Search/solarwinds
Vendor

solarwinds

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
storage profiler
Connections
211 relationships
Russian snoops add OAuth abuse to targeted phishing campaigns
Google is tracking three distinct suspected Russian cyber-spy groups that are targeting individuals in academia, aerospace, defense, government agencies, and think tanks across Europe and the US. The UNC (unclassified) groups, as Google calls them, have been orchestrating these highly targeted campaigns since at least last year, and they remain ongoing. Some of the phishing and OAuth-abuse operations used in the attack took place this month. Each campaign had fewer than 100 targets, and under 10 victims, the threat-intel team told The Register. Despite the small numbers, if you work in government, NGOs, academia, or aerospace, you may be a target, and over the past few months the Russian snoops have adapted their attacks to abuse legitimate authentication flows. This makes these types of social engineering tactics appear more legitimate – and allows the cyber operatives to compromise personal accounts across multiple platforms, Google warns. It also means that potential victims may not recognize these as phishing attempts. Google says it wants to raise awareness about these campaigns “so that targets can more readily recognize malicious outreach.” In other words: don’t blindly trust that calendar invite that purports to come from the US State Department. UNC6293 The security analysts have been tracking one of the three, UNC6293, for almost two years. UNC6293 is a suspected APT29 (aka Cozy Bear, which Google now tracks as Ice Relic – insert eyeroll) phishing squad that poses as US State Department employees to lure victims into giving the snoops long-term access to their email correspondence. APT29 is probably best known for the 2020 SolarWinds hack, and infosec analysts from the UK and US governments, and the private sector, often link it to Russia's Foreign Intelligence Service (SVR). On Thursday, Google’s Threat Intelligence Group (GTIG) said it's now tracking two other suspected Russian groups, UNC7005 and UNC5976, which also conduct phishing, abuse OAuth flows, and/or deploy malware to these same types of targeted individuals. Last summer, GTIG documented UNC6293 phishing for app passwords belonging to people who are critical of Russia. In this campaign, they impersonated State Department personnel, and they’ve continued using that lure while also adding OAuth phishing into their toolkit. “In June 2026, GTIG observed OAuth phishing where UNC6293 requested targets share either the full URL or ‘verification code’ after performing a legitimate login to an external provider,” Google threat analysts Gabby Roncone and Wesley Shields said in the Thursday report. “By providing the requested verification code the target would grant UNC6293 access to the account.” UNC7005 GTIG also asserts, with “moderate confidence,” that UNC7005 is another initial access group connected to APT29/Cozy Bear/Ice Relic – and the SVR. This crew, first identified in February, usually targets academia, diplomatic, and nonprofit personnel across Ukraine, Western Europe, and the US. While it shares similarities with UNC6293, Google tracks it separately “due to its lower sophistication and poor operational security, infrastructure with divergent characteristics, and incorporation of malware.” Reliaquest and Microsoft first sounded the alarm on this group - Redmond tracks UNC6293 as Storm-2945 - after spotting a campaign compromising captive portal networks to deliver infostealers, keyloggers, and other malware. The Russian intelligence operatives targeted users of public Wi-Fi networks at places like hotels, conference centers, and other shared venues in the hospitality sector in an AI-assisted operation that began in February. UNC7005 also enjoys device-code phishing for both Microsoft and WhatsApp accounts. Most recently, the phishing lures look like invitations to diplomatic events and conferences delivered via email with links to attacker-controlled websites. The crew also tends to reuse website templates. They did this in May, we’re told, re-using the website template from an operation that used the theme of an "embassy invite." The later campaign spoofed the real GLOBSEC forum - a geopolitical gabfest that focuses on Eastern Europe. Once victims visit the attacker-controlled website, the snoops fingerprint the victim’s system and prompt them to confirm their attendance at a conference. “The registration process is thorough, and notably contains an epicurean wine selection, which was a theme in multiple previous ICE RELIC-linked phishing campaigns,” the Googlers wrote. In May and June, UNC7005 carried out social engineering attacks spoofing WhatsApp and prompting the victim to either join a voice call, encrypted chat, or download a file. Joining the voice call triggers a malicious JavaScript that records audio and video of the target, which the malware uploads to the attacker’s command-and-control server. While Google doesn’t say how the Russians use the stolen images and audio, attackers can use both to help carry out convincing social engineering campaigns. Also in May, the goons conducted “a much broader phishing wave than any we had previously observed,” Roncone and Shields wrote. This one targeted prominent, mostly US-based academics, diplomats, and researchers whose work focused on Russia and former Soviet states. The miscreants’ website was more “elaborately built to social engineer the target,” with specific information about a resolution supporting Ukraine, plus contact details for general questions or tech support. Those contacts were a hotline to the attackers, not a helpdesk. When users click the button that, they believe, will download a “Summit Companion App” to read the full resolution, they inadvertently put infostealers on their own Mac OS and Windows devices. Since August, the same crew also started both Google and Microsoft account OAuth phishing operations using cloud infrastructure. UNC5976 Finally, UNC5976 is yet another suspected Russian cyberespionage group and again likes to steal OAuth tokens. GTIG began tracking OAuth-related activity from this crew in March 2026. In these campaigns, UNC5976 buys up several domains with names related to file sharing and then creates a cloud project related to the domain. The domains host a fake file sharing page that prompts users to “Continue with Google” via a popup link. The links takes them to a legitimate Google OAuth login page, asks them to sign in, and after authenticating the credentials redirects the victim to a Google Cloud project URL that saves the authentication token for the attacker. GTIG calls UNC5976 “distinct” from the other two initial access groups, and notes that this may indicate “differing strategic mandates and potential alignment with alternative Russian intelligence services.” It also uses dedicated infrastructure for post-compromise activity instead of residential proxies, plus more malware and tooling in its OAuth operations. ®
theregister.comAug 21, 2026extracted
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. Cybersecurity company ReliaQuest analyzed the web shell after it is believed to have been deployed in recent data theft attacks exploiting CVE-2026-12569, a critical remote code execution vulnerability affecting PTC Windchill. ReliaQuest says the implant is not a generic web shell repurposed for the attacks, but was instead built with detailed knowledge of Windchill's internal APIs, database schema, keystore, and file-vault structure. "This appears to be an application-specific evolution of Clop's established mass-exploitation playbook," ReliaQuest said in a report shared with BleepingComputer. The researchers say they found the web shell during the intelligence collection process. The researchers say the activity is likely linked to Clop based on extortion emails containing addresses used on the ransomware gang's data leak site, previously observed X-windchill-req headers also used in the web shell, and TTps commonly used by the threat actors. The Clop extortion gang has a long history of breaching enterprise platforms in data theft attacks, with previous campaigns targeting Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers, the latter affecting more than 2,770 organizations worldwide. As BleepingComputer reported in July, Clop targeted exposed PTC Windchill and FlexPLM servers in a data theft extortion campaign involving exploitation of CVE-2026-12569 and the deployment of JSP web shells. At the time, ReliaQuest said attribution was unconfirmed, but the attacks shared similarities with previous Clop data-theft campaigns targeting secure file-sharing applications. Ransom-ISAC later confirmed Clop activity associated with the attacks, including extortion emails sent to hundreds of employees at affected organizations and containing the gang's latest contact information. PTC began releasing fixes for CVE-2026-12569 on June 17, and CISA later added the vulnerability to its Known Exploited Vulnerabilities catalog following warnings of heightened threat activity. A web shell built specifically for Windchill Analysis by ReliaQuest and BleepingComputer confirms the tool was designed to target Windchill servers rather than act as a generic web shell. The malware is a JavaServer Pages (JSP) web shell that directly imports Windchill-specific classes, including MethodContext, WTConnection, and WTKeyStoreUtil. These classes allow the shell to use Windchill's own functions to access its database, decrypt stored credentials, and locate files stored in application vaults. "The web shell connects to Windchill's database through the application's own MethodContext and WTConnection classes, meaning its queries run under the application's existing database identity rather than through a separately configured attacker account," explains ReliaQuest. "As a result, database telemetry may attribute this activity to the application's normal service identity, limiting the value of alerts that rely solely on detecting new accounts or unexpected source hosts." The web shell is controlled using a custom protocol sent through the HTTP X-windchill-req header, which contains eight characters, with the first character specifying the command and the remaining seven matching a fixed value. The web shell supports the following commands: S – Steal Windchill secrets and configuration: Reads Windchill's LDAP configuration and uses the application's ownWTKeyStoreUtil.decryptProperty() function to decrypt the LDAP manager password and other encrypted application data. L – Map Windchill's file vault: Searches Windchill's database for filenames, storage paths, and file sizes. The results are written to a file namedflst.txt , which can then be retrieved by the attackers usingG command. D – Enumerate directories and retrieve files: Enumerates supplied paths and reads portions of files. G – Read a file: Retrieves the contents of a specified file. R – Delete a file: Deletes a specified file. J – Load and execute additional Java code: Passes a Base64-encoded ZIP archive and loads compiled Java bytecode directly into memory and executes it within the Windchill process. O – Identify the operating system: Returns the operating system name. E – Echo supplied data: Echoes data in theX-windchill-prm header to verify the webshell is responding. ReliaQuest says the web shell's vault enumeration is also designed specifically to query certain tables in Windchill's database. BleepingComputer's analysis shows that these tables are ApplicationData, FVITEM, FVMOUNT, and MasteredOnReplicaItem. The cybersecurity company recommends that organizations immediately patch vulnerable Windchill systems and look for unusual JSP files in Windchill directories, especially those containing reference to X-windchill-req. Organizations that suspect their Windchill servers were compromised should also change the LDAP manager password and other Windchill credentials, as they should be considered compromised. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 18, 2026extracted
Security Hub Extended adds Supply Chain Security as its tenth category
Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted a partner reception that brought our leadership together with partner executives to plan what comes next. These are companies investing real engineering and real go-to-market (GTM) alongside us, and increasingly with each other, because the model resonates with the customers they’re talking to every day. The most common question we heard at the booth was when Supply Chain Security was coming. It’s here. And that’s the thing I want to spend the most time on today, because it’s the category customers keep asking us about. Supply Chain Security: The category customers have been asking for Software supply chain risk has moved from a security-team concern to a board-level conversation. SolarWinds showed what happens when a build system is compromised. Log4j showed what a single transitive dependency vulnerability can do at global scale. The xz utils backdoor showed the patience of a maintainer-compromise attack executed over years. Each demonstrated a different dimension of the same problem, and the pace is accelerating. Attackers know that a fast way into an enterprise is through the open source packages that enterprise unknowingly trust. Every customer I talked to at Black Hat had this on their risk register. Most still hadn’t operationalized a solution, because doing so meant a standalone deployment, a new contract, a new console, and integration work their security team couldn’t prioritize. That’s the friction we aim to remove. Security Hub Extended now offers Supply Chain Security with Chainguard and Socket as the curated partners. Supply Chain Security uses the same model as everything else in Extended. Every offering has pay-as-you-go pricing, one bill, no required long-term commitment. For enterprises that prefer to continue using the procurement process they always have, Security Hub Extended Private Offers are also available. These are committed term agreements with deeper discounts, the ability to aggregate spend across partners on a single AWS bill, and both monthly and annual payment options throughout the term. You pick the path that fits how you buy. What Chainguard does Chainguard gives you open source dependencies rebuilt from source in a hardened, verified build process, so what enters your environment is malware-resistant and provenance-backed. Their research shows that rebuilding from source would have stopped 98% of known malicious packages from ever reaching production. If you can’t verify the source, it never appears in the Chainguard repository. That’s the filter between the public registry and your developers. What Socket does Socket analyzes the actual behavior of open source packages to block malicious dependencies at the time of install. Not after a Common Vulnerability and Exposures (CVE) is published days or weeks later. At the moment the package tries to land in your environment, Socket flags it based on what it does, not what a database says about it. Its reachability analysis then tells you which vulnerabilities are exploitable from your code instead of drowning your team in noise. You pay for the distinct packages you check, not for how often your builds run. Why they work together Together, Chainguard and Socket cover the two questions that matter: Can I trust what I’m pulling in? Can I stop malicious components before they get built into my applications? Chainguard helps secure the foundation your code is built on. Socket secures the packages you pull into it. Both help protect your software supply chain regardless of where you deploy—across clouds or on-premises. Activate both through Security Hub Extended and their findings flow into Security Hub in OCSF (Open Cybersecurity Schema Framework) alongside everything else, so a supply chain risk is correlated and prioritized next to your endpoint, identity, and cloud signals. From there, it routes out to the downstream tools you’ve already integrated, so it fits the pipeline your builders run today. 23 partners, 10 categories. Built on what customers asked for Every partner in Security Hub Extended is here because customers told us they needed that capability and that specific solution was already working for them. We add categories because the threat landscape evolves, and we add partners because customers point us to who’s solving those problems well. The goal is straightforward: Simplify adopting the security solutions your peers are already succeeding with, through the AWS relationship you already have. The full set today spans endpoint, identity, email, network, data, browser, cloud, AI, security operations, and now supply chain. The 23 curated partners are 7AI, Britive, Chainguard, CrowdStrike, Cyera, Island, LayerX, Native Security, Noma, Okta, Oligo, Opti, Palo Alto Networks, Proofpoint, SailPoint, SentinelOne, Socket, Splunk, Sublime, Upwind, Varonis, Zenity, and Zscaler. Our focus now is deepening integrations and reducing activation friction so these solutions work together, not in isolation. That’s where the real value compounds. What we’re building next Everything I’ve described so far is the commercial model working: Customers buying best-of-breed security through one AWS relationship with the flexibility they expect. But the bigger vision is the integration layer that makes these tools genuinely better together, not just easier to buy together. The integration we’re most focused on is cross-partner correlation, turning signals from an endpoint solution, an identity solution, and a cloud solution into one exposure and one attack path instead of three disconnected alerts. Right alongside that, we’re dramatically reducing the activation, deployment, and integration friction so customers go from subscribing to seeing value in hours rather than weeks. Both efforts enable the curated solutions you already trust to deliver stronger outcomes together than they do apart. That’s the build we’re accelerating with our partners now, and you’ll hear more leading into re:Invent. Explore what’s available If you’re running open source in production and don’t yet have supply chain visibility, start there. Activate Chainguard and Socket through the Security Hub console today. If you’re managing multiple security vendor relationships and want to understand what consolidation looks like with Security Hub Extended, talk to your AWS account team. Pricing for every partner is published on our pricing page , no sales call required. And if you’re already using Security Hub for posture management and threat detection, the Extended plan is available in the same console you already use. We’re just getting started. If you have feedback about this post, submit comments in the Comments section below. Michael Fuller Michael has been with AWS for 16 years and led product for AWS Security Services for 11 years. Michael has 29 years in the industry and held several roles in product management, business development, and software development for IBM, Cisco, and Amazon. Michael has a Bachelor’s of Science in Computer Engineering from the University of Arizona and an MBA from the University of Washington.
aws.amazon.comAug 18, 2026extracted
Philips and GE investigating Clop ransomware data theft claims
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. While a GE spokesperson said the company is aware of the claim and is "working to assess the potential issue," a Philips spokesperson confirmed its systems were breached but said the incident has been contained and didn't affect customers. "Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data," Philips said in a statement shared with Reuters. "This has no impact on customer environments." GE and Philips spokespersons have yet to reply after BleepingComputer also reached out to them for more details and to confirm the Clop ransomware gang's claims. This comes after oil giant Shell also said on Friday that it is investigating a potential security incident after the Clop hacking group claimed it stole 89GB of data. "We are aware of a potential incident," a Shell spokesperson told BleepingComputer when asked to confirm the gang's data theft claims. "We are working with our security teams and relevant experts to investigate. While the three companies have yet to share more information, the Clop gang has listed them on its leak site as part of a batch of 43 new victims likely targeted in data theft attacks exploiting a critical improper input validation vulnerability (tracked as CVE-2026-12569) against Internet-exposed PTC Windchill and PTC FlexPLM instances. PTC says the two enterprise software platforms are widely used by high-profile companies across the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. The company says more than 30,000 customers globally use its products, including over 1,500 brand and retail customers using FlexPLM. In these attacks, Clop claims it stole a wide range of sensitive data from the companies' compromised systems, including backups, project plans, photos of facilities, drawings, diagrams, blueprints, and more, belonging to Shell, GE, and Philips. PTC began releasing CVE-2026-12569 security patches on June 17 and urged customers to review environments for indicators of compromise (IOCs) in a private advisory, even though there was no confirmation of in-the-wild exploitation. Since then, cybersecurity company ReliaQuest and the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) have confirmed Clop's Windchill and FlexPLM attacks, in which the threat actors have been deploying JSP webshells to steal sensitive data from victims' compromised PLM platforms. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also confirmed that the flaw is actively exploited in attacks after PTC warned of "heightened threat activity" on June 26, mandating federal agencies to secure their PTC Windchill and FlexPLM instances within three days after adding it to its catalog of known exploited vulnerabilities. This vulnerability has also prompted emergency action from German authorities, with the Federal Office for Information Security (BSI) warning PTC customers in the middle of the night to patch systems as quickly as possible. The Clop extortion gang has a long history of targeting enterprise platforms in data theft attacks, breaching Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers in previous campaigns, with the latter affecting over 2,770 organizations worldwide. Starting in early August 2025, it also began exploiting an Oracle EBS zero-day flaw to steal sensitive files from many organizations. The list of victims includes many high-profile organizations worldwide, including The Washington Post, GlobalLogic, Harvard University, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air. The U.S. Department of State now offers a $10 million reward for any information linking the cybercrime gang's attacks to a foreign government. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 17, 2026extracted
N-able warns of N-central auth bypass flaw exploited in attacks
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. The company on Sunday released hotfix 2026.3.1.7 to address the security issue, which affects all versions of N-central before 2026.3. On August 1st, the vendor disclosed that it detected active exploitation and launched an investigation that uncovered additional security concerns affecting all versions of N-central, its flagship Remote Monitoring and Management (RMM) platform. In an update the next day, the company announced the hotfix and strongly recommended all customers to upgrade immediately to the new release. Hosted deployments already received the update, while customers of on-premises instances need to install it manually. N-central is a remote monitoring and management (RMM) platform used by managed service providers (MSPs) and corporate IT departments to manage large clusters of multi-OS systems and network devices. Because of this, compromising these servers allows threat actors to extend the attack beyond N-able’s direct customers. The product was also targeted last year, in zero-day attacks that prompted CISA to issue an urgent alert. In the past, threat actors compromised other notable RMM/MSP platforms, including Kaseya VSA, ConnectWise ScreenConnect, SimpleHelp, and SolarWinds Orion. CVE-2026-18577 is the result of an incomplete patch for CVE-2026-18576, a vulnerability described as an “authentication bypass using an alternate path or channel, which affected all N-central versions through 2026.1. Both vulnerabilities could be exploited for administrative account takeover. N-able has not shared any technical details about the security issue or provided information about the number of customers targeted or compromised through CVE-2026-18577. The vendor provided indicators of compromise on the hotfix download page, including four specific IP addresses, a registered service named ‘Cloudflared,’ and ‘svchost.exe’ in the users’ documents folder. If any of these are found, customers are advised to contact N-able support immediately and engage their own security team. It should be noted that attackers frequently abuse Cloudflared, the legitimate tunneling utility from Cloudflare, to create outbound tunnels that expose compromised machines or provide remote access without opening inbound firewall ports. The vendor also says that agents do not need immediate updates to mitigate CVE-2026-18577, but the action is recommended to get the latest fixes and features. N-able’s status update “strongly recommends” that customers remain vigilant and monitor their environments closely, while the company also promised to share more updates as quickly as possible. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 3, 2026extracted
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from forum chatter to real targets. The full weekly recap report follows. ⚡ Threat of the Week Anthropic Disclosed its Models Targeted 3 Organizations - Anthropic revealed that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "large-scale retrospective review" in response to the recent Hugging Face incident. "After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations," it said. Mythos: Map Attack Paths to Collapse Lateral Breach Routes Access the Gartner® CTEM report to see how the Mythos platform continuously maps cross-domain attack paths and isolates key choke points to break active lateral movement to critical assets. Get the full report ➝ 🔔 Top News Coldcard Hardware Wallet Flaw Linked to $88.6M Bitcoin Theft - A vulnerability in Coldcard hardware wallet firmware is said to have been exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seed phrases were generated using a flawed random number generator. "Coldcard firmware contains an RNG integration error that causes ngu.random to use MicroPython's deterministic Yasmarang fallback instead of the STM32 hardware RNG," Square Engineering said. "This does not mean every remote attacker can immediately recover every seed. Practical cost depends on available UID information, boot timing, prior RNG calls, and derivation cost." Russian Hackers Exploit Microsoft OWA Flaw to Maintain Mailbox Access - Russian threat actors exploited a security flaw in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. The activity has been attributed to Laundry Bear. The new wave of exploitation revolving around CVE-2026-42897 culminates with the deployment of a previously unknown JavaScript browser-based implant codenamed OWAReaper that's specifically built for persistent access within Microsoft's webmail client. Critical Rails Flaw Leads to Arbitrary File Read - Ruby on Rails shipped patches for a critical Active Storage vulnerability (CVE-2026-66066, CVSS score: 9.5) that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. The flaw can be exploited to expose Rails process environment and secrets such as secret_key_base, master key, database passwords, cloud storage credentials, and API tokens, which may enable remote code execution or lateral movement into connected systems. CVE-2026-66066 is exploitable when libvips is used, enabling an attacker to upload a specially crafted image to a vulnerable application and read arbitrary files on the server. A key prerequisite for the attack is that the server must allow image uploads from untrusted users. Additional details of the flaw have been released by the Rails team, along with tools to help assess vulnerable applications. "Because this vulnerability requires no authentication and targets the default image processor in modern Rails environments, it is essential to apply vendor patches and rotate secrets immediately," Akamai said. Coordinated Attacks Target 30+ Minnesota Water Systems - A coordinated cyber attack campaign targeted over 30 water systems in Minnesota on July 26 and 27, 2026. "The nature and extent of the impact varied by system, and the investigation is still determining how many experienced operational disruptions," Minnesota IT Services (MNIT) said. The activity has not been officially attributed to any known threat actor, although Iranian threat actors have been previously implicated in similar attacks targeting water facilities in the U.S. "At this time, there are no active requests from Minnesota communities for residents to modify their drinking water use," MNIT added. The development has prompted the U.S. government to issue an advisory, urging "critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible." Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses, resulting in boil water notices and sustained manual operations. Organizations are advised to disconnect the PLC from the internet, enable password protection and change default passwords, and allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets. Censys said it identified 4,148 internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley, with more than 70% of them located in the U.S. Similarly, there are 4,117 internet-exposed hosts that fingerprint as Siemens SIMATIC S7-1200 and 2,072 internet-exposed hosts that fingerprint as Schneider Electric hardware. Over the weekend, Michigan reported cyber attacks on nine of the state's water systems but an official told Associated Press that all systems were operating "safely." The campaign underscores the escalating threat to poorly protected operational technology (OT) assets from adversaries seeking to disrupt critical infrastructure services across the U.S. and elsewhere. Hijacked Wi-Fi Networks Lead to CornFlake Malware - Storm-2945, a sub-cluster associated with Midnight Blizzard (aka APT29), has been conducting "widespread but targeted traffic manipulation attacks" involving hospitality sector networks served by captive portals across the world. The campaign, ongoing since May 2026, has been codenamed CaptiveCrunch by Microsoft. This involves manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. "As part of the CaptiveCrunch campaign, Storm-2945 has leveraged their AitM position to redirect users through actor-controlled phishing infrastructure and has also delivered malware purporting to be browser or operating system updates in response to automated connectivity checks issued by users' browsers," Microsoft said. This includes a fully-featured Windows remote access trojan (RAT) called CornFlake with capabilities to conduct system enumeration, collect files and keystrokes, steal credentials and session tokens, conduct audio and video surveillance, monitor for removable media, and provide the threat actor a remote shell on infected systems. Also delivered via the trojan is a PowerShell-based infostealer called ChocoShell to harvest browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials from compromised systems. The campaign is orchestrated via a web-based C2 panel called FruitStone. The infrastructure employs a variety of ClickFix techniques to trick the victim into downloading and executing the malware. There is also evidence indicating that the attackers are using similar ClickFix landings for Android devices to download and install an APK file. As of July 16, 2026, a portion of CaptiveCrunch landing pages have been found to redirect users to device code authentication flow experiences. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-48449 (Adobe Campaign Classic), CVE-2026-18556, CVE-2026-18577 (N-able N-central), CVE-2026-44827, CVE-2026-45804, CVE-2026-44513 (Hugging Face Diffusers), CVE-2026-17583 (Thermo Fisher Scientific), CVE-2026-66066 (Rails), CVE-2026-10702 (Mozilla Firefox), CVE-2026-60004, CVE-2026-58443 (Gitea), CVE-2026-63077, CVE-2026-59792, CVE-2026-59793, CVE-2026-59794, CVE-2026-59795, CVE-2026-59796 (JetBrains TeamCity), CVE-2026-61511 (vBulletin), CVE-2026-53264 (Linux Kernel), CVE-2026-53921 (OpenWrt), CVE-2026-64765, CVE-2026-64766, CVE-2026-64764, CVE-2026-64763, CVE-2026-43776, CVE-2026-43818, CVE-2026-28981 (Apple iOS and macOS), CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 (libssh2), from CVE-2026-59686 through CVE-2026-59690 (Progress Kemp LoadMaster), from CVE-2026-66036 through CVE-2026-66041 (FFmpeg), CVE-2026-66398 (phpMyFAQ), CVE-2026-64645, CVE-2026-64649, CVE-2026-64642, CVE-2026-64641 (Next.js), CVE-2026-13385 (ASUS), from CVE-2026-16804 through CVE-2026-16807 (Google Chrome), CVE-2026-52824 (Kimai), CVE-2026-53565, CVE-2026-53566 (Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows), CVE-2026-9770, CVE-2026-13230 (TP-Link Kasa EC70 v4 and EC71 v4 smart cameras), CVE-2026-15682 (AnyDesk), CVE-2026-53481, CVE-2026-53483 (Dell PowerProtect Data Domain), CVE-2026-52886, CVE-2026-54758, CVE-2026-57233 (Notepad++), CVE-2026-57807 (miniOrange OAuth Single Sign On - SSO WordPress plugin), CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321 (SolarWinds Serv-U), CVE-2026-16771 (AT&T Arris BGW210-700), CVE-2026-13723 (Develar), CVE-2026-16637 (OPeNDAP Hyrax), CVE-2026-15969, CVE-2026-15971, CVE-2026-15974, CVE-2026-15976, CVE-2026-15977, CVE-2026-15978 (SGLang), CVE-2026-15657, CVE-2026-15658 (foreUP), CVE-2026-16503, CVE-2026-16504 (VPS.org), CVE-2026-48395, CVE-2026-48396 (Adobe Bridge), CVE-2026-5674 (PipeWire PulseAudio), CVE-2026-34909 (Ubiquiti UniFi OS), and CVE-2026-17059 (keycloak-services). 