Search/shutterstock
Vendor

shutterstock

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
ntfserver
Connections
200 relationships
Spyware, Apple invia una “notifiche di minaccia” agli utenti in 110 Paesi
Avviso di sicurezza di Apple per la possibile diffusione di una campagna cybercriminale in diversi Paesi. Apple ha inviato una nuova serie di notifiche agli utenti per una nuova minaccia informatica visto che gli stessi potrebbero essere stati presi di mira da spyware mercenario . Si tratta di un software di sorveglianza sofisticato in grado di compromettere i dispositivi. Gli avvisi hanno raggiunto utenti in 110 Paesi . In generale le notifiche hanno riguardato clienti in oltre 150 Paesi ed è così stato possibile ottenere un’indicazione della portata globale raggiunta dalle tecnologie di sorveglianza utilizzate anche da Governi e agenzie statali. La compagnia ha sottolineato che questo nuovo sistema di comunicazione rappresenta un miglioramento nel supporto agli utenti, con aggiornamenti diretti sui loro dispositivi. Un nuovo sistema di avviso direttamente sull’iPhone La notifica, ha spiegato la multinazionale con base a Cupertino , “ può comparire direttamente sulla schermata di blocco dell’iPhone attraverso un avviso push “. In questi termini, l’utente riceve l’invito ad adottare immediatamente alcune misure di sicurezza. Apple , sempre nell’ottica di un supporto continuo, ha inoltre aggiornato l’esperienza associata alla notifica. Si è voluto così rendere più semplice accedere alle informazioni e alle indicazioni su come procedere. Il messaggio visualizzato avverte: “ Abbiamo rilevato un attacco di spyware mercenario mirato al tuo iPhone. Puoi adottare subito alcune misure per proteggere i tuoi dati e il tuo dispositivo “. L’avvio delle notifiche avviene inoltre tramite e-mail e si possono visualizzare quando l’utente accede al proprio account Apple . Avviso e indagini Ricevere una notifica di questo tipo non significa necessariamente che l’attacco abbia avuto successo. Tuttavia, è un invito a prendere la questione con grande serietà . Tra le misure suggerite c’è l’attivazione della Modalità isolamento (Lockdown Mode) , una funzione di sicurezza progettata per rendere molto più difficile la riuscita di attacchi sofisticati condotti attraverso spyware . Secondo Apple , finora non c’è stato alcun caso “ di compromissione di un dispositivo con la Modalità isolamento attiva “. La stessa notifica fornisce inoltre indicazioni su come chiedere assistenza e su chi contattare per ricevere supporto . Un singolo avviso, inoltre, può essere la base per successive indagini . Attacchi rari ma sempre più sofisticati Gli attacchi attraverso spyware altamente sofisticati rimangono relativamente rari, almeno secondo gli esperti. Negli ultimi anni, tuttavia, la diffusione di tecnologie di sorveglianza sempre più potenti ha sollevato preoccupazioni per il loro possibile utilizzo contro giornalisti, attivisti, esponenti della società civile e oppositori politici. Le notifiche di Apple hanno quindi una funzione che supera la semplice protezione del singolo dispositivo. “ Possono diventare un segnale d’allarme per individuare campagne di sorveglianza più vaste , aiutando analisti e organizzazioni specializzate a identificare ulteriori casi di abuso “. Seguici anche sul nostro canale WhatsApp Vai al sito di Cybersecurity Italia. L'articolo Spyware, Apple invia una “notifiche di minaccia” agli utenti in 110 Paesi sembra essere il primo su CyberSecurity Italia .
cybersecitalia.itAug 20, 2026extracted
Exclusive: Linux Foundation's Akrites to Go Live in September
A major industry coalition set up to defend critical open-source software against AI-enabled cyber threats is expected to operationalize its vulnerability disclosure and remediation platform in September, Infosecurity has learned. The initiative, called Akrites, was launched at the end of June 2026 by the Linux Foundation, the Open Source Security Foundation (OpenSSF) and over 20 founding members. These include AI frontier labs Anthropic and OpenAI; cloud and tech giants like Amazon Web Services, Cisco, Google, Microsoft and its subsidiary GitHub, IBM and its subsidiary Red Hat and NVIDIA; cybersecurity firms like Chainguard, Endor Labs and Zscaler; and large enterprises, such as Citi, JPMorganChase, Ericsson and Vodafone. Each member of the coalition must donate between one and 10 engineers to the project and pay membership fees based on which of the three membership tiers they chose – Associate, General and Premier –, each corresponding to a level of benefits. At launch, the Linux Foundation announced two major missions for the initiative: Establish a shared security incident response team (SIRT) for mitigating and remediating vulnerabilities in open-source packages and libraries Develop a standardized coordinated vulnerability disclosure (CVD) process, built on confidentiality-first principles and industry-standard tooling Infosecurity spoke to Christopher ‘CRob’ Robinson, OpenSSF’s CTO and chief security architect, who was appointed as CTO of Akrites in June. He described Akrites’ sole mission as “coordinating AI-enabled vulnerability reports to upstream open-source maintainers so that the fixes are available to the whole ecosystem.” He said the team responsible for the initiative’s tooling, including the vulnerability management and SIRT platform, had now produced “the first draft of the tool chain.” He revealed that the initiative’s main platform will be based on Carnegie Mellon University's Vulnerability Information and Coordination Environment (VINCE), a vulnerability management platform developed in 2020 by the Computer Emergency and Response Team Coordination Center (CERT/CC), a unit of the university’s Software Engineering Institute (SEI). “We have a substantial amount of additional capabilities leveraging large language models (LLMs) to do deduplication, patch creation and more,” added the Akrites CTO, who confessed he’s already received thousands of vulnerability reports after two months of launching the project, an estimated 30% of these are duplicates. “Today, we’re bringing in some additional experts from the Akrites members to go through and do a penetration test and a security audit and then we’ll be augmenting the tools to allow the input of a combination of real and synthetic data through the system to make sure it functions as we design,” Robinson explained. When ready, the finished platform will be open-sourced and available for anyone to use for their own purposes. Additionally, Robinson said the Akrites-run platform is expected to “go live” and “start taking automated vulnerability reports” some time in September. “I have been trying to do something like Akrites my whole career,” he said. “I feel right now we have the tools, the willpower and access to the technical experts, so I’m very optimistic on our chances that we’re going to be able to provide a very valuable service to the global open-source ecosystem.” Stay tuned to Infosecurity for further updates on Akrites and similar initiatives to tackle the explosion of AI-enabled vulnerability reports in open-source projects. Image credits: Linux Foundation / IB Photography / Shutterstock.com
infosecurity-magazine.comAug 19, 2026extracted
OpenAI Tightens AI Safeguards Following Hugging Face Incident
Following the recent Hugging Face incident, in which an OpenAI model went rogue and targeted the open-source platform while attempting to complete a task, the AI firm said it is adding greater urgency to its efforts to strengthen AI safeguards. In an update published on August 18, the AI firm said that as models become more capable, the risks associated with developing and testing them internally also grow. Following Hugging Face, the company paused certain frontier AI workloads that could execute code or access the internet, and has since introduced stricter controls including workload sandboxing, network isolation and continuous security testing. The pace of testing has been temporarily slowed and its largest planned frontier reinforcement learning (RL) run remains on hold. The company is looking to evolve its Preparedness Framework, first published in December 2023. The framework is the process of tracking and preparing for advanced AI capabilities that could introduce new risks of severe harm. The company has found that following internal evaluations of Astra, one of its upcoming models, it may meet the critical level of cyber capability threshold under the Preparedness Framework. On August 7, OpenAI said it was pausing internal activities relating to Astra until it meets stricter security controls. In its latest update, it revealed that Astra workloads remain paused until they are fully migrated and enhanced to meet the new security bar. How OpenAI is Strengthening AI Safeguards As OpenAI expects its models will soon drive most security, the firm’s safeguarding approach must scale with the AI capabilities. The safeguards rest on three principles. Monitoring, which detects and allows us to respond to concerning behavior Alignment, which reduces the likelihood of harmful or unauthorized actions Security measures, which limit what AI systems can access or affect The AI firm has expanded its monitoring capabilities to detect potentially dangerous model behavior. Its new multi-stage monitoring system uses classifiers to identify suspicious activity and escalate concerns to automated investigators that analyze tool usage, reasoning processes and model actions. OpenAI said the system is designed to issue an alert within 30 minutes of detecting “concerning activity”, with enhanced monitoring now required for advanced models that can use external tools. Investment is also being increased in alignment with research to reduce risks associated with increasingly capable AI systems. The company is applying additional controls during reinforcement learning training to discourage behaviors such as reward hacking, deception and attempts to bypass safeguards. OpenAI argued that as AI models develop stronger cyber capabilities and gain access to external systems, ensuring they remain aligned with intended goals will be critical to preventing misuse and reducing cybersecurity risks. Image credit: TY Lim / Shutterstock.com
infosecurity-magazine.comAug 19, 2026extracted
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
Meta has confirmed that one of its AI models exploited a vulnerability in a third-party service during testing, joining OpenAI and Anthropic in reporting similar incidents. Meta said the incident occurred during testing by independent firm Irregular. A misconfiguration by Irregular allowed one of Meta’s models to access the internet during evaluation. The AI then went on to exploit a security vulnerability in a third-party service. The tech giant said the exploit occurred in a manner similar to previously-reported instances with other companies. “Meta learned of this when Irregular notified us, and we are currently investigating and will issue a full retrospective once we have all the facts," said a statement by a Meta spokesperson sent to Infosecurity. Separately, on August 4, Open AI published an update describing how two external testing partners identified incidents in which testing configurations and controls allowed model activity to extend beyond the test environment. One involved Irregular. OpenAI said that during a Capture-the-Flag-style evaluation intended to be isolated from the internet, a testing-environment misconfiguration allowed models to access the public internet. The second related to the UK’s AI Security Institute (AISI), which said it had detected unusual data transfers leaving its research systems during a routine cyber evaluation. This and the recent breaches by OpenAI and Anthropic models have raised security concerns among the cybersecurity community. “When several of the world’s most capable AI systems reach real people, services and companies from test environments within a matter of weeks, we can no longer dismiss these as isolated incidents,” said Tim Hudson, president of OpenSSL, a free open-source software library that provides secure digital communications. “We are seeing a recurring pattern: autonomous systems are given an objective, internet access and excessive authority - and those responsible only discover afterwards what the systems have done.” This does not mean that AI has developed malicious intent of its own, rather poorly constrained objectives, vulnerable interfaces and permissions to act are allowing these acts to be carried out. “We need to be careful to not assume that an AI independently decided to become a cybercriminal. It was given internet access, tools and an objective by people. The concern is that it was then able to chain actions together in ways its creators did not fully anticipate,” noted Javvad Malik, Lead CISO Advisor at KnowBe4. AI Firms Criticized for One-Upmanship Across the cybersecurity sector, many are becoming increasingly skeptical of the competition among vendors who claim their models are the most powerful. “There also appears to be an underlying game of one-upmanship between AI vendors touting how powerful their models are,” Malik said. Meanwhile, Alex Goller, Principal Solution Architect EMEA at Illumio, said that the fact that there has been three similar incidents across the biggest AI players is “simply ridiculous.” “We've seen guardrails intentionally loosened to test their limits – Meta's model didn't need to be clever to breach another company's systems. The timing of conveniently finding the exact same problem either means it's a stunt or they weren't paying enough attention during testing. Either way, both answers are worrying,” he said. AI Governance is Key The key theme across the incident is that AI was given a task to conduct but was not constrained by sufficient guardrails to stop it behaving in a way that compromised external organizations. Jack Nelson, CISO at Ivanti, said, "Security teams and their organizations need to carefully map a governance plan and policies for AI agents. As they become more powerful, so will their chances of conducting rogue activities that can have significant long-term impact. Malik said the key takeaway from these issues is governance. “As organizations give AI greater access to systems and data, human oversight, least-privilege permissions and effective monitoring become essential,” he said. Robust guardrails and visibility into what actions AI is undertaking will need to be prioritized and invested in. AI agents should be governed by least-privilege access, privacy-by-design principles and real-time monitoring. Infosecurity has contacted Irregular for comment. Image credit: Poetra.RH / Shutterstock.com
infosecurity-magazine.comAug 6, 2026extracted
ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point
Open AI’s ChatGPT entered the top 10 of the most impersonated brands in phishing attacks for the first time in the second quarter of 2026, according to a Check Point study. This included a fake "ChatGPT Plus payment failed" email the cybersecurity company observed in June. The malicious email was dressed up to look exactly like an OpenAI billing notice and led victims to a page built purely to steal full credit card details. The inclusion of OpenAI’s top customer-focused tool is “a strong signal of where attacker attention is heading next,” said Check Point. “As AI tools move from novelty to daily habit for millions of people managing subscriptions, payments, and work tasks through them, they become just as attractive a target as any bank or tech giant. Expect AI platforms to keep climbing this list in future quarters.” Big Tech Organizations: The Most Impersonated Brands As detailed in Check Point’s Q2 Brand Phishing Report, Microsoft remains the top impersonated brand, , as it did in the previous quarter. It accounts for 23% of all phishing attempts, nearly double the share of LinkedIn, the second-most targeted brand – also owned by Microsoft. Google, Apple and Amazon also made the top five most impersonated brands, which accounted for over half of all phishing attempts. Brand phishing is described by Check Point as an operation where a scammer impersonates a trusted, well-known company, through email, a fake website or both, in order to steal login credentials, payment details or personal information. Real world cases this quarter ranged from fake payment failure emails to full replica online stores, fake login pages and malware disguised as software updates. How to Prevent Brand Phishing As the top five most impersonated brands in Q2 2026 suggests, technology was the most targeted industry overall, followed by social networks and banking. Other real cases in the report included a cloned Michael Kors store that replicates the entire checkout, a fake UNIQLO storefront in a country where it doesn't even operate and a dodgy PayPal login page with a warped logo that looks AI-generated. In a blog published on July 23, Check Point provided recommendations to mitigate the threat of brand phishing. These include: Stopping phishing messages inline before they reach an inbox, rather than relying on detection once the damage is already done Using AI powered detection to catch brand impersonation, business email compromise, credential harvesting, QR code phishing and AI generated attacks with a level of accuracy manual review can’t match Consolidating email and workspace protection across Microsoft 365, Google Workspace and collaboration tools into a single platform, reducing operational complexity Automating investigation and response so security teams can resolve real threats faster Image credit: Celia Ong / CKA / Shutterstock.com
infosecurity-magazine.comJul 24, 2026extracted
CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities
