Search/tanium
Vendor

tanium

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
endpoint configuration toolset solution
Connections
68 relationships
Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited
Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched Zimbra servers are falling to CVE-2026-73570 attacks At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. AI supply chain risk is showing up in developer workflows first In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mostly in research demos. Suspected Iran-linked attack knocked UK power plant offline for days News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attacks. Production data in testing is still common, and Tricentis’ CISO wants it gone In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for a week until it was fixed. CISA’s logging guidance works beyond government The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? AI will not fix a governance problem in your camera estate Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials. Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. What 90 days and a small budget can buy in AI agent security In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why hardening and incident response become the buyer’s job. Fake bank websites play dead to evade security scanners A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra. Android car head units infected with proxy botnet malware through built-in software updaters A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found. PaperCut NG/MF vulnerabilities exploited in zero-day attacks PaperCut Software has identified the two vulnerabilities chained in these attacks and urged users to install a second patch. Cybersecurity job ads demanding AI skills double in a year Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. Fake OpenAI Codex download tricks macOS users into installing malware A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. Bogus recruiters go after high-value corporate credentials on mobile Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate The Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group, cutting off access to malware that had been used against U.S. government agencies for years. Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild. Cyberattack causes network outage at Boston Scientific, disrupts global operations Medical technology company Boston Scientific suffered a cyberattack that disrupted its IT systems and caused a network outage, affecting global operations. Manchester Airports Group breached, millions of customers’ data stolen Someone broke into the systems of Manchester Airports Group (MAG) and walked away with a “quantity” of customer data from three UK airports, the company has confirmed. North Korean remote workers are broadening their job hunt beyond IT North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in sales and marketing and the medical profession. Two alleged TeamPCP hackers arrested over global supply chain attacks Two men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then used it to break into organizations around the world. Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping Google introduced a batch of network security changes coming in Android 17, aimed at making it harder for network operators, snoops, and scammers to track what you do on your phone. The cybercrime supply chain has five stages, each with a price In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. Ransomware attackers are zeroing in on mid-market companies Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite. HOL Guard: Open-source antivirus for AI agents HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 milliseconds. Hottest cybersecurity open-source tools of the month: August 2026 Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. Product showcase: AI Paper Trail shows the privacy cost of talking to AI Proton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see. Cybersecurity jobs available right now: August 25, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the month: August 2026 Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, Abnormal AI, F5 Networks, Intezer, Netscout, ScienceLogic, Searchlight Cyber, SelectHub, ServiceNow, Snyk, Tanium, and Tufin.
helpnetsecurity.comAug 30, 2026extracted
New infosec products of the month: August 2026
New infosec products of the month: August 2026 Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, Abnormal AI, F5 Networks, Intezer, Netscout, ScienceLogic, Searchlight Cyber, SelectHub, ServiceNow, Snyk, Tanium, and Tufin. ServiceNow organizes autonomous security around six solution areas ServiceNow has announced an acceleration of its Autonomous Security vision with six unified solutions that help deliver prevention-first, AI-native cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, and agentic incident response, and cyber risk and compliance. Tanium expands autonomous security across AI, exposure management and SecOps Tanium has announced a series of new autonomous security capabilities across the Tanium Autonomous IT Platform. Spanning agentic AI, exposure management and security operations, the capabilities empower IT and security operators to stay ahead of an AI-accelerated threat landscape, safely, without losing control. Snyk unveils continuous AI pentesting and agent red teaming Snyk has announced the general availability of Evo Continuous Offensive Security (COS), enabling security teams to continuously test applications with autonomous, AI-powered pentesting and AI agent red teaming while providing validated proof of what attackers could actually exploit. ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5 ScienceLogic has announced Skylar AI 2.5, expanding secure deployment options for organizations with stringent security, sovereignty, and compliance requirements, while introducing enhancements that strengthen AI performance, operational intelligence, and enterprise integrations. The release further improves AI accuracy, platform performance, and natural language user experience across the ScienceLogic AI Platform. Searchlight Cyber combines exposure and threat intelligence in new PTEM platform Searchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence to help organizations prioritize and reduce the exposures most likely to be exploited. The platform combines two core capabilities. Searchlight Exposure provides continuous exposure visibility, attack surface discovery, and exploitability validation, while Searchlight Threat delivers intelligence on what threat actors are discussing, developing, and targeting. A10 Networks introduces AI Gateway to secure and manage enterprise AI A10 Networks has announced the general availability of the A10 AI Gateway, a centralized, intelligent control plane that gives organizations unified routing, cost management, and governance across every AI agent, application and large language model (LLM) they use. DataGrout helps enterprises control AI usage, governance and LLM costs SelectHub has announced the launch of DataGrout, its specialized AI research lab introducing an LLM inference optimization platform and AI governance solution for enterprises. DataGrout’s mission is to drive token reduction for agentic workflows, chatbots and AI tools, while equipping IT and FinOps leadership with a policy-driven, auditable LLM payload and cost monitoring system to track company-wide AI utilization. NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic. By extending protection from the attack target towards its source, NETSCOUT helps operators prevent compromised subscriber devices from disrupting their own networks, consuming costly capacity and attacking customers and organizations across the internet. F5 enhances AI Gateway to control AI costs, access, and security F5 has introduced enhancements to the F5 AI Gateway and integrated the solution into the F5 AI Security Platform. The enhanced F5 AI Gateway seamlessly enforces policies on every AI request, giving enterprises a unified control plane to govern how AI models, agents, and tools are accessed and used, while optimizing the economics of AI at scale. The F5 AI Guardrails dashboard (Source: F5) Intezer adds native response automation without separate SOAR Intezer has announced Workflows, a native automation and response builder that enables security teams to create and customize response workflows directly inside the Intezer platform. Workflows brings response into the same platform where alerts are triaged and investigated, allowing organizations to automate post-investigation actions without maintaining a separate Security Orchestration, Automation, and Response (SOAR) system. Tufin expands Unified Control Plane with AI intelligence and multi-vendor automation Tufin has announced the availability of Tufin Orchestration Suite (TOS) 5.3, helping enterprises further simplify security operations and maintain consistent control across increasingly complex multi-vendor, hybrid environments. In addition to these updates to the platform, Tufin also released its new AI-powered Segmentation Intelligence solution, which continuously analyzes an organization’s segmentation policies to understand segmentation intent, identify policy gaps and drift, and recommend how to close those gaps. Abnormal AI expands email security from detection to data protection and phishing-simulation training Abnormal AI announced an expansion of its email security platform with three new capabilities: Control Center, Email DLP Rules, and AI Phishing Coach upgrades. Together, the launch extends Abnormal’s behavioral AI across all three surfaces of email risk: what comes into the inbox, what leaves the organization, and how people are trained to recognize an attack.
helpnetsecurity.comAug 28, 2026extracted
Top product launches at Black Hat USA 2026
Top product launches at Black Hat USA 2026 Black Hat USA 2026 is underway in Las Vegas, and vendors are using the moment to unveil what they hope will define the next year of defense. Here are the announcements drawing the most attention on the ground, and why they matter for teams weighing new budgets. Impersonation Protection enables members to authenticate phone calls, video meetings, emails, WhatsApp and Slack messages, texts, and other communications in real time. BlackCloak moves the security control out of the potentially compromised channel, and puts the focus on the basis of trust between the two parties. The expanded capability extends functionality beyond BlackCloak’s membership. Members can now invite the people they trust most: family members, wealth advisors, lawyers, executive assistants, caregivers, and household staff, into their own circle of trust. Invited contacts download a free version of the BlackCloak app, register their device, and can then both send and receive authentication requests with the member. Stairwell, the AI SOC that stops breaches no one else can, today announced the availability of Backstory, an agentic investigation platform that traces related malware variants, identifies affected systems, and maps the full blast radius of an incident in seconds, so enterprises know what happened, where it spread, and what needs to be contained before precious time is lost. Jscrambler launched its Unified Client-Side Security Platform, introducing a new approach to securing applications and customer data where AI-powered risks increasingly operate: inside the browser. Organizations can deploy individual solutions based on their priorities or expand across initiatives over time, giving CISOs, security architects, AppSec, Security Engineering, Privacy, GRC, and SOC teams shared visibility, continuous runtime enforcement, and a common operational foundation through a single platform. Novee announced the expansion of its AI penetration testing platform to mobile applications. With this addition, Novee becomes the industry’s first complete AI pentesting platform across the modern application attack surface, providing continuous, autonomous coverage. The platform tests web apps and APIs, along with desktop, AI and LLM-enabled applications. Filigran has announced XTM One, an AI-native agentic layer that automates Continuous Threat Exposure Management (CTEM) workflows across the Filigran XTM Platform. XTM One introduces a dedicated AI orchestration layer that connects OpenCTI and OpenAEV into a single, continuous workflow. Security teams move manually between tools, ingesting threat intelligence in one system, building attack scenarios in another, and tracking remediation in separate dashboards. ServiceNow accelerated its Autonomous Security vision with six unified solutions that help deliver prevention-first, AI-native cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, and agentic incident response, and cyber risk and compliance. NodeZero WebApp Pentesting closes the gap by delivering production-safe autonomous testing that spans web applications, infrastructure, cloud, data, and identity. It proves what is actually exploitable, quantifies the business consequence of each attack path, and maps those paths to the tactics of known threat actors, enabling companies to accurately prioritize and urgently fix vulnerabilities that matter. VibeGuard 2.0 harmoniously runs on the endpoint, automatically discovers and protects all agents and interacts with users rather than blocking, and frustrating, developers. It can cover all agentic variations and plugins, delivering complete coverage and very granular policies that secures specific agent commands and tools. Tanium is extending the Tanium Autonomous IT Platform across three areas: agentic AI, exposure management, and security operations, giving operators a complete view from external attack surface to endpoint, and the ability to act on it autonomously, at scale. Snyk has announced the general availability of Evo Continuous Offensive Security (COS), enabling security teams to continuously test applications with autonomous, AI-powered pentesting and AI agent red teaming while providing validated proof of what attackers could exploit.
helpnetsecurity.comAug 5, 2026extracted
Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
Many companies are showcasing their cybersecurity products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. To help cut through the clutter, the SecurityWeek team is publishing a digest summarizing vendor announcements at Black Hat USA 2026, including new products and services, updates to existing offerings, reports, and other initiatives. The first part of this roundup was published on August 3. Astelia unveils agentic AI exposure management capabilities Astelia launched its new agentic AI capabilities for its exposure management platform, automating reachability analysis and remediation workflows across the entire vulnerability lifecycle. By adding this new agentic layer, the platform now evaluates newly disclosed vulnerabilities and their reachability, assesses operational impact, coordinates remediation across security and IT teams, and helps drive each issue toward resolution. Human approval remains built into key decision points, with every action logged and auditable. AvePoint adds continuous data sensitivity classification to Confidence Platform AvePoint has introduced Kinetic Classification, a capability that continuously re-evaluates data sensitivity across Microsoft 365, Google Workspace, and other business applications, replacing static, one-time labeling. AvePoint also added new tools to its Rapid Recovery system, including a Rapid Recovery Wizard and Express Recovery for Entra ID, meant to help teams prioritize restoration of critical data after an incident. CrowdStrike publishes 2026 Threat Hunting Report CrowdStrike’s 2026 Threat Hunting Report finds that AI is now embedded across modern adversary operations, with threat actors using AI to accelerate attacks, exploit vulnerabilities within hours of public disclosure, and target enterprise AI systems and software supply chains. The report also highlights a sharp rise in cloud-focused attacks, AI supply chain compromises, and abuse of trusted authentication workflows, underscoring the need for organizations to secure AI environments while using AI to defend against increasingly automated threats. Cisco Talos research shows how threat actors are weaponizing AI Cisco Talos released new research detailing how threat actors are using AI and LLMs in real-world cyberattacks. Drawing on recovered prompt logs, attack tooling and threat actor conversations, the research documents how AI is being used to develop malicious code, build fraud infrastructure, and accelerate vulnerability research and exploitation. The research found that threat actors rarely need sophisticated jailbreaks; sophisticated threat groups are leveraging AI as a development assistant to rapidly build exploits; and that adversaries use AI across various steps of the attack lifecycle and operations. Drata extends trust management platform to AI agents Drata has extended its Trust Management Platform, announcing the limited availability of AI Agent Governance, which is designed to help enterprises discover, monitor, govern, and prove traceability of the AI agents running inside the organization. The product ships first for Anthropic, with early access customers already running it end-to-end in production. Horizon3 extends production-safe autonomous pentesting to web applications Horizon3.ai announced NodeZero WebApp Pentesting, an expansion that enables the NodeZero platform to autonomously and safely test web applications the way attackers operate. It proves what is actually exploitable, quantifies the business consequence of each attack path, and maps those paths to the tactics of known threat actors. The announcement comes just as the company raised $250 million in funding. Huntress expands Managed ESPM with free RMM Guard Huntress announced that its RMM Guard is now available for free to all customers with an agent deployed, as part of its broader Managed ESPM effort. This release is focused on detecting and blocking rogue remote monitoring and management tools that attackers increasingly abuse to gain and maintain access. RMM Guard identifies and blocks unauthorized RMM software on endpoints before it can be used for persistence or remote control, lets teams define which RMM tools are approved and which should be blocked, and adds extra protection for isolated machines so approved remote access tools do not get blanket access. The announcement comes in light of a new N-central RMM vulnerability being exploited in the wild. Legit Security releases VibeGuard 2.0 for coding agent endpoint security Legit Security has released VibeGuard 2.0, an endpoint-based tool that discovers and secures AI coding agents such as Claude Code, Cursor, and GitHub Copilot. It operates at the endpoint level, applying policy enforcement and granular controls over specific agent commands and tools. New features include guardrails for skill discovery, blocking of risky operations, MCP security controls, command monitoring against built-in or custom policies, and anti-tampering protections meant to stop agents or users from disabling the tool. Netskope announces DataSec Command Center Netskope announced its Netskope One DataSec Command Center, a unified control plane that discovers, understands, tracks, and protects sensitive data of any kind wherever it lives and moves, from AI environments to the network. With Netskope One DataSec Command Center, security teams gain full visibility into their sensitive data and a seamless path from discovery to remediation across their entire data landscape. ProjectDiscovery announces general availability of Neo ProjectDiscovery announced the general availability of Neo v1, and a new Pay-as-you-go model. After six months of private beta testing with enterprise customers, ProjectDiscovery is making Neo available to everyone to help teams move from periodic, manual testing toward continuous security that runs alongside development. Teams of all sizes can access autonomous security testing across code, applications, APIs, cloud and networks with this new pay-as-you-go model, without traditional procurement and budget barriers. Qualys adds scanless vulnerability detection to ETM platform Qualys has introduced InstaScan, a scanless detection capability inside its Enterprise TruRisk Management (ETM) platform. The feature is powered by Agent Insta, an AI agent that continuously matches newly published vendor advisories against an organization’s existing asset inventory and telemetry rather than relying on scheduled scans. It normalizes software identities into standard identifiers (such as CPEs and PURLs) to build a consolidated inventory, then flags affected assets and issues confidence-scored findings. SailPoint unveils SailPoint Identity Security SailPoint has unveiled SailPoint Identity Security, a combination of SailPoint Agentic Fabric and SailPoint Human Fabric designed to deliver a continuous, real-time loop to discover, govern, and protect digital environments across human, non-human and agentic identities. Sectigo launches automation gateway for certificate lifecycle management Sectigo has released Sectigo Orchestration Gateway (SOG), a new automation layer inside its Sectigo Certificate Manager (SCM) platform. The gateway lets IT teams automate certificate discovery, issuance, renewal, and deployment across servers, load balancers, CDNs, WAFs, and access systems from a single install. It includes native support for platforms such as IIS, Apache, F5, NGINX, and Citrix, along with direct integrations with credential managers CyberArk, Delinea, HashiCorp, and BeyondTrust for just-in-time credential retrieval. Sevii expands ADR platform with autonomous preemptive security module Sevii announced a major expansion of the Sevii Autonomous Defense & Remediation (ADR) platform with the general availability of an Autonomous Preemptive Security (APS) module. The new module extends the platform to continuously transform external global and internal environmental cyber intelligence into autonomous hypothesis hunting, exposure validation, compromise detection, and autonomous remediation. Sysdig launches AI-native offering for cloud runtime defense Sysdig has launched Sysdig Secure AI, an AI-native addition to its Sysdig Secure cloud-native application protection platform (CNAPP). The offering provides three ways to apply AI to cloud defense: autonomous agents that prioritize risks and issue remediations, a “headless” mode that integrates with AI coding agents such as Claude, Cursor, and Codex, and a GenAI assistant (formerly Sysdig Sage) that explains risks and recommends fixes in plain language. Tanium expands Autonomous IT Platform with new agentic and exposure tools Tanium added new capabilities across its Autonomous IT Platform in three areas. Tanium Atlas now includes Agentic Performance Analysis for root-cause tracing, Background AI Agents that run alert-to-resolution workflows autonomously, and an MCP Server that exposes Tanium data to clients like Claude and Microsoft Security Copilot. New exposure management tools add External Attack Surface Management and Attack Path Mapping, while a new Agent-Guided Threat Hunting feature runs hypothesis-driven hunts mapped to MITRE ATT&CK, paired with a private-preview integration with Google Threat Intelligence. Torq unveils SOC Brain Torq has introduced Torq SOC Brain, a new self-learning layer of its AI SOC Platform that continuously learns from historical investigations, analyst decisions, and organization-specific security operations to create a personalized intelligence engine. By utilizing its Recall, Reflex, and Retrospect capabilities, the system reasons from precedent and organizational history to adapt to each team’s unique risk logic and deliver increasingly accurate threat classifications over time. Viakoo adds configuration drift remediation module for OT and IoT devices Viakoo has introduced Device Configuration Manager (DXM), a new module for its Viakoo Action Platform aimed at correcting configuration drift in OT and IoT environments. The agentless tool continuously audits device settings against defined baselines, flags unauthorized changes, and automatically restores devices to a compliant state. Viakoo also expanded its integrations to include Armis, Forescout, Nozomi Networks, Claroty, and Tenable. DXM is expected to become available in Q4 2026. Vicarius publishes state of vulnerability remediation report Vicarius released its “Exposed and Unfixed: The 2026 State of Vulnerability Remediation” report, which shows that siloed workflows and manual administrative handoffs leave 79% of organizations vulnerable to known exploits they already knew about. The report data found that 75% of critical vulnerability responses simply trigger an administrative workflow rather than actually resolving the threat, 50% of organizations consider a vulnerability “closed” based on pure risk acceptance or ticket generation rather than running a verified rescan to ensure the patch worked, and 79% of organizations experienced a security incident in the past 12 months involving a vulnerability that was already sitting in their inventory. Zimperium releases automated mobile forensic investigation tool Zimperium has introduced Deep Insights, a mobile forensic investigation tool built to automate analysis of mobile device attacks. The tool reconstructs full attack timelines from collected evidence, allowing tier-one SOC analysts to investigate incidents without specialized mobile forensics expertise. It also runs automated pre- and post-travel comparisons to flag suspicious changes in device state. Deep Insights is expected to become generally available in September 2026.
securityweek.comAug 4, 2026extracted
Tanium expands autonomous security across AI, exposure management and SecOps
Tanium expands autonomous security across AI, exposure management and SecOps Tanium has announced a series of new autonomous security capabilities across the Tanium Autonomous IT Platform. Spanning agentic AI, exposure management and security operations, the capabilities empower IT and security operators to stay ahead of an AI-accelerated threat landscape, safely, without losing control. “Tanium is the platform that governs and manages them with Tanium Atlas — where every action is auditable, boundaries are enforced, and everything is grounded in what’s actually happening on the endpoint right now. What we are introducing extends that same principle across the full lifecycle from external exposure to detection to remediation,” said Harman Kaur, CTO at Tanium. That attack surface is expanding on every front: more identities, cloud services, and AI tooling are being deployed faster than security teams can vet them, while attackers use that same AI to move at machine speed. Keeping pace, let alone getting ahead, demands autonomous security: the ability to detect, decide, and remediate at that same speed. That is what Tanium is delivering, extending the Tanium Autonomous IT Platform across three areas: agentic AI, exposure management, and security operations, giving operators a complete view from external attack surface to endpoint, and the ability to act on it autonomously, at scale. Agentic AI and Tanium Atlas Tanium Atlas is an autonomous operating system built natively on the Tanium Autonomous IT Platform. It is designed to take IT and security operators from question to resolution in a single experience. Tanium Atlas runs through a governance model that makes it auditable and keeps it within limits defined by the operator, and can be reviewed after the fact. New capabilities within Tanium Atlas include: Agentic Performance Analysis: With the introduction of Agentic Performance Analysis, an operator can use Tanium Atlas to trace a slow machine back to its actual root cause in moments, replacing hours of manual log correlation. Background AI Agents: Tanium Atlas doesn’t just wait for someone to ask. Background AI Agents continuously surface issues before operators need to ask, and Tanium Atlas executes full alert-to-resolution workflows within limits operators define. Tanium Automate: Tanium Automate is expanding with endpoint-level sequence execution and a generalized API step, enabling playbooks to run faster on each endpoint while also connecting directly to external systems through REST and GraphQL APIs. As Tanium Atlas advances, Automate becomes the governed execution layer that turns endpoint intelligence and AI-assisted recommendations into safe, orchestrated action across endpoints and connected systems. Tanium Atlas MCP Server: Tanium Atlas MCP Server exposes approved Tanium data and actions as tools inside Claude, Microsoft Security Copilot, Copilot Studio, and other MCP-compatible AI clients through a governed Model Context Protocol server, allowing agents to interact with the Tanium Autonomous IT Platform and Tanium Atlas. That real-time endpoint foundation extends beyond the endpoint itself, to what an organization has exposed to the internet. Exposure management Organizations have blind spots beyond the firewall, and AI is accelerating how fast new vulnerabilities surface, with no clear sense of what to fix first. Fragmented tools amplify the problem, leaving teams exposed for longer than ever. Tanium is introducing two new exposure management capabilities that address this directly. Tanium’s External Attack Surface Management: This capability closes that gap by unifying real-time internet visibility from Censys to continuously discover an organization’s internet-facing assets, including hosts, services, web properties, and certificates, with endpoints to provide one continuously updated view of the full attack surface. Attack Path Mapping: Attack Path Mapping connects the dots between something exposed on the internet and what it can reach inside an organization’s network, showing the exact chain an attacker would follow to access the most sensitive systems. Instead of chasing every vulnerability equally, teams can see which single fix would shut down the most attack routes at once, prioritizing the fixes that get closest to an organization’s crown jewels. Tanium Endpoint Management is the connective tissue that turns these findings into confident, autonomous action. Because Tanium collects real-time intelligence from every endpoint, Exposure Management never scores risk in the abstract. Knowing where you are exposed is only part of the picture. When threats are already in motion, operators need the ability to hunt, validate and respond at the same speed attackers move. Security operations Tanium is introducing two new security operations capabilities: Agent-Guided Threat Hunting and the Tanium and Google Threat Intelligence integration. Proactive threat hunting is one of the most valuable things a security team can do, and one of the least done because it takes a rare kind of expert and hours of manual work per hunt. Agent-Guided Threat Hunting: Tanium Atlas changes the economics of proactive threat hunting. A hunter describes a hypothesis in plain language, and Tanium Atlas runs the hunt autonomously across the estate, reasoning over live endpoint data, choosing the right tool for the question, and mapping what it finds to MITRE ATT&CK. Tanium and Google Threat Intelligence integration (private preview): A hypothesis often starts with intel, and that’s where Tanium and Google Threat Intelligence comes in. SecOps teams buy threat intel, but the hard part is knowing whether a threat is live in your environment, and stopping it before it spreads. The intelligence gained from Mandiant’s frontline expertise, VirusTotal’s crowdsourced data and Google’s vast visibility is now incorporated with Tanium’s real-time visibility and control across more than 36 million endpoints worldwide, so hunts and triage start from a higher-confidence signal, and analysts spend less time chasing false positives. This integrated offering can quickly take a hunter from intel to live hunt to fleet-wide action. “Effective security operations require both high-fidelity intelligence and the ability to act on it instantly,” said Miton Adhikari, head of Google Security OEM Partnerships at Google. “By incorporating Google Threat Intelligence into Tanium’s real-time visibility and control across endpoints, Tanium operators can validate signals against what’s actually running in their environment and rapidly move from intel to remediation, at scale.” The capabilities Tanium is introducing share a single foundation: Tanium Atlas, the autonomous operating system that connects external exposure, endpoint intelligence and security operations into one governed, auditable experience. For IT and security operators facing an AI-accelerated threat landscape, that foundation is what makes autonomous security possible, not by removing humans from the loop, but by giving each operator the reach and speed to stay ahead of it, safely.