🎥 Cybersecurity Webinars AI Can Build Exploits in Minutes. Can Your Security Team Keep Up? → AI is collapsing the time between vulnerability disclosure and attack. Advanced models can now uncover flaws, generate working exploits, and chain them into complete attack paths at machine speed. This webinar presents a practical framework for gaining the visibility, context, and response speed needed to investigate and stop threats before attackers pull ahead. How to Control the Open-Source Security Debt Created by AI Coding Tools → Learn how AI coding tools are expanding unvetted open-source use, accelerating vulnerability backlogs, and weakening existing governance. This webinar shows how to measure the resulting remediation debt, connect it to breach, audit, and productivity risks, and identify which governance models can contain it without slowing development. 📰 Around the Cyber World Now-Patched Gitea Flaw Detailed - NoScope shared additional technical details of a security flaw in Gitea (CVE-2026-27771, CVSS score: 8.2) that was patched back in May 2026. The vulnerability allowed unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials. "Gitea's container registry implements the OCI Distribution Specification, which authenticates clients with a bearer token issued by a dedicated token service. On affected versions, that token service issued a valid, signed JWT to requesters presenting no credentials at all," NoScope said. "The token was honest about what it represented, carrying UserID: -1 and an empty Scope, but no registry read endpoint ever consulted those fields. Catalog listing, tag enumeration, manifest retrieval and blob download all accepted it. Any unauthenticated party on the internet could enumerate every container repository on an instance, including those marked private, and pull their layers." SQLite Critical CVEs or AI Slop? - JFrog said it uncovered a set of SQLite CVEs (CVE-2026-51302, CVE-2026-51303, CVE-2026-51300, CVE-2026-51297, CVE-2026-51296, and CVE-2026-51304) that seem to be instances of AI-generated slop making their way into official vulnerability feeds and receiving critical severity scores before technical validation. The analysis found that the advisories referenced functions that didn't exist in the affected SQLite versions, cited incorrect or impossible source code locations, included PoCs that failed to reproduce any vulnerability, and, most importantly, were not listed on SQLite's official CVE page. The findings show that organizations must take steps to distinguish legitimate vulnerabilities from questionable or AI-generated vulnerability reports before initiating unnecessary remediation, patching efforts, or automated security workflows. LegacyHive Flaw Detailed - LevelBlue published a technical breakdown of LegacyHive, a PoC released by Chaotic Eclipse (aka Nightmare-Eclipse) last month coinciding with the release of Microsoft's Patch Tuesday update. The vulnerability is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading Windows user profiles. On exploitation, LegacyHive can allow attackers to load other users' hives and gain access to application data and Windows Explorer history, among others. "For EDR platforms with visibility into native Windows APIs, the strongest signals are user-mode invocations of NtCreateDirectoryObjectEx and NtCreateSymbolicLinkObject," LevelBlue said. "These functions are rarely used outside system components, debugging tools, or specialized research utilities. Seeing both from the same process should immediately warrant investigation. Even without NT API telemetry, LegacyHive leaves a distinctive execution chain. The attack combines offline access to ntuser.dat or UsrClass.dat, modification of registry hives through Microsoft's Offline Registry API, batch oplock requests, and CreateProcessWithLogonW using LOGON_WITH_PROFILE. Each operation is legitimate in isolation but observing them together within a short time window is highly unusual and well suited for behavioral correlation by EDR and SIEM platforms." Chinese Military Taps Into U.S. Models - According to a new report from Reuters, Chinese military researchers have distilled cutting-edge models developed by U.S. companies OpenAI and Anthropic to train domestic AI systems to advance the country's defense capabilities. The report was based on a review of more than 80 Chinese academic papers and patents. Exposed Police Dashboard Lays Bare How China Tracks Foreigners - An internet-exposed police dashboard named "Dynamic Control Platform for Overseas Personnel" has revealed how law enforcement agencies in the country track over 700 foreigners, including those in the northern Chinese city of Zhangjiakou. "In total, it had entries for nearly 12,000 people, which included fugitives, people from Hong Kong and Taiwan, as well as more than 300 foreign journalists," The New York Times reported. "Some of them had not been to Zhangjiakou." The dashboard displayed entries about people grouped by nationality, with their birth date, sex, marital status, address and occupation, and sometimes their religion. The leak was discovered by security researcher and journalist Marc Hofer. The system is believed to be developed by a Beijing company named Origin Dynamic, which filed a patent application in 2023 for a similar "information interface for non-Chinese citizens." The Problem of DangleGeddon - Cybersecurity researchers have once again warned of the risks posed by dangling DNS infrastructure across government, banking, automotive, manufacturing, and pharmaceutical sectors. A dangling DNS record is an active Domain Name System entry (DNS) that points to a resource no longer owned, used, or controlled by the original organization. This typically occurs when web applications, cloud storage, or virtual servers are deleted without first removing their corresponding CNAME or A records from the domain registrar. An attacker can leverage this behavior to claim that abandoned cloud service name or IP address, effectively hijacking a trusted subdomain. This, in turn, can permit the attacker to host malicious content and serve phishing pages or malware, inflict reputational damage by abusing the trusted brand's subdomain, steal user credentials to create convincing phishing pages that appear to be legitimate services, perform cookie theft, and bypass security controls if the legitimate brand's subdomain is allowlisted in security tools. In one case analyzed by Silent Push, an unspecified automotive company left a dangling DNS record pointing to a developmental application gateway hosted by an Azure virtual machine (VM). "This device can potentially be operationalized and passively receive stored XSS from internal scripts and API calls," it said. "Developers' credentials, like API keys and authentication headers, could be harvested for reuse to expand access into the company. In addition, the VM could serve as a platform for malware hosting with the coveted TLS lock." Microsoft Teams Vishing Leads to Chaos Ransomware - A Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 has used a "consistent set of IT-themed cloud domains and personas to gain remote access to victims' systems" between February and June 2026 in attacks targeting dozens of North American organizations. "Following initial access, STAC4749 operators deployed a modular post-exploitation toolset, including a custom loader and backdoor to maintain persistent, controlled access and support follow-on activity," Sophos said. "In several incidents, attackers later leveraged this access to deploy Chaos ransomware." IAB Uses Teams Phishing for Ransomware Attacks - A suspected initial access broker (IAB) for ransomware attacks has been observed using Teams vishing that convinces victims to launch a Quick Assist remote support session. The initial access is used to run PowerShell scripts to gather host information and deploy a Go-based backdoor dubbed GoGRPC. Four different versions of the backdoor have been spotted: Lep, Giver, Pet, and Kind. "These variants have overlapping capabilities but notable implementation differences," Zscaler said. "GoGRPC is actively evolving. Each variant modifies its payloads and capabilities, adding or removing functionality to better support the threat actor's objectives. Recent changes indicate an increased targeting of corporate environments, which may be tied to ransomware attacks." In some instances, the threat actor has also deployed a backdoor called BlindDoor, a Go-based reverse SOCKS proxy known as RevSocket, and a Python-based reverse SOCKS proxy referred to as PyGRPC. Arch Linux Disables AUR Package Adoption Amid Malware - Arch Linux has taken the step of temporarily disabling package adoption due to a surge in malicious takeovers of existing packages. "Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation," the maintainers said. "We will send a follow-up once we're able to. In the meantime, feel free to report suspicious adoption events or commits that haven't been dealt with yet, and stay vigilant!" In June 2026, a separate campaign targeted AUR via more than 400 packages. New Dolphin X Infostealer Spotted - A new infostealer called Dolphin X uses an AI behavioral profiler to score and prioritize infected users based on their application usage, browsing activity, and installed software to identify high-value victims and maximize profits. The malware targets more than 300 applications and attempts to exfiltrate browser passwords, cryptocurrency wallets, SSH keys, and cloud tokens. Dolphin X has been advertised on the cybercrime underground by a vendor using the alias Kontraktnik since May 2026. A lifetime subscription ranges from $1,140 for basic access to $3,420 for the full-featured version. "A single archive can contain data from nine browsers, more than 100 wallet extensions, 65 desktop wallets, 10 password managers, and 30 cloud command-line tools," Varonis said. "This gives the malware potential access to everything from a victim's personal accounts to the credentials used to manage their employer's cloud environment." Attackers Turn to Microsoft's Trusted Login System for Phishing - Bad actors are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft's legitimate authentication infrastructure in phishing attacks, allowing them to bypass security controls. Check Point said it identified more than 200 phishing emails targeting users across approximately 120 organizations worldwide between June 25 and the second week of July 2026. "The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page," it said. "Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft's trusted authentication flow while concealing its malicious intent." FBI Arrests Man Accused of Using Steam Games to Drain Victims' Crypto Wallets - The U.S. Federal Bureau of Investigation (FBI) arrested Zyaire Wilkins, a 21-year-old Florida resident and student, of uploading fake video games that contained malware to Steam that, when downloaded and installed by unsuspecting gamers, stole their passwords and other valuable data, and drained their cryptocurrency wallets. Per the FBI, Wilkins and his accomplices are alleged to have infected around 8,000 victims, and then hacked around 80 cryptocurrency wallets to steal at least $220,000 worth of cryptocurrency. Turning Keystroke Noise to Text - A new study from a group of academics from Tohoku University has demonstrated a new acoustic side-channel attack that can reconstruct text typed on a laptop by just analyzing the sound of keystrokes. While prior attacks relied on collecting labeled recordings from the target keyboard beforehand or required specialized hardware, the latest eavesdropping attack enables stealthy eavesdropping in two real-world scenarios, including physical spaces (public and semi-public) and online meetings. The system works by first isolating individual keystrokes from an audio recording, grouping similar sounds together, and then using a Transformer-based language model to determine the most likely sequence of characters. "Our method combines unsupervised acoustic clustering with Transformer-based language model inference and iterative self-training, enabling stable character inference under highly uncertain acoustic-to-character mappings," the researchers said. "We demonstrate that the proposed method achieves over 99% reconstruction accuracy with only 100-150 observed keystrokes under a close-proximity recording setup using a smartphone placed near the target device, significantly outperforming prior unsupervised baselines in low-data regimes." Two Open-Source Software Supply Chain Attack Campaigns - Socket has flagged a fake corepack.org site that's impersonating Corepack, a Node.js tool for managing package managers, and using it as a lure to deliver an infostealer and proxyware to developers who download it. "The site has existed in some form since early 2026 as a low-quality, apparently AI-generated imitation, but it recently started serving executable downloads," Socket said. "Corepack is not distributed as a Windows installer, and the real project has no official website at corepack.org. Any download offered there should be treated as malicious." It's assessed that the site is AI-generated. In a related development, JFrog identified a massive set of 148 npm packages that are disguised as student web proxies, but hide mutable remote code execution vectors and a high-performance Wisp-compatible WebSocket traffic generator. "They were designed to silently enlist visiting browsers into distributed denial-of-service botnets while generating aggressive popunder advertising revenue," it said. Some aspects of the campaign were highlighted by SafeDep in late May 2026. AI linked to more than half of cybercrime in Africa - A new report from INTERPOL has found that AI is enabling 55% of reported cybercrimes across Africa, making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect. This encompasses digital sextortion and online harassment, as well as sophisticated business email compromise (BEC) schemes. "The absence of real-time, inter-agency data sharing between banks, telecoms and law enforcement creates a dangerous blind spot in efforts to combat financial fraud," INTERPOL said. "This vulnerability is being exploited by criminals who have moved beyond simply stealing existing credentials to creating entirely synthetic identities. Combining real personal data with fabricated elements, these AI-generated digital personas can bypass even advanced biometric verification systems and have been used to open bank accounts, secure mobile loans and register SIM cards under false names." Security Risks of Exposed MCP Servers - Google-owned Wiz has warned that enterprises are exposing Model Context Protocol (MCP) servers to the internet, with some of them returning full tool catalog to an anonymous caller, fetching real data, and revealing a sensitive backend. "These expose sensitive data like employee PII and internal business records, write and delete operations on production systems, and in some cases code execution and access to cloud credentials," Wiz said. "The protocol's first widely-used version shipped without an authentication mechanism. The spec added OAuth 2.1 in March 2025, but nearly all the servers we found still run the original version and don't use it. The pattern is the same across most of them: backend credentials baked into the deployment, a managed cloud endpoint that's internet-reachable by default, no auth layer added on top." Nuclear-Sabotage Malware Benchmark Trick Most Frontier AI Models - A multi-stage reverse-engineering benchmark developed by SentinelOne tests "whether a model can keep a malware investigation trustworthy as new evidence repeatedly invalidates its earlier conclusions," in contrast to other AI benchmarks that test bounded tasks. Developed based on its own analysis of the Fast16 malware, the study found that "OpenAI's GPT-5.6 Sol was the only publicly available model to complete the full eight-stage investigation, giving concrete shape to what 'Frontier-class' capabilities offer analysts." That said, humans remain essential to define objectives, expose blind spots, and retain final publication authority. An Open Directory Reveals NGINX Rift and Ghost CMS Exploits - An exposed directory on a Singapore-hosted VPS, 165.154.236[.]93, has been found to stage exploits for NGINX Rift (CVE-2026-42945), a long-standing heap overflow, and a blind SQL injection in the Ghost Content API (CVE-2026-26980), alongside Splunk, PaperCut, Samba, WebLogic, and D-Link NAS tooling. "The recovered shell history from the directory recorded the attacker running the exploits against live external infrastructure, using out-of-band (OOB) DNS callbacks to verify execution, and using the same server to catch reverse shells," Hunt.io said. "Alongside the web exploits were a broader RCE toolkit and pre-staged install files for AdaptixC2 and SuperShell. The target list spanned eleven countries across five continents and leaned heavily toward high-value sectors: federal and state government, universities, healthcare and financial services." The activity is believed to be the work of a Chinese-speaking threat actor. CISA Issues Guidance to Isolate Vital Systems and Manage OSS Risks - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued guidance to help critical infrastructure operators protect essential services from growing cyber threats and ensure continuity of operations during cyber incidents or geopolitical crises by maintaining robust isolation and recovery plans. "State-sponsored cyber actors target critical infrastructure for several nefarious reasons such as espionage or service disruption, often linked to broader geopolitical conflicts," CISA said. "During crises or conflicts, operators of critical infrastructure and network defenders may isolate essential operational technology (OT) systems as an emergency measure to prevent adversaries from executing cyberattacks, to contain ongoing threats, and to facilitate the restoration of compromised systems." The agency has also outlined considerations and best practices for federal entities to securely use, evaluate, and publish open-source software. "The guidance urges agencies to obtain sufficient transparency into all relevant components, including training data, of the AI system before deeming the product as OSS for risk management purposes," it said. "Only with transparency and access can agencies understand and study the software, analyze it for vulnerabilities, and remediate any found vulnerabilities or risks." RubyGems Cryptojacking Campaign - A set of 199 malicious gems published to RubyGems has been found to embed an identical XMRig cryptojacking payload to mine Monero cryptocurrency on developer systems. "Each gem is a trojanized copy of a popular, legitimate Ruby library," Palo Alto Networks Unit 42 said. "The payload uses a 5-hour delayed Thread.new{sleep 18000; ...} trigger to evade sandbox analysis." In addition to taking steps to achieve persistence via multiple methods, the malware uses SSH for lateral movement and is capable of infecting other ecosystems, including Node.js, Python, Docker, Git, and VS Code extensions. Mend.io, which also shared details of the campaign, said the payload is hidden inside a dotfile (lib/.threadpool.rb) that standard directory scans skip by default. Email Threat Landscape in Q2 2026 - Microsoft said phishing volume linked to the Tycoon 2FA phishing platform, including QR code phishing and CAPTCHA-gated phishing, fell 92% from pre-disruption averages in the second quarter of 2026 between April and June. However, the tech giant said it "observed continued growth in Teams-based social engineering, particularly voice phishing (vishing), with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter." Microsoft said it detected approximately 7.6 billion email-based phishing threats throughout the quarter, with monthly volumes declining modestly from 2.7 billion in April to 2.4 billion in June. HTML and PDF attachments remained the two most common malicious payload types across the quarter, together accounting for roughly 60-70% of all payload-based attacks each month. In early June 2026, Microsoft said it detected a large-scale BEC campaign that reached more than 67,000 users across more than 42,000 organizations in under three hours, most of them in the U.S., with an aim to redirect salary payments to attacker-controlled bank accounts. 🔧 Cybersecurity Tools EMBA → Firmware is where critical bugs hide longest because it is opaque, fragmented, and painful to inspect manually. EMBA turns that black box into an actionable security report: it extracts embedded-device firmware, runs static and emulation-based analysis, builds an SBOM, and flags outdated components, insecure binaries, vulnerable scripts, and hard-coded credentials through a command-line workflow with web-based reporting. Built for penetration testers, product-security teams, and developers, it compresses days of firmware triage into a repeatable open-source process. GrantGuard → Every "always allow" click in Claude Code can leave behind a standing permission that remains long after the task ends, with pasted API keys, credential-store access, unrestricted git push, or destructive commands buried in rarely reviewed settings. GrantGuard is an open-source, local-only tool that finds these accumulated grants, classifies them by risk, and lets users remove unsafe permissions through a browser interface or CLI, without sending settings off-device or loading third-party runtime packages. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law. Conclusion The useful question is not whether a system is exposed. It is which quiet assumption lets it reach farther than intended: a default, a trusted workflow, an abandoned endpoint, or code nobody checked. That is where the next incident is probably waiting. Not in the loudest alert, but in the handoff everyone assumes belongs to someone else. Check the boundaries. Then check what crosses them.
thehackernews.comAug 3, 2026extracted
NCSC-2026-0265 [1.00] [M/H] Kwetsbaarheden verholpen in SolarWinds Serv-U
SolarWinds heeft meerdere kwetsbaarheden verholpen in Serv-U. De kwetsbaarheden in SolarWinds Serv-U betreffen voornamelijk insecure direct object reference (IDOR) en broken access control. Deze maken het mogelijk voor aanvallers met bepaalde privileges, zoals domain administrator of group administrator toegang, om privileges te escaleren naar system administrator of root-niveau. Hierdoor kunnen zij op afstand willekeurige code uitvoeren en systeembeheerrechten verkrijgen. Sommige kwetsbaarheden maken het ook mogelijk om SMTP-sessies te kapen, accounts over te nemen, of persistent cross-site scripting (XSS) uit te voeren die sessies van beheerders kan compromitteren. De impact van deze kwetsbaarheden is op Windows-omgevingen doorgaans minder groot dan op andere platformen. Exploitatie vereist meestal dat de aanvaller al beschikt over geauthenticeerde toegang met hoge privileges, zoals domain administrator rechten. De verholpen kwetsbaarheden betreffen zoals gezegd overwegend kwetsbaarheden die kunnen worden misbruikt in zo genaamde 'Evil Admin'-scenario's. Dit soort kwetsbaarheden zijn doorgaans niet eenvoudig te misbruiken door ongeathenticeerde kwaadwillenden op afstand. Echter zijn er in deze updates dermate veel verholpen dat het aan te raden is om, naast het inzetten van de updates, te controleren hoe de rechtenstructuur is geïmplementeerd. Dit geldt voornamelijk voor onderdelen die publiek toegankelijk zijn.
advisories.ncsc.nlJul 27, 2026extracted
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution and deployment of hex-named JSP web shells under /Windchill/login/," according to a new coordinated advisory released by Ransom-ISAC along with eCrime.ch and DEFUSED. Upon gaining an initial foothold, the attackers have been found to conduct file system enumeration, stage engineering/design data, and ultimately carry out double extortion data theft. Targets of the campaign include manufacturing, automotive, aerospace, and retail sectors. It's suspected that threat actors are exploiting CVE-2026-12569 (CVSS score: 9.3), a critical security flaw in PTC Windmill that was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog late last month. In an advisory, PTC warned customers that it had "received continued reports of heightened threat activity," adding that unknown attackers are exploiting the vulnerability to deploy JSP web shells against susceptible systems. "In the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation," researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen said. Ransom-ISAC has shared four IP addresses as indicators of compromise (IoCs), all of which match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to originate from previously compromised accounts and are sent to hundreds of users within an impacted organization, along with ways to contact the Cl0p ransomware crew. In a separate post on X, ReliaQuest said it observed threat actors actively exploiting CVE-2026-12569 to facilitate "unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration." "The actor behind these attacks remains unconfirmed. However, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories," it added. The Cl0p gang has a storied history of going after security flaws in widely-used enterprise products to break into target organizations for data theft and extortion attacks. Previous campaigns mounted by the group have weaponized file transfer appliances, including those from Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, as well as a vulnerability in Oracle E-Business Suite. Update Attack surface management platform Censys said it observed fewer than 100 instances of PTC Windchill exposed to the internet as of June 1, 2026, with a decline in publicly-accessible instances shortly after PTC's advisory on June 17. As of July 20, 2026, there were a little over 80 internet-exposed Windmill instances. "80% of observed Windchill instances are found in the U.S., and nearly a quarter of hosts running Windchill are on Akamai infrastructure, which aligns with the product's enterprise customer profile," it said. "Data stolen from these instances may include files like product designs and specs, bills of materials, supplier and vendor data, and other intellectual property. This is particularly concerning given that PTC's customer base includes defense contractors, energy suppliers, medical technology companies, and electronics manufacturers, among others." (The story was updated after publication on August 3, 2026, to include additional insights from Censys.)
thehackernews.comJul 25, 2026extracted
OPERATIONAL SUMMARY 1° SEMESTRE 2026
OPERATIONAL SUMMARY 1° SEMESTRE 2026 OPERATIONAL SUMMARY 1° SEMESTRE 2026 Pubblicazione PL02/260724/CSIRT-ITA Il primo semestre del 2026 vede gli eventi cyber in aumento del 47% rispetto al primo semestre del 2025 (2.171 a fronte di 1.474) prevalentemente in ragione delle oltre 1.000 notifiche NIS ricevute e gestite dal CSIRT Italia. Il dato non deve pertanto essere interpretato come un aumento reale della minaccia o degli impatti subiti dai soggetti nazionali, ma come il risultato di una maggiore capacità di intercettare e gestire fenomeni che precedentemente, potevano non emergere con la stessa tempestività o granularità. Di questi eventi 1.072 sono stati classificati come incidenti con impatto confermato mentre gli eventi senza impatto confermato sono stati 1.099, sostanzialmente allineati ai 1.164 del primo semestre 2025 (in diminuzione del 6%). L’andamento degli eventi è stato altresì influenzato, in particolare a maggio e giugno, dalla ripresa di campagne DDoS di natura hacktivista – quasi sempre senza impatti significativi – nonché da alcuni incidenti relativi a fornitori di servizi IT i cui effetti si sono propagati lungo la filiera, interessando più organizzazioni appartenenti a settori economici differenti. Dal punto di vista della minaccia risultano ricorrenti nel semestre, oltre al DDoS, esposizione dati, phishing, compromissioni di caselle di posta elettronica, abuso di credenziali valide e sfruttamento di vulnerabilità note. Nel confronto con il primo semestre 2025, si osserva un aumento delle minacce legate alla compromissione di credenziali, all’esposizione di dati e allo sfruttamento di vulnerabilità; risultano invece in flessione DDoS, ransomware e misconfiguration. Anche la distribuzione settoriale osservata nel primo semestre 2026 deve essere letta, in primo luogo, alla luce dell’entrata a regime degli obblighi di notifica previsti dalla NIS2. In tale quadro, i settori maggiormente interessati da eventi cyber nel primo semestre 2026 risultano Manifatturiero, Tecnologico, Sanitario. Rispetto al primo semestre 2025, risulta meno interessata la Pubblica amministrazione centrale e locale. Nel primo semestre 2026 sono stati registrati 181 ransomware a danno di soggetti italiani rispetto ai 206 rilevati nel corrispondente periodo del 2025. Seppur in diminuzione del 12%, tale minaccia si conferma una delle tipologie a maggiore impatto sulla continuità operativa delle vittime e sulla confidenzialità delle informazioni. I settori più interessati sono stati Manifatturiero, Vendita al dettaglio e Tecnologico. L’analisi degli eventi rilevati evidenzia come i principali fattori abilitanti le compromissioni ransomware siano l’utilizzo di credenziali valide precedentemente compromesse, lo sfruttamento di servizi di accesso remoto o VPN non adeguatamente configurati o protetti, nonché lo sfruttamento di vulnerabilità note e servizi esposti. Le campagne DDoS osservate nel primo semestre 2026 confermano la persistenza di tale tipologia di minaccia, spesso caratterizzata da finalità dimostrative, di disturbo o riconducibili a contesti hacktivisti e geopolitici, ma senza impatti significativi sulla continuità dei servizi. La dinamica DDoS ha avuto fasi di intensità variabile con un picco a febbraio, in concomitanza con l’apertura dei Giochi Olimpici Invernali Milano Cortina 2026, in cui gruppi filorussi hanno interessato prevalentemente strutture ricettive situate nei comprensori che ospitavano le competizioni, soggetti della Pubblica amministrazione centrale e locale e operatori del settore dei trasporti. L’impatto è risultato complessivamente limitato: nel mese di febbraio solo il 6% degli eventi ha determinato l’indisponibilità, comunque temporanea, dei siti web oggetto dell’attacco. A marzo e aprile l’attività si è mantenuta su livelli contenuti, mentre a maggio, a seguito delle notizie relative al sostegno politico dell’Italia all’Ucraina, sono riprese campagne hacktiviste contro soggetti italiani, con 117 DDoS, concentrati soprattutto alla fine del mese, e impatti misurabili – temporanee indisponibilità o rallentamenti dei servizi esposti interessati – in circa 20 occasioni. Nel mese di giugno le campagne sono proseguite, interessando prevalentemente amministrazioni pubbliche centrali e locali, trasporti, telecomunicazioni, servizi finanziari, autorità portuali e operatori del comparto energetico. In totale ha censito 407 DDoS nel primo semestre 2026, in diminuzione del 32% rispetto allo stesso periodo del 2025. Nel primo semestre 2026, l’attività di monitoraggio ha riposto particolare attenzione a esposizioni di servizi remoti, interfacce amministrative, piattaforme di gestione, sistemi non aggiornati, account o asset potenzialmente compromessi. Nel periodo sono emerse, inoltre, vulnerabilità in prodotti ampiamente utilizzati come Fortinet, Citrix, Cisco, Microsoft SharePoint ed Exchange, PostgreSQL, SolarWinds, Apache, N8n, Ubiquiti, Exim, Palo Alto, SAP NetWeaver, Roundcube e ulteriori soluzioni ampiamente utilizzate in ambienti enterprise e infrastrutturali. Il monitoraggio si è quindi concentrato sul rilevamento di asset e servizi potenzialmente interessati da tali vulnerabilità al fine di procedere con comunicazioni di allertamento preventivo, in 7.634 casi ai sensi dell’Art. 2 comma 1 della Legge n. 90/2024. In totale, CSIRT Italia ha individuato complessivamente, nel primo semestre 2026, 24.303 asset e servizi a rischio e 1.560 asset potenzialmente compromessi, informando tempestivamente i soggetti a cui questi afferiscono. I punti d’ingresso più frequenti delle attività malevole censite nel primo semestre 2026 sono stati le campagne malevole via e-mail, l’impiego di credenziali valide precedentemente compromesse, il phishing e il social engineering in generale. Il quadro conferma come una quota rilevante delle attività osservate faccia leva non soltanto su debolezze tecniche, ma anche su comportamenti, processi e modalità di gestione delle identità digitali: apertura di allegati o link malevoli, inserimento di credenziali su portali fraudolenti, riutilizzo di password, mancato ricorso a meccanismi di autenticazione robusta o gestione non tempestiva di account compromessi. In alcuni casi, gli attacchi hanno seguito dinamiche riconducibili alla supply-chain, evidenziando come la postura di sicurezza dei fornitori possa rappresentare un ulteriore 07 I semestre 2026 fattore di esposizione per le organizzazioni clienti. Tale quadro risulta coerente con quanto osservato nel primo semestre 2025 e conferma la centralità del fattore umano nella prevenzione degli attacchi, accanto al rafforzamento dei controlli tecnici, dei processi di gestione delle identità e delle attività di monitoraggio. Nel primo semestre 2026 sono state pubblicate 37.032 nuove CVE, in aumento del 54% rispetto alle 24.098 del primo semestre 2025. Di queste, 5.722 presentano almeno un Proof of Concept (PoC), mentre per 69 CVE è stato rilevato lo sfruttamento attivo. Tale sensibile incremento è verosimilmente ascrivibile al crescente utilizzo di modelli AI di frontiera (frontier models), che stanno riducendo i tempi necessari per l’analisi del codice, il vulnerability research e la generazione di Proof of Concept, in particolare per alcuni vendor (maggiori dettagli in sezione 3.2.).