Two vulnerabilities affecting Fortinet’s malware analysis and detection FortiSandbox have been exploited in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) has warned. The vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089 are both critical, with a severity rating (CVSS) of 9.1 each. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog on July 16, suggesting evidence of observed exploitation in the wild. The agency urged rolling out patches across federal government by July 19. ForitSandbox Exploits Can Lead to Execute Rogue Commands CVE-2026-39808 was detected by Samuel de Lucas Maroto, a security researcher at KPMG Spain, and disclosed by Fortinet on April 14. It is an operating system (OS) command injection vulnerability affecting Fortinet’s FortiSandbox versions 4.4.0 to 4.4.8. When exploited, it allows an attacker to execute unauthorized code or commands via . Fortinet has released a patch in FortiSandbox version 4.4.9. The second bug, CVE-2026-25089, was initially identified by Adham El Karn, a security researcher within the Fortinet Product Security team, and was disclosed by the cybersecurity firm on June 9. It is an OS command injection vulnerability affecting Fortinet’s FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8 and all 4.2 versions, FortiSandbox Cloud versions 5.0.4 to 5.0.5 and FortiSandbox PaaS versions 5.0.4 to 5.0.5. When exploited, it allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Fortinet has released a patch in FortiSandbox versions 4.4.9 and 5.0.6. CISA required US federal agencies to apply mitigations and patches released by Fortinet. For cloud-based services, agencies should discontinue using the product if mitigations are unavailable. CISA has not confirmed whether these vulnerabilities have been used in ransomware campaigns. Image credits: Piotr Swat / bluestork / Shutterstock.com
infosecurity-magazine.comJul 17, 2026extracted
Anthropic and OpenAI Security Tools Could Fuel Cyber-Attacks, Researchers Warn
As organizations turn to Anthropic and OpenAI-powered agents to automate vulnerability discovery and patch management, researchers have warned that the extensive access these tools require could transform them into potential attack vectors. A new report published by the AI Now Institute on July 8 by Heidy Khlaaf, chief AI scientist, and Boyan Milanov, senior research scientist, demonstrated a proof-of-concept (PoC) exploit that enables remote code execution in two of the most used AI-powered command-line interfaces (CLIs), Anthropic’s Claude Code and OpenAI’s Codex. The exploit affects Claude Code when used with Claude Sonnet 4.6 and 5, as well as Opus 4.8 and Codex when used with GPT-5.5. These tools can be manipulated into running malicious code on a user's machine simply by having them review or analyze a third-party open-source codebase, a commonly recommended defensive use case. Prompt Injection Chain Enables Silent Remote Code Execution The PoC exploit starts with an imaginary attacker hiding malicious instructions inside the files of an open-source library, for example in code comments or documentation, in a way designed to manipulate how the AI interprets commands. A victim then uses Claude Code or Codex in "auto-mode" or "auto-review" mode, a standard feature that automatically executes commands judged to be safe without asking for human approval, only pausing on things flagged as risky. Because the injected instructions are crafted to trick the AI's judgment, the AI assistant is fooled into believing the attacker's malicious commands are harmless or routine. Consequently, it runs them automatically without alerting the user. The key mechanism is a multi-stage prompt injection combined with tool-use exploitation. When the AI agent begins scanning the repository, it doesn’t just read code passively but it builds a semantic model of the project by parsing source files, scripts and documentation. The attacker takes advantage of this by embedding natural-language instructions inside trusted-looking artifacts (e.g. README.md) that are interpreted by the model as part of its task context rather than untrusted input. These injected instructions are crafted to reshape the agent’s planning process. Instead of directly telling the model to execute something obviously malicious, which would trigger safeguards, the instructions suggest that a specific script (e.g. security.sh) is a standard part of the project’s security workflow, frame execution of that script as necessary to complete the user’s request (“run security checks”) and align with the agent’s goal (vulnerability analysis), making the action appear legitimate. At the same time, the repository contains a second-stage payload comprised of the following: A shell script (security.sh) that appears to run common tools (e.g. linters or static analyzers) A hidden malicious binary (code_policies) that the script executes A decoy source file (code_policies.go) that makes the binary look benign and consistent with expected build artifacts When the agent evaluates whether it is safe to execute the script, it relies on its internal classifier and heuristics. Because the script references familiar security tooling, the binary appears to correspond to legitimate source code and the documentation frames execution as routine, the agent misclassifies the action as safe. In auto-mode or auto-review mode, this classification is critical as the agent is explicitly authorized to execute shell commands without human approval if they are deemed low-risk. As a result, the agent autonomously: Decides that running security.sh is part of the requested analysis Executes the script via its tool interface (e.g. shell access) Indirectly launches the malicious binary Triggers arbitrary code execution on the host system This results in remote code execution, meaning the attacker's code runs on the victim's machine even though the victim believed they were having the AI passively scan a codebase for vulnerabilities. An Attack with Low Requirements What's notable is how little is required to pull this off. There's no need for special hooks, plugins, skills, model context protocol (MCP) servers or custom configuration files. It works with a completely out-of-the-box install of either tool. The victim simply needs to run the assistant in its standard automated review mode and point it at a codebase containing the attacker's hidden instructions, something as ordinary as asking the AI to "scan this library for vulnerabilities." The researchers tested this on Linux systems using specific versions of both tools, Claude Code versions 2.1.116, 2.1.196, 2.1.198, and 2.1.199, and Codex version 0.142.4. The significance of this is that it undermines the idea that these AI agents can safely be used for defensive security work, since the attack surface is identical to the access required for their intended, legitimate purpose. The researchers emphasized this aspect of their finding as governments and companies push to deploy these tools more broadly for automated security review and patching, including initiatives like Anthropic's Project Glasswing, Palantir's MA-S2 standard, and OpenAI's Patch the Planet and Daybreak programs, some of which touch safety-critical infrastructure. This technique could likely transfer to other agentic AI coding platforms beyond Anthropic’s and OpenAI’s since the core issue is architectural, the researchers argued, giving an AI agent the autonomy to decide for itself what's safe to execute creates a new trust boundary that attackers can target directly, by convincing the AI rather than the human that malicious code is safe to run. While they noted that their report “is not within the scope of the security disclosure policies for either Anthropic or OpenAI,” Khlaaf and Milanov contacted both companies to inform them of their findings and offered support to verify the issues raised. Architectural Risk Undermine AI Agent Safety, Warns Expert Eljan Mahammadli, head of AI provenance at Polygraf AI, said the significance of the research lies in the underlying weakness it exposes, not the specific exploit used. “An AI coding agent has no reliable way to distinguish the text it reads from instructions it is supposed to follow,” he said, this is because everything in its context window is processed with the same authority. That lack of attribution means malicious instructions, once embedded, are treated as equally trustworthy, which is why similar attacks keep reappearing in different forms. He argued this is not something a model update can fix, since it reflects a deeper architectural issue. “The problem is a property of how these systems handle language and not a defect that can be trained away,” he said. From a provenance perspective, he described it as a failure of attribution, where the agent cannot determine where text comes from or whether it should be trusted. Nevertheless, Mahammadli pushed back on the idea suggested by the AI Now researchers that the findings undermine AI’s role in defensive security. He said the issue is specific to a common but flawed setup: agents that combine access to untrusted data, command execution and sensitive environments in a single process, with only a safety classifier as a guardrail. “When those powers sit together, a single injected instruction is enough to turn the agent against its operator,” he said, arguing that stronger runtime controls and separation of capabilities are key. He also highlighted that, counterintuitively, more advanced models sometimes detected inconsistencies in the exploit but executed it anyway. This challenges the assumption that stronger models are inherently safer. “A more capable and more compliant agent can simply be a more effective executor of whatever instruction reaches it,” he said, warning that deployment in critical systems is moving faster than solutions to this core trust problem. Image credits: Robert Way / gguy / Shutterstock.com
infosecurity-magazine.comJul 10, 2026extracted
Anthropic's Fable 5 and Mythos 5 Are Back with New Security Guardrails
Anthropic’s latest frontier large language models (LLMs), Claude Mythos 5 and Claude Fable 5, are available again – but with added security limitations. On June 30, just 19 days after the US government enacted export controls on both models which forced Anthropic to suspend their global distribution, the decision was lifted. The same day, the AI lab announced it was redeploying both models from July 1. However, they will now come with additional limitations aimed to address AI safety and security concerns raised by the US government. Fable 5 Equipped With New US-Approved Safeguards Fable 5, a general-access LLM powered by the same underlying frontier AI model as Mythos 5 – itself an upgrade from Claude Mythos Preview – is now available to users globally across all the Claude Platform, Claude.ai, Claude Code and Claude Cowork. For premium users who have subscribed to Pro, Max, Team and select Enterprise plans, the model will be included for up to 50% of weekly usage limits through July 7, after which it will be available via usage credits. Anthropic is also rolling out availability of the general-access model on AWS, Google Cloud and Microsoft Foundry. The AI company confirmed it had reviewed the Amazon report that prompted the export control directive. In the report, researchers had found a jailbreak, a method of prompting Fable 5 so that it identified software vulnerabilities and, in one case, provided an exploit – therefore bypassing the model’s built-in safeguards. While Anthropic said that the reported technique “did not expose any unique Mythos-level cyber capabilities,” the company is releasing a new version of Fable 5 equipped with “an improved safety classifier that targets and blocks the behavior described in the report.” A classifier is a small, automated AI systems that, during an interaction with an LLM, detects when the model is asked to perform a potentially harmful task or to produce potentially harmful outputs and then blocks it from responding to requests. According to Anthropic, the new classifier blocks the jailbreak identified by Amazon researchers “in over 99% of cases.” It may, “in a very small fraction of cases,” provide information after a potentially harmful user request but Anthropic claimed it wouldn’t be “detailed enough to help a cyber attacker.” “The model’s safeguards are not expected to block all low-risk routine cyber defense capabilities – just those that are potentially harmful,” said the company. When a request to Fable 5 is blocked, the users will be notified that it has been redirected to Opus 4.8. “The new classifier also comes at the cost of flagging benign requests more often during routine coding and debugging tasks,” Anthropic admitted. It said it would continue to refine the safeguards to better distinguish genuine misuse from legitimate requests and reduce false positives. Anthropic said researchers from the US Department of Commerce’s Center for AI Standards and Innovation (CAISI) have tested the new safeguards and described them as “extraordinarily strong.” Anthropic Teams Up with Government and Industry to Accelerate AI Security Before lifting export controls on Fable 5 and Mythos 5 on June 30, the US government approved Mythos 5 to be redeployed to a set of US organizations that operate and defend critical infrastructure. “We continue to coordinate with the government to expand access to the broader set of domestic and international partners in the Glasswing program,” Anthropic noted. The company also said it was collaborating with the US government to accelerate AI security, including via pre-deployment testing and evaluation. In the meantime, the AI lab has worked with Amazon, Microsoft, Google and other Glasswing partners to draft a consensus framework for assessing the severity of AI jailbreaks – including finding a standard definition of what constitutes a “universal jailbreak” – and how AI developers should respond to them. Finally, the AI lab has launched a new HackerOne program where security researchers can submit potential cyber jailbreaks they’ve discovered in Fable 5 for review. Image credits: wutianzeri / RixAiArt / Shutterstock.com
infosecurity-magazine.comJul 1, 2026extracted
Cisco Vulnerability Exploited Months Before Disclosure, Google Warns
A threat actor started exploiting a severe vulnerability in Cisco products at least two months before the flaw was disclosed, a new Google report warned. Tracked as CVE-2026-20245, this high-severity (CVSS 7.8) privilege escalation vulnerability stems from insufficient validation of user-supplied input in the command-line interface (CLI) of Cisco Catalyst SD-WAN Controller, formerly known as SD-WAN vSmart. It affects several versions of Cisco Catalyst SD-WAN Manager as well as related products like Cisco Catalyst SD-WAN Validator. Affected versions of these products are vulnerable regardless of the installation – on-premises, Cloud-Pro, Cloud (Cisco Managed) and Government (FedRAMP). Authenticated, local attackers can exploit it by uploading a crafted file to the affected system and can consequently execute arbitrary commands as root. The zero-day vulnerability was disclosed by Cisco on June 4 after it has observed “limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.” However, at the time of disclosure, no patch was available. The tech giant started releasing Catalyst SD-WAN Manager updates with the CVE-2026-20245 fix on June 10. Vulnerability Disclosure in June, Exploitation in March In a new report published on June 24, security researchers at Mandiant, part of Google Cloud, said they identified a threat actor targeting SD-WAN infrastructure at a service provider in early 2026. From late 2025 to January 2026, Mandiant observed multiple unauthorized peering connections to the victim’s SD-WAN Manager devices. The researchers noted that this malicious activity could be linked to the exploitation of CVE-2026-20127 or CVE-2026-20182 as the vulnerabilities were not disclosed, and patches were not available during this period. CVE-2026-20127 and CVE-2026-20182 are critical vulnerabilities recently disclosed by Cisco that affect the peering authentication mechanism for Cisco Catalyst SD-WAN controllers. Both could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges. The Mandiant researchers noticed further unauthorized peering connections on a device running a software version unaffected by CVE-2026-20127 in March. They checked with Cisco, which confirmed that these connections did not leverage CVE-2026-20182 either and could instead be using stolen certificate material from a previous compromise of the same device. They later found that a threat actor established initial access via unauthorized peering connections to facilitate Secure Shell (SSH) access and then used that access to manipulate default account passwords to evade detection. They also identified that a threat actor exploited what is now known as CVE-2026-20245 in Cisco Catalyst SD-WAN Manager to gain root-level access via a malicious CSV upload. This latter actor then deleted malicious files, reverted configuration changes and executed a validation script to ensure indicators have been purged. “It is unclear if the same threat actor was responsible for the late 2025 to January 2026 and March 2026 rogue peering activity,” Mandiant said. New Living-Off-the-Edge Paradigm for Threat Actors Nevertheless, Google highlighted that this campaign “underscores the living-off-the-edge paradigm, where threat actors prioritize the compromise of network appliances to bypass traditional security perimeters.” Mandiant further emphasized that orchestrators managing edge devices and software-defined networking appliances “often lack the telemetry required for deep forensic analysis, and their role as a central control plane provides a stealthy platform for persistent, wide-scale access to internal enterprise traffic.” “For state-sponsored actors, the ability to exploit zero-day vulnerabilities in these platforms remains a premier vector for long-term strategic intelligence collection,” Google concluded. Additionally, Matei Badanoiu, lead security researcher at Pentest-Tools.com, highlighted that these findings reinforce another paradigm: threat actors often exploit vulnerabilities long before they are known and fixed. "In the case of Cisco and the above CVE, the window has been open for at least two months before the patch and advisory. Whoever used this vulnerability had working knowledge of it in this period while defenders had none,” Badanoiu said. Image credits: PJ McDonnell / Bangla press / Shutterstock.com
infosecurity-magazine.comJun 25, 2026extracted
Europol-Led Operation Endgame Takes Down StealC and Amadey Infostealers