helpnetsecurity.comAug 4, 2026extracted
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full recap of what broke, what was exploited, and what needs attention now. ⚡ Threat of the Week New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code - Searchlight Cyber disclosed a pre-authenticated remote code execution vulnerability in WordPress Core that can be exploited anonymously on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it's already seeing proof-of-concept (PoC) exploits in circulation and that it's beginning to see the first signs of in-the-wild exploitation. "This is going to hurt," watchTowr CEO Benjamin Harris said. "WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers, but plenty will not, and that is where the damage will be done. Our advice is simple: patch as fast as you possibly can, and do not stop there. Put the controls and investigations in place to determine whether an attacker got there first and to detect and remove any backdoors that may already have been dropped before you patched." The cybersecurity company said it's the latest example of vulnerabilities being surfaced by AI-assisted tooling and how the technology is being abused by attackers to weaponize them. AI Broke Vulnerability Management. Here Is the CISO Case The AI security job market is no longer theoretical. SANS tracked hiring across 10 specific roles and mapped verified job data, salary ranges, and the skills required to get there. The three-tier framework gives your team a clear view of which roles to prioritize now and which to develop toward. Download Now ➝ 🔔 Top News SonicWall SMA Zero-Days Exploited as 0-Days - A previously undocumented threat actor codenamed UTA0533 has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior to their public disclosure since June 22, 2026. The discovery was made following an incident response investigation initiated earlier this month. The impacted organization has not been identified. "This threat actor was observed using multiple zero-day exploits, malware designed specifically for SonicWall SMA VPN appliances, as well as other attacker tradecraft," Volexity said. The vulnerabilities in question are CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2), both of which could be chained to facilitate arbitrary command execution and take over susceptible devices. Patches for both vulnerabilities were released by SonicWall last week. DoS Flaw in OpenSSL - The Okta Red Team disclosed details of HollowByte, a denial-of-service (DoS) flaw in OpenSSL. "By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can force a server to allocate disproportionate chunks of memory before any security handshake even begins," Okta said. Put differently, an unauthenticated attacker -- through 11 bytes of carefully crafted data -- can convince OpenSSL to reserve up to 128 KB of heap memory for a handshake message that never actually arrives, causing a server to exhaust available RAM and trigger a DoS condition. The OpenSSL team resolved the issue in versions 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21. "Instead of trusting the header outright, OpenSSL now grows the buffer only as bytes actually land on the wire. A claim with no follow-through now costs the server nothing," Okta said. CISA Adds New SharePoint RCE Zero-Day to KEV Catalog - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability, CVE-2026-58644 (CVSS score: 9.8), is a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code. Patches for the flaw have been released as part of the Patch Tuesday updates released on July 14, 2026. Microsoft revised its bulletin to clarify that CVE-2026-58644 has been exploited in the wild, meaning the shortcoming was weaponized as a zero-day prior to the fixes becoming available. The development came as Microsoft shipped its largest Patch Tuesday on record, addressing 622 vulnerabilities. OkoBot Malware Framework Infects Windows to Phish Crypto Seed Phrases - A new malware framework called OkoBot is designed to capture the contents of cryptocurrency wallet windows. OkoBot is an updated version of TookPS, which is a downloader for retrieving malicious commands and scripts from attacker-controlled servers to further propagate attacks, including a Python-based infostealer and a remote access trojan called TeviRAT. "This campaign differs from previous activity in that it uses a new framework to deliver all malicious modules and orchestrate them via an SSH tunnel," Kaspersky said. "In total, the framework includes more than 20 malicious payloads and implants, covering a wide variety of functions. At the time of writing, the threat remains active." The infection chain makes use of ClickFix and malware distributed through GitHub that masquerades as legitimate software for initial access. It also comes with a web browser extensions loader to deliver Rilide, a browser-based stealer, as well as inject an implant into Trezor Suite, Ledger Wallet, and Ledger Live processes to collect seed phrases, log keystrokes and clipboard content, take screenshots, and capture keystrokes and the video stream of the target application's window using the OkoSpyware module. Hundreds of victims of the OkoBot campaign have been detected in more than 25 countries, with the highest concentration in Brazil, Vietnam, Canada, Mexico, and Türkiye. The activity remains unattributed. NadMesh Scans Exposed AI Services for Cloud Keys and Kubernetes Tokens - A new Go botnet called NadMesh has been observed hunting for exposed AI services related to ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio to steal AWS keys and Kubernetes tokens. "It folds scanning, exploitation, and credential/AI-service intelligence harvesting into a single autonomous platform," QiAnXin XLab said. "On the victim, the bot agent establishes persistence along three independent paths: an SSH public-key backdoor (.ssh/authorized_keys), persistence files in multiple locations (/dev/shm/.a, /var/tmp/.a, /tmp/.a), and hidden cron watchdogs (/etc/cron.d/.sys_monitor, /etc/cron.d/.s)." ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-63030, CVE-2026-60137 (WordPress Core), CVE-2026-58644, CVE-2026-56164 (Microsoft SharePoint Server), CVE-2026-56155 (Microsoft Active Directory Federation Services), CVE-2026-53412 (Zoom Desktop Client for Windows and Zoom VDI Client for Windows), CVE-2026-44747, CVE-2026-27690, CVE-2026-44761 (SAP), CVE-2026-57219, CVE-2026-57221 (RabbitMQ), CVE-2026-59208, CVE-2026-54305 (n8n), CVE-2026-60105 (Monsta FTP), CVE-2026-14960, CVE-2026-14961 (tdeio64.sys driver), CVE-2026-33894, CVE-2026-33895 (Digital Bazaar node-forge), CVE-2026-6875 (ServiceNow AI Platform), CVE-2026-42533, CVE-2026-60005, CVE-2026-56434 (F5 NGINX Plus and NGINX Open Source), CVE-2026-20296, CVE-2026-20297 (Splunk Enterprise), CVE-2026-15265 (Tenable Agent), CVE-2026-6423 (ESET Inspect Connector), CVE-2026-15053 (Tanium Server), CVE-2026-44909, CVE-2026-59173, CVE-2026-59762 (HTTP/2 server implementations), CVE-2026-14890 (SGLang), CVE-2026-14266 (7-Zip), CVE-2026-59084 (Apache Tomcat), CVE-2026-15682 (AnyDesk), and CVE-2026-54523 (Kyverno). 🎥 Cybersecurity Webinars Your AI Agent Has Credentials. Can You Stop It When It Goes Rogue? Hands-on testing of OpenClaw shows how agentic AI can expose secrets, bypass safety controls, and create a powerful new attack surface. Join Okta Threat Intelligence Director Jeremy Kirk to examine how attackers are abusing AI agents and learn practical ways to control access, enforce least privilege, detect shadow AI, and shut down risky agents before they cause damage. When AI Ships 50× More Code, Human Review Stops Scaling → AI-assisted development is pushing code production beyond what traditional security reviews and CVE-driven remediation can handle. This webinar gives security leaders a practical framework for governing the expanding attack surface, building secure-by-default controls, and enabling teams to develop at machine speed without surrendering control of software risk. 📰 Around the Cyber World New Campaign Delivers Remcos RAT - A new malware distribution campaign has abused the credibility of government institutions to increase the likelihood of infection success. The activity targets Indian businesses and taxpayers using Goods and Services Tax (GST)-related themes to distribute malware. "The threat actors impersonated legitimate government departments and distributed malicious emails disguised as official notifications related to taxation, refunds, compliance requirements, and regulatory matters," Seqrite Labs said. "The threat actors employ convincing documents and filenames that closely resemble official GST notifications, making it difficult for recipients to distinguish malicious content from legitimate government correspondence." The end goal is to deploy Remcos RAT and steal sensitive information. India's Kudankulam Nuclear Power Plant Suffers a Data Leak - The Kudankulam Nuclear Power Plant located in the Indian state of Tamil Nadu suffered an accidental exposure after Reliance Infra (RPOWER) got hit by a ransomware group called World Leaks, a spin-off of Hunters International, which, in turn, is another variant of the Hive ransomware family. The leak consists of 18,997 files, totalling 14.3GB of data, per security researcher Rakesh Krishnan. They contain purported blueprints for the ventilation and cooling systems used in Unit 3 and Unit 4, along with a complete floor layout of a "common control room". It's assessed that Reliance Infra was not impacted directly, but rather through a third-party vendor named Yotta. In a statement shared on X, the Nuclear Power Corporation of India Limited said: "The scope of the contract includes Engineering, Procurement/supply, Construction and Commissioning of Common service facilities. These facilities are of conventional nature and are typically found in thermal power plants as well as other process industries. They are not related to nuclear safety or nuclear security systems." It also noted that "the information claimed to be available in the public domain pertains only to conventional Balance of Plant (BoP) common service facilities and does not relate to any nuclear safety - or nuclear security-related systems or information." Blind Eagle Shows No Signs of Stopping - Nearly a year after Blind Eagle's activities were documented, a new report from LevelBlue has found the threat actor to be active, moving part of its VBScript delivery infrastructure onto the Russian bulletproof hosting provider Proton66 as of June 2025. The group has also devised a bespoke string-obfuscation scheme, a RunPE loader built entirely on a bare AutoIt3 interpreter, and an upgraded version of AsyncRAT that introduces Windows Notification Facility (WNF) process injection, a custom Base28 payload encoding, a full Hidden VNC (HVNC) banking-fraud module with browser profile cloning, and a Chrome App-Bound Encryption (ABE) bypass, per LevelBlue. Qilin Ransomware Use of EDR Killer - Qilin ransomware operations have been observed adopting aggressive, kernel-level defense evasion to blind and disable endpoint security products before its main ransomware payload is executed on a victim's network. The EDR killer, packed via the Shanya packer, is sold on illicit marketplaces for $2,000. "The EDR killer compares the returned locale to a known locale blacklist to avoid attacking any Commonwealth of Independent States (CIS) countries such as Russia and Belarus," Flashpoint said. "The EDR killer then writes a vulnerable driver to disk and loads this driver via Service Manager. This driver is the ThrottleStop driver from TechPowerUp LLC's free and legitimate application of the same name, used to bypass CPU throttling. However, the driver suffers from a vulnerability, allowing the malware to map physical memory to kernel-mode virtual memory to perform direct kernel read and write operations." Also put to use is a custom Rust-written loader that performs reflective Portable Executable (PE) loading of the ransomware payload. DefiTuna Suffers a Security Incident - DeFiTuna, an Automated Market Maker (AMM) on the Solana blockchain, was exploited on July 16, 2026, for $569,601 USDC. "The attackers created a highly illiquid TUNA/USDC pool and used it as the destination for borrowed USDC routed through Jupiter," CertiK said. "Because the swap returned only a negligible amount of TUNA, DeFiTuna's value calculation rounded the position's total assets down to zero. The protocol then incorrectly treated the position as healthy, allowing the attackers to bypass the solvency check and withdraw the USDC through attacker-controlled liquidity positions." Next.js Opts for Scheduled Security Releases - Vercel announced that Next.js is adopting a formal security release program, replacing ad-hoc patches for security fixes following a surge in AI-assisted vulnerability discovery. "This kind of scheduled, pre-announced security release has become standard practice for major open source projects, and we think it's the right model for Next.js at its current scale," Vercel said. "Here's what you can expect going forward: roughly once a month, we'll publish advance notice of upcoming security releases. Each announcement will include the expected release timeline and the highest anticipated severity among the vulnerabilities it covers. This lead time lets you plan your upgrades, and it lets us coordinate with hosting providers and other platform partners to deploy mitigations, such as firewall rules, that help protect applications that haven't been patched yet." Disguised Gambling Apps Target Brazil - A new analysis from 9to5Mac has revealed more than 60 "jacket apps" on the App Store that are disguised as simple games and utilities that become online betting platforms when accessed from Brazilian IP addresses. Most of the apps are published by developer accounts with only a single App Store listing, with further investigation linking them to a "public GitHub repository containing instructions for a Cursor agent to create simple, vibe-coded apps that serve as fronts for the betting platforms." Ransomware Stats for Q2 2026 - The Gentlemen has become the most active ransomware group for Q2 2026, claiming 300 victims, surging past Qilin (289), DragonForce, Akira, and LockBit. Another group named Deadlock resurfaced after 11 months of silence with 75 June victims. In all, the top 11 tracked groups accounted for 1,368 of Q2's victim claims across 99 countries. "What sets The Gentlemen apart is its packaging, where affiliates receive ready-made tools that ship and update faster than most competing programs," ReliaQuest said. 2 Members of Chinese Money Laundering Network Charged with Laundering $43M in Investment Fraud - The U.S. Justice Department unsealed charges against a New York man and woman for conspiracy to launder money derived from cyber investment fraud scams. "Between 2020 and 2022, Zhuoying Chen, 27, of Brooklyn, New York, and Haojie Zhang, 38, of Queens, New York, managed a network of more than a dozen individuals based in Queens and Brooklyn, who opened 140 bank accounts in the name of approximately 45 shell companies to launder at least $43 million in proceeds of investment scams," the department said. "Then, Chen and Zhang allegedly conspired with China-based co-conspirators to transfer the funds involved in the fraud schemes abroad. The fraud schemes consist of perpetrators contacting victims via messaging services or social media applications. The perpetrators would initiate relationships with the victims and gain their trust, convincing victims to send money for lucrative investment opportunities. The perpetrators would show the victims fake profits on the purported investment and encourage the victims to invest more. The perpetrators would then steal the victim's funds." U.S. Cyber Agency Uses Mythos to Audit Government Code - Reuters reported that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic's AI model Mythos to audit government software for defects that could potentially offer a pathway for foreign spies and cybercriminals, citing three people familiar with the matter. 🔧 Cybersecurity Tools VisionSec → It is an open-source, self-hosted threat intelligence platform that combines domain monitoring, phishing detection, exposed-service scanning, GitHub secret discovery, breach checks, email security assessments, and Telegram alerts in a modular Docker-based deployment. The project remains at an early stage, with no published releases at the time of writing. owLSM → It is an open-source Linux security agent that uses eBPF LSM to run stateful Sigma rules inside the kernel, block malicious activity, correlate events across multiple probes, and provide detailed context for security monitoring and response. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law. Conclusion That is the week: exposed systems, weak checks, old tools, and attackers moving faster than patch cycles. Review what applies, fix the obvious gaps first, and assume anything public has already been tested.
thehackernews.comJul 20, 2026extracted
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
F5 on Wednesday announced an out-of-band security rollout that patches eight vulnerabilities in NGINX and BIG-IP. The most severe flaw is CVE-2026-42533 (CVSS score of 9.2), a critical issue in NGINX Plus and NGINX Open Source that could be exploited via crafted HTTP requests to cause a heap buffer overflow and restart the NGINX worker process. “A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map’s regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions,” F5 explains. An attacker can exploit the security defect without authentication, but only under conditions they cannot control. On systems with Address Space Layout Randomization (ASLR) disabled, the attacker can achieve code execution. F5’s patches also resolve several high-severity NGINX bugs, including weaknesses in the ngx_http_slice_module module and the ngx_http_ssi_module module that can be exploited without authentication. Successful exploitation of the flaws allows attackers to leak memory contents, restart the NGINX worker process, or cause a use-after-free in the NGINX worker process to modify memory or restart the process. Two high-severity vulnerabilities addressed in NGINX Ingress Controller could allow authenticated attackers to inject arbitrary NGINX configuration directives to delete files and disable services, or create or modify Ingress or TransportServer resources to cause a denial-of-service (DoS) condition. F5 also resolved a high-severity security defect in BIG-IP that could be exploited by remote, unauthenticated attackers to increase memory resource utilization when an HTTP/2 profile is configured on a virtual server, causing a DoS condition. F5 makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found in the company’s out-of-band security notification. Related: Trend Micro, Tanium, ESET, and Tenable Patch Severe Product Vulnerabilities Related: Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell Related: Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
securityweek.comJul 16, 2026extracted
Old UEFI Shims Expose Systems to Secure Boot Bypass
Nearly a dozen Unified Extensible Firmware Interface (UEFI) shim bootloaders signed by Microsoft allow attackers to bypass Secure Boot protections, ESET warns. Small, trusted pieces of software bridge a computer motherboard’s UEFI firmware and the operating system, typically a Linux distribution, enabling the machine to boot with Secure Boot enabled. By using Microsoft-signed UEFI shim bootloaders, Linux distributions can establish a trust model without requiring individual keys to be built into the motherboard’s NVRAM. The shims allow bootloaders, kernels, and other components to run during Secure Boot. While various vulnerabilities have been addressed in the open source shim project over time, not all vendors updated their bootloaders, and these older shims remained signed and trusted within the Secure Boot chain, exposing systems to potential attacks. According to ESET, 11 such old, forgotten UEFI shims, primarily from version 0.9 and earlier, lingered around until revoked by Microsoft on June 2026 Patch Tuesday. Two CVEs were assigned, namely CVE-2026-8863 and CVE-2026-10797. The vulnerable shims, ESET says, could be exploited to “bypass UEFI Secure Boot on any UEFI-based machine that trusts Microsoft’s Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CA) certificate, regardless of the installed operating system (OS).” Coming from various tools and packages, these shims extend the attack surface through their trusted second-stage bootloaders. Additionally, attackers could bring their own vulnerable shims to systems that have enrolled the Microsoft third-party UEFI certificate. “Signing and compilation timestamps of the applications trusted by the shims we reported span from 2013 to 2025 – enough to confirm that a significant portion of these binaries were old and likely affected by numerous publicly known vulnerabilities, [such as] BootHole in the case of GRUB2,” ESET notes. Continuous trust in these old, vulnerable shims allows attackers to execute untrusted code during the boot process and deploy bootkits even if Secure Boot is enabled. ESET reported the findings to CERT/CC in February 2026. In June, Microsoft revoked all vulnerable applications and added them to the UEFI DBX (Forbidden Signature Database). According to CERT/CC, system admins should update the signature database (DB) before applying DBX revocations. “In practice, this means updating trusted boot applications and certificates first, followed by deployment of the revocation list. Failure to follow this order may cause systems to reject newly updated boot components. Enterprises, virtualization providers, and cloud operators managing large-scale deployments should prioritize validation and deployment of these updates to prevent the execution of vulnerable or unsigned binaries during physical or virtual machine startup,” CERT/CC notes. Since 2017, shims have been signed and documented after a vetting process, but those approved before then are not documented, and many old, still-trusted shims may remain, potentially exposing systems to attacks. Related: New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones Related: Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Related: Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities Related: Unpatched Cursor Vulnerability Exposes Users to Code Execution
securityweek.comJul 16, 2026extracted
Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
Cybersecurity companies TrendAI (Trend Micro), ESET, Tenable, and Tanium released product updates this month to patch severe vulnerabilities. Tenable told customers this week that it has fixed a critical-severity path traversal in the Tenable Agent. The security hole, tracked as CVE-2026-15265, may allow an attacker to achieve remote code execution. [ Read: SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits ] ESET informed customers on Tuesday that it has discovered and patched a high-severity local privilege escalation vulnerability in Inspect Connector for Windows. “On systems with the affected ESET product installed, an attacker could send self-crafted Advanced Local Procedure Call (ALPC) requests to the vulnerable process’ interface,” ESET explained in its advisory. “Without proper authentication or origin validation in place, this message would be accepted and processed, enabling the attacker to access restricted functionality.” ESET has also published a separate advisory for a medium-severity DoS vulnerability in its security products for Linux. Tanium informed customers last week about a high-severity DoS flaw affecting Tanium Server. “This vulnerability could allow an unauthenticated, network-based attacker to perform a denial of service attack against the Tanium Server,” the company noted. Trend Micro informed Cleaner One Pro users last week of a medium-severity arbitrary file deletion vulnerability that could “allow a malicious app already running on your device to trick the cleanup process into deleting a file it shouldn’t have access to.” The vendor noted that local access is required for exploitation and the vulnerability cannot be exploited remotely. Palo Alto Networks also released patches this month, addressing over a dozen vulnerabilities in its products. While there is no evidence of exploitation for the latest vulnerabilities, it’s not uncommon for threat actors to target security products in their attacks. For instance, Palo Alto Networks and Trend Micro recently confirmed in-the-wild exploitation. *the information and the link for the Trend Micro vulnerability have been updated; it initially erroneously referenced an older vulnerability. Related: Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Related: Vulnerabilities Patched in CrowdStrike, Tenable Products Related: Trend Micro Patches Critical Apex One Vulnerabilities
securityweek.comJul 16, 2026extracted
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/[email protected] @asyncapi/[email protected] @asyncapi/[email protected] @asyncapi/specs(v6.11.2, v6.11.2-alpha.1) "The compromised packages deploy an obfuscated first-stage payload that downloads an encrypted second-stage payload, identified as Miasma, from IPFS," Socket said. The poisoned packages ship a hidden JavaScript implant, with each of them containing an injected source file that decodes to the same second-stage downloader. Unlike previous iterations that leveraged install hooks to trigger the execution of a JavaScript payload, the malicious code in this case is run when the infected module is loaded by Node.js, after which it launches a detached background node that downloads and executes the malware from IPFS. The next-stage payload is an encrypted JavaScript loader named "sync.js," which is written to operating system-specific paths and executed. The downloader URL is "ipfs[.]io/ipfs/QmQobZSp1wRPrpSEQ56qnyq7ecZh5Bg5k1fnjt4SUwwHb9." The loader contains two components - The encrypted final JavaScript payload, which decodes to the Miasma tasking framework A large encrypted blob used by the runtime's spawn-chain framework The framework bundles 744 modules and is built as a command framework that supports six independent command-and-control (C2) communication channels using HTTP, Nostr relay, IPFS, BitTorrent DHT, libp2p GossipSub P2P mesh, and an Ethereum smart contract. Besides facilitating credential theft, AI tool poisoning, LAN lateral movement, and worm-like propagation on npm, PyPI, and Cargo registries, Miasma features a persistence mechanism of its own, setting up a systemd, crontab, macOS launchd, and Windows Registry autostart keys. "Although the malware has some similarities to the Shai-Hulud and Miasma campaigns, and it contains the Miasma string multiple times inside its code, this malware isn't the same as them, nor is it attributed to the Miasma/Shai-Hulud/TeamPCP campaigns that we've seen in the past," OX Security's Moshe Siman Tov Bustan said. Furthermore, it incorporates a dead man's switch that monitors a stolen token and triggers a directory wipe if the token is revoked, while avoiding systems identified as sandboxes or virtual environments, as well as those that have their current language set to Russian or have security tools from CrowdStrike, SentinelOne, Microsoft Defender, CarbonBlack, Cylance, Osquery, Tanium, and Qualys installed. "Its clearest operational path is REST-based C2: the implant beacons to an HTTP endpoint, accepts encrypted tasking, and posts command results back to the same infrastructure. Around that core, the payload also carries support for upload transport, command ciphering, node signing, payload updates, file management, shell execution, and persistence writing." According to StepSecurity, the attacker is said to have gained push access to the repositories and used the project's own legitimate GitHub Actions release pipeline to publish packages with valid OIDC provenance attestations. The supply chain attack did not involve the theft of an npm token. "Both attacks are CI/CD pipeline compromises, not stolen npm tokens or malicious maintainers," security researcher Rohan Prabhu said. "The attacker pushed commits under a placeholder git identity and let each repository's real release workflow do the publishing via npm's GitHub OIDC trusted-publisher integration." "The resulting packages carry legitimate SLSA provenance attestations, proving only that the project's authorized workflow produced them, not that the triggering commits were legitimate. Provenance does not protect against a compromised push credential." All five malicious versions have since been unpublished from the npm registry. It's advised to treat any endpoint that imported or executed one of the affected package versions as potentially compromised. However, it bears noting that exposure depends on whether the infected module was loaded as part of a build or a developer workflow. "There is no preinstall/postinstall/install script anywhere in any of the three package.json files," StepSecurity said. "This dropper fires when the poisoned module is require()d during normal use of the generator: the moment a build or CI job actually calls into the library, not at npm install time." Update SafeDep has characterized the malware as "either a private, parallel build by the same operators or a separate group that adopted the Miasma brand after the source was published." Microsoft, which is tracking the malicious artifacts under the names MiasmStealer and Supychain, said the campaign executes at module-load time, unlike the more common postinstall-hook supply chain attack pattern. "When any consuming build or application imports a poisoned package, the injected block runs immediately," the tech giant's security research team said. "Because the trigger is an import rather than an install script, the common npm install –ignore-scripts mitigation does not neutralize it." Microsoft also noted that the compromise originated from a pwn request against the "asyncapi/generator" repository stemming from a misconfigured GitHub Actions workflow ("pull_request_target"). "The asyncapi/generator repository contained a workflow file that used pull_request_target to trigger on pull requests, but then checked out the pull request's code rather than the base branch," Wiz researchers Rami McCarthy and Merav Bar said. "This is dangerous because pull_request_target runs in the context of the base repository with full access to secrets. When the workflow checks out attacker-controlled code from the pull request and executes it, those secrets become accessible." The Google-owned security firm said the potential for pwn request had been identified as far back as April 2026, when a researcher named Florence Njeri submitted a proof-of-concept (PoC) payload that exploited the vulnerability. A pull request containing the fix remained open and unmerged when the attack took place on July 14, 2026. While the payload shares some technical characteristics with the Miasma malware framework previously documented in Shai-Hulud supply chain attacks, the activity has not been conclusively tied to a specific threat actor. "The Miasma branding may reflect code reuse, imitation, or deliberate mislabeling," Aikido Security researcher Raphael Silva said. "No definitive attribution is made here." Further analysis has determined that several of the implemented features related to credential harvesting, AI-tool poisoning, dead man's switch, and propagation via npm, PyPI, and Cargo vectors have been toggled off, although Microsoft warned that they "could be enabled through persistence." (The story was updated after publication to include additional insights.)
thehackernews.comJul 15, 2026extracted
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it. In research published July 13, Microsoft mapped the campaigns, which ran from mid-2025 into mid-2026, to three distinct techniques. It also worked with Salesforce to roll out new detection and governance tooling aimed at addressing the activity authentication logs miss. That is what makes this hard to catch. When the access comes from a real user who approved a connected app, or from an integration the company already trusts, the traffic reads as ordinary use, and sign-in and authentication monitoring barely registers it. What matters is what the app or account does once it is in, and that is exactly what most Salesforce logging was not built to show. Microsoft groups the activity into three intrusion paths: vishing calls that trick employees into approving a malicious connected app, stolen OAuth tokens from compromised software vendors, and misconfigured guest access to Salesforce sites. Each maps onto a Salesforce incident from the past year, and Microsoft says it saw the activity across tenants in industries including retail, education, and manufacturing. The phone call The first path is the one that kicked off the whole run. Starting in mid-2025, the actors placed voice-phishing (vishing) calls posing as IT support and talked employees through Salesforce's OAuth consent screen, getting them to authorize an attacker-controlled connected app dressed up as Salesforce's own Data Loader tool. Once consent was granted, the app could make API calls as that user, letting the attackers enumerate the org's Salesforce data, hold persistent access to CRM records, and hunt for credentials that might open the door to other SaaS platforms. No malware, no stolen password replay. Just a phone call and a consent click. This is the campaign Google's Threat Intelligence Group (GTIG) and Mandiant documented in mid-2025, tracking the initial access as UNC6040 and the follow-on extortion as UNC6240, both of which kept claiming to be ShinyHunters to lean harder on victims. Google confirmed one of its own corporate Salesforce instances was hit in June 2025, with the attackers taking largely public business contact data before Google cut them off. The same wave was publicly linked to breaches at Chanel and Pandora, with Adidas, Qantas, Allianz Life, and several LVMH brands also named as targets. Mandiant's advice to defenders was blunt: these calls exploit a help desk's instinct to be helpful, standard identity checks often do not apply, and the safe move is to hang up and call back on a known-good channel. Stolen tokens from trusted vendors The second path skips the employee entirely. Instead of phishing a user, the attackers compromise a third-party vendor whose app already holds OAuth access to its customers' Salesforce orgs, steal the connection secrets or tokens, and use them to query and export data across many downstream instances at once. Because the traffic comes from an approved integration, it does not trigger sign-in alarms and blends into normal automation. Microsoft points to three incidents here. The August 2025 Salesloft Drift compromise is the biggest and the clearest: attackers stole OAuth and refresh tokens tied to the Drift AI chat integration and turned them against Salesforce customer environments. Google estimated that the Drift token theft potentially exposed more than 700 organizations, among them Cloudflare, Zscaler, Palo Alto Networks, Proofpoint, PagerDuty, and Tanium. Google tracks the cluster as UNC6395; Cloudflare's Cloudforce One calls it GRUB1. Salesloft later traced the root cause to the attacker's access to its GitHub account as early as March 2025, which was used to reach Drift's AWS environment and harvest the tokens. The operators were there for secrets, running SOQL queries to sift through support cases and other objects for AWS keys, Snowflake tokens, and passwords, then deleting their query jobs to slow down anyone investigating. The November 2025 Gainsight incident ran the same play against a different vendor. Salesforce pulled Gainsight-published apps after spotting unusual API activity, and GTIG tied the campaign to ShinyHunters affiliates across more than 200 affected Salesforce instances. The people behind the ShinyHunters name claimed the Salesloft and Gainsight waves together reached close to 1,000 organizations, a figure that has not been independently confirmed. The most recent case, from June 2026, is the Klue compromise. Attackers got into the competitive-intelligence platform through a long-disused but still-active legacy credential left over from a test integration that was never deployed, pushed a code update that harvested customers' OAuth tokens, and used those to reach Salesforce and Gong data belonging to Klue customers, including Huntress and Recorded Future. Microsoft tracks the Klue actor as Storm-3138. One naming wrinkle for anyone cross-referencing reports: most of the industry, Huntress and Datadog included, ties the Klue extortion to a group calling itself Icarus, and a Telegram account claiming to be ShinyHunters also took credit. The labels blur because these identities overlap and get claimed opportunistically, which holds across this whole set of campaigns. Guest access left open The third path needs no credentials at all. Microsoft saw a rise in suspicious guest-user activity against Salesforce Aura endpoints, the framework behind Experience Cloud sites. Where guest-user permissions were misconfigured, the actors reached Aura functionality without authenticating. Calling the GraphQL Aura controller, they used cursor-based pagination to pull records past the standard 2,000-record query limit, walking off with far more than the guest role was meant to expose. Microsoft's related detection points to the AuraInspector tooling used to probe these endpoints. No exploit was involved. The org had left the guest role able to see more than it should, and the actors read it for everything it was worth. What Microsoft and Salesforce shipped to catch it The signal that does exist lives in what happens after access: which connected app made a call, what OAuth scopes it holds, how much it is querying, and whether any of that is normal for the tenant. Microsoft worked with Salesforce to surface exactly that in Defender for Cloud Apps. For customers running Salesforce Shield Event Monitoring, the upgraded Salesforce connector onboards the Real-Time Event Monitoring framework for near-real-time detection and adds connected-app attribution, tying activity to a specific app identity and its granted OAuth scopes, along with more session and API context. Alongside detection, Microsoft added posture and governance features for connected OAuth apps: a view of highly privileged apps holding elevated scopes, a way to surface unused apps that have sat inactive for 90 days or more while keeping live permissions, and a 0 to 100 risk score per app that teams can wire to alerts and policies. The aim is to find the over-permissioned and forgotten integrations before someone else does. Shrinking the OAuth attack surface Microsoft's guidance is practical and matches what the vendors said after each incident: connect Salesforce instances to Defender for Cloud Apps for the extra telemetry, turn on and actually watch Salesforce event logs, and lock down Experience Cloud guest-user access. Beyond the product-specific steps, the durable fixes are the familiar ones. Inventory the connected apps, cut the ones nobody uses, scope the rest to least privilege, and be ready to revoke and rotate tokens the moment an integration starts behaving oddly. The pattern under all three paths is the same. The identity controls most companies spent the last decade building were made for human logins: MFA, conditional access, and session policies. The OAuth apps, integration accounts, and service credentials that do the actual work in a modern Salesforce stack mostly sit outside all of it, unwatched and over-permissioned. The attackers who figured this out ran it for a year, and more than once, the way in was nothing more exotic than a credential someone forgot to switch off. The Hacker News has reached out to Microsoft for further details on its attribution of the actors behind these campaigns and will update this story with any response.
