Search/zscaler
Vendor

zscaler

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
zscaler internet access admin portal
Connections
91 relationships
Exclusive: Linux Foundation's Akrites to Go Live in September
A major industry coalition set up to defend critical open-source software against AI-enabled cyber threats is expected to operationalize its vulnerability disclosure and remediation platform in September, Infosecurity has learned. The initiative, called Akrites, was launched at the end of June 2026 by the Linux Foundation, the Open Source Security Foundation (OpenSSF) and over 20 founding members. These include AI frontier labs Anthropic and OpenAI; cloud and tech giants like Amazon Web Services, Cisco, Google, Microsoft and its subsidiary GitHub, IBM and its subsidiary Red Hat and NVIDIA; cybersecurity firms like Chainguard, Endor Labs and Zscaler; and large enterprises, such as Citi, JPMorganChase, Ericsson and Vodafone. Each member of the coalition must donate between one and 10 engineers to the project and pay membership fees based on which of the three membership tiers they chose – Associate, General and Premier –, each corresponding to a level of benefits. At launch, the Linux Foundation announced two major missions for the initiative: Establish a shared security incident response team (SIRT) for mitigating and remediating vulnerabilities in open-source packages and libraries Develop a standardized coordinated vulnerability disclosure (CVD) process, built on confidentiality-first principles and industry-standard tooling Infosecurity spoke to Christopher ‘CRob’ Robinson, OpenSSF’s CTO and chief security architect, who was appointed as CTO of Akrites in June. He described Akrites’ sole mission as “coordinating AI-enabled vulnerability reports to upstream open-source maintainers so that the fixes are available to the whole ecosystem.” He said the team responsible for the initiative’s tooling, including the vulnerability management and SIRT platform, had now produced “the first draft of the tool chain.” He revealed that the initiative’s main platform will be based on Carnegie Mellon University's Vulnerability Information and Coordination Environment (VINCE), a vulnerability management platform developed in 2020 by the Computer Emergency and Response Team Coordination Center (CERT/CC), a unit of the university’s Software Engineering Institute (SEI). “We have a substantial amount of additional capabilities leveraging large language models (LLMs) to do deduplication, patch creation and more,” added the Akrites CTO, who confessed he’s already received thousands of vulnerability reports after two months of launching the project, an estimated 30% of these are duplicates. “Today, we’re bringing in some additional experts from the Akrites members to go through and do a penetration test and a security audit and then we’ll be augmenting the tools to allow the input of a combination of real and synthetic data through the system to make sure it functions as we design,” Robinson explained. When ready, the finished platform will be open-sourced and available for anyone to use for their own purposes. Additionally, Robinson said the Akrites-run platform is expected to “go live” and “start taking automated vulnerability reports” some time in September. “I have been trying to do something like Akrites my whole career,” he said. “I feel right now we have the tools, the willpower and access to the technical experts, so I’m very optimistic on our chances that we’re going to be able to provide a very valuable service to the global open-source ecosystem.” Stay tuned to Infosecurity for further updates on Akrites and similar initiatives to tackle the explosion of AI-enabled vulnerability reports in open-source projects. Image credits: Linux Foundation / IB Photography / Shutterstock.com
infosecurity-magazine.comAug 19, 2026extracted
Security Hub Extended adds Supply Chain Security as its tenth category
Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted a partner reception that brought our leadership together with partner executives to plan what comes next. These are companies investing real engineering and real go-to-market (GTM) alongside us, and increasingly with each other, because the model resonates with the customers they’re talking to every day. The most common question we heard at the booth was when Supply Chain Security was coming. It’s here. And that’s the thing I want to spend the most time on today, because it’s the category customers keep asking us about. Supply Chain Security: The category customers have been asking for Software supply chain risk has moved from a security-team concern to a board-level conversation. SolarWinds showed what happens when a build system is compromised. Log4j showed what a single transitive dependency vulnerability can do at global scale. The xz utils backdoor showed the patience of a maintainer-compromise attack executed over years. Each demonstrated a different dimension of the same problem, and the pace is accelerating. Attackers know that a fast way into an enterprise is through the open source packages that enterprise unknowingly trust. Every customer I talked to at Black Hat had this on their risk register. Most still hadn’t operationalized a solution, because doing so meant a standalone deployment, a new contract, a new console, and integration work their security team couldn’t prioritize. That’s the friction we aim to remove. Security Hub Extended now offers Supply Chain Security with Chainguard and Socket as the curated partners. Supply Chain Security uses the same model as everything else in Extended. Every offering has pay-as-you-go pricing, one bill, no required long-term commitment. For enterprises that prefer to continue using the procurement process they always have, Security Hub Extended Private Offers are also available. These are committed term agreements with deeper discounts, the ability to aggregate spend across partners on a single AWS bill, and both monthly and annual payment options throughout the term. You pick the path that fits how you buy. What Chainguard does Chainguard gives you open source dependencies rebuilt from source in a hardened, verified build process, so what enters your environment is malware-resistant and provenance-backed. Their research shows that rebuilding from source would have stopped 98% of known malicious packages from ever reaching production. If you can’t verify the source, it never appears in the Chainguard repository. That’s the filter between the public registry and your developers. What Socket does Socket analyzes the actual behavior of open source packages to block malicious dependencies at the time of install. Not after a Common Vulnerability and Exposures (CVE) is published days or weeks later. At the moment the package tries to land in your environment, Socket flags it based on what it does, not what a database says about it. Its reachability analysis then tells you which vulnerabilities are exploitable from your code instead of drowning your team in noise. You pay for the distinct packages you check, not for how often your builds run. Why they work together Together, Chainguard and Socket cover the two questions that matter: Can I trust what I’m pulling in? Can I stop malicious components before they get built into my applications? Chainguard helps secure the foundation your code is built on. Socket secures the packages you pull into it. Both help protect your software supply chain regardless of where you deploy—across clouds or on-premises. Activate both through Security Hub Extended and their findings flow into Security Hub in OCSF (Open Cybersecurity Schema Framework) alongside everything else, so a supply chain risk is correlated and prioritized next to your endpoint, identity, and cloud signals. From there, it routes out to the downstream tools you’ve already integrated, so it fits the pipeline your builders run today. 23 partners, 10 categories. Built on what customers asked for Every partner in Security Hub Extended is here because customers told us they needed that capability and that specific solution was already working for them. We add categories because the threat landscape evolves, and we add partners because customers point us to who’s solving those problems well. The goal is straightforward: Simplify adopting the security solutions your peers are already succeeding with, through the AWS relationship you already have. The full set today spans endpoint, identity, email, network, data, browser, cloud, AI, security operations, and now supply chain. The 23 curated partners are 7AI, Britive, Chainguard, CrowdStrike, Cyera, Island, LayerX, Native Security, Noma, Okta, Oligo, Opti, Palo Alto Networks, Proofpoint, SailPoint, SentinelOne, Socket, Splunk, Sublime, Upwind, Varonis, Zenity, and Zscaler. Our focus now is deepening integrations and reducing activation friction so these solutions work together, not in isolation. That’s where the real value compounds. What we’re building next Everything I’ve described so far is the commercial model working: Customers buying best-of-breed security through one AWS relationship with the flexibility they expect. But the bigger vision is the integration layer that makes these tools genuinely better together, not just easier to buy together. The integration we’re most focused on is cross-partner correlation, turning signals from an endpoint solution, an identity solution, and a cloud solution into one exposure and one attack path instead of three disconnected alerts. Right alongside that, we’re dramatically reducing the activation, deployment, and integration friction so customers go from subscribing to seeing value in hours rather than weeks. Both efforts enable the curated solutions you already trust to deliver stronger outcomes together than they do apart. That’s the build we’re accelerating with our partners now, and you’ll hear more leading into re:Invent. Explore what’s available If you’re running open source in production and don’t yet have supply chain visibility, start there. Activate Chainguard and Socket through the Security Hub console today. If you’re managing multiple security vendor relationships and want to understand what consolidation looks like with Security Hub Extended, talk to your AWS account team. Pricing for every partner is published on our pricing page , no sales call required. And if you’re already using Security Hub for posture management and threat detection, the Extended plan is available in the same console you already use. We’re just getting started. If you have feedback about this post, submit comments in the Comments section below. Michael Fuller Michael has been with AWS for 16 years and led product for AWS Security Services for 11 years. Michael has 29 years in the industry and held several roles in product management, business development, and software development for IBM, Cisco, and Amazon. Michael has a Bachelor’s of Science in Computer Engineering from the University of Arizona and an MBA from the University of Washington.
aws.amazon.comAug 18, 2026extracted
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this month. "The campaign used a multi-stage attack chain to establish and maintain access on infected systems, with TELESHIM abusing the Telegram API for command-and-control (C2) communication to blend in with legitimate internet traffic," Sudeep Singh, senior manager of APT research at Zscaler ThreatLabz, said in a technical write-up published last week. The attack chain starts with an ISO file containing a legitimate executable ("RegSchdTask.exe") that's used to sideload a rogue DLL ("AsTaskSched.dll"), a 32-bit Windows backdoor called TELESHIM that then leverages Telegram as C2 to retrieve next-stage components. Two of these payloads are used to trigger a second DLL side-loading chain comprising "GoProAlertService.exe" and "pthreadVC2.dll," with the latter acting as a reflective loader codenamed MIXEDKEY to decrypt the contents of "C99F29AC08454855B3D538960BB2F34F.PCPKEY" and execute it. Both TELESHIM and MIXEDKEY have been found to rely on heavy code obfuscation techniques, including string encryption, control flow flattening (CFF), mixed boolean arithmetic (MBA), and opaque predicates to deter reverse engineering efforts. TELESHIM also employs an array of methods to detect the presence of virtualization-based analysis environments. Some of these are listed below - Hypervisor detection using CPUID RAM speed check using the Windows Management Instrumentation (WMI) TELESHIM C2 communications supports two types of messages - Control messages, which are used to register the infected host by sending the host's MAC address and executing received commands and exfiltrating the results back to the server in chunks if the output is larger than 1,000 bytes Download and execute messages, which are used to download and run secondary payloads as scheduled tasks What's notable about the final payload is that it's locked behind two layers of XOR encryption, the second layer using a technique called environmental keying by encrypting it by means of a decryption key derived from the infected machine's volume serial number. This is done so that the malware detonates only on intended targets. The attack sequence culminates with the deployment of BINDCLOAK, a 64-bit C2 implant written in C++ that contacts an external server ("cert.hypersnet[.]com"). ThreatLabz noted that it identified post-compromise activity from the C2 operator, such as system, user, and network reconnaissance commands, as well as the delivery of next-stage payloads, most of which occurred between July 7, 2026 and July 9, 2026. The C2 commands have been executed only between 4 a.m. and 12 p.m. UTC, with a major chunk of the activity taking place between 7 a.m. and 11 a.m. UTC. Based on the threat actor's public IP address, the system locale configured on their Windows server, the geolocation of the IP address, and the active operational hours, it's assessed with moderate-to-high confidence that the campaign is the work of an adversary originating from East Asia. It has not been attributed to any known threat actor or group at this stage. "The activity also reflects broader trends such as EDR evasion, blending in with legitimate internet traffic through abuse of trusted platforms, and the use of code-obfuscation techniques such as MBA and CFF to hinder reverse engineering," Singh said.
