a three-day deadline to respond and initiate ransom negotiations. If the victim organization is unresponsive, the threat actors declare they will call and email target employees and external clients directly to alert them of the data breach," reports Mandiant. "The extortion letters explicitly emphasize that the leak will compromise client trust, invite substantial regulatory fines, and suggest that external clients sue the victim organization for data mishandling." The report also references the FBI's recent advisory in which law enforcement warned that the Silent Ransom Group was targeting U.S. law firms with in-person data theft attacks. According to the FBI, attackers impersonate internal IT staff over phone calls and emails, then attempt to gain remote access or physically visit offices to "image" computers or create backups while secretly stealing files. While Mandiant said there was limited forensic evidence, the researchers believe these in-person attacks are likely linked to UNC3753 based on similarities in targeting, timelines, and operational behavior. The Silent Ransom Group has been active since at least 2022, when it was part of the Ryuk and Conti cybercrime syndicate. As previously reported by BleepingComputer, the threat actors were previously linked to BazarCall callback phishing campaigns that provided initial access in Conti and Ryuk ransomware attacks. After the Conti syndicate shut down in 2022, the group shifted to standalone data theft and extortion operations under the Silent Ransom Group branding. Researchers say the group no longer relies on traditional ransomware encryption and instead focuses entirely on data-theft extortion, in which they steal sensitive data and pressure victims into paying to prevent leaks. A separate report released this week by Resecurity found that the gang is also operating fast-flux infrastructure to hide and protect its data-leak platforms. DNS fast flux is a method where attackers constantly rotate a domain's IP addresses through a large pool of compromised devices to hide their infrastructure and make takedowns or blocking far more difficult. According to the company, the infrastructure uses residential IP addresses across multiple countries and ISPs to make takedowns more difficult. Resecurity said the group's "business-data-leaks[.]com" leak site and related infrastructure rely on residential proxy networks spread across Latin America, Eastern Europe, Central Asia, the Middle East, and Asia. The researchers also linked the infrastructure to other cybercrime-related services and domains. To defend against the attacks, both Mandiant and the FBI recommend implementing strict verification procedures for IT support interactions, limiting remote access tools, enforcing MFA, restricting USB storage devices, and training employees to recognize voice phishing attempts. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 7, 2026extracted
Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245)
Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245) A 0-day privilege escalation vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager that has yet to be patched by Cisco is being leveraged by attackers. “To exploit this vulnerability, an attacker must have netadmin privileges on an affected system. This would require valid credentials or exploitation of CVE-2026-20182 or CVE-2026-20127. Cisco is not aware of successful exploitation by other methods,” the company shared on Thursday. It also said that it has observed “limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.” About CVE-2026-20245 CVE-2026-20245, which affects the command-line interface of Cisco Catalyst SD-WAN Manager, stems from insufficient validation of user-supplied input. Authenticated, local attackers can exploit it by uploading a crafted file to the affected system, and they can consequently execute arbitrary commands as root. As noted above, attackers must first gain authenticated access to the device, for example by exploiting another vulnerability like CVE-2026-20182, which the company observed being exploited as a zero-day in May 2026, or CVE-2026-20127, which has been leveraged by a “highly sophisticated” threat actor since 2023. CVE-2026-20245 affects all Cisco SD-WAN deployment types: on-prem, Cloud-Pro, Cloud (Cisco Managed), and for Government (FedRAMP). Remediation and investigation The company credited Mandiant for reporting the vulnerability, and has provided indicators of compromise (specific log entries) that may point to exploitation. Cisco is still working on pushing out patches for CVE-2026-20245 and there are no available workarounds. The company’s current advice is that customers upgrade to the fixed software documented in CVE-2026-20182 advisory, and verify the configuration of the edge devices. (Cisco didn’t outright say that CVE-2026-20245 is being exploited in conjuction with those two authentication bypass vulnerabilities, but it seems likely.) “To preserve possible indicators of compromise, customers should issue the request admin-tech command from each of the control components in the SD-WAN deployment before upgrading. After the admin-tech file has been collected, software should be upgraded at the earliest opportunity,” Cisco added. “If the logs show indicators of compromise and the system is confirmed to be compromised, applying the software update alone will not resolve the vulnerability. In such cases, follow the specific remediation steps that will be provided by the Cisco Technical Assistance Center (TAC) to help secure the system.” UPDATE (June 10, 2026, 05:40 a.m. ET): Cisco has started releasing Catalyst SD-WAN Manager updates with the CVE-2026-20245 fix. UPDATE (June 24, 2026, 11:40 a.m. ET): Mandiant researchers shared their findings about how attackers leveraged CVE-2026-20245 in early 2026, and shared indicators of compromise. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comJun 5, 2026extracted