The infrastructure of two infamous information stealer malware strains (infostealers), StealC and Amadey, has been disrupted by an international law enforcement takedown. The action against formed the latest part of Operation Endgame, an ongoing global police investigation to combat ransomware and cybercrime worldwide. It specifically involved Germany’s Federal Criminal Police Office and was coordinated by Europol, which provided intelligence and technical analysis support via its European Cybercrime Centre (EC3) and had strategic oversight through the Joint Cybercrime Action Taskforce (J-CAT), with additional legal support by Eurojust. It also involved several industry partners, including BitSight, ESET, IBM X-Force, Lumen, Microsoft, Mitsui Bussan Secure Directions and Proofpoint. This new episode comes just a few days after the Dutch police announced the takedown of the SocGholish botnet – also as part of Operation Endgame – which was widely used by ransomware groups such as Evil Corp. Amadey and StealC Explained Operation Endgame seized around 50 domains and nearly 200 active IP-based command-and-control (C2) servers associated with Amadey and StealC. Both are infostealers with a dropper function that have been widely used by cybercriminals. StealC was primarily designed to extract sensitive information such as passwords, stored access data and digital identities from compromised computers and to make them available for subsequent illicit use, especially data trading and fraudulent use. While Amadey had similar features, it primarily served as the first link in a larger attack chain. It was equipped with the capability of introducing additional malware into compromised systems. “Together, they form a critical link in the cybercrime supply chain,” noted Europol. According to insight collected by Microsoft, in the first two weeks of May 2026 Amadey and StealC were linked to over 140 000 infected computers worldwide. Breaking the Infostealer Supply Chain With AI In a blog explaining the takedown, Microsoft said it disrupted the Amadey and StealC infostealers by executing a simultaneous, court-authorized takedown. During this operation, the tech giant’s Digital Crimes Unit (DCU) disrupted more than 200 command-and-control (C2) servers. The team also identified over 18,000 victim computers, severed criminal control of those devices and began working with telecommunications providers to help protect affected customers globally. To achieve this, Microsoft utilized AI, including Copilot, to analyze the malware. Instead of manually combing through complex code, investigators asked questions in plain English. According to the blog, this approach helped "surface key details, uncover hidden data, and test findings in a fraction of the time". The AI turned tasks that normally took hours or days into minutes, enabling investigators to quickly realize that although Amadey and StealC were developed by separate cybercriminals, they relied on the same infrastructure. These AI-driven insights ultimately "allowed the legal team to treat both malware families as part of a single conspiracy". For this takedown, Microsoft explained that it focused on "targeting the cyber-attack supply chain, not just individual services." Historically, Microsoft has used civil legal actions and the US Racketeer Influenced and Corrupt Organizations Act (RICO) to target organized crime, but this action was unique because they combined "AI analysis with an expanded use of that law." Instead of tackling each malware tool separately, they used RICO to "charge multiple complicit enablers involved across the operation" under one single conspiracy. Steven Masada, assistant general counsel at Microsoft's DCU, explained, "When multiple parts of an operation are disrupted together, attacks are harder to launch, scale and recover from". He further noted that "it's no longer enough to go after threats one by one" and concluded that defenders "need to interrupt how the attacks are put together". In separate blogs, ESET, BitSight and Mitsui Bussan Secure Directions said they contributed to this effort by providing technical analyses, statistical information, known C2 servers, encryption keys, campaign, build identifiers and other threat intelligence information. Proofpoint and IBM X-Force threat researchers also developed a StealC emulator to identify and track operations, infrastructure and payloads. €41m of Criminal Crypto Assets Frozen In a public statement on June 24, Europol said the main goal of the takedown of SocGholish, StealC and Amadey was “to disrupt the ‘assembly lines’ cybercriminals use to launch ransomware, financial fraud and attacks on critical infrastructure.” The Hague-based European law enforcement agency said beyond the takedowns, this new chapter of Operation Endgame resulted in €41m ($46.5m) of crypto assets of criminal origin identified and frozen and 27 million stolen login credentials recovered. Officers and their private sector partners also took down 326 servers and seized 142 domains, “severely crippling the malware’s distribution network,” Europol noted. Aside from Germany and the Netherlands, Operation Endgame has involved many other countries, such as Canada, Denmark, the UK and the US. Additional partners of the wider operation also include the Shadowserver Foundation, Registrar of Last Resort (RoLR), Infoblox, NorthWave, Orange Cyberdefense, Bitdefender, Have I Been Pwned and Spamhaus. Image credits: PixelBiss / Menno van der Haven / Shutterstock.com
infosecurity-magazine.comJun 24, 2026extracted
AWS Unveils 'Continuum,' an AI-Powered Vulnerability Management Platform
Security teams using Amazon Web Services (AWS) infrastructure now have access to a new Amazon-made platform to manage the whole lifecycle of code vulnerabilities from discovery to remediation. The Seattle-based tech giant launched AWS Continuum among a wave of announcements at AWS Summit New York on June 17, including new AI models and AWS Context, a knowledge graph that gives agents access to the context they need to do their best work. The AWS Continuum platform, available in gated preview, has access to an organization’s full environment, including structured data already living in AWS and unstructured data, such as documents, communications and business priorities. Continuum offers four capabilities: Code vulnerability discovery: Continuum starts by ingesting the existing backlog of vulnerabilities and performing its own vulnerability scan of the environment Code vulnerability prioritization: Continuum uses context to evaluate, enrich and prioritize every finding and provides an evidence-backed list of priorities Code vulnerability validation: Continuum validates findings to surface false positives, provides additional context relevant to the users and constructs working exploit examples in a sandboxed environment Code vulnerability mitigation and remediation: Continuum assesses existing defenses around a validated issue, including blocking and compensating controls along with detection mechanisms. It then draws on its understanding of the codebase, context and findings to recommend mitigation or remediation of the vulnerability with a network change, policy change or code patch AWS noted that Continuum always starts “in learn mode” with a human in the loop. “Every recommendation includes the reasoning behind it. As you gain confidence, you can graduate Continuum to enforce mode, enabling remediation that can be increasingly automated based on categories and risk profiles you define,” the company said in a public statement. The Continuum platform also includes AWS Security Agent, an agent powered by frontier AI models that helps software developers and security engineers do penetration testing, code scanning and threat modelling, with output results provided in the Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege (STRIDE) format. These features will now be called Continuum pen testing, Continuum code scanning and Continuum threat modelling. AWS explained the launch of Continuum was motivated by the “urgent need for a shift” in security workflows. “The operating model that served us for the past decade (collect telemetry, store it, query it, build dashboards to watch it) is no longer keeping pace. We need to shift to the new world: telemetry, context, reasoning and actions,” the company warned. “The latest cybersecurity frontier models further made this shift urgent. Models like Claude Mythos can now find software vulnerabilities and reason through complex attack paths at machine-speed, leading to an exponentially increasing backlog of vulnerabilities.” AWS confirmed customers across financial services, automotive and technology were already using the Continuum platform. Image credits: aileenchik / Shutterstock Gen AI / Shutterstock.com
infosecurity-magazine.comJun 19, 2026extracted
Cybersecurity Experts Urge US to Lift Ban on Anthropic's Frontier AI Models
Over 50 cybersecurity professionals have publicly requested the US government lift the ban on access to Mythos 5 and Fable 5, the latest frontier large language models (LLMs) released by AI company Anthropic. On June 12, Anthropic announced that the US government had issued an export control directive to suspend all access to Fable 5 and Mythos 5, released just a few days earlier, by any foreign national. This decision prompted the AI company to suspend access to both models for all customers to ensure compliance with the directive. Fable 5 was presented by Anthropic as a general-access LLM powered by the same underlying frontier AI model as Mythos 5 – an upgrade from Claude Mythos Preview – but with additional guardrails, especially in areas like cybersecurity where the company said it “could be misused to cause serious damage.” The US government invoked “national security concerns” to explain its directive, which Anthropic believes originated from research that allegedly found a method of bypassing Fable 5’s guardrails. “We reviewed a demonstration of this specific technique being used to identify a small number of previously known, minor vulnerabilities. These vulnerabilities all appear relatively simple and we have found that other publicly-available models are able to discover them as well without requiring a bypass,” stated Anthropic. The company denied the existence of a “universal jailbreak” for Fable 5. Cybersecurity Community Criticizes Fable, Mythos Ban Two days later, a group of 54 CISOs, cybersecurity practitioners and vendors signed an open letter addressed to Howard Lutnick, the US Secretary of Commerce, and Sean Cairncross, the US National Cyber Director. The group asked for the export control directives on Fable and Mythos to be lifted. They also called for the US government to “commit to an open, scientific and transparent process of handling AI risk assessments in the future.” While the signatories acknowledged that Anthropic’s latest models are “quite good at finding flaws and weaponizing exploits,” they argued they are not the only tools that can be used for this purpose. The ability to identify insecure code is a fundamental feature of any secure coding assistant and equivalent capabilities already exist across other models including OpenAI's GPT-5.5, Anthropic's Claude Opus and Sonnet, and Chinese models such as Kimi 2.7, the signatories noted. Additionally, they acknowledged Anthropic’s contribution to prevent Fable from “cyber offensive uses” and said the AI company is now addressing the research that likely prompted the US government’s decision. “To pull the best capabilities away from defenders without a good reason when our adversaries are rapidly advancing is dangerous,” they warned. The open letter also said the US government action has created market uncertainty and risked America’s AI leadership “without any real risk to justify it.” Signatories included Alex Stamos, chief product officer at Corridor and former chief security officer at Facebook and Yahoo, Joe Levy, CEO of Sophos, and Sandra McLeod, CISO at Zoom Communications. Their stance has been shared by other cybersecurity experts. Despite not having signed the open letter, William Wright, CEO of Closed Door Security, said that, while the US reaction “suggests that the worries around jailbreaking these models are real,” banning access to the model is the wrong approach. “Cutting off access to the model so abruptly will cause huge logistical problem, both within Anthropic and within any critical industry partners given access to the model. Rather than foster resilience, this move creates chaos,” he explained. He called the US government to work “transparently and with clear guiding principles” with AI and cybersecurity experts. Image credits: Nwz / jackpress / Shutterstock.com
infosecurity-magazine.comJun 15, 2026extracted
Interpol Dismantles SniperDz Phishing-as-a-Service Platform
Cybersecurity firm Group-IB has revealed that a recent Interpol-led cybercrime law enforcement operation has led to the takedown of an established phishing-as-a-service (PhaaS) platform and the arrest of its main operator developer. The crackdown, dubbed Operation Ramz, ran from October 2025 to February 2026 across 13 countries in the Middle East and North Africa (MENA) region. The results, announced by Interpol at the end of May, included 201 arrests, 53 servers seized and 382 suspects and 3867 victims identified. A further set of almost 8000 pieces of data and intelligence was also disseminated among participating countries to initiate and support future investigations. On June 11, Group-IB, one Interpol’s main partners for this effort, revealed that the operation led to the takedown of SniperDz and the arrest of its primary developer in Algeria. SniperDz: A Global Phishing-as-a-Service Platform SniperDz is a PhaaS platform that has been running since at least 2015. Today, the cybercrime platform has a global reach and has sophisticated offerings, including ready-made phishing kits, infrastructure hosting and operational support to cybercriminals. In 2024, Palo Alto Networks’ Unit 42 said it had discovered over 140,000 phishing pages associated with SniperDz between 2023 and 2024 alone. The researchers noted that phishers can either host these phishing pages on SniperDz-owned infrastructure or download SniperDz phishing templates to host on their own servers. “Surprisingly, SniperDz PhaaS offers these services free of charge to phishers – perhaps because SniperDz also collects victim credentials stolen by phishers who use the platform to compensate for the cost of service,” the Unit 42 report said. Over the past nine years, Group-IB identified more than 20,000 unique domains associated with SniperDz that impersonated at least 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix and Steam. Group-IB’s investigations team identified 80 phishing templates deployed in five languages including Arabic, English, French, Spanish and Hebrew, targeting users of consumer, technology and payment platforms across multiple geographies. Typically, victims were lured to convincing imitation websites designed to harvest credentials, personal information and other sensitive data. Beyond traditional credential theft, the SniperDz platform also leveraged social engineering techniques that exploited the popularity and credibility of public figures across MENA. “Threat actors created fake social media accounts impersonating well-known political personalities and used them to promote phishing links disguised as promotional offers or free internet access,” Group-IB explained. SniperDz Showed Significant OpSec Failures The investigation revealed a significant operational security (OpSec) failure by the suspect, who published video tutorials to recruit and train affiliates. These inadvertently exposed administrative information and account credentials. These, combined with years of social media activity documenting the platform's evolution, affiliate recruitment efforts and the release of new phishing templates helped Group-IB investigators trace the suspect’s digital footprint and identify him. “A Telegram channel used to coordinate operations, which had more than 7,300 subscribers when Group-IB shared its findings with Interpol and a Facebook account followed by more than 19,000 users, provided additional evidence linking the suspect to the platform's activities between 2015 and 2025,” Group-IB added. Once the cybersecurity company handed over the collected information to Interpol, the law enforcement agency coordinated with the Algerian National Police to disrupt the SniperDz infrastructure and arrest the individual suspected to run the operation. According to Dmitry Volkov, CEO of Group-IB, this case was “a textbook example of why adversary-centric intelligence matters." "Disrupting cybercrime requires more than taking down phishing pages. It requires understanding the people, infrastructure and criminal ecosystems behind them,” he said. “By combining threat intelligence, attribution, and close collaboration with law enforcement, we were able to help identify the individual responsible for nearly a decade of phishing activity and contribute to bringing that operation to an end." Image credits: Dr David Sing / Tang Yan Song / Shutterstock.com
infosecurity-magazine.comJun 11, 2026extracted
Google Releases Patch for Chrome Vulnerability Exploited in the Wild
Google has released an emergency update to patch 74 Chrome vulnerabilities, including a high-severity flaw that has been exploited in the wild. This is the fifth Chrome zero-day vulnerability in 2026 that has been exploited before a patch has been made available. The security bulletin, published on June 8, include fixes for 17 critical vulnerabilities, 55 high-severity ones and tow medium-severity ones. The security fixes will roll out “over the coming days/weeks” for Chrome users on Windows, Mac and Linux. $55,000 For Reporting CVE-2026-11645 to Google Among these, CVE-2026-11645 is an out of bounds read and write vulnerability affecting V8 in Google Chrome versions prior to 149.0.7827.103. It was reported to Google on April 27 by a security researcher identified by Google as ‘303f06e3,’ who has previously reported Chrome vulnerabilities. They were awarded $55,000 for disclosing it to the Chrome security team. When exploited, CVE-2026-11645 allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. It has been allocated a high-severity rating of 8.8. Google confirmed it is aware of this flaw being exploited in the wild. However, it did not provide any additional details about the exploitation evidence. “Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” the company said in the advisory. “We will also retain restrictions if the bug exists in a third-party library that other projects similarly depend on, but haven’t yet fixed.” Image credits: Mijansk786 / Wachiwit / Shutterstock.com
infosecurity-magazine.comJun 9, 2026extracted
WhatsApp Discovers NSO Group-Linked Spearphishing Attempts