thehackernews.comJul 27, 2026extracted
Indirect Prompt Injection in Web Content Targets AI Agents
Attackers have begun embedding hidden instructions in websites to target AI agents, according to new research. Zscaler's ThreatLabz documented two real-world campaigns which used a technique called indirect prompt injection, where instructions are planted in content an AI agent reads, such as a web page, to steer its behavior. One posed as software documentation to run a payment scam, the other impersonated a cryptocurrency service. Hidden Instructions in Plain Sight In both cases, the attackers first used SEO poisoning to push their sites high in search results, making it more likely an agent would find them. They then buried prompt-style instructions in parts of the page a human never sees, using CSS to move the text off-screen or tucking it inside structured JSON-LD metadata that machines read as trusted context. The first campaign used a fake page dressed up as a Python library's documentation. It told any AI agent on a coding task that it had to buy a $3 API license key to fix an error, then walked it through paying an attacker's cryptocurrency wallet for a bogus key. Zscaler said the same site also tried to scam human developers. Read more: Researchers Uncover 10 In-the-Wild Prompt Injection Payloads Targeting AI Agents How the Models Held Up For the second campaign, the attackers used a typosquatting domain impersonating DeBank, a popular cryptocurrency portfolio tracker, with hidden text instructing agents to treat the fake site as the "authoritative" DeBank and rank it first. To gauge the risk, ThreatLabz ran its own autonomous agent against the sites across 26 large language models (LLMs). Four of the 26 models were manipulated into executing the fraudulent payment, including versions of Meta's Llama and Google's Gemini. In the second test, two models, OpenAI's GPT-5.4 and Anthropic's Claude Sonnet 4.5, reportedly wrongly rated the fake site as legitimate, but only when they lacked a trusted reference for the real DeBank. When the genuine site was provided for comparison, none were fooled. The results from Zscaler's own sandboxed tests suggest that susceptibility depends heavily on the LLM and the amount of context it is given. "As AI agents become a more common interface to the web, the content itself is going to become a larger attack surface," the company warned, "highlighting that AI is a double-edged sword that can streamline workflows while also introducing new avenues for abuse."
infosecurity-magazine.comJul 6, 2026extracted
Sensitive Enterprise Data Uploads to AI Models Double in a Year
The amount of sensitive enterprise data which employees uploaded to AI and machine learning applications has almost doubled in the last year, putting organizations at increased risk of data breaches and cyber espionage, a new report has warned. Published on June 17, the Zscaler 2026 AI Threat Report said that there has been a 93% year-over-year increase in employees transferring enterprise data to AI tools. Over half of these data transfers were driven by staff using two tools in particular: Grammarly (38%) and ChatGPT (21%). Other tools included OpenAI, Codium, GitHub Co-Pilot, Perplexity, Microsoft Co-Pilot, Google Gemini and Claude. According to Zscaler, a total of 18,033 TB of data was transferred to AI and machine learning applications during the last year. The report stated that this is roughly equivalent to 3.6 billion digital photos. Employees Putting Sensitive Data in ChatGPT Zscaler identified over 410 million Data Loss Prevention (DLP) policy violations related to ChatGPT, representing an increase of 99% year-over-year. These violations were related to sensitive information such as financial records, personally identifiable information (PII), source code, healthcare data, and other regulated content. Employees are not typically acting with malice, rather they are attempting to transfer data to AI models to help them be more efficient at work. However, uploading this information to AI models could have potentially significant data privacy implications. “The riskiest AI applications tend to be those that employees use without thinking—writing assistants, coding helpers, or AI features layered into collaboration suites. Their convenience is exactly what makes them higher risk; they see the same sensitive content employees do, often at the moment it’s created,” warned the report. The AI coding assistant Codium also represented a significant vector for DLP violations, with over 242 million detected by Zscaler. This represented a 100% year-over-year increase, suggesting increased leakage risk for source code and proprietary logic, something which could be highly damaging to businesses. To counter the potential cybersecurity risks around the increased use of AI by employees, Zscaler has made several recommendations: Inventory all GenAl apps and apps with embedded AI functionality: Create a continuously updated catalog of every standalone GenAl tool and every SaaS or internal app that includes AI functionality or features Disable risky AI defaults: Turn off auto-enabled AI functionality in SaaS and productivity apps until they have been reviewed and configured to match your risk posture Apply zero trust to all model interactions: Implement least-privilege access for every user, service, and system that interacts with an AI model Enforce AI guardrails with inline inspection: Ensure inline inspection across all AI/ML traffic to prevent external malicious activity from compromising AI systems and stop sensitive data from being exposed via prompts or in outputs The findings in the report are based on analysis of 989.3 billion total AI and ML transactions in the Zscaler cloud from January 2025 through December 2025.
infosecurity-magazine.comJun 17, 2026extracted
Cybercriminals are moving away from mass phishing campaigns
Cybercriminals are moving away from mass phishing campaigns Phishing activity declined by roughly 20% in both 2024 and 2025, according to research from Zscaler’s ThreatLabz team. The drop followed years of growth that pushed phishing activity above 2 billion hits in 2023. “Phishing volume measured by blocked emails is no longer a reliable proxy for phishing risk.” Researchers found greater use of targeted phishing campaigns designed to resemble routine business communications. The services sector recorded a 65.5% year-over-year increase in phishing activity, making it the most targeted industry in the dataset. Encrypted attack hits by industry (Source: Zscaler) Billing notices, onboarding documents, renewals, support requests, and document-sharing workflows appeared frequently in campaigns targeting the sector. One campaign cited by Zscaler used tax-themed lures and legitimate services such as OneDrive to target more than 29,000 users across 10,000 services organizations. Microsoft and Google topped the list of brands most frequently impersonated in phishing campaigns. Credentials tied to those platforms often provide access to multiple business services through a single account. A Microsoft 365 login can unlock email, files, Teams, SharePoint, OneDrive, and connected SaaS applications. Access to one account can expose a much larger portion of an organization’s environment. AI site builders are becoming part of phishing operations ThreatLabz identified 413,524 AI-generated website instances and classified 37,447 of them as malicious. The activity was associated with platforms including Manus AI, Blackbox AI, Anything AI, Bolt AI, Vercel v0, and Framer AI. Unattributed AI tooling accounted for the largest share of observed activity, followed by Manus AI and Blackbox AI. Researchers documented phishing pages, fake applications, and brand impersonation sites created through these services. One case involved a counterfeit Coinbase Wallet website generated with an AI application builder. The site promoted a fake browser extension and was hosted on a legitimate platform. Researchers noted that branding from the AI platform remained embedded in parts of the page metadata. “What used to require a developer, a template kit, and time now often takes little more than a prompt and a few iterations.” More phishing activity is hidden inside encrypted traffic More than 95% of phishing activity observed by Zscaler was delivered over encrypted channels. Researchers also found that 87% of all malicious activity blocked during 2025 was delivered over HTTPS. Credential theft, session abuse, and redirects increasingly occur through the same encrypted connections employees use to access cloud applications and business services. “What makes this shift more dangerous is where compromise actually happens: in the browser, over HTTPS.” Attackers are bypassing MFA in real time ThreatLabz identified phishing kits that combine adversary-in-the-middle (AiTM) and browser-in-the-middle (BiTM) techniques to intercept login sessions and capture credentials, MFA codes, and session tokens in real time. BlackForce, a phishing-as-a-service platform cited by ThreatLabz, was among the examples. The kit captures credentials, MFA codes, and session information during the login process, turning a single click into a session-level compromise. Attack surface discovery is happening at scale Between October 2025 and March 2026, external decoys deployed in customer environments recorded 89.9 million hostile interactions from 1.37 million unique attacker IP addresses. Attackers were probing exposed services and looking for assets that could provide a path into an organization. Researchers described reconnaissance efforts focused on exposed assets, leaked credentials, misconfigured applications, and forgotten subdomains. Cloud infrastructure is fueling scanning activity ThreatLabz observed more than 121,000 AWS-hosted IP addresses probing customer environments. Public cloud platforms accounted for a significant share of the attacker infrastructure observed in the dataset. Researchers said cloud-hosted infrastructure can be provisioned quickly, used for reconnaissance, and replaced when it is blocked or detected. Zscaler expects phishing campaigns to become more automated in 2026, with AI agents targeting other AI agents, attacks moving between email, messaging apps, SMS, and voice channels, and attackers focusing on active sessions and identities instead of credentials alone.