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245) actively exploited in attacks enabling root privilege escalation. The zero-day flaw impacts all deployment types, including On-Prem Deployment, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP). In a Thursday advisory, Cisco said the issue stems from insufficient validation of user-supplied input, and it can allow local attackers with low privileges to execute arbitrary commands as root. "An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user," the company explained. "To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of CVE-2026-20182 or CVE-2026-20127. Cisco is not aware of successful exploitation by other methods," it added. "Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices." Formerly known as SD-WAN vManage, this network management software helps admins monitor and manage up to 6,000 Catalyst SD-WAN devices from a single dashboard. Cisco's Product Security Incident Response Team (PSIRT) became aware of CVE-2026-20245 exploitation in June after Google Cloud cybersecurity subsidiary Mandiant reported the flaw but did not share any details. However, it shared indicators of compromise (IOCs) warning admins to check their SD-WAN /var/log/scripts.log file for attempts to upload tenant configuration data to vSmart controllers to escalate privileges through legitimate commands, as in the following example: Apr 15 09:44:57 vmanage vScript: Tenant list upload per vsmart serial number: /usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv vpn 0 "For help determining if a Cisco Catalyst SD-WAN Manager has been compromised, customers may open a case with the Cisco TAC," the company added, advising admins first to collect admin-tech files to help with the review. Security patches not yet available Last month, Cisco also tagged a maximum severity Catalyst SD-WAN Controller authentication bypass flaw (CVE-2026-20182) as actively exploited as a zero-day to gain administrative privileges on unpatched devices. While Cisco has not yet released patches for CVE-2026-20245, it advised customers to upgrade to the software fixed for CVE-2026-20182 on May 14. In February, Cisco patched another Catalyst SD-WAN Manager information disclosure security flaw (CVE-2026-20133), which CISA flagged as actively exploited in late April, and, two weeks later, warned that two more flaws (CVE-2026-20128 and CVE-2026-20122) were being abused in the wild. In March, it also addressed and flagged a critical authentication-bypass vulnerability (CVE-2026-20127) that has been exploited in zero-day attacks since at least 2023. Over the last several years, CISA has tagged 90 Cisco vulnerabilities as abused in the wild, four of them in Cisco Catalyst SD-WAN Manager and six others exploited by ransomware operations. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 5, 2026extracted
Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026
Cisco informed customers on Thursday about yet another SD-WAN product vulnerability that has been exploited in the wild – the seventh whose exploitation was detected in 2026. The new vulnerability, which has yet to be patched by Cisco, is tracked as CVE-2026-20245 and it affects the command-line interface (CLI) of Cisco Catalyst SD-WAN Manager. An authenticated local attacker can exploit it to execute arbitrary commands as root via specially crafted files. “This vulnerability is due to insufficient validation of user-supplied input,” Cisco explained in its advisory. “An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user.” The networking giant noted that an attacker needs to have ‘netadmin’ privileges on the targeted system to exploit the flaw, which can be achieved either with compromised credentials or via the exploitation of other SD-WAN vulnerabilities, such as CVE-2026-20182 or CVE-2026-20127. “Cisco is not aware of successful exploitation by other methods,” the vendor said. “Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.” CVE-2026-20182 was fixed by Cisco in mid-May, after the company learned of its in-the-wild exploitation. This authentication bypass flaw was exploited as a zero-day by a threat actor identified as UAT-8616, which had previously also exploited CVE-2026-20127 to gain unauthorized access to SD-WAN systems. CVE-2026-20245 was reported to Cisco by Mandiant. No information has been shared on the attacks exploiting the zero-day, but SecurityWeek has reached out to Mandiant for details. Cisco said its PSIRT learned about the exploitation of the vulnerability in June, which indicates that it rushed to disclose it. Cisco has made available indicators of compromise (IoCs). Patches will be included in a future Catalyst SD-WAN Manager release and no workarounds are available. Other Cisco SD-WAN product vulnerabilities whose exploitation came to light in 2026 include CVE-2026-20128, CVE-2026-20122, and CVE-2026-20133. An older vulnerability, CVE-2022-20775, was also flagged as exploited in the wild this year. Related: Oracle WebLogic Vulnerability Exploited in the Wild Related: Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities Related: Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash Related: Organizations Warned of Exploited Linux Kernel Vulnerability
securityweek.comJun 5, 2026extracted
Red Hat removes tainted packages after software pipeline compromise
Red Hat removes tainted packages after software pipeline compromise Red Hat pulled dozens of packages from its software distribution pipeline on Monday after attackers used a compromised GitHub account to distribute credential-stealing malware to developers. According to the company’s own preliminary analysis, a compromised GitHub account was used to push the malicious code out to customers, hitting 32 packages downloaded roughly 117,000 times a week. Red Hat said it had since removed the affected packages and that “based on current findings, no actions from customers are required.” The attack used a variant of the Mini Shai-Hulud self-propagating worm whose complete source code was published online May 12 by a cybercriminal group tracked as TeamPCP. As cybersecurity company Tenable noted, the criminals “simultaneously announced a $1,000 contest on BreachForums for the largest supply chain attack using the code.” Whether Monday's attack was carried out by TeamPCP itself or a separate actor using its published code could not be immediately determined, researchers said. Palo Alto Networks' Unit 42 warned that the open-sourcing of the worm's code had already spawned copycat activity, making definitive attribution harder, and that Mini Shai-Hulud “is no longer scoped to TeamPCP.” The attack's malware, which its authors named Miasma, differed from the TeamPCP original only cosmetically, with references to the science-fiction series Dune replaced by Greek mythology while the underlying credential-stealing functionality remained intact. Monday's attack is the latest in a cascading series of supply chain intrusions stretching back to September 2025 — when the original Shai-Hulud worm prompted a CISA advisory — that have struck some of the world's most widely used developer tools. Recent incidents have included an attack in March on LiteLLM, which allowed the cybercriminals to breach several organizations including AI recruiting company Mercor. The attack on LiteLLM was followed by a separate wave of compromises attributed to North Korean hackers targeting the axios JavaScript library. That campaign prompted Mandiant chief technology officer Charles Carmakal to warn “the secrets stolen over the past two weeks will enable more software supply chain attacks, software-as-a-service environment compromises, ransomware and extortion events, and crypto heists over the next several days, weeks, and months.” In May, GitHub confirmed it had been breached by TeamPCP after an employee's device was compromised via a malicious Visual Studio Code extension, with the group demanding $50,000 for stolen source code and threatening to leak it for free if no buyer came forward. OpenAI had also warned that two of its employee devices had been compromised in the same wave, following a supply chain attack on the open-source library TanStack. Speaking at the time of the LiteLLM compromise, Adam Reynolds, senior security researcher at Sonatype, warned that because “the malware targets such a broad range of credentials … this creates the potential for second- and third-order effects that may ripple outward over time, leading to further breaches, service disruptions, or misuse of sensitive data well beyond the initial point of compromise.” Alexander Martin is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