thehackernews.comJul 14, 2026extracted
22nd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES - Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. Social Security numbers and payment data were not affected. ShapedPlugin, a WordPress plugin vendor, has faced a supply chain attack that delivered malicious updates for three paid plugins through its official updater. The malware installed a hidden fake WooCommerce plugin to steal admin, database, and 2FA credentials and modify affected websites. Incident analysis tied the compromise to vendor release infrastructure. iRhythm Technologies, a US digital health company focused on remote cardiac monitoring, has experienced a cyberattack involving third-party-hosted business applications. The company confirmed that attackers stole protected health information, proprietary data, and other personal data through a social engineering attack. Clinical systems were not affected. Market intelligence platform Klue has confirmed a breach after attackers used compromised legacy integration credentials to steal OAuth tokens connected to customer Salesforce environments. The tokens enabled theft of sales and customer data from several clients, including Huntress, Recorded Future, Tanium, and Jamf. The Icarus extortion group claimed responsibility. AI THREATS - Researchers have detailed EvilTokens, an AI-powered phishing-as-a-service operation abusing device-code authentication to steal Microsoft 365 tokens. Huntress observed a 1,380% surge in device-code phishing in early 2026, with AI-generated lures and automated workflows lowering attacker effort. Researchers have crafted a fake AI skill that hijacked more than 26,000 AI agents by abusing trusted marketplaces and Instagram ads in a supply chain attack. The package initially appeared clean, then used attacker-controlled external instructions after approval to trigger data exfiltration across agent platforms. LayerX researchers have demonstrated BioShocking AI, a technique that tricks agentic browsers into bypassing their guardrails. Test cases against ChatGPT Atlas, Perplexity Comet, Claude in Chrome, and other AI browsers showed how game-like prompts could expose credentials and user data. VULNERABILITIES AND PATCHES - Cisco has addressed CVE-2026-20245, a high-severity command injection flaw in Catalyst SD-WAN Manager that attackers exploited as a zero-day for months. The flaw allows an administrator to run root commands through a crafted file, affecting on-premises and Cisco-managed cloud deployments. Dify has released version 1.14.2 to fix four vulnerabilities in its open-source AI platform, including critical CVE-2026-41947 and CVE-2026-41948. The flaws could allow unauthenticated access and cross-tenant data exposure, including chat content and uploaded files. Ubiquiti UniFi OS is affected by three flaws, CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, which are reportedly being exploited against network appliances. The vulnerabilities allow unauthorized changes, file access, and command execution, with exploitation observed in Mirai botnet activity. Check Point IPS provides protection against these threats (Ubiquiti UniFi OS Privilege Escalation (CVE-2026-34908), Ubiquiti UniFi OS Directory Traversal (CVE-2026-34909), Ubiquiti UniFi OS Command Injection (CVE-2026-34910)) - Langflow, an open-source AI workflow tool, is reportedly being targeted through exploitation of CVE-2026-55255, alongside ongoing mass exploitation of CVE-2026-33017. Attackers enumerated flow IDs to run victim pipelines and extract embedded API keys, while remote code execution enabled malware deployment and cloud credential theft. Check Point IPS provides protection against this threat (Langflow Remote Code Execution (CVE-2026-33017)) THREAT INTELLIGENCE REPORTS - Researchers have uncovered the FortiBleed campaign, which converts compromised FortiGate firewalls into passive credential stealers across 24 protocols. The operation targeted more than 430,000 devices worldwide and siphoned more than 110 million credentials. Researchers have attributed the StockStay espionage malware to Russia-linked Turla and described targeting of Ukrainian government and defense organizations. The malware evolved from a fake stock app to PDF reader and calculator lookalikes, delivered through phishing with malicious remote desktop configuration files. Researchers have revealed that the Chinese DCloud Uni-App framework powers at least 236,493 scam domains since 2022, including fake crypto exchanges, wallet drainers, WhatsApp phishing, and gambling schemes. Technical fingerprints suggest centralized operators, likely China-based, supporting a broad fraud ecosystem. Researchers have analyzed the FulcrumSec cloud extortion group targeting cloud-native organizations. The group exploits exposed credentials, unpatched applications, and misconfigured storage, then uses broad permissions to move across environments, collect data for months, and exfiltrate it using legitimate tools.
research.checkpoint.comJul 1, 2026extracted
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser tricks jumping the fence, and “normal” workflows turning into phishing pipes because apparently email was not enough hell already. The worst part is how cheap some of it feels. Not elite. Not cinematic. Just stale secrets, fake updates, lazy trust, and random boxes quietly becoming someone else’s infrastructure. Same internet, fresh headache. Let’s get into it. Privacy-first bot defenseCloudflare has teamed up with Google Chrome, Microsoft Edge, and Mozilla Firefox to create a privacy-preserving protocol that websites can use to separate desirable web traffic from undesirable network requests. This involves the use of Private Access Control Tokens (PACT), which allow websites to issue anonymous tokens that assert a given browsing session is being run by a human. "A user's browser can then provide these tokens to other sites to prove that a human is in the loop, reducing the need for annoying and clunky captchas or invasive tracking," Cloudflare said. "PACT is designed so that sites cannot leverage it to track or identify users or their browsing history." Six curl CVEsAISLE said it discovered six vulnerabilities in curl, which range from "classic memory-lifetime issues to logic bugs in how libcurl decides whether a connection, credential, or host identity is still valid." One of the notable vulnerabilities is CVE-2026-8932, which allows the library to "reuse a previously created connection even when some mTLS config-related option had been changed that should have prohibited reuse." AISLE described it as the oldest curl vulnerability reported so far, adding that it has been shipped in releases since curl version 7.7, which was released on March 22, 2001. The identified flaws have been addressed in version 8.21.0. Unauthenticated takeoverA critical security flaw has been disclosed in self-hosted versions of Hoppscotch(CVE-2026-50160, CVSS score: 10.0), an open source API platform, that can result in complete compromise. Offgrid Security's autonomous AI security agent, Kiro, has been credited with discovering the bug. "The POST /v1/onboarding/config endpoint allows an unauthenticated attacker to inject arbitrary InfraConfig keys -- including JWT_SECRET and SESSION_SECRET -- into the database via mass assignment," the project maintainers said. "These keys are not declared in the SaveOnboardingConfigRequest DTO, but because the NestJS ValidationPipe does not strip extra properties, they pass through to the service layer, where Object.entries(dto) iterates all keys without restriction." A successful exploitation leads to full server compromise and persistent access that survives password resets. OffGrid Security told The Hacker News that four independent weaknesses are combined to allow an unauthenticated attacker to overwrite the JWT signing key in a single HTTP request, and the exploit requires no credentials. The issue has been fixed in hoppscotch-backend version 2026.5.0. Proxyware in smart TVsA new report from Spur Intelligence has revealed that more than one-third of LG and Samsung smart TV apps it reviewed contain proxyware that can relay third-party traffic through the TV owner's internet connection with users' consent. The company said it scanned 6,038 apps across LG webOS and Samsung Tizen and found 2,058 that contain residential proxy software. This includes clocks, screensavers, games, fish tanks, and other low-utility apps. On LG webOS, 42.5% of apps carried such code. On Samsung Tizen, the rate was 26.9%. Across both platforms, it reached 34.1%. Bright Data, Massive, and Oxylabs take up the top three SDK providers for webOS and Tizen. "Smart TVs are almost ideal proxy hosts. They sit on the same home network as everything else, but they do not feel like computers, so people rarely audit them like computers," Spur said. "There is no battery drain to notice, no cellular bill to spike, no app switcher full of suspicious background activity. A TV can stay plugged in, signed in, and online for years while the user thinks of it as furniture." The threat intelligence firm said this dynamic also changes the consent equation, as users may not realize what it actually means to sell access to their residential IP address. "Technically, these applications are compliant with gaining consent based on how they inform the user," Spur CTO Alastair Parr told The Hacker News. "However, there is often no verification that the user is either of age or authorized to provide consent on the device. The reality is that there are likely many smart TVs scattered across office spaces and residential homes, quietly part of these networks, without the responsible owners' awareness or consent." Amazon's Device and System Abuse Policy explicitly bars apps that facilitate proxy services for third parties. Similar protections have been enabled by Roku as well. However, LG and Samsung are yet to enforce an equivalent policy. Edgecution via TeamsAn initial access broker (IAB) affiliated with Payouts King ransomware has been observed masquerading as IT personnel in social engineering attacks conducted via Microsoft Teams to deliver a malicious Microsoft Edge browser extension dubbed Edgecution. "The technique utilizes a malicious Microsoft Edge browser extension that exploits the Chrome native messaging protocol to interact with host-native applications beyond the confines of the browser sandbox," Zscaler ThreatLabz said. "By abusing this interface, the attackers gain direct host access, enabling them to manipulate the local filesystem, launch processes, and execute arbitrary code on the compromised host." The malware has two components: a Microsoft Edge browser extension named "Edge Monitoring Agent" that beacons to a command-and-control (C2) server and relays host-based commands to a Python-based backdoor, which can collect system information, enumerate running processes, provide filesystem access, and execute arbitrary Python code and shell commands. The extension will be invisible to a user as it's loaded in a headless Microsoft Edge browser. A similar attack chain involving a Chromium-based extension codenamed SNOWBELT was detailed by Google-owned Mandiant in April 2026. Legacy credential breachCompetitive intelligence company Klue has revealed that a credential dating back to 2022, which was used as part of a limited pilot, was exploited by the Icarus extortionists to steal Salesforce data from its corporate customers, including several cybersecurity companies. In a statement shared with TechCrunch, the company said the credential was "originally provided to a third-party in 2022, for a limited pilot." Klue did not share specifics about the purpose of the pilot, the duration for which it ran, or the identity of the third-party to whom the company gave the credentials. It's also unclear why the credential wasn't revoked immediately, assuming the pilot had concluded. Questions remain about how the attackers managed to acquire this legacy credential in the first place. A number of companies have come forward to confirm they have had limited Salesforce information stolen during the attack, including 8x8, BeyondTrust, Gong, Jamf, HackerOne, Insurity, LastPass, OneTrust, Pendo, Recorded Future, Snyk, Sprout Social, and Tanium. State-crime convergenceNCC Group said it has found growing evidence of nation-state actors increasingly leveraging tools and tactics traditionally associated with financially motivated cybercrime to disguise their espionage and intelligence-gathering operations, blurring the line between the two sets of activities. "Historically, organisations could draw a relatively clear distinction between ransomware attacks driven by financial gain and nation-state operations designed to support strategic objectives. That distinction is becoming increasingly difficult to make," Matt Hull, VP of Cyber Intelligence and Response at NCC Group, said. "What we're seeing is a convergence of criminal and state-backed activity. Threat actors are sharing infrastructure, adopting common tooling and, in some cases, deliberately operating behind established ransomware brands to obscure attribution and delay response efforts." Admin reset alertsGoogle said it's expanding the existing "Super Admin password reset" alert into a broader Admin password reset alert in Alert Center. "Previously, this rule only triggered alerts when a super admin's password was changed," the company said. "With this update, the alert will now cover password resets for all administrator roles within your organization. This update provides admins with better visibility and control over the security of their organization's privileged accounts. Monitoring password changes for all admin roles provides a higher level of oversight to respond more quickly to potential account compromises or unauthorized changes." The change is applicable to all Google Workspace customers. ClickFix targets macOSA new ClickFix campaign has been observed tricking users into copying malicious commands and pasting them to the Terminal app that silently downloads and mounts a malicious DMG file. The disk image file contains a self-signed information stealer that can harvest a user's system password, data from web browsers, wallets, messaging apps, and Keychain, exfiltrate the data, set up LaunchAgent persistence, and tamper with Ledger Live and Trezor Suite installations by replacing legitimate components to hijack cryptocurrency wallet information. The stealer is assessed to belong to the Atomic macOS Stealer (AMOS) lineage, particularly a variant called Odyssey, per Palo Alto Networks Unit 42. The development comes as the cybersecurity company detailed another multi-step ClickFix attack that employs techniques like brandsquatting to deliver a cross-platform trojan with browser-credential stealing, remote shell, live screen streaming, keylogger, file manager, and SSH tunneling capabilities. TfL hackers convictedThalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, have been convicted in the U.K. for orchestrating a cyber attack on Transport for London (TfL) in 2024, costing $38.2 million in losses. The two defendants, who were members of the online criminal collective known as Scattered Spider, were arrested last September but pleaded not guilty to their crimes during a court appearance in November 2025. They are now scheduled for sentencing on July 16, 2026. "Scattered Spider is a prolific criminal group that engages in data extortion and other criminal activities, utilizing social engineering techniques and SIM swap attacks, to obtain credentials, install remote access tools, and/or bypass multi-factor authentication," the U.S. Federal Bureau of Investigation (FBI) said. Marketplace admin extraditedAbdellah Belmili (aka Dila Belmili or SPOX), a 26-year-old Algerian national, has been arrested, charged, and extradited from Spain to the U.S. on charges of conspiracy to commit bank fraud. SPOX is alleged to have acted as an administrator for a cybercrime marketplace ("www.market0day[.]com") as well as created phishing kits that have been used to compromise major U.S. financial institutions. "Between September and November 2020, Belmili advertised the marketplace and facilitated some of the customer support for the marketplace on his personal Telegram channel @SpoxCoder," the U.S. Justice Department said. "In late December 2020, after several customers complained that they had not received their purchases from www.market0day[.]com, Belmili replied that he was no longer the administrator, and instead had opened up a new marketplace – www.spoxy[.]us, advertising the new marketplace – www.spoxy.us, advertising the new marketplace as a 'new store for bulk SMS.' 'Bulk SMS' typically refers to sending phishing or other fraudulent messages via text message." Approximately 5,600 U.S. and international victims have been identified. Collaboration phishingA new phishing campaign is abusing Outlook Groups and Microsoft 365 collaboration features to "make malicious activity appear routine," Fortra said. The attack involves adding targets to an attacker-controlled Microsoft 365 group and then using the group mailbox, shared files, or fake calendar invites (aka CalPhishing) to facilitate credential theft, token capture, or malware delivery. "The technique shifts malicious intent away from a single phishing email into a trusted productivity workflow," the company said. "A user may see what looks like a normal group addition, internal update, shared resource, or calendar item before being pushed toward an action." AI in cybercrimeA new analysis from Sophos has revealed that AI has emerged as a hot button topic in underground communities, as threat actors debate its potential for malware and tool development, while some express concerns about the technology reducing work opportunities. This includes posts selling API keys for generative AI tools, advertising solutions that can enhance social engineering, AI-enabled malware (e.g., ApexAI, Metatron, and PolyEngine), discussing jailbreaks for public AI models to bypass censorship and other safeguards using techniques like role-play framing, multi-stage prompting, and contextual manipulation, and offers to hire or partner with prompt engineers. Threat actors have also discussed the use of public AI assistants for intrusion activity, as well as marketed a tool called Leak Bazaar that claims to use AI to triage and sift through mountains of stolen data before it can be packaged and exchanged with other threat actors. Not all have embraced AI with open arms, however, with some outlining skepticism and worries about how the rise of AI could "reshape roles, pricing, and competitive advantage within the cybercrime economy." 8,500 REDCap instancesCensys has uncovered just over 8,500 REDCap instances globally as of June 16, 2026, with most of them located in the U.S., the U.K., Germany, and Australia. REDCap, short for Research Electronic Data Capture, is a web application used by research institutions globally to hold clinical trial data, participant records, and other sensitive research information. Last week, Google Threat Intelligence Group (GTIG) attributed a year-plus espionage campaign against North American academic, medical, and military research institutions to UNC6508, a China-nexus actor. The intrusion set leveraged internet-facing REDCap servers as an initial access vector to deploy a backdoor called INFINITERED to exfiltrate sensitive data. Exactly how these servers are hacked is unconfirmed. The earliest known compromise dates to September 2023. Surveillance export gapsA report from Human Rights Watch has revealed that a Bulgaria-based surveillance technology firm named Circles sold its tools to countries that were likely to use them for repression or to commit serious human rights violations. Documents describe licenses for exports of Circles' technology to Azerbaijan, Bahrain, Brazil, Dominican Republic, El Salvador, Ghana, Guatemala, Israel, Jordan, Malaysia, Mexico, Morocco, Panama, Serbia, and the U.A.E. Clients included intelligence services, military and police bodies, regional governments, and private companies, Human Rights Watch said. That said, it's currently not known whether the technology was actually exported. "Nonetheless, issuing the licenses demonstrates a major flaw in how individual governments implement E.U. export controls for surveillance technology," the non-profit said. "The controls are intended to limit exports of surveillance technology to destinations where there is a likelihood it could be used to violate rights, and to provide transparency about what exports take place." BitB malware luresA campaign that impersonates popular software brand names has leveraged the Browser-in-the-Browser (BitB) technique to distribute malicious payloads by means of a reusable phishing kit. It makes use of a draggable pop-up with a spoofed URL to serve a fake software update warning. "The campaign uses social engineering to trick victims into downloading and manually executing a malicious installer (e.g., an .exe payload)," Unit 42 said. "The pages simulate a stalled document load and present an 'out of date' software error." Earlier this month, Unit 42 disclosed details of a second BitB campaign involving at least 10 unique domains that was used to steal Microsoft 365 credentials using a draggable, OS/browser-fingerprinted pop-up with a spoofed OAuth URL. In this attack, victims who click a Microsoft sign-in button are presented with what appears to be a standard login page designed to harvest credentials. If there’s a theme here, it’s that attackers do not need magic when the boring crap still works — forgotten creds, lazy trust, fake updates, loose admin paths, and users getting nudged into doing the dangerous part themselves. The future is here, somehow, and it still smells like a misconfigured staging box. Patch what you can. Revoke what you forgot. Maybe glance at the devices you’ve been treating like furniture. See you next ThreatsDay, assuming the internet hasn’t found an even dumber way to catch fire by then.
thehackernews.comJun 25, 2026extracted
BeyondTrust, LastPass Impacted by Klue-Salesforce Incident
LastPass is the latest cybersecurity firm to have disclosed the impact from the Klue hack, which resulted in unauthorized access to customers’ Salesforce instances. A threat actor calling itself Icarus used a compromised legacy credential to access Klue’s systems and generate OAuth tokens to breach third-party platforms Klue integrates with, such as Salesforce. Icarus then accessed the connected Salesforce instances and exfiltrated data in bulk, using automated scripts. Salesforce and Gong have disabled the Klue integration in response to the attack, and over a dozen organizations have already confirmed the impact. Incident notifications from the affected companies reveal that the attackers accessed business data accessible through the Klue integration, and that no internal systems were compromised. LastPass’s notice follows the same lines: “The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.” The company says it has discontinued access to Klue, rotated exposed tokens, notified law enforcement, and launched an investigation together with Klue and Salesforce. “It is important to note that the scope of this incident is limited to only those systems that integrate with Klue’s application. LastPass products, services, and infrastructure were not impacted in any way, and customer vaults remain secure. There is also no evidence the threat actor accessed any Gong-related data,” LastPass said. This week, in addition to LastPass, 8×8 and Pendo announced they were affected. Late last week, HackerOne, Huntress, Insurity, Jamf, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium disclosed the impact from the attack. BeyondTrust also said business contact and sales-related information was stolen from its Salesforce instance, but the notification went unnoticed. On its Tor-based leak site, Icarus has listed several organizations as having their Salesforce data stolen, including Swiss AI communications solutions provider Gms-net. SecurityWeek has emailed the technology company for a statement and will update this article if it responds. Icarus’s website is currently down but, before becoming inaccessible, it listed at least four other companies that have yet to publicly disclose being affected by the Klue incident, which brings the number of victims to roughly 15. Per Huntress’s estimates, however, numerous other Klue customers were likely impacted by the data breach and are expected to come forward. Related: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack Related: OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery Related: Russian Initial Access Broker Behind FortiBleed Campaign Related: Canadian Electricity Provider London Hydro Discloses Data Breach
securityweek.comJun 24, 2026extracted
LastPass customer data exposed through Klue supply chain attack
LastPass customer data exposed through Klue supply chain attack LastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools across organizations, to access customer data stored in its Salesforce environment. “On June 12th LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams which integrates with our Salesforce and Gong systems,“ LastPass said. “We immediately launched an investigation and learned that, as part of this incident, an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass.“ The company said the incident was limited to systems integrated with Klue’s platform and did not affect its products, services, infrastructure, or customer vaults. According to LastPass, the exposed data included standard business contact information and CRM records, including customer names, phone numbers, email addresses, physical addresses, support case information, and sales-related records. LastPass warned that the exposed contact details could be used in phishing or social engineering attacks and urged customers to be wary of unsolicited emails, phone calls, or requests for sensitive information, adding that it will never ask users for their master passwords. After discovering the breach, LastPass revoked employee access to Klue, rotated the exposed API tokens, and launched an investigation with Klue and Salesforce. The company also notified law enforcement and released indicators of compromise, including IP addresses and email sender domains. LastPass previously suffered a major breach in 2022, when attackers stole customer password vault backups. Three years later, researchers at TRM Labs linked cryptocurrency thefts to credentials recovered from some of the stolen vaults, with on-chain evidence pointing to possible Russian-speaking threat actor involvement. Klue breach triggers security vendor disclosures Last week, cybersecurity vendor Huntress acknowledged that it was among multiple companies affected by a breach originating at Klue. Huntress published a detailed account of the incident on June 18, describing it as a “security domino effect” that began with a compromised integration credential and led to the theft of customer data from several connected platforms, including Salesforce. Several other security vendors, including Recorded Future, Tanium, and Jamf, have also disclosed their involvement and published statements detailing how they were affected. An extortion group known as “Icarus,” active since late April 2026, claimed responsibility for the attack on its data leak site. “Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted,” Klue CEO Jason Smith noted. “We recognize that customers rely on Klue to securely connect to their systems, and we understand the seriousness of that responsibility.” “Since identifying the incident, we have been communicating directly with affected customers, sharing investigative findings and supporting their response efforts. Specific remediation guidance has been shared directly with affected customers,” Smith concluded. According to Klue, the incident was traced to a credential created for a limited pilot project in 2022 that was later used by attackers to access customer data. “The threat actor will likely continue to post the data of the companies that it compromised from the Klue breach. Icarus will also likely continue to put pressure on impacted organizations to pay a ransom in exchange for not releasing their data,” Huntress stated. Klue did not say whether it had been in contact with the hackers or planned to negotiate with them.
helpnetsecurity.comJun 24, 2026extracted
LastPass, nuovo data breach: esposti nomi, email, numeri di telefono e indirizzi fisici
L’attacco non avrebbe colpito direttamente l’infrastruttura del password manager, ma un partner tecnologico, la società Klue. Esposti nomi, email, numeri di telefono, indirizzi fisici e dati legati ai casi di supporto. LastPass vittima di nuova violazione di dati. Il produttore del password manager ha comunicato che informazioni personali e record relativi ai casi di assistenza clienti sono stati rubati durante un recente attacco informatico a uno dei suoi partner tecnologici. Secondo un’email inviata a un cliente colpito e condivisa con TechCrunch, la violazione è avvenuta presso Klue, società di market research, e non nei sistemi interni di LastPass. Gli hacker, però, avrebbero sfruttato l’accesso ottenuto per sottrarre una grande quantità di dati relativi ai clienti LastPass. La società è l’ultima di una lista crescente di aziende di cybersecurity coinvolte nel breach di Klue, reso noto la scorsa settimana. Tra le altre realtà colpite figurano HackerOne, Recorded Future e Tanium. I dati rubati In un post pubblicato sul proprio blog, LastPass ha spiegato che i criminal hacker hanno sottratto nomi, numeri di telefono, indirizzi email e indirizzi fisici dei clienti. Sono stati inoltre compromessi dati relativi ai casi di assistenza clienti e informazioni legate alle attività commerciali e di vendita. LastPass ha precisato che la propria infrastruttura non è stata colpita. Secondo l’azienda, anche i password vault dei clienti non risultano coinvolti nell’incidente. Il nodo dei ticket di assistenza Resta però da chiarire il contenuto effettivo dei ticket di supporto sottratti. Questi dati possono contenere frammenti di informazioni private o sensibili, perché i clienti contattano di solito l’assistenza per problemi di fatturazione, accesso agli account o gestione dei servizi. In precedenti incidenti che hanno coinvolto ticket di assistenza clienti, tra i dati esposti sono comparsi anche credenziali e documenti d’identità rilasciati da autorità pubbliche. Al momento non è noto quanti clienti LastPass siano stati coinvolti. I portavoce della società non hanno risposto immediatamente alle richieste di commento di TechCrunch, incluse le domande sul numero degli utenti interessati. LastPass dichiara sul proprio sito di avere oltre 33 milioni di utenti e circa 1,6 milioni di clienti paganti al 2024. Il precedente del 2022 Il nuovo incidente arriva dopo il grave data breach subito da LastPass nel 2022. In quell’occasione, gli hacker riuscirono a sottrarre l’intero archivio dei password vault dei clienti, utilizzati per conservare credenziali sensibili come password, token, dati personali e numeri di carte di credito. I vault erano cifrati con master password conosciute solo dai clienti. Tuttavia, la violazione permise agli aggressori di tentare attacchi brute force offline sui vault protetti da master password deboli, con la possibilità di accedere ai segreti contenuti al loro interno. Diversi furti di criptovalute furono successivamente collegati al breach di LastPass, dopo il sospetto che gli hacker avessero sottratto chiavi di wallet craccando i vault delle vittime. L’attacco a Klue e il gruppo Icarus Il CEO di Klue, Jason Smith, ha dichiarato in un post che l’azienda ha identificato la presenza degli hacker nei propri sistemi il 12 giugno. A rivendicare l’attacco è stato Icarus, un gruppo specializzato in hacking ed estorsione, che ha minacciato pubblicamente di diffondere i dati rubati se non verrà pagato un riscatto.
cybersecitalia.itJun 24, 2026extracted
LastPass confirms data breach in Klue supply chain attack
LastPass announced that hackers accessed support cases containing customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month. The password management platform says its products, services, and infrastructure were not affected by the incident and that customer vaults remained secure. “On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams, which integrates with our Salesforce and Gong systems,” LastPass says. "We immediately launched an investigation and learned that, as part of this incident, an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass.” “The threat actor then used these credentials to access LastPass customer data within our Salesforce environment.” The investigation into the incident did not reveal any evidence that the attacker accessed Gong-related data, which typically includes customer calls and emails. According to LastPass, the following data may have been exposed: Customer names Phone numbers Email addresses Physical addresses Support case information Sales/CRM-related data Attackers may leverage the above information in phishing and social engineering attacks. The general recommendation for users is to be cautious of unsolicited communications over the phone or email, especially those that request sensitive details. The master password should not be shared with anyone. The Klue supply chain attack was claimed by the Icarus extortion group, who compromised the infrastructure of the AI-powered market intelligence platform and stole OAuth tokens that connected customers' Salesforce environments. Icarus hackers gained access to Klue's infrastructure using compromised legacy credentials for an integration service. This gave them access to OAuth tokens that connected Klue to various third-party services. The incident impacted multiple organizations, including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. The threat actor exfiltrated Customer Relationship Management (CRM) data and launched an extortion campaign. LastPass has disabled employee access to Klue, rotated the exposed API/OAuth tokens, and notified law enforcement while the investigation is underway. The company also warned about the threat actors using the sender domains baccarat.com[.]au, robinskitchen.com[.]au, house[.]com.au, noting that only communications from the official support channels should be trusted. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 23, 2026extracted
Klue Breach Enables Hackers to Compromise Cybersecurity Firms via OAuth Tokens
Several companies have disclosed that they were affected by a breach of business intelligence provider Klue, including a number of cybersecurity firms. Huntress, Recorded Future, Jamf and Tanium have all acknowledged using Klue’s intelligence services and confirmed that the breach enabled unauthorized access to their Salesforce accounts via stolen OAuth tokens used for Klue integrations. Klue Battlecards Breach and Salesforce OAuth Token Abuse According to an official statement published by Klue’s CEO, Jason Smith, on June 19, the company detected an intrusion on June 12. An unauthorized actor gained access to Klue’s integration infrastructure, notably the Klue Battlecards app, through a compromised legacy credential. They used this access to obtain OAuth tokens - a secure digital key that allows an application to access a firm’s data on another service without needing a password – and connect Klue to third-party platforms, including Salesforce. They then accessed Klue customer data and leveraged the stolen OAuth tokens to impersonate Klue within those connected Salesforce environments, exfiltrating sensitive customer information before the activity was detected and contained. Klue’s Smith said the company immediately responded by revoking affected credentials and tokens, removing unauthorized code and disabling potentially impacted integrations. Klue also notified law enforcement and launched an internal investigation and comprehensive review of its security controls. It has now engaged CrowdStrike to support with forensics. Customers have been regularly updated about what happened and provided with remediation guidance through various channels. Salesforce also notified the public on June 17 it has disabled Klue Battlecards integration. Klue Breach Affects Cybersecurity Firms In customer-facing blog posts, Huntress, Recorded Future, Jamf and Tanium confirmed that while the breach originated through Klue’s infrastructure, their own products and services remained unaffected. Tanium reassured customers that "there was no impact on our ability to serve them." Meanwhile Jamf stated, "We have no evidence of lateral movement and have contained the incident on our end." However, Huntress warned that customer data may have been compromised, including business names, products trialed/used, subscription details, business contact information and marketing and sales communications. Jamf also warned customers about potential phishing campaigns leveraging the stolen Salesforce data, advising vigilance against malicious actors posing as Jamf employees. Recorded Future disabled Klue’s integration and conducted a forensic analysis, emphasizing the need for continuous monitoring of third-party integrations. The company said, "This incident underscores the critical need for continuous monitoring of third-party integrations, especially those with privileged access to sensitive data." ReliaQuest was the first to detect the suspicious and alerted Klue. However, the company told Infosecurity that it does not use Klue and was not affected by the breach. Commenting on how the attackers exploited OAuth tokens to pivot into connected Salesforce environments, the firm said: "The adversary’s ability to move laterally from a compromised integration to a customer’s CRM demonstrates the evolving tactics of modern threat actors.” Non-cybersecurity firms were also affected, including insurance service provider Insurity and social media analytics platform Sprout Social. The breach was claimed on June 19 by Icarus, a recently identified cyber extortion group. Icarus has just three victims listed on its data leak site, according to ransomware tracking website Ransomware.live. On June 20, the group issued a deadline message to all Klue clients it claims to have contacted, warning that they have until June 22 to respond before their data is released. This article was updated on June 22 to add ReliaQuest's comments, highlighting the company has not been affected by the Klue breach.