helpnetsecurity.comJun 12, 2026extracted
Cybersecurity M&A Roundup: 26 Deals Announced in May 2026
Twenty-six cybersecurity-related merger and acquisition (M&A) deals were announced in May 2026. For a detailed view of the more than 420 acquisitions announced in 2025, check out SecurityWeek’s annual M&A report. Here are some of the most important cybersecurity M&A deals announced in May 2026: Akamai has agreed to acquire LayerX, a company specializing in AI and browser security, for roughly $205 million in an all-cash deal. LayerX has developed a security platform that provides real-time visibility and control over user and agentic activities across browsers, applications, and IDEs. Its technology enables Akamai to expand its Zero Trust and application security portfolio with AI usage control capabilities. Check Point Software Technologies has acquired the team and intellectual property of AI evaluation startup Deepchecks, reportedly for $10 million to $20 million. The goal of the transaction is to accelerate Check Point’s newly launched Agentic Network Security Orchestration platform. By integrating Deepchecks’ continuous monitoring and LLM evaluation technology, Check Point provides an essential validation layer for autonomous AI security agents. Cisco has announced its intent to acquire Israeli non-human identity security startup Astrix Security for an estimated $400 million. The goal of the transaction is to extend Cisco’s Zero Trust architecture to what it calls the ‘agentic workforce’. By integrating Astrix’s non-human identity management tools directly into Cisco Identity Intelligence, Duo IAM, and Splunk, Cisco plans to give security teams the ability to discover, authenticate, govern, and continuously monitor autonomous AI actors across the enterprise network infrastructure. Cycurion acquires Halo Privacy, HavenX, and Secuvant Publicly traded cybersecurity provider Cycurion, Inc. has announced the acquisition of Halo Privacy, HavenX, and Secuvant. The Secuvant deal was valued at $2.875 million, while specific purchase terms for Halo Privacy and HavenX were withheld. The unified goal of these consecutive acquisitions is to build a massive, end-to-end defense platform that combines Cycurion’s solutions with Halo’s secure communications, HavenX’s forensic attribution capabilities, and Secuvant’s automated SOC-as-a-Service workflows. Data security giant Cyera has completed the acquisition of five-month-old endpoint data protection startup Genie Security for an estimated $50 million. The transaction is designed to expand Cyera’s Data Security Posture Management (DSPM) ecosystem. By absorbing Genie Security’s endpoint telemetry agents into its platform, Cyera aims to address a critical corporate blind spot: preventing sensitive corporate data from being leaked or fed into generative AI tools and autonomous software agents. Data monetization and edge computing firm Datavault AI has entered into a binding letter of intent to acquire cybersecurity vendor CyberCatch in an all-stock transaction valued at roughly $100 million. Once finalized, CyberCatch will operate as a wholly-owned subsidiary, keeping its current management intact. The main goal of the acquisition is to bake CyberCatch’s AI-powered continuous compliance testing and automated penetration tools directly into Datavault AI’s edge GPU processing network. Industrial cybersecurity firm Dragos has acquired xIoT security specialist Phosphorus, a move aimed at strengthening its ability to help organizations secure and manage the growing number of connected devices embedded across critical infrastructure and other operational networks. Cybersecurity ratings firm SecurityScorecard has completed the acquisition of British internet scanning and threat intelligence startup Driftnet for an undisclosed sum. The primary goal of the transaction is to embed Driftnet’s high-fidelity, port-agnostic scanning capabilities into SecurityScorecard’s newly launched TITAN AI engine. Agentic security company Torq has completed the acquisition of fellow Israeli cybersecurity startup Jit for an estimated $70 million. The transaction brings Jit’s entire 30-person team under the Torq umbrella. The primary goal of the acquisition is to append Jit’s advanced AI Context Graph layer directly onto Torq’s AI SOC platform. WatchGuard acquires Perimeters.io WatchGuard Technologies has finalized the acquisition of cloud application security startup Perimeters.io. The goal of the transaction is to absorb Perimeters’ technology to power WatchGuard’s newly launched service, WatchGuard CloudDR. By merging Perimeters’ technology directly into its MSP-focused ecosystem, WatchGuard intends to give its partners a single, multi-tenant dashboard to continuously audit configurations, flag compromised credentials via ITDR, and automatically neutralize shadow AI and shadow IT risks across cloud applications. Cloud security giant Zscaler has announced its intent to acquire AI and data security firm Symmetry Systems. The goal is to bring native identity and data mapping directly into Zscaler’s Zero Trust Exchange. By integrating Symmetry Systems’ access-graph technology, Zscaler will give security teams a centralized visual control plane to track exactly what data autonomous AI agents are touching, enforce absolute least-privilege data policies, and automatically contain anomalous agent behaviors. Other cybersecurity M&A deals announced in May 2026: Boost Security acquires SecureIQx and Korbit.ai Related: Cybersecurity M&A Roundup: 33 Deals Announced in April 2026
securityweek.comJun 8, 2026extracted
Anthropic Expands Claude’s Enterprise Security Governance With 28 New Integrations
Anthropic announced last week that Claude now connects with 28 security and compliance platforms, a move designed to make the AI assistant a more manageable and governable tool within corporate IT environments. The integrations span a wide range of enterprise security categories, including data loss prevention, SASE, SIEM, identity management, e-discovery, and AI observability. At the heart of the rollout is the Claude Compliance API, which gives IT and security teams programmatic access to two key data streams: conversation content from Claude Enterprise (chats, uploaded files, and projects), and activity event logs from Claude Enterprise and the Claude Platform (user logins, admin actions, and configuration changes). The integrations enable security teams to apply existing monitoring and governance policies to Claude the same way they do for other workplace software. The list of integration partners includes CrowdStrike, Palo Alto Networks, Microsoft, Okta, Zscaler, Netskope, Cloudflare, Datadog, Fortinet, Wiz, SailPoint, Relativity, ReliaQuest, Sumo Logic, Geordie AI, Forcepoint, Cribl, Mimecast, Smarsh, Snyk, Cyera, Proofpoint, Rubrik, Tenable, Trellix, Theta Lake, Varonis, and IBM. For organizations already using one of the 28 supported platforms, getting started requires only connecting and configuring a Claude instance, after which data flows automatically into existing dashboards and alerting workflows. Anthropic has published documentation for Claude Enterprise and the Claude Platform in its Help Center. Security vendors that are not yet part of the network can apply to join. Anthropic recently announced that its Mythos model has detected more than 23,000 potential vulnerabilities across 1,000 open-source projects. Thousands of these findings have been confirmed. Related: Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI Related: Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere Related: 1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials Related: AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop
securityweek.comMay 26, 2026extracted
Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
Chinese-speaking individuals are the target of a new campaign that uses a trojanized version of SumatraPDF reader to deploy the AdaptixC2 Beacon post-exploitation agent and ultimately facilitate the abuse of Microsoft Visual Studio Code (VS Code) tunnels for remote access. Zscaler ThreatLabz, which discovered the campaign last month, has attributed it with high confidence to Tropic Trooper (aka APT23, Earth Centaur, KeyBoy, and Pirate Panda), a hacking group known for its targeting of various entities in Taiwan, Hong Kong, and the Philippines. It's assessed to be active since at least 2011. "The threat actors created a custom AdaptixC2 Beacon listener, leveraging GitHub as their command-and-control (C2) platform," security researcher Yin Hong Chang said in an analysis. It's believed that Chinese-speaking individuals in Taiwan, and individuals in South Korea and Japan, are the targets of the campaign. The starting point of the attack is a ZIP archive containing military-themed document lures to launch the rogue version of SumatraPDF, which is then used to display a decoy PDF document, while simultaneously retrieving encrypted shellcode from a staging server to launch AdaptixC2 Beacon. To accomplish this, the backdoored SumatraPDF executable launches a slightly modified version of a loader codenamed TOSHIS, which is a variant of Xiangoop, a malware linked to Tropic Trooper, and has been used in the past to fetch next-stage payloads like Cobalt Strike Beacon or Merlin agent for the Mythic framework. The loader is responsible for activating the multi-stage attack, dropping both the lure document as a distraction mechanism and the AdaptixC2 Beacon agent in the background.The agent employs GitHub for C2, beaconing out to the attacker-controlled infrastructure to fetch tasks to be executed on the compromised host. The attack moves to the next stage only when the victim is deemed valuable, at which point the threat actor deploys VS Code and sets up VS Code tunnels for remote access. On select machines, the threat actor has been found to install alternative, trojanized applications, likely in an attemptto better camouflage their actions. What's more, the staging server involved in the intrusion ("158.247.193[.]100") has been observed hosting a Cobalt Strike Beacon and a custom backdoor called EntryShell, both of which have been put to use by Tropic Trooper in the past. "Similar to the TAOTH campaign, publicly available backdoors are used as payloads," Zscaler said. "While Cobalt Strike Beacon and Mythic Merlin were previously used, the threat actor has now shifted to AdaptixC2."
thehackernews.comApr 24, 2026extracted
「9割が90分以内、最速は1秒」 企業AIシステム侵害の絶望的なスピード感
Zscaler�́A��Ƃ�AI�V�X�e�����U���҂ɂ���ċɂ߂ĒZ���ԂŐN�Q�������Ԃ𖾂炩�ɂ����BAI���p���}�g�傷�����A�Z�L�����e�B�ǂ��t���Ă��Ȃ�����������ɂȂ����B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@�N���E�h�Z�L�����e�B��Ƃ�Zscaler��2026�N1��27���i�č����ԁj�A�uThreatLabz 2026 AI Security Report�v�����J�����B���Ђ̃N���E�h�Z�L�����e�B�v���b�g�t�H�[���uZscaler Zero Trust Exchange�v��ʂ���2025�N1�12���ɏ������ꂽ��1������AI�i�l�H�m�\�j�^ML�i�@�B�w�K�j�g�����U�N�V�����͂������ʁA��Ƃ�AI�V�X�e���̃T�C�o�[���X�N�ɑ��ď\���Ȕ������ł��Ă��Ȃ����Ƃ����炩�ɂȂ����B �@���|�[�g�ɂ��ƁAAI�^ML�g�����U�N�V�����͑O�N��83���������A���p�����AI�A�v���P�[�V������3400�ȏ�ɒB�����B���Z�E�ی��Z�N�^�[���SAI�^ML�g���t�B�b�N��23�����ߍł�AI���p���i��ł������A�e�N�m���W�[�Z�N�^�[�͑O�N��202���A����Z�N�^�[��184���Ɣ����I�Ȑ������L�^�����B �@�����������̑g�D�ł́A�A�N�e�B�u��AI���f����g�ݍ���AI�@�\�̊�{�I�Ȉꗗ���\���ɔc���ł��Ă��Ȃ��BAI�K�o�i���X�͎������x���̗D�掖���ɂȂ��Ă���ƃ��|�[�g�͎w�E���Ă���B �@Zscaler�̃��b�h��[������Ƃ�AI�V�X�e����ΏۂɁA�G�ΓI�������Ńe�X�g�������ʁA�قڑ����ɏd��ȏ�Q�����������B���䂳�ꂽ�X�L�����ɂ����āA�d��ȐƎ�i�������Ⴍ�j���͐����Ŕ������ꂽ�B�ŏ��̏d��ȏ�Q����������܂ł̒����l�͂킸��16���ŁA9���̃V�X�e����90���ȓ��ɐN�Q���ꂽ�B�ł��ɒ[�ȃP�[�X�ł́A�킸��1�b�Ŗh�䂪�˔j���ꂽ�B���͑ΏۂƂȂ����S�ẴV�X�e���ʼn��炩�̏d��ȐƎ㐫����������Ă���B �@Zscaler�̃f�B�[�y���E�f�T�C���i�T�C�o�[�Z�L�����e�B�S���G�O�[�N�e�B�u�o�C�X�v���W�f���g�j�́A�uAI�͂��͂�P�Ȃ�������c�[���ł͂Ȃ��B�ƍ߃O���[�v�⍑�Ǝ�̂�AI�𗘗p���Ď����I�������ɍU�����d�|���鎞��ɂȂ��Ă���B�G�[�W�F���g�^AI�̕��y�ɂ��A�N�����牡�W�J�i���e�������[�u�����g�j�A�f�[�^�ގ�܂ł������Ői�s����\��������v�Əq�ׂĂ���B �@2025�N�AAI�^ML�A�v���P�[�V�����ւ̊�ƃf�[�^�]���ʂ�1��8033TB�ɒB�����B����͑O�N��93�����ŁA��36�����̃f�W�^���ʐ^�ɑ�������B���@�`�F�b�N�c�[���uGrammarly�v�i3615TB�j��uChatGPT�v�i2021TB�j�Ȃǂ̃c�[�����A���Ƀf�[�^�]���ʂ̑����T�[�r�X�������B �@ChatGPT������4��1000�����̃f�[�^�����h�~�iDLP�j�|���V�[�ᔽ�����o����A�Љ�ۏ�ԍ��A�\�[�X�R�[�h�A��ËL�^�̋��L���s���܂܂�Ă����BThreatLabz���|�[�g�ł́AAI�T�[�r�X�ɒ~�ς��ꂽ�f�[�^���A����A�T�C�o�[�X�p�C�����̗D��x�̍����^�[�Q�b�g�ɂȂ�ƌx�����Ă���B �@���|�[�g�́AChatGPT�i2025�N��1150���g�����U�N�V�����j��uCodeium�v�i420���g�����U�N�V�����j�Ȃǂ̃X�^���h�A����AI�c�[���ɉ����A��ƌ���SaaS�iSoftware as a Service�j�A�v���P�[�V�����ɒ��ڑg�ݍ��܂ꂽ�u�g�ݍ���AI�v�̃��X�N�ɂ����y���Ă���B �@������SaaS�ł�AI�@�\�̓f�t�H���g�i����j�ŗL��������Ă���A�]���̃Z�L�����e�B�t�B���^�[�ɂ�錟�o���P�[�X������B���̂��߁u�@���f�[�^���Ď��Ȃ���AI���f���ɗ��o����o�b�N�h�A�ɂȂ��Ă��܂��v��Zscaler�͎w�E���Ă���B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpMar 31, 2026extracted
RSAC 2026 Conference Announcements Summary (Day 2)