therecord.mediaJun 2, 2026extracted
国内金融機関のフィッシングテンプレートも 日本の企業や個人が知るべきサイバー脅威のトレンドとは
���{���ő�̕W�I�Ƃ����t�B�b�V���O�T�[�r�X���o�ꂷ��ȂǁA�T�C�o�[���Ђ͍��܂��Ă���B�U���҂�AI�����p�A�I�y���[�V�����̑�K�͉��A�������A�I�������}���ɐi�߂Ă���BGoogle�̋��ЃC���e���W�F���X���啛��[�t�A�i���X�g���A�T�C�o�[���Ђ̃g�����h����������B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@���E�I�ɂ܂��܂����܂�T�C�o�[�U���̋��ЁB���{�̊�Ƃ�l�����ɒ��ڂ��ׂ��|�C���g�͉����BGoogle Threat Intelligence Group�iGTIG�j�̕���[�t�A�i���X�g�A���[�N�E�}�N�i�}���iLuke McNamara�j����2026�N5��25���A����ɂ��Đ��������B �@�����ꌗ�̈Ŏs��Ńt�B�b�V���O�T�[�r�X�iPhaaS�FPhising as a Service�j���}���ɐ������Ă���B����̓t�B�b�V���O�U���ɕK�v�ȃc�[���^�C���t����̔�����T�[�r�X�B���Ƃ�_�����V�A�ꌗ�̃T�[�r�X�ƈقȂ�A�����ꌗ�ł͌l��W�I�Ƃ��Ă���̂������Ƃ����B �@����Ƃ��ẮA���K�̃X�}�[�g�t�H���ʒm�Ɍ����������s�����b�Z�[�W�𑗐M����B��Q�҂������N���N���b�N���āA���K�T�C�g�Ɍ����������U�T�C�g�ɏ�����͂���ƁA�F�؏�����^�C���p�X���[�h�����A���^�C���ŖT�A�ގ悷��B�ގ悵�����Ϗ����U���Ҏ��g�̃f�o�C�X��̃f�W�^���E�H���b�g�ɓo�^���A���z�Ȏ����ATM����̈����o�����s���Ă���B �@���ɒ��ڂ����̂́uYY Lai Yu�v�Ƃ���PhaaS�ŁA���{���ő�̕W�I�Ƃ��Ă���BAmazon�AApple�ADMM�A�G�|�X�J�[�h�AJA�o���N�AJCB�J�[�h�AJR�A����،��A�����J���A�}�l�b�N�X�،��A�C�V���A�쑺暌��A�I���R�J�[�h�APayPay�A�y�V�،��A����}�ւȂǂ��̃e���v���[�g�p�ӁB����Ƀ|�C���g�Ҍ���~�̓d�C�����⏕���ւ̑Ή��Ȃǂ��܂߁A���{�̏���҂Ɍ��������x�ȃ��[�J���C�Y���s���Ă���Ƃ����B �@���E�I�ɁA�\�t�g�E�F�A�T�v���C��F�[����v���b�g�t�H�[���̐N�Q��ʂ��A�����̊�Ƃ�l�ɑ��Q��^����P�[�X�������Ă���B �@�}�N�i�}�����͓��{�ɂ�����v���b�g�t�H�[���Ǝ�i�������Ⴍ�j���̗�Ƃ��āB2025�N�㔼��Google�̃Z�L�����e�B�R���T���e�B���O�g�D�ł���Mandiant�����肵���uKnowledgeDeliver�v���������B �@�uKnowledgeDeliver�v�́A�����̑����̊w�Z���ƂŎg���Ă���I�����C���w�K�V�X�e���B�Ǝ㐫�͐ݒ��̕s���ɋN������B2026 �N2��24���ȑO�ɓ������ꂽ�o�[�W�����ł́A�����̌ڋq���ɂ����ċ��ʂ̐ݒ�t�@�C�����g���A�����ASP.NET�}�V���L�[���n�[�h�R�[�h����Ă����B �@���̂��߁A��������献����肵���U���҂́A���̌ڋq��KnowledgeDeliver�C���X�^���X��N�Q�ł����B�����ăT�C�g�Ɉ��ӂ̂���X�N���v�g�ߍ��݁A�K��[�U�[���}���E�F�A�Ɋ����������B �@�T�C�o�[���Ђ̍ŐV�g�����h���A�}�N�i�}�����́u���Ђ̋K�͂Ɣ͈͂̊g��v�u���m���������\�͂̌���v�u�n���w�I�ȗv���v�uAI�i�l�H�m�\�j�ɂ��Ǝ�i�������Ⴍ�j�����p���X�N�̑����v��4�_�ɂ܂Ƃ߂Ă���B ���Ђ̋K�͂Ɣ͈͂̊g�� �@�]���̃l�b�g���[�N�ւ̐N���ɂ����ގ�ɉ����A�\�t�g�E�F�A�T�v���C��F�[���U���A�C���T�C�_�[�̊��p�Ȃǎ�������l�����A�U���̋K�͂ƑΏ۔͈͂��g�債�Ă���B ���m���������\�͂̌��� �@�U���҂͌��m�̉���ւ̒��͂����߂Ă���B�ȑO�̓V�X�e���Ƀ}���E�F�A�ڎd���ގ�����嗬���������A���݂͂܂��F�؏��𓐂ݏo���A���K�̃A�C�f���e�B�e�B�[���ăV�X�e���ɐN���������ւƕω����Ă���B����ɂ��A�Z�L�����e�B�V�X�e���ɂ�錟�m���瓦��₷���Ȃ��Ă���B �n���w�I�ȗv�� �@���E�I�Ȓn���w���̕ω��ɔ����A���Њ����̃g�����h���ω����Ă���B���Ǝx���^�X�p�C�����͈ȑO���犈�������A�����Đ��E�e�n�Ŕ������Ă��镴���̉e���ŁA�n�N�e�B�r�X�g�ɂ��U�����������Ă���B �@AI�ɂ��U���ł́A�K�͂̊g��A�X�s�[�h�̉������A���x�����i�ށB�X�L���̖R�����U���҂ł����x�ōL�͈͂ȍU�����\�ɂȂ����_�����ڂ���Ă���B �@�U���҂́A�����̒�@����j��H�����ގ�Ɏ���܂ŁA������i�K��AI�����p���Ă���B���ݍł���ʓI�Ɏg���Ă���̂͒�����^�X�N�̃g���u���V���[�e�B���O�����A�����n�X�p�C�O���[�v�Ȃǂł́A��p�̃C���t�������p���A��@����V�X�e���N�Q�Ɏ���܂ŁA�U���I�y���[�V�����S�̂����������铮�����m�F����Ă���B �@�܂��A�v���O�����R�[�h�̈Ӑ}��W�b�N��ǂݎ��\�͂ɗD�ꂽ�t�����e�B�AAI���f�����o�ꂵ�A�U���҂ɂ��Ǝ㐫�̔������������Ă���B�Ⴆ�A��v�f�F�̃v���Z�X���u���ɔc�����A�F��������ĐN���ł���Ǝ㐫�������o����������������Ă���B �@�S�ʓI�ɁAAI�͍U�����������A���������邾���łȂ��A�����̃Z�L�����e�B������蔲���邽�߂̋��͂ȃc�[���Ƃ��Ĉ��p����n�߂Ă���B�U�����Ɩh�䑤�̃X�s�[�h����������������AAI�ɂ��U���ɂ�AI�őΉ����邵���Ȃ��ƁA�}�N�i�}�����͐������Ă���B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpMay 29, 2026extracted
Qevlar’s new AI agents correlate CVEs, incident data, and active exploitation signals
Qevlar’s new AI agents correlate CVEs, incident data, and active exploitation signals Qevlar has announced a new set of AI agents designed to bridge the disconnect between Security Operations Centers (SOCs) and vulnerability management teams. The new capabilities help security teams correlate CVEs with live incident data for real-time risk prioritization, automatically identify asset owners to speed remediation, and autonomously hunt for active CVE exploitation. General availability is scheduled for Fall 2026. Finding and exploiting zero-day vulnerabilities has never been faster or easier than in 2026. According to Mandiant’s 2026 report, the mean time to exploit vulnerabilities has dropped to an estimated -7 days, meaning exploitation is now occurring before a patch is released. At the same time, AI systems such as Claude Mythos are lowering the barrier to identifying and operationalizing zero-days, accelerating the speed and scale of exploitation. These shifts are collapsing the traditional response window and exposing the limits of disconnected SOC and vulnerability management workflows. SOC and vulnerability teams hold complementary attack signals but lack a shared workflow or data layer to act on them together. Because incident response and vulnerability management are typically separate functions within organizations, teams operate in silos, resulting in fragmented processes and ad hoc collaboration. As a result, adversaries operate freely across the gaps between them. Qevlar addresses these challenges with three new capabilities: Vulnerability Exploitation Hunter automates the translation of CVE data into hunt queries and proactively searches environments for active exploitation, compressing time from disclosure to detection. CVE Exploitation Intelligence Exchange is a shared intelligence layer that lets both teams operate from the same real-time context on vulnerabilities and their live exploitation. Asset Owner Agent automatically reconciles ownership across CMDB, identity, and operational data sources. “The goal of security teams is no longer just to be faster, but to become stronger over time, continuously reducing the gaps attackers can exploit,” said Ahmed Achchak, CEO of Qevlar. “Most AI SOC tools optimize for speed. We are building for compounding defense. That only happens when you break down the silos between security teams, connect every signal across the security stack, and make the system learn from past cases. Bringing SOC and vulnerability data together is a key step in that direction,” Achchak concluded.
