Search/ovh
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
the-bastion
Connections
7 relationships
OVH reveals semi-secret plan to fix critical Januscape bug with mass reboots – and an Australian crash-test dummy
SYSTEMS What Nvidia's first Groq 3 LPU benchmarks tell us about its $20B gambleGemma 4 31B performance tests offer a best-case scenario for next-gen dataflow accelerators ON-PREM US datacenters tripled their water footprint in 10 years... and those are figures from the start of the AI boom. It can only be worse now. Silo-ed reporting isn't helping ai and ML AI slop is good for business if you know what you're doingYour irresponsibility is someone else's opportunity SAAS Salesforce partners not seeing meaningful revenue from Agentforce AI platform, report saysShow us the money ai and ml AI companies are burning books, advocates complain to FTCFahrenheit 203, the temperature GPUs stop gorging on literature Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career Emperor Penguin Linus Torvalds banishes a bug – with a botThe lad himself finds and fixes a tricky one… or does he? FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan
theregister.comJul 21, 2026extracted
1Campaign platform helps malicious Google ads evade detection
A newly identified cybercrime service known as 1Campaign is enabling threat actors to run malicious Google Ads that remain online for extended periods while evading scrutiny from security researchers. 1Campaign is a cloaking service that passes Google’s screening process and shows malicious content only to real potential victims. Security researchers and automated scanners are served benign white pages. The operation has been active for at least three years and is managed by a developer using the name ‘DuppyMeister,’ according to a report from data security company Varonis. “The tool passes Google's screening, filters out security researchers, and keeps phishing and crypto drainer pages online for as long as possible, funneling real users to attacker-controlled sites,” the researchers say. 1Campaign provides “customers” with a user-friendly dashboard where they can get an overview of their operations and set the parameters for their campaigns. The platform can filter visitors in real time, directing traffic to landing pages based on predefined criteria, including geography, internet service provider (ISP), and device characteristics. The researchers say that this targeted approach allows attackers to concentrate on users in regions where the phishing lure is relevant, while filtering out traffic from countries with a higher likelihood of security scrutiny or scanning activity. In one instance, Varonis observed aggressive filtering that blocked 99.4% of 1,676 visitors accessing the malicious ads. This translates into a success rate of just 0.6%, or 10 visitors. The system evaluates each visitor and assigns a fraud risk score between 0 and 100. This reflects the likelihood of non-genuine visitors, and is derived from checking infrastructure details such as cloud providers, data centers, VPNs, and security vendors. "Visitors from Microsoft Corporation, Google, Tencent Cloud Computing, OVH Hosting, and other cloud providers are automatically flagged with high fraud scores and blocked," Varonis says in a report today. Based on IP address ranges, ISP, and behavioral patterns, the system can also determine if the malicious ads are accessed by security scanners. Varonis has observed traffic linked to 1Campaign being distributed in the United States, Canada, the Netherlands, China, Germany, France, Japan, Hungary, and Albania. The cybercrime platform also offers a Google Ads launcher tool that helps operators launch both malicious and benign campaigns. The developer claims that this tool enables bypassing Google’s policy limitations and impersonating legitimate brands in ads. Despite Google introducing multiple safeguards, its ad platform is still used to promote fraud, malware, and crypto-drainers. 1Campaign stands out, though, as it is designed specifically to launch malicious ads that pass Google's automatic inspection and likely survive until victims report them or the campaign is reported manually. Such a cloaking system makes static URL scanning less effective. Varonis says that using realistic browser fingerprints and patterns that mimic human interaction would render better analysis and detection results. For automated detection, Varonis recommends rotating through a diverse IP pool and user-agent configurations to avoid consistent fingerprinting. Users are advised to avoid promoted search results, or at least treat them with suspicion, and bookmark official software distribution channels. Double-checking the URL in the address bar is also recommended before entering account credentials or other sensitive information. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comFeb 24, 2026extracted