As hundreds of vendors descend on San Francisco for the RSAC 2026 Conference, the sheer volume of news can be overwhelming. To help you navigate the noise, SecurityWeek is providing a daily digest of the most significant announcements. Below is our curated roundup of essential product and service updates, along with reports from the second day of the event. Roundups of announcements from day 1 and the days leading up to the conference are also available. Offensive security firm Assail has launched Ares, an autonomous red-teaming platform designed to discover, chain, and exploit vulnerabilities across APIs, mobile applications, and web applications. Ares is a self-healing, self-teaching platform that autonomously adapts attack strategies in real time and requires no hands-on expertise to manage. BlackCloak has released three new capabilities for its Digital Executive Protection platform. Impersonation Protection, now enhanced with device-level biometric validation and geolocation signals, lets BlackCloak members authenticate the legitimacy of communications from other members in real time via the mobile app. Search Suppression complements the existing Data Broker Removal service by automatically suppressing a member’s PII from search engine results while broker removal requests are still being processed. Member Travel Advisory (coming this spring) delivers AI-synthesized, continuously updated risk analysis across cybersecurity, physical, geopolitical, and social dimensions for every country directly within the app. ConductorOne announced a new integration with CrowdStrike Falcon Next-Gen Identity Security that feeds live threat signals drawn from real-time detections, behavioral analytics, and threat intelligence directly into ConductorOne’s access governance workflows. Security teams can filter and prioritize high-risk identities during access reviews and approval decisions based on real-time activity, rather than risk scores. ConductorOne’s policy engine can also use those Falcon signals to automate responses and trigger a review, deny access, or revoke entitlements the moment risk levels shift. Cyera has introduced a new suite of capabilities, including Browser Shield for AI and Data Lineage, to provide real-time visibility into how employees and autonomous agents interact with sensitive data. Browser Shield prevents data exposure at the prompt level within public AI models, while the Data Lineage tool automatically maps how agents move and transform files across their lifecycle. Additionally, the new Cyera MCP allows security teams to build their own data security agents to automate threat hunting and risk remediation using plain-language queries. CrowdStrike launches cloud security innovations, Falcon Data Security, Agentic MDR CrowdStrike announced new Falcon Cloud Security enhancements to help eliminate cloud risk through adversary-informed prioritization. Organizations can identify cloud exposures most likely to be exploited and their root causes, enabling faster remediation. CrowdStrike also introduced Falcon Data Security, a new data security solution that stops data theft across the agentic enterprise. Falcon Data Security discovers, classifies, and stops data theft in real time. The security giant also unveiled Agentic MDR for managed detection and response. Falcon Complete’s analysts build and deploy intelligent agents to automate high-friction security workflows and stop breaches. Darktrace launches adaptive security awareness training and introduces MSSP offering Darktrace has announced Adaptive Human Defense, which replaces scheduled security awareness training with behavioral AI-driven micro-coaching sessions delivered in real time as risks appear in a user’s inbox. Darktrace also unveiled an expansion of Darktrace / EMAIL to include full-message, cross-channel analysis across email, Microsoft Teams, Slack, and Zoom, enabling detection of blended social engineering campaigns across all four platforms, including prompt-injection threats targeting corporate AI assistants. The company also announced a new managed email security offering for MSSPs, built on Darktrace / EMAIL’s Self-Learning AI. Drata has released three new agentic AI capabilities for its trust management platform. The first, Agentic TPRM Assessment (now generally available), automates vendor security reviews by autonomously accessing live evidence from Drata Trust Centers, evaluating controls against defined criteria, and generating findings, follow-ups, and executive reports. The second, Agentic Questionnaire Response (in beta), manages the full security questionnaire lifecycle from intake and drafting to SME collaboration and final delivery, with configurable human-in-the-loop controls. The third, AI Trust Center Creation, ingests a customer’s existing artifacts and quickly auto-generates a complete Trust Center preview. Eclypsium has released the Eclypsium Supply Chain Security Platform version 4.3. The latest version of the platform provides continuous monitoring of network edge devices for vulnerabilities, indicators of compromise, and unknown binaries that may harbor vulnerabilities and custom malware introduced via the IT supply chain. GC Cybersecurity has unveiled its 5th generation Autonomous Data Protection Platform. The new ISE Autonomous Data Protection Platform is designed to address the growing risk of sensitive data exposure across AI, cloud, and SaaS environments. Powered by agentic AI and a 5th generation cybersecurity architecture, the platform continuously discovers, classifies, and protects data in real time, going beyond traditional perimeter-based defenses. Hadrian has released Nova, an agentic pentesting product that autonomously simulates offensive techniques against an organization’s external attack surface, including chaining vulnerabilities and escalating access across real assets. Testing is customer-scoped and repeatable on demand, with findings reviewed by human experts before delivery. Nova is priced per test and is available immediately. KnowBe4 launches phishing alert button for Microsoft Teams and expands platform KnowBe4 is extending its one-click Phish Alert Button (PAB) to Microsoft Teams, allowing users to report suspicious messages directly within the collaboration platform. The integration enables security teams to manage threats from both email and Teams within a single, streamlined workflow. KnowBe4 also expanded its Artificial Intelligence Defense Agents (AIDA) platform with deepfake training agents that generate custom, high-fidelity deepfake simulations featuring an organization’s own leaders to train employees on how to spot AI-generated impersonations. Living Security announced the general availability of its AI-native Human Risk Management platform. Powered by the Livvy AI risk intelligence engine, the platform is designed to secure the “hybrid workforce” — both human employees and AI agents operating across enterprise systems. The platform analyzes behavioral signals across the workforce to identify risk, explain why it matters, and guide remediation before incidents occur. Huntress has expanded its Managed Identity Threat Detection & Response (ITDR) product to cover Google Workspace, adding to its existing Microsoft 365 coverage. The solution detects anomalous authentication activity, attacker-created Gmail inbox rules designed to suppress MFA notifications or hide security alerts, and logins from data center providers commonly associated with threat actors. iCOUNTER announced the general availability of its Counter Threat Operating System (CTOS), a new platform designed to introduce “compromise intelligence” as a control layer for third-party risk. The initial release includes CTOS-TPR, which detects early-stage adversary activity such as reconnaissance and targeting aimed at vendors and partners. By continuously monitoring threat activity and mapping it against an organization’s extended ecosystem, CTOS enables companies to identify and act on risks before they lead to breaches. Miggo is expanding its Runtime Defense Platform to protect AI and agentic environments, with new capabilities including AI-BOM, runtime guardrails and agentic detection and response. It tackles the fact that agents are making decisions dynamically at runtime, so security teams need visibility and protection where models, tools and data actually interact. The enhancement gives security teams visibility and control over AI agents, MCP toolchains and Shadow AI running in production. NetRise launched Provenance, a new product that identifies risk associated with contributors to the open source components inside enterprise software and connected devices. Provenance adds a layer of trust and intelligence to the NetRise Platform, enabling teams to see a variety of project health signals, including advisory relationships and how compromises propagate through dependency graphs, defining a blast radius from a malicious contributor. Novee has launched autonomous AI red teaming for LLM applications, designed to uncover flaws in chatbots, copilots, and agents. It tests for real AI-specific attack paths such as prompt injection, jailbreaks and agent manipulation rather than relying on traditional appsec approaches that were not built for AI behavior. Nudge Security adds new AI agent discovery capabilities Nudge Security announced an expansion of its platform with the addition of AI agent discovery, enabling customers to gain immediate visibility and control over agent identity and permissions. The new capabilities discover AI agents at the source of creation, understand their access risks, and engage their human creators to gain additional context regarding the scope of use for each agent. RSA has announced expanded integration with Microsoft, adding support for the new Microsoft 365 E7: The Frontier Suite through RSA ID Plus for Microsoft, which provides authentication for both human users and AI agents across hybrid, cloud, and on-premises environments. Separately, RSA announced several new passwordless enhancements: a next-generation desktop passwordless client for macOS and Windows, enhanced mobile passkeys with proximity verification, and datacenter passwordless support for Linux and other OS servers. Sectigo has introduced the Sectigo Partner Platform (SPP), a multi-tenant CLM platform designed for MSPs, MSSPs, VARs, and distributors. Unlike single-tenant alternatives, SPP gives each end customer a fully isolated tenant with separate certificate inventories, usage reporting, billing, and admin controls, all managed through a single partner interface. The platform integrates with Sectigo Certificate Manager (SCM) and automates certificate validation, issuance, and renewal workflows. SPP is currently available to a limited number of channel partners, with broader rollout planned. SentinelOne and LevelBlue are combining SentinelOne’s Purple AI and Singularity Platform with LevelBlue’s threat intelligence and Indigo platform to give organizations a unified, AI-powered security operations model, covering MDR, managed SIEM, and incident response in one place. The goal is to reduce dwell time and fragmentation that make most enterprise security stacks hard to manage. Sentra announced a new solution to help organizations securely adopt Google Workspace with Gemini by addressing key AI adoption risks. The platform tackles four core risks: shadow and unused sensitive data, over-permissioning, incorrect or missing labels, and data leakage through AI-generated outputs, using in-place discovery, classification and automated labeling. These capabilities give organizations the visibility and controls needed to maintain data governance, compliance and cost efficiency while preparing for AI. Skyhawk Security has introduced a new Threat Actor Context capability that maps simulated cloud attack scenarios to known adversary tradecraft, campaigns and CVEs. The product enhancement was built for prioritization. It gives security teams more context on which attack paths are most relevant based on real-world threat activity, helping them focus on the true risks to critical assets. Tenable has introduced Hexa AI, an agentic AI engine within the Tenable One platform that automates security workflows and transforms exposure intelligence into coordinated action. Hexa AI helps security teams prioritize and remediate risk at machine speed across IT, cloud, identity and AI environments. By leveraging Tenable’s Exposure Data Fabric, the platform enables organizations to move from reactive response to proactive, continuous risk reduction. Vectra AI has expanded its platform with three new exposure management capabilities. The first is a passive, agentless continuous asset inventory that automatically discovers and tracks unmanaged, OT, and IoT devices across hybrid environments. The second is proactive exposure detection, which identifies observed security and compliance gaps such as risky protocol usage, weak encryption patterns, and exposed credential files. The third is environment observability, providing network-wide visibility into PQC readiness, Zero Trust posture, data movement, and network performance. Zscaler publishes threat research and announces new integrations Zscaler has published its Threatlabz 2026 VPN Risk Report, which shows that 51% of organizations experienced a VPN-related security incident in the past 12 months. The study also found that only 5% trust their VPN infrastructure to detect and stop AI-enabled threats, and only 6% of organizations can deploy a critical VPN patch within 24 hours. Zscaler also announced that it’s now part of Databricks’ new Open Security Lakehouse Ecosystem, which unifies all structured and unstructured security data into a single platform that integrates with any tool to enable social engineering detection, insider threat detection, and anomaly detection.