infosecurity-magazine.comJun 22, 2026extracted
More Cybersecurity Firms Disclose Impact From Klue Hack
At least nine organizations have publicly acknowledged the impact of the supply chain attack on market intelligence platform Klue. The incident occurred on June 11-12 and affected Klue’s integration with Salesforce, resulting in data being exfiltrated from the Salesforce instances of multiple Klue customers, including several cybersecurity firms. On Friday, Klue confirmed previous security reports that the attackers used compromised legacy credentials to access its systems and compromise Salesforce integrations. “The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments,” Klue said. The company revoked the affected credentials and tokens, disabled the integrations across multiple services, and has been investigating the attack together with CrowdStrike and law enforcement. “Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted,” the company said. To date, at least nine Klue customers have disclosed impact from the incident, including cybersecurity firms HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. Insurity and Sprout Social also notified their customers of the incident. All the affected companies pointed out that the intrusion was limited to the Salesforce instances and did not involve their systems, as Klue said in its incident notice. Across the board, the hackers stole business information from the affected organizations’ Salesforce CRMs, including sales account data and business contact information, such as names, email addresses, job titles, phone numbers, and business addresses. Salesforce disabled the Klue integration in the wake of the incident, and revenue intelligence platform Gong did the same on Friday, warning that the hackers exploited its Klue integration to access internal licensed user data. “We can confirm no direct impact on call recordings or customer transcripts. Examples of data accessed included user names, user business titles, and user emails,” Gong said. In its analysis of the incident, Huntress suggested that a threat actor named Icarus might have been responsible for the attack. Since then, Icarus has added Klue to its Tor-based leak site, claiming responsibility for the attack and threatening to publish the information stolen from Klue customers’ Salesforce instances. Per the threat actor’s posts, the data would be released on June 22, unless Klue and the affected organizations engage in negotiations. Related: Cybersecurity Firms Impacted by Klue Supply Chain Attack Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems Related: Laravel-Lang Packages Poisoned for Malware Delivery
securityweek.comJun 22, 2026extracted
AIに「パッチを当てろ」と命じる時代へ Taniumが描く“自律型IT”の正体
����AI�̈��p���i�ޒ��A�h�䑤�̉^�p���f�����]���_���}���Ă���B���������ω��܂��āA�^�j�E���̓C�x���g�uConverge Tokyo 2026�v�ŁA�����I��IT�^�p��ڎw���V�\�z��AI��Ղ\�����BNEC�̎���ƂƂ��ɁAAI�����IT���Y�Ǘ��̊�����T��B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@�^�j�E����2026�N6��12���A��ÃC�x���g�uConverge Tokyo 2026�v��ANA�C���^�[�R����l���^���z�e�������ŊJ�Â����B��u���ł̓Z�L�����e�B�^�p����������V���Ȏ����^OS�Ƃ��āuTanium Atlas�v�\�������A���E26����̃G���h�|�C���g�̈ꌳ�Ǘ�����������NEC�ɂ�铱������Љ���������B���̗l�q�����|�[�g���悤�B �@�^�j�E���́A�G���h�|�C���g�Ǘ��ƃZ�L�����e�B�^�p�̉����E��������A���^�C���Ŏ�������uTanium�v�v���b�g�t�H�[������Ă���BTanium�v���b�g�t�H�[���͓Ǝ��̍������U�A�[�L�e�N��������݂Ƃ��A��K�͊���IT���Y�Ǘ���p�b��K�p�̌��������x�����Ă����B �@��u���ɓo�d�����A�^�j�E���̌��c�p�T���i��\���s���В��j�͍���̃C�x���g�̃e�[�}���u�]���_�v���Əq�ׂ��B �@�U�����͐���AI�����p���A�����ԂŐƎ�i�������Ⴍ�j����������A�U���v���O�������J�������肵�Ă���B����ŁA�h�䑤�͒P��̐Ǝ㐫�̑Ώ���3���ȏォ�����Ă���P�[�X������A�U�����Ɩh�䑤�̊i���͊J�����肾�B �@���������܂����AI�����p�����h��̐��ւ̓]���͋}���ƂȂ��Ă���B������x�����邽�߁A�^�j�E���͐V���ȃr�W�����Ƃ��āu�����I��IT�v�iAutonomous IT�j���f���Ă���B �@Autonomous IT�Ƃ́A���A���^�C���ȃG���h�|�C���g�f�[�^����ՂɁAAI���[���̏�Ԃ�X�N���x����]�����A�D��x�̍����[�������A�p�b��K�p�̐����m����\�����A�K�v�ɉ����Ď����C���܂Ŏ��{���郋�[�v�^��IT�^�p���f�����B���\����Tanium Atlas�́AAutonomous IT�\�z����̉����钆�j���i�Ɉʒu�t������B �@��̓I�ɂ́ATanium�v���b�g�t�H�[���͐Ǝ㐫�̉e������[���₻�̐������A���^�C���Ŗԗ��I�ɔc�����A��ĂɃp�b���K�p���Ă��̓��̂����Ɋ����m�F�ł���B���ꂾ���łȂ����X�N�̍����[�������A�p�b��K�p���������Z�o���A�����C�����J�n����B �@���\���ꂽTanium Atlas�́A���A���^�C���Ŏ��W�����G���h�|�C���g�̏�����ՂɓW�J�����uAI�t�@�[�X�g�v�̓����R���\�[�����B�C���^�t�F�[�X�̓���b�g�Θb���̃R���\�[���ŁA���[�U�[�������A�N�V�����̎��s�𓊂�������ƁA���A���^�C���f�[�^����荞��Ń��[�U�[�̈Ӑ}�𗝉����A�����ƍs���Ɍ������u�ő��̃p�X�v�����B �@�����I�Ȃ̂́A����I�ɌJ��Ԃ����ʂ̃^�X�N�I�ɍ쐬���A������u�y�[�W�v�Ƃ��ĕۑ��E�ė��p�ł���_���BServiceNow��Microsoft������O����AI�G�[�W�F���g�Ƃ̘A�g���ł��A���G�ȃ^�X�N�̏������X�s�[�h�A�b�v�����A�g���u����P�b�g�̑ؗ��Ȃǂ�h����B �@���̑��A���s�\��̃A�N�V�����̉e���͈͂�]������u���X�N�x�[�X�E�J���L�����[�V�����v�@�\������B�^�X�N�̏d�v����X�N��AI���������A���X�N�������^�X�N�����s����Ƃ��́A�����̒��ɐl�Ԃ̏��F�����߂�Ƃ������̂��B�������ɂ�������Nj����A�K�o�i���X����S���̊ϓ_����K�X�A�^�X�N�����Ƀq���[�}���E�C���E�U�E���[�v��g�ݍ��ނƂ����ŋ߂̐���AI���p�̃g�����h�ɂ̂��Ƃ����@�\�A�b�v�f�[�g���B �@����̓G���h�|�C���g���瓾����f�[�^�����p���A����̑���Ɋւ��郊�X�N����̓x�������u�X�R�A���v���ă��[�U�[�ɒ���R���t�B�f���X�X�R�A�@�\����������v�悾�B�Ⴆ�uWindows�v�̃p�b��K�p��T�[�h�p�[�e�B�[���A�v���P�[�V�����̓W�J�A�|���V�[�̓K�p�Ƃ���������̃A�N�V�������s���A���ꂪ�S�̂łǂ̒��x�����������A���邢�͂��̑��삪�ǂꂭ�炢�댯��X�N�������X�R�A�����Ė�������B �@IT�S���҂͂���܂ŁA����̃p�b������S���ǂ����f���邽�߁A�uReddit�v�Ȃǂ̌f����SNS�����Ď�|�����T���A�����ɗ����Ă����B�����������������f�ޗ��i�����ł���A�Ǘ��҂�SNS��f�������ď����W���镉�S���y���ł���\��������B �@Tanium Atlas�͂����̖ڋʋ@�\�ɉ����āAOT�^IoT��o�C���f�o�C�X�AAI���[�N���[�h�Ȃǂ��܂ފǗ��Ώۃf�o�C�X�̑啝�Ȋg���A�V���h�[IT��A�O���[�o���ł̃����e�i���X�E�B���h�E�̓����A�w���v�f�X�N�Ɩ����x������uJump Gate�v�ȂǁA�����̋@�\�����Ƃ����B �@�܂��A����u���ł́ANEC�̕���^�ꎁ�iCorporate Executive CISO �� NEC�Z�L�����e�B ������j�����Ђɂ�����^�j�E�������̏\�����B �@NEC�͐Ǝ㐫�̐��m�Ȕc����AIT���Y�Ǘ��̓O��A�p�b��K�p�Ȃǂ̌���̍�ƕ��y����ړI�ɁA���ЃO���[�v���E26����̒[�����ꌳ�Ǘ�����Tanium�������B�����̌��ʁA�S�Ђ�PC�̏�Ԃ�Ǝ㐫��5���Ŕc���ł���悤�ɂȂ������A�p�b��z�M�ɂ����鎞�Ԃ�Z�k�A����S���҂̍�ƕ��S��15����1�ȉ��ɂ���Ƃ��������ʂ��Ƃ����B �@���㎁�̓t�����e�B�AAI����̖h�䑤��4�̉ۑ�Ƃ��āA�u���Y�Ǘ��̖��O��Ɨ��x�̑e���v�u�Ǝ㐫�C���̃��\�[�X�s���v�u�]���^�h��̗L�����ቺ�v�u�ӎv����̒x���v��������B �@�T�C�o�[�U���҂�AI�����p���鍡�AIT���Y�Ǘ��ł̓\�t�g�E�F�A���i�\�iSBOM�j�����p�������W���[���P�ʂ̓��肪�K�v���B�܂��A�Ǝ㐫�C�����P���ȃ}���p���[�s���ł͂Ȃ��A�\�����[�V�����ɂ������������߂���B����܂œ������Ă����{���ΓI�Ɏキ�Ȃ钆�A����܂Ōo���������Ƃ̂Ȃ��ӎv���肪���߂��邾�낤�B �@���㎁�́u��������e�i���X��Ǝ㐫��͏d�v�����A�ً}�̑Ή����K�v�Ȗ�肪��������\��������B���Ȃ킿�A�o�c�w���܂ߑg�D���r�W�l�X�A���[�ɃT�[�r�X���~���锻�f������O�Ɍ��߂Ă������Ƃ��d�v���B�r�W�l�X�A���[�ł����Ă������e�i���X�̂��߂Ɏ~�߂�̂ł���ΊǗ����ꂽ�_�E���^�C�����v�Ǝw�E����B �@����܂ł̊�{�I�ȃZ�L�����e�B��͍�����L�������A���㎁�͑傫���ς��_�Ƃ��āu���x�v�Ɓu�K�́v��������BAI�ɂ��U���͔����R�ꂪ�Ȃ��u�������Ă���Ȃ��v�Ƃ��A�o�c�哱�ʼn��L��4�_��i�߂�K�v������Əq�ׂ��B �@�ł́ANEC��AI����ɂǂ̂悤�ȃZ�L�����e�B�̎��g�݂�i�߂Ă���̂��B���Ђ́A���Ђ��ŏ��̌ڋq�Ƃ���u�N���C�A���g�[���v�Ƃ����R���Z�v�g���f���A�Г��Ŏ��s������J��Ԃ��Ȃ���ŐV�̑�����H���A�����œ����m�E�n�E����ʂ��Љ��ڋq�ɊҌ�����Ƃ����A�v���[����̗p���Ă���B �@�Ⴆ�A���Ђ̃T�[�r�X�u�T�C�o�[�U�����[�g�f�f�v���Г��V�X�e���ɓK�p���A�U���o�H�肵�A�D��I�Ɏ��ׂ�IT�V�X�e������肵�Ă��鑼�A�uTanium SBOM�v���g�������x�ׂ̍������Y�Ǘ��ɂ��Z�p���̉����ACVSS�i���ʐƎ㐫�]���V�X�e���j�����łȂ��G�N�X�v���C�g�̌��J�ȂǁA�����I�ȗv����g�ݍ��킹���Ǝ��̃��[�e�B���O�ɂ��p�b��K�p�̗D�揇�ʕt���ɂ��A�v���Z�X�����X�N�x�[�X�����Ă���B �@������C�O���_���܂�NEC�S�̂ɓK�p���A�c�[���ꂷ�邱�Ƃŏ̔c�����X�s�[�h�A�b�v�����B����ɂ��A���ЂŎZ�o���Ă���Z�L�����e�B�X�R�A��5�N��100�_�ȏ�㏸�A�v���X�N�N���[�Y����2��6000���ɒB���A���X�N�Ώ����x��2.3�{�ƂȂ����B���㎁�́u���K�͂̓��Ǝ�Ȃ�g�b�v2�����炢�ɓ���v�ƕ]������B �@���㎁�̓��X�N�x�[�X�̐Ǝ㐫�Ǘ��̈Ӌ`�ɂ��āu�����{�������f���t���ɂ�������ł́A��Â�����������邽�߂ɁA���̂悤�Ȋϓ_�ł̑d�v�ɂȂ�B�������Ȃ����͎̂��Ȃ����߁A�܂��͎��Y�Ǘ��̓O���i�߂Ăق����v�Ƙb���B �@���㎁�͍u���̍Ō�ɁA�u����ꂪ�Λ����ׂ��͖��m�̋��Ђł͂Ȃ��A���������ꂽ�����̉ۑ肾�v�Ƃ܂Ƃ߂�B���̖h��V�X�e���̗��x�����߁A�X�s�[�h�ƋK�͂������Ɉ����グ�邩���|�C���g�ƂȂ�B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpJun 21, 2026extracted
Klue OAuth breach victim list grows as Icarus hackers claim attack
Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack. The disclosure comes after cybersecurity firms Huntress and ReliaQuest detailed how attackers abused compromised Klue Battlecards integrations to steal Salesforce CRM data from multiple organizations. In a statement published this week, Klue CEO Jason Smith confirmed that the company discovered unauthorized activity on June 12 affecting part of Klue's integration infrastructure. "On June 12, we identified unauthorized activity affecting a portion of Klue's integration infrastructure. Since then, we've been working alongside trusted cybersecurity experts to understand what happened, support our customers, and restore the connections you rely on," wrote Smith. "Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments." The company says there is currently no evidence that customer content stored directly within the Klue platform was impacted and that the incident was limited to third-party integrations. Klue says it immediately revoked affected credentials and tokens, removed unauthorized code, disabled impacted integrations, launched an investigation, and notified law enforcement. The company also confirmed it engaged CrowdStrike to assist with the response. ReliaQuest and Huntress found that the attackers used stolen OAuth credentials associated with Klue integrations to access customer Salesforce environments and conduct large-scale data theft. ReliaQuest observed attackers generating OAuth tokens and using Python scripts to query Salesforce's API for extended periods, as data was stolen. Huntress later disclosed that its own Salesforce environment was affected by the Klue breach and that the stolen data included business contacts, sales communications, pricing information, and other records. Icarus claims responsibility While BleepingComputer and Huntress previously linked the incident to the Icarus extortion operation, the threat actors have now publicly claimed responsibility on their data leak site. "As you've probably already heard, Klue.com has been impacted by us recently. A number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated," reads the Icarus post. The threat actors went on to pressure Klue and affected organizations to contact them through the Session messaging platform to prevent the leaking of stolen data. The post comes after BleepingComputer previously reported that the attacks were linked to Icarus, after sources shared extortion emails sent to affected organizations. Huntress also independently connected the operation to Icarus through Session Messenger IDs used in the extortion emails and the group's data leak site. Since then, additional victims have disclosed that they were affected by the attacks, including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. Almost all say the incident led to the theft of data from their Salesforce instances and did not affect their platforms, infrastructure, payment information, or internal systems. Several organizations warned that the stolen business contact information could be used in follow-on phishing, social engineering, and extortion campaigns and urged customers to be vigilant. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 19, 2026extracted
Klue breach lead to Salesforce data theft, Huntress affected
Klue breach lead to Salesforce data theft, Huntress affected Cybersecurity vendor Huntress was among multiple companies hit by a breach originating at Klue, a market intelligence platform used to integrate CRM and sales data across various business tools. Huntress published a detailed account of the incident on June 18, framing it as a “security domino effect” that began with one compromised integration credential and cascaded into theft of customer data across several connected platforms, including Salesforce. Attack timeline According to Huntress’s writeup, the attackers first gained access to Klue’s backend infrastructure on June 11 using a long-dormant API credential originally created for an abandoned third-party integration prototype. From there, they pushed a malicious code update designed to harvest OAuth tokens that Klue’s customers used to connect the platform to services including Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack. Those stolen tokens were then used to query customer CRM systems directly and exfiltrate data. “Klue staff disabled the remote access and removed the token-theft code from their servers, and issued a general alert to customers on June 13, which did not indicate which customers were impacted,” Huntress stated. “But on June 16, emails began to appear in the inboxes of some Huntress staff with the subject line ‘top secret email’ and a warning: ‘Your data has been downloaded…You have 48 hours to communicate with us.'” Extortion email received by Huntress (Source: Huntress) Huntress attributes the attack to the extortion group calling itself “Icarus,” active since late April 2026, based on matching Session Messenger IDs found both in the extortion emails and on the group’s dark-web leak site. Huntress said the attackers made off with business contacts, price quotes, and other sales-related data and messaging, but not threat data, passwords, payment card information, or engineering data relating to the Huntress agent or telemetry. It also stressed that its products and infrastructure haven’t been affected. The company has shared indicators of compromise and recommended other Klue customers review logs, request access records from affected vendors, and consider revoking active sessions tied to the compromised integrations. Several security vendors, such as Recorded Future, Tanium, and Jamf, have also publicly stepped forward and released official statements on how they’ve been affected. Salesforce cuts off Klue app On Wednesday, Salesforce announced it had “disabled the connection between the Klue Battlecards app, installed by individual customers, and Salesforce”, after detecting unusual activity involving the app. “As a result, organizations will not be able to connect to Salesforce via this app until further notice,” the company said. On Thursday, Klue CEO Jason Smith said that since identifying unauthorized activity, they have revoked affected credentials and tokens, removed the unauthorized code pushed by the attackers, disabed potentially impacted integrations, and started an investigation. Law enforcement has been notified, he confirmed, and affected customers have been contacted and provided with information that should help with their own incident response. “Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted,” he added, and said that they are planning to further strengthen their security controls, credential management practices, monitoring capabilities, and deployment processes. The breach is part of a broader pattern of attackers targeting trusted third-party integrations rather than Salesforce itself: throughout 2025, a string of OAuth-abuse campaigns have hit other Salesforce-connected SaaS integrations, namely Drift and Gainsight. Update: June 19, 11:20 AM ET: The article was updated to note that several security vendors have also released official statements about this situation. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comJun 19, 2026extracted
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. To that end, organizations will be unable to connect to Salesforce via the app until further notice, the American cloud-based software company noted in an alert published this week. "Salesforce took this action because our security teams recently detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data via the app's connection to Salesforce," it noted. "This issue is limited to Klue's app connection and does not arise from a vulnerability within the Salesforce platform." The development comes as an extortion group dubbed Icarus compromised and exfiltrated data from customers of Klue, including cybersecurity company Huntress. "The data that was copied from our Salesforce account includes business contacts, price quotes, and other sales-related data and messaging," Huntress said. "No threat data, passwords, payment card information, or engineering data relating to the Huntress agent or telemetry we collect was affected." In its own update, Klue said it detected unauthorized activity affecting a portion of Klue's integration infrastructure on June 12, 2026, adding the attackers gained access through a compromised legacy credential associated with an integration service. "The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments," Klue CEO Jason Smith said. "Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted." Specifically, the intrusion is said to have allowed the threat actor to push a code update capable of collecting OAuth tokens that its customers use to connect Klue to their own systems. In response to the breach, Klue has taken steps to revoke affected credentials and tokens, remove unauthorized code, stop remote access, disable potentially impacted integrations, and launch a comprehensive investigation. As of June 16, 2026, some of Huntress employees have received an email with the subject line "top secret email" and a warning that states: "Your Salesforce data has been downloaded ... You have 48 hours to communicate with us. Do the right decision." "The threat actor seems to have leveraged a long-disused but still active credential to conduct the initial compromise – one that was originally created by Klue for them to prototype a third-party integration they later abandoned," the company said. "The threat actor then pivoted into Klue's infrastructure to steal the tokens used by Klue's customers, then used those stolen credentials to query those customers' CRM tools directly and, eventually, to exfiltrate the data." Not much is known about the Icarus actor other than the fact that they have been active since April 28, 2026, and have claimed a total of two victims to date. That said, the data theft campaign mirrors prior attack waves mounted by ShinyHunters and UNC6395. ReliaQuest, in its own analysis of the Klue integration abuse, said the activity shares similarities with the third-party OAuth-abuse playbook associated with the Salesloft Drift and Gainsight compromises that targeted Salesforce environments last year. "In the attacks we observed, the adversary first authenticated through a compromised Klue integration service account, generated OAuth tokens, and ran automated Python scripts (identifiable by Python-urllib user-agent strings)," ReliaQuest researchers Thassanai McCabe and Alexa Feminella said. "These scripts first enumerated the org's object catalog via GET /services/data/v59.0/sobjects, then looped REST API queries against the Salesforce query endpoint (/services/data/v59.0/query) and paginated results via the QueryMore cursor for almost 24 hours." These are assessed to be bulk data retrieval actions designed to pull large volumes of CRM records through the Salesforce REST API. This included a "concentrated burst" of nearly a thousand queries in 15 minutes against at least one environment and an extraction window that lasted more than six hours in another case. It's unclear how many Salesforce customers were affected by the latest attacks, although Klue said it has been communicating directly with impacted customers, sharing investigative findings, and assisting with their response efforts. "The common thread is the abuse of OAuth tokens or credentials from a trusted third-party vendor," ReliaQuest said. "These integrations are non-human identities with persistent, often broad access to sensitive data, yet they are typically monitored far less closely than employee accounts. That gap is why a 24-hour automated query loop could run from a 'trusted' integration account without tripping the usual alarms." Update The threat actor known as Icarus has officially listed Klue as one of their victims as of June 19, 2026. "This appears to confirm the attribution of who was behind the original attack, however," Huntress said. "As you've probably already heard, Klue.com has been impacted by us recently," according to a message posted on Icarus' leak site. "A number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated." "We advice [sic] Klue to contact us for a swift resolution, in order not to affect the companies you work with. On the other note, if Klue doesn't want to accommodate this request, we advice [sic] the companies who want to protect their data to contact us via Session." In the aftermath of the incident, a number of security vendors and other firms have publicly confirmed they have been impacted - Jamf (Impact limited to business data fields within the Salesforce environment) Recorded Future (Impact limited to business data fields stored in our Salesforce database, such as client contact names and email addresses, along with certain business contract information) Tanium (Compromised information includes sales account data, such as opportunity names and values, and other sales-related messaging, as well as business contact information stored in Salesforce, such as names, job titles, and email addresses, and in some cases phone numbers, social media contact details, and business addresses) Gong (Compromised information includes internal licensed user data for a subset of customers, such as names, business titles, emails, but not call recordings or transcripts) Insurity (Impact limited to a very small set of active credentials, which have since been rotated) Sprout Social (Impact limited to business contact details, such as names, professional email addresses, phone numbers, job titles, and mailing addresses, along with organizational and account information, including company details, industry, and account-status information, and related commercial CRM records) OneTrust (Impact limited to third-party CRM-related data accessible through the Klue-Salesforce integration) HackerOne (Impact limited to business relationships and sales activity, including business contact information, such as email and phone numbers, and sales account and opportunity records) Snyk (Impact limited to business data fields within the Salesforce environments, including customer business contact information and only the title and description from a limited subset of customer support cases) LastPass (Impacted limited to standard business contact information and related CRM data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data) Pendo (Compromised information relates to business relationships and sales activity, including business contact information, non-sensitive deal and contract records, and limited non-proprietary business communications) 8x8 (Impact limited to fragmented contract and opportunity information, sales team notes, and contact information (names, business addresses, phone numbers, and email addresses of the customers) BeyondTrust (Impact limited to business contact and general sales-related customer information in its Salesforce CRM system) Huntress security researcher John Hammond told The Hacker News there are no indications at this stage that suggest any potential connections with past Salesforce-related attacks. "As far as we know, Icarus does not seem to be related or involved with the previous Salesforce incidents," Hammond said. "Their leak site states they have only been active since April 2026 and have only indicated two prior victims unrelated to past Salesforce campaigns." "SaaS supply chain breaches are accelerating," Obsidian Security said. "Threat actors have shifted from targeting individual organizations to targeting the SaaS vendors those organizations trust, because compromising one vendor means access to hundreds of enterprise environments at once." "When the attacker gained access to Klue's OAuth tokens, they didn't need a password, an MFA code, or a phished employee. They had the token. From Salesforce's perspective, that token is Klue. So access was granted and CRM records were queried at scale. Login activity did occur, but it came from infrastructure with no connection to Klue's legitimate environment." Icarus Publishes Stolen Data The threat actor behind the Klue compromise has listed data for Huntress and several other companies on its data leak site. In a statement shared with The Hacker News, Huntress confirmed that the 3.4 GB data posted is legitimate and limited to Salesforce CRM data. This includes - Contact information (e.g., full names, work emails, job title, phone number, and business addresses) Business names Products trialed/used Subscription details (units, pricing) Sales-related communications (such as price quotes, contacts, and tasks) with Huntress customers and partners, and Opportunity notes (i.e., free-form fields where teammates can capture and track thoughts and next steps) The data leak files were hosted on an IP address belonging to a Russian bulletproof hosting provider named PROSPERO. IP addresses associated with PROSPERO have been previously linked to exploitation efforts targeting Ivanti Endpoint Manager Mobile (EPMM). "In the coming weeks, impacted companies should watch for potential phishing campaigns that use compromised Salesforce-specific data," the managed security platform said. "Cybercriminals may pose as Klue or other victim vendors and use this data to try to collect further information about businesses." (The story was updated after publication on June 23, 2026, to reflect the latest developments.)
thehackernews.comJun 19, 2026extracted
Will AI Kill the Bug Bounty Industry?