acn.gov.itJul 24, 2026extracted
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecurity company ReliaQuest reported on Thursday, Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies' compromised PLM platforms. "ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration," the company said. "The actor behind these attacks remains unconfirmed. however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories." Clop's Windchill and FlexPLM attacks were also confirmed yesterday by the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC), a non-profit organization dedicated to the tracking and defense against ransomware threats. Ransom-ISAC's Brandon Parsons from Ascent Solutions told BleepingComputer that Clop is using what appear to be previously compromised email accounts to send extortion messages to multiple employees of targeted organizations. "The extortion emails appear to originate from randomly compromised accounts, are sent to hundreds of users within an impacted organization and include Cl0p’s latest contact information," Parsons said. "This extortion approach is consistent with what we observed with the Oracle EBS campaign last year, except for the use of new email addresses." As BleepingComputer has learned, it is a common tactic for this cybercrime group to change email addresses before launching a new extortion campaign. Flagged as actively exploited in attacks PTC began releasing security patches for the CVE-2026-12569 flaw on June 17 and, while it didn't confirm in-the-wild exploitation, it released remediation guidance in a private advisory and urged customers to review their environments for indicators of compromise (IOCs). After PTC warned customers of "heightened threat activity" on June 26, the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to secure their PTC Windchill and FlexPLM instances within three days. According to German news outlet Heise, CVE-2026-12569 also prompted emergency action from German authorities, with the Federal Office for Information Security (BSI) emailing and calling PTC customers in the middle of the night and warning them to patch their systems as quickly as possible. German authorities reacted with the same urgency in March after reports that a similar critical Windchill and FlexPLM flaw (CVE-2026-4681) may be exploited or was likely to be exploited soon. On Thursday, ReliaQuest advised PTC customers to patch Windchill and FlexPLM systems and place them behind VPNs or trusted access gateways if possible. Additionally, if they suspect compromise, they should isolate the affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service. A PTC spokesperson was not immediately available for comment when contacted by BleepingComputer earlier this week. PTC Windchill and PTC FlexPLM are enterprise software platforms in a category known as Product Lifecycle Management (PLM) and used to track, design, and manage products from original idea to final manufacturing. The two PLM systems are widely popular among engineering, manufacturing, quality, and supply chain teams across high-profile companies in the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. PTC says that its products are used by more than 30,000 customers globally, including over 1,500 brand and retail customers using FlexPLM. Clop's data theft campaigns The Clop extortion gang has a long history of breaching enterprise platforms in data theft attacks, with previous campaigns targeting Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers, the latter affecting more than 2,770 organizations worldwide. Most recently, it exploited an Oracle EBS zero-day flaw to steal sensitive files from many organizations since early August 2025, including Harvard University, The Washington Post, GlobalLogic, the University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air. After breaching their systems and exfiltrating sensitive documents, Clop publishes the stolen data on its dark web leak site, making it available for download via Torrent if victims refuse to pay a ransom. The U.S. Department of State now offers a $10 million reward for information that could link this cybercrime gang's attacks to a foreign government. Update July 24, 07:42 EDT: Added more info on the attacks from Ransom-ISAC. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 24, 2026extracted
Cyber insurance e gestione dei rischi: l’impatto delle nuove clausole di esclusione delle polizze
C’era un tempo in cui ottenere una polizza cyber insurance era relativamente semplice: un questionario di poche pagine, qualche dichiarazione sull’uso dell’antivirus e dei backup, e la copertura era garantita. Quel tempo è finito. L’esplosione dei sinistri ransomware tra il 2019 e il 2022, con riscatti medi passati da poche decine di migliaia a diversi milioni di dollari, ha costretto il mercato assicurativo a una revisione radicale dei criteri di sottoscrizione. Il risultato è un mercato profondamente cambiato: premi aumentati del 50-150% in tre anni, questionari tecnici di assessment che richiedono evidenze concrete di controlli specifici e clausole di esclusione sempre più dettagliate che escludono dalla copertura esattamente gli scenari per cui le organizzazioni pensavano di essere assicurate. Per i CISO e i responsabili IT, questo cambiamento ha implicazioni operative immediate: la polizza cyber non è più uno strumento che si acquista e si dimentica fino al sinistro. È un documento contrattuale che impone obblighi di sicurezza continui, che richiede evidenze documentali al momento della sottoscrizione e del rinnovo e che può essere invalidato – con conseguente rifiuto del risarcimento – se l’organizzazione non mantiene nel tempo i controlli dichiarati nel questionario di proposta. Indice degli argomenti Il mercato globale della cyber insurance ha attraversato una fase di rapida maturazione accelerata dalla sinistrosità eccezionale del periodo 2020-2022. Le compagnie assicurative, che in precedenza offrivano coperture ampie con criteri di sottoscrizione relativamente superficiali, si sono trovate a gestire un volume di sinistri ransomware che in alcuni casi ha superato i premi incassati, generando loss ratio superiori al 100%. La risposta del mercato è stata duplice: aumento significativo dei premi e introduzione di requisiti tecnici di sicurezza sempre più stringenti come precondizione per la copertura. In Italia, il mercato della cyber insurance rimane relativamente giovane rispetto ai mercati anglosassoni, ma la tendenza internazionale si sta trasferendo rapidamente anche nel contesto domestico. Le compagnie internazionali che operano nel mercato italiano (Chubb, AXA XL, Zurich, Generali, Allianz) hanno allineato i propri questionari di sottoscrizione agli standard dei mercati più maturi, introducendo requisiti tecnici specifici che molte PMI italiane faticano a soddisfare. Il risultato è un fenomeno di selezione avversa: le organizzazioni con posture di sicurezza deboli faticano a ottenere copertura o la ottengono a premi proibitivi, mentre quelle con controlli robusti beneficiano di condizioni più favorevoli. L’entrata in vigore della direttiva NIS2, recepita in Italia con il D.lgs. 138/2024, ha introdotto un elemento di discontinuità significativo nel rapporto tra le organizzazioni nei settori critici e il mercato assicurativo cyber. Da un lato, la NIS2 ha formalizzato un set di requisiti minimi di sicurezza che le organizzazioni sono tenute ad implementare (misure di gestione del rischio, autenticazione multi-fattore, gestione degli incidenti, sicurezza della supply chain) che coincidono in larga misura con i requisiti tecnici che gli assicuratori stavano già richiedendo. Dall’altro, la direttiva ha aumentato il profilo di rischio delle organizzazioni soggette introducendo sanzioni significative per i soggetti non conformi, un elemento che gli assicuratori stanno iniziando a considerare nel pricing del rischio. Dal punto di vista degli assicuratori, la NIS2 ha avuto un effetto paradossale: ha reso più trasparente e verificabile il livello di sicurezza delle organizzazioni nei settori critici attraverso il processo di registrazione ACN e le valutazioni di conformità, ma ha anche evidenziato che molte di queste organizzazioni hanno gap significativi rispetto ai requisiti della direttiva. Le compagnie più sofisticate stanno iniziando a utilizzare la conformità NIS2 come indicatore proxy del rischio: un’organizzazione che può dimostrare adeguamento a NIS2 è, per definizione, un’organizzazione che ha implementato un set minimo di controlli di sicurezza che riducono il rischio assicurativo. Il questionario di sottoscrizione tradizionale chiedeva dichiarazioni generiche: «avete un antivirus?», «eseguite backup regolari?», «avete un piano di incident response?». Le risposte erano autodichiarazioni non verificate, e le compagnie le accettavano come tali. Il nuovo approccio degli assicuratori è radicalmente diverso: per le polizze sopra determinate soglie di massimale (tipicamente 2-5 milioni di euro) molte compagnie richiedono un assessment tecnico condotto da una terza parte indipendente prima della sottoscrizione. Questo assessment verifica l’effettiva implementazione dei controlli dichiarati, non la sola dichiarazione della loro esistenza. Per le polizze di importo inferiore, i questionari si sono evoluti in documenti molto più dettagliati che richiedono evidenze specifiche: non «avete la MFA?» ma «su quale percentuale degli utenti è implementata la MFA? Su tutti gli accessi remoti? Su tutti gli account privilegiati? Con quale tecnologia? Esistono eccezioni documentate?». La capacità di rispondere a queste domande con precisione e con documentazione di supporto è diventata un prerequisito per ottenere condizioni competitive. Le organizzazioni che rispondono in modo vago o che non dispongono della documentazione richiesta vengono classificate come rischi più elevati, con premi corrispondentemente più alti o coperture ridotte. Le clausole di esclusione nelle polizze cyber insurance sono la sezione del contratto più critica e meno letta. Le organizzazioni acquistano una polizza convinte di avere una copertura ampia per qualsiasi incidente cyber, e scoprono al momento del sinistro che l’evento specifico che si è verificato rientra in una delle numerose esclusioni previste dal contratto. Questa scoperta, nel momento peggiore possibile, quando l’organizzazione sta già gestendo una crisi, può avere conseguenze finanziarie devastanti. Le esclusioni nelle polizze cyber si sono moltiplicate e si sono rese più specifiche negli ultimi anni, in risposta alla sinistrosità elevata. Alcune esclusioni sono storiche e relativamente note (gli atti di guerra e gli attacchi di cyber terrorismo) ma la loro interpretazione si è fatta più controversa dopo che alcune compagnie hanno tentato di applicare la war exclusion ad attacchi ransomware condotti da gruppi legati a governi stranieri (il caso NotPetya/Merck è il riferimento più citato, con dispute legali durate anni). Le esclusioni più recenti e meno note riguardano invece la negligenza nell’aggiornamento dei sistemi, le vulnerabilità preesistenti, gli attacchi alla supply chain e le restrizioni specifiche sul ransomware. Una delle clausole di esclusione in più rapida diffusione riguarda gli incidenti causati da vulnerabilità note non patchate. La logica è apparentemente ragionevole dal punto di vista dell’assicuratore: se una vulnerabilità critica è nota, pubblicata nel database CVE e per cui esiste una patch disponibile da settimane o mesi, un’organizzazione che non l’ha applicata ha contribuito causalmente al proprio danno attraverso negligenza. In questi casi, le compagnie contestano il risarcimento totale o applicano clausole di riduzione proporzionale del risarcimento in funzione del «grado di colpa» dell’assicurato. Questa logica ha implicazioni operative concrete: le organizzazioni con processi di patch management carenti sono esposte non solo al rischio tecnico di compromissione, ma anche al rischio assicurativo di vedersi negare il risarcimento proprio quando ne hanno più bisogno. La documentazione del processo di patch management (SLA di remediation per ogni livello di severity, evidenza delle patch applicate con timestamp, gestione documentata delle eccezioni) diventa quindi un elemento di tutela assicurativa oltre che un controllo di sicurezza. Un’organizzazione in grado di dimostrare che i propri processi di patch management sono strutturati e documentati è in una posizione molto più solida in caso di contestazione del sinistro, anche se una specifica vulnerabilità non era stata patchata alla data dell’incidente. Gli attacchi alla supply chain rappresentano uno degli scenari di maggiore incertezza nel mercato della cyber insurance. Il problema fondamentale è la diffusione del danno: un attacco a un singolo fornitore può colpire simultaneamente centinaia di clienti, generando sinistri aggregati che eccedono di gran lunga i premi raccolti. Il caso SolarWinds, con migliaia di organizzazioni colpite attraverso un singolo aggiornamento software compromesso, ha evidenziato in modo drammatico l’esposizione sistemica degli assicuratori al rischio cyber della catena di fornitura. La risposta del mercato è stata l’introduzione di clausole specifiche che limitano o escludono la copertura per incidenti originati da fornitori terzi, o che introducono sublimiti di copertura significativamente inferiori al massimale principale per questa categoria di eventi. Le formulazioni di queste clausole variano significativamente tra le compagnie, ma alcune tendenze sono comuni: esclusione o sublimite per incidenti causati da vulnerabilità nel software di terze parti installato nell’organizzazione assicurata; limitazioni per incidenti causati da provider cloud o CSP di grandi dimensioni (con riferimento specifico agli hyperscaler); clausole di aggregazione che limitano il risarcimento totale in caso di eventi sistemici che colpiscono simultaneamente un numero elevato di assicurati. Prima di sottoscrivere una polizza, è essenziale verificare come vengono trattati gli scenari supply chain e negoziare esplicitamente le condizioni di copertura per i fornitori critici dell’organizzazione. Il ransomware è la minaccia che più di ogni altra ha trasformato il mercato della cyber insurance, e le clausole relative sono tra le più complesse e controverse delle polizze moderne. Le restrizioni più comuni riguardano tre aree: le condizioni per la copertura del riscatto, i requisiti tecnici che condizionano la copertura ransomware, e le implicazioni legali del pagamento. Sul fronte del riscatto, molte compagnie hanno introdotto requisiti specifici: il pagamento deve essere autorizzato dalla compagnia prima di essere effettuato (con tutto ciò che questo implica in termini di tempistiche in una situazione di emergenza); deve essere gestito attraverso un intermediario specializzato approvato dalla compagnia; deve seguire un processo di due diligence per verificare che il destinatario non sia un soggetto sanzionato (un requisito che deriva dal rischio di violazione delle normative OFAC negli USA e dei regolamenti europei sulle sanzioni). La copertura del riscatto è inoltre condizionata alla dimostrazione che l’organizzazione non aveva opzioni alternative praticabili per il ripristino, il che significa che la presenza di backup immutabili e testati non solo è un requisito per mantenere la copertura ransomware, ma può anche essere usata dalla compagnia per contestare il pagamento del riscatto se i backup erano disponibili e avrebbero consentito il ripristino. La logica è quella di un controllo morale sull’azzardo: la copertura ransomware non deve diventare un incentivo a non investire nei backup e a pagare il riscatto invece di ripristinare dai backup stessi. Il mercato della cyber insurance ha de facto standardizzato un set di requisiti tecnici minimi che le organizzazioni devono soddisfare per ottenere copertura a condizioni ragionevoli. Questi requisiti non sono sempre esplicitati in modo identico da ogni compagnia, ma convergono su un nucleo comune che riflette i controlli di sicurezza con il maggiore impatto sulla riduzione del rischio di sinistro. La conoscenza di questi requisiti è essenziale non solo per chi sta per sottoscrivere una nuova polizza, ma anche per chi deve rinnovare una polizza esistente: i requisiti si sono inaspriti significativamente negli ultimi anni, e molte organizzazioni scoprono al rinnovo che i controlli che erano sufficienti tre anni fa non lo sono più. L’MFA è diventato il requisito di ingresso più universale nel mercato della cyber insurance: senza MFA su tutti gli accessi remoti e su tutti gli account privilegiati, la maggior parte delle compagnie rifiuta la proposta o applica esclusioni significative per gli incidenti causati da compromissione delle credenziali. La ragione è empirica: i dati di sinistrosità mostrano con chiarezza che la maggior parte degli incidenti ransomware e dei data breach inizia con la compromissione di credenziali non protette da MFA e gli assicuratori non intendono coprire rischi che l’assicurato potrebbe eliminare con un controllo relativamente semplice e poco costoso. La protezione degli accessi privilegiati attraverso soluzioni PAM (Privileged Access Management) è il requisito successivo che molte compagnie stanno introducendo per le polizze di importo più elevato. La logica è la stessa: gli account privilegiati sono il bersaglio finale della maggior parte degli attacchi ransomware (perché consentono di cifrare l’intera infrastruttura) e la loro protezione riduce significativamente il potenziale di danno anche in caso di accesso iniziale compromesso. Le evidenze richieste tipicamente includono: nome e versione della soluzione PAM adottata, percentuale di account privilegiati gestiti attraverso il vault, modalità di gestione delle sessioni (registrazione, JIT access), e frequenza di rotazione delle password privilegiate. L’EDR (Endpoint Detection and Response) è il secondo requisito tecnico universalmente richiesto: la presenza di un EDR con copertura completa degli endpoint è considerata dagli assicuratori come il controllo tecnico con il maggiore impatto sulla riduzione del tempo di rilevamento degli incidenti e quindi sul costo finale del sinistro. Le compagnie più sofisticate distinguono tra EDR di diversa generazione, richiedendo strumenti con capacità di detection basata sul comportamento (behavioral detection) piuttosto che solo signature-based, e verificano la copertura effettiva attraverso il questionario: un EDR installato sull’80% degli endpoint lascia un 20% di superficie non protetta che può essere sfruttata come punto di ingresso. Il backup immutabile, ossia un backup che non può essere modificato o cancellato da nessun processo, incluso il ransomware, è il requisito che condiziona specificamente la copertura ransomware. La logica è diretta: se l’organizzazione ha backup immutabili, testati e aggiornati, il ripristino è possibile senza pagare il riscatto, riducendo il costo potenziale del sinistro per la compagnia. Le caratteristiche richieste tipicamente includono: separazione fisica o logica dei backup dall’infrastruttura produttiva (air gap o immutabilità a livello di storage), frequenza dei backup proporzionata alla tolleranza alla perdita di dati (RPO), test di restore documentati con frequenza almeno trimestrale e conservazione per un periodo sufficiente a coprire il tempo medio di permanenza di un ransomware prima del rilevamento (tipicamente 30-90 giorni). La nullità del contratto assicurativo o la sua annullabilità per dichiarazioni inesatte o reticenti è il rischio più grave che un’organizzazione affronta nel rapporto con la cyber insurance. Il Codice civile italiano (art. 1892 c.c.) prevede che il contratto sia annullabile se l’assicurato ha taciuto o dichiarato inesattamente circostanze rilevanti per la valutazione del rischio, anche in buona fede, purché la compagnia dimostri che non avrebbe concluso il contratto o lo avrebbe concluso a condizioni diverse se avesse conosciuto la circostanza taciuta. In ambito cyber, le dichiarazioni rilevanti sono quelle relative allo stato dei controlli di sicurezza: se al momento del sinistro emerge che un controllo dichiarato come implementato non lo era effettivamente, la compagnia ha basi solide per contestare il contratto. Gli errori più comuni nella compilazione dei questionari di proposta non sono sempre frutto di malafede: spesso derivano da una conoscenza imprecisa dello stato dei controlli interni, dalla tendenza a rispondere in modo ottimistico («stiamo implementando la MFA» invece di «la MFA non è ancora implementata»), o dalla mancata comprensione del significato tecnico esatto delle domande. Un responsabile IT che risponde «sì» alla domanda «avete un sistema di backup regolare» pensando ai backup dei file condivisi, senza considerare che i backup non sono testati e non sono immutabili, sta fornendo una risposta tecnicamente vera ma sostanzialmente fuorviante che potrebbe essere usata per contestare la copertura in caso di sinistro ransomware. La documentazione dei presidi di sicurezza organizzativi (policy scritte, procedure documentate, evidenze di formazione) è tanto importante quanto l’implementazione tecnica dei controlli. Una compagnia che in fase di sinistro verifica lo stato dei controlli non si limita a guardare se i sistemi funzionano: verifica se esisteva una governance formale che richiedesse quei controlli, se il personale era formato sul loro utilizzo e se esisteva un processo di verifica periodica della loro efficacia. La mancanza di documentazione, anche in presenza di controlli effettivamente implementati, indebolisce significativamente la posizione dell’assicurato in caso di contestazione. Il fascicolo di compliance assicurativa, ossia l’insieme di documenti che l’organizzazione dovrebbe mantenere per supportare le dichiarazioni fatte nel questionario di proposta, dovrebbe includere almeno: le policy di sicurezza approvate e aggiornate (information security policy, acceptable use policy, incident response policy, backup policy); le evidenze dei training di security awareness con date e partecipanti; i report dei vulnerability assessment e penetration test più recenti; i log dei test di restore dei backup con i risultati; la documentazione del processo di patch management con SLA rispettati; i verbali dei tabletop exercise sull’incident response. Questo fascicolo non deve essere prodotto al momento del sinistro, deve essere mantenuto aggiornato continuamente e deve essere disponibile in tempi brevi in caso di richiesta della compagnia. La gestione del sinistro cyber è un processo che inizia molto prima che l’incidente si verifichi. Le organizzazioni che gestiscono meglio i propri sinistri non sono necessariamente quelle che hanno le polizze più ampie: sono quelle che hanno costruito un rapporto strutturato con la compagnia prima dell’incidente, che conoscono in dettaglio le procedure di notifica e i tempi richiesti e che hanno predisposto la documentazione necessaria per supportare la richiesta di risarcimento. In un momento di crisi operativa, avere un processo chiaro da seguire, invece di dover improvvisare mentre si gestisce l’emergenza tecnica, fa la differenza tra una gestione del sinistro efficiente e una caotica. Il primo passo critico è la notifica tempestiva alla compagnia. La maggior parte delle polizze prevede un termine entro cui l’incidente deve essere notificato (tipicamente 24-72 ore dalla scoperta) e il mancato rispetto di questo termine può essere causa di riduzione o diniego del risarcimento. Questo termine deve essere noto a chiunque nel team di incident response abbia responsabilità di comunicazione: non solo al CISO, ma anche al legal e al management che potrebbero essere i primi a ricevere informazioni sull’incidente. La notifica iniziale non deve essere completa, anche perché è impossibile avere tutte le informazioni nelle prime ore, ma deve avvenire entro i termini contrattuali, anche se si tratta solo di una notifica preliminare che verrà integrata nelle ore e nei giorni successivi. La documentazione dell’incidente, composta da cronologia degli eventi, sistemi coinvolti, misure adottate, costi sostenuti, è la base del risarcimento. Le compagnie non rimborsano costi non documentati: ogni spesa sostenuta durante la gestione dell’incidente (IR team esterno, forensics, legal, PR, costi di ripristino, riscatto eventuale) deve essere documentata con fatture, contratti e evidenze del nesso causale con l’incidente. Tenere un log cronologico dettagliato fin dalle prime ore, con timestamp, azioni intraprese, persone coinvolte e costi sostenuti, è una delle pratiche più semplici e più efficaci per massimizzare il rimborso assicurativo. Le compagnie dispongono di liquidatori specializzati in sinistri cyber che valuteranno ogni voce di costo: la qualità della documentazione è direttamente proporzionale alla velocità e all’ampiezza del rimborso.
cybersecurity360.itJul 7, 2026extracted
Identità digitali e privilegi minimi: la centralità dei sistemi IAM nella governance aziendale
Ogni incidente di sicurezza significativo degli ultimi anni ha in comune un elemento ricorrente: credenziali compromesse o privilegi eccessivi. Il ransomware che cifra l’intera infrastruttura di un’organizzazione raramente sfrutta una vulnerabilità zero-day sofisticata: quasi sempre si propaga attraverso account con privilegi amministrativi mal governati. Il data breach che espone milioni di record spesso origina non da un attacco esterno brillante, ma da un account interno con accesso a più dati di quanti ne servissero realmente. L’insider threat che compromette sistemi critici è reso possibile da permessi mai revocati dopo un cambio di ruolo avvenuto mesi prima. In tutti questi scenari, un programma maturo di Identity and Access Management (IAM) sarebbe stato il controllo in grado di limitare significativamente il danno, se non di prevenirlo del tutto. Questo perché l’IAM non è una tecnologia, ma una disciplina di governance che definisce chi ha accesso a cosa, perché, per quanto tempo e con quale livello di verifica. Quando è implementata correttamente, trasforma la gestione delle identità da una funzione IT amministrativa in un controllo di sicurezza strategico che riduce la superficie di attacco, limita il movimento laterale e produce la tracciabilità necessaria per la compliance normativa. Indice degli argomenti L’Identity and Access Management è l’insieme di politiche, processi e tecnologie che governano la gestione delle identità digitali e dei loro diritti di accesso alle risorse dell’organizzazione. In un’infrastruttura moderna, distribuita su cloud, on-premise e ambienti ibridi, con utenti che accedono da dispositivi diversi in location diverse, l’IAM è il sistema che risponde continuamente a tre domande fondamentali: chi sei (autenticazione), cosa ti è permesso fare (autorizzazione), e cosa hai fatto (audit e tracciabilità). Queste tre funzioni, integrate in un sistema coerente, costituiscono il nucleo della governance della sicurezza. La relazione tra IAM e Zero Trust è strutturale: il modello Zero Trust («non fidarsi mai, verificare sempre») presuppone che nessuna identità sia intrinsecamente fidata per il solo fatto di trovarsi all’interno della rete aziendale. Ogni richiesta di accesso deve essere valutata in funzione dell’identità verificata del richiedente, del dispositivo utilizzato, del contesto della richiesta (ora, localizzazione, comportamento recente) e della sensibilità della risorsa richiesta. Questa valutazione continua e contestuale è impossibile senza un sistema IAM maturo che centralizzi la gestione delle identità, implementi l’autenticazione adattiva e mantenga log completi di ogni accesso. Il principio del minimo privilegio (Principle of Least Privilege, PoLP) stabilisce che ogni utente, processo o sistema dovrebbe avere accesso esclusivamente alle risorse strettamente necessarie per svolgere le proprie funzioni, e solo per il tempo in cui tale accesso è necessario. Formulato per la prima volta da Jerome Saltzer e Michael Schroeder nel 1975 nel contesto della progettazione dei sistemi operativi, il PoLP è oggi uno dei principi fondanti della sicurezza informatica moderna, citato esplicitamente nelle linee guida NIST, nei framework CIS Controls e nei requisiti normativi di NIS2 e DORA. I vantaggi del PoLP per il business vanno ben oltre la riduzione del rischio tecnico. Dal punto di vista della conformità normativa, il minimo privilegio è un requisito esplicito o implicito di praticamente tutti i framework di sicurezza rilevanti: dimostrare la sua implementazione semplifica significativamente i processi di audit e certificazione. Dal punto di vista operativo, la riduzione dei permessi non necessari riduce anche la complessità della gestione: meno eccezioni, meno conflitti di autorizzazione, meno overhead di riconciliazione tra sistemi diversi. Dal punto di vista della resilienza, limita il raggio di azione di ogni incidente: un account compromesso con accesso minimo causa danni minimi; un account compromesso con accesso amministrativo globale può compromettere l’intera infrastruttura. L’isolamento degli accessi, cioè la separazione netta tra utenti con funzioni diverse, tra ambienti con livelli di criticità diversi, tra sistemi con diversi profili di rischio, è il meccanismo operativo attraverso cui il principio del minimo privilegio si traduce in resilienza concreta. Un’organizzazione che ha implementato correttamente l’isolamento degli accessi è un’organizzazione in cui la compromissione di un account non implica automaticamente la compromissione di altri account o sistemi: ogni identità è una bolla isolata con connessioni esplicite e limitate verso altre identità e risorse. Il valore dell’isolamento emerge con particolare chiarezza nell’analisi degli incidenti reali. L’attacco alla Colonial Pipeline del 2021, che ha causato l’interruzione del più grande oleodotto degli Stati Uniti, è partito da una VPN con credenziali compromesse che aveva accesso a sistemi OT non adeguatamente separati dalla rete IT. Se l’accesso VPN fosse stato limitato ai soli sistemi necessari, il danno sarebbe rimasto confinato. Il caso SolarWinds ha mostrato come account di servizio con privilegi eccessivi abbiano consentito il movimento laterale verso sistemi che non avrebbero mai dovuto essere raggiungibili da quel tipo di account. In entrambi i casi, l’isolamento degli accessi non avrebbe prevenuto l’accesso iniziale, ma avrebbe drasticamente limitato il raggio d’azione dell’attaccante. Un’architettura IAM matura si compone di strati funzionali interconnessi che coprono l’intero ciclo di vita dell’identità: dalla creazione alla gestione quotidiana, dalla verifica dell’autenticità alla tracciabilità degli accessi. I componenti fondamentali di questa architettura sono: l’Identity Provider (IdP) centralizzato; il sistema di autenticazione multi-fattore; il motore di autorizzazione basato sui ruoli (RBAC) o sugli attributi (ABAC); il sistema di Privileged Access Management (PAM) per gli account privilegiati; la piattaforma di Identity Governance and Administration (IGA) per il ciclo di vita e le revisioni periodiche. In ambienti cloud e multicloud, l’architettura IAM deve gestire un’ulteriore complessità: ogni provider cloud ha il proprio sistema IAM nativo (AWS IAM, Azure Entra ID, Google Cloud IAM) con modelli di permessi e logiche differenti. La soluzione architetturale è la federazione delle identità attraverso un Identity Provider centralizzato (tipicamente Microsoft Entra ID, Okta, Ping Identity o un sistema equivalente) che gestisce le identità in un’unica fonte di verità e le federa con tutti i provider cloud e le applicazioni SaaS attraverso protocolli standard (SAML 2.0, OIDC, SCIM). Questo approccio garantisce che la gestione del ciclo di vita delle identità – provisioning, modifica, deprovisioning – avvenga in un unico punto, riducendo il rischio di inconsistenze tra sistemi diversi. L’autenticazione a più fattori (MFA) è oggi il controllo di sicurezza con il miglior rapporto tra efficacia e costo nell’intero panorama della cyber security. Il dato estrapolato dal Microsoft Security Intelligence Report è inequivocabile: l’MFA blocca oltre il 99,9% degli attacchi di account takeover automatizzati. Eppure, la sua adozione rimane incompleta in molte organizzazioni, spesso limitata agli accessi da internet ma non agli accessi interni o implementata per gli utenti privilegiati ma non per l’intera base utenti. Questa implementazione parziale lascia aperte le vulnerabilità più sfruttate: le credenziali di account non protetti da MFA sono il vettore di accesso iniziale nella maggioranza degli incidenti documentati. L’autenticazione adattiva o risk-based porta il concetto di MFA a un livello superiore: invece di richiedere sempre lo stesso secondo fattore indipendentemente dal contesto, valuta il rischio della richiesta di accesso in tempo reale e calibra il livello di verifica richiesto di conseguenza. Un accesso da un dispositivo noto, dall’indirizzo IP aziendale, durante l’orario lavorativo standard, con un pattern comportamentale coerente con la storia dell’utente: rischio basso, accesso con solo secondo fattore. Un accesso da un paese mai visitato prima, alle 3 di notte, da un dispositivo non registrato: rischio alto, richiesta di verifica aggiuntiva o blocco con notifica al team di sicurezza. Il ciclo di vita di un’identità aziendale è il processo che governa la creazione, la gestione e la dismissione di un account dall’ingresso di un utente nell’organizzazione alla sua uscita. Ogni fase di questo ciclo presenta rischi specifici se non è governata da processi formali: il provisioning senza approvazione porta ad account con permessi eccessivi; la gestione senza revisioni periodiche porta all’accumulo di privilegi non necessari; il deprovisioning tardivo o incompleto lascia account attivi dopo la cessazione del rapporto di lavoro. Gli account orfani, cioè gli account di utenti che hanno lasciato l’organizzazione ma il cui accesso non è stato revocato, sono una delle vulnerabilità più frequenti e più sottovalutate nella gestione delle identità. Le statistiche di settore indicano che in organizzazioni senza processi automatizzati di deprovisioning, una percentuale significativa degli account attivi appartiene a persone che non hanno più un rapporto con l’organizzazione: ex dipendenti, consulenti a progetto terminato, fornitori il cui contratto è scaduto. Questi account sono potenziali vettori di accesso non autorizzato, sia da parte degli ex-utenti stessi, sia da parte di attaccanti che ne hanno compromesso le credenziali e sono invisibili ai sistemi di monitoraggio comportamentale perché non mostrano anomalie rispetto al pattern storico dell’utente. L’implementazione operativa del principio del minimo privilegio in un’organizzazione esistente, in cui i permessi si sono accumulati nel tempo senza una governance sistematica, è uno dei progetti IAM più complessi e politicamente delicati. La complessità tecnica è reale: mappare i permessi effettivi di centinaia o migliaia di utenti su decine di sistemi diversi richiede strumenti dedicati e un processo metodico. La complessità politica è altrettanto reale: ridurre i privilegi di utenti che li hanno sempre avuti genera resistenza, percezione di perdita di autonomia e potenziali impatti operativi se i permessi vengono rimossi senza un’analisi accurata delle effettive necessità. La strategia più efficace è quella incrementale: iniziare dall’inventario e dall’analisi (sapere cosa c’è prima di cambiarlo), procedere con la rimozione dei permessi evidentemente superflui (account con zero utilizzo, permessi su sistemi non pertinenti al ruolo) e affrontare i casi più complessi, dove l’utente usa effettivamente permessi che non dovrebbe avere con un processo di rivalutazione che coinvolge il manager e il data owner. Un approccio che tenta di correggere tutto contemporaneamente genera inevitabilmente impatti operativi e resistenza organizzativa che possono bloccare il progetto prima che produca risultati significativi. Il Role-Based Access Control (RBAC) è il modello di autorizzazione più diffuso nelle organizzazioni di medie e grandi dimensioni: i permessi vengono assegnati a ruoli, e gli utenti vengono assegnati a ruoli. Questo approccio semplifica la gestione quando un utente cambia ruolo, si cambia l’assegnazione del ruolo e i permessi si aggiornano automaticamente, ma richiede che i ruoli siano definiti con granularità sufficiente a rispettare il principio del minimo privilegio. Un sistema con pochi ruoli molto ampi è facile da gestire ma garantisce privilegi eccessivi; un sistema con molti ruoli granulari rispetta il PoLP ma aumenta la complessità della gestione. L’Attribute-Based Access Control (ABAC) rappresenta l’evoluzione del RBAC: le decisioni di autorizzazione non sono basate solo sul ruolo dell’utente, ma su un insieme di attributi contestuali (il dipartimento, il livello gerarchico, la localizzazione, l’ora del giorno, la classificazione del dato richiesto, lo stato di sicurezza del dispositivo). Questo approccio consente politiche di accesso molto più precise («i medici del reparto oncologia possono accedere alle cartelle dei propri pazienti nelle ore di servizio dal dispositivo aziendale») ma richiede un’infrastruttura IAM più sofisticata e una gestione degli attributi accurata e aggiornata. Per le organizzazioni in settori regolamentati con requisiti di accesso granulari – sanità, finanza, difesa – l’ABAC è spesso l’unico approccio in grado di soddisfare contemporaneamente i requisiti operativi e quelli di conformità. Gli account privilegiati di amministratori di sistema, DBA, account di servizio con accesso root e account di gestione dei sistemi di sicurezza sono il bersaglio più appetibile per un attaccante che ha ottenuto un accesso iniziale. Con un account privilegiato, il movimento laterale verso qualsiasi sistema dell’organizzazione diventa immediatamente possibile. Il Privileged Access Management (PAM) è la categoria di strumenti e processi dedicata specificamente alla protezione di questi account ad alto rischio, e la sua implementazione è raccomandata come priorità assoluta in qualsiasi programma IAM. Un aspetto spesso trascurato riguarda gli accessi privilegiati dei fornitori terzi: system integrator, MSP e consulenti IT che operano con credenziali privilegiate sui sistemi del cliente sono uno dei vettori di attacco supply chain più frequentemente documentati e uno dei meno governati dai programmi PAM tradizionali, che tendono a concentrarsi sugli account interni trascurando quelli esterni. Le funzionalità core di una soluzione PAM includono: il vault delle credenziali privilegiate (le password degli account amministrativi non sono mai visibili agli utenti, vengono generate automaticamente, ruotate periodicamente e iniettate nelle sessioni senza essere mostrate); la registrazione completa delle sessioni privilegiate (ogni comando eseguito durante una sessione amministrativa viene registrato con timestamp, consentendo l’analisi forense post-incidente e la verifica delle attività); il controllo granulare dei comandi (possibilità di limitare quali comandi specifici un utente privilegiato può eseguire, anche all’interno di una sessione amministrativa); l’accesso just-in-time (gli account privilegiati vengono abilitati solo per la durata specifica del task, con scadenza automatica e revoca al termine). Il privilege creep, cioè la progressiva e involontaria accumulazione di permessi non necessari da parte degli utenti nel corso del tempo, è uno dei problemi più pervasivi nella gestione delle identità aziendali. Non è il risultato di decisioni deliberatamente sbagliate: è il prodotto naturale di organizzazioni che cambiano. Un utente che assume temporaneamente le funzioni di un collega in malattia riceve i permessi necessari e poi non li vede revocati. Un manager che partecipa a un progetto speciale ottiene l’accesso ai sistemi del progetto e lo mantiene anche dopo la conclusione. Un dipendente che cambia dipartimento ottiene i permessi del nuovo ruolo senza che quelli del vecchio siano rimossi. Con il tempo, ogni utente accumula un profilo di permessi che non corrisponde più al suo ruolo attuale: un profilo che, se le sue credenziali vengono compromesse, fornisce all’attaccante un accesso molto più ampio del necessario. La prevenzione del privilege creep richiede due meccanismi complementari: la revisione periodica degli accessi (access certification o access review) e la gestione formale delle eccezioni temporanee. La revisione periodica è il processo attraverso cui, a intervalli regolari, ogni manager certifica che i permessi dei propri collaboratori siano ancora appropriati per il ruolo corrente. Le piattaforme IGA (Identity Governance and Administration) automatizzano questo processo: inviano campagne di revisione ai manager, raccolgono le risposte e implementano automaticamente le revoche approvate, riducendo l’overhead operativo e garantendo la copertura sistematica di tutti gli utenti. La frequenza delle revisioni degli accessi deve essere proporzionale alla criticità del sistema e al livello di privilegio dell’account: gli account privilegiati (amministratori, DBA, account di servizio) devono essere revisionati almeno trimestralmente; gli account standard degli utenti finali almeno semestralmente; gli accessi a sistemi critici classificati (sistemi di autenticazione, sistemi di backup, sistemi di sicurezza) almeno ogni 90 giorni con revisione da parte di un responsabile di secondo livello. Le normative NIS2 e DORA prevedono implicitamente questi requisiti di revisione come parte degli obblighi di gestione del rischio e di controllo degli accessi. Le approvazioni temporanee, ossia i meccanismi che consentono di concedere accessi eccezionali per un periodo limitato senza modificare permanentemente il profilo dell’utente, sono lo strumento che sostituisce la pratica informale di «dammi i permessi per questo task e poi li togliamo». Implementati correttamente, prevedono: una richiesta documentata con motivazione e durata prevista, un’approvazione esplicita da parte del responsabile e del data owner, una scadenza automatica che revoca l’accesso senza necessità di intervento manuale, e una notifica al team di sicurezza per gli accessi temporanei a sistemi critici. Il risultato è che le eccezioni alla regola del minimo privilegio diventano visibili, documentate e automaticamente reversibili invece di trasformarsi silenziosamente in permessi permanenti. La gestione delle identità e degli accessi è un’area trasversale a praticamente tutti i framework di sicurezza e compliance rilevanti per le organizzazioni che operano in ambienti IT complessi. La ISO 27001:2022, nella sua versione aggiornata, include controlli specifici sull’IAM nell’Annex A: A.5.15 (gestione degli accessi), A.5.16 (gestione delle identità), A.5.17 (informazioni di autenticazione), A.8.2 (diritti di accesso privilegiati), A.8.4 (accesso al codice sorgente). I CIS Controls v8 includono tre controlli interamente dedicati alla gestione degli accessi (CIS Control 5: Account Management, CIS Control 6: Access Control Management, CIS Control 12: Network Infrastructure Management). NIS2 richiede esplicitamente l’autenticazione a più fattori e sistemi di autenticazione continua come misure di sicurezza obbligatorie per i soggetti essenziali e importanti. La tracciabilità degli accessi, cioè la capacità di ricostruire chi ha avuto accesso a quale risorsa, quando, da quale dispositivo e con quale risultato, è un requisito trasversale a tutti i framework di compliance e assume un’importanza critica nelle attività di risposta agli incidenti. Senza log completi e integri degli accessi, è impossibile ricostruire la catena di eventi che ha portato a una compromissione, identificare tutti i sistemi raggiunti dall’attaccante, e dimostrare alle autorità di vigilanza la portata effettiva dell’incidente e le misure adottate. I requisiti di tracciabilità impongono standard precisi su tre dimensioni: la completezza dei log (quali eventi devono essere registrati: ogni autenticazione riuscita e fallita, ogni modifica ai permessi, ogni accesso a risorse classificate, ogni azione di account privilegiati); la conservazione (per quanto tempo i log devono essere mantenuti: NIS2 richiede almeno 12 mesi, con 6 mesi di accesso immediato; GDPR e normative finanziarie possono richiedere periodi più lunghi); l’integrità (i log devono essere protetti da modifiche non autorizzate: il logging centralizzato su sistemi separati dagli ambienti monitorati è il controllo fondamentale per garantire che i log non vengano alterati da un attaccante che ha compromesso i sistemi che li generano). L’implementazione di un sistema di logging IAM conforme ai requisiti normativi richiede l’integrazione tra il sistema IAM, il SIEM aziendale e una piattaforma di log management con retention configurata sulle scadenze normative. La correlazione degli eventi IAM con altri eventi di sicurezza nel SIEM (un’autenticazione riuscita seguita da un accesso anomalo a sistemi inusuali, una serie di autenticazioni fallite seguita da un successo da IP diverso) è il meccanismo che trasforma i log da archivio passivo a strumento di rilevamento attivo delle minacce.