securityweek.comMar 25, 2026extracted
RSAC 2026 Conference Announcements Summary (Day 1)
As hundreds of vendors descend on San Francisco for the RSAC 2026 Conference, the sheer volume of news can be overwhelming. To help you navigate the noise, SecurityWeek is providing a daily digest of the most significant announcements. Below is our curated roundup of essential product and service updates, along with reports from the first day of the event. A roundup of announcements from the days leading up to the conference is also available. Acalvio has released 360 Deception, a cyber deception framework designed to break AI-driven attack automation. By incorporating 360 Deception into their existing tech stack, organizations will be able to disrupt AI-driven threat campaigns and expose malicious intent before compromise occurs. 360 Deception makes cyber defense dynamic and extends it to real assets. The platform creates a high-uncertainty environment that exposes attackers early by disrupting the stable ground truth that automated attack tools depend on. Application security startup Apiiro announced that it is expanding the power of its AI coding security agent, Guardian Agent, with a new capability to identify security and compliance risks before code is ever written, called AI Threat Modeling. Apiiro AI Threat Modeling generates architecture-aware threat models from specs and tickets, enabling teams to identify and fix risks before code is written. By identifying risks earlier, teams can reduce rework, avoid late-stage delays, and keep development moving without adding new security bottlenecks. Arctic Wolf announces new Aurora platform and agentic SOC Arctic Wolf announced the availability of the new Aurora Superintelligence Platform, designed to accelerate the adoption of AI across cybersecurity. Built on a transformative agentic framework called the Swarm of Experts, the platform helps IT and security teams rapidly and confidently adopt Agentic AI to solve the trust and reliability challenges that have slowed adoption in cybersecurity. Arctic Wolf also announced the availability of the new Aurora Agentic SOC. Built on the Aurora Superintelligence Platform, the Aurora Agentic SOC combines Arctic Wolf’s Concierge Experience with turnkey agentic AI. Arctic Wolf also announced a partnership with cloud security firm Wiz to deliver a new integration between Wiz solutions and the Aurora Superintelligence Platform. ArmorCode, in partnership with the Purple Book Community, released The State of AI Risk Management 2026, highlighting a growing “confidence gap” between perceived AI security readiness and actual operational risk. Based on a survey of more than 650 cybersecurity leaders, the report reveals that while 90% of organizations claim visibility into their AI footprint, 59% admit or suspect shadow AI is operating outside of governance processes. At the same time, 70% report vulnerabilities introduced by AI-generated code already making their way into production environments. Astrix has expanded its platform with a four-method AI agent discovery architecture and a real-time policy engine designed to give security teams full visibility and control over AI agents running across the enterprise. Discovery is handled through four complementary approaches: direct integrations with AI platforms, non-human identity fingerprinting to surface shadow agents authenticating via credentials, telemetry ingested from existing endpoint and network sensors, and a bring-your-own-service option for homegrown or non-standard deployments. A new Agent Policies feature lets security teams define allow, flag, and block rules scoped by user, department, platform, and resource type, evaluated before an agent action executes. BeyondTrust has expanded capabilities across its Pathfinder Platform to deliver a unified approach to securing AI agent coworkers that operate alongside users, as well as autonomous AI workloads executing at scale across cloud and SaaS environments. New capabilities include endpoint privilege enforcement for AI coworkers, AI agent discovery and risk analysis, and secrets management for autonomous agents. The company also announced new threat research from BeyondTrust Phantom Labs, which found that the majority of enterprises are running shadow AI agents with privileged access that security teams cannot see or govern. Black Duck has announced the general availability of Black Duck Signal, an application security solution designed to secure AI-generated code and agentic development workflows. Signal delivers AI-native security designed to reason, validate, and remediate risk at the speed and scale of modern development. Built on an agentic architecture powered by multiple best-in-class LLMs and enhanced by Black Duck’s Context AI, Signal brings contextual security reasoning directly into development workflows. Broadcom has announced Symantec CBX (Carbon Black XDR), a cloud-based platform that merges capabilities from its Symantec and Carbon Black product lines into a single XDR solution. The platform combines Symantec’s prevention, Adaptive Protection, data security, Cloud SWG, and Incident Prediction features with Carbon Black’s EDR technology, providing coverage across endpoints, networks, and data. CBX uses AI to correlate signals across those attack surfaces into high-confidence incidents, and includes an Incident Prediction capability that attempts to forecast an attacker’s next four to five moves. Symantec CBX is expected to be available later this year. Cloud Security Alliance launches CSAI Foundation The Cloud Security Alliance (CSA) has established CSAI, a dedicated 501(c)3 non-profit foundation focused exclusively on AI security and safety, with a stated mission of securing the agentic control plane (covering identity, authorization, orchestration, runtime behavior, and trust assurance for autonomous AI agent ecosystems). CSAI builds on CSA’s existing AI Safety Initiative and will operate six programs: an AI Risk Observatory for threat intelligence and CVE tracking specific to agentic AI; best practices guidance covering identity-first controls, runtime authorization, and privilege governance for non-human actors; education and credentialing including three new TAISE certification tracks; a CxO collaboration program for enterprise security executives; and a global assurance program. Cisco has introduced agent discovery in Identity Intelligence, agentic IAM capabilities in Duo, and Model Context Protocol policy enforcement with adaptive risk protection in Secure Access. These features enable registration of agents mapped to human owners, fine-grained task-based permissions, and routing of tool traffic through an MCP gateway for full visibility and governance. Cisco also released ‘AI Defense: Explorer Edition’ for self-serve red teaming of models and applications, including dynamic adversarial testing against prompt injection and jailbreaks. In addition, the company launched the open-source DefenseClaw framework for automated scanning, inventory, and sandboxing of agent skills and assets, as well as an Agent Runtime SDK for embedding policy enforcement at build time across major frameworks. Commvault announced an expanded integration with Microsoft Security to better connect threat detection with trusted recovery. The new integration uses Microsoft Sentinel, Microsoft Security Copilot, and the Commvault Cloud platform to streamline resilience operations and enable real-time data insights, helping organizations move quickly from identifying a threat to validating and restoring clean data faster with greater confidence. ConductorOne announced its AI Access Management product extension, a unified control plane for managing access to AI tools, agents, and MCP connections across the enterprise. The platform enables organizations to accelerate AI adoption while maintaining full visibility, policy enforcement, and compliance. Cribl has introduced background detection for Cribl Guard, an AI-driven capability that continuously scans in-flight logs, traces, and events to identify previously unknown patterns of PII, secrets, and regulated data. The detection model runs entirely within Cribl Workers, meaning sensitive data is analyzed inside the customer’s own infrastructure rather than being sent to an external service. When a new pattern is detected, findings are surfaced in the Cribl interface with full event context, and security teams can convert a finding into an active Guard rule in a single action. CrowdStrike announced new platform innovations that extend AI agent discovery, shadow AI governance, and runtime threat detection directly from the endpoint – the point of AI execution – to every surface where AI agents operate across SaaS, browser, and cloud environments. CrowdStrike also announced that its Falcon Next-Gen SIEM now ingests and correlates Microsoft Defender for Endpoint telemetry, enabling Microsoft endpoint customers to modernize security operations without deploying additional sensors. CrowdStrike also unveiled native Falcon Onum real-time data pipelines, federated search across third-party data stores, third-party intelligence integration, and its Query Translation Agent. CyberProof announced the availability of CyberProof Defense Center (CDC) Reveal360, a centralized visibility hub that delivers continuous insights into enterprise security posture, service performance, and operational outcomes to help teams understand what their security program is delivering. CDC Reveal360 brings together threat, defense, exposure, and asset estate data from across cloud and security ecosystems into configurable, persona-aligned workspaces that evolve as the environment changes. Dataminr launched Dataminr for Cyber Defense, an agentic AI solution designed to move the SOC from reactive triage to predictive intelligence. By fusing internal telemetry with external signals, the solution autonomously investigates and financially quantifies risk. Dropzone AI has introduced AI Threat Hunter, a new autonomous agent designed to continuously and proactively search for security threats across an organization’s environment without increasing workload. The tool automates complex threat hunting processes, analyzing large datasets, investigating anomalies, and integrating across security platforms. By reducing the time needed to conduct investigations, the AI Threat Hunter expands SOC capabilities, allowing human analysts to focus on higher-value strategic work while improving overall security visibility and response. Fenix24 has debuted Argos99, its asset intelligence and resiliency platform, now available as a standalone SaaS offering. Originally developed by Fenix24’s recovery teams during real-world breach restoration efforts, Argos99 ingests and correlates telemetry from more than 60 cloud and on-prem data sources to deliver real-time visibility into an organization’s assets, how they operate, and how they depend on one another. Argos99 was built from hundreds of real-world incident response engagements to address that exact problem. The platform was reverse engineered by the Fenix24 team using insights gained from breach restoration efforts to both dramatically accelerate ransomware recovery and provide critical resiliency intelligence for organizations who want to invest in their cyber resiliency in advance of an attack. Flashpoint is announcing three new capabilities designed to connect threat intelligence more directly to asset risk and operational workflows. The first is a threat-informed External Attack Surface Management (EASM) module that continuously discovers internet-facing assets and automatically maps them to Flashpoint’s vulnerability intelligence. The second is an in-platform Priority Intelligence Requirements (PIRs) feature that lets teams formally tie alerts, investigations, and reporting to defined business risk priorities. The third is a new anonymous browser within Flashpoint Managed Attribution that provides an isolated environment for investigating underground forums, suspicious links, and threat actor activity. Forcepoint and F5 announced a new alliance to help enterprises secure AI across its lifecycle—from foundational data discovery and classification through runtime protection and continuous assurance. Forcepoint’s AI-native Data Security Posture Management (DSPM) data discovery and classification capabilities combined with F5 AI Red Team and F5 AI Guardrails functionality in the F5 Application Delivery and Security Platform (ADSP) will provide runtime protections for AI applications, APIs, models, and agents help organizations operationalize AI safely while maintaining control and visibility over sensitive enterprise data. Forescout unveils network segmentation capabilities and publishes report Now available within the Forescout 4D Platform, Forescout’s new agentless, cloud-native network segmentation capabilities help organizations model and validate zones based on device identity, function, behavior, and risk. Forescout also published its 2026 Riskiest Connected Devices Report, which shows that network infrastructure now surpasses traditional endpoints in overall risk. Among the topline findings, financial services now has the highest average device risk of any industry — more than three times that observed in retail and significantly higher than government and healthcare. Geordie AI has released a new solution for managing AI agent risk through context engineering. Geordie’s new remediation suite, named Beam, assesses risk and continuously feeds mitigation back to the agent using context-based controls. Google Cloud is debuting a suite of AI-powered security innovations designed to transition organizations toward an ‘Agentic SOC’. These updates integrate frontline threat intelligence directly into autonomous AI agents to automate complex investigation and response tasks. Illumio is delivering new enhancements to Illumio Insights to expand how lateral movement risk is exposed and mitigated, anchored by the introduction of Network Posture. By further enriching its AI security graph, Illumio now delivers system-wide, real-time visibility across hybrid, multi-cloud, and OT environments, surfacing end-to-end attack paths and showing where risk must be prioritized and mitigated. Intel 471’s Cyber Threat Exposure Bundle brings together three core capabilities (Attack Surface Exposure, Third-Party Exposure and Brand Exposure) into a single, intelligence-driven solution on the Verity471 platform. With this unified approach, security teams can close visibility gaps across complex external environments and turn high-fidelity threat intelligence into clearly prioritized remediation actions. The solution continuously discovers internet-facing