WhatsApp has asked a US court to hold a blacklisted spyware firm in contempt, after claiming it has violated a permanent injunction banning it from targeting users. The messaging giant said on June 8 that it “successfully disrupted” social engineering attempts linked to Israeli firm NSO Group after investigating user complaints. “They tried to trick people into clicking on malicious links to drive them to external websites outside of WhatsApp, similar to previously reported one-click phishing campaigns linked to NSO,” it said. “We also caught them creating test accounts and groups on WhatsApp, which we took down.” Last year, the commercial spyware firm was ordered to pay damages of over $167m after hacking into about 1400 WhatsApp users' devices. That ruling was the culmination of a six-year court case which began after Meta engineers detected attempts by NSO to use its spyware tool, Pegasus, to target WhatsApp users including human rights activists, journalists and diplomats. The zero-click spyware is often used by repressive regimes to monitor opposition figures and activists. There have also been reports that the malware was used to hack Amazon boss Jeff Bezos’s phone. In 2021, NSO Group was added to the US Commerce Department’s Entity List to prevent it from buying components from American companies. WhatsApp said the firm should be held in contempt of court to send a clear message. “When a malicious company on the US government’s Entity List continues to defy US courts, existing restrictions must remain firmly in place,” it said. “Easing them would undermine US national security and put American companies and billions of people worldwide who depend on secure communications at risk.” Fighting Back Against Spyware NSO Group remains defiant and is appealing its permanent injunction. Last month, 12 civil rights organizations filed amicus briefs to fight the appeal. In the meantime, WhatsApp said it had made a “significant contribution” to the Spyware Accountability Initiative – a fund dedicated to helping civil society organizations fight back against the threat of spyware. WhatsApp published three domains used in the alleged NSO Group phishing campaign, so other users can check if they were also targeted. It claimed that attacks might come via email, text message, WhatsApp message “or something else.” Image credit: Samuel Boivin / Shutterstock.com
infosecurity-magazine.comJun 9, 2026extracted
Meta AI Bug Exposes Over 20,000 Instagram Accounts
Unauthorized third parties gained access to thousands of Instagram accounts by exploiting a vulnerability in an AI support tool, Meta has revealed. Meta said it discovered the problem with the AI-powered High Touch Support (HTS) tool on May 31. The tool is meant to help users locked out of their Instagram accounts regain access by sending them a new password link. “The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account,” Meta explained in a letter to the Main attorney general’s office (OAG). “As a result, when an individual provided an email address not previously associated with the account, the system incorrectly sent a password reset link to that unassociated email rather than rejecting the request.” As a result, the threat actors were able to receive password reset links for accounts they didn’t own, and log-in if the rightful account holder didn’t have two-factor authentication (2FA) enabled. According to the regulatory filing, 20,225 Instagram uses had their accounts compromised in this manner. Among the data exposed by the security snafu were: Contact information (email address and/or phone number) Date of birth Social media posts and content (photos, videos, stories) Direct messages and communications Account activity and interaction history Profile information (biography, profile photo) Connected accounts and linked services Clearing up the Mess Meta said it took immediate steps to address the incident, including disabling the AI-assisted HTS support tool and vulnerable code path, and invalidating all existing password reset links. The social media giant also enrolled affected accounts into a “mandatory security checkpoint” preventing authentication before account access. It told impacted users to reset their passwords and reauthenticate through secure, verified channels. “Prior to re-launching the tool, Meta will fix the authentication check in the Instagram recovery entry point to ensure proper verification of email addresses against existing account information before any password reset is initiated,” the firm added. “Additionally, Meta is conducting a comprehensive review of similar account recovery flows across Meta’s platforms to identify and remediate any potential issues.” The firm is writing to individuals potentially impacted by the incident, urging them to review account security settings and enable two-factor authentication. Image credit: Pavel105 / Shutterstock.com
infosecurity-magazine.comJun 8, 2026extracted
Anthropic Expands Mythos Access to 150 More Organizations
Access to Anthropic's most capable AI model has been extended to an additional 150 organizations, widening a program that uses frontier AI to find vulnerabilities in the world's most critical software. Anthropic announced the expansion of Project Glasswing on June 2, building on an initial group of roughly 50 partners that gained access to Claude Mythos Preview in April. That cohort has since used the model to reportedly uncover more than 10,000 high- or critical-severity flaws, the AI company said. Why the Scope of Glasswing has Widened The new partners sit in more than 15 countries and cover sectors thinly represented at launch, including power, water, healthcare, communications and hardware, with many being software vendors whose code is embedded in other organizations. Anthropic said it chose them because a cyber-attack on any of their codebases could be catastrophic, estimating that for most a major breach could affect more than 100 million people. The firm framed the move as preparation for a shift it has repeatedly flagged. Within six to 12 months, it expects rival developers to field models with comparable cyber capabilities, potentially released without safeguards against misuse. General access to Mythos-class models remains off the table, Anthropic acknowledged that the safeguards needed to release one safely do not yet exist anywhere. Discovery is Outpacing the Fix The expansion sharpens a problem the industry is already wrestling with: finding flaws has become far easier than fixing them. Anthropic itself has said the bottleneck now lies in verifying, disclosing and patching the vulnerabilities these models surface. Jeff Williams, founder of OWASP and CTO of Contrast Security, said the announcement piles fresh pressure on teams that were already overwhelmed. "AI is turning vulnerability discovery into an industrial-scale activity, but most organizations still remediate at human speed," he said. Finding more flaws does not make software safer, Williams argued, unless organizations can validate, prioritize, fix and deploy at the same pace. The real opportunity, he suggested, is to point AI at threat modeling and secure design rather than yesterday's scan-and-patch cycle. Gunter Ollmann, CTO of Cobalt, said the findings show automated tools such as SAST and DAST can only reach so far, and that pairing AI analysis with skilled human direction surfaces flaws conventional approaches miss. "The organizations that benefit most from these advances will be the ones that can rapidly validate, prioritize and remediate the issues being discovered before attackers find them first," Ollmann concluded. Image credits: JRdes / Samuel Boivin / Shutterstock.com
infosecurity-magazine.comJun 3, 2026extracted
Infosecurity Europe: Bayer Reinvents Security Awareness Training to Counter AI Threats
AI is shaping Bayer’s approach to security as the life sciences firm aims to become one of Europe’s leading agentic deployment organizations in the pharmaceutical industry. At Infosecurity Europe 2026, Kevin Jones, Bayer’s CISO, told attendees that the company has fundamentally changed how its workforce is prepared for AI-driven threats, moving away from checklist-style technical guidance toward psychology-first security awareness. "We scrapped everything to do with technical in our awareness training," Jones said, explaining that conventional advice, such as looking for spelling mistakes, suspicious URLs or odd attachments no longer works when attackers "have learnt to spell, in five different languages, all in real time, and it’s all generated with AI at scale." He argued that the human element must be reframed: that employees are taught to recognize psychological manipulation, ask whether someone is applying undue pressure or posing as an authority and to "stop and pause and think" before breaking process. Jones described the training as mandatory and behavior-focused. “Towards the end of last year, our CFO in the Europe, Middle East and Africa region received a very accurate sounding phone call from our global CFO, who asked them to quickly transfer them money over the weekend,” he explained. He said that because staff followed the new guidance, "everyone reported it" and there was zero loss. That story, Jones said, proved that reframing security awareness around adversary psychology can turn employees into an effective early defense against increasingly realistic social engineering. AI Access Tied to Training Completion Jones also explained that AI competence within Bayer’s staff is now tied to controlled access: small, role-based training modules are prerequisites for accessing internal AI platforms like myGenAssist, Bayer’s homemade response to commercial generative AI platforms like OpenAI’s ChatGPT, and additional ones for building agents within the platform. In practice, the life sciences company has created a tiered access model that gates who can develop and run agentic workflows. Jones said this system entices staff members to complete training and allows the security team to “track our data.” Towards a Human-On-the-Loop Approach for the SOC This AI-savvy approach is also applied to Bayer’s security operations. Jones said he would like security operations center (SOC) analysts to evolve from manual triage to supervised automation. “We are assuming they will not be able to work at the speed of agents,” he said. Jones expects SOC teams to move "from human in the loop to human on the loop within two to three years" as agent-assisted processes scale and he emphasized new operational playbooks and training to support that shift. “It means that analysts need to start thinking about using and managing AI agents themselves, not only AI co-pilots or assistants anymore,” he said. “I would encourage you to think of SOCs less as security operations centers and more as cyber resilience centers, because in the future, they will need to be able to change things in your environments, in a controlled way, to keep it resilient,” he added. AI Use Clauses in Third-Party Contracts Jones made clear that workforce requirements are paired with stricter third-party obligations, with suppliers also required to complete AI training before receiving tiered access to myGenAssist. Additionally, Bayer has established an internal AI Governance Council that defines every strategic move for using and deploying AI – standards that suppliers that integrate with Bayer’s AI ecosystem are expected to meet. Procurement contracts have also been updated with AI-specific security annexes that require suppliers to disclose how they use Bayer data, which AI tools they employ, and to report incidents. These contract changes are being rolled out to major partners now and will be deployed across the supplier base over the next 18 months. "Suppliers must inform us how they're using our data," Jones said, underscoring that transparency and contractual controls are non-negotiable. Image credits: brunocoelho / Taljat David / Shutterstock.com
infosecurity-magazine.comJun 2, 2026extracted
New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
A previously unreported threat actor has been observed targeting cryptocurrency firms with custom macOS malware, fake recruiter approaches and the hijacking of internal development pipelines. Wiz has attributed the activity to a financially motivated cluster, now tracked as Jinx-0164, according to new analysis from the company. Active since at least mid-2025 and focused almost entirely on macOS, the actor shares techniques with North Korean groups such as UNC1069, also known as Sleet. However, it implements these techniques differently and shows no infrastructure overlap with tracked actors. Wiz stopped short of linking it to any state-sponsored threat actor. Fake Meetings and a Cloned Audio Driver The intrusions typically begin on LinkedIn, where the attacker poses as a business contact or recruiter using a credible profile. The target is invited to a virtual meeting on a lookalike domain impersonating a service such as Microsoft Teams. Joining the call triggers a fake technical fault and a prompt to run a "fix," which installs the malware. The payload, a Python-based stealer and remote access tool named Audiofix, masquerades as a system audio driver and runs on both Intel and Apple Silicon machines. Audiofix harvests Keychain contents, browser credentials, SSH keys, cloud provider keys and details from 51 cryptocurrency wallet extensions. It also hijacks Discord, Slack and Telegram sessions and monitors the clipboard for copied wallet addresses. From Laptops to Code Pipelines Rather than pivoting into cloud accounts, Jinx-0164 turned harvested GitHub tokens against the victim's development infrastructure, using the open-source tool nord-stream to pull secrets from CI/CD pipelines. It then injected Audiofix into internal repositories, disguising commits under other developers' names and pushing them to main or existing branches. When colleagues built from the poisoned repositories, their machines were infected too, turning the build process into a propagation channel. Wiz said GitHub's Vigilant Mode, which flags unverified commits, helped expose the impersonation and halt the spread. The group's reach has extended beyond direct intrusions. On April 7, it trojanized version 4.9.1 of the npm package @velora-dex/sdk, a widely used decentralized exchange toolkit, appending code that fetched a second macOS backdoor called MINIRAT. The recruitment-themed lure is itself well established among crypto-focused attackers, echoing earlier campaigns by groups such as Slow Pisces. Wiz urged defenders to watch for the published indicators of compromise, unexpected use of VPN services including Mullvad, Astrill and ExpressVPN, and secret exfiltration from CI/CD workflows. It also advised enabling logs that are off by default, such as GitHub IP logging, and treating unverified commits as suspect. Image credit: alexgo.photography / Shutterstock.com
infosecurity-magazine.comMay 28, 2026extracted
Fake Streams, Counterfeit Merch and Other Scams: How Fraudsters Target F1 Fans
Cybercriminals and fraudsters have dedicated entire ecosystems to scamming and stealing from Formula 1 fans, a new report has warned. According to the Bitdefender Cybersecurity Grand Prix Fan Threat Index, the growing global digital ecosystem around motorsport makes it an ideal target for scammers. Fans and Formula 1 teams alike now find themselves in attackers’ crosshairs. Scams targeting F1 fans range from being sold counterfeit merchandise and fake grand prix tickets, to illegal streaming services and social media scams. All designed to steal personal information, credit card details, generate illicit revenue and distribute malware. Motorsport fans are also being duped into having their devices unwittingly roped into being part of a notorious botnet of millions of devices used to carry out DDoS attacks, according to Bitdefender. “Why motorsports? Because things are moving fast and when things are moving fast, people make mistakes,” said Bogdan Botezatu, senior director of threat research at Bitdefender. The new Bitdefender report is the culmination of a yearlong project analyzing the cybercriminal landscape around Formula 1 weekends. “We know how cybercriminals operate before, during the races and after them,” said Botezatu during the launch of the report at Maranello, Italy, the headquarters of the Scuderia Ferrari HP Formula 1 team, of which Bitdefender is the official cybersecurity. Fake F1 Streaming Apps Like many sports, F1 races are mostly locked behind TV channels or online services which require paid subscriptions. One of the most common scams deployed by cybercriminals during race weekends is tricking people into downloading applications which they are told will allow them to watch the races for free. Advertised on social media, Discord and Telegram, these applications require users to manually install APK files outside official app stores. In some instances, the report explained, scammers use the Clickfix social engineering technique to bypass any protections users may have on their device. Those who use illegitimate streaming services are often unknowingly providing scammers with various monetization streams. This can range from excessive advertising, forced redirects and aggressive pop-ups, all the way up to installing infostealer malware on the victim’s machine with the aim of stealing their usernames, passwords and banking information. And to add insult to injury, the victim has likely been tricked into downloading a falsely advertised app which doesn’t even show the race in the first place. An alternative option some fans have turned towards to watch F1 broadcasts are streaming boxes. With cost in mind, many users have purchased cheap, third-party boxes. While they may save the user money, they can come with unexpected cybersecurity risks like malware pre-installed on the device. Formula 1 Fans Targeted by Counterfeit Merchandise Many Formula 1 fans are passionate about a particular team, especially the more high-profile entrants, such as Mercedes, McLaren, Ferrari or Red Bull. However, official merchandise isn’t cheap, meaning many fans will actively be on the lookout for discounts and deals. According to Bitdefender, fake motorsport shops aggressively advertise on social media, promoting heavily discounted merchandise through adverts on social media. A common scam sees fraudsters post adverts which claim to offer merchandise at 80% discounts. It’s a pattern which has been used to scam fans of other major sporting events like the World Cup or the Olympics. In some cases, the buyer will receive a shoddy discount bootleg of real merchandise. In others, the fake online store serves as a phishing site and is used to steal personal information and banking information. In both cases, this scam infrastructure is set up by threat actors who are skilled at cloning websites and exploiting social media platforms to promote them. To avoid falling victim to cybercrime and scams around Formula 1, sports and other major events, Bitdefender has urged users to be wary of products and services offered which seem to be good to be true. Anti-phishing or anti-virus applications can also help users stay safe. Image credit: cristiano barni / Shutterstock.com