helpnetsecurity.comMay 28, 2026extracted
Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks
Google Cloud this week announced an always-on autonomous platform designed to protect enterprises from the rising wave of AI-powered cyberattacks. The new Google AI Threat Defense cybersecurity solution leverages AI to identify machine-powered threats faster and stop them before they can do harm. According to Google, the platform continuously prioritizes critical real-world risks and can help organizations implement defenses that predict attack paths and proactively deploy remediation. Google AI Threat Defense combines Mandiant’s frontline and incident response experience with Wiz’s cloud security platform (recently acquired by Google) and Gemini’s reasoning and code remediation capabilities powered by Gemini and CodeMender. “By connecting real-world exposure directly to autonomously creating and prioritizing patching, AI Threat Defense helps organizations actively predict attack paths, prioritize the most significant threats, and deploy verified fixes faster than adversaries can exploit them,” Google says. To match the speed of attackers and help organizations surface weaknesses in their software, AI Threat Defense uses the same four-step framework that the internet giant is relying on to stop threats and transform vulnerability management. It involves mapping the environment for asset visibility, conducting deep-dive assessments and AI-driven posture validation, implementing workflows for fast, autonomous vulnerability remediation, and implementing machine-speed detection and response. The first step, Google says, requires exposure reduction by making sensitive assets unreachable from the internet. Each organization also needs to understand its time to remediation and its ability to prioritize risks, and needs to scan environments using AI to identify exposed APIs, applications, configurations, identities, and permissions. “Traditional attack surface management helps identify what is exposed, but organizations now need an AI penetration tester that can continuously analyze every exposure, determine whether it can actually be exploited, and understand what it would enable an attacker to do before attackers do the same,” the Silicon Valley tech giant says. Deep-dive code analysis and AI-driven adversarial testing and validation, the internet giant says, should focus on internet-accessible applications and services, data flows, authentication mechanisms, and business-critical systems. AI Threat Defense, it says, deploys AI agents designed to find deep vulnerabilities, enriches and validates the findings to uncover dependencies across source code libraries and binaries, and creates actionable response plans to help organizations manage surges in critical issues and roll out AI-generated patches. Just as attackers leverage AI to accelerate their attacks, AI Threat Defense aims to reduce time to remediate to minutes by proactively generating fixes directly in a developer’s IDE or CLI at build time. Each patch is tested, and libraries are tagged across source control and production environments for tracking. “Harnessing the full reasoning power of Gemini, CodeMender works seamlessly with Antigravity and Wiz to empower engineering teams to replace vulnerable code, re-write older code to modern, memory-safe languages, and to analyze library dependencies to coordinate seamless rollouts. In parallel, it automates triage and prioritizes remediation across applications and cloud infrastructure,” Google says. Finally, Google says, AI Threat Defense was also designed to implement machine-speed detection and real-time defense, defining ownership and tracking outcomes, establishing a consistent operational framework to help customers fight AI with AI. Related: UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia Related: RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems Related: Caught Off Guard: Securing AI After It Hits Production
securityweek.comMay 28, 2026extracted
Google AI Threat Defense targets attackers using AI to find flaws faster
Google AI Threat Defense targets attackers using AI to find flaws faster Google Cloud introduced AI Threat Defense, an automated cybersecurity platform that combines several of the company’s security assets to find, prioritize, and patch software vulnerabilities at machine speed. The product is aimed at enterprises contending with attackers who use AI to discover and exploit flaws in hours or days, compressing windows that once stretched into weeks. The platform fuses the Gemini family of models, the cloud security firm Wiz, the AI code-fixing agent CodeMender, and the threat intelligence and incident response practice Mandiant. Google Cloud completed its acquisition of Wiz earlier and folded it into the security portfolio alongside Mandiant, which it acquired in 2022. What Google AI Threat Defense does The product operates across a four-stage framework that Google calls Prepare, Scan and Prioritize, Remediate, and Monitor. In the Prepare stage, the platform uses Wiz to map exposed applications, infrastructure, APIs, identities, and runtime environments, reducing what attackers can reach. A pen-testing agent built into Wiz simulates attacks to determine which exposures are exploitable. In the scanning stage, the system runs multiple AI models against the environment. Lighter, faster models handle broad coverage across assets, and frontier models perform deeper analysis on internet-facing applications, customer-facing services, authentication logic, and other systems judged to carry the highest risk. Google’s reasoning for the multi-model design is that no single model finds every class of vulnerability; performance varies across application logic, cloud configuration, binary analysis, and exploitability validation. Customers access the models through the Gemini Enterprise Agent Platform. Once a vulnerability is identified, Mandiant supplies the playbooks for response, including guidance on managing surges of critical issues and retiring legacy products. Remediation in the developer workflow The remediation stage centers on CodeMender, a Google DeepMind agent that generates fixes inside a developer’s integrated development environment or command-line interface. CodeMender works with Wiz and Antigravity to replace vulnerable code, rewrite older code in memory-safe languages, and analyze library dependencies so patches can be coordinated across components. Before any patch reaches production, the platform generates tests to verify the fix. Patched libraries are tagged in source control and production, producing an audit trail that records which model generated each fix and when. Google describes the workflow as autonomy under human supervision. Runtime monitoring The Monitor stage relies on agents tied to Google Security Operations, the company’s security operations center product. These agents handle detection, triage, investigation, and threat hunting across network, identity, and application telemetry. The platform also uses hardened container images that are built, signed, and verified daily to limit the attack surface at runtime. Market context “Our secure-by-default architecture automatically blocks 10 million spam emails every minute, and protects billions of users and customers across our broad portfolio,” Francis deSouza, COO, Google Cloud and President, Security Products, explained. The company’s earlier security work includes zero trust architecture, the Titan security chip, and Google Security Operations. DeSouza wrote that the collapse of the exploit window has made human-speed vulnerability management unviable for enterprise risk, framing AI Threat Defense as Google’s response to attackers who have automated reconnaissance and exploitation. The product enters a market where most security vendors are layering AI features onto existing tools. Google’s pitch centers on combining vulnerability discovery with prioritized, automatically generated patches, drawing on the Wiz risk context, CodeMender remediation, Gemini reasoning, and Mandiant operational guidance.
helpnetsecurity.comMay 27, 2026extracted
KnowledgeDeliver flaw exploited as a zero-day to install web shells
Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell. The flaw is a deserialization issue tracked as CVE-2026-5426 and can be exploited without authentication. It stems from the use of a shared hardcoded machine key in the web portal configuration across all KnowledgeDeliver customer deployments. ViewState deserialization Threat actors obtained the machine key and used it in ViewState deserialization attacks to sign malicious ViewState payloads and achieve remote code execution at the operating system level. Mandiant in late 2025 responded to an attack on a KnowledgeDeliver server and says that initially, the vulnerability was exploited as a zero-day to inject a malicious script into the web platform. Exploitation was possible due to the use of “identical pre-shared ASP.NET machine keys across multiple customer deployments,” the researchers said. “KnowledgeDeliver installations deployed before Feb. 24, 2026 relied on a standardized web.config file provided by the vendor. This configuration file contained hardcoded machineKey values used by the ASP.NET framework to encrypt and sign data, including ViewState payloads,” Mandiant explains. According to the researchers, the malicious code on the platform “convinced users to download a fake installer,” which led to the machine getting infected with a Cobalt Strike beacon, essentially planting a backdoor. “The payload was encrypted using a key that used the name of the compromised organization, which indicated that the threat actor prepared this payload specifically for the targeted organization,” Mandiant says in a report today. Godzilla web shell delivery Mandiant says the threat actor deployed the .NET-based in-memory web shell, Godzilla (a.k.a. BlueBeam), which has also been used in similar attacks observed by Microsoft in late 2024. In August 2024, researchers at cybersecurity company ASEC had also reported that Godzilla was being deployed in ASP.NET environments in ViewState deserialization attacks targeting companies in the financial sector. Mandiant notes that the threat actor compromising KnowledgeDeliver instances executed commands to escalate their control over the web server's file system. This allowed them to modify an application JavaScript file with code that prompted users to install a “security authentication plugin” and to load a malicious script from a domain under the attacker’s control. Over the past year, hackers have used improperly secured machine keys in ViewState deserialization attacks targeting web platforms for various products. In March last year, threat actors abused a hardcoded machine key to craft a malicious payload that allowed access to Gladinet CentreStack's secure file-sharing servers. In July 2025, hackers compromised 85 Microsoft SharePoint servers after stealing the machine key to create signed malicious ViewState payloads. State-sponsored actors also used ViewState deserialization attacks to deploy a reconnaissance tool named WeepSteel on Sitecore servers that exposed the ASP.NET machine key. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 26, 2026extracted