22nd September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Several major European airports including Heathrow, Berlin, Brussels, Dublin, and Cork have experienced a cyber-attack, resulting in disruptions to electronic check-in and baggage drop systems using Collins Aerospace’s MUSE software. The incident led to flights delays, cancellations, and diversions, with affected airports advising passengers to confirm travel plans. Luxury brands Gucci, Balenciaga, and Alexander McQueen were hit by a data breach that resulted in the theft of personal information of potentially millions of customers worldwide. The stolen data includes names, email addresses, phone numbers, physical addresses, and total amount spent by each customer, but not financial details such as credit card information. The cybercriminal group Scattered Lapsus$ Hunters claimed responsibility for the attack. Google has confirmed a cyber attack that resulted in hackers creating a fraudulent account within its Law Enforcement Request System platform, though no official data requests were made and no user data was accessed via the account. The incident raised concerns over potential unauthorized access and impersonation of law enforcement. The attack was claimed by Scattered Lapsus$ Hunters group. Hotels in Brazil and other countries have been victims of cyber-attacks that resulted in theft of guest payment card data from front-desk systems via phishing-delivered malware. The incidents involved VenomRAT enabling credential theft, remote access, and data exfiltration, impacting travelers’ financial information across multiple regions. The campaign is attributed to the RevengeHotels group, which leveraged LLM-generated code. Check Point Harmony Endpoint provides protection against this threat (RAT.Win.Venom; Loader.Win.Venom) Venture capital firm, Insight Partners, has been a victim of a ransomware attack that resulted in data exfiltration and server encryption. The breach impacts 12,657 individuals and includes banking and tax data, personal information of current and former employees, limited partners’ data, as well as fund, management and portfolio information. American jewelry company Tiffany’s has suffered a data breach that resulted in the theft of customer personal data and gift card details. Attackers gained unauthorized access to company systems, compromising names, postal and email addresses, phone numbers, sales data, internal client reference numbers, as well as gift card numbers and associated PINs. SonicWall has disclosed a security incident involving unauthorized access to cloud-stored firewall backup preference files through brute-force attacks. According to the company, 5% of registered firewalls had their encrypted credential-containing backup files accessed, with information that could ease exploitation of affected devices. VULNERABILITIES AND PATCHES Fortra has disclosed maximum severity vulnerability CVE-2025-10035 affecting the License Servlet of Fortra’s GoAnywhere Managed File Transfer (MFT) software. The flaw results from deserialization of untrusted data, allowing remote, low-complexity command injection if the attacker can forge a valid license response signature. Successful exploitation targets externally exposed admin consoles and could enable unauthorized system access and command execution. A critical authentication bypass vulnerability in the Case Theme User WordPress plugin allowed unauthenticated attackers to gain access to arbitrary user accounts, including administrators, by exploiting flaws in the Facebook social login implementation when the target’s email address is known. Mass exploitation has been observed in the wild with over 20,900 blocked attempts, as the flaw enables attackers to completely compromise vulnerable WordPress sites. Google has released a security patch addressing 4 vulnerabilities affecting Chrome. Among the vulnerabilities is CVE-2025-10585, a high severity type confusion vulnerability in V8. According to Google, an exploit for the vulnerability already exists in the wild, confirming that it could have potentially been exploited as a zero-day. THREAT INTELLIGENCE REPORTS Check Point Research has analyzed a sophisticated ClickFix campaign leveraging fake job offers to deploy a Rust Loader, PureHVNC RAT, and the Sliver C2 framework across an eight-day intrusion. The investigation revealed multiple PureHVNC variants, features of PureRAT builder and PureCrypter, as well as details on PureCode, the developer of the malware. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Researchers found that Russian threat actors Turla and Gamaredon collaborated in Ukraine, with Gamaredon’s tools deploying and relaunching Turla’s backdoor. On the shared machines, Gamaredon deployed a wide range of tools, while Turla only deployed Kazuar v3. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat (APT.Win.Turla; APT.Wins.Turla.tays; APT.Wins.Turla.ta.*; InfoStealer.Wins.Gamaredon; InfoStealer.Win.Gamaredon; APT.Win.Gamaredon) Researchers analyzed Iran’s MuddyWater APT shifting from opportunistic to much more targeted spearphishing. It deploys custom malware (BugSleep, StealthCache, Phoenix), uses open-source tools, and operates across AWS, Cloudflare, DigitalOcean, OVH, M247, SEDO, and bulletproof hosts. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat (APT.Wins.MuddyWater; APT.Win.MuddyWater; APT.Wins.MuddyWater.ta.*) Researchers detail a recent TA415 campaign against US government and academic targets tied to US–China economic issues. The group impersonated key orgs and figures, using obfuscated Python loaders to set up VS Code Remote Tunnels for remote access and data theft.