cybersecurity360.itJul 3, 2026extracted
Il confine IT/OT non dà garanzie. E il caso del porto di Ancona lo dimostra
Per bloccare un porto oggi non è necessario manomettere le gru, sabotare i sistemi di ormeggio o compromettere i radar. Basta cifrare gli account cloud che coordinano la logistica. Lo dimostra l’attacco ransomware al porto di Ancona dello scorso dicembre, documentato in un’analisi tecnica pubblicata recentemente dalla società americana Resecurity. Il gruppo Anubis aveva compromesso (solo) degli account Office 365 e Azure configurati in modo non sicuro, senza avvicinarsi a un singolo sistema di controllo industriale. Eppure, le navi sono state deviate, il cargo bloccato, le operazioni doganali fermate. Questo ridisegna il perimetro del rischio informatico nei porti italiani ed europei in modo che molti responsabili della sicurezza non si aspettano. Indice degli argomenti La violazione è iniziata l’11 dicembre 2025 con una mail. Qualcuno, nell’organizzazione che gestisce operativamente l’Autorità di Sistema Portuale del Mare Adriatico Centrale, ha aperto un allegato malevolo. Da lì, il gruppo ransomware Anubis ha avviato una sequenza che segue le tappe consuete: escalation dei privilegi, movimento laterale nella rete, accesso ai sistemi di produzione, esfiltrazione di dati, cifratura. La rivendicazione pubblica è arrivata a gennaio 2026: il gruppo ha pubblicato il materiale sottratto e la compromissione è diventata ufficialmente un incidente di sicurezza noto. La richiesta di riscatto è stata di dieci milioni di dollari in Bitcoin, con un ultimatum di sette giorni prima della pubblicazione integrale dei dati sottratti. I sistemi cifrati erano quelli che gestivano il tracciamento del cargo, i calendari delle navi e i processi doganali: tre funzioni che, se inaccessibili simultaneamente, rendono di fatto impossibile operare un qualsiasi porto. L’autorità portuale ha dichiarato che la perdita ha riguardato circa il 2% dei dati complessivi, che i backup hanno preservato la parte restante e che la maggior parte del materiale sottratto era già di dominio pubblico o prossimo alla pubblicazione. Vincenzo Garofalo, Commissario straordinario dell’Autorità di sistema portuale del mare Adriatico centrale, oggi sull’accaduto risponde così a CyberSecurity360: “Siamo una pubblica amministrazione che ha saputo affrontare un evento imprevedibile e così complesso come l’attacco informatico che abbiamo subito. Lo abbiamo potuto fare perché l’Ente è strutturato per gestire queste situazioni. Purtroppo, per quanto si possa fare prevenzione e prepararsi, questi avvenimenti hanno una chiara natura criminosa sulla quale non si può mai abbassare la guardia. Un fatto che ci ha spinto a potenziare ulteriormente gli investimenti a difesa dell’Autorità di sistema portuale e a coinvolgere, in maniera ancora più approfondita, tutto il personale che ha partecipato negli ultimi mesi ad una nuova serie di corsi specialistici per alzare il livello di attenzione su questi rischi e per gestire con efficacia qualsiasi segnale di anomalia coinvolgendo nell’immediato la struttura informatica dell’Adsp”. Sono affermazioni che si leggono in ogni comunicazione post-incidente orientata a contenere l’impatto reputazionale. Ma il rapporto di Resecurity dice qualcosa di più scomodo: i protocolli di backup erano obsoleti e hanno rallentato significativamente il ripristino, proprio nel momento in cui ogni ora di blocco si traduceva in pressione crescente per favorire il pagamento. Il rapporto di Resecurity segnala un dato che vale la pena isolare: l’attacco non ha richiesto il targeting dei sistemi di tecnologia operativa. La compromissione è avvenuta esclusivamente attraverso vulnerabilità IT, in particolare account Office 365 e Azure configurati in modo non sicuro, producendo comunque conseguenze nel dominio ciber-fisico. Il dibattito sulla sicurezza delle infrastrutture critiche si è a lungo organizzato attorno alla distinzione tra IT e OT: da una parte i sistemi informatici aziendali, dall’altra i sistemi di controllo industriale che governano i processi fisici, con la convinzione che la separazione tra i due ambienti offrisse una garanzia strutturale. Il caso di Ancona dimostra che questa impostazione è superata. I sistemi informatici ordinari – quelli usati per gestire le operazioni amministrative, le comunicazioni interne, la logistica documentale – sono ormai così intrecciati con i processi operativi reali che la loro compromissione produce effetti fisici comparabili a un attacco ai sistemi di controllo industriale. Le piattaforme cloud, le applicazioni SaaS, i sistemi di gestione documentale integrati con le procedure doganali: tutto questo forma uno strato informatico senza il quale le banchine, fisicamente intatte, non riescono a funzionare. Nei porti, dove la dipendenza dall’integrazione digitale è particolarmente densa e i sistemi legacy particolarmente radicati, l’esposizione è più manifesta che in altri settori. Anubis è un gruppo giovane. È comparso per la prima volta a dicembre 2024 e ha lanciato il proprio programma di affiliazione a febbraio 2025 sul forum clandestino RAMP, il Russian Anonymous Marketplace, dove opera sotto l’alias superSonic. Su altri forum come XSS ed Exploit usa il nome Anubis_media. Non ha nessuna relazione con il malware Android omonimo degli anni precedenti: è un gruppo completamente distinto. Fonte: resecurity.com. Il modello adottato è il ransomware-as-a-service: il gruppo sviluppa gli strumenti, recluta affiliati e cede loro l’accesso in cambio di una percentuale variabile del bottino, dall’80% per le operazioni ransomware complete al 50% per chi si limita a vendere le credenziali di reti già compromesse. Il gruppo afferma di aver superato 20 milioni di dollari di ricavi, mantiene un profilo X con cui amplifica la visibilità delle violazioni rivendicate, e dichiara di non colpire organizzazioni nei paesi dell’ex Unione Sovietica e nei paesi BRICS. Anubis tecnicamente sfrutta vulnerabilità note e non corrette: VPN SonicWall prive di autenticazione a più fattori, la vulnerabilità CVE-2025-26399 su SolarWinds Web Help Desk, VPN SSL Cisco. Impiega macchine virtuali QEMU (quick emulator) per nascondersi agli strumenti di rilevamento, una tecnica di evasione progressivamente più diffusa nel ransomware avanzato. Il tratto più caratteristico di Anubis è la doppia estorsione praticata con coerenza: prima si esfiltra, poi si cifra. Questo ordine non è casuale. Consente di esercitare pressione sulla vittima anche nel caso in cui disponga di copie di backup: il rischio di vedere pubblicati contratti, dati del personale e informazioni riservate è una leva di coercizione che sopravvive al ripristino dei sistemi. Nel caso del porto di Ancona, il materiale sottratto ha incluso contratti, dati del personale e piani di sicurezza e informazioni sulle operazioni di protezione portuale. Resecurity ha sottolineato che questa categoria di dati non ha valore soltanto in un contesto di estorsione informatica: è esattamente il tipo di informazioni che le organizzazioni criminali coinvolte nel contrabbando cercano per pianificare operazioni, mappare vulnerabilità procedurali e reclutare personale interno. L’incidente informatico diventa così anche un potenziale incidente di sicurezza fisica. Il porto di Ancona non è un caso astratto da manuale. È un porto italiano, parte di un sistema di quindici autorità di sistema portuale che rientrano pienamente nel perimetro della direttiva NIS2, recepita in Italia con il decreto legislativo 138/2024. Le autorità portuali sono soggetti essenziali ai sensi della direttiva: gestiscono infrastrutture critiche per il trasporto, sono interconnesse con i sistemi doganali nazionali e con le piattaforme logistiche europee, e i loro incidenti producono effetti transfrontalieri. NIS2 impone misure di gestione del rischio proporzionate all’esposizione: autenticazione sicura, gestione degli account privilegiati, backup testati, sicurezza della catena di approvvigionamento digitale, notifica degli incidenti significativi all’Agenzia per la Cybersicurezza Nazionale (ACN) entro 24 ore. Introduce anche la responsabilità diretta degli organi di gestione: i vertici delle autorità portuali non possono più delegare la questione al reparto IT. Il caso di Ancona solleva domande concrete. Gli account Office 365 e Azure privi di adeguate protezioni erano stati identificati come rischio nella valutazione prevista da NIS2? I backup erano stati testati con la frequenza necessaria, o la dipendenza da protocolli obsoleti era rimasta invisibile fino all’attacco? La notifica all’ACN è avvenuta nei tempi previsti, considerando che la violazione risale a dicembre 2025 e la rivendicazione pubblica è arrivata a gennaio 2026? Il caso di Ancona non è isolato. È l’episodio più recente di una tendenza documentata e in accelerazione. Nel 2017, NotPetya ha paralizzato la danese Maersk, causando perdite stimate tra i 200 e i 300 milioni di dollari e bloccando le operazioni globali per oltre una settimana. Nel 2023, LockBit 3.0 ha fermato il porto di Nagoya per due giorni, interrompendo le forniture di componenti Toyota. Nel 2026, il porto di Vigo ha dovuto ricorrere a operazioni manuali dopo un attacco ransomware. Resecurity prevede un’intensificazione di questa pressione dal 2026 al 2030, alimentata da tre fattori che si rafforzano reciprocamente: la digitalizzazione accelerata del settore marittimo, la proliferazione del modello ransomware-as-a-service che abbassa la soglia di ingresso per i gruppi criminali, e l’uso dei porti come obiettivi in operazioni di guerra ibrida da parte di attori statali. I porti non sono soltanto snodi commerciali: gestiscono circa il 90% del commercio globale e la loro compromissione produce effetti che vanno dal danno economico immediato alla destabilizzazione delle catene di approvvigionamento nazionali. La prima implicazione riguarda la superficie di attacco. L’adozione di strumenti cloud e piattaforme SaaS nei porti ha spostato il perimetro di sicurezza in modo che molte organizzazioni non hanno ancora pienamente assorbito. Il presupposto che i sistemi critici siano quelli con accesso diretto all’infrastruttura fisica è errato, secondo gli esperti: qualsiasi account con accesso privilegiato a sistemi che coordinano le operazioni portuali è un bersaglio ad alto valore. L’autenticazione a più fattori su tutti gli accessi amministrativi non è una buona prassi: è un requisito minimo, e la sua assenza è precisamente il tipo di lacuna che Anubis sfrutta sistematicamente. La seconda riguarda la catena di fornitura digitale. Il punto di ingresso nell’incidente di Ancona non è stata l’autorità portuale in senso stretto, ma la società che ne gestisce le operazioni. I fornitori di servizi con accesso privilegiato all’infrastruttura sono spesso meno presidiati rispetto all’organizzazione principale, e diventano la via d’accesso preferita. NIS2 richiede esplicitamente di estendere la gestione del rischio ai fornitori rilevanti, inclusi quelli che gestiscono operativamente sistemi informatici critici per conto dell’organizzazione. La terza riguarda i backup. L’incidente ha dimostrato che esistere e funzionare sono condizioni diverse. Testare regolarmente la capacità di ripristino, con prove reali, non solo verifiche documentali, è il discrimine tra una risposta all’incidente efficace e una che si trasforma in capitolazione. La quarta riguarda il valore dei dati operativi. I piani di sicurezza portuale e le informazioni sulle operazioni di vigilanza appartengono a una categoria diversa dai dati personali o commerciali: il loro valore per organizzazioni criminali coinvolte nei traffici illeciti può superare di molto quello di contratti e dati del personale. Proteggerli richiede un approccio che non si esaurisce nel rispetto del GDPR. Il porto di Ancona non è l’eccezione. È la dimostrazione di una condizione diffusa: quella di infrastrutture critiche che si sono digitalizzate senza sviluppare parallelamente la maturità necessaria per gestire l’esposizione che questa digitalizzazione comporta. Il problema non è l’assenza di indicazioni su cosa fare: le misure sono documentate, codificate nei framework internazionali e richieste dalla normativa. È la distanza tra ciò che viene richiesto e ciò che viene effettivamente implementato in organizzazioni pubbliche che operano con vincoli di budget, cicli burocratici lenti e una cultura della sicurezza informatica che si è sviluppata in ritardo rispetto alla trasformazione tecnologica. E quindi le autorità di sistema portuale italiane dispongono delle condizioni necessarie per adempiere agli obblighi che NIS2 impone? Il coordinamento tra Ministero delle Infrastrutture e dei Trasporti, ACN e le singole autorità portuali è sufficientemente operativo da consentire la condivisione dell’intelligence sulle minacce prima che un attacco dimostri l’inadeguatezza dei presidi? La risposta a queste domande determina se Ancona resta un caso isolato o diventa il primo di una serie. La storia degli attacchi ai porti degli ultimi anni suggerisce con chiarezza quale delle due opzioni sia più probabile, se le condizioni strutturali non dovessero cambiare.
cybersecurity360.itJul 1, 2026extracted
Adriatic Port Cyber-Attack by Anubis Sparks Warning Over Maritime Security Risks
An attack by the Anubis ransomware group on a port authority on the Adriatic has been cast as a warning to maritime infrastructure. New analysis, published on June 11 by threat intelligence firm Resecurity, examined a cyber-attack which saw Anubis list the Adriatic Port Authority on its data leak site. The Adriatic Port Authority (Autorità di Sistema Portuale del Mare Adriatico Centrale), which runs the Italian port of Ancona, said the breach dated back to December 11 2025 and was attributed to Anubis in January 2026, when the group claimed it and leaked the data. The authority put the loss at about 2% of its data, with backups preserving the rest, and described most of the stolen material as public or soon-to-be-public, though employee records reached the dark web. Resecurity's account went further, describing crippled operations, rerouted vessels and a reported $10m Bitcoin ransom demand. The stolen data, according to Resecurity, included contracts, employee records and, more sensitively, port safety plans and details of security operations, the kind of information prized by groups involved in smuggling or insider recruitment. The firm believes the attackers gained access through a spear-phishing email targeting staff at the company that manages the port, then laterally moved to core systems. It said the attack did not need to target operational technology, working purely through IT weaknesses such as insecure cloud accounts managing Office 365 and Azure. The Anubis Affiliate Machine Anubis surfaced in December 2024 and launched an affiliate program in February 2025, renting out its toolkit through a ransomware-as-a-service (RaaS) model built around double extortion. It is unrelated to the older Android banking malware of the same name. Rather than a flat cut, the group offers affiliates 80% for deploying ransomware, 60% for data extortion and 50% for initial access brokers. A model it boasts has earned more than $20m, with victims across healthcare, construction and engineering. Resecurity tied the group to mass exploitation of internet-facing systems, often via known but unpatched flaws, including: SonicWall VPNs left without multi-factor authentication SolarWinds Web Help Desk (CVE-2025-26399) Cisco SSL VPNs The CitrixBleed 2 flaw (CVE-2025-5777) Beyond the port itself, Resecurity placed the attack in a run of ransomware hits on ports, from Maersk to Japan's Nagoya, and warned that outdated port IT and thin cyber maturity leave the sector exposed as digitization widens the attack surface, a growing maritime security concern it expects to deepen through 2030.
infosecurity-magazine.comJun 15, 2026extracted
Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack
Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: DockSec: Open-source AI-powered Docker security scanner DockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanation and remediation. Created by Advait Patel, the Python tool runs Trivy, Hadolint, and Docker Scout against a developer’s Dockerfile and image, correlates the findings, returns a 0-100 security score, and proposes line-specific fixes. Treating AI agents like service accounts for federated query security In this interview with Help Net Security, Paras Malhotra, CISO at Starburst, explains how the company handles data governance across federated query environments. Topics include layering Starburst’s access controls above native source permissions, tiering vendor risk across more than 200 partners and connectors, and building audit trails for autonomous agents. NOVA microhypervisor brings AMD DMA isolation to shared AI infrastructure BlueRock has issued the latest open-source release of its NOVA Microhypervisor with DMA remapping support for AMD platforms that have IOMMU hardware virtualization. The capability is enabled by default and extends hardware-level isolation across virtual machines, devices, and memory in shared execution environments. The security in smartphones is helping send them to landfills The WEEE Forum estimated that 5.3 billion mobile phones became electronic waste in 2022. Many of these devices still function. The average smartphone stays in use for about three years, and owners often replace handsets that retain enough computing power for other jobs. A team at the Université Libre de Bruxelles examined a barrier to giving those devices a second life. Every set of AI guardrails can be broken by the right prompt AI companies use guardrails to block harmful outputs such as deepfakes, malware, and instructions for biological weapons or illicit drugs. A new mathematical proof by Apostol Vassilev, a senior scientist at NIST, suggests those protections have inherent limits. For any finite set of guardrails, there exists a prompt that can bypass them if discovered. NOVA microhypervisor brings AMD DMA isolation to shared AI infrastructure BlueRock has issued the latest open-source release of its NOVA Microhypervisor with DMA remapping support for AMD platforms that have IOMMU hardware virtualization. The capability is enabled by default and extends hardware-level isolation across virtual machines, devices, and memory in shared execution environments. The security in smartphones is helping send them to landfills Billions of working smartphones reach the end of their service lives each year and move into drawers, recycling streams, and waste piles. The WEEE Forum estimated that 5.3 billion mobile phones became electronic waste in 2022. Many of these devices still function. The average smartphone stays in use for about three years, and owners often replace handsets that retain enough computing power for other jobs. A team at the Université Libre de Bruxelles examined a barrier to giving those devices a second life. Every set of AI guardrails can be broken by the right prompt Companies that build AI systems wrap them in guardrails meant to block harmful output, including deepfakes, malware, and instructions for making biological weapons or illicit drugs. When a user prompts the system for such content, the guardrails are designed to flag the request and refuse. A new mathematical proof sets a limit on how secure those guardrails can ever be. CISA orders federal agencies to “patch smarter” The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive that will change how the US federal government approaches vulnerability management. How to use NIST and ISO frameworks to govern AI agents Security leaders no longer need convincing that AI agents introduce risk. What’s missing is how to govern them once they move into production and begin operating autonomously across enterprise environments. CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) A vulnerability (CVE-2026-28318) that can be exploited to crash SolarWinds Serv-U file transfer servers is being leveraged by attackers in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Friday. The agency has ordered US federal civilian agencies to address it by June 19, 2026, either by implementing a patch or implementing mitigations. Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751) A Qilin ransomware affiliate is believed to be exploiting CVE-2026-50751, an authentication bypass vulnerability in Check Point VPN Remote Access and Mobile Access, the company announced on Monday. Check Point Remote Access VPN enables and secures connections between corporate networks and remote or mobile devices. LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271) A command injection vulnerability (CVE-2026-42271) in BerryAI’s LiteLLM open-source AI gateway is being exploited by attackers, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog on Monday. Record Microsoft Patch Tuesday, fresh zero-day Microsoft marked its largest-ever Patch Tuesday this month, by shipping fixes for nearly 200 vulnerabilities. Within hours, “Nightmare Eclipse”, the researcher behind weeks of escalating Windows exploit releases, dropped a proof-of-concept exploit for a new zero-day: “RoguePlanet”, which abuses a race condition in Windows Defender to spawn a command shell running with SYSTEM-level privileges. Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520) Ivanti has patched two critical vulnerabilities (CVE-2026-10520 and CVE-2026-10523) in Ivanti Sentry and has urged customers to implement the fix right away. Though the vulnerabilities are not known to be actively exploited, security researchers have already released technical details about the former, which may be used by attackers to craft a working exploit. Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert A zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools is being exploited in the wild, Charles Carmakal, CTO at cybersecurity firm Mandiant, part of Google Cloud, warned today. The architecture of subtraction: Why it’s time to erase the roads, not just map the traffic AI-assisted vulnerability discovery and exploit development are making patching increasingly inadequate as a primary defense. Advanced AI models can shrink the time from vulnerability discovery to exploitation from months to hours, while organizations struggle to patch systems as quickly as new flaws are identified. Product showcase: Staying ahead of the threat horizon with Aunoo Aunoo is an open strategic intelligence platform that uses AI agents to monitor intelligence sources, including for cybersecurity, to compile a daily briefing and alert on defined criteria. Each source is checked for credibility and quality before it is included. The platform runs in any browser and can send its findings via Slack, Discord, Teams, email or using the internal chat. When attacks spread too far: Lessons from real cyber attack case studies In this Help Net Security video, Michael Adjei, Director, Systems Engineering at Illumio, explains three real world cyber attacks and what went wrong during detection. Cyber resilience metrics that drive action In this Help Net Security video, Pete Bowers, COO at NormCyber, explains how organizations can build a cyber resilience metrics program that supports better decisions. He questions common ways of measuring resilience, such as risk registers, tool scores, and annual tests, and points out their limits. GitHub Copilot app launches as desktop home for AI coding agents GitHub introduced the Copilot app, a desktop application built for working with AI coding agents, at Microsoft Build 2026. The release expands GitHub’s Copilot product line beyond editor integrations and command-line tools into a dedicated workspace for directing several agents at once. Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup The 2026 FIFA World Cup will bring millions of visitors and an estimated 6 billion spectators to a tournament spread across 16 host cities in the United States, Canada and Mexico. In a new report, Intel 471 describes the 2026 FIFA World Cup as “the largest and most complex cyberattack surface in sporting history.” Hackers used Meta’s AI support system to hijack over 20,000 Instagram accounts Meta has revealed that attackers hijacked 20,225 Instagram accounts by exploiting a flaw in the company’s AI-assisted account recovery system. According to the company, a vulnerability in High Touch Support (HTS) allowed unauthorized parties to perform password resets on Instagram accounts. Microsoft changes how Defender for Endpoint EDR updates are delivered on Windows Microsoft will distribute Defender for Endpoint EDR updates through Microsoft Update, enabling EDR security improvements to be released independently of monthly Windows operating system updates. The rollout started for Windows 10 devices in late May 2026 and will expand to Windows 11 and other supported Windows versions later this year. Microsoft expects deployment to be completed by fall 2026. Meta claims NSO Group still targets WhatsApp users despite court order Meta claims it disrupted spear-phishing attempts linked to NSO Group and is asking a US federal court to hold the spyware vendor in contempt for allegedly violating an injunction that bars it from targeting WhatsApp and its users. Mythos Preview can weaponize N-day vulnerabilities in hours Mythos Preview can develop working exploits from newly disclosed software vulnerabilities in hours, cutting down a process that has historically taken days or weeks, according to Anthropic. Google patches Chrome zero-day exploited in the wild (CVE-2026-11645) Google has fixed 74 vulnerabilities in Chrome, including a high-severity zero-day (CVE-2026-11645) that has been exploited in the wild. The fix has been shipped in Chrome 149.0.7827.102/.103 for Windows and macOS and Chrome 149.0.7827.102 for Linux, with the update rolling out to users over the coming days and weeks. French government messaging platform breached through account hijacking French authorities are investigating a compromise of Tchap, the government’s secure messaging platform, after hackers hijacked a user account and gained access to public chat rooms. Anthropic’s Claude Fable 5 is out for public use, with safeguards for high-risk requests Days after publishing research on how advanced AI systems could amplify cyber operations in the wrong hands, Anthropic released Claude Fable 5, a Mythos-class model for general use. The company said Mythos-class models possess advanced cybersecurity and research biology capabilities that can provide information and guidance beyond what is typically available through conventional online sources. New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials A new Browser-in-the-Browser (BitB) phishing campaign is targeting Microsoft 365 users with fake login popups designed to closely mimic legitimate browser authentication windows, according to Palo Alto Networks Unit 42. Identity theft is turning into a chain reaction for victims For a growing number of victims, identity theft no longer ends with a fraudulent charge or a compromised account. More than one in four people who contacted the Identity Theft Resource Center during the reporting period were dealing with multiple identity-related incidents, according to the organization’s 2026 Trends in Identity Report. X Square Robot open sources its robot-free data collection framework Companies building robots for physical work spend large amounts of time and money operating machines by hand to gather training examples. Each session with a physical robot produces a small number of demonstrations per day, which slows the growth of datasets used to train embodied AI. Human demonstrators offer a cheaper source of data, and X Square Robot has put a system for this approach into public release. Making the cloud prove it followed your privacy wishes Companies that store personal data in cloud key-value databases should handle deletion requests by running the operation and confirming the job is complete. The people making those requests and the regulators overseeing them have had limited means to confirm the data is gone or that the record of its removal is genuine. GDPRuler, a middleware system from researchers at the Technical University of Munich and the University of Lisbon, sits between an application and an unmodified key-value database and enforces privacy rules as data passes through it. 9 out of 10 people can no longer distinguish real from AI-generated content Online fraud is becoming harder to distinguish from legitimate activity as AI-generated messages, voices, photos, reviews, and identities become more convincing. Nearly nine in ten adults say they can no longer tell what is real from AI-generated content, according to the latest Malwarebytes survey. The share increased from 66% in 2025 to 85% in 2026. FBI seizes 13 websites linked to alleged Chinese intelligence-gathering effort Federal authorities have seized 13 internet domains allegedly used to target current and former U.S. government employees and military personnel with access to classified and sensitive information. 52% of direct-to-IP threats are missing from intelligence feeds Security tools are good at inspecting websites, domains, URLs, and files, so attackers are moving lower in the stack and communicating directly with IP addresses, where visibility is limited. According to Palo Alto Networks’ report, this creates a visibility gap that allows malicious traffic to blend into normal internet activity and evade detection. Google Colab CLI opens runtimes to Claude Code and Codex Google released the Google Colab Command-Line Interface, a tool that connects local terminals to remote Colab runtimes. The CLI provides an execution platform for developers and AI agents, letting users provision compute, run local Python scripts on remote runtimes, and retrieve artifacts back to local machines. OpenAI is locking down parts of ChatGPT to reduce data theft risks OpenAI has started rolling out Lockdown Mode for ChatGPT, an optional security setting that restricts access to external resources and several product capabilities. It is available for personal accounts, including Free, Go, Plus, and Pro plans, as well as self-serve ChatGPT Business accounts. Samsung just made Galaxy phones more secure in One UI 9 beta Samsung’s One UI 9 beta integrates Lockdown mode into the power menu. This is the screen that contains Power off, Restart, and emergency options. Opening it initiates Lockdown mode, disabling biometric authentication. The security questions around Chinese AI coding models in U.S. software Software developers across the United States are using AI models built in China to write, debug, and review code, drawn by prices below those of American alternatives. These models carry risks for the security of American software, according to a report from Booz Allen Hamilton, which tested how the models respond when the user appears to work for the U.S. government. Malware ships with bugs that defenders could use against it Static analysis tools have spent years scanning legitimate software for security bugs before it goes out the door. The same scanners work on malware, and malware carries a steady supply of its own bugs. Researchers ran four of these tools across 658 leaked malware projects and found that close to 90 percent contained at least one recognized software weakness. Apple expands what parents can block, approve, and limit Apple has previewed a set of new child safety features coming to iPhone, iPad, and the Mac later this year, expanding parental controls with tools that help families manage app access, web browsing, communication, and screen time. Apple Intelligence can now replace weak passwords without user intervention Apple’s next generation of Apple Intelligence, the company’s personal intelligence system, expands its capabilities and introduces new security features in Passwords. With the new update, Passwords can automatically replace weak or compromised passwords. Scams now operate like real businesses with budgets and targets Social media has overtaken email as a primary attack vector, showing changes in how people consume information and interact online, according to Bitdefender’s Global Scam Intelligence Report 2026. Fraud campaigns use advertisements, sponsored content, impersonation pages, and direct messages to reach users. Apple extends Private Cloud Compute to third-party data centers Apple is bringing its Private Cloud Compute (PCC) platform to Google Cloud, expanding the infrastructure behind Apple Intelligence to third-party data centers. Introduced in 2024, PCC provides cloud-based processing for AI workloads that exceed the capabilities of on-device models while maintaining Apple’s security and privacy guarantees. Building reusable workflows with custom agents in Copilot CLI Developers spend much of their working time in the terminal, generating commands, debugging issues, and running scripts close to their systems. Repeated terminal work tends to pile up small steps such as re-running the same commands, re-explaining context, and translating logs into a form a team can act on. Custom agents in GitHub Copilot CLI address these patterns by turning repeated tasks into reusable workflows. Organizations can’t see much of their mobile AI activity Organizations have limited visibility into AI activity on mobile devices despite security leaders expressing confidence in their AI governance, according to Lookout’s “Solving for the Mobile AI Blind Spot: Executive Confidence Meets Technical Reality” report. Prompt injection still drives most agentic AI security failures in production A backdoor sat on PyPI for three hours in March 2026. Nearly 47,000 downloads occurred during the window. The compromised package, LiteLLM, serves as the language-model gateway for CrewAI, DSPy, Microsoft GraphRAG, and dozens of other AI agent frameworks. Anyone pulling an update during that window pulled in an autonomous attack bot named hackerbot-claw along with it. Threat actors are recruiting the people who hold cloud logins Companies keep most of their data and applications in cloud platforms that anyone can reach with the right login. That setup turns each employee holding those credentials into a security variable, and members of the cybercrime underground have built methods to reach those people. Intel 471 tracked this activity into 2026 and sorted insider risk into three categories that cloud-reliant organizations contend with. Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware Cybercriminals are using TikTok and Instagram Reels videos to spread Vidar, an infostealer malware, through fake downloads for popular paid software, according to ReversingLabs. The researchers uncovered two campaigns behind the activity, each using a different approach to draw in viewers before sending them to external download sites. Google sues China-based scammers over Gemini AI abuse Google has filed a lawsuit against Outsider Enterprise, a China-based cybercrime network for using AI tools, including Gemini, to build phishing websites and scam infrastructure. Cybercriminals are moving away from mass phishing campaigns Phishing activity declined by roughly 20% in both 2024 and 2025, according to research from Zscaler’s ThreatLabz team. The drop followed years of growth that pushed phishing activity above 2 billion hits in 2023. Authorities dismantle crypto laundering service that moved €336 million for cybercriminals An international law enforcement operation has dismantled a cryptocurrency laundering service linked to ransomware groups and other cybercriminals that processed more than €336 million in illicit funds. Cybersecurity jobs available right now: June 9, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: June 12, 2026 Here’s a look at the most interesting products from the past week, featuring releases from AISLE, Drata, Elastic, Filigran, IDnow, and Ridge Security.