AI is disruptive. Anthropic’s Claude Mythos model, and its successors, promise to be even more disruptive: they could threaten the existing bug bounty and/or in-house offensive security industries. AI has been widely adopted by both cybersecurity attackers and defenders. Attackers use it to help find bugs and craft attacks from sophisticated social engineering through to developing exploit and malware code. Defenders use it to help detect attacks in progress, detect deepfakes, and help code new software, and for bug bounty hunters and offensive security practitioners, to unearth bugs to fix them before they can be exploited. So far, AI has proven to be a force multiplier rather than a position replacement. Mythos threatens to alter this balance. The evolution of bug bounty programs Bug bounties and pentesting are in a state of flux. That’s nothing new: everything in cybersecurity is constantly in flux. But the Mythos arrival may provide the most rapid flux in offensive security yet. A bounty is a reward. ‘Dead or alive’, was an early 19th-century US tagline. That concept still survives, but with law enforcement now offering bounties for information on live cybercriminals. A bug bounty is a reward for finding a bug not a person. In 1983, Hunter & Ready offered a free Volkswagen Beetle car (commonly known as a Bug) as the reward for finding a computer bug in its VRTX operating system. The new tagline was ‘Get a bug if you find a bug’. The concept of bug bounties had arrived and began to expand from the 1990s: Netscape in 1995; IDefence introducing the middleman concept in 2002 (any person could report any bug to any vendor); Mozilla for Firefox in 2004, Google in 2010, and Facebook in 2011. The HackerOne (with Kara Sprague as CEO) and Bugcrowd (co-founded by Casey Ellis) bug-bounty platforms were established in 2012, followed by YesWeHack in 2015, and Intigriti (Inti De Ceukelaire) in 2016. These are the four primary bounty platforms. Throughout the 2010s the concept expanded and many more companies began to offer bug bounties. By 2022, bounty hunter Youssef Samouda was able to tell SecurityWeek, “With Meta and Google, I make around $400,000 per year.” At the end of 2022, AI in the form of LLMs became generally available, and by late 2024 and early 2025 the modern concept of autonomous agentic AI began to take center stage. By June 2025, autonomous offensive security firm XBOW, had achieved #1 position in HackerOne’s leaderboard. The history of bug bounties shows a consistent combination of expansion with an increasing use of automation and artificial intelligence – which brings us to today. In-house offensive security has followed a similar path but driven by salary rather than reward. Bug bounty today Cassim Khouani (known online as Aituglo and listed in the top 30 Hackers on YesWeHack) wrote The state of Bug Bounty in 2026, published on April 13, 2026. In it, he describes using Claude to aid discovery. Overnight, it discovered ten bugs. “Sounds great on paper. Except half of them were duplicates, and the rest took weeks to get triaged because the report queue on that program had become unmanageable. Welcome to bug bounty in 2026.” He believes bug bounty as we know it today is dying. “What comes next can be better, if we play it right.” Everybody, he suggests, is using one or other form of AI to search for bugs, 24/7 without getting tired. It succeeds, but with side effects: “We end up in a constant mental fog, jumping from one tmux pane to another, switching from one program to the next.” And the bounty platforms themselves suffer from so many new AI-assisted submissions, with triaging and payments taking longer. Companies paying bounties are also suffering with more bug reports, some of poor quality and some critical. “More and more companies are stepping back from bug bounty,” he writes, “while others [such as Google] increase their rewards or change their policy.” Note that after Khouani wrote this in mid-April 2026, Google lowered its Chrome bug bounties and raised its Android bounties on April 30, 2026, citing AI as the cause for both. This is flux with its foot on the pedal: rapid change but not necessarily for the better. “The bug bounty of 2024 is dead. The one in 2026 is a different sport. The hunters who will make it are not those who launch the most agents, but those who know what to look for and where to look. AI is a multiplier, not a replacement.” This was written by Khouani based on his experience of using Claude to assist in bug finding. But then along came Claude Mythos, announced almost at the same moment he published his article. Anthropic’s claims for Mythos going forward suggest the future of AI is more than just a force multiplier. Mythos discovering vulnerabilities Mythos reportedly performs better than any other AI model in finding zero day bugs. “Over the past few weeks, we have used Claude Mythos Preview to identify thousands of zero-day vulnerabilities (that is, flaws that were previously unknown to the software’s developers),” announced Anthropic on April 7, 2026, “many of them critical, in every major operating system and every major web browser, along with a range of other important pieces of software.” In May 2026, Anthropic said its Mythos Preview had identified more than 23,000 potential vulnerabilities after scanning thousands of open-source software projects. Anthropic is apparently so concerned about its ability to find unfound bugs that it has released Mythos Preview to major software providers, allowing them to find and fix their own vulnerabilities (Project Glasswing) before the model becomes generally available. The CSA is equally concerned, having published a paper titled, “The ‘AI Vulnerability Storm’: Building a ‘Mythos-ready’ Security Program”, in which it recommends: “Introduce AI agents to the cyber workforce across the board, enabling defenders to match attackers speed and begin closing the gap.” Fed Chair Powell and Treasury Secretary Bessent met with the heads of major US banks to discuss the cyber risks that may be introduced by Mythos; Reuters has reported ‘Banking industry scrambles for Anthropic’s Mythos as global regulators review risks’; and the media has been full of wild, weird, and wonderful reporting. But one area has had little reporting so far: if Mythos is capable of finding bugs and developing exploit chains so rapidly, what effect will this have on the value and future of the existing bug bounty and offensive security industries? Organizations could just point Mythos at their software and find the bugs without needing to pay bounties or employ expensive pentesters and red teams. The future of bug bounty and offensive security Bug bounty and offensive security are not going away; but both must adapt to a new reality. AI is like sniping: the projectile and its effect may be autonomous, but it still needs a human to aim and pull the trigger. Complete autonomy is still in the future, and that human involvement will remain for years to come. It’s the speed of delivery and the accuracy that has changed. Keep Calm and Carry On: Mythos is not revolutionary Tod Beardsley, VP of security research at runZero, counsels that Mythos should be viewed in the historical concept of an industry barely 30 years old: any advance will seem huge and disruptive while it’s happening. “To be blunt, I don’t think Mythos is fundamentally different or the ‘YOU MUST BUY THIS’ security tooling that Anthropic’s marketing would like us to believe. It’s better tooling, for sure…” But, he adds, “To think that this (or any) model is so fundamentally powerful, dangerous, and revolutionary that you’d be a fool to not buy is to ride along with the classic FUD-based marketing that so often colors cybersecurity marketing… This is just another step on the road to better understanding the risk profile of your particular network.” Richard Ford, CTO at Integrity360, agrees with the need to stay calm but adds, ‘be ready to adapt’. “Anthropic’s own system card shows that this level of performance relied on uncensored models, extended compute, and heavy resampling. In other words, this is not yet a real-world scenario.” Nevertheless, he adds, “Bug bounty programs and human-led testing rely on expertise and time. AI will start to reshape that, although areas like business logic will still depend on human understanding.” It’s adaptation, not replacement, says Chris Payne, VP of forward deployed cyber engineers at Sevii. “Discovery accelerates for everyone, but the real bottleneck has always been investigation and remediation. The defenders who win will pair agentic AI with strong governance so they can investigate, hunt, and remediate at machine speed and endless scale, which will close the gap attackers are widening as we speak.” Jon David, co-founder and MD at NR Labs, agrees with this. The power of Mythos and future AI will allow attackers to find and exploit vulnerabilities faster than defenders can fix them. “But if we leverage AI in the same capacity, it also allows us to find and patch the vulnerabilities before they’re public in production. We must just make sure we’re using the same capabilities as the attackers on ourselves before they do.” This should ensure the continuance of in-house offensive security teams. Bounty hunters and bounty platforms have a slightly different problem to solve: participating companies are likely to become reluctant to pay bounties for an increasing volume of existing but largely irrelevant bug slop already found by hunters and their AI agents, and likely to increase with Mythos. “The widely used Curl project ended its HackerOne program in January 2026 because over 95% of submissions were AI-generated junk,” comments Melissa Bischoping, head of threat research & intelligence at Tanium. “HackerOne [also] paused the Internet Bug Bounty in March, explicitly citing an imbalance between AI-assisted discovery and remediation capacity. Mythos makes this worse by an order of magnitude.” The need for adaptation. Evolving AI increases the speed of discovery and decreases the time to exploitation. Kara Sprague, CEO at HackerOne, points out this is not the gap meant in the CSA report. “The gap they are describing isn’t the gap from discovery to exploitation; it’s clear that it has already collapsed. The gap they are referring to is the operational gap between discovery and remediation: organizations still patch on human timelines, manage risk through quarterly assessments and run remediation through change processes that were never designed for AI-velocity threats.” AI-assisted discovery has flooded programs with low-to-mid-severity findings that maintainers cannot absorb. This will increase with Mythos. “The incentives of such bounty programs need to be rebalanced to favor remediation, which is now the key constraint,” she continues. “Vulnerability findings often sit for a long time before remediation, and this trend will continue as the volume increases. It then becomes a question of prioritizing learning from mistakes rather than focusing on individual issues as that approach hasn’t been scalable and certainly won’t be as these advanced models become more distributed,” adds Shlomie Liberow, founder at aisy.ai, and formerly head of hacker R&D at HackerOne. Bounty platforms are already strained by the number of bugs being discovered. And corporations are unable to keep pace with existing patch levels. What is required is the ability to prioritize high severity bugs over low value bugs, and incentives to prioritize high severity over low value will be built into the programs. The longer view. Corporate options for vulnerability detection remain primarily third-party bounty hunters or in-house offensive security teams. The best option will be governed by whichever adopts the latest technology functionality faster and more intelligently. “Today, frontier model providers (like Anthropic) make AI abundantly cheap to use, reducing the cost of vulnerability research,” suggests Aaron Sant Miller, VP and AI lead for Booz Allen’s Integrated Cyber Business. “If organizations increasingly choose to bring this function in-house, you can expect the bug bounty industry to take a hit. Conversely, bounty hunters may find AI reduces their own cost and time – we may see more bounties executed per month, at a lower cost per bounty. Today’s balancing act will be shaped by adoption.” It may be different tomorrow. The current cost of AI is being eaten by the frontier model developers, and the price to users is artificially low. Once the market has been hooked, the developers may increase their prices to reflect the true market cost. When that happens, organizations will reconsider outsourcing again. “Once AI usage costs begin to reflect their true operating costs, the cost of bug discovery will normalize; organizations and hunters alike will have to determine the fair market price for vulnerability discovery,” he continues. “Overall, in-house security teams that readily adopt AI and evolve their workflows will be more resilient to the disruption.” Sprague agrees that the market for vulnerability hunting is already changing, but she notes, “The total value of the bounty market is growing, not shrinking. High-severity, business-logic and AI-specific vulnerability research (for example, prompt injection, model extraction, adversarial manipulation) is paying more than ever, because very few researchers can do it well.” For in-house offensive teams, she says, “Red teaming was already evolving beyond ‘can we get in’ toward mapping business process fraud paths, executive targeting, third-party compromise chains, privileged identity abuse across SaaS estates. Mythos can’t model your business. It can’t tell you that the real crown jewel isn’t in the codebase at all.” She sees continuous AI-executed adversarial testing with human expertise woven throughout. “Novel attack paths, business logic vulnerabilities and the creative lateral thinking that turns a low-severity finding into a crown jewel compromise still require human ingenuity. AI raises the floor; it doesn’t replace the ceiling.” Summary AI is changing the rules for human vulnerability hunters, but not replacing the requirement. AI can find a never-ending volume of bugs – they will always exist, in both old and new software. But this new AI-discovered volume of bugs, with many of them being low severity, ultimately inconsequential slop, has highlighted the real problem. It’s not finding the bugs (that hasn’t been a problem for years); it’s distinguishing the meat from the slop with rapid remediation. AI is not good at this. It requires human knowledge and ingenuity. In-house human offensive security, using AI but not relying on it, can do this well – and the value of in-house detection and remediation will remain. External bounty hunting will be most impacted, but will continue to offer a valuable service if the bounty paid can be refocused on critical bugs and remediation. This will offer a valuable alternative for those companies that find employment of a permanent in-house team to be too costly. Vulnerability hunting, like every other aspect of cybersecurity, is subject to new technology. And like every other aspect of cybersecurity, the advice to practitioners remains the same: keep calm, adapt, and carry on. Related: Cyber Insights 2026: Offensive Security; Where It Is and Where It’s Going Related: OpenAI Launches Bug Bounty Program for Abuse and Safety Risks Related: Microsoft Bug Bounty Program Expanded to Third-Party Code
securityweek.comJun 9, 2026extracted
Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data
FEATURE When Instructure “reached an agreement” with data theft and extortion crew ShinyHunters this week, the education tech giant assured Canvas users after attackers claimed to have stolen data tied to 275 million students, teachers, and staff that their private chats and email addresses would not turn up on a dark-web marketplace, and that they would not be extorted over the incident. “We received digital confirmation of data destruction (shred logs),” Instructure assured the nearly 9,000 affected universities and K-12 schools. “We have been informed that no Instructure customers will be extorted as a result of this incident, publicly or otherwise.” Not a single responder that The Register spoke with believes this is true. “Do I believe they deleted the data? No. They're criminals and scumbags,” Recorded Future threat intelligence analyst Allan Liska, aka the Ransomware Sommelier, told us. “But, this is part of what Max Smeets calls ‘The Ransomware Trust Paradox,’” he added. “Ransomware groups have to, minimally, not post data they claimed to have deleted or no one will pay them in the future, but this is done knowing that the data is likely not deleted.” Halcyon Ransomware Research Center SVP Cynthia Kaiser, who previously spent two decades at the FBI, said she doesn’t think that anyone who studies ransomware groups’ operations believes the gang actually destroyed the stolen files. The operational reality at 3 a.m. during finals week or enrollment season can push institutions toward a very different calculation “‘We destroyed the data’ is a standard line from extortion groups once a payment is made or negotiations conclude, but time after time it has proven untrue,” Kaiser told The Register. “ShinyHunters in particular has a documented history of recycling, reselling, and re-leveraging stolen data across campaigns – data they claimed was contained from earlier intrusions has resurfaced on criminal forums months and years later.” Kaiser also doesn’t think this is the last threat that the schools will face from the Canvas breach. “Halcyon expects targeted phishing waves against staff, students, and parents over the next six to 12 months using leaked names, email addresses, and Canvas chat context to make the lures convincing,” she said. To be clear: Instructure execs never directly said the company paid the ransom, and we don’t know the exact amount of money the criminals demanded from the digital learning biz. We do know, however, that “reached an agreement” is corporate-speak for the victim paid up. Alliance Risk CEO David Vainer estimates the figure sits somewhere between $5 million and $30 million. Meanwhile, this latest extortion attack illustrates the impossible choice facing organizations entrusted with protecting people’s data when digital thieves breach their networks and steal sensitive information. “The FBI says don’t pay,” Doug Thompson, chief education architect at cybersecurity firm Tanium, told The Register. “But the operational reality at 3 a.m. during finals week or enrollment season can push institutions toward a very different calculation. Until that incentive structure changes, education is likely to remain unusually vulnerable to extortion pressure.” To pay, or not to pay? The US federal government, law enforcement agencies, and private-sector threat intelligence analysts all advise victims not to pay a ransom. “Paying ransoms rewards and incentivizes the criminals, funding their search for new victims, and I’ve long advocated before for a ban on ransomware payments,” Emsisoft threat analyst Luke Connolly told us. “But in the absence of regulation applying to all organizations, the stark reality is that Instructure faced a crisis, and they negotiated to try to minimize risk and harm.” No company wants to pay a ransom to its attackers, and most say they won’t – at least in principle – because they don’t want to fund criminal operations and incentivize the crooks. There’s also no guarantee that paying will guarantee the return of their data or prevent additional extortion attempts. CrowdStrike surveyed 1,100 global security leaders last summer, and of the 78 percent who said they experienced a ransomware attack in the past year, 83 percent of those that paid ransoms were attacked again. Plus 93 percent lost data regardless of payment. While data suggests that fewer organizations are paying criminals’ ransom demands - Chainalysis found the percentage of paying victims in 2025 dropped to an all-time low of 28 percent, despite attacks hitting record highs - when faced with extortion or a ransomware infection, the "to pay or not to pay" debate becomes much more complicated. “Most organizations still say publicly that they won't pay, and many genuinely don't, but when the alternative is mass downstream harm to students, parents, and thousands of customer institutions, the calculus shifts,” Kaiser said. “Pay-or-leak groups like ShinyHunters specifically engineer that calculus by creating intense financial and reputational pressure, and when demands go unmet, they escalate to direct harassment of victim companies, employees, and clients.” ShinyHunters did just that. The crew initially compromised Instructure in late April, and after the initial pay-or-leak deadline passed on May 6, ShinyHunters switched tactics to school-by-school extortion. They injected a ransom message into about 330 Canvas school login portals, causing Instructure to take the platform offline for a day - during final exams and Advanced Placement testing for many. Other ransomware scum have gone to horrifying extremes, posting pictures and addresses of preschool children in an effort to get a payday, leaking cancer patients’ nude photos and threatening them with swatting attacks. Mandiant Consulting CTO Charles Carmakal previously told The Register that ransomware infections have morphed into "psychological attacks” with crooks SIM swapping executives’ kids to pressure their parents into paying. Calculating risk In addition to responding to criminals directly harassing their students, patients, customers and employees, victim organizations also have to take into account potential lawsuits if the crooks dump individuals’ personal or health data, and the reputational hit from seeing all of this protected information published online. The decision about what to do in a ransomware attack revolves around risk reduction, Liska said. “Not paying a ransom means an increased risk of data exposure, which in this case could cause serious harm,” he told us. “While there is no good decision in most ransomware negotiations, the idea is to protect as many people as possible and that may mean that paying is the least bad option.” While he didn’t respond to or investigate the Instructure case, “protecting children's data is absolutely a critical factor in these types of decisions, especially when the attacks originate from one of the groups associated with The Com,” Liska added. The Com, a loosely knit group of primarily English speakers who are also involved in several interconnected networks of hackers, SIM swappers, and extortionists such as ShinyHunters and Scattered Lapsus$ Hunters, has been known to blackmail kids and teens into carrying out shootings, stabbings, and other real-life criminal acts. “These groups are known to coerce victims using threats of physical harm, including bricking and swatting," he said. "Not paying may have increased the risk of serious harm to the children whose data was exposed.” A representative of ShinyHunters contacted The Register to "deny any and all association, affiliation, and/or linkage with 'The Com' including 'Scattered Lapsus Hunters'" The rep said "There is no actual concrete evidence to support that we are associated, affiliated, or linked to the aforementioned. These are baseless allegations and industry propaganda surrounding 'The Com.'" The Shiny one admitted that some of their crew's tactics are similar to those the other gangs use but suggested it's lazy to assume a link. "If China or North Korea used vishing to infiltrate organizations networks would they also immediately become associated with “The Com?'" the representative asked. Ed sector 'more likely to pay' Instructure’s intrusion follows several other high-profile attacks against education-sector software providers. In December 2024, PowerSchool suffered a breach, affecting tens of millions of students. The company reportedly paid about $2.85 million in bitcoin in exchange for a video supposedly showing the attackers destroying the data. But about five months later, in May 2025, the ed-tech provider’s school district customers received individual extortion threats from either the same ransomware crew that hit PowerSchool or someone connected to the crooks. Earlier this year, ShinyHunters claimed it stole data from K-12 software provider Infinite Campus as part of a broader wave of Salesforce-related intrusions. “Education keeps emerging as one of the sectors where organizations are still more likely to pay under pressure,” Thompson said. In addition to students’ – especially minors’ – data containing highly sensitive personal details, and therefore presenting an attractive target for attackers, this is also driven in part by market pressure and economics. There will be future attacks, without a doubt It’s costly and inconvenient for schools to switch learning management systems, and they are typically locked into multi-year contracts with these software vendors, according to Thompson. “The other issue is concentration,” he said. “A relatively small number of vendors hold data for enormous portions of the education system. PowerSchool, Infinite Campus, Canvas, Blackboard; those four hold records on something close to every American student, and hackers know it. Three of the four have been breached at a multi-million-record scale in the last 18 months.” Thompson said he expects to see additional attacks against major education platforms to follow. “The economics are good. Instructure paid. PowerSchool paid last year. Every other ed-tech vendor's board just had a conversation about what their number would be,” he told us. “The pattern is established.” According to Connolly, the universities and K-12 schools affected by the Canvas hack shouldn’t consider their data safe, regardless of Instructure’s assurances or the crooks' promises to delete it. “There will be future attacks, without a doubt.” ® Correction: The estimate of $5 million to $30 million comes from Alliance Risk CEO David Vainer.
theregister.comMay 14, 2026extracted
OpenAI Launches 'Daybreak' to Help Build Secure By Design Software
OpenAI has announced Daybreak, a new initiative based on its frontier large language models (LLMs) and its AI-coding assistant, Codex, to help developers build secure software from the ground up. Unveiled on May 12, OpenAI said Daybreak builds from its Trusted Access for Cyber (TAC) program, a scheme that reserves access to certain frontier models to a selective number of organizations. The initiative already includes three of OpenAI’s latest models: the general-purpose version of GPT‑5.5; GPT‑5.5 with TAC, which offers more precise safeguards for verified defensive work in authorized environments; and GPT‑5.5‑Cyber. It also features Codex Security, a code‑review assistant based on Codex that is currently available only as a research preview. Where the TAC program is primarily focused on vetted users tapping into LLMs to identify and fix vulnerabilities, Daybreak aims to tackle the vulnerability problem from the start of the software development lifecycle. Speaking to Infosecurity, Willie Tejada, SVP & GM of Cloud Native Security Fabric at Aviatrix, explained that OpenAI's press release is intentionally broad because Daybreak is "a platform play, not a model announcement." He said the initiative aims to help cyber defenders do three things: build an editable threat model of a given code repository focused on realistic attack paths, discover and test vulnerabilities in an isolated environment and propose and validate patches directly in the repo. "The pitch is that it compresses hours of manual security analysis into minutes," Tejada added. In a series of short videos posted on social media, OpenAI shared some of the tasks that software developers and cybersecurity defenders can perform as part of the initiative. These include: Scanning a codebase using Codex Security’s 10 subagents, identifying vulnerabilities, fixing them and adding regression tests Triaging vulnerability backlog, prioritizing vulnerabilities that should be fixed (e.g. by severity, impact or exploitability) and deploying agents to open pull requests Automating vulnerability detection, validation and response (e.g. looking for the latest CVEs, deploying an agent to investigate their impact on the business, searching logs for exploitation evidence) “The goal is simple: accelerate cyber defenders and continuously secure software,” the OpenAI announcement said. “Because those same capabilities can be misused, Daybreak pairs expanded defensive capability with trust, verification, proportional safeguards and accountability.” According to Tejada, Daybreak is "OpenAI's bid to own the security developer toolchain the same way GitHub Copilot captured the coding assistant market." The company also said it will soon deploy new “cyber-capable models” in cooperation with industry and government partners. As of May 2026, OpenAI said its TAC program includes hundreds of organizations and "thousands of individual defenders." These include IT and cybersecurity organizations like Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, NVIDIA, Oracle, Palo Alto Networks, Sophos and Zscaler. The TAC also includes large enterprises, especially in finance and private equity, such as Bank of America, BBVA, BlackRock, BNY, Citibank, Goldman Sachs, JPMorgan Chase, Morgan Stanley and US Bank. While only a handful of government-linked research organizations, like the US Center for AI Standards and Innovation (CAISI) and the UK AI Security Institute (UK AISI) are currently part of the TAC program, OpenAI confirmed in early May its intention to expand it to more government agencies. Anthony Grieco, SVP, chief security and trust officer at Cisco, believes frontier models like GPT 5.5 are “powerful force multipliers for defenders.” “They are fundamentally changing the velocity of our operations, enabling us to move faster on everything from incident investigation to proactive exposure reduction,” he said. “But speed cannot be traded for trust. The true value of this technology isn't found in the model alone, but in the enterprise-ready framework we wrap around it. A framework that helps us make more secure products. Our focus is on transforming our secure development and operations processes with these new capabilities. For us, it's about enabling innovation that is as reliable as it is fast.” Experts Raise Concerns About AI-Powered Vulnerability Research While many experts regard the launch of Daybreak as a step in the right direction in a bid to use frontier AI models to help fix vulnerabilities alongside other software development tasks, it also raised a lot of concerns. David Stuart, a cybersecurity evangelist at data security solutions provider Sentra, warned that to unlock the capabilities of frontier AI agents, organizations must grant these systems access to their environment. “That may include code repositories, infrastructure configurations and build pipelines. Before introducing these tools, organizations need to understand what sensitive data lives in those environments and whether it is governed well enough for an AI agent to interact with it,” he said. “The same access that makes these tools useful also makes them part of the data attack surface. That governance work needs to happen before the agent is deployed.” Meanwhile, Andrew Wesie, a vulnerability researcher and CTO of AppSec company Xint.io, said that vulnerability researchers should also ensure they’re aware of the details of security offerings from GenAI companies like OpenAI and Anthropic if they don’t want to be trapped in an expensive ecosystem that will lock them in. “For example, how many tokens are burned during [Daybreak] assessments, what is the false positive rate and how will pricing work for enterprise code bases that have millions of lines of code? Without this information, it’s hard to know if teams should build their AppSec pipelines around monolithic models,” he cautioned. Many believe the democratization of AI-powered vulnerability research is to be welcomed. However, Melissa Bischoping, head of threat research and intelligence at Tanium, warned it also “tightens the bottleneck around remediation.” As software companies find and develop bug fixes at an “unprecedented pace,” consumers of the software may not necessarily be ready to deploy patches. “Many organizations today still struggle with the ‘old way’ of monthly patching at the scale of the last few years. That ship has sailed, and we’ve got to rethink and rebuild our patching systems for this era,” she said. She argued that patch management teams will have to deal with “dozens or hundreds of micro-patches per week” as bugs are uncovered. Clyde Williamson, a senior product security architect at Protegrity, which provides data security solutions designed for AI workflows, noted that finding vulnerabilities has never been the hardest problem, prioritization is. This article was updated on May 13 to add comments from cybersecurity professionals. Image credits: Thrive Studios ID / TY Lim / Shutterstock.com
infosecurity-magazine.comMay 12, 2026extracted
Vercel Finds More Compromised Accounts in Context.ai-Linked Breach
Vercel on Wednesday revealed that it has identified an additional set of customer accounts that were compromised as part of a security incident that enabled unauthorized access to its internal systems. The company said it made the discovery after expanding its investigation to include an extra set of compromise indicators, alongside a review of requests to the Vercel network and environment variable read events in its logs. "Second, we have uncovered a small number of customer accounts with evidence of prior compromise that is independent of and predates this incident, potentially as a result of social engineering, malware, or other methods," the company said in an update. In both cases, Vercel said it notified affected parties. It did not disclose the exact number of customers who were impacted. The development comes after the company that created the Next.js framework acknowledged the breach originated with a compromise of Context.ai after it was used by a Vercel employee, enabling the attacker to seize control of their Google Workspace account and then use it to gain access to their Vercel account. "From there, they were able to pivot into a Vercel environment, and subsequently maneuvered through systems to enumerate and decrypt non-sensitive environment variables," Vercel noted. Further investigation by Hudson Rock has revealed that one of Context.ai employees was infected with Lumma Stealer in February 2026 after searching for Roblox auto-farm scripts and game exploit executors, indicating that this event may have been the "patient zero" that triggered the whole chain of malicious actions. "We now understand that the threat actor has been active beyond that startup's [referring to Context.ai] compromise," Vercel CEO Guillermo Rauch said in an X post. "Threat intel points to the distribution of malware to computers in search of valuable tokens like keys to Vercel accounts and other providers." It's unclear if Vercel employees' use of the Context AI Office Suite was sanctioned or an instance of shadow AI, which refers to the unauthorized use of artificial intelligence (AI) tools within SaaS apps without formal IT review or vetting, exposing organizations to unintended risks. The AI Office Suite has since been deprecated by Context.ai. "OAuth integrations are useful because they reduce friction," Tanium said. "They're also dangerous because they can inherit trust from the user and the organization. When attackers abuse an approved integration, they may avoid some of the controls teams rely on for direct account compromise." "What stands out operationally is less the volume of data exposed and more the attackers' velocity and ability to enumerate internal environments before detection. That changes the job for defenders. The challenge shifts from prevention to rapid scoping and blast-radius reduction."