research.checkpoint.comSep 22, 2025extracted
Koske, il malware Linux generato dall’AI: ripensare l’approccio alla sicurezza per proteggersi
Nel panorama delle minacce, ha fatto il suo ingresso Koske, il nuovo malware Linux generato dall’AI. “Il malware Koske rappresenta una nuova minaccia per i sistemi Linux, progettato per attività di cryptomining, mostra caratteristiche avanzate di evasione e persistenza mediante componenti rootkit”, commenta Pierluigi Paganini, analista di cyber security e Ceo Cybhorus. Ecco come proteggersi da un malware che “rappresenta una svolta preoccupante nell’evoluzione delle minacce informatiche, in particolare per l’ambiente Linux, storicamente percepito come più sicuro rispetto ad altri sistemi operativi”, secondo Riccardo Michetti, Cyber Threat Intelligence Manager per Maticmind. Ma non dobbiamo rischiare “di fissarci sull’oggetto – il singolo malware – perdendo di vista il processo che lo ha creato, che è la vera, profonda rivoluzione in atto nel panorama della cybersicurezza”, nell’era del vibe coding, secondo Riccardo Paglia, Go To Market Manager per Maticmind. Indice degli argomenti Koske è un nuovo malware Linux generato dall’intelligenza artificiale sviluppato per attività di cryptomining. Il malware Koske supporta infatti il mining di 18 criptovalute, selezionando miner ottimizzati per CPU o GPU in base all’hardware dell’host infetto. Passa automaticamente da una moneta o da un pool all’altro in caso di fallimento, prendendo di mira asset come Monero, Ravencoin, Zano, Nexa e Tari. I ricercatori di Aquasec hanno riferito che il codice dannoso utilizza rootkit e file immagine poliglotti per eludere il rilevamento. “Questa sofisticazione riduce drasticamente l’efficacia degli strumenti tradizionali di rilevamento statico e comportamentale, aumentando la resilienza contro le contromisure”, avverte Martina Fonzo. “L’uso di immagini polyglot per mascherare codice malevolo e l’esecuzione interamente in memoria rendono le tecniche tradizionali di rilevamento inefficaci”, conferma Annalisa Cocco, Senior Cybersecurity Advisor per Maticmind. Gli aggressori sfruttano un server configurato in modo errato per inserire backdoor e scaricare due file JPEG poliglotti tramite URL abbreviati. Le immagini sono file poliglotti che nascondono codice malevolo aggiunto al termine ed eseguono direttamente nella memoria per eludere il rilevamento antivirus. “In un contesto dove persino un’immagine può contenere codice eseguibile, è fondamentale che tutto il personale sviluppi una awareness continua e aggiornata, capace di riconoscere pattern anomali e rischi emergenti”, evidenzia Annalisa Cocco. Uno è un codice C compilato in un file .so rootkit; l’altro è invece uno script shell invisibile che sfrutta strumenti di sistema standard per persistere senza lasciare tracce visibili. “La distribuzione dei payload principali e secondari avviene tramite file immagine a doppio uso. Gli autori delle minacce aggiungono script shell dannosi a file immagine legittimi (per esempio immagini di orsi panda), che vengono nascosti all’interno delle immagini e conservati su piattaforme di archiviazione immagini legittime e gratuite (freeimage, postimage e OVH images)”, si legge nel rapporto di Aquasec. “Questa tecnica non è steganografia, ma piuttosto abuso di file poliglotti o incorporamento di file dannosi. La tecnica infatti utilizza un file JPG valido con codice shell dannoso nascosto alla fine. Solo gli ultimi byte vengono scaricati ed eseguiti, rendendola una forma subdola di abuso poliglotta. Si tratta di un file a doppio uso che elude il rilevamento mescolando i dati dell’immagine con payload eseguibili. I primi X byte sono l’immagine stessa, mentre l’ultima parte del file è un codice shell destinato all’esecuzione dopo la consegna del payload principale al sistema di destinazione”. ’assistenza della Gen AI “A preoccupare tuttavia è la probabile origine: un codice sviluppato con l’assistenza di intelligenza artificiale, evidenziata da strutture modulari, commenti ben scritti e comportamenti adattivi“, avverte Paganini. Infatti, “identificato da Aqua Security, Koske è un miner di criptovalute sofisticato e silenzioso, progettato con l’evidente supporto di strumenti di GenAI. Questo aspetto, più di ogni altro, merita una riflessione strategica da parte di chi si occupa di Threat Intelligence e difesa cyber”, continua Michetti. Infatti assistiamo, secondo Martina Fonzo, Responsabile Market Intelligence per Maticmind, a “un’evoluzione significativa nel panorama malware, caratterizzato da capacità AI-driven di adattamento dinamico alle risorse hardware e persistente evasione tramite tecniche fileless e polyglot execution in memoria”. Gli aggressori hanno ottenuto l’accesso tramite un’istanza JupyterLab configurata in modo errato, quindi hanno garantito la persistenza dirottando le configurazioni della shell e i processi di avvio per eseguire script invisibili. “I server JupyterLab