helpnetsecurity.comJun 14, 2026extracted
Splunk, Palo Alto Networks Patch Severe Vulnerabilities
Splunk and Palo Alto Networks on Wednesday rolled out patches for multiple vulnerabilities across their product portfolios, including critical and high-severity bugs. Palo Alto Networks drew attention to a high-severity security flaw in the Cortex XSOAR and Cortex XSIAM platforms that could allow attackers to access and modify restricted resources. Tracked as CVE-2026-0274, the issue is described as the improper validation of credentials in the CommvaultSecurityIQ integration of the affected products and does not require a special configuration to be triggered. The company also rolled out patches for eight medium and low-severity security defects in PAN-OS, Prisma Access Agent, Cortex XSOAR, and GlobalProtect App. Palo Alto Networks says it is not aware of any of these vulnerabilities being exploited in the wild. On Wednesday, Splunk published a dozen advisories detailing security weaknesses in its products and third-party libraries they use. The most severe of the bugs is CVE-2026-20253 (CVSS score of 9.8), a critical-severity arbitrary file creation and truncation issue affecting Splunk Enterprise. Unauthenticated attackers can exploit the flaw through a PostgreSQL sidecar service endpoint. “The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials,” Splunk explains. Splunk also released fixes for three high-severity Splunk Enterprise security defects that could lead to remote code execution (RCE), SSRF attacks, and XSS attacks, respectively. Additionally, the company patched four medium-severity bugs in Splunk Enterprise, and another in Splunk SOAR, warning they could be exploited to exfiltrate sensitive data, reassign saved search ownership to arbitrary users, or inject ANSI escape codes into SOAR application log files. Splunk also rolled out fixes for roughly three dozen vulnerabilities in third-party software components in Splunk Enterprise and Splunk SOAR. The company made no mention of any of these vulnerabilities being exploited in the wild. UPDATE 06.19.2026: Splunk has confirmed that CVE-2026-20253 has been exploited in attacks. Related: Critical FreeScout Vulnerability Leads to Full Server Compromise Related: SolarWinds Patches Four Critical Serv-U Vulnerabilities Related: Hackers Abuse QEMU for Defense Evasion Related: Several Code Execution Flaws Patched in Veeam Backup & Replication
securityweek.comJun 11, 2026extracted
No Patch Planned for Exploited Arista EOS Vulnerability
Hackers have been exploiting a vulnerability in Arista Extensible Operating System (EOS) as a zero-day that will not be patched. Arista EOS is a modular, Linux-based network operating system designed for the vendor’s high-performance switches for data center, cloud, and enterprise environments. Tracked as CVE-2026-7473 (CVSS score of 6.9), the security defect exists because, in certain configurations, the tunnel protocol type is not verified, potentially leading to non-configured tunnel traffic being processed. The flaw can be triggered only on devices running Arista EOS that have been configured as a tunnel endpoint with a decapsulation IP, such as decap-groups, a GRE (Generic Routing Encapsulation) tunnel interface, or VXLAN (Virtual Extensible LAN). “A device configured to decapsulate one tunnel type will also incorrectly accept and decapsulate other tunnel protocols destined to the same IP address, even if those protocols were not explicitly configured,” Arista explains. According to the company, the security defect impacts 7020R, 7280R/R2, and 7500R/R2 series products. Certain IP-in-IPv6 and GUE IPV6 decap group scenarios apply to 7280R3, 7500R3, and 7800R3 series devices. “This issue has been reported as being exploited in the wild,” Arista notes in a May advisory. The company has provided detailed mitigation instructions, but noted that no patches or hotfixes will be released to address the vulnerability. “No software upgrade path is planned to address this issue due to the risk of breaking existing configuration on deployments. The recommended resolution of this issue is to follow the appropriate mitigation instructions,” Arista says. On Tuesday, the US cybersecurity agency CISA added CVE-2026-7473 to its Known Exploited Vulnerabilities (KEV) list, urging federal agencies to address it within two weeks. CISA also expanded its KEV list to include two recently disclosed flaws, one in Chrome (CVE-2026-11645) and another in Cisco SD-WAN (CVE-2026-20245), both of which have been exploited in the wild as zero-days. Related: Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation Related: Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks Related: Everest Forms Vulnerability Exploited to Hack WordPress Sites Related: SolarWinds Serv-U Vulnerability Exploited in the Wild
securityweek.comJun 10, 2026extracted
Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks
Check Point on Monday warned that a critical-severity authentication bypass vulnerability affecting its VPN and firewall products has been exploited in the wild as a zero-day. Tracked as CVE-2026-50751 (CVSS score of 9.3), the security defect is described as a logic flow weakness in the validation process of Remote Access and Mobile Access certificates. It exists in the deprecated IKEv1 key exchange and allows remote attackers to establish VPN sessions without a valid password. According to Check Point, the vulnerability has been exploited in the wild since May 7, with activity surrounding it increasing in early June. “To date, the observed exploitation has been limited to a few dozen targeted organizations globally,” the company notes in its advisory. Check Point also says that at least one attack was confirmed to have been mounted by a Qilin ransomware affiliate. “Based on the post-exploitation activity we observed, we assess with medium confidence that the actor behind the exploitation of CVE-2026-50751 is financially motivated and uses Qilin ransomware. We believe that this threat actor infrastructure is exploiting other VPN related vulnerabilities such as the ones published by Palo Alto, Fortinet and F5,” Check Point notes. While investigating the security bug, the company identified a second issue in the IKEv1 key exchange’s certificate validation logic. Tracked as CVE-2026-50752, it allows attackers to mount man-in-the-middle attacks on VPN site-to-site connections, but has not been exploited in the wild. Check Point has released hotfixes for the vulnerable appliances to address both CVEs, as well as indicators of compromise (IoCs) and mitigation guidance. On Monday, the US cybersecurity agency CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it by June 11. Related: Google Patches 5th Chrome Zero-Day Exploited in 2026 Related: Everest Forms Vulnerability Exploited to Hack WordPress Sites Related: SolarWinds Serv-U Vulnerability Exploited in the Wild Related: Cisco Warns of Available PoC for Critical Unified CM Vulnerability
securityweek.comJun 9, 2026extracted
8th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 8th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES DentaQuest, a U.S. dental benefits administrator owned by Sun Life, has suffered a data breach after threat group ShinyHunters leaked exfiltrated data. Analysts assessed that 2.6 million accounts were exposed, including names, emails, government IDs, and health insurance details. Password manager Dashlane has disclosed an attack in which threat actors brute-forced two-factor codes to register unauthorized devices and download encrypted password vaults for less than 20 users. The campaign began May 31 and was contained after lockouts. The United Nations World Food Programme has disclosed unauthorized access to its Gaza self-registration application, exposing names, identification numbers, mobile numbers, and location data. The breach affected about 600,000 Palestinian households across Gaza, and WFP suspended the platform while responding to the incident. Russia’s Federal Security Service claims that foreign intelligence agencies hacked mobile devices belonging to senior Russian officials. The alleged spyware operation enabled access to correspondence, calls, geolocation data, contact lists, and covert audio and video surveillance. Hola, whose Windows browser serves millions of users, has confirmed a supply chain compromise that pushed an unauthorized executable to some users. The file operated as a cryptominer, installed as a Windows service, and excluded itself from Defender. An independent review found impact limited to about 0.1% of users. AI THREATS Check Point highlighted an AI security risk after reports that attackers used Meta’s AI support chatbot to seize Instagram accounts. Granting AI agents account recovery authority to change emails or approve requests without identity checks can enable unauthorized access, showing that permissions and verification shape the risk. Researchers demonstrated a notification-based prompt injection technique called Fake Context Alignment that manipulated Google’s Gemini voice assistant through incoming messages. The attack hid authorization prompts and enabled device control, auto-joining Zoom video calls, and cross-device memory poisoning. Google deployed classifier updates after disclosure. Researchers described an AI-enabled EDR evasion lab where a threat actor automates malware development and testing against Sophos, CrowdStrike, and Microsoft Defender. LLM-driven agents and an automated Active Directory panel coordinate iterative trials, supporting stealthy post-exploitation tied to ransomware deployment and data theft. VULNERABILITIES AND PATCHES Google has released its June Android security patch for 124 vulnerabilities, including CVE-2025-48595, a high-severity Android Framework flaw under exploitation. Local attackers can use the vulnerability to gain code execution and escalate privileges on devices running Android 14 or later. Cisco has released patches for CVE-2026-20230, a critical Unified Communications Manager and Session Management Edition flaw that allows unauthenticated network attackers to write files and escalate to root. A public proof-of-concept was already published. The bug requires WebDialer enabled, and fixes include 14SU6 and an interim 15.x COP. SolarWinds Serv-U CVE-2026-28318 has been exploited in attacks against file transfer servers. The unauthenticated flaw lets crafted HTTP POST requests using a deflate header crash the service and disrupt operations. SolarWinds fixed the vulnerability in Serv-U 15.5.4 HF1. CVE-2026-41089 in Microsoft Windows Netlogon is being exploited in attacks against Windows Server domain controllers. The critical stack-based buffer overflow flaw can allow remote code execution through crafted network requests. Successful exploitation may give attackers SYSTEM-level control of domain controllers in vulnerable Active Directory environments. Check Point IPS provides protection against this threat (Microsoft Windows Netlogon Remote Code Execution (CVE-2026-41089)) THREAT INTELLIGENCE REPORTS Check Point Research has investigated a large-scale impersonation and click-hijacking scheme that reroutes downloads from fake open-source sites through a gated traffic distribution system. Impersonating tools like Ghidra and dnSpy, it led to infection by RemusStealer, AnimateClipper, and a new loader called SessionGate. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Check Point Research linked a Dutch seizure of about 800 servers at hosting provider WorkTitans B.V. to Iranian cyber espionage operations. MuddyWater, Agrius, and Nimbus Manticore used this infrastructure for attacks that enabled remote access, credential theft, and scanning. Check Point researchers have surveyed the 2026 U.S. midterm threat landscape, finding that operations focus on phishing, brand impersonation, and domain abuse rather than ballot tampering. Russian-linked Doppelganger networks cloned major media sites, vote-related domains increased, and exposed ActBlue and WinRed credentials surfaced. Researchers identified a months-long espionage campaign that covertly siphoned a senior executive’s Microsoft Outlook mailbox at a major global stock exchange. Attackers used legitimate cloud storage services and disguised update tasks to persist and move data in small batches, enabling five months of undetected access.
research.checkpoint.comJun 8, 2026extracted
⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
Monday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through repos. The ugly part: basic tricks still worked. A chatbot got fooled. A bot token got leaked inside the malware. The same old mistakes showed up again. And while everyone chased the loud stuff, quieter attackers sat in inboxes for months, reading mail and stealing it bit by bit. Lots to cover. Grab coffee. Read up. ⚡ Threat of the Week Miasma Worm Hits 73 Microsoft GitHub Repositories in Supply Chain Attack - Microsoft's GitHub repositories became the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including Azure, Azure-Samples, Microsoft, and MicrosoftDocs. The development prompted GitHub to disable access to those repositories. Miasma is assessed to be a variant of the Mini Shai-Hulud worm that TeamPCP publicly released in mid-May 2026. Your VPN is Helping Attackers Move as Fast as AI The Zscaler ThreatLabz 2026 VPN Risk Report reveals a dangerous disconnect: while attackers use AI to move at machine speed, legacy VPNs are leaving defenders blind and exposed. When you can’t see what’s happening, response time collapses and the odds of containment drop with it. Get the Report ➝ 🔔 Top News Google Fixes Android Framework Flaw Under Exploitation - Google released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation. Tracked as CVE-2025-48595 (CVSS score: 8.4), the security flaw has been described as a case of privilege escalation without requiring any user interaction. The vulnerability impacts devices running Android versions 14, 15, 16, and 16 QPR2 (Quarterly Platform Release 2). Google has acknowledged there are indications that CVE-2025-48595 may be under "limited, targeted exploitation." As is typically the case, the tech giant did not reveal any specifics about who may have been behind the activity, the targets affected, and the scale of such efforts. U.S. Action Disrupts Investment Fraud Schemes - The U.S. Department of Justice announced the results of a sweeping action undertaken by government authorities and private sector companies to combat cyber-enabled and cryptocurrency fraud targeting Americans. The "Disruption Week" operation led to the takedown of millions of social media, email, and internet access accounts used by transnational cybercrime groups in Southeast Asia to defraud victims. Private sector entities voluntarily froze over $3.8 million in cryptocurrency involved in the laundering of funds stolen from Americans. The efforts are part of an ongoing U.S. government initiative called Scam Center Strike Force, which aims to dismantle transnational criminal organizations running cyber-enabled fraud and "pig butchering" (aka romance baiting) scams from compounds in Southeast Asia, along with the human trafficking and money laundering operations that fuel the illicit enterprise. China-Linked TA4922 Broadens Focus to Europe, Africa - A new Chinese-speaking cybercrime group has expanded its reach from East Asia into Europe and Africa, while rapidly overhauling the malware it employs to hack into corporate networks. The actor, tracked as TA4922, is financially motivated and focused on gaining remote access to victim systems for data theft, fraud, and the resale of access. Some elements of the threat actor's tactics overlap with Silver Fox and Void Arachne. Its operations are unusually varied, leveraging malware delivery, credential phishing, and credit card theft across different campaigns. While historical attacks targeted Japan, the actor has also targeted organizations in Taiwan, Korea, Singapore, and India, the U.K., Germany, Italy, and South Africa. The lures are localized, impersonating tax authorities, finance departments and human resources teams in the target's own language to distribute Atlas RAT, RomulusLoader, and SilentRunLoader through DLL side-loading techniques. OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework - A previously unreported threat cluster dubbed OP-512 has been observed targeting Microsoft Internet Information Services (IIS) servers to deploy a bespoke web shell framework. The espionage-focused activity has been assessed as originating from China. "OP-512 was highly likely conducting espionage through a compromised Internet Information Services (IIS) web server on an organization whose sector and geography align with China-linked intelligence priorities," ReliaQuest said. The web shell framework facilitates file management and authenticated command execution. Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for 5 Months - Unknown threat actors managed to spy on a senior member of an unnamed global stock exchange for at least five months. There are still several unanswered questions, like who was behind it and how they obtained initial access. However, what's evident is that the attacker spent several months inside the Outlook mailbox and likely accessed sensitive information. The goal of the operation was most likely cyber espionage, but details are scant on which stock exchange was targeted. The earliest sign of malicious activity was observed on October 10, 2025. The attack led to the deployment of a mailbox stealer that ran in 2-4 week intervals to hoover up email data. The captured information was exfiltrated via Dropbox and Microsoft OneDrive Personal, transferring only small batches at a time to avoid raising any red flags. The data exfiltration runs lasted through March 2026. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-28318 (SolarWinds Serv-U), from CVE-2026-39210 through CVE-2026-39217 (FFmpeg), CVE-2026-20245 (Cisco Catalyst SD-WAN Manager), CVE-2026-20230 (Cisco Unified Communications Manager), CVE-2026-3300 (Everest Forms Pro plugin), CVE-2025-48595 (Google Android) CVE-2026-8501 (PCTCore64.sys), CVE-2026-10629 (Verizon IMS network), CVE-2026-7299 (Appsmith), CVE-2026-10621, CVE-2026-10622 (Collibra Agent), CVE-2026-0826 (HP Poly Voice), CVE-2026-8206 (Themeum Kirki - Freeform Page Builder, Website Builder & Customizer plugin), CVE-2026-23479, CVE-2026-23631 aka DarkReplica, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589 (Redis), CVE-2026-49200, CVE-2026-49201 (Acer Wave 7 routers), CVE-2026-8874, CVE-2026-8876, CVE-2026-8878, CVE-2026-8879, CVE-2026-8881, CVE-2026-8888, CVE-2026-8889 (Securly), CVE-2026-10881, CVE-2026-10882, CVE-2026-10883 (Google Chrome), CVE-2026-41722, CVE-2026-41723, CVE-2026-41724 (Broadcom VMware Cloud Foundation Operations), CVE-2026-34908, CVE-2026-34909 (UniFi OS Server), CVE-2026-4372 (Hugging Face), CVE-2026-45495 (Microsoft Edge), CVE-2026-42253 (Apache ActiveMQ), CVE-2026-9614 (Ivanti ISTM), CVE-2026-48019 (laravel/framework), CVE-2026-5386 (KMW CCTV security cameras), CVE-2026-5509 (TP-Link Archer BE450 v1 and Archer BE7200 v1), CVE-2026-4387 (StrongDM), CVE-2026-8633 (IBM WebSphere), and CVE-2026-9739 (MCP Toolbox). 🎥 Cybersecurity Webinars Learn How to Validate What Your SIEM, EDR, and SOC Catch → Automated pentesting finds flaws. It doesn't prove your defenses caught them. Join Picus experts to learn where testing falls short, why "clean" reports can mislead, and how validation shows what your SIEM, EDR, and SOC actually detect. Stop AI-Powered Attacks Before They Spread → AI is making cyberattacks faster, harder to spot, and easier to scale. This webinar shows why old defenses fail against threats like Mythos-and how Zero Trust helps block movement, limit damage, and stop attacks before they grow. Learn How to Detect and Stop Risky AI Use in Real Time → AI tools are spreading through the workplace faster than security teams can control. Every pasted file, prompt, or piece of code can expose sensitive data to systems that the business never approved. This webinar shows how to detect risky AI use, stop leaks in real time, and keep company data out of uncontrolled AI tools. 📰 Around the Cyber World Five Eyes Warns of China Exploiting LinkedIn to Target Security Personnel - Chinese military intelligence services are using LinkedIn and other professional networking sites like Indeed and Upwork to recruit people with access to government, military, foreign policy, or sensitive economic information, the U.S. and its Five Eyes intelligence partners said in an advisory. The aim is to acquire privileged military, political and economic intelligence that can provide China with a strategic and tactical advantage over the Five Eyes, per the advisory. "These actors use an aggressive online recruitment strategy whereby intelligence officers or their affiliates pose as employees of private consultancies, think tanks, or human resources firms, and place online job advertisements for foreign policy and defense analysts," the agencies said. Bloomberg reported that China has been targeting Five Eyes nationals with security clearance, particularly those working in foreign affairs, security, and intelligence, and military personnel, including people stationed in the Asia-Pacific region, as well as journalists, academics, and think-tank employees with knowledge of unclassified information. Targets are offered payments in exchange for increasingly privileged information. Payments may arrive through a number of online platforms, including reputable services like PayPal, Zelle, and Wise, or via Western Union and cryptocurrency. Over 20K Accounts Likely Impacted in Instagram Attack Campaign - Meta has revealed that 20,225 Instagram accounts may have been impacted in a recent attack abusing an AI-powered support tool. The attacks involved compromising the accounts simply by asking Meta's chatbot to link their own email address to the targeted account. This enabled unauthorized third parties to reset the account password and take control of it. Many of the high-profile accounts were then sold on the dark web. The exploitation of the High Touch Support (HTS) tool was discovered on May 31, 2026. The filing published on Maine's Attorney General website lists April 17 as the date when the breach occurred, indicating the first unauthorized access may have occurred weeks before it was discovered. It's currently what personal information, if any, the threat actors may have accessed. The use of the tool has since been disabled. The development comes as a vulnerability was disclosed in Instagram's web-based password reset flow that exposed unredacted email addresses and phone numbers associated with user accounts when providing a user name as input. Hola Browser for Windows Compromised to Deliver Cryptocurrency Miner - Sophos discovered an XMRig cryptocurrency miner binary bundled within a certified version of the Hola Browser installer for Windows. Hola attributed the anomaly to a supply chain compromise affecting its "update distribution pipeline," which allowed the unauthorized payload to evade detection. "This was a supply chain compromise, and critically, no user data was accessed, exfiltrated, or compromised at any point during this incident affecting 0.1% of users," Hola said. "We have since completely rebuilt our distribution pipeline, implemented advanced code-signing verification, and introduced tighter access controls and continuous monitoring across our infrastructure." Malicious npm Packages Target Trusted Brands - A threat actor has been deploying dozens of malicious packages to npm targeting AI companies, luxury brands, and venture capital firms. These packages drop a new malware strain that impersonates an AI coding tool. The malicious code is launched by means of a post-install hook. "When the binary payloads are run, a terminal window pops up and prompts the user for user information and OpenAI or Anthropic API keys," OpenSourceMalware said. "Meanwhile, in the background, the malware is already harvesting ~/.local/share/stardrop/auth.json and other files for credentials." 2 npm Packages Deliver Epsilon Stealer - Two malicious npm packages, turbo-axios and faster-axios, targeted developers searching for the popular axios HTTP client. "Both are trojanized copies of the real axios source with a single addition: a postinstall hook that fetches and eval()s remote JavaScript," SafeDep said. "The chain terminates in Epsilon Stealer, a malware-as-a-service (MaaS) Electron infostealer that harvests browser credentials, crypto wallets, and messaging sessions, then opens a persistent WebSocket channel for arbitrary command execution." Malicious npm Package Leaks Own Telegram Bot Token - In a related development, OX Security flagged a malicious npm package named cms-store-ren that exfiltrates data to Telegram, while leaking its own bot API token in the process. "cms-store-ren is a malicious npm package that collects data from developers' machines and then sends them to a Telegram channel," OX Security said. "It also downloads a potentially malicious JavaScript file from a remote server and tries to execute it, although this behavior wasn't yet weaponized. The package acts as a downloader/loader whose primary purpose is to fetch and execute a second-stage payload while reporting successful infections back to the malicious actor." Fake Document Factory Taken Down in Spain - French and Spanish authorities, with support from Europol, dismantled an online marketplace selling fake identity documents to migrant smuggling rings operating in Europe to evade border controls, fraudulently obtain residence rights, and facilitate secondary movements within the region. The counterfeit document production facility, located in Alicante, Spain, led to one arrest and the seizure of approximately 800 forged European documents, document-production equipment, digital devices, a vehicle, and €1,580 in cash. "The search of the apartment, rented under a false name, uncovered a fully operational counterfeit document workshop, highlighting the industrial-scale production methods increasingly used by organised crime groups involved in document fraud," Europol said. Former IBM Executive Accuses Company of Covering Up Hacks - A former IBM cybersecurity executive accused the company of getting hacked three times in the previous decade by foreign governments and then covering up the breaches. William Barlow, who was IBM's vice president of threat intelligence until August 2019, said IBM concluded Chinese hackers breached its core network between 2013 and 2016, but that the software company went on to conceal the incidents and never publicly disclosed them. Breaches at two other IBM subsidiaries were also covered up in a similar manner, a lawsuit unsealed last week revealed. Gafgyt Botnet Variant Targets DD-WRT Router - A new variant of the Gafgyt botnet called C0XMO is now targeting DD-WRT router firmware by exploiting a stack buffer overflow vulnerability (CVE-2021-27137). "Unlike earlier versions, this malware separates its lateral movement into a standalone Python script," Fortinet FortiGuard Labs said. "This approach helps the attacker target various system architectures and device types more efficiently." The activity was discovered in March 2026 in connection with an attack targeting a Japanese technology firm. Once C0XMO is delivered and executed on the victim host, it sets up persistence, terminates competing processes and red teaming utilities, and then establishes a connection with a remote server to accept DDoS attack commands against specific targets. It also comes with a scanner to facilitate lateral movement via SSH, Telnet, Android Debug Bridge (ADB), and other HTTP-based exploits (e.g., CVE-2025-34054, CVE-2016-15047, CVE-2015-2051, CVE-2022-35914, and CVE-2021-27137). Malicious PyPI Package Drops Backdoor - Parsimonius, a malicious typosquat of the parsimonious Python package, "incorporated the legitimate parsimonious parsing functionality to avoid suspicion while simultaneously deploying a Telegram-based backdoor," Zscaler said. "Once installed, the backdoor provided attackers with remote access capabilities and facilitated the theft of sensitive data, including .env files and bot authentication tokens." The package racked up 2,474 downloads, prior to it being removed. VECT Ransomware Suffers From New Flaws - A new analysis of the Windows version of VECT ransomware has uncovered additional vulnerabilities that "can leave files renamed, partially encrypted, inconsistently modified, or damaged in ways the attacker's own decryptor cannot reliably reverse," Morphisec revealed. "These bugs change the recovery picture. A VECT incident does not necessarily produce one clean class of encrypted files. The same .vect suffix can represent several outcomes: a file that was only renamed, a file encrypted in a single pass, a large file with only selected regions modified, or a file left inconsistent by failed writes or shared-state races." Handala Brand Used for Physical and Influence Operations - Recorded Future has revealed that Iran's Ministry of Intelligence (MOIS) has likely expanded the use of its Handala persona to include external physical and influence operations targeting U.S. and Israeli interests, bringing cyber, physical, and influence personas under a single umbrella. The threat intelligence company said it observed significant overlaps in the online activities of Handala Hack Team, a new Handala-branded persona named "Handala Popular Resistance Front," and three influence operations networks dubbed VIPEmployment, MOISIRAN, and Brave Israel. "Notably, the HPRF and the three influence operations networks all almost certainly share a modus operandi: their administrators solicit individuals to conduct physical attacks and espionage targeting U.S. and Israeli entities, on behalf of Iranian intelligence agencies, for a financial reward," Recorded Future said. "By encompassing these groups under the Handala brand, MOIS likely seeks to take advantage of Handala's global recognition to amplify its solicitation efforts." New Android Trojan OverlayPhantom Spotted - A new Android banking trojan referred to as OverlayPhantom has been observed targeting more than 180 apps across 10 countries via malicious URLs, aiming to steal credentials via fake overlays and real-time screen sharing. "The malware employs a two-stage infection chain, using a dropper application that impersonates trusted platforms, including the official Austrian government identity application, ID Austria, and the widely used consumer platform TikTok, to deceive victims into installing it," Cyble said. "Once deployed, OverlayPhantom masquerades as 'Google Play Services' and abuses Android's accessibility service to gain persistent, elevated control of the infected device." The malware is equipped to run over 30 remote commands to enable automated gestures, clipboard manipulation, credential theft, and data exfiltration. Targets of the malware include financial and cryptocurrency apps serving users in the U.S., Australia, Germany, France, Belgium, Finland, the Netherlands, Italy, Spain, and the U.K. Fake Copyright Infringement Notice Emails Lead to Credential Theft - Threat actors are using official-looking copyright removal requests to target Chrome extension developers, warning them of imminent removal and urging them to appeal by clicking on a link ("dmca-chrome-extensions[.]click") within 48 hours. "After you enter your extension's ID to 'verify' it, the page pulls in your extension's real name and icon," Malwarebytes said. "But it's all part of a phishing attack designed to steal your Google username and password." Other campaigns have been found to use pirated PC games and modified installers for franchises like Far Cry, Need for Speed, FIFA, and Assassin's Creed to distribute a Windows password-stealing malware; fake payment invoices that trick recipients into calling a bogus customer support agent as part of refund scams; counterfeit websites impersonating BlueWallet and OpenAI ChatGPT to deliver a macOS stealer and clipper. For Windows systems, the website mimicking ChatGPT is used to deliver a credential-stealing malware loader, while Mac users get Odyssey Stealer, a fork of Atomic Stealer (AMOS). Bypassing Malicious Skill Scanners - Trail of Bit said it was able to bypass ClawHub's malicious skill detector, Cisco's agent skill scanner, and scanners integrated into skills.sh to push rogue skills to public skill marketplaces and steal sensitive data from developer systems. One of the malicious skills used prompt injection to "convince the guard model that the malicious payload is nothing to worry about," the company said. "The skill tells the agent to configure its package managers (npm and yarn) to use an attacker-controlled registry, but dresses the subterfuge up in the language of corporate environment configurations and virtual private network access to convince the LLM analyzer the change is innocuous." The takeaway here is that trust can never be outsourced to a third-party scanner and that they cannot reliably detect malicious content in agent skills. To counter the risks, organizations are recommended to curate skill marketplaces for their employees and agents using trustworthy open-source collections. Phishing Campaigns Drop Remcos RAT - Payment slip-themed phishing emails are being used to distribute a link pointing an external file-hosting service like MediaFire, which triggers the download of a screen saver (.SCR) file, which kicks off a multi-stage chain that ends in the deployment of Remcos RAT by means of an AutoIt script after performing anti-analysis checks. The activity has been attributed by JUMPSEC to a threat group called BlackToad, which is likely an affiliate of the broader Nigerian e-crime ecosystem that's tracked as SilverTerrier with its own set of targeting lures and tradecraft. It also exhibits some infrastructure overlap with a cluster documented by Agoda Engineering as BoredFluff, which targeted hotel staff in 2024 through fake guest enquiries to deliver Remcos RAT through a malware loader named GuLoader. Pink, a New Com-Affiliated Actor - A new cybercrime brand called Pink (aka CL-CRI-1147), is leveraging vishing for initial access with the primary objective of data theft and extortion. It's assessed to be part of the broader Com ecosystem, embracing techniques similar to those of ShinyHunters and CL-CRI-1116 (Blackfile/Redact). The group's data leak site went live on May 31, 2026. "The threat actor leverages vishing for initial access, impersonating internal IT personnel to convince a user to input credentials into a phishing site, allowing the actor to gain access to the victim's account and MFA," Palo Alto Networks Unit 42 said. "After gaining access to the victim's account, the actor rapidly identifies and exfiltrates data from platforms like SharePoint and OneDrive, similar to other Com-affiliated groups." The threat actor has also been found to make use of compromised victim accounts to send their initial extortion email as well as internal Teams messages. According to Google, the activity maps to a threat group it calls UNC6671. 🔧 Cybersecurity Tools CAI → It is an open-source framework for building AI agents that help with cybersecurity work, from security testing and vulnerability discovery to defense automation. It supports 300+ AI models and includes built-in tools for tasks like reconnaissance, exploitation, privilege escalation, and security assessment. PMG → It is a free, open-source tool that blocks malicious open-source packages before they install. It sits in front of package managers like npm, pip, and Poetry, checks packages with SafeDep threat intelligence, and helps protect developers and AI coding agents from supply-chain attacks. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law. Conclusion That's the week. Nothing here is new. Same tricks. Same shortcuts. Same open inboxes. That's what makes it worse. Patch what matters first. Warn the people who click everything. Back up the important stuff. Then log off for a bit. It'll be messy again by next Monday.