thehackernews.comApr 23, 2026extracted
Critical Vulnerability in Claude Code Emerges Days After Source Leak
Anthropic’s Claude Code is in the news again – and not for the best reasons. Within days of each other, Anthropic first leaked the source code to Claude Code, and then a critical vulnerability was found by Adversa AI. Claude Code Leak On March 31, 2026, Anthropic mistakenly included a debugging JavaScript sourcemap for Claude Code v2.1.88 to npm. Within hours, researcher Chaofan Shou discovered the sourcemap and posted a link on X – kicking off a global rush to examine de-obfuscated Claude Code’s code. Sigrid Jin, a 25-year-old student at the University of British Columbia, worked with Yeachan Heo to reconstruct the Claude Code. “It took two humans, 10 OpenClaws, a MacBook Pro laptop, and a few hours to recreate the popular AI agent’s source code and share it with the world,” reports Yahoo, proving that what goes up (on the internet) does not come down (off the internet). The result now persists on the internet, comprising 512,000 lines of TypeScript in 1,900 files. It is awkward but not catastrophic for Anthropic. “While the Claude Code leak does present real risk, it is not the same as model weights, training data or customer data being compromised. What was exposed is something more like an operational blueprint of how the current version of Claude Code is designed to work,” explains Melissa Bischoping, senior director of security & product design research at Tanium. The key is that researchers can see how Claude Code is meant to work but cannot recreate it because the leak does not include the Claude model weights, the training data, customer data, APIs or credentials. “It is not a foolproof roadmap to exploitation, but it is meaningful insight into how the tool handles inputs, enforces permissions and resists abuse,” continues Bischoping. “Another layer of risk from this leak is that adversaries may use the blueprint to build lookalikes that appear and behave like Claude Code on the surface, but install malware or harvest credentials and data,” she adds. Awkward and embarrassing for Anthropic, but not directly harmful to Claude Code. Vulnerability in Claude Code But a genuine and critical vulnerability has now been discovered in Claude Code proper by Adversa AI Red Team. “Claude Code is… a 519,000+ line TypeScript application that allows developers to interact with Claude directly from the command line. It can edit files, execute shell commands, search codebases, manage git workflows, and orchestrate complex multi-step development tasks,” reports Adversa. Claude Code includes a permission system based on allow rules (auto-approve specific commands), deny rules (hard-block specific commands), and ask rules (always prompt). Adversa provides an example: { "deny": ["Bash(curl:*)", "Bash(wget:*)"], "allow": ["Bash(npm:*)", "Bash(git:*)"] } Never allow curl or wget (prevent data exfiltration), but auto-allow npm and git commands (common development tools). That sounds correct and reasonable. The flaw, however, is that the deny rules can be bypassed. “The permission system is the primary security boundary between the AI agent and the developer’s system,” reports Adversa. “When it fails silently, the developer has no safety net.” The problem stems from Anthropic’s desire for improved performance following the discovery of a performance issue: complex compound commands caused the UI to freeze. Anthropic fixed this by capping analysis at 50 subcommands, with a fall back to a generic ‘ask’ prompt for anything else. The code comment states, “Fifty is generous: legitimate user commands don’t split that wide. Above the cap we fall back to ‘ask’ (safe default — we can’t prove safety, so we prompt).” The flaw discovered by Adversa is that this process can be manipulated. Anthropic’s assumption doesn’t account for AI-generated commands from prompt injection — where a malicious CLAUDE.md file instructs the AI to generate a 50+ subcommand pipeline that looks like a legitimate build process. If this is done, “behavior: ‘ask’, // NOT ‘deny’” occurs immediately. “Deny rules, security validators, command injection detection — all skipped,” writes Adversa. The 51st command reverts to ask as required, but the user gets no indication that all deny rules have been ignored. Adversa warns that a motivated attacker could embed real-looking build steps in a malicious repository’s CLAUDE.md. It would look routine, but no per-subcommand analysis runs at all when the count exceeds 50. This could allow the attacker to exfiltrate SSH private keys, AWS credentials, GitHub tokens, npm tokens or Env secrets. It could lead to credential theft at scale, supply chain compromise, cloud infrastructure breach and CI/CD pipeline poisoning. “During testing, Claude’s LLM safety layer independently caught some obviously malicious payloads and refused to execute them. This is good defense-in-depth,” writes Adversa. “However, the permission system vulnerability exists regardless of the LLM layer — it is a bug in the security policy enforcement code. A sufficiently crafted prompt injection that appears as legitimate build instructions could bypass the LLM layer too.” Related: Hackers Weaponize Claude Code in Mexican Government Cyberattack Related: Claude Code Flaws Exposed Developer Devices to Silent Hacking Related: Trump Orders All Federal Agencies to Phase Out Use of Anthropic Technology
securityweek.comApr 2, 2026extracted
みずほFG、サイバー脅威の兆候から検知 エンドポイント可視化で「脅威ハンティング」実践
�^�j�E���݂͂��كt�B�i���V�����O���[�v�ɂ�鐻�i������������J�����B���O���[�v�̓G���h�|�C���g�Ǘ����i�����A�G���h�|�C���g�������������Ѓn���e�B���O�����H���Ă���Ƃ����B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@�^�j�E����2026�N2��20���A�݂��كt�B�i���V�����O���[�v�ɂ��G���h�|�C���g�Ǘ����i�̓�����������J�����B �@�݂��كt�B�i���V�����O���[�v�iFG�j�́A���ݒ��ʂ��Ă���3��T�C�o�[���X�N�Ƃ��āu�����T���E�F�A�i�g����v���^�}���E�F�A�j�v�u�T�[�h�p�[�e�B�[���N�_�Ƃ������Ёv�u���ƃA�N�^�[�ɂ�鍂�x�ȃT�C�o�[�U���v�������Ă���A���ꂼ��ɑ���Ή�����������Ă���B �@���̈�Ƃ��ē��O���[�v�ł́A2018�N���^�j�E���̃G���h�|�C���g�Ǘ����i�uTanium�v�����A�i����������T�C�o�[���X�N�ւ̑Ή��͋����Ɏ��g��ł����B �@�݂��كt�B�i���V�����O���[�v��Tanium�����p���ăG���h�|�C���g�̋��������A���^�C���ɉ������A�T�C�o�[�U���̋��Ђ�i�K���瑨���邽�߂̑̐����\�z���Ă���B �@���ɁA���m�̋��Ђɑ��Ĕ\���I�ɒ����E���͂��s���u���Ѓn���e�B���O�v�����H���邱�ƂŁA�C���V�f���g�̑��������Ɛv���ȑΉ����\�ɂ��Ă���Ƃ����B �@�݂��كt�B�i���V�����O���[�v�̃T�C�o�[�Z�L�����e�B�������ŊC�O�T�C�o�[�Z�L�����e�B���i��[���̎����߂�Ĉ�m�����́ATanium�̓����ɂ���ăG���h�|�C���g�Z�L�����e�B����I�ɉ^�p�ł���悤�ɂȂ邽�߁A����Z�L�����e�B��̃R�X�g��\�[�X�̍œK����}���Ă��������Ƃ��Ă���B �@�܂����O���[�v�̃T�C�o�[�Z�L�����e�B�������ŃT�C�o�[���X�|���X��[���̃A�\�V�G�C�g�߂�y��D�厁�ɂ��ƁATanium�����ۂɁuDLL�i���I�����N���C�u�����j�̃T�C�h���[�f�B���O�v�̎����p�����U�������m�������Ƃ��m�F�����Ƃ����B �@����������̃��[���x�[�X�̊Ď��Ō��m���悤�Ƃ���ƁA�ǂ����Ă��ߌ��m�������Ȃ��Ă��܂����ATanium�̋��Ѓn���e�B���O�Ȃ炻�̓s�x���ۂ̐N�Q�Ȃ̂��ߌ��m�Ȃ̂���l�̔��f�ōs���邽�߁A�����I�ȊĎ����\�ɂȂ�Ƃ����B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpMar 30, 2026extracted
Cyber Insights 2026: Threat Hunting in an Age of Automation and AI
Threat hunting is in flux. What started as a largely reactive skill became proactive and is progressing toward automation. Threat hunting is the practice of finding threats within the system. It sits between external attack surface management (EASM), and the security operations center (SOC). EASM seeks to thwart attacks by protecting the interface between the network and the internet. If it fails, and an attacker gets into the system, threat hunting seeks to find and monitor the traces left by the adversary so the attack can be neutralized before damage can be done. SOC engineers take new threat hunter data and build new detection rules for the SIEM. That’s a theoretical representation – precise details vary between different organizations. Proactive or reactive? A common perception of cybersecurity defines defense as necessarily reactive. Defenders are naturally forced into a position of reacting to attacks, while attackers are free to be proactive in their own activity. In many cases this is valid, but the distinction doesn’t fit neatly into threat hunting. Threat hunting is reactive in seeking evidence of an event that has already happened; but is proactive since it doesn’t know what the event was, nor even if it really happened. It assumes a breach but doesn’t know the breach has occurred until it finds evidence. Understanding how threat hunting differs from reactive security provides a deeper understanding of the role, while hinting at how it will evolve in the future. “Threat hunting is one of the most proactive actions an analyst can perform,” claims David Norlin, CTO at Lumifi Cyber. “I also argue that free-form threat hunting is perhaps the most effective way at finding unknown threats. It’s unlikely the precise technical means of exploitation will be seen by threat hunting, but exploits and malicious tampering usually leave artifacts and residual signals that can be detected.” Dave Tyson, chief intelligence officer at iCOUNTER, continues, “Threat hunting assumes a cyber adversary has already infiltrated your environment and is either hiding in the shadows, has implanted a web shell or backdoor, or deployed malware waiting to detonate at a predetermined time. In practice, adversaries often become aware of these discovery efforts and may react defensively, sometimes executing their payloads such as ransomware prematurely.” In this sense, threat hunting can reverse the traditional role: the defender is proactive, forcing the attacker to become reactive. The evolution from reactive threat hunting to proactive hunting is explained by Scott Miserendino, VP of engineering, advanced cybersecurity solutions at DataBee. “Traditional hunting often relies on known indicators of compromise (IOCs) and signature-based detection, which means teams are always one step behind attackers. In a world where attack methodologies evolve daily and AI-generated malware can create infinite variants, reactive hunting is no longer enough. “Proactive threat hunting,” he continues, “starts with behavioral analysis, zero-day malware detection and anomaly detection, not just known signatures. By leveraging machine learning and advanced analytics, security teams can identify patterns that deviate from normal network behavior – such as unusual beaconing, encrypted command-and-control traffic, or file characteristics that suggest malicious intent – even when those threats have never been seen before.” Anomalous activity within the network is the key. This must include anonymous behavior of accredited identities. A background knowledge of current cyber threat intelligence (CTI), championed by Frankie Sclafani, director of cybersecurity enablement at Deepwatch, is also important. “Cyber threat intelligence serves as cybersecurity’s early warning system, aiming to understand the nature and source of attacks, identify adversaries and targets, recognize the presence of existing attacks, and assess the likelihood of imminent attacks. CTI helps defenders prepare for and prevent attacks, rather than merely respond to them,” he says. Behavioral anomaly detection can trigger a threat hunter’s curiosity, while CTI knowledge can focus attention more deeply. Allison Wikoff, director and Americas lead for global threat intelligence at PwC, adds, “Proactive hunting is about forming scenarios based on threat actor behaviors and testing them before an alert ever fires.” AI-assisted attacks are so frequent and stealthy this cannot be achieved without automated assistance, and threat hunting already relies heavily on machine learning anomaly detection. All automation, including attacks, are being supercharged by AI – and this is the future for threat hunting. The continuing rise of automation Automation in threat hunting already exists with machine learning behavioral analysis both learning the behavioral baseline and then flagging divergence from it. Machine learning is artificial intelligence now being enhanced by rapidly improving generative AI, which in turn is being enhanced by agentic AI. Most of the cyber world (commercial business, cybersecurity, and cyber attackers) are already on this conveyor belt – but threat hunting may be a bit slower. “Some types of threat hunting can be meaningfully automated, usually within the context of looking for new indicators of known threats that have surfaced within the last few days,” says Norlin. However, he adds, “There will be no replacing the unpredictability and idle curiosity of a human analyst. This is arguably the best kind of threat hunting – a human roaming around a large dataset in search of something interesting. Humans love novelty, and good threat hunters are largely occupied by this pursuit, whether they consciously know it or not. It’s going to be a long time before AI mimics this inquisitive spirit, if it ever does.” “Instead of chasing known TTPs, next-generation threat hunters will rely on anomaly-based AI systems trained on historical baselines and user behavior patterns,” says Ariel Parnes, former IDF 8200 cyber unit colonel and COO at Mitiga. “Successful teams in 2026 will hunt for deviation, not confirmation,” he continues. “The shift from ‘assume breach’ to ‘assume anomaly’ will define the next era of proactive defense, especially across cloud and SaaS environments where logs are fragmented and ephemeral.” Much of today’s threat hunting is already automated. “Cybersecurity tools and anomaly detection systems are constantly scanning for suspicious patterns,” says Ihar Kliashchou, CTO at Regula. This is likely to continue and expand through 2026. “Systems establish behavioral baselines for each identity (human and non-human), detect deviations in real-time, and alert analysts. The automation scales to monitor millions of identities continuously. Human threat hunters shift from tactical detection to strategic investigation – validating detections, understanding context, determining response,” expands Jason Martin, co-founder and co-CEO at Permiso. The limiting factor, he adds, is the setup time. “Behavioral baselines require 60-90 days of baseline data before anomaly detection becomes reliable. Organizations that establish baselines in Q1 2026 will have mature proactive hunting by Q3 2026. Those starting in Q3 will not have reliable detection until late 2026 or Q1 2027.” The implication is clear. Companies that have not yet started on the automation trail are likely to get burned by bad actors adopting AI automation at a faster rate. The next shift in automation is likely to be an adoption of agentic AI-assisted threat hunting. Exactly what this means, the extent to which it will be adopted, and the timeline toward it is, however, heavily debated. But in one form or another it is inevitable. Attackers are already developing and adopting full agentic AI models; and the only way that defenders, including threat hunters, can keep up will be through their own agentic systems. “AI can be used both to detect and to generate threats, making it a double-edged sword. We might soon see AI-powered attacks that adjust tactics in real time, and defensive systems will need to match that level of speed and adaptability,” warns Kliashchou. For now, agentic AI in threat hunting will be limited to discrete AI agents tackling individual tasks. In some places this has already started. The full agentic capability has an additional AI agent orchestrating and automating the individual agents into one system that will not merely locate behavioral anomalies but will suggest remedial action and have the ability to perform that remediation without human intervention. That, however, is a long way off for now. “Agentic AI will increase automation in reconnaissance, enrichment and even suggestion of hypotheses, but human oversight will remain critical for context, legal decisions and complex reasoning. Over time, the balance may shift but not to full replacement,” comments Kevin Curran, IEEE senior member and professor of cybersecurity at Ulster University. “Full automation is extremely unlikely to replace human hunters. Humans remain critical for hypothesis-driven investigation, adversary emulation and interpreting ambiguous behaviors,” says Ashley Jess, senior intelligence analyst at Intel 471. “As agentic AI continues to advance, AI will take on routine and data-intensive tasks, freeing human analysts up to focus on strategic investigations and complex decision-making – a partnership rather than replacement scenario,” adds Devon Kerr, director of threat research at Elastic. “The role of AI is not to replace hunters but to expand what they can see,” concludes Biswajit De, CTO at CleanStart. “Instead of reviewing isolated alerts, teams will rely on AI agents that continuously evaluate build integrity, verify dependencies, and surface patterns that signal early-stage tampering. Over time, this will make proactive threat hunting more automated, more continuous, and more sensitive to signals that typically appear long before an incident.” The reason for this almost total rejection of fully autonomous agentic AI-instigated automated remediation is the wide belief that current AI, so good for so many tasks, is so poor at understanding business context. It doesn’t understand what it finds. “AI can tell you what is anomalous; human hunters tell you why it matters. The reason for this divide is simple: AI lacks business context, can’t truly understand attacker motivation, and struggles with the judgment calls that define sophisticated threat hunting,” explains Mitch Davies, senior data scientist and cyber threat research at Arkose Labs. “Context determines everything – automated response works beautifully when context is clear, like with known malware signatures, but fails spectacularly when context is ambiguous,” he continues. This doesn’t mean that all autonomous remediation is off the table. It has been an option with standard ML-based anomaly detection systems for years; but is generally restricted to contained or constrained instances – like isolating an endpoint. “Automated systems can take immediate action,” says Jess, “such as quarantining hosts or isolating compromised endpoints, when high-confidence threats are detected.” The attempt is to mitigate fast-moving threats, like ransomware or infostealers, and reduce the need for human intervention in time-sensitive scenarios. “Adversaries are also increasingly exploring AI to develop and optimize their kits,” he continues, “so defenders will need to leverage some automation alongside intelligence-driven hunting to keep pace.” ‘Contain’ is the key word for automated remediation in the near future. “Automated responses in the form of automatic containment will grow for high-confidence detections to reduce dwell time,” says Curran. “Organizations will adopt safety checks, risk thresholds and rollback procedures to avoid business disruption while enabling swift containment.” The pressure to expand automated remediation is growing, but the dangers are too fierce with current AI. The constant danger we have known from all detection systems continues – the cost of false positives. “We see this constantly in fraud prevention,” comments Davies, “automated blocking must balance security against customer friction. Block too aggressively, and you’re causing revenue loss and user lockout. The solution is tiered automation: low-risk actions like isolating endpoints or blocking suspicious IPs can be automated, but high-risk actions like taking down production systems always need human oversight.” This is the conundrum faced by almost all defensive use of AI. We are hampered by AI’s inability to cater for the intricacies of business environments. If we make one mistake in our use, the consequences could be disastrous for us personally or our company. Attackers have no such concerns. If they make a mistake, it is of little consequence. They simply learn from the mistake and try again. The result of this lack of consequence for attackers is a rapid adoption of AI. The potential severity of consequence for defenders requires the insistence on human oversight within the AI loop – and that results in delay. Attackers are rapidly becoming too fast for us to detect and stop. That’s the conundrum. We dare not unleash the full potential of defensive AI while sooner or later we must. And all of this will unravel over the next couple of years. Visibility gaps The visibility gap affects all of cybersecurity. How can you secure what you don’t know? For threat hunters this translates directly into, How can you monitor and search what you cannot see? The primary culprits in the visibility gap are shadow IT (now increasingly shadow AI), unapproved software-as-a-service (SaaS) applications, and remote working. All are increasing. “Shadows complicate hunting by creating blind spots and unauthorized telemetry sources. This is a growing issue as teams adopt new tools rapidly,” comments Curran. “Remote work increases the diversity of endpoints, network contexts and authentication patterns, making baseline-building harder and increasing false positives.” Ian Ashworth, security operations lead at Fortra, adds, “Unapproved SaaS applications or artificial intelligence (AI) tools create visibility gaps and potential data exposure risks. Environments with remote or hybrid workforces introduce new challenges for threat hunting, as devices outside traditional network boundaries can create visibility gaps and inconsistent logging.” Shadow AI is worsening the long standing shadow IT problem. “Shadow AI is just a new class of Shadow IT to manage – but one with significantly more complexity and potential consequences,” comments Melissa Bischoping, director of endpoint security research at Tanium. “Every executive I’ve spoken with has become increasingly concerned about an employee copying and pasting sensitive company data, such as financial information or intellectual property, into an AI chat box that isn’t managed by the organization itself. This creates a risky, muddy opportunity for data spillage.” It’s not a passing issue – it’s accelerating in 2026. “The reason is simple: it’s easier than ever to spin up SaaS tools, AI services, and cloud resources without IT approval. Generative AI adoption has turbocharged this trend. The impact on threat hunting is severe because you can’t hunt threats on infrastructure you don’t know exists. Shadow AI tools processing sensitive data represent exfiltration vectors you’re not monitoring – massive blind spots in your security posture,” says Arkose Labs’ Davies. “I think we’re in a phase of extreme acceleration with AI, especially around misuse. We are likely going to see major compromises associated with AI-connected services in email, workplace tools, and AI-enabled SaaS applications,” warns Lumifi’s Norlin. “As soon as we start connecting agents that receive input from the wider world, we are creating new attack surface for exploitation.” It’s no different than the waves of SQL injection and other input or injection type attacks we’ve seen in the past, except, he says, “You now have a semi-intelligent, autonomous system with tools at its disposal that can receive input that may not be filtered by any governing system or external gateway. To do their job, they have to be connected to backend sources of data that feed into context. This is ripe for misconfiguration as administrators race them into production and don’t audit the data sources to which they’re connected.” “The detection approach requires hunting for symptoms: anomalous data flows, unusual API calls, unrecognized authentication patterns, employees using personal accounts for business purposes. But here’s the crucial part – technical controls alone won’t solve this. Shadow IT exists for a reason: official tools are too slow, too restrictive, or don’t meet business needs,” he adds. “If you’re only watching approved infrastructure, you’re missing a huge chunk of your actual attack surface. Shadow AI makes this worse because data exfiltration often looks legitimate (someone copying a file or using an API),” cautions Aimee Cardwell, CISO in Residence with Transcend. Most people using shadow AI are just trying to get work done faster and don’t realize the risk. “This is why I work so hard to enable the business with easy to use approved solutions. If you make the secure path the path of least resistance, people are more likely to use it,” she adds. Remote working has been a security concern since before the pandemic, but the practice expanded because of it. It is theoretically more manageable if the organization provides company devices, but that can be very expensive and doesn’t preclude people still using their own unmanaged devices. “One of the primary ways that remote work impacts threat hunting is by increasing the attack surface – remote workers may be more likely to access enterprise resources via personal devices, or to use enterprise devices to access malicious infrastructure,” explains Jason Baker, managing security consultant, threat Intelligence at GuidePoint Security. “Threat hunting is less likely to be achievable against personally owned devices, but enterprise endpoints such as corporate laptops should still be ‘hunt-able’.” “Remote work can significantly impact threat hunting. Depending on geographic jurisdiction and privacy laws, organizations may have limited ability to collect and analyze user data when employees work remotely or off network, such as from home or hotels. This makes visibility and context more difficult and requires new detection and data governance approaches,” adds iCOUNTER’s Tyson. The visibility gap cannot be tackled if you don’t know where it exists. Finding it is the first priority. Shining a light into it can make it more accessible to threat hunters, but not always easy. The light may leave some dark corners, and there may be new visibility gaps appearing that haven’t been found. This is one area where the experience, curiosity and imagination of human hunters remains important. Final Thoughts Threat hunting is evolving from network-focused to behavior-focused; from reactive to hypothesis-driven; and from human-only to human-AI hybrid, suggests Davies. “The goal isn’t to predict the future perfectly – it’s to get better at recognizing ‘wrong’ faster, even when we don’t know exactly what kind of ‘wrong’ we’re facing.” AI will continue to enhance detection, correlation, and response, but it’s the human element – understanding behavior, context, and risk – that ensures effective defense, says PwC’s Wikoff. “Ultimately, threat hunting is not just about tools or technology, but about people using those tools to stay one step ahead of adversaries.” Ashworth adds, “While many aspects can and should be automated, the combination of human expertise and AI-assisted analysis will remain the most effective approach.” The general view is that threat hunting will adopt more tools and more automation in the future. AI will become widespread, and the use of automatic remediation will increase – but always under human oversight and final control. That, however, is an idealized view based on threats and threat hunting today. The rapid evolution of AI is disrupting everything, and adversaries are adopting and using AI faster than defenders can defend. A ‘human in the loop’ of defense may be comforting today but will become a liability in the future. Any delay caused by human triaging could become disastrous. There may be a time in the not distant future where human involvement in remediation will necessarily be withdrawn in favor of autonomous agentic AI remediation. At that point, the threat hunter will necessarily evolve further from proactive tactics to predictive strategy based on autonomous remediation. Related: Creating an Effective Threat Hunting Program with Limited Resources Related: Profile of a Threat Hunter Related: The Wild West of Agentic AI – An Attack Surface CISOs Can’t Afford to Ignore Related: Beyond GenAI: Why Agentic AI Was the Real Conversation at RSA 2025
securityweek.comJan 26, 2026extracted
Tanium integrates AI-driven Triage and Identity Insights into Microsoft Security Copilot
Tanium integrates AI-driven Triage and Identity Insights into Microsoft Security Copilot Tanium announced the general availability of Tanium Security Triage Agent and Tanium Security Triage Agent with Identity Insights in Microsoft Security Copilot. “Agentic AI is transforming the workflows used by security operations to respond, prioritize and act,” said Dan Varga, VP of engineering at Tanium. “Through our collaboration with Microsoft, we’ve built a new class of AI-driven capabilities inside Microsoft Security Copilot. The Tanium Security Triage Agent and Tanium Security Triage Agent with Identity Insights combine Tanium’s real-time endpoint intelligence with Microsoft’s AI. Together, we’re empowering security analysts to investigate and respond to threats with speed, precision and confidence.” Microsoft Security Copilot is AI-powered security product that enables security professionals to respond to threats quickly, process signals at machine speed and assess risk exposure in minutes. It combines an advanced large language model (LLM) with a security-specific model that is informed by Microsoft’s unique global threat intelligence and more than 84 trillion daily signals. Agents in Security Copilot autonomously manage high-volume security and IT tasks and seamlessly integrate with Microsoft Security solutions and partner solutions. Purpose-built for security, these agents learn from feedback, adapt to organizational workflows with your team in-control and operate securely within Microsoft’s Zero-Trust framework. “AI is the force multiplier for defenders, and when partners bring their agentic innovation into the Security Copilot ecosystem, the impact is exponential. Together, we’re not just building tools—we’re creating a new era of intelligent, collaborative cyber defense,” said Vasu Jakkal, corporate VP, Microsoft Security. Designed to streamline and accelerate alert triage for security operations teams and enhanced by Security Copilot’s agentic AI framework, the Tanium agents autonomously investigate Tanium Threat Response alerts. By collecting endpoint artifacts, analyzing context, including identity information from Microsoft Sentinel data lake and Microsoft Entra ID, and recommending next steps, the Tanium agents help security analysts to make faster, more informed security operations decisions.
helpnetsecurity.comNov 19, 2025extracted
AI chatbots are sliding toward a privacy crisis
AI chatbots are sliding toward a privacy crisis AI chat tools are taking over offices, but at what cost to privacy? People often feel anonymous in chat interfaces and may share personal data without realizing the risks. Cybercriminals see the same opening, and it may only be a matter of time before information shared in an AI chatbot conversation ends up in a major data leak. When workplace tools go unchecked Experts warn that users should stay alert when using platforms such as ChatGPT or Gemini, since what seems like a simple exchange can still leave a lasting data trail. Before sharing personal or sensitive details, it is worth remembering that these conversations may be stored and used to train future models unless the user requests otherwise. These risks are already visible inside companies. Concentric AI found that GenAI tools such as Microsoft Copilot exposed around three million sensitive records per organization during the first half of 2025. Much of this happened because employees used AI tools outside approved systems, leaving internal data exposed and poorly monitored. Some reports indicate that as much as 80% of AI tools used by employees operate without oversight from IT or security teams. According to Harmonic Security, enterprises upload roughly 1.3 gigabytes of files to GenAI tools every quarter, and about 20% of those files include sensitive data. As a result, most organizations now see GenAI as a leading IT concern, with the main issues involving data leaks and model manipulation. From private prompts to public results The problem reaches beyond internal company systems. Research shows that some of the most used AI platforms collect sensitive user data and share it with third parties. Users have little visibility into how their information is stored or reused, leaving them with limited control over its life cycle. This leads to an important question about what happens to the information people share with chatbots. In one case, shared ChatGPT chats appeared in Google search results after users publicly shared links that were later indexed. OpenAI has since removed the feature that made those links searchable, though private sharing remains available. That wasn’t an isolated case. Hundreds of thousands of Grok conversations were also found in Google search results. A recent study set out to see how much of that information chatbots remember and how accurately they can describe what they’ve learned about a user. The findings showed how easily personal details surface during ordinary exchanges and raised concerns about how long this data lasts or how it’s reused. The rise of shadow AI One of the more worrying trends in business is the growing use of shadow AI, where employees turn to unapproved tools to complete tasks faster. These systems often operate without company supervision, allowing sensitive data to slip into public platforms unnoticed. Most employees admit to sharing information through these tools without approval, even as IT leaders point to data leaks as the biggest risk. While security teams see shadow AI as a serious problem, employees often view it as low risk or a price worth paying for convenience. “We’re seeing an even riskier form of shadow AI,” says Tim Morris, Chief Security Advisor at Tanium, “where departments, unhappy with existing GenAI tools, start building their own solutions using open-source models like DeepSeek.” Soon after its release, DeepSeek quickly found its way into both personal and professional use. Early on, experts began pointing out the privacy and security risks linked to its use, and the U.S. Navy, for instance, has prohibited its personnel from using it for work-related tasks. What’s particularly alarming is that user data may be stored on servers in China, where different laws on access and data oversight apply. Accountability begins with awareness Companies need to do a better job of helping employees understand how to use AI tools safely. This matters most for teams handling sensitive information, whether it’s medical data or intellectual property. Any data leak can cause serious harm, from damaging a company’s reputation to leading to costly fines. “AI governance only works if it’s actionable,” said Brooke Johnson, Chief Legal Counsel and SVP of HR and Security at Ivanti. “First, acknowledge that AI use is likely taking place across your organization, whether sanctioned or not. Conduct assessments to understand what tools are being used and which ones meet your standards. Then, create pragmatic policies on when and how AI can be applied. Equip teams with vetted platforms that are easy to access and secure, reducing reliance on unsanctioned alternatives.”
helpnetsecurity.comOct 31, 2025extracted
Open Source Community Thwarts Massive npm Supply Chain Attack
A potential npm supply chain disaster was averted in record time after attackers took over a verified developer’s credentials. On September 8, Josh Junon, a developer with over 1800 GitHub contributions in the last year, confirmed on Bluesky his npm account was compromised. Junon had been alerted by other users that his account had started posting packages with backdoors to all popular packages the developer was involved in. The developer, commonly known as ‘qix,’ said he received an email to reset his two-factor authentication (2FA) that looked “very legitimate,” but that was malicious. He added that it only involved his npm account and that he was in contact with NPM to resolve the issue. Compromised npm Packages The compromised ‘qix’ npm account published malicious versions for dozens of packages Junon was involved in. These included some npm packages for high-volume JavaScript projects: chalk (approximately 300 million weekly downloads) strip-ansi (approximately 261 million weekly downloads) color-convert (approximately 193 million weekly downloads) color-name (approximately 191 million weekly downloads) error-ex (approximately 47 million weekly downloads) simple-swizzle approximately 26 million weekly downloads) has-ansi (approximately 12 million weekly downloads) The payload implanted in the malicious packages is a crypto-clipper that steals funds by swapping wallet addresses in network requests and directly hijacking crypto transactions. Crypto-Stealer Attack Chain Explained This sophisticated malware targets cryptocurrency users through two main attack vectors. First, it checks if a wallet extension (like MetaMask) is present. If not, it launches a passive address-swapping attack, intercepting all web traffic by hijacking the browser’s fetch and XMLHttpRequest functions. The malware then replaces legitimate crypto addresses with attacker-controlled ones, using the Levenshtein distance algorithm to pick the most visually similar address, making the swap nearly undetectable to the naked eye. If a wallet is detected, the malware escalates to active transaction hijacking. It intercepts outgoing transactions (e.g., eth_sendTransaction) and modifies the recipient address in memory before the user signs it. The victim sees a legitimate-looking confirmation screen, but if they don’t verify the address carefully their funds are sent straight to the attacker. The attack chain is stealthy and automated, exploiting both human perception (via address spoofing) and technical vulnerabilities (via wallet API manipulation). By compromising a trusted npm package, the malware spreads silently, infecting websites and stealing funds without raising immediate suspicion. One of the primary Ethereum addresses used in the attack is 0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976. People can see its activity live on Ethereum-scanning website Etherscan to traxksome of the stolen funds A GitHub Gist listing all affected wallets has also been created. An Averted Crisis that Should Be “Celebrated” Four hours after Junon confirmed the compromise, he shared a message from NPM saying that all impacted package versions had been taken down. While many people started calling this hack the “biggest supply chain attack in history” on social media, many voices have challenged this narrative. Josh Bressers, VP of security at Anchore, said on LinkedIn: “Here's the thing nobody seems to be talking about. This all lasted for only a few hours. It's amazing how fast open source can respond to things like this. Everyone works together. Information can be shared. The number of people now working on this isn't just larger than your security team, it's larger than your company.” Katie Paxton-Fear, an ethical hacker who recently started working as a staff security advocate at Semgrep, published a video on LinkedIn emphasizing that a major crisis has been averted. “Obviously, any security breach is bad, but this is not the major security breach that people are making it out to be,” she said. She highlighted that the estimated total loss only amounted to $20, thanks primarily to the rapid response of the open source community. “The malware was noticed and people started talking about it on GitHub within only 15 minutes of the malicious packages going live. Some of the packages were taken down by maintainers just one hour after the compromise happened, and the rest of them by NPM within two hours,” she explained. According to Arda Büyükkaya, a senior cyber threat intelligence analyst at EclecticIQ, the attacker’s crypto address shows $66.52. Nevertheless, Paxton-Fear argued that this incident is “a win that shows that the open source model works and that should be celebrated.” In another LinkedIn post, Melissa Bischoping, the senior director of security and product design research at Tanium, went further: “If you're panicking about that NPM thing, please don't. There's a virtually 0 chance you're impacted by this, and you should not burn your teams by having them pick apart every corner of your infrastructure for evidence of these compromised packages.” She continued: “These were up for a couple of hours on a Monday morning (US time) The chances of them being downloaded and shipped into your software in that window of time are very, very small - nearly 0. Of all of the things I think you should have your team pull late nights for, this isn't one of them.” How to Mitigate This Threat However, those who still think they may be affected can take immediate action to block vulnerable dependencies. According to Jan-David Stärk, a team lead and software engineer at Hansalog, to force-safe versions across an entire project, developers can use overrides in their package.json, by adding the following to pin trusted versions of the compromised packages: { "name": "your-project", "version": "1.0.0", "overrides": { "chalk": "5.3.0", "strip-ansi": "7.1.0", "color-convert": "2.0.1", "color-name": "1.1.4", "is-core-module": "2.13.1", "error-ex": "1.3.2", "has-ansi": "5.0.1" } } Then, developers should clean their project by deleting node_modules and package-lock.json, then run npm install to generate a fresh, secure lockfile. This will ensure that no malicious versions remain in their dependency tree.