mal configurati sono spesso esposti su Internet senza autenticazione. Una volta ottenuto l’accesso, scarica immagini apparentemente innocue, come file JPEG raffiguranti panda, che in realtà sono file polyglot: immagini contenenti codice eseguibile nascosto. Questo codice viene poi eseguito direttamente in memoria, eludendo i tradizionali antivirus basati su scansioni su disco. Il malware stabilisce la persistenza tramite una combinazione di tecniche come modifica dei file .bashrc, creazione di job cron, servizi systemd, e injection di rootkit in user space sfruttando la funzione readdir() usando il meccanismo di LD_Preload per nascondere file e processi. L’intero framework è progettato per garantire resilienza e silenziosità, qualità oggi fondamentali per le operazioni cyber‑criminali che puntano a monetizzare l’accesso ai sistemi piuttosto che danneggiarli esclusivamente”, evidenzia Michetti. “Il punto non è semplicemente che un’AI possa scrivere codice malevolo”, spiega Riccardo Paglia: “La vera svolta è la democratizzazione e l’accelerazione della minaccia. Stiamo entrando nell’era del cosiddetto vibe coding: la capacità di tradurre un’intenzione, un’idea espressa in linguaggio naturale, in codice funzionante. Questa è una tecnologia dal potenziale immenso per l’innovazione, ma è intrinsecamente a doppio taglio. Lo stesso strumento che permette a uno sviluppatore di creare un’app complessa descrivendone il “vibe”, permette a un malintenzionato di generare un’arma informatica descrivendone l’attacco. La barriera all’ingresso nel mondo del cybercrime non è più la competenza tecnica nella programmazione, ma l’abilità nel formulare la richiesta giusta a un’AI“. “Per comprendere la gravità di questo passaggio”, continua Paglia, “è utile un’analogia storica: l’evoluzione dal cryptomining al ransomware. Anni fa, le infezioni da cryptominer erano viste come un fastidio. In realtà, erano una fase di ricognizione a basso rischio: un modo per testare le difese, stabilire una testa di ponte e monetizzare un asset compromesso senza dare nell’occhio. Una volta confermata la vulnerabilità, quella stessa porta veniva usata per l’attacco finale e devastante: il ransomware“. cryptominer “Oggi, il malware generato dall’AI sta assumendo il ruolo del ‘nuovo cryptominer’, ma su una scala esponenziale. Un aggressore può usarlo per: Generare migliaia di varianti uniche di malware per testare in modo massivo e automatizzato le difese globali, imparando in tempo reale cosa funziona e cosa no”, prosegue Paglia: “Identificare i sistemi vulnerabili non con un’unica infezione, ma con uno sciame di “sonde” intelligenti. L’escalation, il ‘nuovo ransomware’, sarà un attacco di seconda fase, costruito su misura dall’AI sulla base dei dati raccolti. Un malware perfettamente adattato per colpire un bersaglio specifico, le cui difese sono già state mappate e superate nella fase di ricognizione. Si tratta di un ciclo evolutivo della minaccia, auto-apprendente e incredibilmente veloce”. Per questo motivo, “Koske, quindi, non è il mostro finale. È il primo segnale di un’era in cui la velocità, la scala e l’adattabilità degli attacchi supereranno di gran lunga le capacità delle strategie di difesa tradizionali. La nostra risposta non può essere incrementale; deve essere un ripensamento fondamentale del nostro approccio alla sicurezza“, suggerisce Paglia. “Dietro ai nuovi acronimi e buzzword che dominano il panorama della cybersecurity moderna si celano, in realtà, tecniche antiche: modalità di offuscamento, dissimulazione e mascheramento già presenti da secoli anche in ambiti non informatici. L’arte di nascondere un messaggio in un contesto apparentemente innocuo – concetto alla base di tecniche come la steganografia, i file poliglotta o l’approccio dual-use – non è una novità. È solo il mezzo ad essere cambiato: oggi, al posto dell’inchiostro invisibile, si usano i bit. Queste tecniche sfruttano formati apparentemente legittimi (immagini, file audio, documenti) per mascherare codici malevoli, rendendone difficile l’individuazione e l’analisi”, avvisa Giovanni Del Panta, Responsabile Cybersecurity Architects per Maticmind. Nel contesto cyber, un file dual-use ha un aspetto legittimo, ma funzionalità malevole nascoste. Tipico il caso di immagini che contengono in coda script bash, shellcode o payload compilati, come nel caso del malware Koske. I metodi più diffusi per prevedono l’utilizzo di Polyglot Files. Un file poliglotta è progettato per essere interpretabile come due formati diversi contemporaneamente. Ad esempio, un file che è allo stesso tempo una JPEG e uno script shell. Questa tecnica viene utilizzata per evadere i controlli di sicurezza, poiché lo scanner potrebbe vedere solo l’immagine, ignorando il codice eseguibile nascosto. A differenza dei poliglotta, la steganografia non si limita ad “accodare” codice, ma nasconde i dati all’interno del contenuto stesso del file, modificando i bit meno