thehackernews.comJun 8, 2026extracted
CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)
CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) A vulnerability (CVE-2026-28318) that can be exploited to crash SolarWinds Serv-U file transfer servers is being leveraged by attackers in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Friday. The agency has ordered US federal civilian agencies to address it by June 19, 2026, either by implementing a patch or implementing mitigations. About CVE-2026-28318 CVE-2026-28318 is an uncontrolled resource consumption vulnerability that can be triggered by remote, unauthenticated attackers. The flaw resides in how the Serv-U service handles HTTP POST requests that include the Content-Encoding: deflate header. By sending thusly crafted request, an attacker can force Serv-U to consume an excessive amount of resources, causing the service to crash and creating a denial-of-service condition. The vulnerability was disclosed by SolarWinds on June 3, after it released Serv-U 15.5.4 Hotfix 1, which fixes it. “Customers who downloaded and installed Serv-U 15.5.4 should also download and install Serv-U 15.5.4 Hotfix 1,” the company said. Alternatively, they can use their web application firewall to limit access to the server only to known addresses, and block POST requests containing “content-encoding’, “as this functionality is not required by the service.” Don’t dismiss this Serv-U DoS bug A remote code execution vulnerability (CVE-2021-35211) affecting SolarWinds Serv-U software has previously been exploited as a zero-day by suspected Chinese attackers for cyber espionage purposes, and later by the Cl0p ransomware outfit. In 2022, an input validation vulnerability (CVE-2021-35247) was targeted in Log4j-related attacks. Two years ago, the “trivially exploitable” CVE-2024-28995 was also leveraged by attackers. CISA hasn’t provided details about the in-the-wild exploitation of CVE-2026-28318, and there’s currently no indication of it being exploited by ransomware-wielding gangs. SolarWinds Serv-U is a self-hosted solution that allows organizations to securely transfer files over a network. It’s often used by organizations working in regulated industries and sectors, such as healthcare, finance, and government, where data sovereignty and audit trails are a requirement. While vulnerabilities that allow total compromise of Serv-U deployments are preferred by attackers, a DoS bug can be used to disrupt organizations’ operations or to distract enterprise defenders from other covert activity. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comJun 8, 2026extracted
SolarWinds Serv-U Vulnerability Exploited in the Wild
The US cybersecurity agency CISA on Friday warned of attacks targeting a SolarWinds Serv-U vulnerability that had been patched a couple of days earlier. Tracked as CVE-2026-28318 (CVSS score of 7.5), the bug is described as a denial-of-service (DoS) issue that can be exploited via specially crafted POST requests to crash the Serv-U service. Successful exploitation of the security defect does not require authentication, SolarWinds warned on Thursday. The flaw was addressed in Serv-U 15.5.4 Hotfix 1. SolarWinds encourages all customers to download and install the hotfix, including those who recently upgraded to Serv-U 15.5.4. According to SolarWinds, the hotfix prevents attackers from crashing the Serv-U service via requests containing the ‘Content-Encoding: deflate’ header and some data. Users of Serv-U versions 15.4.2, 15.5, and 15.5.1, which have reached End-of-Life (EoL), are advised to upgrade to a supported release as soon as possible. While SolarWinds’s advisory makes no mention of CVE-2026-28318 being exploited in the wild, CISA on Friday added the bug to its Known Exploited Vulnerabilities (KEV) catalog. It’s unclear who is behind the attacks and whether the vulnerability has been exploited as a zero-day. In line with Binding Operational Directive (BOD) 22-01’s requirements, CISA urged federal agencies to patch the CVE by June 19 to keep their networks protected against active threats. While BOD 22-01 only applies to federal agencies, all organizations are advised to apply SolarWinds’ hotfix as soon as possible. The company’s advisory contains detailed instructions on installing the hotfix and on removing it if necessary. Related: Chrome 149 Patches 429 Vulnerabilities Related: Mirasvit Vulnerability Exploited to Execute Code on Magento Servers Related: Gitea Vulnerability Exposed 30,000 Deployments to Attacks Related: Half of the 6 Million Internet-Facing FTP Servers Lack Encryption
securityweek.comJun 8, 2026extracted
CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-28318 (CVSS score: 7.5), is a denial-of-service (DoS) bug that causes the service to crash under certain conditions. CISA described it as an uncontrolled resource consumption vulnerability that results in a DoS condition. "SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate," SolarWinds said in an advisory released earlier this week. The issue has been addressed in SolarWinds Serv-U version 15.5.4 HF1. As mitigations, it's advised to limit access to known addresses and block any request containing "content-encoding" since the vulnerable service does not require this functionality. There are currently no details on how the vulnerability is being exploited in real-world attacks, or who is behind them. It's also unclear how many internet-exposed Serv-U instances are compromised, if any. CISA has ordered Federal Civilian Executive Branch (FCEB) agencies to address the flaw by June 19, 2026. In the past, multiple flaws in Serv-U have been exploited by bad actors, including those associated with the Cl0p ransomware gang.
thehackernews.comJun 6, 2026extracted
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned today that hackers are now actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers. Serv-U is the company's Windows and Linux file transfer software that offers Managed File Transfer (MFT) and FTP server capabilities, which allow users to securely exchange files via HTTP/HTTPS, FTP, FTPS, and SFTP. SolarWinds released Serv-U 15.5.4 Hotfix 1 on Thursday to patch this denial-of-service vulnerability (tracked as CVE-2026-28318) and said it stems from an uncontrolled resource consumption weakness. "SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate," the company said. Remote attackers can exploit the security flaw without privileges in low-complexity attacks that don't require user interaction. SolarWinds also advised admins who can't immediately deploy the patch to limit access to known addresses and to block any POST request containing "content-encoding," since the vulnerable Serv-U service does not require this functionality. The Internet intelligence platform Shodan currently tracks over 12,000 Serv-U servers exposed online, and Internet security watchdog Shadowserver just over 3,100, but there is no information on how many have already been patched. Days after SolarWinds addressed the vulnerability, CISA flagged it as exploited in the wild and added it to the Known Exploited Vulnerabilities Catalog, ordering all Federal Civilian Executive Branch agencies to patch their servers against ongoing attacks by June 19, as mandated by Binding Operational Directive (BOD) 22-01. While BOD 22-01 applies only to U.S. government agencies, the cybersecurity agency also urged all network defenders, including the private sector, to secure their networks against ongoing CVE-2026-28318 attacks as soon as possible. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," CISA warned. "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable." In recent years, multiple cybercrime and state-backed hacking groups have targeted vulnerabilities in Serv-U to steal sensitive corporate and customer data. For instance, the Clop ransomware gang exploited a Serv-U remote code execution vulnerability (CVE-2021-35211) to breach corporate networks in a 2021 campaign. DEV-0322 Chinese hackers also deployed CVE-2021-35211 exploits in zero-day attacks starting in July 2021. More recently, in June 2024, cybersecurity companies GreyNoise and Rapid7 tagged a Serv-U path-traversal vulnerability (CVE-2024-28995) as actively exploited. Over the past several years, CISA has tagged 11 vulnerabilities across various SolarWinds products as actively exploited in attacks, one of which has also been abused by ransomware gangs. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 5, 2026extracted
Le 4 dimensioni del rischio sistemico cyber nell’era dell’intelligenza artificiale
Man mano che l’intelligenza artificiale (IA) si integra sempre di più nelle infrastrutture digitali, sociali e istituzionali, il rischio sistemico cyber emerge come una delle sfide più critiche e sottovalutate. Ecco un modello per la comprensione e la gestione del rischio sistemico cyber nell’era dell’intelligenza artificiale, basato su insegnamenti tratti dalla regolamentazione finanziaria, dalla teoria dei sistemi complessi e dalla sicurezza informatica. L’obiettivo è fornire una solida base concettuale e uno strumento diagnostico operativo per la governance della cyber security in contesti complessi e interconnessi. Indice degli argomenti Il panorama delle minacce cibernetiche ha subito una trasformazione radicale negli ultimi anni. Se in passato la sicurezza informatica era tradizionalmente concepita come un problema tecnico circoscritto, come la vulnerabilità di un sistema, l’accesso non autorizzato a un database o l’interruzione di un servizio, la convergenza tra intelligenza artificiale, piattaforme digitali globali e infrastrutture critiche interconnesse ha creato le condizioni per un nuovo paradigma: il rischio sistemico cyber. Il concetto di rischio sistemico, elaborato originariamente nell’ambito della regolamentazione finanziaria dopo la crisi del 2008 (Schwarcz, 2008; Kaufman, 2003), descrive fenomeni in cui un guasto localizzato può propagarsi attraverso reti di interdipendenze (linkages) fino a destabilizzare l’intero sistema di riferimento (effetto domino e contagio). Applicato alla cyber sicurezza, questo concetto acquisisce una dimensione nuova e, per molti versi, più insidiosa: a differenza delle crisi finanziarie, un attacco informatico può verificarsi in pochi secondi, colpire simultaneamente migliaia di nodi interconnessi e, se potenziato da sistemi di IA, adattarsi dinamicamente alle contromisure difensive. Ecco la risposta a tre domande: In cosa si differenzia il rischio sistemico cyber dal rischio cyber “ordinario”? In che modo l’intelligenza artificiale amplifica o trasforma i meccanismi di propagazione del rischio sistemico cyber? In che modo gli attuali strumenti normativi europei (AI Act, DSA, NIS2, DORA) si rapportano a questa sfida e quali riforme sono necessarie? Il concetto di rischio sistemico ha trovato la sua attuale formalizzazione nell’ambito della regolamentazione bancaria e finanziaria. Il Rapporto Lamfalussy del 1990 ha stabilito i primi standard per la riduzione del rischio sistemico nei sistemi interbancari internazionali. La crisi finanziaria del 2008, originata dal fallimento della banca d’investimenti Lehman Brothers, ha poi trasformato questo concetto da strumento accademico a priorità assoluta per la regolamentazione. Il Regolamento UE n. 1092/2010 ha istituito l’European Systemic Risk Board (ESRB), che definisce il rischio sistemico all’articolo 2, lettera c), come “un rischio di perturbazione del sistema finanziario con il potenziale di avere gravi conseguenze negative per il mercato interno e l’economia reale”. Questa definizione introduce due dimensioni fondamentali, applicabili anche al dominio cyber: la dimensione collettiva (destabilizzazione del sistema o instabilità sistemica) e la dimensione individuale (danno grave ai soggetti che operano nel sistema). In un rapporto del 2020, l’ESRB ha evidenziato come gli incidenti cibernetici possano propagarsi attraverso sistemi interconnessi, creando effetti di contagio analoghi a quelli delle crisi finanziarie. A differenza dei rischi finanziari tradizionali, tuttavia, le minacce cibernetiche presentano caratteristiche distintive che le rendono, in un certo senso, ancora più problematiche dal punto di vista sistemico. Il Digital Operational Resilience Act (DORA), entrato in vigore nel gennaio 2023, rappresenta il primo tentativo sistematico di applicare la logica macroprudenziale al rischio sistemico cyber nel settore finanziario. DORA riconosce esplicitamente che questo rischio sistemico ha spesso origine dalla concentrazione su fornitori di servizi ICT terzi, in particolare i provider cloud, configurando così una vulnerabilità strutturale tipicamente esogena. il rischio sistemico cyber Si definisce il rischio sistemico cyber come la probabilità che un evento cyber scateni una serie di guasti successivi attraverso sistemi interconnessi, con effetti collettivi che superano la somma dei danni individuali e che hanno il potenziale di destabilizzare infrastrutture critiche IT/OT, mercati o istituzioni fondamentali per il funzionamento della società. Caratteristiche del rischio sistemico cyber: Interdipendenza: l’elevata interconnessione delle infrastrutture digitali amplifica l’impatto di attacchi anche limitati, estendendo i danni oltre il target primario. Single Point of Failure: la concentrazione di servizi (es. cloud provider) crea dei nodi critici la cui compromissione può bloccare interi settori. Effetto domino (contagio): un incidente in un’azienda può infettare fornitori, partner e clienti, propagandosi attraverso la catena di approvvigionamento. Ampiezza del danno: i danni collettivi superano la somma dei danni individuali, provocando perdite di reputazione, di fiducia e operative su vasta scala. A partire dall’analisi comparata di oltre venti definizioni di rischio sistemico (Hacker, Kasirzadeh & Edwards, 2025; Renn et al., 2022; Helbing, 2013), identifichiamo quattro dimensioni fondamentali applicabili specificamente al dominio cyber. Tabella: Dimensioni del rischio sistemico cyber. L’integrazione dell’intelligenza artificiale nei sistemi cyber non solo introduce nuovi vettori di attacco, ma trasforma strutturalmente i meccanismi di propagazione del rischio sistemico. Possiamo identificare quattro livelli distinti: Livello 1: Single-model systemic risks Livello 2: Multi-model systemic risks Livello 3: Model-platform integration risks Livello 4: Model-institution integration risks Un singolo modello di IA ampiamente adottato può rappresentare un punto critico di fallimento sistemico. Quando un Large Language Model (LLM) o un sistema di IA per il rilevamento delle intrusioni viene implementato su milioni di dispositivi, una vulnerabilità nel modello, come l’iniezione di prompt, un attacco avversario o una backdoor inserita durante la fase di addestramento (data poisoning), può essere sfruttata simultaneamente su scala globale. L’omogeneità tecnologica, che rappresenta un vantaggio in termini di manutenibilità e standardizzazione, in questo caso diventa un fattore di rischio sistemico, sostituendo la diversità difensiva con una superficie di attacco uniforme. I sistemi complessi che orchestrano più modelli di IA in pipeline automatizzate, sempre più diffusi nelle infrastrutture di sicurezza, possono causare guasti correlati e sincronizzati. Quando un modello “A” che rileva le anomalie di rete è alimentato dall’output di un modello “B” che classifica il traffico, un attacco che compromette B invalida silenziosamente i giudizi di A. I framework multi-agente, come LangChain o AutoGPT applicati alla cyber security, introducono delle dipendenze a grafo che le metodologie di analisi del rischio tradizionali, basate su architetture a catena lineare, non sono progettate per rilevare. L’integrazione di modelli IA in piattaforme digitali su larga scala genera loop di feedback rischiosi. Un sistema di moderazione dei contenuti basato sull’intelligenza artificiale può essere manipolato in modo da amplificare sistematicamente la disinformazione sulle minacce informatiche, come la diffusione di false notizie su vulnerabilità inesistenti che causano una “patch storm”. Inoltre, i suoi output possono essere reinseriti come dati di addestramento in modelli successivi, fenomeno noto come “collasso del modello” e documentato da Shumailov et al. (2024). Il livello più grave si manifesta quando i sistemi IA sono incorporati in istituzioni di governance critiche, come i sistemi giudiziari, le forze dell’ordine, le infrastrutture finanziarie e le catene di comando militari. Un attacco a un sistema IA integrato in un’infrastruttura di questo tipo non mette a repentaglio solo l’operatività tecnica del sistema, ma anche la legittimità e l’integrità delle decisioni istituzionali che ne derivano. Questo è lo scenario più difficile da risolvere, perché le conseguenze si stratificano nel tessuto normativo e sociale. Comprendere i meccanismi attraverso cui un incidente cyber localizzato si trasforma in una crisi sistemica è fondamentale per progettare architetture di sicurezza resilienti. 6 vettori principali di propagazione Distinguiamo sei vettori principali di propagazione: tramite software della supply chain; mediante dipendenze di fiducia (Trust Chain); via protocolli condivisi; attraverso concentrazione cloud; tramite modelli IA condivisi; mediante lock-in. Propagazione tramite software della supply chain Come dimostrato dall’attacco a SolarWinds del 2020, la compromissione di un fornitore di software affidabile può inserire delle backdoor in migliaia di organizzazioni che si fidano ciecamente degli aggiornamenti firmati digitalmente. L’intelligenza artificiale (IA) accelera questo vettore, consentendo l’analisi automatizzata di milioni di righe di codice per individuare i punti di inserimento ottimali per il malware. Propagazione tramite dipendenze di fiducia (Trust Chain) I protocolli di autenticazione federata, i certificati digitali e i sistemi PKI creano catene di fiducia la cui compromissione di un singolo nodo radice può invalidare istantaneamente l’intera infrastruttura su cui si basano. Propagazione tramite protocolli condivisi Le vulnerabilità presenti in protocolli ampiamente adottati (BGP, DNS, TLS) costituiscono una superficie di attacco trasversale a diversi settori e organizzazioni. Un attacco BGP hijacking può reindirizzare silenziosamente il traffico Internet a livello globale prima che i meccanismi di rilevamento si attivino. La propagazione tramite concentrazione cloud La migrazione delle infrastrutture critiche verso un numero limitato di provider hyperscale (AWS, Azure, GCP) crea dei Single Point of Failure dal punto di vista geopolitico. Propagazione tramite modelli IA condivisi La convergenza su un numero limitato di modelli LLM di base per le applicazioni di sicurezza (intelligence sulle minacce, automazione SOC e scansione delle vulnerabilità) crea una dipendenza comune la cui compromissione avrebbe conseguenze a catena sull’intero ecosistema della cyber sicurezza. Propagazione tramite lock-in La circostanza per cui un’azienda o un intero settore è così dipendente da un fornitore o da un Paese rischia di diventare una minaccia (o una trappola) per la stabilità o l’indipendenza operativa L’intelligenza artificiale agisce da amplificatore del rischio sistemico cyber attraverso tre meccanismi distinti e interconnessi: automazione e scala degli attacchi; evasione adattiva; ingegneria sociale potenziata. I sistemi di IA consentono di condurre attacchi su larga scala e a una velocità impensabile in precedenza. Un agente IA può condurre attacchi di credential stuffing su milioni di account in modo simultaneo, generare campagne di phishing altamente personalizzate basate sull’analisi dei profili social delle vittime e individuare e sfruttare automaticamente vulnerabilità in sistemi precedentemente ritenuti sicuri. Questa automazione abbassa drasticamente la soglia di accesso alle capacità offensive sofisticate, ampliando il numero di potenziali attori della minaccia e aumentando la frequenza degli incidenti potenzialmente rilevanti dal punto di vista sistemico. I modelli generativi avversari (GAN) e le tecniche di apprendimento per rinforzo (reinforcement learning) consentono di sviluppare malware in grado di modificare dinamicamente la propria firma per eludere i sistemi di rilevamento basati su firme. Più in generale, gli attacchi avversari ovvero perturbazioni minime e impercettibili agli input dei sistemi di IA, possono causare classificazioni errate critiche nei sistemi di rilevamento delle intrusioni (IDS), nei sistemi di autenticazione biometrica o nei sistemi di analisi del malware. La difficoltà di rilevare questi attacchi li rende particolarmente pericolosi in contesti ad alta criticità. I Large Language Model riducono drasticamente il costo della creazione di contenuti ingannevoli di alta qualità. È possibile produrre audio e video deepfake credibili in tempo reale per simulare CEO o altre figure autorevoli durante attacchi BEC (Business Email Compromise) evoluti. Questa capacità trasforma i vettori di attacco, che in precedenza erano limitati dall’investimento in competenze umane, in vettori automatizzabili e scalabili, con implicazioni dirette sul rischio sistemico: la fiducia nelle comunicazioni digitali, bene infrastrutturale fondamentale per il funzionamento dell’economia digitale, viene erosa a livello strutturale. La Direttiva NIS2 (UE 2022/2555) rappresenta un’evoluzione significativa del quadro normativo europeo in materia di sicurezza delle reti e dei sistemi informativi. A differenza della versione precedente, la NIS2 estende esplicitamente il proprio ambito di applicazione a nuovi settori critici quali l’energia, i trasporti, la sanità, le infrastrutture digitali, le amministrazioni pubbliche e lo spazio. Introduce obblighi sostanziali in materia di gestione del rischio, notifica degli incidenti e sicurezza della catena di approvvigionamento. Dal punto di vista del rischio sistemico cyber, la direttiva NIS2 rappresenta un progresso significativo nell’affrontare la concentrazione sui fornitori critici e le dipendenze della catena di approvvigionamento ICT. L’articolo 21 impone ai soggetti essenziali e importanti di adottare misure tecniche, operative e organizzative proporzionate per la gestione dei rischi per la sicurezza dei sistemi, prestando particolare attenzione alla sicurezza della catena di approvvigionamento. Tuttavia NIS2 mantiene un approccio prevalentemente settoriale che non riesce a cogliere appieno i rischi sistemici, derivanti dall’interazione tra l’intelligenza artificiale e le infrastrutture critiche. Il Cyber Resilience Act (CRA – Regolamento UE 2024/2847), entrato in vigore il 10 dicembre 2024, rappresenta la risposta normativa dell’Unione Europea per mitigare il rischio sistemico derivante dalle vulnerabilità dei prodotti digitali connessi (sia hardware che software). L’obiettivo principale è innalzare il livello di sicurezza informatica di base per ridurre l’impatto di attacchi che potrebbero paralizzare le infrastrutture critiche, le imprese e i servizi essenziali nell’UE. Il CRA contribuisce a ridurre il rischio sistemico attraverso le seguenti azioni: La marcatura CE: i prodotti digitali dovranno soddisfare requisiti di sicurezza obbligatori per poter accedere al mercato UE e garantire un “livello minimo” di protezione. La normativa classifica i prodotti in classi di criticità (Classe I e Classe II, nonché prodotti critici) per poter applicare valutazioni di conformità proporzionali al rischio. I produttori devono gestire le vulnerabilità e segnalare gli incidenti gravi all’ENISA per poter accelerare la risposta alle minacce. Il Digital Operational Resilience Act (DORA) è il primo strumento normativo europeo che traduce in modo organico il pensiero macroprudenziale nella gestione del rischio sistemico cyber. DORA si applica a un’ampia gamma di enti finanziari: banche, assicurazioni, mercati e gestori di fondi, nonché ai loro fornitori di servizi ICT critici, inclusi i provider di cloud computing. I pillar di DORA per la gestione del rischio sistemico cyber: Gestione del rischio ICT: framework obbligatorio con identificazione, classificazione e documentazione degli asset ICT critici. Gestione degli incidenti: notifica alle autorità competenti entro 4 ore per gli incidenti gravi e entro 72 ore per una descrizione preliminare. Test di resilienza operativa: TLPT (Threat-Led Penetration Testing) obbligatorio per le entità significative. Rischio ICT di terze parti: registri contrattuali, diritti di audit, strategie di exit. Condivisione delle informazioni: possibilità di partecipare a meccanismi di condivisione su cyber minacce. L’articolo 34, paragrafo 1, del DSA impone alle Very Large Online Platforms (VLOP) e alle Very Large Online Search Engines (VLOSE) – con una soglia di 45 milioni di utenti attivi mensili nell’UE – di identificare, analizzare e mitigare i rischi sistemici derivanti dalla progettazione o dal funzionamento dei loro servizi. La tassonomia del DSA individua quattro categorie di rischio sistemico: diffusione di contenuti illegali; effetti negativi sui diritti fondamentali; effetti sul discorso civico e sui processi elettorali; effetti sulla salute pubblica, sui minori e sul benessere. Nel contesto cyber, il DSA si concentra soprattutto sui rischi sistemici legati alla diffusione di disinformazione su vulnerabilità e minacce, alla manipolazione delle informazioni durante gli incidenti cyber critici e all’amplificazione delle campagne di ingegneria sociale su larga scala. Il DSA non menziona esplicitamente la cybersicurezza come categoria autonoma di rischio sistemico, ma le sue previsioni si applicano indirettamente quando le vulnerabilità delle piattaforme o gli attacchi informatici generano violazioni dei diritti fondamentali o mettono a repentaglio la sicurezza pubblica. L’AI Act (Regolamento UE 2024/1689) definisce il rischio sistemico all’articolo 3, paragrafo 65, come un “rischio specifico delle capacità ad alto impatto dei modelli General Purpose AI (GPAI) che ha un impatto significativo sul mercato dell’Unione a causa della sua portata o a causa di effetti negativi effettivi o ragionevolmente prevedibili sulla salute pubblica, sulla sicurezza, sulla sicurezza pubblica, sui diritti fondamentali o sulla società nel suo insieme e che può propagarsi su larga scala lungo la catena del valore”. Il Code of Pratice per l’Intelligenza Artificiale (luglio 2025) classifica le capacità di cyberoffensiva come una delle quattro categorie di rischio sistemico specificate nell’Appendice 1.4, insieme ai rischi CBRN (Chimico, Biologico, Radiologico, Nucleare), alla perdita di controllo e alla manipolazione dannosa. Questo riconoscimento esplicito è significativo, ma l’approccio dell’AI Act al rischio sistemico cyber presenta alcune limitazioni strutturali rilevanti per gli esperti di sicurezza che è necessario colmare. L’attacco SolarWinds del 2020, attribuito al gruppo APT29 russo, ha chiaramente dimostrato il meccanismo del rischio sistemico cyber tramite la supply chain. La compromissione del ciclo di build della piattaforma Orion di SolarWinds ha inserito una backdoor (SunBurst) in aggiornamenti firmati digitalmente e distribuiti a oltre 18.000 organizzazioni, tra cui agenzie governative statunitensi, aziende private e infrastrutture critiche. Dal punto di vista delle categorie citate in questo articolo, SolarWinds rappresenta un rischio di livello 1 (modello di distribuzione software ampiamente adottato) che si trasforma in un rischio di livello 4 (compromissione delle istituzioni di governance). Le quattro dimensioni del rischio sistemico sono tutte soddisfatte: scala globale (18.000 organizzazioni), natura collettiva (compromissione dell’intera catena di fiducia degli aggiornamenti software), irreversibilità (presenza di backdoor latenti per mesi prima della loro rilevazione) e complessità (propagazione attraverso meccanismi di fiducia impliciti e difficili da sostituire). L’intelligenza artificiale (IA) trasformerebbe questo scenario in modo qualitativo: i sistemi di IA per l’analisi automatizzata dei codebase potrebbero individuare i punti di inserimento ottimali per il malware in tempi drasticamente ridotti. Gli agenti IA potrebbero inoltre personalizzare dinamicamente il comportamento della backdoor in base al profilo dell’organizzazione target. Le tecniche di apprendimento automatico avversario (adversarial machine learning) potrebbero infine rendere il malware invisibile ai sistemi di rilevamento basati su IA. WannaCry (2017) e NotPetya (2017) hanno segnato la transizione del ransomware da strumento criminale opportunistico a vettore di rischio sistemico. WannaCry, sfruttando l’exploit EternalBlue sviluppato dalla NSA e poi t rafugato dal gruppo Shadow Brokers, ha colpito oltre 200.000 sistemi in 150 Paesi in sole 24 ore, paralizzando il Servizio Sanitario Nazionale britannico e causando danni stimati tra i 4 e gli 8 miliardi di dollari. NotPetya, mascherato da ransomware ma in realtà è un wiper, ha causato danni per oltre 10 miliardi di dollari: Maersk ha perso il controllo dell’intera infrastruttura IT globale e A.P. Moller ha dovuto reinstallare 45.000 PC e 4.000 server. Lo schema Ransomware-as-a-Service (RaaS) rappresenta il Livello 2: si tratta di ecosistemi multi-attore in cui sviluppatori di exploit, operatori di piattaforme RaaS, affiliati e riciclatori di denaro interagiscono come un sistema organizzato. L’intelligenza artificiale sta accelerando questo modello. Gli strumenti automatizzati per l’identificazione delle vulnerabilità abbassano la soglia d’ingresso per i nuovi affiliati. I modelli linguistici migliorano la qualità delle comunicazioni di riscatto e delle tattiche di negoziazione. Invece i sistemi di IA per l’analisi delle reti aziendali ottimizzano la scelta degli obiettivi con il massimo impatto. Il caso dell’attacco al sistema idrico di Oldsmar, in Florida (2021), in cui un attaccante ha cercato di aumentare la concentrazione di idrossido di sodio nell’acqua potabile a livelli letali, mostra la convergenza tra il rischio cyber e il rischio fisico per le infrastrutture critiche. Sebbene in questo caso l’attacco sia stato rilevato grazie all’attenzione di un operatore umano, l’integrazione dell’intelligenza artificiale (IA) nei sistemi SCADA/ICS potrebbe mascherare le modifiche malevole ai set-point di controllo, attribuendole a un comportamento normale del sistema o a variazioni naturali dei parametri. Questo scenario corrisponde alLivello 4: l’integrazione dell’IA nei sistemi di controllo industriale per le infrastrutture critiche (energia, acqua, trasporti e sanità) crea vulnerabilità strutturali la cui materializzazione potrebbe avere conseguenze potenzialmente irreversibili sulla sicurezza pubblica. Il problema fondamentale è che i sistemi OT/ICS tradizionali non sono stati progettati con la sicurezza informatica come requisito primario. Inoltre, la loro integrazione con i sistemi IA, senza un’adeguata segregazione, introduce una complessità che aumenta le superfici di attacco. Ma senza un corrispondente aumento delle capacità difensive. Un vettore spesso sottovalutato del rischio sistemico cyber è la manipolazione delle informazioni relative alle minacce e vulnerabilità. Le campagne di disinformazione che amplificano artificialmente la percezione della gravità di una vulnerabilità possono causare il cosiddetto “patch panic“, saturando le capacità operative dei SOC. Le campagne che minimizzano le vulnerabilità reali ritardano l’applicazione delle patch critiche, mentre le false attribuzioni degli incidenti informatici possono provocare crisi diplomatiche o militari. I LLM rendono queste campagne altamente scalabili e personalizzabili. Un attore ostile può generare automaticamente centinaia di varianti di un articolo tecnico plausibile su una vulnerabilità fittizia, distribuirle sui canali social e sui forum tecnici e creare così una percezione artificiale di consenso all’interno della comunità della sicurezza. Questo vettore opera tra il Livello 3 (integrazione modello-piattaforma) e il Livello 4 (impatto istituzionale) e il suo trattamento nel DSA e nell’AI Act è frammentato e inadeguato. La principale modifica necessaria è la separazione concettuale tra la definizione di rischio sistemico e i criteri per l’individuazione dei modelli soggetti agli obblighi dell’articolo 55. Il rischio sistemico cyber dovrebbe essere definito in termini di impatto collettivo e propagazione a cascata, a prescindere dal livello di avanzamento del modello che lo genera. I criteri di soglia (compute, benchmark, parametri) dovrebbero determinare solo quali modelli sono soggetti agli obblighi regolatori più stringenti e non se il rischio esiste. La gestione del rischio sistemico cyber nell’era dell’intelligenza artificiale richiede un coordinamento sistematico tra l’AI Office, i Digital Services Coordinators, l’ENISA, le varie Autorità o Agenzia nazionali. In particolare: Istituzione di un Joint Systemic Cyber Risk Board a livello UE, con rappresentanza dell’AI Office, dell’ESRB, dell’ENISA e delle autorità nazionali NIS2, con il compito di produrre valutazioni annuali del rischio sistemico cyber amplificato dall’IA. Sviluppo di protocolli di “Reciprocal Risk Analysis” per sistemi ibridi AI-piattaforma, che valutino congiuntamente il rischio sistemico cyber sotto il DSA e l’AI Act. Obbligo di condivisione tempestiva delle informazioni sugli incidenti informatici con rilevanza sistemica tra le autorità competenti per NIS2, DORA, AI Act e DSA, con un formato standardizzato basato sul modello STIX/TAXII. Al di là delle modifiche normative, chi si occupa di cybersicurezza deve adattare le proprie metodologie di valutazione del rischio per incorporare la dimensione sistemica amplificata dall’IA. Adottare metodologie di Threat Modeling estese alla dimensione sistemica: il tradizionale framework STRIDE deve essere integrato con un’analisi delle dipendenze sistemiche che includa la mappatura delle catene di fiducia, delle dipendenze dai modelli IA condivisi e dei vettori di propagazione cross-organizzazione. È necessario implementare esercizi di red teaming per i livelli 2 e 3: le tradizionali simulazioni che testano la resilienza di singoli sistemi o organizzazioni non sono più sufficienti. È necessario condurre esercizi che simulino la compromissione di modelli di IA condivisi o di piattaforme ad alta diffusione e che valutino la propagazione degli effetti a cascata. Sviluppare indicatori di rischio sistemico cyber (SRCI): analogamente agli indicatori macroprudenziali finanziari, è necessario sviluppare metriche quantitative per misurare la concentrazione su modelli IA condivisi, il grado di interconnessione tra i sistemi critici mediata da componenti IA e la velocità di potenziale propagazione degli incidenti. Integrare la gestione del rischio IA nelle politiche di sicurezza: i Chief Information Security Officer (CISO) devono sviluppare politiche specifiche per la gestione del rischio sistemico introdotto dall’adozione di modelli IA di terze parti e includere clausole contrattuali che garantiscano la trasparenza riguardo agli aggiornamenti di sicurezza, ai bug bounty e alla gestione degli incidenti. La misura più urgente per ridurre il rischio sistemico cyber nell’era dell’intelligenza artificiale (IA) è l’istituzione di meccanismi che consentano la condivisione rapida delle informazioni su incidenti che coinvolgono modelli di IA tra organizzazioni e settori diversi. Ovvero un “ISAC per l’IA“, che permetta alla comunità della sicurezza di rispondere collettivamente a vettori di attacco emergenti prima che si propaghino a livello sistemico. Il rischio sistemico cyber nell’era dell’intelligenza artificiale rappresenta una delle sfide più complesse e sottovalutate della governance cyber. Per comprendere e gestire adeguatamente questo rischio, sono necessari tre cambiamenti di paradigma fondamentali. Il primo cambiamento riguarda l’unità di analisi: non il singolo sistema o la singola organizzazione, ma le reti di interdipendenze attraverso cui i guasti si propagano. Il secondo cambiamento riguarda invece il rapporto tra IA e rischio cibernetico: l’IA non è solo un nuovo vettore di attacco. Ma è un amplificatore strutturale del rischio sistemico che trasforma la natura delle minacce, sia in termini quantitativi che qualitativi. Il terzo cambiamento riguarda infine la governance: il rischio sistemico cibernetico non può essere gestito con approcci settoriali frammentati. Ma richiede framework integrati che coordinino le molteplici dimensioni normative (AI Act, DSA, NIS2, DORA) attorno a una comprensione condivisa del rischio sistemico. Il modello citato, con le sue quattro dimensioni (scala, natura collettiva, irreversibilità e complessità) e i quattro livelli di rischio (single-model, multi-model, model-platform e model-institution), fornisce agli analisti della sicurezza, ai regolatori e ai responsabili delle decisioni uno strumento operativo per affrontare questa complessità con strumenti analitici adeguati. La profonda digitalizzazione delle infrastrutture critiche, la crescente integrazione di sistemi di IA in funzioni istituzionali fondamentali e la concentrazione dell’ecosistema tecnologico su un numero limitato di modelli e fornitori creano le condizioni per incidenti informatici di portata sistemica senza precedenti. Dotarsi di framework concettuali rigorosi, strumenti normativi adeguati e capacità operative all’altezza della sfida, dunque, non è un’opzione. Ma rappresenta una necessità per garantire la continuità del funzionamento delle nostre società digitali. Achuthan, K., Ramanathan, S., Srinivas, S., & Raman, R. (2024). Advancing cybersecurity and privacy with artificial intelligence: current trends and future research directions. Frontiers in Big Data, 7, 1497535. Bengio, Y. et al. (2025). International AI Safety Report. arXiv preprint arXiv:2501.17805. European Systemic Risk Board. (2020). Systemic cyber risk. ESRB Report. Frankfurt: ESRB. European Systemic Risk Board. (2024). Advancing macroprudential tools for cyber resilience — Operational policy tools. ESRB. Galaz, V., Centeno, M. A., Callahan, P. W., et al. (2021). Artificial intelligence, systemic risks, and sustainability. Technology in Society, 67, 101741. Gutiérrez de Rozas, L. (2022). The first ten years of the European Systemic Risk Board (2011–2021). Financial Stability Review, (42), 121–152. Hacker P. (2024). Sustainable AI Regulation. Common Market Law Review, 61, 345–386. Hacker P., & Holweg, M. (2025). The Regulation of Fine-Tuning: Federated Compliance for Modified General-Purpose AI Models. SSRN Working Paper. Hacker, P., Kasirzadeh, A., & Edwards, L. (2025). AI, Digital Platforms, and the New Systemic Risk. Working Paper, September 2025. Helbing, D. (2013). Globally networked risks and how to respond. Nature, 497, 51–59. Jin, S., Bei, Z., Chen, B., & Xia, Y. (2024). Breaking the Cycle of Recurring Failures: Applying Generative AI to Root Cause Analysis in Legacy Banking Systems. arXiv preprint arXiv:2411.13017. Kasirzadeh, A. (2025). Two types of AI existential risk: decisive and accumulative. Philosophical Studies, 182, 1975–2003. Kaufman, G. G. (2003). Too big to fail in banking: What does it mean? Journal of Financial Stability, 1(1), 4–29. Micova, S. B., & Calef, A. (2023). Elements for Effective Systemic Risk Assessment under the DSA. Interoperability of Law. Renn, O., et al. (2022). The role of risk perception for risk governance. In O. Renn (Ed.), Risk governance. London: Routledge. Roshanaei, M., Khan, M. R., & Sylvester, N. N. (2024). Enhancing cybersecurity through AI and ML: Strategies, challenges, and future directions. Journal of Information Security, 15(3), 320–339. Schwarcz, S. L. (2008). Systemic risk. Georgetown Law Journal, 97(1), 193–249. Shumailov, I., Shumaylov, Z., Zhao, Y., et al. (2024). AI models collapse when trained on recursively generated data. Nature, 631, 755–759. Uuk, R., Gutierrez, C.I., Guppy, D., et al. (2024). A Taxonomy of Systemic Risks from General- Purpose AI. arXiv preprint arXiv:2412.07780. Wachter, S., Mittelstadt, B., & Russell, C. (2024). Do large language models have a legal duty to tell the truth? Royal Society Open Science, 11(8), 240197.