185,000 Likely Impacted by 7-Eleven Data Breach
The data breach suffered by convenience store chain giant 7-Eleven in mid-April likely impacts just over 185,000, breach notification website HaveIBeenPwned reports. The incident, 7-Eleven said in a data breach notice filed with the Maine Attorney General’s Office earlier this month, occurred on April 8 and involved systems containing franchise documents. 7-Eleven said that personal information such as names and addresses was likely stolen in the attack, but did not disclose the number of potentially affected individuals. In mid-April, the infamous extortion group ShinyHunters listed 7-Eleven on its leak website, claiming to have stolen 600,000 Salesforce records, and demanding a ransom to be paid by April 21. The group later offered the data for sale on a Russian hacking forum. The allegedly stolen data has since been published online and added to HaveIBeenPwned, which parsed the dataset and analyzed it. According to the website, the leaked information is consistent with 7-Eleven’s statement on the incident and includes names, addresses, email addresses, and dates of birth. The incident, HaveIBeenPwned says, appears to affect roughly 185,300 individuals. For a small subset, additional data fields were compromised as well. Over the past year, ShinyHunters has been targeting the Salesforce instances of major organizations, mainly through phishing, third-party integrations, and misconfigurations. Following a February alert from Mandiant about escalating ShinyHunters-branded activity, the hacking group claimed responsibility for attacks against Instructure, Vimeo, Wynn Resorts, Vercel, and Medtronic. Related: Oncology Institute Discloses Data Breach Related: 266,000 Affected by Data Breach at Radiology Associates of Richmond Related: DocketWise Data Breach Impacts 143,000 Related: American Lending Center Data Breach Affects 123,000 Individuals
securityweek.comMay 26, 2026extracted
Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment
Threat actors exploited a KnowledgeDeliver zero-day vulnerability to deploy web shells and backdoors, Google-owned Mandiant reports. A learning management system (LMS) built by Digital Knowledge, KnowledgeDeliver is widely used for enterprise and educational e-learning, mainly in Japan. The exploited zero-day, tracked as CVE-2026-5426 (CVSS score of 7.5), existed because Digital Knowledge deployments used a standardized ‘web. config’ file that contained hardcoded ‘machineKey’ values. These keys are used by the ASP.NET framework for data encryption and signing. The presence of the hardcoded values across independent installations allowed threat actors with knowledge of the keys to compromise other deployments by mounting ViewState deserialization attacks. “The ASP.NET ViewState persists page state across postbacks. When the machineKey is known, a threat actor can craft a malicious ViewState payload. By sending this payload in an HTTP request, the threat actor can make the server deserialize it,” Mandiant explains. This type of attack is not new, and was previously seen in the exploitation of Sitecore instances and CentreStack deployments, as well as in attacks involving the Godzilla post-exploitation framework. The KnowledgeDeliver zero-day exploitation, Mandiant says, also led to the deployment of Godzilla web shells (also known as Bluebeam). Deployed in memory, the malware allows threat actors to execute additional commands and payloads on the infected machines. The attackers used Godzilla to modify access permissions to the web application directory and to modify an application JavaScript file to load a malicious script and to display a fake security alert asking the user to install a fake plugin. Ultimately, the systems were infected with a Cobalt Strike backdoor. Because the payload was encrypted with a key containing the victim organization’s name, Mandiant believes that the backdoor was prepared specifically for the organization. Mandiant has provided indicators of compromise (IoCs) associated with the attack and recommends that organizations monitor their environments for potential intrusions. Organizations are also advised to rotate the machine keys for their instances and to restrict access to the LMS. All KnowledgeDeliver deployments before February 24, 2026, are impacted by the zero-day and potentially at risk of exploitation. Related: TrendAI Patches Apex One Zero-Day Exploited in the Wild Related: Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days Related: Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild Related: Researcher Drops YellowKey, GreenPlasma Windows Zero-Days
securityweek.comMay 26, 2026extracted
CISA orders feds to patch actively exploited Drupal vulnerability
CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited. Drupal is typically used by large organizations managing massive data structures and multi-site installations, including government entities, educational organizations, major research universities, and high-profile enterprise and media organizations. Google/Mandiant researcher Michael Maturi discovered this vulnerability (now tracked as CVE-2026-9082) in Drupal's database abstraction API. The security flaw can be exploited without authentication, allowing attackers to trigger arbitrary SQL injection on PostgreSQL-powered sites via specially crafted requests. Successful exploitation can potentially lead to information disclosure, privilege escalation, and even remote code execution. The Drupal security team tagged the flaw as "highly critical" before releasing patches and confirming that exploitation attempts had been detected in the wild. "Since CVE-2026-9082 was released, Imperva has observed over 15,000 attack attempts targeting almost 6,000 individual sites across 65 countries," cybersecurity firm Imperva warned on May 21. "Attacks are primarily targeting Gaming and Financial Services sites so far, at collectively almost 50% of all attacks." Internet security watchdog group Shadowserver now tracks nearly 670 unpatched Drupal installations exposed online, most of them from North America (272) and Europe (273). On Friday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog and ordered Federal Civilian Executive Branch (FCEB) agencies to patch their systems by midnight on Wednesday, May 27, as mandated by Binding Operational Directive (BOD) 22-01. Although BOD 22-01 applies only to U.S. federal agencies, CISA advised all defenders, including those in the private sector, to apply CVE-2026-9082 patches as soon as possible to secure their organizations' devices. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise [..] Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice," the cybersecurity agency warned. "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable." Over the last several years, CISA has flagged 5 Drupal vulnerabilities that have been exploited in the wild, two of which have also been abused in ransomware attacks. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 26, 2026extracted
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon. The vulnerability, tracked as CVE-2026-5426 (CVSS score: 7.5), stems from the use of hard-coded ASP.NET machine keys, leading to unauthenticated remote code execution via a ViewState deserialization attack. The abuse of publicly disclosed ASP.NET machine keys by threat actors was first documented by Microsoft in February 2025. "An unknown threat actor leveraged this access to inject malicious code into the LMS platform, with the goal of infecting users visiting the site," Google Mandiant and Google Threat Intelligence Group (GTIG) said. The security flaw impacted Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026. It's worth noting that similar vulnerabilities in Sitecore Experience Manager (XM) and Gladinet CentreStack and TrioFox have also been exploited by threat actors. The problem is rooted in the fact that KnowledgeDeliver installations relied on a standardized web.config file provided by the vendor that contained hard-coded machineKey values used by the ASP.NET framework to encrypt and sign data, including ViewState payloads. As a result, a threat actor who manages to obtain the keys from one deployment could leverage them to compromise other internet-facing KnowledgeDeliver instances. "The ASP.NET ViewState persists page state across postbacks," Google said. "When the machineKey is known, a threat actor can craft a malicious ViewState payload. By sending this payload in an HTTP request (via the __VIEWSTATE parameter), the threat actor can make the server deserialize it." In the activity observed in connection with CVE-2026-5426, attackers have been found to deploy the Godzilla (aka BLUEBEAM) web shell, granting them the ability to run commands or drop additional payloads. Among the commands executed were instructions to escalate their control over the web server's file system by granting "Everyone" complete access to the web application directory. Subsequently, the threat actor tampered with an application JavaScript file to include code that displayed a fake security alert, urging users to install a "security authentication plugin." In tandem, the unauthorized modifications made it possible to stealthily load a malicious script hosted on an attacker-controlled domain. The script, in turn, convinced users to download a fake installer, ultimately infecting the machines with Cobalt Strike Beacon. "The payload was encrypted using a key that used the name of the compromised organization, which indicated that the threat actor prepared this payload specifically for the targeted organization," Google said. "The exploitation of KnowledgeDeliver highlights the severe risks of using shared secrets in deployment templates. A single leaked key can compromise an entire ecosystem of installations. By implementing unique secrets and robust endpoint monitoring, organizations can defend against these deserialization attacks."