assets, monitors vendors, detects brand impersonation and applies intelligence-led prioritization by enabling streamlined remediation and more proactive threat management. Keeper Security has officially launched KeeperDB, a new vault-embedded database access capability that enables secure, policy-controlled database interactions directly from the Keeper Vault. KeeperDB enables developers, database administrators and security teams to work with sensitive data through a unified interface that simplifies workflows while maintaining strict access governance. KeeperDB broadens KeeperPAM with a vault-native interface that unifies database session management within the zero-trust and zero-knowledge platform. By embedding database access directly into the Vault, KeeperDB helps reduce credential sprawl, standardize database access workflows and strengthen audit readiness across cloud and on-prem environments. Kiteworks has released Compliant AI, a governance layer that enforces attribute-based access control (ABAC), FIPS 140-3 validated encryption, and tamper-evident audit logging on every AI agent interaction with regulated data, independent of the underlying model, prompt, or agent framework. Controls are applied at the data access layer via four checkpoints: agent authentication, ABAC policy evaluation at the operation level, FIPS 140-3 encryption in transit and at rest, and full audit logging fed directly into the organization’s SIEM. The product ships with three Governed Agent Assists: a Folder Operations Assist for navigating and managing folder hierarchies, a File Management Assist for handling the full data lifecycle in line with retention and disposal requirements, and a Forms Creation Assist for generating governed data collection forms from natural language. Lumu announced new capabilities to its flagship NDR solution. Lumu Defender now extends Continuous Compromise Assessment beyond the network to include endpoints, cloud environments, and user behaviors. Lumu continuously confirms whether an organization is compromised by observing live network activity and validating it against known malicious infrastructure. By linking confirmed malicious communications to identities, endpoints, cloud services, and email, Lumu delivers real-time Continuous Compromise Assessment across the environment. NVIDIA has explained how the new NVIDIA OpenShell runtime is being built to provide tools for controlling autonomous agents in an infrastructure policy layer, adding security in the environment, rather than the model or application layer. Currently in early preview, the OpenShell runtime is being developed as organizations are rapidly defining their strategies for long-running AI agents such as OpenClaw. Instead of relying on behavioral prompts, OpenShell enforces constraints on the environment the agent runs in, so security policies are out of reach of the agent — they’re applied at the system level. Operant AI releases Agent ScopeGuard and launches partnership program Operant AI has released Agent ScopeGuard, a new capability within its Agent Protector product that enforces operational boundaries for AI agents at runtime, blocking out-of-scope actions before they execute. ScopeGuard enforces boundaries at the infrastructure level using GPU-accelerated processing, evaluating every agent action against a defined policy in real time. Security teams can configure per-agent scope policies specifying which data sources, APIs, workflows, and data types each agent is authorized to access or modify. Operant AI also launched an AI Infrastructure Ecosystem Partnership Program, through which the company will integrate its runtime security capabilities directly into the inference stacks of AI infrastructure providers. OmniTrust (formerly Integrity Security Services) has officially launched as an independent entity and unveiled its Trust Lifecycle Management (TLM) platform. The platform unifies device lifecycle management, identity lifecycle management, and TrustAI, a framework for the identity, authorization, and monitoring of autonomous AI models and agents. New global research from OpenText and the Ponemon Institute — titled “Managing Risks and Optimizing the Value of AI, GenAI & Agentic AI” — found that while more than half of organizations have fully or partially deployed gen-AI, fewer than one in five have reached AI maturity (defined as fully deployed AI in cybersecurity with security risks assessed). In addition, fewer than half have a risk-based governance strategy in place to manage what they have already built. Palo Alto Networks introduces new security innovations Palo Alto Networks introduced a new set of security innovations designed to help enterprises safely deploy agentic AI and scale AI‑driven workflows. The company announced Prisma Browser for Business, an AI‑enabled workspace for small businesses that lets teams safely use apps and AI tools from any device while blocking AI‑driven threats; Prisma AIRS 3.0, a new platform designed to secure the full agentic AI lifecycle; Agentic SASE enhancements to Prisma SASE; and Next-Generation Trust Security (NGTS) capabilities to automate certificate lifecycle management and support post-quantum readiness. Qualys has introduced Agent Val into its Enterprise TruRisk Management platform. The new agentic AI layer uses TruConfirm to safely validate exploitability of high-risk exposures directly in production environments, incorporating business context and asset criticality. It then feeds confirmed results back into the platform to prioritize remediation and apply mitigations such as isolation when patching is not possible. After mitigation, Agent Val re-validates to confirm the exploit path is closed. RapidFort has partnered with Nutanix to integrate its software supply chain security capabilities into the Nutanix Kubernetes Platform, enabling enterprises to run secure, compliant Kubernetes environments without slowing development. The combined solution delivers hardened, near-zero CVE container images and automated vulnerability remediation, helping organizations reduce risk while maintaining speed across hybrid and multicloud environments. By extending security across the entire software lifecycle, the partnership allows enterprises to proactively manage vulnerabilities, strengthen compliance, and safely support modern workloads such as AI and generative AI at scale. RSA has added a deploy-anywhere capability to its ID Plus identity and access management platform. The sovereign deployment supports private cloud, multi-cloud, on-premises, and air-gapped environments while delivering unified authentication, SSO, access control, and identity governance. It provides end-to-end phishing-resistant passwordless authentication with offline options, along with RSA Mobile Lock, Risk AI, and Help Desk Live Verify to counter advanced threats and bypass attacks. Rubrik announced its Semantic AI Governance Engine (SAGE), a real-time AI governance engine that enables safe, scalable AI agent deployment with semantic policy interpretation and integrated remediation. SAGE removes the AI agent governance bottleneck by enabling real-time, intent-based control at scale. The company also announced a new integration that combines Microsoft’s identity threat detection with Rubrik’s automated identity rollback and recovery capabilities, helping organizations respond faster to identity-based attacks. SandboxAQ, the $5.75 billion Google spinoff focused on AI and quantum, announced new capabilities on its AQtive Guard platform. These newly added capabilities are designed to help organizations identify and track AI systems in use, apply guardrails, and reduce risks (such as prompt injection, data leakage, and unintended system actions) as these systems become part of day-to-day workflows. SentinelOne launched a new set of AI security capabilities focused on two fronts: securing AI and using AI to automate investigations and response. The updates include giving enterprises visibility and control over autonomous agents, AI red teaming, and one-click, agentic investigations that can analyze threats and trigger remediation in real time. SentinelOne also introduced these capabilities for on-prem and air-gapped environments, enabling highly regulated organizations to adopt AI-driven security. Snyk has unveiled Snyk Agent Security, a new solution designed to secure autonomous AI agents from development through production. The suite addresses shadow AI risks by providing automated discovery, risk intelligence, and policy enforcement within the developer workflow. Key features include the general availability of Evo AI-SPM and new red-teaming tools to protect AI-native applications against prompt injection and data leakage. SOCRadar launched its new AI Agent Marketplace, an integrated hub where organizations can browse, purchase, and deploy specialized autonomous AI agents tailored for specific cybersecurity tasks and use cases in the SOCRadar Extended Threat Intelligence Platform. This includes phishing detection, brand abuse protection, and dark web monitoring. SOCRadar also introduced Identity and Access Intelligence capabilities to its Extended Threat Intelligence Platform to bridge the gap between internal identity security and external exposure. The new capabilities are designed to secure identity blind spots such as credential exposures detected in third-party SaaS environments, dark web marketplaces, and collaboration platforms. Spektion has expanded its platform to perform continuous runtime exposure management. It collects six categories of execution data, including execution state, privilege level, network exposure, blast radius, embedded component vulnerabilities, and pre-CVE weakness patterns, then ranks all exposures by observed exploitability in the specific environment. The platform provides visibility into AI agents, MCP servers, AI-generated executables, custom applications, and embedded libraries that lack CVE coverage, while filtering out non-executing vulnerable software. It also enables early identification of zero-day exploit patterns. Sublime Security announced the general availability of its Autonomous Detection Engineer (ADÉ), an end-to-end AI agent that detects threats and automatically creates or improves detection coverage. ADÉ can run end-to-end without analyst intervention – from picking up a newly reported threat to generating and accepting a high-confidence detection. Other new features include full coverage for spam and graymail, increased transparency, and detection labels. Sysdig has launched runtime security for AI coding agents, enabling organizations to safely adopt autonomous development tools. Sysdig provides the real-time visibility organizations need to monitor agent behavior and identify risky activity across cloud and development environments. Sysdig’s purpose-built runtime detections for AI coding agents help organizations safely adopt agentic tools by identifying risky or suspicious behaviors, such as the installation of new AI coding agents, attempts to open sensitive files or bypass unauthorized credential access, risky command-line arguments that weaken safeguards, and dangerous activity, including reverse shells, binary tampering, and persistence mechanisms. Torq released Agentic Builder, an extension of its AI SOC Platform designed to transform natural language descriptions of security goals into production-grade AI agents and workflows. By shifting the ‘cognitive load’ of engineering from humans to machines, the tool allows security teams to automate complex tasks, including alert triage, investigation, and response. The platform further ensures operational reliability by using the Torq Socrates orchestrator to test, validate, and continuously auto-calibrate these agents against real-world data and evolving threats. Upwind has developed a three-stage pipeline for real-time identification and blocking of malicious prompts sent to large language models. A lightweight classifier first filters incoming traffic to detect LLM-bound requests in under one millisecond with 99.88% accuracy. Identified prompts then undergo semantic analysis using the Nvidia nv-embedcode-7b-v1 model via NIM microservices, achieving 94.53% detection accuracy for prompt injections and indirect jailbreaks in under 0.1 milliseconds. High-risk or uncertain cases escalate selectively to the NVIDIA Nemotron-3-Nano-30B model with NeMo Guardrails for final validation, delivering overall precision near 95% while preserving sub-millisecond end-to-end latency and low cost at production scale. Versa announced early access for Versa Secure Enterprise Browser, a browser-native security capability integrated into the VersaONE Universal SASE Platform that enforces identity-aware, posture-aware, and data-aware policies directly within the browser session. Built on Chromium, it protects employees accessing SaaS, web, and AI applications by governing actions such as file uploads, data copying, and AI tool usage. Versa has also announced a new cloud-delivered capability that extends SSE to inspect and secure inbound internet traffic, collaboration with Intel for AI-driven security, networking, and analytics, and integration between Versa Secure SD-WAN and Zscaler Internet Access. Vorlon has released ‘The Agentic Ecosystem Security Gap: 2026 CISO Report’, a survey of 500 US security leaders that surfaces a troubling contradiction at the heart of enterprise security. Organizations are more confident, more tooled, and more breached than ever, with 99.4% reporting at least one SaaS or AI ecosystem incident in 2025 despite widespread claims of strong or comprehensive protection. The report points to a gap in security architecture, where existing tools lack visibility into the runtime layer of AI agents, integrations, and data movement across the ecosystem. Wiz unveils AI Application Protection Platform and Red Agent Wiz (now part of Google Cloud) launched its AI Application Protection Platform (AI-APP) to secure every layer of AI applications (infrastructure, data, access, models, agents, and applications) from code to runtime. Wiz AI-APP brings together visibility, risk analysis, and runtime protection into a single, graph-powered platform. Wiz also unveiled Red Agent, an AI-powered attacker that acts as a sophisticated security researcher, but with AI speed and scale. Zenity announces AI agent security and OpenClaw security framework Zenity announced two product updates focused on securing AI agents: a new continuous, contextual security model designed to track how risk evolves across agent interactions, and an open-source security framework for OpenClaw that lets developers inspect prompts, evaluate tool use, and analyze outputs before execution.