cybersecurity360.itJun 4, 2026extracted
In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: Trump Mobile data breach Phone provider Trump Mobile has confirmed that customers’ names, addresses, email addresses, phone numbers, and other data was exposed to the internet. The company reportedly said a third-party platform provider was responsible for the exposure. Russian hackers’ deep reach in Treasury emails Documents presented in a Freedom of Information Act lawsuit filed by Bloomberg News against the US government show that the Russian state-sponsored APT responsible for the 2019-2020 SolarWinds supply chain attack had deep access to Treasury emails. The hackers reportedly focused on only eight email accounts linked to 300 other email addresses. The Treasury had roughly 94,000 people at the time. VS Code Remote SSH extension vulnerability A remote code execution (RCE) vulnerability in the Visual Studio Code (VS Code) Remote‑SSH extension could allow attackers to pivot to remote systems, security researcher Suman Kumar Chakraborty warns. The issue exists because, upon initiating a Remote SSH connection, the extension writes a bootstrap shell script to the Temp directory. An attacker with access to the system can modify the script before it is transmitted and executed on the remote server, to deploy a reverse shell. UK Visa Portal exposes over 100,000 documents Immigration portal UK Visa Portal publicly exposed over 100,000 documents of people who applied for a UK visa, TechCrunch reports. Not affiliated with the UK government, the website requires applicants to upload selfies and passports, and to pay a fee for obtaining visas. The exposed files were stored in an AWS S3 bucket and were secured earlier this week. LinkedIn phishing campaign abuses Adobe Target Phishers are posing as LinkedIn in a new phishing campaign posing as a business inquiry. The emails contain fake contract attachments masquerading as PDFs. In fact, they are HTML files directing victims to the Adobe Target A/B testing platform. The attackers are abusing Adobe Target to track users and serve them fake login pages to steal their credentials before redirecting them to LinkedIn. 2026 FIFA World Cup in attackers’ crosshairs Just as the 2026 FIFA World Cup is about to kick off, Group-IB has discovered over 4,300 fraudulent domains impersonating FIFA, including a sophisticated phishing campaign run by Chinses-speaking hacking group Ghost Stadium. The threat actor has set up over 300 domains, including a pixel-perfect clone of the legitimate FIFA site. The phishers could cause hundreds of millions of dollars in losses. Veeam, Notepad++, Roundcube patches Veeam this week resolved two high-severity vulnerabilities in its Backup & Replication product, warning they could lead to privilege escalation and arbitrary file writes. Notepad++ patched three security issues, including two leading to arbitrary code execution. The latest Roudcube security updates fix eight flaws, including unauthenticated SQL injection and arbitrary file delete bugs. CISA responds to recent supply chain attacks The US cybersecurity agency CISA has expanded its KEV catalog with three vulnerabilities describing recent software supply chain attacks. These include Daemon Tools Lite, TanStack, and Nx Console (which led to the 3.800 internal GitHub repositories hack). CISA also issued an alert on the Megalodon and Nx Console attacks, urging organizations to hunt for and remediate potential compromises. NPM invalidated granular access tokens in response to these attacks. Supply chain attack hits 176 NPM packages Sonatype warns of a supply chain attack involving 176 malicious NPM packages containing postinstall scripts designed to install information-stealing malware on the victims’ computers. The malware harvests and exfiltrates credentials, system and directory information, environment variables, CI/CD secrets, and other tokens and sensitive information. All malicious packages have the version number 99.99.99. Contractor jailed for hacking former employer Maxwell Schultz, 36, of Columbus, Ohio, was sentenced to 24 months in federal prison for hacking into his employer’s network after his contract was terminated in May 2021. Impersonating another contractor, he obtained login credentials, accessed the former employer’s systems, and executed a script that reset roughly 2,500 passwords, locking out employees and contractors and causing more than $862,000 in losses. Schultz pleaded guilty in November 2025.
securityweek.comMay 29, 2026extracted
Build Application Firewalls Aim to Stop the Next Supply Chain Attack
Many of the most serious supply chain issues are caused by flaws built into applications during the CI/CD build process. A build application firewall may be the solution. The SolarWinds supply chain attack of 2020, resulting in around 18,000 affected organizations, should have been a learning point. It demonstrated a key style of supply chain attack – but we didn’t learn how to prevent them. The same approach of compromising the development cycle of a widely used tool has been successfully repeated many times since then. In March 2026, North Korean actors hijacked an Axios npm library maintainer’s account and published two malicious versions. Axios is widely trusted and usage is usually automated. During the brief period before the malicious versions were removed, it is believed they were downloaded by around 3% of the Axios userbase. The endgame was a remote access trojan, ultimately delivered via CI/CD. Separately, but also in February/March 2026, TeamPCP compromised Aqua’s Trivy vulnerability scanner, BerriAI’s LiteLLM, and Checkmarx/kics. The successful purpose was to get into the CI/CD of widely used tools. On March 31, Mercor announced itself to be ‘one of thousands of companies impacted by a supply chain attack involving LiteLLM’. In early April, the European Commission lost 300Gb of data to hackers using an API key compromised in the Trivy supply chain attack. The problem is bad code being introduced into the CI/CD application build process. This could be invisible to the developer. Most build systems pull in npm or PyPI automatically from the repository. But a compromised package, a typo squatted dependency, or a malicious version will still get included in the build. Scanners are designed to check what goes into CI/CD, and again at the end of the build. They can often detect problematic code, but sometimes they cannot. There are two primary reasons: the bad intent may not appear to be bad (for example, a post to GitHub when GitHub is not considered a dangerous destination since it is the source of many npm packages), and the presence of an unknown zero day that simply isn’t detected. The latter could be called the ‘Mythos effect’. The power of contemporary AI frontier models is likely to unearth a multitude of vulnerabilities that can be inserted into the build, and then help bad actors generate stealthy exploits to use against the built application. Standard CI/CD scanners are unlikely to find these, nor highlight the unrequired distribution of secrets to a usually acceptable IP address. This type of supply chain attack will only increase. “If we don’t know there’s a vulnerability, we just let the package in,” comments David Pulaski, co-founder at InvisiRisk. “The scanner is like a doorman letting someone in because their invitation looks good. But once inside, that vulnerability does something malicious – like post a secret to a bad location or post a secret it shouldn’t post to a good location. Once the vulnerability gets inside, it goes to work fulfilling its malicious purpose.” Pulaski’s solution is not to scan but to inspect each and every package that enters the build process. InvisiRisk has developed a firewall for the CI/CD process: a BAF or build application firewall. “The guest the doorman lets in might walk out with our jewels. But we’re watching inside the build, and we can see what is happening.” Hardened runners are commonly used to prevent bad stuff getting into the build and secrets being sent to malicious destinations, but they can only see DNS. “They don’t do deep packet inspection like a real firewall,” says Pulaski. “So, if you’re stealing jewelry and you’re taking it right back to GitHub, it’ll say, yeah, go ahead and take it.” The firewall’s deep packet inspection, however, will see the jewels being stolen, and will understand exactly where they are being sent. Similarly, it doesn’t need to know a vulnerability to detect its presence – it will detect any activity that is not precisely what is expected. InvisiRisk’s BAF is designed to enforce policy during the build rather than just scan the content or finished build. That policy can be defined by the user with the help of a wizard, or it can be developed over time by using the firewall. It will make suggestions on what it considers to be risky actions. The firewall’s own AI will explain in detail why it considers an action worrisome, and the potential risk from it. An added bonus from this BAF will help the entire software ecosphere. SBOMs are mandatory for successful software sales. The requirement has long been apparent, but Biden’s EO 14028 formalized it as necessary for all software sold into the federal government. A major purpose of this has always been to reduce supply chain issues by understanding exactly what is included in a software application. The formal SBOM idea spread globally and is now supported by several regulations. But the quality of SBOMs can leave much to be desired. “We believe our SBOM tool is the finest SBOM tool there is,” claims Pulaski. “We watch the software being built. We’re not looking at lists and manifests and other documents to see what’s in the software, we see and check everything ourselves. So, if there is an open source library in your code, we know exactly what it is and where it came from. We know the provenance and dependencies of everything. If anything is pulled or pushed somewhere it shouldn’t be pulled or pushed from, we can stop it.” From this process, the InvisiRisk TruSBOM tool will build a 100% full and accurate SBOM. Related: New Class of CI/CD Attacks Could Have Led to PyTorch Supply Chain Compromise Related: Trellix Source Code Repository Breached Related: CISA, NSA Share Guidance on Securing CI/CD Environments
securityweek.comMay 11, 2026extracted
Progress warns of critical MOVEit Automation auth bypass flaw
Progress Software warned customers to patch a critical authentication bypass vulnerability in its MOVEit Automation enterprise-grade managed file transfer (MFT) application. MOVEit Automation automates complex data workflows without requiring manual scripting and serves as a central automation orchestrator to schedule and manage file transfers between different systems, including local servers, cloud storage, and external partners. Tracked as CVE-2026-4670, the security flaw affects MOVEit Automation versions before 2025.1.5, 2025.0.9, and 2024.1.8. Remote threat actors can exploit it without privileges on the targeted systems in low-complexity attacks that don't require user interaction. "We have addressed the vulnerability and the Progress MOVEit Automation team strongly recommends performing an upgrade to the latest version," the company says in a Thursday advisory. "Upgrading to a patched release, using the full installer, is the only way to remediate this issue. There will be an outage to the system while the upgrade is running." The same day, Progress also released security updates to address a high-severity privilege escalation vulnerability (CVE-2026-5174) stemming from an improper input validation weakness in the same software. According to a Shodan search shared by PwnDefend cybersecurity consultant Daniel Card, over 1,400 MOVEit Automation instances are exposed online, and over a dozen are linked to U.S. local and state government agencies. However, there is no information regarding how many of these systems have already been secured against CVE-2026-4670 attacks. While the company has yet to flag these security issues as exploited in the wild, other MoveIT MFT vulnerabilities have been targeted in attacks in recent years. For instance, the Clop ransomware gang exploited a zero-day in the MOVEit Transfer secure file transfer platform in an extensive series of data theft attacks in 2023 that affected more than 2,100 organizations and over 62 million individuals, according to Emsisoft estimates. MFT software is an attractive target for ransomware actors, as seen in previous Clop data-theft campaigns targeting security flaws in Accellion FTA, SolarWinds Serv-U, Gladinet CentreStack, GoAnywhere MFT, and Cleo. Progress Software says its MOVEit MFT solutions are used by more than 3,000 enterprise organizations and over 100,000 users worldwide. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 4, 2026extracted
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware. Browser extensions act normally while pulling data and running code. Even update channels are used to push payloads. It’s not breaking systems—it’s bending trust. There’s also a shift in how attacks run. Slower check-ins, multi-stage payloads, andmore code kept in memory. Attackers lean on real tools and normal workflows instead of custom builds. Some cases hint at supply-chain spread, where one weak link reaches further than expected. Go through the whole recap. The pattern across access, execution, and control only shows up when you see it all together. ⚡ Threat of the Week Vercel Discloses Data Breach—Web infrastructure provider Vercel has disclosed a security breach that allows bad actors to gain unauthorized access to "certain" internal Vercel systems. The incident originated from the compromise of Context.ai, a third-party artificial intelligence (AI) tool, which was used by an employee at the company, it added. "The attacker used that access to take over the employee's Vercel Google Workspace account, which enabled them to gain access to some Vercel environments and environment variables that were not marked as 'sensitive,'" the company said. It's currently not known who is behind the incident, but a threat actor using the ShinyHunters persona has claimed responsibility for the hack. Context.ai also disclosed a March 2026 incident involving unauthorized access to its AWS environment. However, it has since emerged that the attacker also likely compromised OAuth tokens for some of its consumer users. Furthermore, Hudson Rock uncovered that a Context.ai employee was compromised with Lumma Stealer in February 2026, raising the possibility that the infection may have triggered the "supply chain escalation." 99% of What AI Found Is Still Unpatched. See the Defensive Answer Anthropic's Mythos weaponized bugs that survived decades of human review. Atlassian's CISO, Frost & Sullivan, and leaders from Kraft Heinz and Glow Financial Services show how autonomous validation discovers what's exploitable, proves controls hold, and re-validates fixes. Register for Free ➝ 🔔 Top News Law Enforcement Operation Brings Down DDoS-for-Hire Operation—Law enforcement agencies across Europe, the U.S., and other partner nations cracked down on the commercial DDoS-for-hire ecosystem, targeting both operators and customers of services used to target websites and knock them offline. As part of the effort, authorities took down 53 domains, arrested four people, and sent warning notifications to thousands of criminal users. The U.S. Justice Department said court-authorized actions were undertaken to disrupt Vac Stresser and Mythical Stress. The actions are a persistent cat-and-mouse game, as booted services often reappear under new names and domains despite repeated takedowns. While these disruptions tend to have short-term results, the resilience of the criminal activity indicates that arrests need to be combined with infrastructure seizures, financial disruption, and user deterrence for lasting impact. Newly Discovered PowMix Botnet Hits Czech Workers—An active malicious campaign is targeting the workforce in the Czech Republic with a previously undocumented botnet dubbed PowMix since at least December 2025. "PowMix employs randomized command-and-control (C2) beaconing intervals, rather than persistent connection to the C2 server, to evade the network signature detections," Cisco Talos said. The never-before-seen botnet is designed to facilitate remote access, reconnaissance, and remote code execution, while establishing persistence by means of a scheduled task. At the same time, it verifies the process tree to ensure that another instance of the same malware is not running on the compromised host. AI-Driven Pushpaganda Exploits Google Discover to for Ad Fraud—A novel ad fraud scheme has been found to leverage search engine poisoning (SEO) techniques and artificial intelligence (AI)-generated content to push deceptive news stories into Google's Discover feed and trick users into enabling persistent browser notifications that lead to scareware and financial scams. The Pushpaganda campaign has been found to target the personalized content feeds of Android and Chrome users. "This operation, named for push notifications central to the scheme, generates invalid organic traffic from real mobile devices by tricking users into subscribing to enabling notifications that presented alarming messages," HUMAN Security said. Google has since rolled out fixes and algorithmic updates to address the issue. Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT—A social engineering campaign has abused Obsidian, a cross-platform note-taking application, as an initial access vector to distribute a previously undocumented Windows remote access trojan called PHANTOMPULSE in attacks targeting individuals in the financial and cryptocurrency sectors. Elastic Security Labs is tracking the activity under the name REF6598. It employs elaborate social engineering tactics through LinkedIn and Telegram to breach both Windows and macOS systems by tricking victims into opening a cloud-hosted vault in Obsidian. PHANTOMPULSE is an artificial intelligence (AI)-generated backdoor that uses the Ethereum blockchain for resolving its C2 server. On macOS, the attack is used to deliver an unspecified payload. CPUID Downloads Hijacked to Serve STX RAT—Unknown threat actors hijacked the official CPUID download page to serve trojanized installers that ultimately led to the deployment of STX RAT, a remote access trojan with infostealer capabilities. The attack did not compromise CPUID's original signed binaries, the threat actors served their own trojanized packages via redirect. "The threat actor compromised the official CPUID download page to serve a trojanized package, employing DLL sideloading as the initial execution vector followed by a layered, five-stage in-memory unpacking chain designed to evade detection," Cyderes said. "The use of a timestomped compilation timestamp, reflective PE loading, and exclusively in-memory payload execution demonstrates a deliberate effort to hinder forensic analysis and bypass traditional security controls." 108 Malicious Chrome Extensions Steal Google and Telegram Data—A cluster of 108 Google Chrome extensions has been found to communicate with the same command-and-control (C2) infrastructure with the goal of collecting user data and enabling browser-level abuse by injecting ads and arbitrary JavaScript code into every web page visited. The extensions provide the expected functionality to avoid raising red flags, but malicious code running in the background connects to the threat actor's C2 server to perform the nefarious activities. At the center of the campaign is a backend hosted on a Contabo virtual private server (VPS), with multiple subdomains handling session hijacking, identity collection, command execution, and monetization operations. There is evidence indicating a Russian malware-as-a-service (MaaS) operation, based on the presence of a payment and monetization portal in its C2 infrastructure. OpenAI Launches GPT-5.4-Cyber—OpenAI announced a new model, GPT-5.4-Cyber, specifically designed for use by digital defenders. Artificial intelligence (AI) companies have repeatedly warned that more capable AI models could create an opening for bad actors to exploit vulnerabilities and security gaps in software with new speed and intensity. Unlike Anthropic, which said its new Claude Mythos model is only being privately released to a small number of trusted organizations due to concerns that it could be exploited by adversaries, OpenAI said "the class of safeguards in use today sufficiently reduce cyber risk enough to support broad deployment of current models," but hinted at the need for more advanced protections in the long term. Defending critical software has long depended on the ability to find and fix vulnerabilities faster than attackers can exploit them. GPT-5.4-Cyber has a lower refusal boundary for legitimate cybersecurity work than standard GPT-5.4. It adds capabilities aimed at advanced defensive workflows, including binary reverse engineering. "We don't think it's practical or appropriate to centrally decide who gets to defend themselves," OpenAI stated. "Instead, we aim to enable as many legitimate defenders as possible, with access grounded in verification, trust signals, and accountability." The use of AI for vulnerability discovery and analysis means that the barrier to entry for attackers is collapsing. Bad actors could ask an AI model to analyze differences between two versions of a binary and generate an exploit at a faster rate. Rob T. Lee, chief of research at the SANS Institute, said the debut of Mythos and GPT-5.4-Cyber is "nothing more than one vendor trying to one-up another," adding, "We need to start benchmarking how one AI model is able to find code vulnerabilities over another and how quickly they are doing it. There are real risks at stake here." At the same time, researchers from AISLE and Xint found that it's possible to replicate Mythos's results with smaller, cheaper models. "The critical variable in AI vulnerability discovery is not the model alone," Xint said. "It is the structured system that decides where to look, validates that findings are real and exploitable, eliminates false positives, and delivers actionable remediation." 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-20184 (Cisco Webex Services), CVE-2026-20147 (Cisco Identity Services Engine and ISE Passive Identity Connector), CVE-2026-20180, CVE-2026-20186 (Cisco Identity Services Engine), CVE-2026-33032 (nginx-ui), CVE-2026-32201 (Microsoft SharePoint Server), CVE-2026-27304 (Adobe ColdFusion), CVE-2026-39813, CVE-2026-39808 (Fortinet FortiSandbox), CVE-2026-40176, CVE-2026-40261 (Composer), CVE-2025-0520 (ShowDoc), CVE-2026-22039 (Kyverno), CVE-2026-27681 (SAP Business Planning and Consolidation and Business Warehouse),CVE-2026-34486, CVE-2026-29146 (Apache Tomcat), CVE-2026-40175 (Axios), CVE-2026-32196 (Microsoft Windows Admin Center), CVE-2026-20204 (Splunk Enterprise), CVE-2026-20205 (Splunk MCP Server) CVE-2026-6296, CVE-2026-6297, CVE-2026-6298, CVE-2026-6299, CVE-2026-6358, CVE-2026-5873 (Google Chrome), CVE-2026-34078 (Tails), CVE-2026-34622 (Adobe Acrobat Reader), CVE-2026-33413 (etcd), CVE-2026-1492 (User Registration & Membership plugin), CVE-2026-23818 (HPE Aruba Networking Private 5G Core On-Prem), CVE-2025-54236 (Magento), CVE-2026-26980 (Ghost CMS), CVE-2026-40478 (Thymeleaf), CVE-2026-41242 (protobufjs), CVE-2026-40871 (Mailcow), CVE-2026-5747 (AWS Firecracker), and CVE-2025-50892 (eudskacs.sys). 🎥 Cybersecurity Webinars The Force Awakens in AppSec: Rethinking Mythos & Organizational Defenses at AI Speed → This webinar explores how AI-powered hacking is making traditional security patching too slow to be effective. It focuses on the "patch gap"— the dangerous time between a bug being found and fixed—and offers a new way to prioritize vulnerabilities based on real-world risk. The session provides practical strategies for security leaders to defend against automated, high-speed attacks. The Rise of the Agent: Moving to Autonomous Exposure Validation → This webinar explores how "agentic" AI is changing security testing by using autonomous AI agents to simulate real-world attacks. Unlike traditional scanners, these tools continuously find and validate which security gaps are actually reachable by hackers. The session focuses on moving from slow, manual checks to automated exposure validation to stay ahead of AI-driven threats. 📰 Around the Cyber World Vect Partners with BreachForums and TeamPCP —Dataminr revealed that the Vect ransomware group has formalized partnerships with the BreachForums cybercrime marketplace and TeamPCP hacking group. The partnership will allow BreachForums members to deploy ransomware and will use the victims of TeamPCP's supply chain attacks to attack organizations that are in a vulnerable state. "Between the two partnerships, Vect will lower the barrier to entry for ransomware actors, incentivize group members to carry out attacks, and exploit pre-existing breaches to broaden impact," the company said. "The convergence of large-scale supply chain credential theft, a maturing RaaS operation, and mass dark web forum mobilization represents an unprecedented model of industrialized ransomware deployment." MuddyWater Targets Global Organizations via Microsoft Teams —The Iranian hacking group known as MuddyWater has been observed using targeted social engineering to approach targets via Microsoft Teams by masquerading as IT support staff to trick them into running a botnet malware called Tsundere (aka Dindoor). "A notable aspect of this intrusion was the abuse of Deno, a legitimate JavaScript and TypeScript runtime typically used for backend application development," CyberProof said. "The attacker leveraged deno.exe to execute a highly obfuscated, Base64‑encoded payload -- tracked as DINODANCE -- directly in memory, minimizing on-disk artifacts and complicating detection." Once decoded, the malware establishes C2 communications with a remote server, exfiltrating basic host metadata such as username, hostname, and operating system details. Multi-Stage Intrusion Drops Direct-Sys Loader and CGrabber Stealer —An attack chain involving ZIP archives distributed through GitHub user attachment URLs is abusing DLL side-loading to deliver a malware loader called Direct-Sys Loader, which performs anti-analysis checks and then drops CGrabber. The malware, for its part, avoids infecting machines running in the Commonwealth of Independent States (CIS) countries and collects browser credentials, crypto wallet data, password manager data, and a broad range of application artifacts. "By skipping execution on machines in those regions, they reduce the risk of attracting attention from local law enforcement and avoid targeting their own infrastructure or allies," Cyderes said. "The Direct-Sys Loader and CGrabber Stealer represent a cohesive, multi-stage, stealth-focused malware ecosystem engineered with advanced detection-evasion capabilities." Russian Hackers Target Ukrainian Agencies —Threat actors linked to Russia broke into more than 170 email accounts belonging to prosecutors and investigators across Ukraine in recent months," Reuters reported, citing data from Ctrl-Alt-Intel. The espionage activity also targeted officials in Romania, Greece, Bulgaria, and Serbia. Speaking to The Record, Ukraine's State Service of Special Communications and Information Protection (SSSCIP) confirmed that local government agencies were targeted in a long-running hacking campaign that it has been tracking since 2023, with the attacks weaponizing flaws in Roundcube webmail software to run malicious code as soon as a specially crafted message is opened. The campaign is believed to be the work of APT28 (aka Fancy Bear). Infostealer Lookup Services are Changing Cybercrime —Hudson Rock revealed that infostealer lookup services, some accessible via a simple search on Google, are rapidly fueling a new era of initial access, shifting how cyber attacks begin and transforming a complex hacking process into a simple, automated transaction. "These platforms have effectively turned billions of compromised credentials and active session cookies into a highly searchable, low-cost commodity available to the masses," it said. "Because this data is so easily accessible, organizations can no longer afford to be reactive." AdaptixC2 Detailed —Kaspersky has detailed the inner workings of an open-source command-and-control (C2) framework known as AdaptixC2, which has seen increased adoption by bad actors over the past year. Written in Go and C++, AdaptixC2 is designed for post-exploitation and stealthy interaction with its malicious agents deployed on compromised systems. It also employs diverse network communication and post-exploitation techniques to get around traffic monitoring tools and minimize its footprint. "Unlike many general-purpose C2 platforms, AdaptixC2 focuses on advanced agent-to-C2 communication and specific evasion techniques designed to bypass modern security tools, including EDR and NDR solutions," the company said. "The framework provides the flexibility to develop custom agents while also including standard agent implementations in Go and C++ for Windows, macOS, and Linux. Additionally, it supports a modular approach to extending its functionality." Adware Update Delivers EDR Killer —In an unusual attack, a browser-hijacking adware family rolled out a multi-phase update that attempted to disable security software on infected hosts. The adware is signed by Dragon Boss Solutions LLC, a U.A.E.-based company that claims to conduct search monetization research and has promoted modified versions of the Chrome browser (e.g., Chromstera, Chromnius, and Artificius). "The signed software silently fetches and executes payloads capable of killing antivirus products, all while running with SYSTEM privileges," Huntress said. The antivirus killing capability was observed starting in late March 2025, although the loader and updater components date back to late 2024. "The operation uses an off-the-shelf software update mechanism to deploy these MSI and PowerShell-based payloads. Establishing WMI persistence disables security applications and blocks reinstallation of protective software," it added. The MSI installer, downloaded from a fallback update server, performs reconnaissance, queries for installed security products, and runs a PowerShell script ("ClockRemoval.ps1") to terminate running processes, disable antivirus services by tampering with the Windows Registry, delete installation directories, and force deletion when uninstallers fail. What's significant is that the update mechanism can be modified to deploy any payload. To make matters worse, the primary update domain baked into the operation to retrieve the MSI installer – chromsterabrowser[.]com – was left unregistered, meaning any threat actor could have registered the domain for as little as $10 and push malicious updates, turning an adware infection into a potential supply chain compromise. The domain has since been sinkholed. That said, 23,565 unique IP addresses connected to the sinkhole during a 24-hour monitoring period. The infections are concentrated around the U.S., France, Canada, the U.K., and Germany. These included universities, OT networks, government entities, primary and secondary educational institutions, healthcare organizations, and multiple Fortune 500 companies. India Will Not Require Smartphone Makers to Preload Aadhaar App —The Indian government will no longer require smartphone makers like Apple and Samsung to preload devices with a state-owned biometric identification app, Reuters reported. India's IT ministry reviewed the proposal and "is not in favour of mandating the pre-installation of the Aadhaar App on smartphones," UIDAI said in a statement. The Aadhaar request was the sixth time in two years the government has sought pre-installation of state apps on phones, according to industry communications. Smartphone makers flagged concerns about device security and compatibility when they received the Aadhaar preload proposal, and also flagged higher production costs as they would have been required to run separate manufacturing lines for India and export markets. SQL Injection Campaign Targets Payment Services —An active SQL injection campaign is operating through attacker infrastructure located in Canada. The campaign has targeted 35 websites, with confirmed successful SQL injection exploitation and data exfiltration affecting three organizations operating in the payment, real estate, and developer service sectors. Attacker-side artifacts indicate coordinated and deliberate exploitation rather than opportunistic scanning. QEMU Abused for Defense Evasion —Threat actors are abusing QEMU, an open-source machine emulator and virtualizer, to hide malicious activity within virtualized environments. "Attackers are drawn to QEMU and more common hypervisor-based virtualization tools like Hyper-V, VirtualBox, and VMware because malicious activity within a virtual machine (VM) is essentially invisible to endpoint security controls and leaves little forensic evidence on the host itself," Sophos said. Two clusters of activity have been detected: STAC4713, which has used QEMU as a covert reverse SSH backdoor to deliver tooling and harvest domain credentials with the end goal of likely deploying Payouts King ransomware (likely tied to former BlackBasta affiliates) after obtaining initial access via exploitation of known security flaws in SolarWinds Web Help Desk, and STAC3725, which exploits Citrix Bleed 2 (aka CVE-2025-5777) for obtaining a foothold and installs ScreenConnect for persistent remote access. The threat actors then deploy a QEMU VM to install additional tools for conducting enumeration and credential theft. "Follow-on activity differed across intrusions, suggesting that initial access brokers originally compromised the victims’ environments and then sold the access to other threat actors," Sophos said. Fake Adobe Reader Site Drops ScreenConnect —Threat actors are using fake Adobe Acrobat Reader website lures to lure victims into installing ConnectWise's ScreenConnect. The attack chain was detected in February 2026. "The attack uses .NET reflection to keep payloads in memory only, which helps it evade signature-based defenses and hinder forensic examination," Zscaler ThreatLabz said. "A VBScript loader dynamically reconstructs strings and objects at runtime to defeat static analysis and sandboxing. Auto-elevated Component Object Model (COM) objects are abused to bypass User Account Control (UAC) and run with elevated privileges without user prompts." The attack employs an in-memory .NET loader that's responsible for launching ScreenConnect. Nearly 6M Hosts Use FTP —Censys said it observed about 5,949,954 hosts running at least one internet-facing FTP service, down from over 10.1 million in 2024, which amounts to a decline of 40% in two years. Of these, nearly 2.45 million hosts had no evidence of encryption. "Over 150,000 IIS FTP services return a 534 response, indicating TLS was never set up," Censys said. "For most use cases, FTP can be replaced without significant disruption. If FTP must remain, enabling Explicit TLS is a configuration change, not a protocol upgrade, and both Pure-FTPd and vsftpd support it natively." Malformed APKs Bypass Detections as New Android RATs Emerge —Threat actors are increasingly using malformed APKs, which refer to Android packages that can be installed and run on Android but are intentionally broken by using unsupported compression methods, header manipulation, or false password protection, to bypass static analysis tools and delay detection. Cleafy has released an open-source tool called Malfixer to detect and fix malformed APKs. The development comes as Zimperium flagged four new Android malware families, RecruitRat, SaferRat, Astrinox (aka Mirax), and Massiv, that are capable of harvesting sensitive information and facilitating unauthorized financial transactions. In all, campaigns distributing these malware families target over 800 applications across the banking, cryptocurrency, and social media sectors. RecruitRat leverages recruitment-related social engineering and fraudulent job-seeking platforms for initial access. SaferRat is distributed through fake websites that claim to offer free access to premium streaming platforms and legitimate video streaming software. All four banking trojans abuse the native Session Installation API to bypass Android's sideloading restrictions and request accessibility services permissions to carry out their malicious activities. Over 200 PrestaShop Stores Expose Installer —More than 200 PrestaShop online stores have left their installation folder exposed online, allowing attackers to abuse the behavior to overwrite database configuration, gain admin access, and execute arbitrary code on the server. According to Sansec, the affected stores span 27 countries, including France, Italy, Poland, and the Czech Republic. Another set of 15 stores has been found to expose the Symfony Profiler, which is enabled when PrestaShop runs in debug mode. How to Contain a Domain Compromise via Predictive Shielding —Microsoft detailed an attack chain in which a threat actor targeted a public sector organization in June 2025, methodically progressing from one state of the attack lifecycle to the next, starting with dropping a web shell following the exploitation of a file-upload flaw in an internet-facing Internet Information Services (IIS) server. The attacker then performed reconnaissance, escalated their privileges, leveraged the compromised IIS service account to reset the passwords of high-impact identities, and deployed Mimikatz to harvest credentials. Then, the threat actor abused privileged accounts and remotely created a scheduled task on a domain controller to capture NTDS snapshots. The attacker also planted a Godzilla web shell on the Exchange Server and leveraged their privileged context to alter mailbox permissions, allowing them to read and manipulate all mailbox contents. The threat actor subsequently used Impacket to enumerate the role assignments and other activities that were flagged and blocked by Microsoft Defender. "The threat actor then launched a broad password spray from the initially compromised IIS server, unlocking access to at least 14 servers through password reuse," Microsoft said. "They also attempted remote credential dumping against a couple of domain controllers and an additional IIS server using multiple domain and service principals." After Microsoft Defender's predictive shielding was enabled in late July 2025, the attacker's attempts to sign in to Microsoft Entra Connect servers were blocked. The campaign stopped on July 28, 2025. Cargo Theft Malware Actor Conducts Remote Access Campaigns —In November 2025, Proofpoint detailed a threat actor that used compromised load boards to gain access to trucking companies with the end goal of freight diversion and cargo theft. New research from the enterprise security company has revealed that the attacker abused multiple remote access tools like ScreenConnect, Pulseway, and SimpleHelp to establish persistence to a controlled decoy environment, with attempts made to identify financial access, payment platforms, and cryptocurrency assets to conduct freight fraud and broader financial theft. The actor maintained access for more than a month. At least one ScreenConnect instance is said to have leveraged a third‑party signing‑as‑a‑service provider to re-sign the installer with a valid but fraudulent code‑signing certificate. "This reconnaissance focused on identifying financial access – such as banking, accounting, tax software, and money transfer services – as well as transportation‑related entities, including fuel card services, fleet payment platforms, and load board operators," the company said. "The latter activity was likely designed to support crimes against the transportation industry, including cargo theft and related financial fraud." British National Pleads Guilty to Scattered Spider Campaign —Tyler Robert Buchanan, who was extradited from Spain to the U.S. last April following his arrest in the European nation in June 2024, pleaded guilty to hacking a dozen companies and stealing at least $8 million in digital assets. He pleaded guilty to one count of conspiracy to commit wire fraud and one count of aggravated identity theft. "From September 2021 to April 2023, Buchanan and other individuals conspired to conduct cyber intrusions and virtual currency thefts," the U.S. Justice Department said. "The victims and intended victims included interactive entertainment companies, telecommunications companies, technology companies, business process outsourcing (BPO) and information technology (IT) suppliers, cloud communications providers, virtual currency companies, and individuals." Buchanan and his co-conspirators conducted SMS phishing attacks targeting a victim company's employees, tricking them into clicking on bogus links that exfiltrated their credentials via a phishing kit to an online Telegram channel under their control. The stolen data was then used to access the accounts, gather confidential company information, and siphon millions of dollars' worth of virtual currency after conducting SIM swapping attacks. 🔧 Cybersecurity Tools Cirro → It is an open-source tool designed to help security experts find hidden risks in cloud environments. It works by collecting data about people, their permissions, and the digital resources they use, then turning that information into a visual map. By showing how these different pieces are connected, the tool makes it easier to spot "attack paths"—the step-by-step routes a hacker could take to move through a system and reach sensitive data. While it is currently focused on Azure, it is built to be flexible so users can add other platforms over time. Janus → It is an open-source tool designed to help security teams track technical failures during operations. It automatically pulls logs from command-and-control (C2) platforms like Mythic and Cobalt Strike to identify where tools failed or commands were blocked. By organizing these "friction points" into reports, Janus helps teams see exactly where their workflow slows down and what tasks need to be improved or automated. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion That wraps this week’s recap. Most of it isn’t loud, but it shows how easy it is for trusted paths to turn into entry points and for normal activity to hide real access. Keep an eye on the basics. Check what you trust, watch how things run, and don’t ignore the small changes.