significativi (LSB) dei pixel o dei sample audio, senza alterare l’aspetto esteriore del file. “In ambito difensivo, la steganografia rappresenta una sfida particolarmente insidiosa”, secondo Del Panta: nessun codice eseguibile evidente: il malware è nascosto nei dati, non come parte del flusso binario eseguibile. download apparentemente innocuo: l’immagine sembra legittima, non genera allarmi. necessità di analisi forense specializzata: è richiesto un contesto sospetto per giustificare un’analisi approfondita. assenza di firme statiche: le signature AV tradizionali non riescono a intercettare contenuti offuscati o criptati all’interno dell’immagine. Tuttavia, ciò non significa che sia sempre più difficile da contrastare. Se viene identificato il metodo di embedding, per esempio tramite pattern noti come LSB o tool come steghide, è possibile sviluppare rilevatori automatici su larga scala, basati su euristiche, entropia o pattern di anomalia”. Koske mostra un comportamento simile all’intelligenza artificiale nel suo modulo di connettività, utilizzando diversi metodi per testare l’accesso a GitHub, risolvendo i problemi tramite il ripristino del DNS e dei proxy e forzando dinamicamente i proxy funzionanti. “Ciò che rende Koske davvero critico è la sua struttura e il comportamento, fortemente indicativi di una generazione tramite LLM. Il codice è ben scritto, modularizzato, con commenti chiari e strategie di fallback per ogni fase operativa. Il malware è in grado di adattarsi all’ambiente in cui si trova, verificando per esempio la connettività con diversi strumenti (curl, wget, TCP raw) e tentando automaticamente il ripristino della connessione agendo su iptables, DNS e proxy. Si comporta quasi come un agente autonomo, riducendo al minimo l’intervento dell’attaccante. Questa capacità di adattamento e automazione è la vera forza di Koske, e al tempo stesso la sua più grande minaccia”, sottolinea Michetti. Questa strategia adattiva e automatizzata suggerisce uno sviluppo assistito dall’intelligenza artificiale. “Questo segna un’evoluzione pericolosa: l’uso dell’AI non solo potrebbe migliorare sensibilmente la qualità del malware, ma gli conferisce capacità di adattamento dinamico”, mette in guardia Paganini. “Diversi componenti dello script suggeriscono il coinvolgimento di LLM: commenti dettagliati e ben strutturati e modularità; flusso logico basato sulle migliori pratiche con abitudini di scripting difensive; autorialità offuscata utilizzando frasi serbe e sintassi neutralizzata. “Questo codice potrebbe essere stato progettato per apparire “generico”, rendendo difficile l’attribuzione e l’analisi”, continua il rapporto. Inoltre, “il processo di sviluppo dei codici malevoli coadiuvato dall’utilizzo di sistemi di AI generativa, è notevolmente più efficace“, aggiunge Paganini. “L’intelligenza artificiale è ormai sempre più utilizzata dagli attaccanti per sviluppare codice più efficiente, evasivo e resistente. Stiamo assistendo alla nascita di una nuova categoria di malware, quella ‘AI-powered’, in cui il ciclo di sviluppo, adattamento e diffusione è accelerato e automatizzato”, avverte Michetti. “Di fronte a questo cambio di paradigma, le nostre contromisure devono evolvere radicalmente”, avverte Paglia. Il nuovo malware Koske, recentemente analizzato da Aquasec, sfrutta esattamente queste tecniche: utilizza immagini JPEG dual-use contenenti rootkit .so compilati o script bash furtivi. le immagini sono caricate su piattaforme legittime di image hosting (es. Freeimage, Postimage, OVH), per sfruttare la fiducia dei sistemi verso fonti non sospette. solo i byte finali delle immagini vengono scaricati ed eseguiti, eludendo gran parte delle protezioni basate su signature o analisi comportamentale. il caricamento in memoria (memory-only execution) rende ancora più difficile il tracciamento e la rimozione. Questa forma di attacco non si basa sulla steganografia pura, ma su file poliglotta, eppure dimostra quanto sottile sia il confine tra le tecniche e come spesso vengano combinati più approcci per massimizzare l’evasione”, spiega Del Panta. “L’efficacia di queste tecniche è proporzionale alla loro capacità di nascondersi e alla difficoltà della decodifica. I moderni strumenti cibernetici, spesso potenziati da AI e machine learning, amplificano questa capacità in modo esponenziale, ponendo nuove sfide alla difesa”, avverte il responsabile Cybersecurity Architects per Maticmind. AquaSec ha trovato indirizzi IP serbi, frasi in serbo e lingua slovacca nel repository GitHub dei miner, ma non è riuscita ad attribuire con certezza gli attacchi. “Senza tecnologie difensive AI-driven, contrastare queste minacce sarà sempre più difficile. Attori nation-state e gruppi dediti al cybercrime sono estremamente interessati all’evoluzione di questa tecnologie ed ai suoi possibili impieghi”, sottolinea Paganini. Le difese devono quindi spostarsi verso un approccio più proattivo e comportamentale. “Questa