securityweek.comMar 24, 2026extracted
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More
ThreatsDay Bulletin is back on The Hacker News, and this week feels off in a familiar way. Nothing loud, nothing breaking everything at once. Just a lot of small things that shouldn’t work anymore but still do. Some of it looks simple, almost sloppy, until you see how well it lands. Other bits feel a little too practical, like they’re already closer to real-world use than anyone wants to admit. And the background noise is getting louder again, the kind people usually ignore. A few stories are clever in a bad way. Others are just frustratingly avoidable. Overall, it feels like quiet pressure is building in places that matter. Skim it or read it properly, but don’t skip this one. Emerging RaaS exploiting FortiGate flawsGroup-IB has shed light on the various tactics adopted by The Gentlemen, a nascent Ransomware-as-a-Service (RaaS) operation that consists of about 20 members. It originated from a payment dispute after its operator "hastalamuerte" opened a public arbitration thread on the RAMP cybercrime forum, accusing Qilin ransomware operators of unpaid affiliate commission amounting to $48,000. The group primarily uses CVE-2024-55591, a critical authentication bypass vulnerability in FortiOS/FortiProxy, for initial access. "The group maintains an operational database of approximately 14,700 already exploited FortiGate devices globally," the company said. "Separate from exploited devices, the operators maintain 969 validated brute-forced FortiGate VPN credentials ready for attack." The Gentlemen also employs defense evasion via the bring your own vulnerable driver (BYOVD) technique to terminate security processes at the kernel level. About 94 organizations have already been attacked by this threat group since its emergence in July/August 2025. Pre-auth RCE chain in ITSM platformFour security flaws (CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, and CVE-2025-71260) have been disclosed in BMC FootPrints, a widely deployed ITSM solution, that could be chained into pre-authentication remote code execution. The attack sequence begins with an authentication bypass (CVE-2025-71257) that extracts a guest session token ("SEC_TOKEN") from the password reset endpoint, which is then used to reach an unsanitized Java deserialization sink (CVE-2025-71260) in the "/aspnetconfig" endpoint's "__VIEWSTATE" parameter. Exploitation via the AspectJWeaver gadget chain enables arbitrary file write to the Tomcat web root directory, achieving full remote code execution. Armed with the SEC_TOKEN, an attacker could also exploit two SSRF flaws (CVE-2025-71258 and CVE-2025-71259) and potentially leak internal data. The issues were addressed in September 2025. Loader deploys stealthy C2 malwareThe malware loader known as Hijack Loader is being used to deliver a previously undocumented, C++-based command-and-control (C2) framework known as SnappyClient. "SnappyClient has an extended list of capabilities, including taking screenshots, keylogging, a remote terminal, and data theft from browsers, extensions, and other applications," Zscaler ThreatLabz said. "SnappyClient employs multiple evasion techniques to hinder endpoint security detection, including an Antimalware Scan Interface (AMSI) bypass, as well as implementing Heaven’s Gate, direct system calls, and transacted hollowing. SnappyClient receives two configuration files from the C2 server, which contain a list of actions to perform when a specified condition is met, along with another that specifies applications to target for data theft." The framework was first discovered in December 2025. The attack chain involves the distribution of malicious payloads after a user visits a website impersonating the Spanish telecom firm Telefónica. It's assessed that the primary use for SnappyClient is cryptocurrency theft, with a possible connection between the developers of HijackLoader and SnappyClient based on observed code similarities. Deep link abuse enables command executionProofpoint has detailed a new technique called CursorJack that abuses Cursor's support for Model Context Protocol (MCP) deep links to enable local command execution or allow installation of a malicious remote MCP server. The attack takes advantage of the fact that MCP servers commonly specify a command in their "mcp.json" configuration. "The cursor:// protocol handler could be abused through social engineering in specific configurations," the company said. "A single click followed by user acceptance of an install prompt could result in arbitrary command execution. The technique could be leveraged both for local code execution via the command parameter or to install a malicious remote MCP server via the URL parameter." The enterprise security firm has also released a proof-of-concept (PoC) exploit on GitHub. Mass exploitation hits Citrix flawsA new campaign is actively targeting known security flaws in Citrix NetScaler (CVE-2025-5777 and CVE-2023-4966). According to Defused Cyber, more than 500 exploit attempts have been recorded against its honeypot system on March 16, 2026. "Highly elevated exploit activity against older vulnerabilities can often precede a zero-day vulnerability," it said. Teams phishing grants remote accessRapid7 said it's seeing an increase in phishing campaigns where threat actors impersonate internal IT departments via Microsoft Teams. "The primary objective is to persuade users to launch Quick Assist, granting the TA remote access to deploy malware, exfiltrate data, or facilitate lateral movement across the network," it added. "The recent surge in Teams-based delivery highlights a critical vulnerability in how organizations manage external access. Teams often allows any external user to message internal staff. This is the functional equivalent of operating an email server without a gateway filter." ClickFix delivers AutoHotKey backdoorA new ClickFix-style campaign has compromised a Pakistani government website ("wasafaisalabad.gop[.]pk") to deliver fake CAPTCHA lures. The attack chain installs an MSI installer via a disguised clipboard command, which drops an AutoHotKey-based backdoor polling a remote server for tasks, Gen Digital said. It's currently not known how the website was breached. The social engineering tactic has proved so effective that even nation-state groups such as North Korea's Lazarus group, Iran's MuddyWater, and Russia’s APT28 have adopted it. In January, researchers from Sekoia reported that a separate ClickFix framework dubbed IClickFix had been injected into over 3,800 WordPress sites since 2024. Stealer upgrade spreads via pirated gamesThe malware loader known as Hijack Loader is being used to deliver an updated version of an information stealer referred to as ACRStealer. "This updated variant follows similar evasion techniques and C2 initialization strategy to make it even stealthier," G DATA said. "This integration with HijackLoader highlights ACRStealer's versatility and modularity, which will likely attract more malicious actors to use it as a final payload." In these campaigns, Hijack Loader is downloaded from the domain associated with PiviGames, a Spanish portal hosting pirated PC games. The development comes against the backdrop of another campaign that involved several cases of malware being distributed through PiviGames. Live chat phishing steals sensitive dataA new phishing campaign has been observed using LiveChat, a customer service software featuring live messaging, to steal data. Phishing emails using refund-related themes are used to redirect users to a link hosted via LiveChat's service ("direct.lc[.]chat"), from where they are asked to click on a link sent in the chat to complete the refund by entering their personal and financial information. "Unlike typical refund scams or credential phishing, this campaign engages victims through a real-time chat interface, impersonating well-known brands in order to harvest sensitive data such as account credentials, credit card details, multi-factor authentication (MFA) codes, and other personally identifiable information (PII)," Cofense said. RagaSerpent expands multi-region espionageA SideWinder-adjacent cluster known as RagaSerpent is suspected to be leveraging tax audit and government compliance themes in spear-phishing emails to deliver multi-stage malware for command-and-control (C2) and establish sustained access across targeted organizations in Southeast Asia, including Indonesia and Thailand. The attack chain is consistent with a prior campaign targeting India using similar tax-related lures to deliver a legitimate enterprise tool called SyncFuture TSM, developed by a Chinese company. "This is not unusual in APT operations: in-country targeting can be used to complicate attribution (e.g., by creating noisy 'domestic' victimology) or to reach foreign diplomats/missions operating inside India—a pattern explicitly noted in reporting on SideWinder’s broader geographic targeting and diplomatic victim set," ITSEC Asia said. The recent campaigns show the threat actor has expanded its operations beyond South Asia and into Africa, Europe, the Middle East, and Southeast Asia. Unauthenticated access exposed device dataDJI has patched a security flaw in its backend that could have allowed attackers to take over all its Romo smart vacuums. Security researcher Sammy Azdoufal said DJI servers returned data for any device just by providing a device serial number. DJI shared the data on any device without any authentication or authorization. The researcher said he was able to map the locations of more than 7,000 Romo smart vacuums and 3,000 DJI portable power stations that shared the same server. New password layer strengthens account securityWhatsApp has begun testing support for setting an alphanumeric account password. It can be anywhere between six and 20 characters long and should include at least one letter and one number. Adding an alphanumeric password to the equation is likely an effort to make brute-force attempts harder. For example, if a threat actor carries out a SIM swap to intercept messages and bypass two-factor authentication, they would still need to enter the 6-20 character-long password to gain access to the victim's WhatsApp account. Suspected ransomware group appears fabricatedMore evidence has emerged that the 0APT ransom group is likely a fake and a fraud. "Thus far, the threat actor has not provided credible proof of ransomware or data exfiltration attacks as the data samples on the DLS appeared to be fabricated," Intel 471 said. "For example, the files that supposedly contained metadata of data stolen from victim networks were unusually large, reaching several terabytes each. Additionally, partial downloads of those files indicated they did not contain any useful data, and in fact, we observed several instances in which the content contained a repeating pattern of null bytes." Google blocks millions of risky appsGoogle rejected 1.75 million policy-violating Android apps and blocked more than 80,000 developer accounts from the Google Play Store in 2025, down from 2.36 million apps and 158,000 accounts in 2024. The company said that through 2025, it blocked more than 255,000 Android apps from obtaining excessive access to sensitive user data, and that it implemented more than 10,000 safety checks on published apps and strengthened detection capabilities by integrating Google's latest generative artificial intelligence (AI) models into the review process. Android's built-in security suite, Play Protect, which now scans over 350 billion apps every day, has identified over 27 million malicious apps sideloaded from outside Google Play. Play Protect's 'enhanced