thehackernews.comApr 20, 2026extracted
Hackers Abuse QEMU for Defense Evasion
Threat actors have been abusing QEMU in campaigns leading to the deployment of ransomware and remote access tools, Sophos reports. A cross-platform open source machine emulator, QEMU allows users to run a guest VM on top of their operating system (VM host). Over the past years, security researchers documented several malicious campaigns using QEMU to establish covert communication channels and deploy backdoors, and Sophos now says it has observed an uptick in abuse since late 2025. As part of a campaign first observed in November 2025, tracked as STAC4713 and potentially linked to the PayoutsKing ransomware, threat actors used the machine emulator as a covert reverse SSH backdoor for payload delivery and credential harvesting. At first, the hackers targeted exposed SonicWall VPNs that lacked MFA for initial access, but later switched to exploiting CVE-2025-26399, a remote code execution (RCE) vulnerability in SolarWinds Web Help Desk. The attackers created a scheduled task to launch a QEMU VM with System privileges and to establish persistence. Upon launch, the virtual hard disk image creates a reverse SSH tunnel, providing the threat actors with direct access to the VM. Sophos observed the attackers creating a volume shadow copy snapshot, copying the Active Directory database and the SAM and SYSTEM hives to temporary folders, and performing network share discovery and file access using native Windows tools. The cybersecurity firm attributes the attacks to Gold Encounter, a closed hacking group operating the PayoutsKing ransomware. The gang is known to target VMware and ESXi environments for encryption. In February 2026, Sophos observed a second campaign abusing QEMU. Tracked as STAC3725, it has been relying on the exploitation of CVE-2025-5777 (the infamous CitrixBleed2 bug) for initial access and on a malicious ScreenConnect client to achieve persistence. Following the NetScaler exploitation, the attackers created a start service, installed the remote access tool to retrieve QEMU and a virtual disk image, and manually executed the attack within the VM. The hackers were observed deploying roughly a dozen tools and libraries, harvesting credentials, enumerating Kerberos usernames, performing Active Directory reconnaissance, staging payloads, and exfiltrating data. “Follow-on activity differed across intrusions, suggesting that initial access brokers originally compromised the victims’ environments and then sold the access to other threat actors,” Sophos notes. Organizations are advised to search for unauthorized QEMU installations, rogue scheduled tasks, unusual port forwarding rules, and monitor outbound SSH tunnels, which could reveal potential compromise. Related: Next.js Creator Vercel Hacked Related: Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers Related: Microsoft Paid Out $2.3 Million at Zero Day Quest 2026 Hacking Contest Related: 100 Chrome Extensions Steal User Data, Create Backdoor
securityweek.comApr 20, 2026extracted
Payouts King ransomware uses QEMU VMs to bypass endpoint security
The Payouts King ransomware is using the QEMU emulator as a reverse SSH backdoor to run hidden virtual machines on compromised systems and bypass endpoint security. QEMU is an open-source CPU emulator and system virtualization tool that allows users to run operating systems on a host computer as virtual machines (VMs). Since security solutions on the host cannot scan inside the VMs, attackers can use them to execute payloads, store malicious files, and create covert remote access tunnels over SSH. For these reasons, QEMU has been abused in past operations from multiple threat actors, including the 3AM ransomware group, LoudMiner cryptomining, and ‘CRON#TRAP’ phishing. Researchers at cybersecurity company Sophos documented two campaigns where attackers deployed QEMU as part of their arsenal and to collect domain credentials. One campaign that Sophos tracks as STAC4713 was first observed in November 2025 and has been linked to the Payouts King ransomware operation. The other, tracked as STAC3725, has been spotted in February this year and exploits the CitrixBleed 2 (CVE‑2025‑5777) vulnerability in NetScaler ADC and Gateway instances. Running Alpine Linux VMs Researchers note that the threat actors behind the STAC4713 campaign are associated with the GOLD ENCOUNTER threat group, which is known to target hypervisors and encryptors for VMware and ESXi environments. According to Sophos, the malicious actor creates a scheduled task named ‘TPMProfiler’ to launch a hidden QEMU VM as SYSTEM. They use virtual disk files disguised as databases and DLL files, and set up port forwarding to provide covert access to the infected host via a reverse SSH tunnel. The VM runs Alpine Linux version 3.22.0 that includes attacker tools such as AdaptixC2, Chisel, BusyBox, and Rclone. Sophos notes that initial access was achieved via exposed SonicWall VPNs, while exploitation of the SolarWinds Web Help Desk vulnerability CVE-2025-26399 was observed in more recent attacks. In the post-infection phase, the threat actors used VSS (vssuirun.exe) to create a shadow copy, then used the print command over SMB to copy NTDS.dit, SAM, and SYSTEM hives to temp directories. More recently observed incidents attributed to the threat actor relied on other initial access vectors. The researchers say that in an attack in February, GOLD ENCOUNTER used an exposed Cisco SSL VPN, and in March they posed as IT staff and tricked employees over Microsoft Teams into downloading and installing QuickAssist. According to a Zscaler report this week, Payouts King is likely tied to former BlackBasta affiliates, based on its use of similar initial access methods like spam bombing, Microsoft Teams phishing, and Quick Assist abuse. The strain employs heavy obfuscation and anti-analysis mechanisms, establishes persistence via scheduled tasks, and terminates security tools using low-level system calls. Payouts King encryption scheme uses AES-256 (CTR) with RSA-4096 with intermittent encryption for larger files. The dropped ransom notes point victims to leak sites on the dark web. The second campaign that Sophos observed (STAC3725), has been active since February and exploits the CitrixBleed 2 vulnerability to gain initial access to target environments. After compromising NetScaler devices, the attackers deploy a ZIP archive containing a malicious executable that installs a service named ‘AppMgmt,’ creates a new local admin user (CtxAppVCOMService), and installs a ScreenConnect client for persistence. The ScreenConnect client connects to a remote relay server and establishes a session with system privileges, then drops and extracts a QEMU package that runs a hidden Alpine Linux VM using a custom.qcow2 disk image. Instead of using a pre-built toolkit, the attackers manually install and compile their tools, including Impacket, KrbRelayx, Coercer, BloodHound.py, NetExec, Kerbrute, and Metasploit, inside the VM. Observed activity includes credential harvesting, Kerberos username enumeration, Active Directory reconnaissance, and staging data for exfiltration via FTP servers. Sophos recommends that organizations look for unauthorized QEMU installations, suspicious scheduled tasks running with SYSTEM privileges, unusual SSH port forwarding, and outbound SSH tunnels on non-standard ports. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comApr 17, 2026extracted
CISO Conversations: Ross McKerchar, CISO at Sophos
Ross McKerchar began his Sophos career as the firm’s first security engineer 18 years ago and is now the company’s CISO. We discussed his journey and the role of the CISO. “Like most youngsters, I played video games as a child. By the time I was 16, I was already convinced that IT would be a good, solid career – so I went on to take a computer science degree at the University of Edinburgh.” But then came a realization. “I’m probably going to offend a lot of people with this, but much of IT is quite boring.” When you talk about IT, people’s eyes glaze over, he continues. But if you talk about cybercrime, they become engaged. “It’s whole of world rather than just the box in the computer room. It’s geopolitical, it’s adversarial, and it affects everybody, everywhere.” Conflict, he adds, makes for good stories – so, he shifted his interest from IT to cybersecurity. The path to leadership and team management How and why did he become a leader in cybersecurity? There is always a question over whether leadership is a genetic quality or something that can be learned: nature, or nurture – or both. McKerchar’s short answer is that it can be learned, but only if you enjoy it. For himself, he suggests, there was an element of both growing into it, and growing with it. “When I joined Sophos 18 years ago, I was basically the first internal cybersecurity employee. In that sense, I was always the leader – of a team of one. Now I am the CISO with a much larger team.” Along that route, he has had to acquire or learn skills that cannot be gained from a degree in computer science: how to recruit quality team members in an age typically described as a skills gap; how to manage that team to provide optimum performance; and how to maintain the team at that optimum performance. “The skills gap is real,” he says, “but I think it is mischaracterized both in number and effect. The cybersecurity profession is growing faster than most others. So, in this sense there is an ever-increasing demand. Education is responding with more training in security fundamentals, so there are more people looking for work in cybersecurity.” The problem is the demand is not for the people straight out of college with a piece of paper but no experience, but for people with both experience and combined emotional and business intelligence. The skills gap is at the senior level rather than the graduate level. Part of this is the continuing tendency for companies to ramp up security only after an attack. As a result, the security team suddenly leaps from two to a dozen in rapid time – and at such times, the employer wants seasoned professionals rather than newbie grads. This creates a double problem for CISOs. Firstly, although there are more people looking for positions, the positions available are not looking for those people – those positions are more attractive to the people you already have. This is the second problem: managing and maintaining the existing team. “You have to hang on to your team members because they could go – they could leave and get another job tomorrow.” So, finding a good team is hard, but keeping it is just as hard. McKerchar’s approach is to encourage his team members to be the best version of themselves possible. “You hire smart people to tell you what to do. The role of the leader is to get the obstacles out of their way so they can do just that.” This doesn’t mean absolute carte blanche for the team. The leader must keep a light touch on the tiller to keep the team and its direction in line with the company’s business objectives. But the aim is to manage a happy and fulfilled team, because happy people stay when unhappy people leave. However, the one constant in cybersecurity is change. There’s this new thing called AI. And one of the most often touted effects of AI will be an increase in the automation of expertise, and a corresponding reduction of the need for human experts – and by extension, a narrowing of the skills gap. McKerchar is reserving judgment. “I spend a lot of time talking to my CISO peers,” he explains, “and I have to say the current narrative we’re hearing from the media and business leaders is very different from the one I’m hearing from peers.” He suggests that whatever reduction in hiring we’ve seen so far has been from firms taking a gamble – betting that in a year’s time they won’t need the hire, so they’re not doing it now. He also suspects that some firms are now reversing that bet. “It’s been an interesting time. The LLMs are trained on public data, and it’s a challenge to get them to work well within an organization where organizational rather than public context is everything in triaging alerts. My human ops analysts really understand the business, and where to go and who to speak to – they almost have a sixth sense over whether an alert is more or less serious than is obvious. AI will get there, but it’s not there yet.” It’s tempting to describe current AI as high in knowledge, but low in understanding. Nevertheless, adversarial use of AI is something that all defenders are watching closely. Cybersecurity is, by its nature, largely reactive. It is the attacker that is proactive, always looking for and developing new ways to attack; and the defender that must react with new ways to defend against new and previously unknown attack methodologies. AI is still a developing technology, and nobody yet knows its future capabilities. “That’s the million dollar question,” says McKerchar. “Where’s it going to land?” He gives two suggestions. The first is the current primary adversarial use of AI: developing more advanced lures for phishing. “There is some evidence of it being used to automate attacks at scale, but the quality of the phishing isn’t yet at the level of a sophisticated attacker. It’s just the volume that has been significantly increased.” He is more concerned with AI’s ability to find new vulnerabilities, and the attackers are bound to use this ability. Finding zero days is expensive, so when they are found by attackers, they tend to be used somewhat sparingly against high value targets with supply chain potential. But if the cost of the zero day is reduced and there are more of them, they will be used against smaller firms with weaker defenses. Those smaller firms with proprietary software are not typical targets for zero days; but as the cost of zero days comes down, so their attractiveness will go up. Mental health This doesn’t change the reactive nature of cyber defense – the difficulty is that it will increase the pressure on defenders through increased volume and sophistication of attacks. And this adds to the work of the CISO. Both the CISO and the security team will need to cope with increasing pressure. This isn’t new, but it’s getting worse. And sustained pressure is a primary cause of the mental health issue known as burnout. “Burnout is a real thing in cybersecurity,” comments McKerchar. It is complete mental exhaustion and withdrawal from work, and is described by the World Health Organization as ‘a syndrome conceptualized as resulting from chronic workplace stress that has not been successfully managed.’ Cybermindz uses a technique known as I-Rest to treat burnout, which affects both CISOs and the entire security team. I-Rest is also used by the military to treat PTSD, so it is tempting to consider burnout as a form of slow burn PTSD caused by long term unmitigated stress. But as with all illnesses, prevention is better than cure. “Take my own situation,” continues McKerchar. “I’ve been continuously on call for 18 years.” He applies the same formula to the entire cybersecurity workforce, from the day each employee starts employment until now, and still ongoing. “The worst thing about cybersecurity is there’s nearly always something brewing that makes you uneasy – and it always seems to get worse on a Friday.” Being on call in cybersecurity is 24/7, including every Saturday and Sunday. “Even when not in the office, there’s this constant unease that something could blow up at any time.” Preventing burnout requires reducing base stress levels and ensuring periods of zero stress. “You can’t expect people to put in a sprint when they’re running a constant marathon. So, I try to reduce the workload and increase the fun element. It’s not simply a case of insisting on decent work hours but also allowing people to work on the projects they want to work on – so the fun stuff as well as the critical projects.” Even without burnout, people’s effective IQ drops through simple tiredness. “The last thing you need is a team that is sitting there and operating at 60% of their intellect when they’re trying to do the most important work of their careers. So, when we have a big incident, it is important that we define shift rotations and handovers and prevent people from overworking. There’s always some who just want to work – they want to keep going. But identifying them and making sure they don’t feel all the weight is solely on their shoulders, and insisting they understand that they must work in a sustainable fashion because we need them sharp – that’s very important for me.” Managing stress levels, raising spirits, and avoiding constant tiredness is McKerchar’s way to prevent burnout. Hacking back A separate recurring theme in cybersecurity is whether cyber defenders should have the same right of retaliation as kinetic defenders. Few neutral observers question the right of Ukraine to retaliate in kind following the Russian invasion of 2022. Should cyber defenders have the same right following a cyberattack (a cyber invasion of their systems)? That is, should there be a right to hack back? It’s a perennial question, but the consensus is that such a right belongs only to the government and not to individual companies. That said, McKerchar and Sophos took the question to its limits in a project it calls Pacific Rim. It discovered Chinese hackers attacking Sophos firewalls, and increased its own observation and telemetry while improving its firewalls’ security. Over time, it discovered a compromised device that was being used by the attackers to develop exploits. It responded by putting its own kernel implant on the device so that it could monitor the attackers’ activity. At a superficial level, this implant could be viewed as a form of hacking back even though it involved a local rather than foreign device – but it wasn’t ‘hacking’. Sophos obtained legal counsel and liaised with both the US NSA and the UK NCSC to ensure conformance with privacy regulations, and legality through the compromised device’s EULA with Sophos. “I wouldn’t call it ‘hacking back’,” says McKerchar, “but we took some unusually robust actions to defend ourselves against this adversary. It’s more an example of walking the line, surveilling the adversaries while they developed exploits on our own devices, but keeping our customers safe from the actions we took.” Mentoring Advice, or ‘mentoring’ in the professional jargon, is another important facet of a CISO’s role. While not written into the job description, most CISOs happily advise members of their team on how to succeed with their own ambitions. This begs one question: what was the best mentoring, or advice, this CISO received in the early stages of his career? For McKerchar, it was the simple statement, “Executives don’t like surprises.” It didn’t sound profound, but he came to realize it was all about communication. Security must often deliver bad news to, or highlight failings in, other departments. How you deliver that news is important. “How you communicate these issues and how you bring people on board and get them working with you is remarkably hard. You must have good relationships. They must trust you, and you must be able to have one-on-one conversations first – there’s almost an order of how you want to tell people and it’s almost like a saving-face thing. That simple bit of advice helped me understand the importance of stakeholder and relationship management.” ‘Communication’ and ‘trust’ were recurring themes throughout our conversation with McKerchar. The advice he gives to his own team is individual, depending upon the person concerned. But the most common is, “Understand what it is you really want to achieve. People,” he continues, “tend to tell you what they think you want to hear. They’ll typically say, ‘I want to be a CISO, a leader’.” They don’t necessarily know whether they want to be a hands-on technical leader, or a hands-off theorist, a business leader, or a consultant. They’re basically just saying ‘I want to be a success’. But you must know the destination before you can choose the best route to get there. His second piece of advice is not to concentrate purely on technical skills. “I see so many people who just over-index on technical skills and don’t build up the emotional intelligence, the cross-functional execution and communication skills required to get stuff done in a large organization. That’s the number one thing I see holding people back.” Threats We always close these conversations with a simple question: what are the biggest threats we’ll likely face over the next few years? Certain themes are relatively consistent, such as AI. But McKerchar diverges. “I should probably say ‘AI’, but I’m going to say ‘Trust’; and especially within the cybersecurity industry. I think the cybersecurity industry has a bad and growing trust problem. And the reason is a distinct and continuing trend for cybersecurity products to be the cause of breaches.” He has a point. Recent examples include F5, SonicWall, Okta, Barracuda ESG, Codecov, MOVEit, Kaseya, 3CX, and of course SolarWinds. “As someone deep in the cybersecurity industry, the obvious response could be to stand aside and look on with some weird form of schadenfreude at the tribulations of our competitors. But the real problem is it creates a trust issue for the whole industry. Collectively, we need to up our game in how we build and develop our own products; and I don’t know how that’s going to happen, because the market incentives don’t typically push vendors in that direction.” If customers cannot trust the security products they use to defend themselves, everybody suffers – and this concern perhaps helps to explain the extreme measures he and his firm took to protect his own products, and his clients, from Chinese APTs during the Pacific Rim episode. Related: CISO Conversations: Are Microsoft’s Deputy CISOs a Signpost to the Future? Related: CISO Conversations: Maarten Van Horenbeeck, SVP & Chief Security Officer at Adobe Related: CISO Conversations: Nick McKenzie (Bugcrowd) and Chris Evans (HackerOne)
securityweek.comApr 15, 2026extracted
White House Seeks to Slash CISA Funding by $707 Million
The Trump administration is proposing a $707 million reduction in the budget of the Cybersecurity and Infrastructure Security Agency (CISA) for fiscal year 2027. A proposal from the Office of Management and Budget indicates that the cut aims to refocus CISA on its core mission: protecting federal networks and critical infrastructure. The goal is also to eliminate “weaponization and waste”. “CISA was more focused on censorship than on protecting the Nation’s critical systems, and put them at risk due to poor management and inefficiency, as well as a focus on self-promotion,” the new budget proposal reads. The proposed budget seeks to streamline operations by eliminating some CISA programs deemed redundant by the administration. This includes removing school safety initiatives that overlap with existing state and federal programs. Additionally, the proposal calls for the dissolution of offices dedicated to international affairs and stakeholder engagement, as well as the termination of programs focused on combating misinformation and propaganda. The $707 million cut would bring CISA’s budget down to roughly $2 billion. It’s worth noting that in 2025 the White House proposed a $491 million cut from CISA’s budget, but the amount was reduced to approximately $135 million after Congress pushed back. CISA’s budget saw significant growth during the previous administration. The increase was triggered by major cybersecurity incidents, such as those affecting SolarWinds and Colonial Pipeline. In the first months of the second Trump administration, roughly 1,000 people (one-third of staff) reportedly left CISA through voluntary resignations and layoffs. The White House had been seeking a significant workforce reduction. However, CISA now reportedly wants to recruit more than 300 people for mission-critical roles. Nick Andersen was recently appointed acting director of CISA. Andersen, who previously served as executive assistant director for cybersecurity at the agency, replaced Madhu Gottumukkala, who left for a role at the Department of Homeland Security. President Donald Trump recently renominated Sean Plankey for the role of director at CISA. Related: Concerns Raised Over CISA’s Silent Ransomware Updates in KEV Catalog Related: Tight Cybersecurity Budgets Accelerate the Shift to AI-Driven Defense
securityweek.comApr 7, 2026extracted
APERION releases SmartFlow SDK for secure, on-prem AI governance without cloud reliance
APERION releases SmartFlow SDK for secure, on-prem AI governance without cloud reliance APERION launched SmartFlow SDK, providing a secure, on-premises path for enterprises migrating away from compromised cloud-based AI gateways. The launch coincides with a 200% increase in web traffic since the March 24 LiteLLM supply chain attack that compromised an estimated 36% of all cloud environments. LiteLLM was the victim of a supply chain attack in which the threat actor group TeamPCP compromised the most widely used open-source LLM proxy in the Python ecosystem through a cascading breach of Aqua Security’s Trivy vulnerability scanner. The compromise has forced enterprises across financial services, healthcare, and defense to urgently reassess their AI infrastructure dependencies. The entire LiteLLM package, with approximately 95 million monthly downloads, remains quarantined on the Python Package Index. APERION’s flagship product, SmartFlow, is an on-premises, Kubernetes-native AI governance control plane that was architecturally unaffected by the incident. SmartFlow is deployed as a software appliance behind the enterprise firewall, with no dependency on public package registries, no cloud data transit, and no external CI/CD pipelines in the customer deployment path. “The LiteLLM supply chain attack is the AI era’s SolarWinds or NotPetya moment. It validates what we have been building toward since day one: regulated enterprises cannot govern their AI from the cloud,” said Craig Alberino, CEO of APERION. “In the week since the breach, we have seen a 200% increase in web traffic from enterprises searching for LiteLLM alternatives and AI gateway security. These are not startups. These are institutions that define what production-grade means in financial services and healthcare. AI governance infrastructure is an estimated $40 to $50 billion market opportunity, and enterprises are now making purchasing decisions based on deployment model and supply chain security, not just features.” SmartFlow is in production with paying enterprise customers including DDA, the leading AI-powered commercial real estate investment due diligence platform, which has achieved 99.999% uptime over four months of continuous operation. Active evaluations are underway at multiple Fortune 500 institutions in financial services. The company holds 22 patent positions covering enterprise AI governance, sovereign model deployment, and autonomous AI control plane architecture. The SmartFlow SDK, also released this week, is a Python library providing enterprise developers an immediate path from evaluation to production-grade AI governance. The SDK detects whether a SmartFlow appliance is available and configures accordingly: full enterprise features with an appliance, or a standalone software gateway with feature parity to LiteLLM and OpenRouter without one. APERION has also published a migration whitepaper for organizations transitioning from compromised or discontinued AI gateway dependencies. “The March 2026 supply chain attack was not an anomaly. LiteLLM had 17 or more CVEs before this incident,” said Scott Ancheta, CTO of APERION. “When your AI governance layer depends on a public package registry and an unaudited CI/CD pipeline, you are not running enterprise-grade infrastructure. SmartFlow was built from the ground up as a governed appliance because we understood that the deployment model is the security model. Our Rust-based infrastructure delivers sub-5 millisecond routing overhead and our MetaCache semantic caching achieves 55% to 75% hit rates at p95 latency on production hardware. These are published, verifiable benchmarks from NVIDIA GTC 2026.” SmartFlow is deployed on-premises as a Kubernetes-native software appliance, storing zero customer data by design. The platform integrates with enterprise identity providers including Entra ID, LDAP, SAML, and OIDC for per-user audit trails and compliance-ready reporting. SmartFlow’s no-code policy engine maps to EU AI Act, NIST AI RMF, FINRA, SEC, OCC, and HIPAA requirements. The company estimates the AI governance infrastructure market at $40 to $50 billion, representing 5% to 15% governance capture of overall AI infrastructure spend.
helpnetsecurity.comApr 3, 2026extracted
New Progress ShareFile flaws can be chained in pre-auth RCE attacks
Two vulnerabilities in Progress ShareFile, an enterprise-grade secure file transfer solution, can be chained to enable unauthenticated file exfiltration from affected environments. Progress ShareFile is a document sharing and collaboration product typically used by large and mid-sized companies. Such solutions are an attractive target for ransomware actors, as previously seen in Clop data-theft attacks exploiting bugs in Accellion FTA, SolarWinds Serv-U, Gladinet CentreStack, GoAnywhere MFT, MOVEit Transfer, and Cleo. Researchers at offensive security company watchTowr discovered an authentication bypass (CVE-2026-2699) and a remote code execution (CVE-2026-2701) in the Storage Zones Controller (SZC) component present in branch 5.x of Progress ShareFile. SZC gives customers more control over their data by allowing them to store it on their infrastructure (either on-prem or in a third-party cloud provider) or on the Progress systems. Following watchTowr's responsible disclosure, the problems have been addressed in Progress ShareFile 5.12.4, released on March 10. How the attack works In a report today, watchTowr researchers explain that the attack begins by exploiting the authentication bypass issue, CVE-2026-2699, which gives access to the ShareFile admin interface due to improper handling of HTTP redirects. Once inside, an attacker can modify Storage Zone configuration settings, including file storage paths and security-sensitive parameters such as the zone passphrase and related secrets. By exploiting the second flaw, CVE-2026-2701, attackers can obtain remote code execution on the server by abusing file upload and extraction functionality to place malicious ASPX webshells in the application’s webroot. The researchers note that, for the exploit to work, attackers must generate valid HMAC signatures and extract and decrypt internal secrets. However, these are achievable after exploiting CVE-2026-2699 due to the ability to set or control passphrase-related values. Impact and exposure By watchTowr's scans, there are about 30,000 Storage Zone Controller instances exposed on the public internet. The ShadowServer Foundation currently observes 700 internet-exposed instances of Progress ShareFile, most of which are located in the United States and Europe. watchTowr discovered the two flaws and reported them to Progress between February 6 and 13, and the full exploit chain was confirmed on February 18 for Progress ShareFile 5.12.4. The vendor released security updates in version 5.12.4, released on March 10. Although no active exploitation in the wild has been observed as of writing, systems running vulnerable versions of ShareFile Storage Zone Controller should be patched immediately, as the public disclosure of the chain is likely to entice threat actors. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comApr 2, 2026extracted
Loading 40 more…