infosecurity-magazine.comSep 9, 2025extracted
Salesloft GitHub Account Compromised Months Before Salesforce Attack
Threat actors had access to Salesloft’s GitHub account between March and June 2025 and performed reconnaissance in preparation for the widespread Salesforce-Salesloft data theft campaign. The data breach occurred between August 8 and August 18, when the attackers used compromised OAuth tokens for the Drift AI chatbot to export large volumes of data from Salesforce environments. Attributed to a threat actor tracked as UNC6395, the campaign hit hundreds of organizations and focused on the extraction of AWS access keys, passwords, and Snowflake-related access tokens from the stolen data. Initially believed to affect only accounts using the Salesforce-Salesloft Drift integration, the attack was later found to have affected other entities as well, including Google Workspace customers. The attack resulted in Salesforce disabling the Salesloft integration, and in Drift being taken temporarily offline to improve its security. On September 7, the Salesforce-Salesloft integration was restored. However, the campaign was not the result of a weakness in Drift, Salesloft said on Sunday. Instead, it was possible because hackers had compromised the company’s GitHub account half a year ago. “In March through June 2025, the threat actor accessed the Salesloft GitHub account. With this access, the threat actor was able to download content from multiple repositories, add a guest user and establish workflows,” Salesloft revealed. The investigation into the incident, performed by Mandiant, revealed that the hackers performed reconnaissance in the Salesloft and Drift application environments, and then accessed Drift’s AWS instance, exfiltrating OAuth tokens for customers’ integrations. “The threat actor used the stolen OAuth tokens to access data via Drift integrations,” Salesloft says. According to the company, the attack has been contained and the attackers evicted from its environments, and Mandiant has validated that. What Salesloft did not specify, however, was the number of impacted organizations. According to previous estimations, roughly 700 companies might have been affected. In the cybersecurity space, Cloudflare, Palo Alto Networks, and Zscaler were the first to confirm impact from the attack, followed shortly by Proofpoint, SpyCloud, Tanium, and Tenable. The list of cybersecurity firms impacted by the incident, however, has grown to over a dozen, and also includes BeyondTrust, Bugcrowd, CyberArk, Cato Networks, JFrog, PagerDuty, and Rubrik. Elastic said a single email account was compromised through the ‘Drift Email’ integration. Esker, Heap, Megaport, Nutanix, Sigma Computing, and Workiva were also hit, Nudge Security reveals. In most cases, the compromised Salesforce instances stored data related to customer support tickets, including business information such as names, email addresses, and phone numbers. Related: Over 6,700 Private Repositories Made Public in Nx Supply Chain Attack Related: How to Close the AI Governance Gap in Software Development Related: PLoB: A Behavioral Fingerprinting Framework to Hunt for Malicious Logins
securityweek.comSep 8, 2025extracted
Qualys, Tenable Latest Victims of Salesloft Drift Hack
Cybersecurity providers Tenable and Qualys are the latest in a growing list of companies affected by a significant supply chain attack targeting Salesforce customer data. The campaign involved the theft of OAuth authentication tokens connected to Salesloft Drift, a third-party application integrated with Salesforce used to automate workflows and manage leads and contact information. In a security alert on September 3, vulnerability assessment firm Tenable said that an unauthorized user gained access to a portion of some of its customers’ information stored in the company’s Salesforce instance. This data included subject lines and initial descriptions provided by customers when opening a Tenable support case as well as commonly available business contact information, such as names, business email addresses, phone numbers and location references. “At this time, we have no evidence that any of this information has been misused,” the security provider noted. Tenable products and data within the Tenable product suite were unaffected. Three days later, risk management firm Qualys issued a similar alert, stating the credentials stolen during the campaign of OAuth token theft had allowed attackers “limited access to some Qualys Salesforce information.” Like Tenable, Qualys confirmed that its products and services were not affected and were still fully operational. Both firms said they disabled the Salesloft Drift application and revoked associated integrations with their systems and/or rotated integration credentials. Tenable also hardened its Salesforce environment and other connected systems to reduce the likelihood of future exploitation. Qualys said it had worked to contain any potential unauthorized access. The risk management provider is also collaborating with Salesforce and with Google Cloud’s Mandiant to investigate the incident. ‘SalesDrift’ Hack: A Growing Victim List The Salesloft Drift supply chain attack (also known as the ‘SalesDrift’ hack) was first identified by the Google Threat Intelligence Group (GTIG), which shared its findings on August 26. Google itself was among the targets, as an attacker exploited stolen authentication tokens to infiltrate email accounts in a limited number of Google Workspace users on August 9. Since then, a flurry of companies have confirmed they had been affected, including BeyondTrust, Bugcrowd, Cato Networks, Cloudflare, CyberArk, Elastic, JFrog, Nutanix, PagerDuty, Palo Alto Networks, Rubrik, SpyCloud, Tanium and Zscaler. Okta revealed on September 2 that it had successfully blocked an attack attempt linked to the Salesloft Drift campaign. The identity security firm stated that enhanced security controls put in place following previous breaches in 2022 and 2023 helped prevent the attack. These measures included restricting inbound IP access to Salesforce, which Okta said stopped the unauthorized access attempt before it could succeed. Nudge Security has created a dashboard which tracks all companies affected by the ‘SalesDrift’ hack and includes the dates of the compromises and links to the security advisories. Initial Salesloft Drift Compromise in March According to a September 7 update by Salesloft, hackers first breached the sales automation platform back in March. The attackers remained dormant while mapping out the company’s internal systems before stealing OAuth tokens from Salesloft customers in June. They then began leveraging those tokens to target customer networks starting in late August. In a later update, also published on September 7, Salesloft indicated that the integration between the Salesloft platform and Salesforce is now restored.
infosecurity-magazine.comSep 8, 2025extracted
⚡ Weekly Recap: Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & More
Cybersecurity never slows down. Every week brings new threats, new vulnerabilities, and new lessons for defenders. For security and IT teams, the challenge is not just keeping up with the news—it’s knowing which risks matter most right now. That’s what this digest is here for: a clear, simple briefing to help you focus where it counts. This week, one story stands out above the rest: the Salesloft–Drift breach, where attackers stole OAuth tokens and accessed Salesforce data from some of the biggest names in tech. It’s a sharp reminder of how fragile integrations can become the weak link in enterprise defenses. Alongside this, we’ll also walk through several high-risk CVEs under active exploitation, the latest moves by advanced threat actors, and fresh insights on making security workflows smarter, not noisier. Each section is designed to give you the essentials—enough to stay informed and prepared, without getting lost in the noise. ⚡ Threat of the Week Salesloft to Take Drift Offline Amid Security Incident — Salesloft announced that it has taken Drift temporarily offline effective September 5, 2025, at 6 a.m. ET, as multiple companies have been caught up in a far-reaching supply chain attack spree targeting the marketing software-as-a-service product, resulting in the mass theft of authentication tokens. "This will provide the fastest path forward to comprehensively review the application and build additional resiliency and security in the system to return the application to full functionality," the company said. "As a result, the Drift chatbot on customer websites will not be available, and Drift will not be accessible. To date, Cloudflare, Google Workspace, PagerDuty, Palo Alto Networks, Proofpoint, SpyCloud, Tanium, Tenable, and Zscaler have confirmed they were impacted by the hack. The activity has been attributed to a threat cluster tracked by Google and Cloudflare as UNC6395 and GRUB1, respectively. Zero Trust + AI: Thrive in the AI Era and Empower Your Workforce It’s no surprise, hackers are using AI in creative ways to compromise users and breach organizations. Zscaler Zero Trust + AI helps defeat ransomware and AI-power attacks today by enabling you to detect and block advanced threats, and discover and classify sensitive data everywhere. Learn more about Zscaler Zero Trust + AI ➝ 🔔 Top News Sitecore Flaw Under Active Exploitation in the Wild — Unknown miscreants are exploiting a configuration vulnerability in multiple Sitecore products to achieve remote code execution via a publicly exposed key and deploy snooping malware on infected machines. The ViewState deserialization vulnerability, CVE-2025-53690, has been used to deploy malware and additional tooling geared toward internal reconnaissance and persistence across one or more compromised environments. The attackers targeted the "/sitecore/blocked.aspx" endpoint, which contains an unauthenticated ViewState form, with HTTP POST requests containing a crafted ViewState payload. Mandiant said it disrupted the intrusion midway, which prevented it from gaining further insights into the attack lifecycle and determining the attackers' motivations. Russian APT28 Deploys "NotDoor" Outlook Backdoor — The Russian state-sponsored hacking group tracked as APT28 has been attributed to a new Microsoft Outlook backdoor called NotDoor (aka GONEPOSTAL) in attacks targeting multiple companies from different sectors in NATO member countries. NotDoor "is a VBA macro for Outlook designed to monitor incoming emails for a specific trigger word," S2 Grupo's LAB52 threat intelligence team said. "When such an email is detected, it enables an attacker to exfiltrate data, upload files, and execute commands on the victim's computer." New GhostRedirector Actor Hacks 65 Windows Servers in Brazil, Thailand, and Vietnam — A previously undocumented threat cluster dubbed GhostRedirector has managed to compromise at least 65 Windows servers primarily located in Brazil, Thailand, and Vietnam. The attacks, per Slovak cybersecurity company ESET, led to the deployment of a passive C++ backdoor called Rungan and a native Internet Information Services (IIS) module codenamed Gamshen. The threat actor is believed to be active since at least August 2024. "While Rungan has the capability of executing commands on a compromised server, the purpose of Gamshen is to provide SEO fraud as-a-service, i.e., to manipulate search engine results, boosting the page ranking of a configured target website," the company said. Google Fixes 2 Actively Exploited Android Flaws — Google has shipped security updates to address 120 security flaws in its Android operating system as part of its monthly fixes for September 2025, including two issues that it said have been exploited in targeted attacks. One of them, CVE-2025-38352, is a privilege escalation vulnerability in the upstream Linux Kernel component. The second shortcoming is a privilege escalation flaw in Android Runtime (CVE-2025-48543). Benoît Sevens of Google's Threat Analysis Group (TAG) has been credited with discovering and reporting the upstream Linux Kernel flaw, suggesting that it may have been abused as part of targeted spyware attacks. Threat Actors Claim to Weaponize HexStrike AI in Real-World Attacks — Threat actors are attempting to leverage a newly released artificial intelligence (AI) offensive security tool called HexStrike AI to exploit recently disclosed security flaws. "This marks a pivotal moment: a tool designed to strengthen defenses has been claimed to be rapidly repurposed into an engine for exploitation, crystallizing earlier concepts into a widely available platform driving real-world attacks," Check Point said. Iranian Hackers Linked to Attacks Targeting European Embassies — An Iran-nexus group conducted a "coordinated" and "multi-wave" spear-phishing campaign targeting the embassies and consulates in Europe and other regions across the world. The activity has been attributed by Israeli cybersecurity company Dream to Iranian-aligned operators connected to broader offensive cyber activity undertaken by a group known as Homeland Justice. "Emails were sent to multiple government recipients worldwide, disguising legitimate diplomatic communication," the company said. "Evidence points toward a broader regional espionage effort aimed at diplomatic and governmental entities during a time of heightened geopolitical tension." 🔥 Trending CVEs Hackers move fast — often exploiting new flaws within hours. A missed update or a single unpatched CVE can open the door to serious damage. Here are this week’s high-risk vulnerabilities making headlines. Review, patch quickly, and stay ahead. This week's list includes — CVE-2025-53690 (SiteCore), CVE-2025-42957 (SAP S/4HANA), CVE-2025-9377 (TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9), CVE-2025-38352 (Linux Kernel/Google Android), CVE-2025-48543 (Google Android), CVE-2025-29927 (Next.js), CVE-2025-52856, CVE-2025-52861 (QNAP QVR), CVE-2025-0309 (Netskope Client for Windows), CVE-2025-21483, CVE-2025-27034 (Qualcomm), CVE-2025-6203 (HashiCorp Vault), CVE-2025-58161 (MobSF), CVE-2025-5931 (Dokan Pro plugin), CVE-2025-53772 (Web Deploy), CVE-2025-9864 (Google Chrome), CVE-2025-9696 (SunPower PVS6), CVE-2025-57833 (Django), CVE-2025-24204 (Apple macOS), CVE-2025-55305 (Electron framework), CVE-2025-53149 (Microsoft Kernel Streaming WOW Thunk Service Driver), CVE-2025-6519, CVE-2025-52549, CVE-2025-52548 (Copeland E2 and E3), CVE-2025-58782 (Apache Jackrabbit), CVE-2025-55190 (Argo CD), CVE-2025-1079, CVE-2025-4613, and a client-side remote code execution (no CVE) (Google Web Designer). 📰 Around the Cyber World New AI Waifu RAT Disclosed — Cybersecurity researchers have discovered a potent Windows-based remote access trojan (RAT) called AI Waifu RAT that uses the power of a large language model to pass commands. "A local agent runs on the victim's machine, listening for commands on a fixed port," a researcher by the name ryingo said. "These commands, originating from the LLM, are passed through a web UI and sent to the local agent as plaintext HTTP requests." The malware specifically targets LLM role-playing communities, capitalizing on their interest in the technology to offer AI characters the ability to read local files for "personalized role-playing" and direct "Arbitrary Code Execution" capabilities. DoJ: "Not all heroes wear capes. Some have YouTube channels" — The U.S. Department of Justice (DoJ) said two YouTube channels named Scammer Payback and Trilogy Media played a crucial role in unmasking and identifying members of a giant scam network that stole more than $65 million from senior citizens. The 28 alleged members of the Chinese organized crime ring allegedly used call centers based in India to call the elderly, posing as government officials, bank employees, and tech support agents. "Once connected, the scammers used scripted lies and psychological manipulation to gain the victims' trust and often remote access to their computers," the DoJ said. "The most common scheme involved convincing victims they had received a mistaken refund and pressuring – or threatening – them to return the supposed excess funds via wire transfer, cash, or gift cards." Those sending cash were instructed to use overnight or express couriers, addressing packages to fake names tied to false IDs. These were sent to short-term rentals in the U.S. used by conspirators, including the indicted defendants, to collect the fraud proceeds. The network has operated out of Southern California since 2019. Analysis of BadSuccessor Patch — Microsoft, as part of its August 2025 Patch Tuesday update, addressed a security flaw called BadSuccessor (CVE-2025-53779) that abused a loophole in dMSA, causing the Key Distribution Center (KDC) to treat a dMSA linked to any account in Active Directory as the successor during authentication. As a result, an attacker could create a dMSA in an Organizational Unit (OU) and link it to any target — even domain controllers, Domain Admins, Protected Users, or accounts marked "sensitive and cannot be delegated" – and compromise them. An analysis of the patch has revealed that patch enforcement was implemented in the KDC's validation. "The attribute can still be written, but the KDC won't honor it unless the pairing looks like a legitimate migration," Akamai security researcher Yuval Gordon said. "Although the vulnerability can be patched, BadSuccessor still lives on as a technique; that is, the KDC’s verification removes the pre-patch escalation path, but doesn't mitigate the entire problem. Because the patch didn't introduce any protection to the link attribute, an attacker can still inherit another account by linking a controlled dMSA and a target account." Phishers Pivot to Ramp and Dump Scheme — Cybercriminal groups advertising sophisticated phishing kits that convert stolen card data into mobile wallets have shifted their focus to targeting customers of brokerage services and using compromised brokerage accounts to manipulate the prices of foreign stocks as part of what's called a ramp and dump scheme. Popular C2 Frameworks Exploited by Threat Actors — Sliver, Havoc, Metasploit, Mythic, Brute Ratel C4, and Cobalt Strike (in that order) have emerged as the most frequently used command-and-control (C2) frameworks in malicious attacks in Q2 2025, per data from Kaspersky. "Attackers are increasingly customizing their C2 agents to automate malicious activities and hinder detection," the company said. The development came as the majority (53%) of attributed vulnerability exploits in the first half of 2025 were conducted by state-sponsored actors for strategic, geopolitical purposes, according to Recorded Future's Insikt Group. In all, 23,667 CVEs were published in H1 2025, a 16% increase compared to H1 2024. Attackers actively exploited 161 vulnerabilities, and 42% of those exploited flaws had public PoC exploits. Fake PDF Converters Deliver JSCoreRunner macOS Malware — Apps posing as PDF converters are being used to deliver malware called JSCoreRunner. Once downloaded from sites like fileripple[.]com, the malware establishes connections with a remote server and hijacks a user's Chrome browser by modifying its search engine settings to default to a fraudulent search provider, thereby tracking user searches and redirecting them to bogus sites, further exposing them to data and financial theft, per Mosyle. The attack unfolds over two stages: The initial package (whose signature has since been revoked by Apple), which deploys an unsigned secondary payload from the same domain that, in turn, executes the main malicious payload. Copeland Releases Fixes for Frostbyte10 Flaws — American tech company Copeland has released a firmware update to fix ten vulnerabilities in Copeland E2 and E3 controllers. The chips are used to manage energy efficiency inside HVAC and refrigeration systems. The ten vulnerabilities have been collectively named Frostbyte10. "The flaws discovered could have allowed unauthorized actors to remotely manipulate parameters, disable systems, execute remote code, or gain unauthorized access to sensitive operational data," Armis said. "When combined and exploited, these vulnerabilities can result in unauthenticated remote code execution with root privileges." The most severe of the flaws is CVE-2025-6519, a case of a default admin user "ONEDAY" with a daily generated password that can be predictably generated. In a hypothetical attack scenario, an attacker could chain CVE-2025-6519 and CVE-2025-52549 with CVE-2025-52548, which can enable SSH and Shellinabox access via a hidden API call, to facilitate remote execution of arbitrary commands on the underlying operating system. Over 1,000 Ollama Servers Exposed — A new study from Cisco found over 1,100 exposed Ollama servers, with approximately 20% actively hosting models susceptible to unauthorized access. Out of the 1,139 exposed servers, 214 were found to be actively hosting and responding to requests with live models—accounting for approximately 18.8% of the total scanned population, with Mistral and LLaMA representing the most frequently encountered deployments. The remaining 80% of detected servers, while reachable via unauthenticated interfaces, did not have any models instantiated. Although dormant, these servers remain susceptible to exploitation via unauthorized model uploads or configuration manipulation. The findings "highlight the urgent need for security baselines in LLM deployments and provide a practical foundation for future research into LLM threat surface monitoring," the company said. Tycoon Phishing Kit Evolves — The Tycoon phishing kit has been updated to support URL-encoding techniques to hide malicious links embedded in fake voicemail messages to bypass email security checks. Attackers have also been observed using the Redundant Protocol Prefix technique for similar reasons. "This involves crafting a URL that is only partially hyperlinked or that contains invalid elements — such as two 'https' or no '//' — to hide the real destination of the link while ensuring the active part looks benign and legitimate and doesn't arouse suspicion among targets or their browser controls," Barracuda said. "Another trick is using the '@' symbol in a web address. Everything before the '@' is treated as 'user info' by browsers, so attackers put something that looks reputable and trustworthy in this part, such as 'office365.' The link’s actual destination comes after the '@.'" U.S. State Department Offers Up to $10M for Russian Hackers — The U.S. Department of State is offering a bounty of up to $10 million for information on three Russian Federal Security Service (FSB) officers involved in cyberattacks targeting U.S. critical infrastructure organizations on behalf of the Russian government. The three individuals, Marat Valeryevich Tyukov, Mikhail Mikhailovich Gavrilov, and Pavel Aleksandrovich Akulov, are part of the FSB's Center 16 or Military Unit 71330, which is tracked as Berserk Bear, Blue Kraken, Crouching Yeti, Dragonfly, Koala Team, and Static Tundra. They have been accused of targeting 500 energy companies in 135 countries. In March 2022, the three FBS officers were also charged for their involvement in a campaign that took place between 2012 and 2017, targeting U.S. government agencies. XWorm Malware Uses Sneaky Methods to Evade Detection — A new XWorm malware campaign is using deceptive and intricate methods to evade detection and increase the success rate of the malware. "The XWorm malware infection chain has evolved to include additional techniques beyond traditional email-based attacks," Trellix said. "While email and .LNK files remain common initial access vectors, XWorm now also leverages legitimate-looking .EXE filenames to disguise itself as harmless applications, exploiting user and system trust." The attack chain uses LNK files to initiate a complex infection. Executing the .LNK triggers malicious PowerShell commands that deliver a .TXT file and download a deceptively-named binary called "discord.exe." The executable then drops "main.exe" and "system32.exe," with the latter being the XWorm malware payload. "Main.exe," on the other hand, is responsible for disabling the Windows Firewall and checking for the presence of -third-party security applications. XWorm, besides meticulously conducting reconnaissance to acquire a comprehensive profile of the machine, runs anti-analysis checks to ascertain the presence of a virtualized environment, and, if so, ceases execution. It also incorporates backdoor functionality by contacting an external server to execute commands, shut down the system, download files, open URLs, and launch DDoS attacks. Recent campaigns distributing the malware through a new crypter-as-a-service offering known as Ghost Crypt. "Ghost Crypt delivers a zipped archive to the victim containing a PDF Reader application, a DLL, and a PDF file," Kroll said. "When the user opens the PDF, the malicious DLL is side-loaded, initiating the malware execution." The PDF Reader application is HaiHaiSoft PDF Reader, which is known to have a DLL side-loading vulnerability, previously exploited to deliver Remcos RAT, NodeStealer, and PureRAT. 2 E-Crime Groups Use Stealerium Stealer in New Campaigns — Two different cybercriminal groups, TA2715 and TA2536, both of which favored Snake Keylogger, have conducted phishing campaigns in May 2025, delivering an open-source information stealer called Stealerium (or variants of it). "The observed emails impersonated many different organizations, including charitable foundations, banks, courts, and document services, which are common themes in e-crime lures," Proofpoint said. "Subject lines typically conveyed urgency or financial relevance, including 'Payment Due,' 'Court Summons,' and 'Donation Invoice.'" Czechia Issues Warning Against Chinese Tech in Critical Infrastructure — NÚKIB, the Czech Republic's cybersecurity agency, has issued a bulletin regarding the threat posed by technology systems that transfer data to, or are remotely managed from, China. "Current critical infrastructure systems are increasingly dependent on storing and processing data in cloud repositories and on network connectivity enabling remote operation and updates," the agency warned. "In practice, this means that technology solution providers can significantly influence the operation of critical infrastructure and/or access important data, making trust in the reliability of the provider absolutely crucial." Google Chrome 140 Gains Support for Cookie Prefixes — Google has released version 140 of its Chrome browser with support for a new security feature designed to protect server-set cookies from client-side modifications. Called a cookie prefix, it involves adding a piece of text before the names of a browser's cookies. "In some cases, it's important to distinguish on the server side between cookies set by the server and those set by the client. One such case involves cookies normally always set by the server," Google said. "However, unexpected code (such as an XSS exploit, a malicious extension, or a commit from a confused developer) might set them on the client. This proposal adds a signal that lets servers make such a distinction. More specifically, it defines the Http and HostHttp prefixes, which ensure a cookie is not set on the client side using script." New Ransomware Strains Detailed — A new ransomware group called LunaLock has hacked an art-commissioning portal called Artists&Clients and is extorting its owners and artists by threatening to submit the stolen artwork to train artificial intelligence (AI) models unless it pays a $50,000 ransom. Another newly observed ransomware crew is Obscura, which was first observed by Huntress on August 29, 2025. The Go-based ransomware variant attempts to terminate over 120 processes commonly tied to security tools like Microsoft Defender, CrowdStrike, and SentinelOne. E.U. Court Backs Data Transfer Deal Agreed by U.S. and E.U. — The General Court of the Court of Justice of the European Union has dismissed a lawsuit that sought to annul the E.U. and U.S. Data Privacy Framework. The court ruled that the new treaty and the US adequately safeguard the personal data of E.U. citizens. The lawsuit alleged that the U.S. Data Protection Review Court (DPRC), which is housed inside the Department of Justice and has been historically seen as a bulwark for checking U.S. data surveillance activities, is not sufficiently independent and does not adequately shield Europeans from bulk data collection by U.S. intelligence agencies. Microsoft to Move to Phase 2 of MFA Enforcement in October 2025 — Microsoft said it has been enforcing multi-factor authentication (MFA) for Azure Portal sign-ins across all tenants since March 2025. "We are proud to announce that multi-factor enforcement for Azure Portal sign-ins was rolled out for 100% of Azure tenants in March 2025," the company said. "By enforcing MFA for Azure sign-ins, we aim to provide you with the best protection against cyber threats as part of Microsoft's commitment to enhancing security for all customers, taking one step closer to a more secure future." The next phase of MFA requirement is scheduled to start October 1, 2025, mandating the use of MFA for users performing Azure resource management operations through Azure Command-Line Interface (CLI), Azure PowerShell, Azure Mobile App, REST APIs, Azure Software Development Kit (SDK) client libraries, and Infrastructure as Code (IaC) tools. Surge in Scanning Activity Targeting Cisco ASA — GreyNoise said it detected two scanning surges against Cisco Adaptive Security Appliance (ASA) devices on August 22 and 26, 2025, with the first wave originating from over 25,100 IP addresses mainly located in Brazil, Argentina, and the U.S. The second spike repeated ASA probing, with subsets hitting both IOS Telnet/SSH and ASA software personas. The activity targeted the U.S., the U.K., and Germany. LinkedIn Expands Verification to Combat Job-Themed Scams — Microsoft-owned professional social network unveiled new measures to strengthen trust and ensure that users are interacting with people who "they say they are." This includes verified Premium Company Pages, requiring recruiters to verify their workplace on their profile, and workplace verification requirements for high-level titles such as Executive Director, Managing Director, and Vice President to tackle impersonation. The changes are an effort to prevent scammers from posing as company employees or recruiters and reaching out to prospective targets with fake job opportunities – a technique pioneered by North Korean hackers. Hotelier Accounts Targeted in Malvertising and Phishing Campaign — A large-scale phishing campaign has impersonated at least 13 service providers that specialize in hotels and vacation rentals. "In these attacks, targeted users are lured to highly deceptive phishing sites using malicious search engine advertisements, particularly sponsored ads on platforms like Google Search," Okta said. "The attacks leverage convincing fake login pages and social engineering tactics to bypass security controls and exploit user trust." It's assessed that the end goal of the campaign is to compromise accounts for cloud-based property management and guest messaging platforms. DamageLib Emerges After XSS Forum Takedown — A new cybercrime forum called DamageLib has grown dramatically, attracting over 33,000 users following the arrest of XSS[.]is admin Toha back in July 2025. While XSS remains online, speculations are abound that it could be a law enforcement honeypot, breeding mistrust among cybercriminals. "Exploit forum traffic surged almost 24% during the XSS turmoil as actors sought alternatives, while XSS visits plummeted," KELA said. "As of August 27, 2025, DamageLib counted 33,487 users -- nearly 66% of XSS's 50,853 members. But engagement lagged: only 248 threads and 3,107 posts in its first month, compared to over 14,400 messages on XSS in the month before the seizure." GhostAction Supply Chain Attack Steals 3,325 Secrets — A massive supply chain attack dubbed GhostAction has allowed attackers to inject a malicious GitHub workflow named "Github Actions Security" to exfiltrate 3,325 secrets, including PyPI, npm, and DockerHub tokens via HTTP POST requests to a remote attacker-controlled endpoint ("bold-dhawan.45-139-104-115.plesk[.]page"). The activity, which allowed the workflows to be triggered automatically on 'push' or manual dispatch, affected 327 GitHub users across 817 repositories. Some of the workflow commits were pushed by a user named "Grommash9," which is no longer accessible. "Over the weekend, we had discussions with developers targeted by the attack and the initial vector is still unclear, but could be related to GitHub tokens leaks," Guillaume Valadon, cybersecurity researcher at GitGuardian, told The Hacker News. "As a prevention measure, they revoked all of their GitHub tokens as well as secrets accessible from their GitHub Actions." New Campaign Abuses Simplified AI to Steal Microsoft 365 Credentials — A new phishing campaign has been observed hosting fake pages under the legitimate Simplified AI domain in a bid to evade detection and blend in with regular enterprise traffic. "By impersonating an executive from a global pharmaceutical distributor, the threat actors delivered a password-protected PDF that appeared legitimate," Cato Networks said. "Once opened, the file redirected the victim to Simplified AI’s website, but instead of generating content, the site became a launchpad to a fake Microsoft 365 login portal designed to harvest enterprise credentials." Japan, South Korea, and the U.S. Take Aim at North Korean IT Worker Scam — Japan, South Korea, and the U.S. joined hands to fight against the growing threat of North Korean threat actors posing as IT workers to embed themselves in organizations throughout Asia and globally and generate revenue to fund its unlawful weapons of mass destruction (WMD) and ballistic missile programs. "They take advantage of existing demands for advanced IT skills to obtain freelance employment contracts from an expanding number of target clients throughout the world, including in North America, Europe, and East Asia," the countries said in a joint statement. "North Korean IT workers themselves are also highly likely to be involved in malicious cyber activities, particularly in the blockchain industries. Hiring, supporting, or outsourcing work to North Korean IT workers increasingly poses serious risks, ranging from theft of intellectual property, data, and funds to reputational harm and legal consequences." New AI-Powered Android Vulnerability Discovery and Validation Tool — Computer scientists affiliated with Nanjing University in China and The University of Sydney in Australia said that they've