infosecurity-magazine.comMay 25, 2026extracted
Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning
Security researchers at EclecticIQ have uncovered a new malicious campaign in which cyber threat actors created fake sites posing as Google Gemini’s coding tool and Anthropic’s Claude Code to deliver information stealing malware. The initial warning came from an independent security research, known as @g0njxa on social media. On April 21, they flagged on X an impersonation campaign exploiting Gemini command line interface (CLI), a feature that lets developers interact with Gemini AI models directly from their terminal. EclecticIQ researchers investigated the campaign based on these findings. They found that the threat actor started deploying malicious domains in early March 2026. They also assessed that the campaign is likely geographically tailored to target users in the US and the UK, as evidenced by the selection of .co.uk, .us.com and .us.org top-level domains in some of the attacker-controlled domains. Infostealer Capabilities To ensure these domains would be attractive to their targets, SEO poisoning methods were used to surface fake domains above legitimate results, directing victims to attacker-controlled infrastructure that mimics genuine AI agent installation pages. The domains lead to an infostealer that targets Windows endpoints and executes entirely in memory through PowerShell, harvesting credentials and sensitive data from a wide range of applications before exfiltrating the results in encrypted form to a command-and-control (C2) server. “The stealer's collection scope reveals a deliberate focus on enterprise users and developer workstations,” the EclecticIQ researchers noted in a May 21 report. It targets both Chromium-family browsers, like Chrome, Edge and Brave, as well as Firefox, to extract login credentials, session cookies, autofill data and form history. Beyond browsers, the script directly targets collaboration and communication platforms that are standard in corporate environments. These include: Slack: local state key extraction and network cookies Microsoft Teams: EBWebView cache cookies under LocalAppData, with DPAPI-protected local state decryption Discord: local storage LevelDB files and local state Mattermost: session cookies and local state Zoom: DPAPI-protected win_osencrypt_key extracted from Zoom.us.ini Telegram Desktop: tdata session directory LiveChat, Notion, Zoho Mail Desktop: session cookies and partitioned storage data EclicticIQ noted that a session cookie or a local state key from any of these platforms grants authenticated access to the victim's workspace, including internal channels, shared files, client communications and connected integrations. The infostealers also collects data from remote access tools, OpenVPN configuration files, cryptocurrency wallets (e.g. Brave Wallet preferences and Spectre wallet data), cloud storage (e.g. Proton Drive, iCloud Drive, Google Drive, MEGA, OneDrive) and user files and system metadata. Finally, it allows the attacker to perform arbitrary remote code execution tasks on the victim’s device. Financially motivated cybercriminals typically leverage such capabilities to transition into hands-on-keyboard intrusions against selected victims and execute interactive code within the compromised environment. Gemini CLI Attack Chain Targeted victims who think they are visiting Gemini CLI are instead directed to fake installation page geminicli[.]co[.]com, which displays what appears to be a legitimate installation instruction. The page prompts the user to copy and paste a PowerShell command into their terminal. When executed, the command reaches out to gemini-setup[.]com to download the infostealer downloader payload. Once downloading is finished, the infostealer establishes a connection to C2 server hosted at events[.]msft23[.]com, an infrastructure used to receive exfiltrated data from compromised hosts. Claude Code Attack Chain On March 30, EclicticIQ observed that someone registered two additional domains impersonating Claude Code, claudecode[.]co[.]com and claude-setup[.]com. In a similar pattern as with the Gemini CLI impersonation, the malicious domain claudecode[.]co[.]com hosts a cloned installation page visually consistent with Anthropic's official documentation and presents the user with a PowerShell command to ‘install’ the tool, while claude-setup[.]com hosts the final payload that was downloaded. After the execution, the infostealer malware sends exfiltrated data to events[.]ms709[.]com, which serves as the C2 server for the Claude Code impersonation campaign. The similarities between both attack chains strongly suggest a single threat actor is behind both campaigns. Image credits: Stock all / aileenchik / Shutterstock.com
infosecurity-magazine.comMay 22, 2026extracted
Apple Blocked $2.2bn in App Store Fraud in the Last Year
Apple blocked App Store users from losing over $2.2bn in fraudulent transactions during the last year and prevented over a billion accounts from being created to commit fraud. The total of fraudulent App Store transactions Apple has blocked over the last six years now stands at more than $11.2bn. The Apple App Store contains over 680,000 apps which are used to sell goods and services. As a widely used ecosystem which people use to make payments, cybercriminals and fraudsters will naturally attempt to target users. Apple said that by combining human review and machine learning, it has built AI models to accelerate fraud detection and quickly evaluate new deceptive tactics used by frausters. “As the digital landscape expands, malicious actors continue to evolve their methods, often using deceptive tactics to target consumers and legitimate businesses,” Apple said in the blog post, published on May 20. “To outpace these challenges, Apple continuously improves its multilayered defenses, leveraging a combination of expert human review and advanced machine learning technologies to detect and stop malicious activity.” Apple continued to face what it described as “large-scale attempts to create fraudulent accounts”. The last year saw Apple systems block 1.1 billion fraudulent customer account creations, preventing threat actors from beginning the process of targeting users. Apple also deactivated an additional 40.4 million user accounts for fraud and abuse. This action wasn’t limited to user accounts. Apple said that during 2025, it terminated 193,000 developer accounts over fraud concerns. Outside of the Apple App Store, the company also took action to block 28,000 illegitimate apps on pirate storefronts. Many of these apps were clones of real apps, designed to deliver malware. “By restricting these storefronts and illicit distribution channels, Apple also protects developers from having their apps cloned, altered, or weaponized for spreading malicious software,” Apple said. Apple also acted to prevent 5.4 million stolen credit cards from being used to make fraudulent purchases. Nearly two million user accounts suspected of being involved in fraud were banned from the ecosystem. Image credit: Tada Images / Shutterstock.com
infosecurity-magazine.comMay 22, 2026extracted
Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool
Microsoft has cracked down on Fox Tempest, a cyber threat actor that fueled Rhysida ransomware attacks and developed tools for major malware strains like Oyster, Lumma Stealer, and Vidar. On May 19, the tech giant unsealed a legal case in the US District Court for the Southern District of New York focused on the group. It also shared details of how its Digital Crimes Unit (DCU) agents have engaged with Fox Tempest’s operators using undercover personas, identified the group’s infrastructure, collaborated with some of the organizations hosting this infrastructure and disrupted the group’s operations. Microsoft is now working with the FBI and Europol’s European Cybercrime Centre (EC3) to uncover the identity of people behind the group. Fox Tempest: A Prolific Cybercrime-Enabling Group Fox Tempest is a financially motivated threat actor that has been active since at least May 2025. The group operates “in the upstream in the malware and ransomware supply chain, as an enabler,” Maurice Mason, principal cybercrime investigator at Microsoft's Digital Crimes Unit, explained during a press briefing held on May 18. This means that, instead of carrying out malicious operations themselves, Fox Tempest provides tools and services enabling other cyber-threat actors to do so. Specifically, the group sells what Microsoft calls a “malware-signing-as-a-service” (MSaaS) offering that further allows cybercriminals to disguise malware as legitimate software and thereby evade traditional security defenses. Microsoft assessed that Fox Tempest has worked closely with several ransomware groups. These include Storm-2501, Storm-0249 and Rhysida, a group tracked by Microsoft as Vanilla Tempest. Rhysida, in particular, was named as a Fox Tempest’s co-conspirator in the lawsuit. The group has been linked to multiple cyber-attacks between 2023 and April 2026, including schools, hospitals, medical institutions and other critical infrastructure organizations worldwide. Rhysida is also believed to be behind an October 2023 hack targeting the British Library and a data extortion attack against Seattle-Tacoma International Airport in September 2024. Additionally, the fraudulent code-signing tool developed by Fox Tempest was identified by Microsoft in the deployment of a number of malware strains including Aurora, Lumma Stealer, Malcert, Oyster, Vidar and many more. It was also spotted in some campaigns deployed by MuddyWater, a cyber-espionage group attributed by several experts to Iran's Ministry of Intelligence and Security (MOIS). Among the countries most targeted by Fox Tempest were the US, France and India, followed by China, Brazil, Germany, Japan, the UK, Italy and Spain. “This doesn’t mean that these countries were targeted by malware or ransomware, but that there was a file on a machine in one of these countries that had been signed by a certificate made using the Fox Tempest-made code-signing service,” noted DCU’s Mason. Fox Tempest’s Code-Signing Abuse Explained To build its MSaaS tool, Fox Tempest abused code-signing tools such as Microsoft’s Artifact Signing, a system introduced as Trusted Signing in 2024 and designed to help software developers verify that software is legitimate and hasn’t been tampered with. “This fraudulent code-signing acts as a fake ID that lets cybercriminals get into the systems by walking right through the front door,” Steven Masada, global head of Microsoft DCU, explained. “It’s so scalable and easy for anyone to use, even for the most non-technical person. You just need to drag and drop a file into a portal and it gets your software signed with Afrtifact Signing.” After engaging with SamCodeSign, a seller of code-signing certificates since at least 2020 who acted as an access broker for Fox Tempest, the DCU team observed that they typically sell their service under three options: Standard version with purchase queue at $5000 Priority sale at $7500 Expedited sale at $9500 Microsoft also collaborated with cybersecurity company Resecurity to explore how Fox Tempest operates. Microsoft Takedown of Fox Tempest Infrastructure The DCU then investigated Fox Tempest’s infrastructure, which initially included a website called Signspace[dot]cloud, using legitimate hosting providers like UK-based Freak Hosting, and Estonia-based Wavecom as the service’s virtual private server (VPS) suppliers. The DCU team shifted its infrastructure in January 2026 and started using Cloudzy, another legitimate VPS provider based in Dubai, in the United Arab Emirates. On May 5, Microsoft filed a civil court action with the Court for the Southern District of New York and was granted a court order three days later. The DCU transferred the groups’ malicious domains to a Microsoft-owned sinkhole, disabled hundreds of virtual machines hosted on Cloudzy with the help of the provider, took down approximately 1000 accounts, and suspended the threat actor’s repository. The DCU team then engaged with SamCodeSign, which shared the issues it was experiencing operating the service. “He’s freaking out, he’s upset, he won’t sell us a certificate anymore,” said DCU’s Mason. Microsoft also observed a significant decrease in Fox Tempest-made certificates. “Every day, we decide what software to trust in seconds guided by simple labels such as ‘verified,’ ‘secure’ and ‘safe to install.’ The problem is that those signs can be manipulated,” said Masada. “For the first time, Microsoft is taking public action against a powerful, but often unseen, enabler within the cybercrime ecosystem, targeting how cybercriminals prepare and employ techniques to optimize their rate of success.” Image credit: gguy / Shutterstock.com
infosecurity-magazine.comMay 19, 2026extracted
Google Launches Android Spyware Forensics Tool for High-Risk Users
Google is rolling out a new feature that will help investigate spyware attacks on Android devices. The new tool, called Android Intrusion Logging, was released on May 12 as part of Google’s Android Advanced Protection Mode (AAPM). This mode, which can be likened to Apple’s Lockdown Mode, was launched in 2025. Designed to enhance the security of Android devices for at-risk users, AAPM packages a set of pre-determined features designed to bolster device protection against scams, fraud and targeted attacks. AAPM’s newest feature, Intrusion Logging, was developed by Google in partnership with civil society organizations, including Amnesty International’s ’s Security Lab and Reporters Without Borders' Digital Security Lab. With Intrusion Logging, high-risk Android users can log their device and network activities for times when they notice suspicious activity or suspect their device has been infected with malware. By doing that, they will allow trusted security experts to perform forensic investigations into their device's behavior, including applications that run on it. These logs include: Security events (e.g. device unlocking, physical access and abusive interactions) Spyware installation and removal Domain name system (DNS) and connections events All forensic logs, collected once a day by default, are encrypted with a user-generated key before the logs are securely archived in the user’s Google account. The logs can later be accessed and decrypted by the user, but not by Google or any unauthorized third parties. When forensic analysis is required, the device owner must explicitly share these logs from the device itself in a secure manner with the forensic analyst. “Intrusion Logging logs may include sensitive information such as browser navigation history. Secure sharing of logs and informed consent are therefore more essential than ever,” warned Amnesty International in a May 12 report. Donncha Ó Cearbhaill, head of security at Amnesty Tech, praised Google for the release of Intrusion Logging on X. He explained that spyware forensic work “has so far relied on incidental logs that were never designed for security analysis and are too often partial and short-lived.” “Now we have the possibility to detect advanced spyware, exploits, unauthorized physical access, even months after the fact,” he added. The feature is opt-in for Pixel devices on Android 16 and later versions with Advanced Protection mode enabled. Users who wish to benefit from Intrusion Logging must have a Google account linked to their device. Google plans to roll Intrusion Logging out beyond Pixel devices in the future. In parallel to the introduction of Intrusion Logging, Amnesty International has releasing updates to Android Quick Forensics (AndroidQF). AndroidQF is a lightweight open source forensic tool for Android devices to quickly extract and analyze critical evidence during investigations, and the Mobile Verification Toolkit (MVT), an Amnesty-made, open source toolkit to simplify and automate the process of gathering forensic traces to identify a potential compromise of Android and iOS devices. Latest Updates to Android Advanced Protection Mode Google also has rolled out a package of updates to its Android Advanced Protection Mode. These include: USB Protection: Now available on all Pixel devices running Android 16 and newer, this feature blocks new USB data connections while the device screen is locked Restricted accessibility services: Starting with Android 17, the mode will remove accessibility service access for all apps that are not explicitly labeled as accessibility tools to prevent malicious exploitation Disabled device-to-device unlocking: To enhance physical security, the ability to unlock one device using another nearby trusted device is being disabled Chrome WebGPU support removal: Support for WebGPU in Chrome will be disabled within this mode to reduce the browser's attack surface Chat notification scam detection: The mode will now integrate scam detection specifically for chat notifications to help identify and block fraudulent messages. Finally, Advanced Protection will be expanded to support managed devices through Android Enterprise later this year. Image credits: Thrive Studios ID / DIA TV / Shutterstock.com
infosecurity-magazine.comMay 14, 2026extracted
OpenAI Launches 'Daybreak' to Help Build Secure By Design Software