minaccia sottolinea anche un punto critico: la sicurezza tecnica non è sufficiente se non è accompagnata da una solida cultura della cyber security. Aggiornare i sistemi è solo una parte della difesa: oggi bisogna aggiornare anche il modo in cui pensiamo la sicurezza. L’AI sta cambiando le regole del gioco, e solo un approccio dinamico, che unisce visibilità, formazione e capacità di risposta rapida, può offrire una protezione efficace contro minacce come Koske”, avverte Cocco. “La difesa efficace non può più basarsi su signature statiche, ma deve: integrare analisi entropiche e semantiche dei file. utilizzare sandbox comportamentali in memoria. sfruttare AI per identificare pattern anomali anche in contenuti apparentemente legittimi. In un mondo dove anche un’innocua immagine di un panda può nascondere un rootkit, la sicurezza deve diventare altrettanto ‘creativa’ quanto gli attaccanti”.”, conclude Giovanni Del Panta. “I rischi futuri si focalizzano sulla crescente capacità dei malware di auto-ottimizzazione e orchestrazione autonoma in ambienti cloud e infrastrutture critiche, imponendo la necessità di implementare modelli di sicurezza avanzati basati su Zero Trust, monitoraggio comportamentale continuo e protezioni runtime per contrastare minacce altamente dinamiche e stealth”, evidenzia Martina Fonzo. La categoria di malware, quella “AI-powered”, “muta radicalmente il paradigma difensivo, che non può più basarsi solo sulla detection tradizionale o sulla reattività manuale”, sottolinea Michetti. “I team di sicurezza devono adottare un nuovo approccio in questo contesto. In primo luogo, occorre migliorare la visibilità in runtime, con strumenti in grado di intercettare anomalie comportamentali e attività sospette in memoria, non solo su disco. In secondo luogo, è fondamentale rafforzare le pratiche di hardening e configurazione sicura, evitando l’esposizione di ambienti come JupyterLab, in questo caso, su Internet senza adeguate protezioni. Ancora più importante, è necessario sviluppare strumenti difensivi altrettanto automatizzati, in grado di riconoscere pattern generati da AI, come la ripetitività nei commenti del codice e l’uso di strutture linguistiche sintetiche”. Koske è un campanello d’allarme. “Dimostra infatti che l’intelligenza artificiale, pur offrendo enormi vantaggi, può essere sfruttata con la stessa efficacia anche per scopi malevoli. Non si tratta più di una possibilità teorica, ma di una realtà operativa. Chi sviluppa codice malevolo può oggi fare affidamento su strumenti che scrivono, ottimizzano e adattano il malware in modo automatico, rendendo l’attribuzione più difficile, la detection più fragile, e la risposta più lenta. Diventa quindi fondamentale investire oggi in nuove tecnologie e tecnice di detection e sicurezza predittiva in grado di rilevare queste nuove minacce basandosi sull’analisi comportamentale e sull’automazione difensiva consentendo ai team di difesa di adattarsi con la stessa rapidità”, conclude Riccardo Michetti. nalisi comportamentale e difesa proattiva “È imperativo accelerare la transizione verso: architetture Zero Trust: nessun attore, interno o esterno, è considerato attendibile per impostazione predefinita. analisi comportamentale (Behavioral Analysis): non si cerca più un malware noto, ma si monitora il comportamento anomalo dei processi e del traffico di rete, indipendentemente dal codice che lo origina. difesa proattiva: utilizzare tecnologie di “deception” (inganno), come honeypot e canary token, per individuare e studiare gli aggressori non appena mettono piede nella rete”, raccomanda Riccardo Paglia. La formazione deve diventare più profonda. “Non basta più insegnare a riconoscere il phishing”, avvisa : “È infatti necessario formare gli sviluppatori a un ‘secure coding’ che tenga conto delle insidie del codice generato dall’AI. I team di sicurezza devono imparare a modellare queste nuove minacce (Threat Modeling). I dirigenti devono comprendere che il rischio strategico è mutato e richiede investimenti mirati. Le Mmetodologie di sicurezza devono essere adattive. Le difese basate su firme statiche sono ormai obsolete”, conclude Riccardo Paglia. “Sebbene l’uso dell’IA per generare codice migliore rappresenti già una sfida per i difensori, questo è solo l’inizio. Il vero punto di svolta è il malware basato sull’IA, ovvero un software malevolo che interagisce dinamicamente con i modelli di IA per adattare il proprio comportamento in tempo reale”, conclude il rapporto. “Questo tipo di capacità potrebbe segnare un salto di qualità nelle tattiche degli avversari, mettendo a serio rischio innumerevoli sistemi”. “In un futuro, molto prossimo, potremo diventare spettatori inermi in una battaglia tra sistemi ‘intelligenti‘ in grado di adattare il proprio comportamento in base alla risposta del sistema bersaglio, e dall’altro lato sistemi di difesa con classificatori con capacità di detection dinamiche”, conferma Paganini.