developed an AI vulnerability identification system called A2 that emulates the way human bug hunters go about discovering flaws, marking a step forward for automated security analysis. According to the study, A2 "validates Android vulnerabilities through two complementary phases: (i) Agentic Vulnerability Discovery, which reasons about application security by combining semantic understanding with traditional security tools; and (ii) Agentic Vulnerability Validation, which systematically validates vulnerabilities across Android's multi-modal attack surface-UI interactions, inter-component communication, file system operations, and cryptographic computations." A2 builds upon A1, an agentic system that transforms any LLM into an end-to-end exploit generator. Spotify DM Feature Carries Doxxing Risks — Music streaming service Spotify, last month, announced a new messaging feature for sharing music with friends. But reports are now emerging on Reddit that it's surfacing as "suggested friends," people with whom users may have shared Spotify links in the past on other social media platforms, potentially revealing their real names in the process. This is made possible by means of a unique "si" parameter in Spotify links that serves as referral information. Spear-Phishing Campaign Targets C-Suite for Credential Theft — A sophisticated spear-phishing campaign has targeted senior employees, particularly those in C-Suite and leadership positions, to steal their credentials using email messages with salary-themed lures or fake OneDrive document-sharing notifications. "Actors behind this campaign are leveraging tailored emails that impersonate internal HR communications, via a shared document in OneDrive, to trick recipients into entering corporate credentials," Stripe OLT said. "Emails are sent via Amazon Simple Email Service (SES) infrastructure. The actor is rotating between many sending domains and subdomains to evade detection." As many as 80 domains have been identified as part of this campaign. Attackers Attempt to Exploit WDAC Technique — In December 2024, researchers Jonathan Beierle and Logan Goins demonstrated a novel technique that leverages a malicious Windows Defender Application Control (WDAC) policy to block security solutions such as Endpoint Detection and Response (EDR) sensors following a system reboot using a custom tool codenamed Krueger. Since then, it has emerged that threat actors have incorporated the method into their attack arsenal to disable security solutions using WDAC policies. It has also led to the discovery of a new malware strain dubbed DreamDemon that uses WDAC to neutralize antivirus programs. It contains an embedded WDAC policy, which is then dropped onto disk and hidden," Beierle said. "In certain cases, DreamDemon will also change the time that the policy was created in an attempt to avoid detection." New NBMiner Cryptojacking Malware Detected — Cybersecurity researchers have discovered a new campaign that leverages a PowerShell script to drop an AutoIt loader used to deliver a cryptocurrency miner called NBMiner from an external server. Initial access to the system is accomplished by means of a drive-by compromise. "The program includes several evasion measures," Darktrace said. "It performs anti-sandboxing by sleeping to delay analysis and terminates sigverif.exe (File Signature Verification). It checks for installed antivirus products and continues only when Windows Defender is the sole protection. It also verifies whether the current user has administrative rights. If not, it attempts a User Account Control (UAC) bypass via Fodhelper to silently elevate and execute its payload without prompting the user." New Campaign Uses Custom GPTs for Brand Impersonation and Phishing — Threat actors are abusing custom features on trusted AI platforms like OpenAI ChatGPT to create malicious "customer support" chatbots that impersonate legitimate brands. These custom GPTs are surfaced on Google Search results, tricking users into taking malicious actions under the guise of a helpful chatbot, underscoring how AI tools can be misused within a broader social engineering chain. "This method introduces a new threat vector: platform-hosted social engineering through trusted AI interfaces," Doppel said. "Several publicly available Custom GPTs have been observed impersonating well-known companies." The attacks can lead to theft of sensitive information, malware delivery, and damage the reputation of legitimate brands. The development is part of a larger trend where cybercriminals abuse AI tools, including impersonation fraud via deepfakes, AI-assisted scam call centers, AI-powered mailers and spam tools, malicious tool development, and unrestricted and self-hosted generative AI chatbots that can craft phishing kits, fake websites; create content for romance or investment scams; develop malware; and assist with vulnerability reconnaissance and exploit chains. McDonald's Poland Fined for Leaking Personal Data — Poland's data protection agency fined McDonald's Poland nearly €4 million for leaking employee personal data, violating GDPR data privacy protections. The incident occurred at a partner company that managed employee work schedules. Personal data such as names, passport numbers, positions, and work schedules were left exposed on the internet through an open directory. This is the second-largest GDPR fine handed out by Polish authorities after fining the country's postal service €6.3 million earlier this year. In related news, vulnerabilities in the McDonald's chatbot recruitment platform McHire exposed over 64 million job applications across the U.S., security researchers Ian Carroll and Sam Curry discovered. The chatbot was created by Paradox.ai, which did not remove the default credentials for a test account (username 123456, password 123456) and failed to secure an endpoint that allowed access to the chat interactions of every applicant. There is no evidence that the test account was ever exploited in a malicious context. A separate set of security issues has also been discovered in the fast-food giant's partner and employee portals that exposed sensitive data such as API keys and enabled unauthorized access to make changes to a franchise owner's website. The issues, according to BobdaHacker, have since been patched. New Influence Operations Discovered — Cybersecurity company Recorded Future flagged two large-scale, state-aligned influence operation networks supporting India and Pakistan during the India-Pakistan conflict of April and May 2025. These influence networks have been codenamed Hidden Charkha (pro-India) and Khyber Defender (pro-Pakistan). "These networks are very likely motivated by patriotism and are almost certainly aligned with India's and Pakistan's domestic and foreign policy objectives, respectively," Recorded Future said. "Each network consistently attempted to frame India or Pakistan, respectively, as maintaining superior technological and military capabilities – and therefore the implied ability for each respective country to exercise tactical restraint – as proof of having the moral high ground, and hence having domestic and international support." Both the campaigns were largely unsuccessful in shaping public opinion, given the lack of organic engagement on social media. A second influence operation involves multiple Russia-linked networks, such as Operation Overload, Operation Undercut, Foundation to Battle Injustice, and Portal Kombat, seeking to destabilize the elections and derail Moldova's European Union (E.U.) accession. Besides attempting to frame the current Moldova leadership as corrupt and counter to Moldova's interests, the activity portrays "Moldova's further integration with the E.U. as disastrous for its economic future and sovereignty, and Moldova as a whole as at odds with European standards and values." The campaign has not achieved any substantial success in shaping public opinion, Recorded Future added. Massive IPTV Piracy Network Uncovered — A large Internet Protocol Television (IPTV) piracy network spanning more than 1,100 domains and over 10,000 IP addresses has been discovered hosting pirated content, illegally restreaming licensed channels, and engaging in subscription fraud. Active for several years, more than 20 major brands have been affected, including: Prime Video, Bein Sports, Disney Plus, NPO Plus, Formula 1, HBO, Viaplay, Videoland, Discovery Channel, Ziggo Sports, Netflix, Apple TV, Hulu, NBA, RMC Sport, Premier League, Champions League, Sky Sports, NHL, WWE, and UFC. Silent Push said it identified a company named XuiOne that's involved in profiting from hosting pirated content. XuiOne is believed to share connections with Stalker_Portal, another well-known open-source IPTV project that has been around since 2013. These services are advertised in the form of Android apps, with the domains distributed via Facebook groups and Imgur. Security Analysis of WhatsApp Message Summarization — NCC Group has published an in-depth analysis of WhatsApp's AI-powered Message Summarization feature, which was announced by the messaging platform in June 2025. In all, the assessment discovered 21 findings, 16 of which were fixed by WhatsApp. This included three notable weaknesses: The hypervisor could have assigned network interfaces to the CVM through which private data could be exfiltrated; any old Confidential Virtual Machine (CVM) image with known vulnerabilities could have been indefinitely used by an attacker; and the ability to serve malicious key configurations to WhatsApp clients could have allowed Meta to violate privacy and non-targetability assurances. Indirect Prompt Injection via Log Files — Large language models (LLMs) used in a security context can be deceived by specially crafted events and log files injected with hidden prompts to execute malicious actions when they are parsed by AI agents. 🎥 Cybersecurity Webinars From Blind Spots to Clarity: Why Code-to-Cloud Visibility Defines Modern AppSec — Most security programs know their risks—but not where they truly begin or how they spread. That gap between code and cloud is costing teams time, ownership, and resilience. This webinar shows how code-to-cloud visibility closes that gap by giving developers, DevOps, and security a shared view of vulnerabilities, misconfigurations, and runtime exposure. The result? Less noise, faster fixes, and stronger protection for the applications your business depends on. Shadow AI Agents: The Hidden Risk Driving Enterprise Blind Spots — AI Agents are no longer futuristic—they’re already embedded in your workflows, processes, and platforms. The problem? Many of them are invisible to governance, fueled by unchecked non-human identities that create a growing attack surface. Shadow AI doesn’t just add complexity; it multiplies risk with every click. This webinar unpacks where these agents are hiding, how to spot them before attackers do, and what steps you can take to bring them under control without slowing innovation. AI + Quantum 2.0: The Double Disruption Security Leaders Can’t Ignore — The next cybersecurity crisis won’t come from AI or quantum alone—it will come from their convergence. As quantum breakthroughs accelerate and AI drives automation at scale, the attack surface for sensitive industries is expanding faster than most defenses can keep up. This panel brings together leading voices from research, government, and industry to unpack what Quantum 2.0 means for security, why quantum-safe cryptography and AI resilience must go hand-in-hand, and how decision-makers can start building trust and resilience before adversaries weaponize these technologies. 🔧 Cybersecurity Tools MeetC2 — It is a clever proof-of-concept C2 framework that uses Google Calendar—yes, the same calendar your team uses every day—as a hidden command channel between an operator and a compromised endpoint. By polling for events and embedding commands into calendar items via Google’s trusted APIs (oauth2.googleapis.com, www.googleapis.com), it shows how legitimate SaaS platforms can be repurposed for covert operations. Security teams can use MeetC2 in controlled purple-team exercises to sharpen detection logic around unusual calendar API usage, validate logging and telemetry effectiveness, and fine-tune safeguards against stealthy cloud-based C2 strategies. In short, it equips defenders with a lightweight, highly relevant testbed to simulate and proactively defend against next-gen adversarial tradecraft. thermoptic – It is an advanced HTTP proxy that cloaks low-level clients like curl to appear indistinguishable from a full Chrome/Chromium browser at the network fingerprinting layer. Modern WAFs and anti-bot systems increasingly rely on JA4+ signatures—tracking TLS, HTTP, TCP, and certificate fingerprints—to block scraping tools or detect when users switch from browsers to scripts. By routing requests through a containerized Chrome instance, thermoptic ensures fingerprints match real browsers byte-for-byte, even across multiple layers. For defenders, this is a powerful way to test detection pipelines against sophisticated evasion tactics, validate JA4+ logging visibility, and explore how adversaries might blend into legitimate browser traffic. For ethical researchers and red teams, thermoptic offers a realistic, open-source platform to simulate stealthy scraping or covert traffic—helping security teams move from theory to resilience in the fingerprinting arms race. Disclaimer: The tools featured here are provided strictly for educational and research purposes. They have not undergone full security audits, and their behavior may introduce risks if misused. Before experimenting, carefully review the source code, test only in controlled environments, and apply appropriate safeguards. Always ensure your usage aligns with ethical guidelines, legal requirements, and organizational policies. 🔒 Tip of the Week Lock Down Your Router Before Hackers Ever Get a Foot in the Door — Most people think of router security as just “change the password” or “disable UPnP.” But attackers are getting far more creative: from rerouting internet traffic through fake BGP paths, to hijacking cloud services that talk directly to your router. The best defense? A layered approach that closes those doors before compromise happens. Here are 3 advanced but practical moves you can start today: Protect Your Internet Route with RPKI Why it matters: Attackers sometimes hijack internet routes (BGP attacks) to spy on or reroute your traffic. Try this: Even if you’re not running a big enterprise, you can check if your ISP supports RPKI (Resource Public Key Infrastructure) using the free Is BGP Safe Yet? tool. If your provider isn’t secured, ask them about RPKI. Use Short-Lived Access Keys Instead of Static Passwords Why it matters: A single stolen router password can let attackers in for years. Try this: If your router supports it (OpenWRT, pfSense, MikroTik), set up SSH access with keys instead of passwords. For home or small office users, tools like YubiKey can generate one-time login tokens, so even if your PC is hacked, the router stays safe. Control Who Can Even Knock on the Door Why it matters: Most router compromises happen because attackers can reach the management port from the internet. Try this: Instead of leaving management open, use Single Packet Authorization (SPA) with a free tool like fwknop. It hides your router’s management ports until you send a secret “knock,” making your router invisible to scanners. Think of your router as the “front door to your digital house.” With these tools, you’re not just locking it — you’re making sure attackers don’t even know where the door is, and even if they do, the key changes every day. Conclusion That wraps up this week’s briefing, but the story never really ends. New exploits, new tactics, and new risks are already on the horizon—and we’ll be here to break them down for you. Until then, stay sharp, stay curious, and remember: one clear insight can make all the difference in stopping the next attack.
thehackernews.comSep 8, 2025extracted
Week in review: Several companies affected by the Salesloft Drift breach, Sitecore 0-day vulnerability
Week in review: Several companies affected by the Salesloft Drift breach, Sitecore 0-day vulnerability Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zscaler, Palo Alto Networks, SpyCloud among the affected by Salesloft Drift breach In the wake of last week’s revelation of a breach at Salesloft by a group tracked by Google as UNC6395, several companies – including Zscaler, Palo Alto Networks, PagerDuty, Tanium, and SpyCloud – have confirmed their Salesforce instances were accessed. Sitecore zero-day vulnerability exploited by attackers (CVE-2025-53690) A threat actor is leveraging a zero-day vulnerability (CVE-2025-53690) and an exposed sample ASP.NET machine key to breach internet-facing, on-premises deployments of several Sitecore solutions, Mandiant has revealed. macOS vulnerability allowed Keychain and iOS app decryption without a password At Nullcon Berlin, a researcher disclosed a macOS vulnerability (CVE-2025-24204) that allowed attackers to read the memory of any process, even with System Integrity Protection (SIP) enabled. Can AI agents catch what your SOC misses? A new research project called NetMoniAI shows how AI agents might reshape network monitoring and security. Developed by a team at Texas Tech University, the framework brings together two ideas: distributed monitoring at the edge and AI-driven analysis at the center. BruteForceAI: Free AI-powered login brute force tool BruteForceAI is a penetration testing tool that uses LLMs to improve the way brute-force attacks are carried out. Instead of relying on manual setup, the tool can analyze HTML content, detect login form selectors, and prepare the attack process automatically. LinkedIn expands company verification, mandates workplace checks for certain roles LinkedIn is rolling out new verification rules to make it easier to confirm that people and companies are who they claim to be. The company will now require workplace verification when someone adds or updates a leadership or recruiter role on their profile. The goal is to cut down on fake accounts and scams while helping businesses, recruiters, and professionals build credibility. Cloudflare confirms data breach linked to Salesloft Drift supply chain compromise Cloudflare has also been affected by the Salesloft Drift breach, the US web infrastructure and security company confirmed on Tuesday, and the attackers got their hands on 104 Cloudflare API tokens. Google fixes actively exploited Android vulnerabilities (CVE-2025-48543, CVE-2025-38352) Google has provided fixes for over 100 Android vulnerabilities, including CVE-2025-48543 and CVE-2025-38352, which “may be under limited, targeted exploitation.” Stealthy attack serves poisoned web pages only to AI agents AI agents can be tricked into covertly performing malicious actions by websites that are hidden from regular users’ view, JFrog AI architect Shaked Zychlinski has found. Attackers are exploiting critical SAP S/4HANA vulnerability (CVE-2025-42957) A critical vulnerability (CVE-2025-42957) in SAP S/4HANA enterprise resource planning software is being exploited by attackers “to a limited extent”, the Dutch National Cyber Security Center (NCSC NL) has warned on Friday. How gaming experience can help with a cybersecurity career Many people might not think that playing video games could help build a career in cybersecurity. Yet the skills gained through gaming, even if they don’t seem relevant at first, can be useful in the field. How to reclaim control over your online shopping data Online shopping is convenient, saves time, and everything is just a click away. But how often do we stop to think about what happens to the data we leave behind, or the risks that might come with it? Detecting danger: EASM in the modern security stack The challenge for security professionals isn’t just defeating threats, it’s finding your vulnerabilities in the first place. That’s where External Attack Surface Management (EASM) tools come in. September 2025 Patch Tuesday forecast: The CVE matrix The CVE has become not only the designator around which we organize and rally, but also the resolution of the CVE is the standard against which we are measured. What the GitGuardian secrets sprawl report reveals about leaked credentials In this Help Net Security video, Dwayne McDaniel, Senior Developer Advocate at GitGuardian, presents findings from The State of Secrets Sprawl 2025. Five habits of highly secure development teams In this Help Net Security video, Brendon Collins, Principal Consultant at Optiv, explores how organizations can embed security and privacy into the software development lifecycle (SDLC) from the very start. CyberFlex: Flexible Pen testing as a Service with EASM CyberFlex is an Outpost24 solution that combines the strengths of its Pen-testing-as-a-Service (PTaaS) and External Attack Surface Management (EASM) solutions. Customers benefit from continuous coverage of their entire attack application attack surface, while enjoying a flexible consumption model. Smart ways CISOs can do more with less In this Help Net Security video, Jill Knesek, CISO at BlackLine, shares practical strategies for CISOs navigating tighter budgets. From maximizing existing tools and vendor partnerships to leveraging AI and making smart investments, she offers actionable advice for maintaining strong security without overspending. GenAI is fueling smarter fraud, but broken teamwork is the real problem More than 80 percent of large U.S. companies were targeted by socially engineered fraud in the past year, according to Trustmi’s 2025 Socially Engineered Fraud & Risk Report. Nearly half of those organizations reported a direct financial loss, with many incidents costing more than $500,000. Cybersecurity signals: Connecting controls and incident outcomes There is constant pressure on security leaders to decide which controls deserve the most attention and budget. A new study offers evidence on which measures are most closely linked to lower breach risk and how organizations should think about deploying them. Boards are being told to rethink their role in cybersecurity A new report from Google Cloud’s Office of the CISO lays out three areas where board oversight is becoming especially important: ransomware, cyber-enabled fraud, and the intersection of innovation and cybersecurity. Complexity and AI put identity protection to the test Identity has become a core pillar of cybersecurity strategy. Remote work, cloud-first adoption, and distributed supply chains have moved identity from “a tactical IT consideration to a strategic pillar of cybersecurity,” according to Cisco Duo’s 2025 State of Identity Security report. Attackers are turning Salesforce trust into their biggest weapon Salesforce has become a major target for attackers in 2025, according to new WithSecure research into threats affecting customer relationship management (CRM) platforms. Cutting through CVE noise with real-world threat signals CISOs are dealing with an overload of vulnerability data. Each year brings tens of thousands of new CVEs, yet only a small fraction ever become weaponized. Teams often fall back on CVSS scores, which label thousands of flaws as “high” or “critical” but fail to show which ones actually matter. The result is wasted effort, long patch backlogs, and exploitable weaknesses left in production. New threat group uses custom tools to hijack search results ESET Research has identified a new threat group called GhostRedirector. In June 2025, this group broke into at least 65 Windows servers, mostly in Brazil, Thailand, Vietnam, and the United States. File security risks rise as insiders, malware, and AI challenges converge Breaches tied to file access are happening often, and the costs add up quickly. Many organizations have faced multiple file-related incidents over the last two years, with financial losses stretching into the millions. The fallout often includes stolen customer data, reduced productivity, and exposure of intellectual property. AIDEFEND: Free AI defense framework AIDEFEND (Artificial Intelligence Defense Framework) is an open knowledge base dedicated to AI security, providing defensive countermeasures and best practices to help security pros safeguard AI and machine learning systems. KillChainGraph: Researchers test machine learning framework for mapping attacker behavior A team of researchers from Frondeur Labs, DistributedApps.ai, and OWASP has developed a new machine learning framework designed to help defenders anticipate attacker behavior across the stages of the Cyber Kill Chain. The work explores how machine learning models can forecast adversary techniques and generate structured attack paths. Cybersecurity jobs available right now: September 2, 2025 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.
helpnetsecurity.comSep 7, 2025extracted
More Cybersecurity Firms Hit by Salesforce-Salesloft Drift Breach
Cybersecurity firms Proofpoint, SpyCloud, Tanium, and Tenable have confirmed that information in their Salesforce instances was compromised as part of the recent Salesforce–Salesloft Drift attack. The campaign was publicly disclosed on August 26, when Google’s threat intelligence team reported that a threat actor tracked as UNC6395 exported large volumes of data using compromised OAuth tokens for the third-party AI chatbot Salesloft Drift. The attackers, Google said, exploited the Salesforce-Salesloft Drift integration to steal data pertaining to hundreds of organizations, targeting sensitive information such as AWS access keys, passwords, and Snowflake-related access tokens. Initially believed to only impact organizations that used the Drift integration, the campaign was later found to have affected other Salesforce customers as well. On August 28, Google revealed that Workspace customers were affected, and security firms Cloudflare, Palo Alto Networks, and Zscaler disclosed impact as well shortly after. Overall, the attack is estimated to have hit over 700 organizations, and Proofpoint, SpyCloud, Tanium, and Tenable have confirmed being affected. Proofpoint revealed that the attackers accessed its Salesforce tenant through the compromised Drift integration, and that they viewed certain information stored in it. “At this time, there is no evidence that this supply chain incident affected Proofpoint’s software, services, security products, customer-protected data, or internal corporate network,” the company said. SpyCloud, which was previously a Salesloft Drift customer, announced that standard customer relationship management fields were compromised in the attack. “Consumer data is not believed to have been accessed. We notified our customers last week that data relating to their relationship with SpyCloud was exposed through this Salesloft Drift incident,” SpyCloud said. Tanium confirmed that the attackers exploited the Salesloft Drift integration to access data in its Salesforce instance, and that information such as names, email addresses, phone numbers, and region/location references was compromised. “We can confirm definitively that unauthorized access was limited to our Salesforce data and no access to the Tanium platform or any other internal systems or resources took place,” Tanium noted. Tenable revealed that support case information, including subject lines, initial descriptions, and business contact details, such as names, phone numbers, business email addresses, and regional/location references, was compromised in the attack. The company also noted that it had no evidence that the stolen information had been misused, adding that it took all the necessary steps to address the issue, including rotating credentials, removing the application, securing its systems, and monitoring the Salesforce instance. Related: Impostor Uses AI to Impersonate Rubio and Contact Foreign and US Officials Related: How to Implement Impactful Security Benchmarks for Software Development Teams Related: The AI Convention: Lofty Goals, Legal Loopholes, and National Security Caveats Related: Achieving “Frictionless Defense” in the Age of Hybrid Networks
securityweek.comSep 5, 2025extracted
Cloudflare confirms data breach linked to Salesloft Drift supply chain compromise
Cloudflare confirms data breach linked to Salesloft Drift supply chain compromise Cloudflare has also been affected by the Salesloft Drift breach, the US web infrastructure and security company confirmed on Tuesday, and the attackers got their hands on 104 Cloudflare API tokens. “We have identified no suspicious activity associated with those tokens, but all of these have been rotated in an abundance of caution,” Sourov Zaman (Head of Security Response), Craig Strubhart (Senior Director of Threat Detection and Response), and Grant Bourzikas (Chief Information Security Officer) stated. “All customers whose data was compromised in this breach have been informed directly by Cloudflare [via email and banner notices in the company’s Dashboard].” Reconnaissance and data theft Several cybersecurity companies – namely: Zscaler, Palo Alto Networks, SpyCloud and Tanium – already acknowledged that the threat actors who breached Salesloft managed to access their Salesforce instances and exfiltrate customer-related data. While the attackers managed to grab names, email addresses, job titles, and location references, they were apparently more interested in data that could be used to compromise victim environments: AWS access keys, passwords, Snowflake access credentials, VPN keys, etc. “Cloudflare uses Salesforce to keep track of who our customers are and how they use our services, and we use it as a support tool to interact with our customers,” Zaman, Strubhart and Bourzikas explained in a report on their post-breach investigation. “Our investigation showed the threat actor compromised and exfiltrated data from our Salesforce tenant between August 12-17, 2025, following initial reconnaissance observed on August 9, 2025. A detailed analysis confirmed the exposure was limited to Salesforce case objects, which primarily consist of customer support tickets and their associated data within our Salesforce tenant.” The case objects contain customer contact information and the messages they exchanged with Cloudflare support (but not the related attachments). “In some troubleshooting scenarios, customers may paste keys, logs, or other sensitive information into the case text fields. Anything shared through this channel should now be considered compromised,” the company’s security leadership team advised. As the other affected organizations, Cloudflare believes that the stolen information will be used by the attackers to launch additional targeted attacks. The company also said the intruders used their Salesforce access to study how its customer support system works and to learn the exact API limits they had to stay under to avoid detection. This knowledge can help them in future attacks against Cloudflare and their customers. Cloudflare has detailed the proactive measures taken to respond to the compromise and prevent future ones, shared indicators of compromise, and security advice for all organizations using SaaS applications and third-party integrations. They confirmed that none of the Cloudflare’s services or infrastructure were compromised as a result of this breach. Additional victims come forward In a report on its own breach, Palo Alto Networks said attackers who compromised its Salesloft Drift OAuth token carried out reconnaissance, data exfiltration, and track-covering activities similar to those seen at Cloudflare. The list of security companies that have confirmed being affected by the Salesloft Drift breach also includes Proofpoint and Rubrik. UPDATE (September 4, 2025, 05:40 a.m. ET): Tenable has also been affected. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comSep 3, 2025extracted
Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations
Salesloft on Tuesday announced that it's taking Drift temporarily offline "in the very near future," as multiple companies have been ensnared in a far-reaching supply chain attack spree targeting the marketing software-as-a-service product, resulting in the mass theft of authentication tokens. "This will provide the fastest path forward to comprehensively review the application and build additional resiliency and security in the system to return the application to full functionality," the company said. "As a result, the Drift chatbot on customer websites will not be available, and Drift will not be accessible." The company said its top priority is to ensure the integrity and security of its systems and customers' data, and that it's working with cybersecurity partners, Mandiant and Coalition, as part of its incident response efforts. The development comes after Google Threat Intelligence Group (GTIG) and Mandiant disclosed what it said was a widespread data theft campaign that has leveraged stolen OAuth and refresh tokens associated with the Drift artificial intelligence (AI) chat agent to breach customers' Salesforce instances. "Beginning as early as August 8, 2025, through at least August 18, 2025, the actor targeted Salesforce customer instances through compromised OAuth tokens associated with the Salesloft Drift third-party application," the company said last week. The activity has been attributed to a threat cluster dubbed UNC6395 (aka GRUB1), with Google telling The Hacker News that more than 700 organizations may have been potentially impacted. While it was initially claimed that the exposure was limited to Salesloft's integration with Salesforce, it has since emerged that any platform integrated with Drift is potentially compromised. Exactly how the threat actors gained initial access to Salesloft Drift remains unknown at this stage. The incident has also prompted Salesforce to temporarily disable all Salesloft integrations with Salesforce as a precautionary measure. Some of the businesses that have confirmed being impacted by the breach are as follows - BeyondTrust Bugcrowd Cato Networks Cloudflare CyberArk Dynatrace Elastic Esker Fastly Google Workspace Heap HackerOne JFrog Megaport Nutanix PagerDuty Palo Alto Networks Pantheon Proofpoint Qualys Rubrik SpyCloud Tanium Tenable Workday Workiva Zscaler "We believe this incident was not an isolated event but that the threat actor intended to harvest credentials and customer information for future attacks," Cloudflare said. "Given that hundreds of organizations were affected through this Drift compromise, we suspect the threat actor will use this information to launch targeted attacks against customers across the affected organizations."
thehackernews.comSep 3, 2025extracted
Loading 2 more…