OpenAI has announced Daybreak, a new initiative based on its frontier large language models (LLMs) and its AI-coding assistant, Codex, to help developers build secure software from the ground up. Unveiled on May 12, OpenAI said Daybreak builds from its Trusted Access for Cyber (TAC) program, a scheme that reserves access to certain frontier models to a selective number of organizations. The initiative already includes three of OpenAI’s latest models: the general-purpose version of GPT‑5.5; GPT‑5.5 with TAC, which offers more precise safeguards for verified defensive work in authorized environments; and GPT‑5.5‑Cyber. It also features Codex Security, a code‑review assistant based on Codex that is currently available only as a research preview. Where the TAC program is primarily focused on vetted users tapping into LLMs to identify and fix vulnerabilities, Daybreak aims to tackle the vulnerability problem from the start of the software development lifecycle. Speaking to Infosecurity, Willie Tejada, SVP & GM of Cloud Native Security Fabric at Aviatrix, explained that OpenAI's press release is intentionally broad because Daybreak is "a platform play, not a model announcement." He said the initiative aims to help cyber defenders do three things: build an editable threat model of a given code repository focused on realistic attack paths, discover and test vulnerabilities in an isolated environment and propose and validate patches directly in the repo. "The pitch is that it compresses hours of manual security analysis into minutes," Tejada added. In a series of short videos posted on social media, OpenAI shared some of the tasks that software developers and cybersecurity defenders can perform as part of the initiative. These include: Scanning a codebase using Codex Security’s 10 subagents, identifying vulnerabilities, fixing them and adding regression tests Triaging vulnerability backlog, prioritizing vulnerabilities that should be fixed (e.g. by severity, impact or exploitability) and deploying agents to open pull requests Automating vulnerability detection, validation and response (e.g. looking for the latest CVEs, deploying an agent to investigate their impact on the business, searching logs for exploitation evidence) “The goal is simple: accelerate cyber defenders and continuously secure software,” the OpenAI announcement said. “Because those same capabilities can be misused, Daybreak pairs expanded defensive capability with trust, verification, proportional safeguards and accountability.” According to Tejada, Daybreak is "OpenAI's bid to own the security developer toolchain the same way GitHub Copilot captured the coding assistant market." The company also said it will soon deploy new “cyber-capable models” in cooperation with industry and government partners. As of May 2026, OpenAI said its TAC program includes hundreds of organizations and "thousands of individual defenders." These include IT and cybersecurity organizations like Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, NVIDIA, Oracle, Palo Alto Networks, Sophos and Zscaler. The TAC also includes large enterprises, especially in finance and private equity, such as Bank of America, BBVA, BlackRock, BNY, Citibank, Goldman Sachs, JPMorgan Chase, Morgan Stanley and US Bank. While only a handful of government-linked research organizations, like the US Center for AI Standards and Innovation (CAISI) and the UK AI Security Institute (UK AISI) are currently part of the TAC program, OpenAI confirmed in early May its intention to expand it to more government agencies. Anthony Grieco, SVP, chief security and trust officer at Cisco, believes frontier models like GPT 5.5 are “powerful force multipliers for defenders.” “They are fundamentally changing the velocity of our operations, enabling us to move faster on everything from incident investigation to proactive exposure reduction,” he said. “But speed cannot be traded for trust. The true value of this technology isn't found in the model alone, but in the enterprise-ready framework we wrap around it. A framework that helps us make more secure products. Our focus is on transforming our secure development and operations processes with these new capabilities. For us, it's about enabling innovation that is as reliable as it is fast.” Experts Raise Concerns About AI-Powered Vulnerability Research While many experts regard the launch of Daybreak as a step in the right direction in a bid to use frontier AI models to help fix vulnerabilities alongside other software development tasks, it also raised a lot of concerns. David Stuart, a cybersecurity evangelist at data security solutions provider Sentra, warned that to unlock the capabilities of frontier AI agents, organizations must grant these systems access to their environment. “That may include code repositories, infrastructure configurations and build pipelines. Before introducing these tools, organizations need to understand what sensitive data lives in those environments and whether it is governed well enough for an AI agent to interact with it,” he said. “The same access that makes these tools useful also makes them part of the data attack surface. That governance work needs to happen before the agent is deployed.” Meanwhile, Andrew Wesie, a vulnerability researcher and CTO of AppSec company Xint.io, said that vulnerability researchers should also ensure they’re aware of the details of security offerings from GenAI companies like OpenAI and Anthropic if they don’t want to be trapped in an expensive ecosystem that will lock them in. “For example, how many tokens are burned during [Daybreak] assessments, what is the false positive rate and how will pricing work for enterprise code bases that have millions of lines of code? Without this information, it’s hard to know if teams should build their AppSec pipelines around monolithic models,” he cautioned. Many believe the democratization of AI-powered vulnerability research is to be welcomed. However, Melissa Bischoping, head of threat research and intelligence at Tanium, warned it also “tightens the bottleneck around remediation.” As software companies find and develop bug fixes at an “unprecedented pace,” consumers of the software may not necessarily be ready to deploy patches. “Many organizations today still struggle with the ‘old way’ of monthly patching at the scale of the last few years. That ship has sailed, and we’ve got to rethink and rebuild our patching systems for this era,” she said. She argued that patch management teams will have to deal with “dozens or hundreds of micro-patches per week” as bugs are uncovered. Clyde Williamson, a senior product security architect at Protegrity, which provides data security solutions designed for AI workflows, noted that finding vulnerabilities has never been the hardest problem, prioritization is. This article was updated on May 13 to add comments from cybersecurity professionals. Image credits: Thrive Studios ID / TY Lim / Shutterstock.com
infosecurity-magazine.comMay 12, 2026extracted
Malicious Hugging Face Repository Typosquats OpenAI
Security researchers have uncovered covert infostealer malware hidden in one of the top-ranking repositories on Hugging Face, in another example of the dangers posed by the AI supply chain. AI security vendor HiddenLayer explained in a blog post that it had identified the Open-OSS/privacy-filter as malicious on May 7. At the time it appeared as one of the top-trending repositories on the platform, with over 244,000 downloads and 667 likes in under 18 hours. These figures “were almost certainly artificially inflated” to make the repository appear legitimate, the report claimed. The repo itself typosquatted OpenAI's legitimate Privacy Filter release, copying its model card almost verbatim, HiddenLayer claimed. The attack chain for this campaign was spread over six stages. If the user landed on the malicious repository they would be instructed to clone the repo and run start.bat (Windows) or python loader.py (Linux/macOS) directly, according to the report. The Python script contained a base64-encoded string which ultimately dropped a malicious executable – a Rust-based infostealer. The infostealer featured multiple techniques to bypass the victim’s security controls. “It hides its use of Windows APIs to defeat static analysis, runs checks to detect debuggers and sandboxes, looks for signs it's running in a virtual machine (VirtualBox, VMware, QEMU, Xen), and attempts to disable Windows Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) to evade behavioral detection,” the report explained. The malware was designed to steal browser passwords and session cookies, Discord tokens, crypto wallets, Telegram sessions, and more. Mitigation Tactics HiddenLayer urged any user that cloned the malicious repo and executed start.bat, python loader.py or any other file from the repository to treat their system as fully compromised. “Because the payload is a credential-harvesting infostealer, do not log into anything from the affected host before wiping it,” the vendor explained. “Once the host is isolated, rotate every credential that was stored in browsers, password managers, or credential stores on that machine, including saved passwords, session cookies, OAuth tokens, SSH keys, FTP credentials (FileZilla in particular), and any cloud provider tokens.” Users should treat browser sessions as compromised even if the password was not saved, as stolen session cookies can help threat actors to bypass MFA. They should also: Move any cryptocurrency wallet funds to a new wallet generated on a clean device, and assume seed phrases, keystores, and wallet extension data may have been stolen Invalidate Discord sessions and reset Discord passwords, since tokens and master keys are explicitly targeted Block the IOCs in the report at egress, and hunt historically for connections to identify any other affected hosts Infostealers continue to fuel a thriving cybercrime economy. Last month, data from KELA revealed at least 347 million credentials were originally obtained by infostealers found on around 3.9 million infected machines. Image credit: sdx15 / Shutterstock.com
infosecurity-magazine.comMay 12, 2026extracted
Three Arrested for Hacking Over 610,000 Roblox Accounts
Police have arrested three people suspected of hacking the accounts of over 610,000 Roblox users. The Prosecutor General’s Office of Ukraine said that a 19-year-old from Drohobych and a further two individuals aged 21 and 22 have been arrested for their suspected involvement involvement in the phishing and malware scheme. According to the investigation, between October 2025 to January 2026, the hackers accessed over 610,000 online game platform Roblox accounts. This access was used to check what in-game items and how much ‘Robux’ account users owned. Robux is the is the in-game currency of Roblox, which players can use real money to buy. Robux gift cards are available for purchase through official Roblox sources and can cost as much as $199.99. Some of the rarest in-game items in Roblox are traded for thousands of dollars on third-party exchanges. That means that access to stolen accounts of those ‘elite’ users who own rare items could prove extremely lucrative to thieves. As part of the scheme, the attackers identified at least 357 accounts as high-value elite accounts, and access to them sold on Russian websites in exchange for payments in cryptocurrency. Authorities believe that the group made over $225,000 from selling these accounts. According to the National Police of Ukraine, the hackers used social engineering lures which claimed to offer Robox players in-game bonuses. However, what the players received was infostealer malware, which stole usernames, passwords and tokens, which provided the attackers with access to the accounts. Working with the cyber police and the Security Service of Ukraine, the Prosecutors of the Lviv region conducted searches at 10 properties associated with those suspected of conducting the criminal activity. These searches resulted in the seizure of computer equipment, storage devices, mobile phones, bank cards, handwritten notes, plus over €2,500 and nearly $35,000. The investigation is ongoing and police said that analysis of the seized devices is underway. If found guilty of distributing the malware and stealing accounts, the defendants face up to 15 years in prison. Infosecurity has contacted Roblox for comment. Image credit: Miguel Lagoa / Shutterstock.com
infosecurity-magazine.comApr 30, 2026extracted
Utilities Tech Supplier Itron Discloses Cyber-Attack, Operations Unaffected
Itron, a global technology provider for the utilities industry, has disclosed it suffered a cybersecurity breach. In an 8-K form filed to the US Securities and Exchange Commission (SEC) on April 24, the US-based firm revealed its IT systems were breached by an unauthorized third-party actor. Upon discovering the activity, Itron, which produces products and services for energy and water resource management, immediately activated its cybersecurity response plan. The firm also launched a comprehensive investigation with the support of external advisors in order to assess, mitigate, remediate and contain the breach. As part of its response efforts, the company also proactively notified law enforcement authorities. Itron confirmed that it has since taken action to fully remediate and remove the unauthorized activity from its systems and has not observed any subsequent unauthorized access within its corporate systems. The company also stated that no unauthorized activity was detected in the customer-hosted portion of its systems and that its operations have continued unaffected in all material respects, meaning day-to-day business activities were not significantly disrupted as a result of the incident. Itron noted that it expects a significant portion of the direct costs incurred in connection with the incident to be reimbursed by its insurers, helping to limit the overall financial impact of the breach. The company added that it is currently evaluating what legal filings and regulatory notifications may be required as a result of the incident and intends to take appropriate action based on its review and findings. Finally, Itron asserted that, at this stage, it does not believe the incident has had, or is reasonably likely to have, a material impact on the company. Image credits: Itron / Mayy Contributor / Shutterstock.com
infosecurity-magazine.comApr 27, 2026extracted
Apple Fixes iOS Notification Bug Exposing Deleted Messages
Apple has issued an emergency update to fix a Notification Services flaw that caused deleted alerts to remain stored on devices, potentially exposing sensitive message content. Tracked as CVE-2026-28950, the issue has been resolved in iOS 26.4.2 and iPadOS 26.4.2, with patches also released for older supported versions of Apple operating systems. The company said the bug stemmed from a logging issue that allowed notifications marked for deletion to persist. Apple added that improved data redaction addresses the problem, but did not confirm whether the flaw had been exploited or how long retained data could remain accessible. Notification Data Persistence Raises Privacy Concerns The update follows reporting that forensic investigators recovered deleted Signal messages from an iPhone by accessing stored notification data rather than the app itself. According to 404 Media, message content remained available even after the app was removed because notifications had been cached in system storage. Although Apple did not reference the case directly, its advisory reflects similar behavior. The company has not explained why notification content was retained or when the issue was introduced. Signal welcomed the fix. "We're grateful to Apple for the quick action here, and for understanding and acting on the stakes of this kind of issue," the company said in an X post on Wednesday. "It takes an ecosystem to preserve the fundamental human right to private communication." Patch Coverage and Mitigation Steps The vulnerability impacts a broad range of iPhones and iPads, including iPhone 11 and later devices. Apple has also backported fixes to iOS 18.7.8 and iPadOS 18.7.8. Users can reduce risk by: Setting notification previews to "Name Only" or disabling message content Installing the latest OS updates promptly Reviewing notification settings for sensitive apps The Electronic Frontier Foundation has warned that notifications may expose metadata or unencrypted content depending on implementation. Apple's update highlights how system-level features can introduce privacy risks, even when applications use encryption. Image credit: Farknot Architect / Shutterstock.com
infosecurity-magazine.comApr 23, 2026extracted
Google Introduces Unique AI Agent Identities in New Gemini Enterprise Platform
Google is betting big on agentic AI and wants professionals to track their AI agents on its new hub Gemini Enterprise Agent Platform. Introduced a few months after the launch of Gemini Enterprise, the Agent Platform is Google’s new hub to manage agentic AI workflows for both Google-made and external AI agents. The platform aims to bring together with a series of existing and new capabilities. Among them, the Agent Platform enables users to assign every agent a unique cryptographic ID that will be referred to for every action an agent takes. These agent IDs are designed to be mapped back to “defined authorization policies that are traceable and auditable,” said Thomas Kurian, Google Cloud’s CEO, speaking at the Google Cloud Next 26 conference, held in Las Vegas from April 22 to April 24. “We’re bringing zero trust verification to every agent and at every orchestration step,” he added. Tackling A New Class of Identity Risk AI agents are poised to disrupt identity management for security professionals. While traditional non-human identities (NHIs), such as API keys or service accounts, are deterministic, AI agents are autonomous and goal oriented. They are capable of understanding a high-level goal, breaking it down into steps and independently executing a series of actions across various applications to achieve that goal. This introduces new types of dynamic digital entities which act on behalf of humans and make independent operational decisions. Agent identities will be listed on Google Cloud’s Gemini Enterprise Agent Platform in Agent Registry, a central library that indexes every internal agent, tool and skill. Finally, the Agent Platform will also feature Agent Gateway, a single dashboard to manage a fleet of AI agents. This includes enforcing policies for all agent-to-agent and agent-to-tool connections and interactions, supporting several agentic AI protocols like model context protocol (MCP) and Agent2Agent (A2A). “It provides secure, unified connectivity between agents and tools across any environment, while enforcing consistent security policies and Model Armor protections to safeguard against prompt injection and data leakage,” said a Google Cloud statement published on April 22. Model Armor is Google Cloud’s own guardrail layer against adversarial attacks, including prompt injection, sensitive data leaks and harmful content. Francis deSouza, COO of Google Cloud, said that security teams need to identify agents, both authorized and unauthorized, used across their workforce. "When you roll out authorized agents, you want to manage their access control, what they should have access to and that may change over time in a way that's more dynamic than human identities," he added. Agent Security Dashboard and Anomaly Detection Introduced At Cloud Next 26, Google Cloud also unveiled Agent Anomaly Detection, a new feature which uses statistical models and a large language model (LLM) as-a-judge framework to identify unusual behavior in real time, flagging potential threats like suspicious reasoning patterns. Anomaly Detection works alongside the existing Agent Threat Detection, which monitors malicious activities such as reverse shells and connections to known bad IP addresses. Another addition is the Agent