thehackernews.comMay 26, 2026extracted
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)
TeamPCP now operates across three package ecosystems in parallel, it reached GitHub's own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appears to have open-sourced its own framework on GitHub. Bottom line up front Three escalations stacked inside a single week. First, GitHub's CISO Alexis Wales publicly named a malicious Nx Console VS Code extension build (v18.95.0, publisher nrwl.angular-console, verified-publisher badge, roughly 2.2 million installs) as the root of an intrusion that exfiltrated approximately 3,800 GitHub-internal repositories; OpenAI, Grafana Labs, and Mistral AI were named as downstream victims. The poisoned extension was live on the Visual Studio Marketplace for roughly 18 minutes. Second, an officially Microsoft-published Python SDK on PyPI (durabletask, the Azure Durable Functions client, roughly 417,000 monthly downloads) was trojanized across three versions (1.4.1 through 1.4.3) inside an approximately 35-minute window, and independent reporting characterizes the second-stage payload as carrying a Linux disk wiper. Third, the same operator pushed a third Mini Shai-Hulud wave through the @antv npm ecosystem: 639 malicious package versions across 323 packages, including echarts-for-react (roughly 1.1 million weekly downloads) and size-sensor (roughly 4.2 million weekly downloads). Action: rotate any developer or CI/CD credentials exposed during the windows below, stop treating publisher-verified or attestation badges as install-time safety signals, and inspect AI coding agent configuration files for persistence. How this developed The week opened with a credentials-to-publish chain that nobody had previously walked end-to-end in public. Reporting from BleepingComputer and Help Net Security ties OIDC credentials harvested in the May 11 TanStack wave to the Nx Console publish on May 18, which means the same operator that built the worm two weeks earlier used its loot to push a trojanized VS Code extension through a verified-publisher account. In parallel, the same operator poisoned the @antv npm ecosystem through a compromised maintainer account ("atool") and dropped a trojanized build of Microsoft's own durabletask SDK on PyPI. Within 72 hours, GitHub itself, Microsoft, and several named AI-lab developer endpoints were affected. By Friday, multiple vendors reported the Shai-Hulud framework source had been published to GitHub, and copycat forks were already running. What changed, by theme The GitHub-internal breach: a multi-stage operation that worked Takeaway: TanStack-harvested credentials from May 11 were used to publish the trojanized Nx Console extension that breached GitHub itself. This is the first publicly confirmed multi-stage operation in the campaign. On 2026-05-18 a malicious build of the Nx Console VS Code extension (v18.95.0, publisher nrwl.angular-console) was published to the Visual Studio Marketplace and was live for approximately 18 minutes before it was pulled. Per Help Net Security and OX Security, an Nx maintainer credential was used to publish; per BleepingComputer, that credential traces back to the TanStack OIDC abuse chain tracked as CVE-2026-45321. On a GitHub employee endpoint, the extension auto-updated during the 18-minute window, exfiltrated developer secrets, and was then used to move laterally through GitHub's internal CI/CD. The intrusion exfiltrated approximately 3,800 GitHub-internal repositories before containment; reporting suggests no customer-tenant data was affected. On 2026-05-21, GitHub CISO Alexis Wales publicly named Nx Console as the root and confirmed OpenAI, Grafana Labs, and Mistral AI as named downstream victims whose developers had auto-update enabled. The practical lesson is uncomfortable: the malicious extension carried the Visual Studio Marketplace verified-publisher badge. Treating that badge as a safety signal at install time would not have prevented this intrusion. A publisher account being legitimate and a specific publish event being legitimate are different claims, and the campaign now operationalizes that gap. The official Microsoft SDK: durabletask 1.4.1 through 1.4.3 Takeaway: For the first time in this campaign, an officially Microsoft-published package surface was trojanized. The second-stage payload reportedly carries a Linux disk wiper. Three malicious versions of the durabletask Python client (Microsoft's official Azure Durable Functions SDK, roughly 417,000 monthly downloads) were published to PyPI on 2026-05-19 and yanked within hours. Per Wiz, Aikido, and Endor Labs, the dropper is injected into the package's Python source files, so importing the SDK is sufficient to execute it. The second stage is a credential stealer and worm that targets AWS, Azure, GCP, HashiCorp Vault, 1Password, and Bitwarden, and that propagates inside cloud environments via AWS SSM (inside EC2) and kubectl exec (inside Kubernetes). iTnews reporting characterizes the second stage as carrying a Linux disk wiper, materially extending the campaign's destructive capability beyond the W20 1-in-6 locale-conditional wipe. If any team installed durabletask versions 1.4.1, 1.4.2, or 1.4.3 on 2026-05-19, the import alone is the trigger. Treat any environment that pulled one of those builds as exposed, including ephemeral CI runners. The @antv npm wave: the largest single burst by package count Takeaway: 639 malicious versions across 323 packages, including echarts-for-react (roughly 1.1 million weekly downloads). Forty-two of the malicious packages were observed displaying fake Sigstore verification badges in the npm UI. On 2026-05-19, a compromised maintainer account ("atool") published a third Mini Shai-Hulud wave across the @antv ecosystem. Independent counts from StepSecurity, Snyk, and Socket agree on 639 malicious versions across 323 packages, which makes this the largest single-hour Shai-Hulud burst the campaign has produced. The roughly 499 KB obfuscated JavaScript payload runs during npm install and harvests more than 20 credential classes: GitHub and npm tokens, AWS keys, GCP and Azure tokens, SSH keys, Kubernetes service accounts, HashiCorp Vault secrets, Stripe API keys, and local password vaults from 1Password and Bitwarden. The persistence vector first seen in the TanStack wave (.vscode/tasks.json and ~/.claude/settings.json) continues here. Endor Labs flagged a previously unreported primitive in this wave: 42 of the malicious packages displayed forged Sigstore verification badges in the npm UI. This pairs poorly with the W20 finding that the prior wave shipped valid SLSA Build Level 3 provenance. Read together, provenance is now being attacked from two directions at once: real attestations produced by hijacked release pipelines, and fake attestations rendered by the registry UI. Pin exact versions and verify lockfile hashes; do not rely on either visual indicator. Per The Hacker News, the GitHub cleanup invalidated roughly 61,274 npm granular access tokens that had write permissions and 2FA bypass. The framework code drop Takeaway: Multiple vendors reported on 2026-05-22 that the Shai-Hulud framework source was published to GitHub. Copycat forks were running within hours. Datadog Security Labs published a static analysis of a public GitHub repository containing what appears to be the complete TeamPCP framework: a modular TypeScript/Bun toolkit for credential harvesting, supply chain poisoning, and encrypted exfiltration. The repository README explicitly carries the strings "Love - TeamPCP" and "Change keys and C2 as needed." OX Security and ReversingLabs corroborated, and OX subsequently documented the first observed deployments from forks. At least three forks had appeared by Datadog's analysis, including one adding FreeBSD support. For defenders, the practical effect is attribution noise. Detection patterns built on framework artifacts (PBKDF2 salt strings, dead-drop string lineage, GitHub repository naming conventions including the reversed-string "niagA oG eW ereH :duluH-iahS") will now also fire on copycat operators with no operational connection to TeamPCP. Behavioral indicators (writes to ~/.claude/settings.json and .vscode/tasks.json, large 2FA-bypassing token harvests, and Session messenger exfiltration to filev2[.]getsession[.]org and seed1[.]getsession[.]org) remain the more durable detection surface. Microsoft broke its silence; CISA did not Takeaway: Microsoft publicly and prominently entered the response coalition. CISA did not add CVE-2026-45321 to the