cybersecurity360.itJul 28, 2025extracted
Microsoft admits it 'cannot guarantee' data sovereignty
UPDATED Microsoft says it "cannot guarantee" data sovereignty to customers in France – and by implication the wider European Union – should the Trump administration demand access to customer information held on its servers. The Cloud Act is a law that gives the US government authority to obtain digital data held by US-based tech corporations irrespective of whether that data is stored on servers at home or on foreign soil. It is said to compel these companies, via warrant or subpoena, to accept the request. Talking on June 18 before a Senate inquiry into public procurement and the role it plays in European digital sovereignty, Microsoft France's Anton Carniaux, director of public and legal affairs, along with Pierre Lagarde, technical director of the public sector, were quizzed by local politicians. Asked of any technical or legal mechanisms that could prevent this access under the Cloud Act, Carniaux said it had "contractually committed to our clients, including those in the public sector, to resist these requests when they are unfounded." "We have implemented a very rigorous system, initiated during the Obama era by legal actions against requests from the authorities, which allows us to obtain concessions from the American government. We begin by analyzing very precisely the validity of a request and reject it if it is unfounded." He said that Microsoft asks the US administration to redirect it to the client. "When this proves impossible, we respond in extremely specific and limited cases. I would like to point out that the government cannot make requests that are not precisely defined." Carniaux added: "If we must communicate, we ask to be able to notify the client concerned." He said that under the former Obama administration, Microsoft took cases to the US Supreme Court and as such ensured requests are "more focused, precise, justified and legally sound." The Cloud Act was signed into law in 2018 following challenges the FBI faced when getting data via service providers through Store Communications Act warrants, which was itself legislated before cloud computing became a viable thing. Microsoft challenged previous requests, including one concerning a 2016 drug trafficking probe, when emails of a US citizen were held on Microsoft servers in Ireland, and Microsoft argued the SCA did not cover data held outside the US. The bill was supported at the time it became law by AWS, Microsoft, and Google – and was criticized by civil rights groups. European cloud providers with skin in the game have talked up the potential data sovereignty issue for customers in the EU, although, as Microsoft has said, it has not received data requests from the US government for data held on Microsoft servers in Europe. Back at the hearing in France, Microsoft was asked if a data request was well framed, would the corporation be "obliged to transmit the data?" Carniaux admitted: "Absolutely, by respecting this process. But again, this has not affected any European company, or a public sector body, since we have been publishing these transparency reports." Microsoft transparency reports are twice yearly publications in which the business reveals how it manages user data requests, content removal, and more. Legrande chimed in to say that for the past three years Microsoft has implemented a technical environment to minimize data transfers and keep customers data within the EU, "whether at rest, in transit or being processed, or whether it is data generated by application logs, including the support part." As proceedings continued, Carniaux was asked if in the event of an injunction that was legally justified, could he, as Microsoft director of public and legal affairs, "guarantee our committee, under oath" that data on French citizens could not be transmitted to the American government without the explicit agreement of the French government. "No," said Carniaux, "I cannot guarantee that, but, again, it has never happened before." The Register asked Microsoft to comment on this but it declined to do so. Mark Boost, CEO at Civo, claimed: "One line of testimony just confirmed that the US hyperscaler providers cannot guarantee data sovereignty in Europe." "Microsoft has openly admitted what many have long known: under laws like the CLOUD Act, US authorities can compel access to data held by American cloud providers, regardless of where that data physically resides. UK or EU servers make no difference when jurisdiction lies elsewhere and local subsidiaries or 'trusted' partnerships don't change that reality. "This is more than a technicality. It is a real-world issue that can impact national security, personal privacy and business competitiveness. We've already seen examples like the Scottish police case, where sensitive data was transferred out of jurisdiction and beyond intended control. The recent Microsoft testimony demonstrates how this can now happen on demand by US authorities. "The French Senate has set a precedent by demanding answers, and the UK and Europe have an opportunity to do the same. We're already seeing a shift towards building homegrown solutions that support true data sovereignty rather than data residency. The government now needs to help industry accelerate this trend by reducing its over-dependence on hyperscalers." AWS was this week at pains to point out "five facts" about how the Cloud Act works following an uptick in "inquiries about how we manage government requests for data." First off, it says the legislation does not give US government "unfettered or automatic access to data stored in the cloud." "The CLOUD Act primarily enabled the US to enter into reciprocal executive agreements with trusted foreign partners to obtain access to electronic evidence for investigations of serious crimes, wherever the evidence happens to be located, by lifting blocking statutes under US law. "Under US law, providers are actually prohibited from disclosing data to the US government absent a legal exception," it adds, "To compel a provider to disclose content data, law enforcement must convince an independent federal judge that probable cause exists related to a particular crime, and that evidence of the crime will be found in the place to be searched." AWS says it has not yet disclosed enterprise or government customer data under the Act; the principles of the Act are "consistent with international law and the laws of other countries"; and the law does "not limit the technical measures and operatonal controls AWS offers to customers to prevent unauthorised access to customer data." The final point AWS makes - and one no doubt aimed at European rivals trying to exploit the data sovereignty movement - is that the Cloud Act does not only apply to US-headquarterd companies, it is applicable to all "electronic communication service or remote computing service providers" that do business stateside. "For example, European-headquartered cloud providers with US operations are also subject to the Act's requirements. OVHcloud, a French headquartered cloud service provider that operates in the US, notes in its CLOUD Act FAQ page that 'OVHcloud will