Security dashboard, powered by Google Cloud’s Security Command Center (SCC), which unifies threat detection and risk analysis within Google Cloud Platform (GCP) environments. Google Cloud said this new dashboard will help security teams map relationships between AI agents and models, automate asset discovery and scan for vulnerabilities in operating systems and language packages. These new capabilities build on Gemini Enterprise’s existing security tools, including Agent Compliance and Agent Policy, which already provide policy enforcement capabilities. Google Cloud Pushes Deeper into Agentic AI and Cybersecurity The Gemini Enterprise Agent Platform launch and release of Google’s new agentic AI security capabilities were among a flurry of Google Cloud announcements at Cloud Next 26. Israeli cloud security firm Wiz, acquired by Google in 2025, has expanded its AI-Application Protection Platform (AI-APP) to embed security directly into developer workflows. The updates bring real-time vulnerability scanning, AI-generated code security, a dynamic AI bill-of-materials (AIBOM) offering and automated remediation into platforms like AI development solution Lovable, integrated development environments (IDEs) and version control systems. Google also released three new agents for cybersecurity professionals. The Threat Hunting agent aims to help security teams proactively hunt for novel attack patterns and stealthy adversary behaviors that bypass traditional defenses. The Detection Engineering agent is designed to identify coverage gaps and create new detections for threat scenarios, reducing toil and transforming detection creation from a manual craft into an automated science. They are both available in preview mode. Finally, coming soon to preview, Google’s Third-Party Context agent has been created to enrich security teams’ workflows with contextual data from third-party content. When available, the three agents will be integrated into Google Security Operations, the firm’s security analytics, threat detection and incident response platform. Google claimed that its Triage and Investigation agent, introduced in April 2025, processed over five million alerts in the last year, “reducing a typical 30-minute manual analysis to 60 seconds.” Finally, Google released a new dark web intelligence feature in Google Threat Intelligence, now available in preview. The tech firms said that internal tests showed the feature can analyze millions of daily external events with 98% accuracy to elevate threats that truly matter. Google also launched two AI-focused processing chips, the Tensor Processing Unit 8t (TPU 8t) for AI training and the Tensor Processing Unit 8i for AI inference. Finally, Google also committed to invest $750m in a new agentic AI partner fund available for global consulting firms, systems integrators, software partners and channel partners. The fund’s goal is to support AI value identification, agentic AI prototyping, agent building and deployment and upskilling. Image credit: gguy / Shutterstock.com
infosecurity-magazine.comApr 23, 2026extracted
OpenAI Unveils GPT-5.4-Cyber for Improving Cyber Defense With AI
OpenAI has launched a new large language model (LLM) focused on use cases for cybersecurity and expanded its Trusted Access for Cyber (TAC) program, as the AI company behind ChatGPT looks to enhance how its models can be deployed for cyber defense capabilities. In a blog post which announced the expanded TAC program, published April 14, OpenAI revealed GPT‑5.4‑Cyber, a variant of GPT 5.4 which has been trained to be “cyber-permissive” and “fine-tuned for cybersecurity use cases.” Initially revealed in February, the OpenAI Trusted Access for Cyber Program was designed to automate identity verification to help reduce the friction of safeguards on cybersecurity-related tasks and partner with a limited set of organizations. This has since been followed by the Anthropic launch of Claude Mythos Preview and Project Glasswing, an initiative designed to discover and fix cybersecurity vulnerabilities in software with the aid of LLMs. Now, OpenAI has opted to publicly announce the expansion of its own program, following what the company described as “many months of iterative improvement.” The company said that it has chosen a staggered release for GPT‑5.4‑Cyber so that it can “learn the most by putting these systems into the world carefully” to help understand the potential benefits and risks. The expansion of TAC sees the introduction of additional tiers to the program, with the highest tiers reserved exclusively for “users willing to work with OpenAI to authenticate themselves as cybersecurity defenders.” New Capabilities for Cyber Defenders In return, users will gain access to a frontier model: “This is a version of GPT‑5.4 which lowers the refusal boundary for legitimate cybersecurity work and enables new capabilities for advanced defensive workflows.” While the expanded tools are currently only available to vetted security vendors, organizations and researchers, OpenAI said it wants to “make these tools as widely available as possible while preventing misuse.” That is why the company has announced a requirement for stronger verification processes to ensure that the cyber defense capabilities of the model can’t be abused. “Cyber capabilities are inherently dual use, so risk isn’t defined by the model alone,” the company said, in reference to how malicious cyber-attackers have also look for ways to enhance their capabilities with AI. The new model is also a reaction to what OpenAI described as “steady improvements in agentic coding” and the “direct implications for cybersecurity” this has. The company has also called for software development itself to be more secure and views GPT‑5.4‑Cyber and TAC can help improve this. “The strongest ecosystem is one that continuously identifies, validates and fixes security issues as software is written,” said the blog post. “By integrating advanced coding models and agentic capabilities into developer workflows, we can give developers immediate, actionable feedback while they are building, shifting security from episodic audits and static bug inventories to ongoing, tangible risk reduction.” Image credit: Samuel Boivin / Shutterstock.com
infosecurity-magazine.comApr 15, 2026extracted
AI Companies to Play Bigger Role in CVE Program, Says CISA
AI companies like OpenAI and Anthropic should play a bigger role in software vulnerability disclosures in the future, according to a leader of the world’s largest vulnerability disclosure scheme. Speaking at the opening of VulnCon26 in Scottsdale, Arizona, on April 14, Lindsey Cerkovnik said AI companies “should be better represented" in the Common Vulnerabilities and Exposures (CVE) program. As chief of the Vulnerability Response & Coordination (VRC) Branch at the US Cybersecurity and Infrastructure Security Agency (CISA), sole sponsor of the MITRE-run CVE program, Cerkovnik and her team manage coordinated vulnerabilities disclosures for the CVE program. She acknowledged that the program has faced a rapid growth of reported vulnerabilities over the past year and that the evolution of AI platforms will likely accelerate that growth. “With the arrival of new AI tools, some helping discover valid vulnerabilities, others perhaps finding things with less value, we’re at a turning point,” Cerkovnik said. Anthropic, OpenAI Speed Up on AI-Powered Vulnerability Research Cerkovnik’s VulnCon speech came just a few days after the launch of Claude Mythos Preview, Anthropic’s new large language model (LLM) that promises to autonomously find and fix cybersecurity vulnerabilities at scale. Today, Mythos is only available to the 40 members of Project Glasswing. In testing, the model allegedly discovered thousands of zero-day vulnerabilities which had not previously been identified. The model also autonomously found and chained several vulnerabilities in the Linux kernel, software used to run most of the world’s servers, which would allow an attacker to escalate from ordinary user access to complete control of a machine Upon testing Mythos Preview in a simulation environment, researchers at the UK’s AI Security Institute (AISI) said they “cannot say for sure” whether Mythos Preview would be able to successfully attack “well-defended systems.” On April 14, OpenAI launched GPT-5.4-Cyber, a version of GPT-5.4 fine-tuned for cybersecurity use cases and only available to members of its "Trusted Access for Cyber Defense" program. 50,000 to 70,000 Expected CVEs in 2026 Notably, the speed of vulnerability disclosures was already accelerating long before the launch of Mythos and OpenAI's GPT-5.4-Cyber. The CVE program counts 327,000 unique CVE records to date. Of those , Jerry Gamblin, principal engineer at Cisco Threat Detection & Response, observed 18,247 were reported in 2026, a 27.9% growth from the same period in 2025. Additionally, Gamblin calculated average of 174 CVEs reported daily this year, compared to 132 in 2025. In February 2026, the Forum of Incident Response and Security Teams (FIRST), which co-hosts VulnCon with the CVE program, forecast a record-breaking 50,000 additional CVEs to be reported in 2026. Gamblin expects an even bigger growth, with a forecast of 70,135 CVEs by the end of this year. This would reflect a 45.6% growth rate compared to 48,171 in 2025. AI Companies Could Become Official Vulnerability Reporters Cerkovnik’s call for closer integration of AI companies into the CVE program aligns with the program’s broader diversification strategy. This strategy was illustrated by the launch of two new forums in July 2025, the CVE Consumer Working Group (CWG) and the CVE Researcher Working Group (RWG). One of the main objectives is to grow the number of CVE Numbering Authorities (CNAs), organizations that are allowed to publicly disclose a vulnerability and attributed it a CVE identifier. At the end of March 2026, the CVE program announced it had reached over 500 contributors, with 502 CNAs now registered. Diversification of the CVE program also means internationalization of the program, with more European-based CNAs to be vetted in the future, commented Nuno Rodrigues Carvalho, head of sector for Incidents and Vulnerability Services at the European Cybersecurity Agency (ENISA). Speaking to Infosecurity, his colleague, Johannes Kaspar Clos, a responsible disclosure expert at ENISA, said he would welcome AI companies to also become CNAs. “We need to include a diverse crowd of cybersecurity practitioners, from product and nationals computer emergency response teams (CERTs) and computer security incident response teams (CSIRTs) to researchers and vulnerability finders. Anthropic is one example of a company who identified vulnerabilities and therefore, is of course rightfully mentioned in being a potential CNA,” Clos said. While he welcomed the launch of Claude Mythos and other AI-powered tools allowing researchers to find more vulnerabilities, Clos added said he would have preferred the capabilities of such models' capabilities to be disclosed "before the products are pushed to the market." "Security testing should be implemented before users are put at risk," he added. CVE Program: A “Top Priority” for CISA Finally, Cerkovnik said the CVE program is “a top priority” for CISA and its parent administration, the US Department of Homeland Security (DHS) and that the security agency will continue funding the program in the future. While she declined to provide any specifics, she said, “Contracts and funding for the CVE program are secure. Funding has never been an issue.” However, she highlighted that DHS was still technically in a shutdown situation and that it currently complicates decision-making at CISA, including around spending for outreach opportunities like her coming to VulnCon. Image credits: Koshiro K / gguy /Shutterstock.com
infosecurity-magazine.comApr 15, 2026extracted
Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies
A new feature aimed at protecting internet users from information stealing malware, or infostealers, has been rolled out in the current version of Google Chrome browser. Alongside the release of Chrome 147, which includes new security patches, Google announced on April 9 that Device Bound Session Credentials (DBSC) is now publicly available on Chrome 146. Initially launched in April 2024, DBSC is designed to block infostealers from harvesting session cookie. The system cryptographically associates authentication sessions to a specific device by generating a unique public/private key pair stored on hardware-backed security modules, such as the Trusted Platform Module (TPM) on Windows and the Secure Enclave on macOS, so that the pair cannot be exported from the machine. “Because attackers cannot steal this key, any exfiltrated cookies quickly expire and become useless to those attackers,” said the Google Account Security team in a blog. The system allows websites to implement hardware-bound sessions with minimal backend adjustments, while the browser automates cryptographic protections and cookie rotation. This ensures backward compatibility, letting apps continue using standard cookies as before. The protocol also minimizes data exposure, sharing only the per-session public key needed for authentication without leaking device identifiers or enabling cross-site tracking or fingerprinting. DBSC was developed as an open standard vetted by the World Wide Web Consortium (W3C) in collaboration with Microsoft and the Web Application Security Working Group, with input from industry stakeholders, including feedback from Okta and other platforms to ensure broad compatibility and effectiveness. After experimenting with an early version of this protocol in 2025, Google observed “a significant reduction in session theft” for sessions protected by DBSC. The system is now enabled for Windows users on Chrome 146 and Google is looking to expand it to macOS in an upcoming Chrome release. The Google Account Security team are also working on future improvements, including expanding support for federated identity with cross-origin key binding, enabling stronger session registration using pre-existing trusted keys (e.g. mTLS or hardware security keys), and exploring software-based key options to broaden device compatibility, particularly for enterprise use cases. Image credit: viewimage / Shutterstock.com
infosecurity-magazine.comApr 10, 2026extracted
ChatGPT Security Issue Enabled Data Theft via Single Prompt
A security vulnerability in ChatGPT executed with a single malicious prompt could be exploited to covertly exfiltrate sensitive data from prompts and messages. The security issue, which enabled data exfiltration and remote code execution, was discovered by cybersecurity researchers at Check Point, who warned it could put user privacy at risk. “A single malicious prompt could turn an otherwise ordinary conversation into a covert exfiltration channel, leaking user messages, uploaded files, and other sensitive content,” Check Point said in a blog post published on March 30. A security update for ChatGPT was deployed on February 20 after researchers reported the issue to OpenAI. Prior to the fix, a hidden outbound communication path from ChatGPT’s isolated execution runtime to the public internet could have put users at risk of having their messages and prompts exposed. Many people have become accustomed ChatGPT and other AI assistants to help more efficiently manage tasks at work. This includes those which involve sensitive corporate data, including account details and private records. LLMs are also being used to discuss personal issues, like their health, personal finances or mental wellbeing. Users expect this information to remain within the system, protected from exfiltration by appropriate guardrails. However, Check Point found that it was possible to bypass these protections. “We found that a single malicious prompt could activate a hidden exfiltration channel inside a regular ChatGPT conversation,” said researchers. The vulnerability allowed for information to be transmitted to an external server through a DNS side channel originating from the container used by ChatGPT. Key to the issue was how the model operated under the assumption that this environment was not designed to send data outward, so when the model was promoted to send data, it did not know how to mediate or resist this. An attacker could take advantage of this by using the prompt and directing ChatGPT to send information exchanged with the model outside the framework to access it themselves. Third-Party Access to Private Prompts In a proof-of-concept Check Point uploaded a PDF containing laboratory test results, which also contained personal information, including a patient name and used the malicious prompt to exploit the vulnerability. When asked if the information was sent to a third-party, ChatGPT responded that it had not, seemingly unaware that because of its actions a server operated by the attacker received highly sensitive data extracted from the conversation. The vulnerability was based around the user entering the prompt themselves. The researchers pointed out that there are multiple ways to trick users into entering commands, for example, by listing the malicious prompt on a website or social media thread about the top prompts for productivity and other terms people may search for. “For many users, copying and pasting such prompts into a new conversation is routine and does not appear risky,” said researchers. “A malicious prompt distributed in that format could therefore be presented as a harmless productivity aid and interpreted as just another useful trick for getting better results from the assistant.” While it’s unknown if this vulnerability was exploited in the wild, Check Point researchers warned that as AI assistants like ChatGPT are increasingly operating in environments which may as involve sensitive data, security must be a priority. “As AI tools become more powerful and widely used, security must remain a central consideration. These systems offer enormous benefits, but adopting them safely requires careful attention to every layer of the platform,” the blog post concluded. Infosecurity has contacted OpenAI for comment. Image credit: Anton Dzhumelia / Shutterstock.com
infosecurity-magazine.comMar 31, 2026extracted
New Wave of AiTM Phishing Targets TikTok for Business