Known Exploited Vulnerabilities catalog in either of the two W21 update tranches. On 2026-05-20 the Microsoft Security Blog published "Mini Shai-Hulud: Compromised @antv npm packages enable CI/CD credential theft," the first formal Microsoft Security Blog post tied to this campaign in 2026. The next day, GitHub's CISO posted publicly on the Nx Console root cause and named downstream victims. Together, these break the multi-week Microsoft silence that prior weekly updates had flagged as anomalous. Federal posture moved the other way. CISA added nine vulnerabilities to the Known Exploited Vulnerabilities catalog inside W21 across two tranches (seven on 2026-05-20 and two on 2026-05-21) and added none of the campaign's tracking identifiers. CVE-2026-45321 is now absent from the KEV catalog despite the GitHub-internal-codebase intrusion, the Microsoft Security Blog publication, the named impact to OpenAI, Grafana Labs, and Mistral AI, and the trojanization of an officially Microsoft-maintained Python SDK. The continued KEV silence is itself the watch item; it is now the longest such gap of the campaign. Monetization stays frozen Takeaway: Vect and CipherForce remained inactive through the window. Direct fetches on 2026-05-24 confirm Vect's victim count unchanged at 25 (most recent posting 2026-04-15, approximately 40 days inactive) and CipherForce inactive at 91 days with 6 victims unchanged. Combined with the earlier Check Point disclosure of cryptographic flaws in Vect 2.0, the affiliate-ransomware monetization channel remains impaired even as the supply chain operation reached new highs. What defenders should do now Inventory installs of the Nx Console VS Code extension v18.95.0 (publisher nrwl.angular-console) on developer endpoints with auto-update enabled. Treat any endpoint that pulled v18.95.0 during the 2026-05-18 Marketplace window as exposed. Inventory durabletask installs of versions 1.4.1, 1.4.2, or 1.4.3 (PyPI) from 2026-05-19. Treat any environment that imported one of those builds as exposed, including ephemeral CI runners. Inventory @antv/* installs and the named packages (echarts-for-react, size-sensor, timeago.js) from the 2026-05-19 window. Tokens, npm credentials, AWS, GCP, Azure, Vault, 1Password, and Bitwarden vaults from affected hosts should be rotated. Rotate any developer or CI/CD credentials that touched the affected extensions or packages, including GitHub PATs, npm granular access tokens, and cloud provider credentials. Do not treat the Visual Studio Marketplace verified-publisher badge or npm Sigstore verification badges as install-time safety signals. Pin exact versions and verify lockfile hashes against a known-good baseline. Inspect developer endpoints for persistence in ~/.claude/settings.json and.vscode/tasks.json . For Kubernetes-attached workloads, audit recent kubectl exec and AWS SSM session history for anomalous activity from compute that ran any of the affected packages. Watch items A CISA Known Exploited Vulnerabilities addition for CVE-2026-45321, a standalone TeamPCP advisory, or a joint advisory with NSA, FBI, or NCSC-UK. After two W21 KEV tranches that excluded the campaign's tracking CVE despite the GitHub-internal breach and the durabletask trojanization, the continued silence is the watch item. A Mandiant or Google Threat Intelligence Group named-actor product on UNC6780 covering the @antv wave, the durabletask compromise, or the Nx Console publish chain. Technical attribution still rests on StepSecurity, Wiz, Snyk, Socket, the Microsoft Security Blog, and the GitHub CISO statement. A formal GitHub incident report or Security Bulletin, including indicators of compromise and a detailed timeline of the May 18 Visual Studio Marketplace publish window. Any Microsoft response on Marketplace publisher-trust validation, given the verified-publisher badge on the malicious build, would be material. Named copycat-operator deployments from forks of the leaked framework, and any operational-confusion incident in which a fork's activity is misattributed to TeamPCP itself. Any verified disk-wipe incident tied to the durabletask Linux wiper or the @antv-wave payload, particularly a CERT-IL or CERT-IR advisory in response to vendor IR engagements disclosing data loss.
isc.sans.eduMay 25, 2026extracted
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)
TeamPCP now operates across three package ecosystems in parallel, it reached GitHub's own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appears to have open-sourced its own framework on GitHub. Bottom line up front Three escalations stacked inside a single week. First, GitHub's CISO Alexis Wales publicly named a malicious Nx Console VS Code extension build (v18.95.0, publisher nrwl.angular-console, verified-publisher badge, roughly 2.2 million installs) as the root of an intrusion that exfiltrated approximately 3,800 GitHub-internal repositories; OpenAI, Grafana Labs, and Mistral AI were named as downstream victims. The poisoned extension was live on the Visual Studio Marketplace for roughly 18 minutes. Second, an officially Microsoft-published Python SDK on PyPI (durabletask, the Azure Durable Functions client, roughly 417,000 monthly downloads) was trojanized across three versions (1.4.1 through 1.4.3) inside an approximately 35-minute window, and independent reporting characterizes the second-stage payload as carrying a Linux disk wiper. Third, the same operator pushed a third Mini Shai-Hulud wave through the @antv npm ecosystem: 639 malicious package versions across 323 packages, including echarts-for-react (roughly 1.1 million weekly downloads) and size-sensor (roughly 4.2 million weekly downloads). Action: rotate any developer or CI/CD credentials exposed during the windows below, stop treating publisher-verified or attestation badges as install-time safety signals, and inspect AI coding agent configuration files for persistence. How this developed The week opened with a credentials-to-publish chain that nobody had previously walked end-to-end in public. Reporting from BleepingComputer and Help Net Security ties OIDC credentials harvested in the May 11 TanStack wave to the Nx Console publish on May 18, which means the same operator that built the worm two weeks earlier used its loot to push a trojanized VS Code extension through a verified-publisher account. In parallel, the same operator poisoned the @antv npm ecosystem through a compromised maintainer account ("atool") and dropped a trojanized build of Microsoft's own durabletask SDK on PyPI. Within 72 hours, GitHub itself, Microsoft, and several named AI-lab developer endpoints were affected. By Friday, multiple vendors reported the Shai-Hulud framework source had been published to GitHub, and copycat forks were already running. What changed, by theme The GitHub-internal breach: a multi-stage operation that worked Takeaway: TanStack-harvested credentials from May 11 were used to publish the trojanized Nx Console extension that breached GitHub itself. This is the first publicly confirmed multi-stage operation in the campaign. On 2026-05-18 a malicious build of the Nx Console VS Code extension (v18.95.0, publisher nrwl.angular-console) was published to the Visual Studio Marketplace and was live for approximately 18 minutes before it was pulled. Per Help Net Security and OX Security, an Nx maintainer credential was used to publish; per BleepingComputer, that credential traces back to the TanStack OIDC abuse chain tracked as CVE-2026-45321. On a GitHub employee endpoint, the extension auto-updated during the 18-minute window, exfiltrated developer secrets, and was then used to move laterally through GitHub's internal CI/CD. The intrusion exfiltrated approximately 3,800 GitHub-internal repositories before containment; reporting suggests no customer-tenant data was affected. On 2026-05-21, GitHub CISO Alexis Wales publicly named Nx Console as the root and confirmed OpenAI, Grafana Labs, and Mistral AI as named downstream victims whose developers had auto-update enabled. The practical lesson is uncomfortable: the malicious extension carried the Visual Studio Marketplace verified-publisher badge. Treating that badge as a safety signal at install time would not have prevented this intrusion. A publisher account being legitimate and a specific publish event being legitimate are different claims, and the campaign now operationalizes that gap. The official Microsoft SDK: durabletask 1.4.1 through 1.4.3 Takeaway: For the first time in this campaign, an officially Microsoft-published package surface was