comply with lawful requests from public authorities. Under the CLOUD Act, that could include data stored outside of the United States'." "Similarly, other cloud providers headquartered in the EU and elsewhere, also have operations in the US." Despite this, mistrust of the Trump administration by some in Europe, notably including Dutch politicians, means worries linger about the state of relations between those in the EU trading bloc and the US. Microsoft, like AWS and Google, has embarked on a campaign to assure any concerned customers in the EU that it can provide data sovereignty in the wake of Trump 2.0 and the US President's less than friendly stance towards nations once considered close allies, including the tariff policy that has derailed predictability in industries across the world. Microsoft President Brad Smith noted the "volatile" economic and geopolitical tensions between the US and Europe and vowed to build more datacenters in Europe among other measures. AWS will have services in place by the end of this year to address worries and Google is tackling these issues too. Nevertheless, there is a movement in Europe to become less reliant on American big tech, with technical advisors pressing the point for independence, and local techies and lobbyists urging the head of the European Commission to create a sovereign infrastructure. Given the billions of dollars US giants transact with customers in Europe, they are going to put up a big fight to retain the business. And they have time on their side, as building self reliance cannot be achieved overnight. We asked Google to comment and it referred us to a previous blog published in May. AWS, which also earlier sent over its aforementioned blog post from July 22, told us it nothing further to add. ® Updated at 08.12 on August 14, 2025 to add: After publication, a spokesperson at OVH Group made contact with The Register to send a statement but didn't respond to our request for an interview. The spokesperson said the blog post from AWS shows "digital sovereignty, and more specifically the question of how extraterritorial laws are applied to data stored in the cloud, is now an unavoidable topic. "This is proof that cloud users need clarity on the Cloud Act, the Patriot Act or FISA 702 and the conditions of their extraterritorial reach." The spokesperson said OVH's HQ, European activities and decision making are "based in France". And it has reviewed the "organizational architecture" of the Group as it is present in several countries, including the US. "Our activities and organization have been organized on a legal, technical and operational level so that OVH US activities are fully independent of the other group entities, in order to protect them from the extraterritorial nature of the American laws and regulation. "OVH Group abides by local laws in the countries it operates in. As such, OVH US may be subject to requests from American authorities within the framework of the Cloud Act as long as these demands are connected to customers of OVH US and are strictly compliant with applicable American law. The French OVH entity (or its European subsidiaries) is not subject to the Cloud Act, the Patriot Act or the FISA."
go.theregister.comJul 25, 2025extracted
New Koske Linux malware hides in cute panda images
A new Linux malware named Koske may have been developed with artificial intelligence and is using seemingly benign JPEG images of panda bears to deploy malware directly into system memory. Researchers from cybersecurity company AquaSec analyzed Koske and described it as "a sophhisticated Linux threat." Based on the observed adaptive behavior, the researchers believe that the malware was developed using large language models (LLMs) or automation frameworks. Koske’s purpose is to deploy CPU and GPU-optimized cryptocurrency miners that use the host’s computational resources to mine over 18 distinct coins. AquaSec identified Serbia-based IP addresses used in the attacks, Serbian phrases in the scripts, and Slovak language in the GitHub repository hosting the miners, but it could make no confident attribution. Pandas attack Initial access is achieved by leveraging misconfigurations of JupyterLab instances exposed online to achieve command execution. After gaining a foothold, the attacker downloads two .JPEG images of panda bears hosted on legitimate services like OVH images, freeimage, and postimage. However, the pictures hide malicious payloads. AquaSec underlines that the threat actor did not use steganography to hide the malware inside images but relied on polyglot files, which are valid in multiple formats. In Koske attacks, the same file can be interpreted as both an image and a script, depending on the application that opens or processes it. While the panda pics feature valid image headers for the JPEG format, they also include malicious shell scripts and C code at the end, allowing both formats to be interepreted separately. A user opening them will see a cute panda bear but a script interpreter will execute the shell code appended at the end of the file. The attacks AquaSec discovered hide one payload in each image, both launched in parallel. “One payload is C code written directly to memory, compiled, and executed as a shared object .so file that functions as a rootkit,” explains AquaSec. “The second is a shell script, also executed from memory, which uses standard system utilities to run stealthily and maintain persistence while leaving few visible traces.” The shell script is executed directly in memory by abusing native Linux utilities, establishing persistence via cron jobs that run every 30 minutes, and custom systemd services. It also performs network hardening and proxy evasion, overwriting /etc/resolv.conf to use Cloudflare and Google DNS, locking it using the chattr +i command, flushing iptables, resetting proxy variables, and using a custom module to brute-force working proxies via curl, wget, and raw TCP checks. This type of adaptability and behavior is what led AquaSec researchers to suspect that the threat actor developed the malware either with the help of a LLM or an automation platform. The C-based rootkit is compiled in memory and uses LD_PRELOAD to override the readdir() function, hiding malware-related processes, files, and directories from user-space monitoring tools. The rootkit filters entries based on strings like koske, hideproc, or by reading hidden PIDs from /dev/shm/.hiddenpid. After establishing network access and setting up persistence, the shell script downloads cryptominers from GitHub. Before deployment, the host’s CPU and GPU are evaluated to determine which miner would be the most efficient choice. Koske supports mining for 18 different coins, including the hard-to-trace Monero, Ravencoin, Zano, Nexa, and Tari. If a coin or mining pool becomes unavailable, the malware automatically switches to a backup from its internal list, indicating a high degree of automation and adaptability. AquaSec warns that while AI-powered malware like Koske is already concerning, future variants may leverage real-time adaptability, evolving into a far more dangerous class of threats. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 24, 2025extracted