Cybercriminals have recently deployed a new set of phishing pages designed to target TikTok for Business accounts by using TikTok- or Google-themed content. Push Security said it had identified a new wave of an Adversary-in-the-Middle (AiTM) phishing pages registered on March 24 within a nine-second window. The cluster of pages were all hosted behind Cloudflare with the same registrar, Nicenic International Group, which Push Security said is commonly abused for bulk phishing domain registration. The pages feature a common naming convention, being various derivations of welcome.careers*[.]com. The list of malicious domains in this style is expected to grow as the campaign ramps up, according to Push Security researchers. While the initial delivery mechanism has not been confirmed, Push Security said it is likely similar to a previously identified campaign reported by Sublime in October, which used dynamically generated emails and featured a cloned Google Careers page. When clicked, the link initially redirects users through a legitimate Google Cloud Storage site before loading the malicious page. The site employs a Cloudflare Turnstile check to prevent security bots from analyzing the page. Victims are presented with either TikTok- or Google-themed content. As users progress through the workflow, they are ultimately directed to an AiTM phishing page. In this instance the victim is required to complete a basic information form before being served with a malicious login page that is in fact fronting a reverse proxy AiTM phishing kit. Why Threat Actors Target TikTok TikTok for Business accounts commonly are used by company marketing teams to manage advertising campaigns. Push Security said the development of targeting TikTok is “notable” given most phishing pages the threat researchers intercept ten to replicate SSO platforms like Google and Microsoft. “TikTok seems a weird choice at first glance. But it makes more sense when we consider that TikTok has been historically abused to distribute malicious links and social engineering instructions,” Push Security said in a blog published on March 26. The platform has been used to deliver infostealers via ClickFix-style instruction with AI-generated videos posed as activation guides for Windows, Spotify and CapCut. The social media platform is also a “common hunting ground” for crypto scammers. It was noted that since most users will opt to “log in with Google” anyone using Google to login to their TikTok account will effectively have both accounts used to distribute ads compromised in one go. This could start a Google Ad Manager exploitation chain where cybercriminals target ad manager accounts to power malvertising scams. Update, April 1, 2026: TikTok confirmed to Infosecurity that the domains mentioned in the report have been officially taken down and are no longer active. Image credit: JarTee / Shutterstock.com
infosecurity-magazine.comMar 27, 2026extracted
Security Researchers Sound the Alarm on Vulnerabilities in AI-Generated Code
Vibe coding tools like Anthropic's Claude Code are flooding software with new vulnerabilities, Georgia Tech researchers have warned. At least 35 new common vulnerabilities and exposures (CVE) entries were disclosed in March 2026 that were the direct result of AI-generated code. This is up from from six in January and 15 in February. The vulnerabilities are being tracked as part of the ‘Vibe Security Radar’ project which was started in May 2025 by the Systems Software & Security Lab (SSLab), part of Georgia Tech’s School of Cybersecurity and Privacy. How Georgia Tech Tracks Flaws Introduced by AI Coding Tools The Vibe Security Radar aims to track vulnerabilities directly introduced by AI coding tools that made it into public advisories, such as the CVE.org, the US National Vulnerability Database (NVD), GitHub Advisory Database (GHSA), Open Source Vulnerabilities (OSV), RustSec and others. Speaking to Infosecurity, Hanqing Zhao, founder of the Vibe Security Radar, “Everyone is saying AI code is insecure, but nobody is actually tracking it. We want real numbers. Not benchmarks, not hypotheticals, real vulnerabilities affecting real users.” He emphasized that this tracking work was fundamental now that more people have stated vibe coding entire projects “straight to production.” “Realistically, even teams that do code review aren't going to catch everything when half the codebase is machine-generated,” he added. 50 Vibe Coding Tool Covered, 74 Vulnerabilities Tracked Zhao claimed that his team tracks approximately 50 AI-assisted coding tools, including Claude Code, GitHub Copilot, Cursor, Devin, Windsurf, Aider, Amazon Q and Google Jules. To develop the Vibe Security Radar dashboard, researchers first pull data from public vulnerability databases, find the commit that fixed each vulnerability, then trace backwards to find who introduced the bug in the first place. “If that commit has an AI tool's signature on it, like a co-author tag or a bot email, we flag it,” Zhao told Infosecurity. Finally, the team uses AI agents to “understand the root cause of each vulnerability and determine whether AI-generated code contributed to it.” “The agents have access to the actual Git repository and commit history, so they can do a real investigation, not just pattern matching,” he said. Out of the 74 confirmed cases of CVEs that were directly due to the use of AI coding tools, Claude Code showed up the most, but Zhao noted that this is mostly because the Anthropic tool “always leaves a signature.” “Tools like Copilot's inline suggestions leave no trace at all, so they're harder to catch,” he added. This domination of Claud Code-introduced flaws could also come from the widespread use of the tool in the software development community. Open-Source Projects Hide Most AI-Linked Flaws However, Zhao admitted that the real number of CVEs due to the use of AI coding tools “is almost certainly higher” than the one shown on the Vibe Security Radar dashboard. “These are just the cases that leave metadata traces. Based on what we see in projects like that, we estimate five to 10 times what we currently detect, roughly 400 to 700 cases across the open-source ecosystem,” he said. “Take OpenClaw for example. It has over 300 security advisories, and we know the project relies heavily on vibe coding. But most of the AI tool traces have been stripped by the authors, so we can only confirm around 20 cases with clear AI signals.” Additionally, there are a lot of vulnerabilities that never get public identifiers (e.g. CVE or GHSA number), which therefore cannot be tracked as easily. Furthermore, Zhao is convinced that the number of vulnerabilities induced by AI coding tools is “only going to grow.” “Last month, Claude Code alone accounted for over 4% of public commits on GitHub and that number is still climbing. More AI code means more AI-introduced vulnerabilities,” he said. The Vibe Security Radar is a long-term project that he and his team will keep improving. “Right now, we rely on metadata like co-author tags and bot emails, but people strip those. The next step is looking at the bigger picture: the project as a whole, commit patterns and the overall coding style. AI-written code has a recognizable feel to it. We're working on models that can pick up on those signals without needing any explicit metadata,” he concluded. Image credit: aileenchik / Shutterstock.com
infosecurity-magazine.comMar 26, 2026extracted
OpenAI Expands Bug Bounty to Cover AI Abuse and 'Safety' Concerns
OpenAI has launched a new bug bounty program to engage researchers in addressing AI abuse and safety risks across its products. The new Safety Bug Bounty program was announced on March 26 and is hosted on Bugcrowd. It complements the firm’s Security Bug Bounty, also hosted on Bugcrowd, that has rewarded 409 security vulnerabilities in OpenAI’s product offerings since its launch in April 2023. With the Safety Bug Bounty, OpenAI wants to encourage disclosures of issues in its products that pose “meaningful abuse and safety risks, even if they don’t meet the criteria for a security vulnerability.” The scenarios covered by this new program encompass: Agentic risks, including model context protocol (MCP) abuse, third-party prompt injection, data exfiltration, disallowed actions at scale on OpenAI’s website or other potentially harmful unlisted behaviors Violations of account and platform integrity (e.g. bypassing anti-automation controls, manipulating account trust signals, evading account restrictions/suspensions/bans) OpenAI proprietary information abuse (e.g. model generations that return proprietary information related to reasoning; vulnerabilities that expose other OpenAI proprietary information) Key Differences: OpenAI’s Security vs. Safety Bug Bounty Programs OpenAI outlined that integrity violations involving a user having access to features, data or functionalities beyond authorized permissions should be reported to the Security Bug Bounty rather than the new Safety Bug Bounty. The company further clarified that general content-policy bypasses without clear safety or abuse impact are not eligible for rewards. For example, it specified that "jailbreaks" that only result in rude language or easily searchable information are out of scope. However, researchers who identify flaws enabling direct user harm with actionable fixes may still qualify for rewards on a case-by-case basis. OpenAI also stated that it periodically runs private bug bounty campaigns targeting specific harm types, including biorisk content issues in ChatGPT Agent and GPT-5. Researchers can already submit issues to the Safety Bug Bounty program via Bugcrowd. An OpenAI team responsible for both Safety and Security Bug Bounty programs will triage submissions, which may be rerouted between the two programs depending on scope and ownership. Image credits: Samuel Boivin / Stock all / Shutterstock.com
infosecurity-magazine.comMar 26, 2026extracted
Citrix Urges Immediate Patching for Critical NetScaler Vulnerabilities
Citrix has released a new critical security bulletin addressing two new vulnerabilities in its NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. The two products, formerly known as Citrix ADC and Citrix Gateway, are networking and security solutions used by enterprises to manage, optimize and secure application delivery and remote access. CVE-2026-3055: Critical Out-of-Bounds Read The first vulnerability, tracked as CVE-2026-3055 is a critical out-of-bounds read with a severity score (CVSS v4.0) of 9.3. Identified internally by Citrix’s parent company, the Cloud Software Group, the flaw is due to insufficient input validation leading to memory overread. If exploited, it can enable an unauthenticated remote attacker to leak potentially sensitive information from the appliance's memory. The products affected by CVE-2026-3055 include: NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-66.59 NetScaler ADC and NetScaler Gateway 13.1 before 13.1-62.23 NetScaler ADC FIPS and NDcPP before 13.1-37.262 However, according to Citrix’s advisory, published on March 23, these vulnerabilities only affect NetScaler systems explicitly configured as a SAML Identity Provider (SAML IDP). Default or standard configurations remain unaffected. Additionally, Citrix noted that only customer-managed instances are affected, not cloud instances managed by Citrix. Customers can determine if they have an appliance configured as a SAML IDP Profile by inspecting their NetScaler Configuration for the specified string: “add authentication samlIdPProfile .*.” Cloud Software Group strongly urges affected customers to install the relevant updated versions as soon as possible, which include: NetScaler ADC and NetScaler Gateway 14.1-66.59 and later releases NetScaler ADC and NetScaler Gateway 13.1-62.23 and later releases of 13.1 NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.262 and later releases of 13.1-FIPS and 13.1-NDcPP NetScaler introduced the Global Deny List feature in its 14.1.60.52 versions. This new feature provides a method of adopting an instant-on patch to a running NetScaler without requiring a reboot. Cloud Software Group has released Global Deny List signatures for mitigating CVE 2026-3055. “Please note that to receive signatures meant for the Global Deny List, you must use NetScaler Console (Console On-prem with Cloud Connect or Console Service). Additionally, mitigation via Global Deny List signatures for CVE 2026-3055 is applicable only on 14.1-60.52 and 14.1-60.57 firmware builds,” the company noted. “We recommend that you adopt fully patched builds as explained above. The Global Deny List feature is meant to be a method of quickly protecting your NetScaler so that upgrades can be done during a scheduled outage window.” There is no known in-the-wild exploitation and no public proof-of-concept (PoC) exploit available at the time of writing. CVE-2026-4368: High-Severity Race Condition Flaw A second vulnerability, tracked as CVE-2026-4368 is a race condition flaw with a severity score (CVSS v4.0) of 7.7. If exploited, CVE-2026-4368 can cause session mix up. It affects NetScaler ADC and NetScaler Gateway version 14.1-66.54 if NetScaler is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Customers can determine if they have an appliance configured as one of the following by inspecting their NetScaler Configuration for the specified strings An Auth Server (AAA Vserver): “add authentication vserver .*” A Gateway (VPN Vserver, ICA Proxy, CVPN, RDP Proxy): “add vpn vserver .*” Affected customers are advised to install NetScaler ADC and NetScaler Gateway version 14.1-66.59 to apply the patch for CVE-2026-4368. Image credits: JHVEPhoto / viewimage / Shutterstock.com
infosecurity-magazine.comMar 24, 2026extracted
'CursorJack’ Attack Path Exposes Code Execution Risk in AI Development Environment
A method that could enable code execution through manipulated installation links in an AI development environment has been identified by security researchers. The technique, dubbed CursorJack by Proofpoint Threat Research, centres on the abuse of Model Context Protocol (MCP) deeplinks within the Cursor Integrated Development Environment (IDE), potentially allowing attackers to install malicious components or execute arbitrary commands under certain conditions. The findings, based on controlled testing as of January 19, 2026, show that exploitation is not automatic. Instead, it depends on user interaction and system configuration. A single click on a crafted link, followed by approval of an installation prompt, may be sufficient to trigger the behaviour in some environments. Manipulating MCP Deeplinks Cursor uses a custom URL scheme to streamline MCP server installation, embedding configuration data directly into deeplinks that launch the IDE when clicked. Proofpoint found that this process can be exploited through social engineering as malicious links can be crafted to appear legitimate while containing harmful configurations. When users click these links and approve the installation prompt, the IDE may execute commands with the same privileges as the user. Because the installation dialogue does not differentiate between trusted and untrusted sources, attackers can disguise their payloads as routine tools. This creates a pathway for both local code execution and the installation of remote malicious servers, depending on the configuration. Security Implications For Developers The research highlights risks for developers, who often operate with elevated permissions and access sensitive assets such as API keys, credentials and source code. While no zero-click exploitation was observed, the reliance on user approval introduces a human factor that attackers may exploit. The study also noted that modern development workflows, particularly those involving AI tools, may condition users to accept prompts without thorough review. This behaviour increases exposure to deceptive installation requests that appear routine. Researchers recommend several mitigation strategies: Introduce verification mechanisms for trusted MCP sources Implement stricter permission controls for command execution Improve visibility into installation parameters Treat deeplinks from unknown origins with caution "The MCP ecosystem requires fundamental security improvements embedded directly into the framework architecture," Proofpoint wrote, "rather than relying on additional security tools or user vigilance as the primary defense." Proofpoint published its own proof-of-concept cod on . The researchers notified Cursor through its vulnerability‑reporting channel. Image credit: bella1105 / Shutterstock.com
infosecurity-magazine.comMar 17, 2026extracted
FBI Calls for Help to Track Steam Malware Campaign
The FBI is asking gamers who unwittingly downloaded malware from the popular Steam platform to help with its investigation. FBI’s Seattle Division issued a notice in mid-March as it continued in its search for the threat actor responsible for the malware campaign. “The FBI believes the threat actor primarily targeted users between the timeframe of May 2024 and January 2026,” it said. “In the investigation, several games have been identified to include, BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova.” The Feds called on any gamers impacted by the campaign to fill out a short form, or do so on behalf of any dependents in their household that may have been victimized. “The FBI is legally mandated to identify victims of federal crimes it investigates. Victims may be eligible for certain services, restitution, and rights under federal and/or state law,” the notice continued. “Your responses are voluntary but may be useful in the federal investigation and to identify you as a potential victim. Based on the responses provided, you may be contacted by the FBI and asked to provide additional information. All identities of victims will be kept confidential.” Asking the Right Questions Judging by the questionnaire attached to the public outreach note, the FBI wants to know from victims whether anyone communicated with them before or after downloading the game, and on what channel. Investigators also want to know whether the victim lost any money, and their crypto wallet or bank account details. Steam is a popular malware distribution channel for infostealers designed to steal personal information and digital money from victims. The platform is also a target for social engineering attacks impersonating its brand. A Guardio report from last year claimed that Steam was the most phished brand of Q1 2025 “by a significant margin.” Fake messages impersonating Steam warn users of payment failures or suspicious logins, but are actually an attempt to trick them into entering their credentials on phishing sites. Others claim the user has won a Steam gift card or similar and encourage them to click through on a malicious link. Image credits: Diego Thomazini / Thrive Studios ID / Shutterstock
infosecurity-magazine.comMar 16, 2026extracted
Loading 40 more…