trojanized. The second-stage payload reportedly carries a Linux disk wiper. Three malicious versions of the durabletask Python client (Microsoft's official Azure Durable Functions SDK, roughly 417,000 monthly downloads) were published to PyPI on 2026-05-19 and yanked within hours. Per Wiz, Aikido, and Endor Labs, the dropper is injected into the package's Python source files, so importing the SDK is sufficient to execute it. The second stage is a credential stealer and worm that targets AWS, Azure, GCP, HashiCorp Vault, 1Password, and Bitwarden, and that propagates inside cloud environments via AWS SSM (inside EC2) and kubectl exec (inside Kubernetes). iTnews reporting characterizes the second stage as carrying a Linux disk wiper, materially extending the campaign's destructive capability beyond the W20 1-in-6 locale-conditional wipe. If any team installed durabletask versions 1.4.1, 1.4.2, or 1.4.3 on 2026-05-19, the import alone is the trigger. Treat any environment that pulled one of those builds as exposed, including ephemeral CI runners. The @antv npm wave: the largest single burst by package count Takeaway: 639 malicious versions across 323 packages, including echarts-for-react (roughly 1.1 million weekly downloads). Forty-two of the malicious packages were observed displaying fake Sigstore verification badges in the npm UI. On 2026-05-19, a compromised maintainer account ("atool") published a third Mini Shai-Hulud wave across the @antv ecosystem. Independent counts from StepSecurity, Snyk, and Socket agree on 639 malicious versions across 323 packages, which makes this the largest single-hour Shai-Hulud burst the campaign has produced. The roughly 499 KB obfuscated JavaScript payload runs during npm install and harvests more than 20 credential classes: GitHub and npm tokens, AWS keys, GCP and Azure tokens, SSH keys, Kubernetes service accounts, HashiCorp Vault secrets, Stripe API keys, and local password vaults from 1Password and Bitwarden. The persistence vector first seen in the TanStack wave (.vscode/tasks.json and ~/.claude/settings.json) continues here. Endor Labs flagged a previously unreported primitive in this wave: 42 of the malicious packages displayed forged Sigstore verification badges in the npm UI. This pairs poorly with the W20 finding that the prior wave shipped valid SLSA Build Level 3 provenance. Read together, provenance is now being attacked from two directions at once: real attestations produced by hijacked release pipelines, and fake attestations rendered by the registry UI. Pin exact versions and verify lockfile hashes; do not rely on either visual indicator. Per The Hacker News, the GitHub cleanup invalidated roughly 61,274 npm granular access tokens that had write permissions and 2FA bypass. The framework code drop Takeaway: Multiple vendors reported on 2026-05-22 that the Shai-Hulud framework source was published to GitHub. Copycat forks were running within hours. Datadog Security Labs published a static analysis of a public GitHub repository containing what appears to be the complete TeamPCP framework: a modular TypeScript/Bun toolkit for credential harvesting, supply chain poisoning, and encrypted exfiltration. The repository README explicitly carries the strings "Love - TeamPCP" and "Change keys and C2 as needed." OX Security and ReversingLabs corroborated, and OX subsequently documented the first observed deployments from forks. At least three forks had appeared by Datadog's analysis, including one adding FreeBSD support. For defenders, the practical effect is attribution noise. Detection patterns built on framework artifacts (PBKDF2 salt strings, dead-drop string lineage, GitHub repository naming conventions including the reversed-string "niagA oG eW ereH :duluH-iahS") will now also fire on copycat operators with no operational connection to TeamPCP. Behavioral indicators (writes to ~/.claude/settings.json and .vscode/tasks.json, large 2FA-bypassing token harvests, and Session messenger exfiltration to filev2[.]getsession[.]org and seed1[.]getsession[.]org) remain the more durable detection surface. Microsoft broke its silence; CISA did not Takeaway: Microsoft publicly and prominently entered the response coalition. CISA did not add CVE-2026-45321 to the Known Exploited Vulnerabilities catalog in either of the two W21 update tranches. On 2026-05-20 the Microsoft Security Blog published "Mini Shai-Hulud: Compromised @antv npm packages enable CI/CD credential theft," the first formal Microsoft Security Blog post tied to this campaign in 2026. The next day, GitHub's CISO posted publicly on the Nx Console root cause and named downstream victims. Together, these break the multi-week Microsoft silence that prior weekly updates had flagged as anomalous. Federal posture moved the other way. CISA added nine vulnerabilities to the Known Exploited Vulnerabilities catalog inside W21 across two tranches (seven on 2026-05-20 and two on 2026-05-21) and added none of the campaign's tracking identifiers. CVE-2026-45321 is now absent from the KEV catalog despite the GitHub-internal-codebase intrusion, the Microsoft Security Blog publication, the named impact to OpenAI, Grafana Labs, and Mistral AI, and the trojanization of an officially Microsoft-maintained Python SDK. The continued KEV silence is itself the watch item; it is now the longest such gap of the campaign. Monetization stays frozen Takeaway: Vect and CipherForce remained inactive through the window. Direct fetches on 2026-05-24 confirm Vect's victim count unchanged at 25 (most recent posting 2026-04-15, approximately 40 days inactive) and CipherForce inactive at 91 days with 6 victims unchanged. Combined with the earlier Check Point disclosure of cryptographic flaws in Vect 2.0, the affiliate-ransomware monetization channel remains impaired even as the supply chain operation reached new highs. What defenders should do now Inventory installs of the Nx Console VS Code extension v18.95.0 (publisher nrwl.angular-console) on developer endpoints with auto-update enabled. Treat any endpoint that pulled v18.95.0 during the 2026-05-18 Marketplace window as exposed. Inventory durabletask installs of versions 1.4.1, 1.4.2, or 1.4.3 (PyPI) from 2026-05-19. Treat any environment that imported one of those builds as exposed, including ephemeral CI runners. Inventory @antv/* installs and the named packages (echarts-for-react, size-sensor, timeago.js) from the 2026-05-19 window. Tokens, npm credentials, AWS, GCP, Azure, Vault, 1Password, and Bitwarden vaults from affected hosts should be rotated. Rotate any developer or CI/CD credentials that touched the affected extensions or packages, including GitHub PATs, npm granular access tokens, and cloud provider credentials. Do not treat the Visual Studio Marketplace verified-publisher badge or npm Sigstore verification badges as install-time safety signals. Pin exact versions and verify lockfile hashes against a known-good baseline. Inspect developer endpoints for persistence in ~/.claude/settings.json and.vscode/tasks.json . For Kubernetes-attached workloads, audit recent kubectl exec and AWS SSM session history for anomalous activity from compute that ran any of the affected packages. Watch items A CISA Known Exploited Vulnerabilities addition for CVE-2026-45321, a standalone TeamPCP advisory, or a joint advisory with NSA, FBI, or NCSC-UK. After two W21 KEV tranches that excluded the campaign's tracking CVE despite the GitHub-internal breach and the durabletask trojanization, the continued silence is the watch item. A Mandiant or Google Threat Intelligence Group named-actor product on UNC6780 covering the @antv wave, the durabletask compromise, or the Nx Console publish chain. Technical attribution still rests on StepSecurity, Wiz, Snyk, Socket, the Microsoft Security Blog, and the GitHub CISO statement. A formal GitHub incident report or Security Bulletin, including indicators of compromise and a detailed timeline of the May 18 Visual Studio Marketplace publish window. Any Microsoft response on Marketplace publisher-trust validation, given the verified-publisher badge on the malicious build, would be material. Named copycat-operator deployments from forks of the leaked framework, and any operational-confusion incident in which a fork's activity is misattributed to TeamPCP itself. Any verified disk-wipe incident tied to the durabletask Linux wiper or the @antv-wave payload, particularly a CERT-IL or CERT-IR advisory in response to vendor IR engagements disclosing data loss.
isc.sans.eduMay 25, 2026extracted
Loading 40 more…