fraud protection' has been expanded to cover over 2.8 billion Android devices in 185 markets, blocking 266 million installation attempts from 872,000 unique risky apps. In a related development, the tech giant has made available Scam Detection for phone calls on Google Pixel devices in the U.S., U.K., Australia, Canada, France, Germany, India, Ireland, Italy, Japan, Mexico, and Spain. It's also being expanded to Samsung Galaxy S26 series in the U.S. 1% of flaws drove most attacksA report from VulnCheck found that a mere 1% of 2025 CVEs were exploited in the wild by the end of the year. Network edge devices accounted for a third of all products exploited last year. "There was a small decrease (-13%) in new vulnerabilities linked to named state-sponsored threat groups and APTs over the course of 2025," the cybersecurity company said. "New CVE exploits attributed to China-nexus groups increased while Iranian exploit activity fell." Another report from IBM X-Force revealed that there has been a 44% increase in cyberattacks exploiting public-facing applications. EU extends CSAM detection rulesThe European Parliament has voted to extend a temporary exemption to E.U. privacy legislation that allows online platforms to voluntarily detect child sexual abuse material (CSAM) until August 2027. Lawmakers said the additional time will allow the bloc to negotiate and adopt a long-term legal framework to prevent and combat CSAM online. AOT malware evades analysis and detectionA previously undocumented attack chain delivered via a phishing URL has been found to distribute a ZIP archive containing a C++ trojan downloader, which then initiates a loader responsible for decrypting and staging the Rhadamanthys stealer and XMRig cryptocurrency miner. "The campaign's core evasion relies on .NET Native Ahead-of-Time (AOT) compiled binaries, which strip traditional .NET metadata, frustrate common .NET analysis tools, and force analysts to fall back on native-level tooling, making detection and reverse engineering significantly harder," Cyderes said. "Sophisticated anti-analysis capabilities: The AOT loader employs a sandbox scoring system evaluating RAM size, system uptime, user file counts, and AV process presence; virtual machine detection via registry inspection; and active suppression of miner activity when monitoring tools like Task Manager, Process Hacker, or x64dbg are detected." Secrets sprawl surges across GitHubGitGuardian's State of Secrets Sprawl report has found that 28,649,024 new secrets were added to public GitHub commits in 2025 alone, up 34% from the previous year. The figure also represents a 152% increase in leaked secrets growth since 2021. In 2025, AI service secrets reached 1,275,105, up 81% year-over-year. Also identified by GitGuardian were 24,008 unique secrets exposed in MCP-related configuration files across public GitHub, including 2,117 unique valid credentials. Malicious themes inject ads and redirectsSix malicious Packagist packages posing as OphimCMS themes have been found to contain trojanized jQuery that exfiltrates URLs, injects full-screen overlay ads, and loads Funnull-linked redirects. The packages are ophimcms/theme-dy, ophimcms/theme-mtyy, ophimcms/theme-rrdyw, ophimcms/theme-pcc, ophimcms/theme-motchill, and ophimcms/theme-legend. "All six ship trojanized JavaScript assets, primarily disguised as legitimate jQuery libraries, that redirect visitors, exfiltrate URLs, inject ads, and in the most severe case load a second-stage payload – a mobile-targeted redirect to gambling and adult content sites, from infrastructure operated by Funnull," Socket said. Multi-stage phishing bypasses security filtersA C-level executive at Swedish security firm Outpost24 was targeted in a sophisticated phishing attack. The multi-chain redirect phishing campaign impersonated JPMorgan Chase to trick the recipient into reviewing a document by clicking on a link and triggering the infection. The link is a redirect URL hosted within Cisco's infrastructure, which then initiates a series of URL redirects that leverage trusted services like Nylas as well as compromised legitimate infrastructure to bypass security filters and conceal the final phishing destination. "Several stages redirect victims through legitimate or previously reputable domains, reducing the likelihood that security scanners or reputation-based filtering will block the link," Specops said. "The attackers went as far as to implement a legitimate Cloudflare-based 'human validation' step to ensure that only real people saw the actual landing page where credentials are requested." The attack, ultimately unsuccessful, is said to have used a new phishing-as-a-service (PhaaS) toolkit named Kratos. Some of this will fade by next week. Some of it won’t. That’s the annoying part, figuring out which “minor” thing quietly sticks around and turns into a real problem later. Anyway, that’s the rundown. Take what you need, ignore what you can, and keep an eye on the stuff that feels a little too easy.
thehackernews.comMar 19, 2026extracted
Shadow AI Risk: How SaaS Apps Are Quietly Enabling Massive Breaches
A new report from Grip Security analyzes 23,000 SaaS application environments. The statistics it found include: 100% of analyzed companies operate SaaS environments with embedded AI; there has been a year-over-year 490% spike in public SaaS attacks; and 80% of documented incidents involve PII and/or customer data. “But what really surprised me,” says Chad Holmes, product marketing consultant at Grip Security, “is that organizations have an average of 140 AI-enabled SaaS environments.” If an AI-enabled app is breached, any integral agentic AI can be used first to access data from connected systems, secondly to cascade from the one breach to a breach of every other AI-enabled environment within the organization – and potentially to expand further into AI-enabled environments in other organizations. This is chaos. The poster boy example of this cascading chaos is the Salesloft Drift incident (the ‘Great SaaS Breach of 2025’). Ultimately more than 700 organizations were affected, including security firms Cloudflare, Palo Alto Networks, Zscaler and CyberArk. UNC6395 attackers compromised Salesloft’s internal systems, starting with their GitHub repositories and moving from there into the Drift AWS environment. Here they stole the active OAuth and refresh tokens used by customers to connect the Drift Chatbot to local installations of Salesforce and other apps such as Slack. Armed with the legitimate pre-approved OAuth token, the attackers were able to impersonate Drift and log directly into Salesforce installations into companies also using the Drift chatbot. One breach of a SaaS app (Drift) cascaded into hundreds of compromises in different companies across the globe. Now it is fair to say that this incident prompted a drive to improve the security of SaaS apps and their AI implementations, but Grip is not convinced it will be enough. “One thing we’re seeing,” comments Holmes, “as we’ve moved outside the traditional perimeter, outside firewalls and network level protections, identity is the new perimeter. The focus is on identity, and if we have that identity, we can log into any environment anywhere.” For attacks against SaaS AI, the key ‘identity’ is a valid OAuth token. It’s worth briefly examining why this is such a threat, if control hasn’t been achieved. Much of it is down to the current need for speed in business. SaaS developers are tempted to rapidly include agentic AI within their own products to improve efficiency ahead of their competition, and they don’t always make the implications apparent to their customers. The customer may have installed shadow AI without knowledge. ‘Shadow’ is the epithet used to describe the use of AI or autonomous agentic AI without formal oversight from the IT and security departments – and if the customer is unaware of the AI within the SaaS app, it is automatically ‘shadow’. Customers adopt these apps too hastily, again to rapidly improve their own efficiency, and often without auditing them. Meanwhile, they have become so accustomed to issuing OAuth tokens that they may do so automatically as required by the SaaS app without considering wider implications from installing shadow AI. While complexity is the enemy of security, SaaS is the disguiser and multiplier of complexity, through poor visibility into its shadow AI. An attacker can often find greater visibility into a SaaS app by stealing the right OAuth access and/or refresh token (courtesy of the modern infostealer that can enter, scrape and depart without the victim realizing it). Armed with the right OAuth token, the attacker can enter the app unhindered, and start gathering data from whatever other systems are connected to the agentic system simply by feeding it tailored prompts through the APIs. However, the danger is not limited to the single SaaS app containing the shadow AI’s own environment – it can cascade to other environments within the organization. IdentityMesh can be an unintentional flaw resulting in a single unified authentication context. This allows the attacker inside the SaaS app to access all other agentic systems within the environment. If one of these has access to third party apps or shared service accounts used across organizations, the attacker can then pivot the attack across multiple organizations – and the cascading effect caused by a single stolen OAuth token in one company can cause the loss of data in many others. “AI is not a future risk, nor is it ‘just an IT problem’,” notes the report. “And crucially, governing it is not optional. It is now one of the most influential forces shaping how modern businesses operate and take on risk.” The report suggests that 2026 may be the worst year yet for SaaS breaches, warning that the increased blast radius may expand further as autonomous workflows outpace existing security controls. There are attempts at regulation, but globally, such regulations are moving in different directions with conflicting mandates, uneven enforcement and increased compliance friction. “AI regulation will get messier before it gets clearer,” says the report. But the chaos can be brought under control. “The way out is not more policy or slower innovation. It is a shift in how AI is governed in practice,” adds the report. The key is increased visibility into, and understanding of, SaaS shadow AI, and more dynamic governance. “Leaders who succeed replace static approvals with continuous oversight, discovery, and risk-based controls. AI becomes a managed third-party risk, monitored continuously, aligned to business outcomes, and governed with the same rigor as any critical supplier.” Related: The Blast Radius Problem: Stolen Credentials Are Weaponizing Agentic AI Related: Microsoft Highlights Security Risks Introduced by New Agentic AI Feature Related: Infostealers: The Silent Smash-and-Grab Driving Modern Cybercrime
securityweek.comMar 18, 2026extracted
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & More
Some weeks in security feel normal. Then you read a few tabs and get that immediate “ah, great, we’re doing this now” feeling. This week has that energy. Fresh messes, old problems getting sharper, and research that stops feeling theoretical real fast. A few bits hit a little too close to real life, too. There’s a good mix here: weird abuse of trusted stuff, quiet infrastructure ugliness, sketchy chatter, and the usual reminder that attackers will use anything that works. Scroll on. You’ll see what I mean. ⚡ Threat of the Week Google Patches 2 Actively Exploited Chrome 0-Days — Google released security updates for its Chrome web browser to address two high-severity vulnerabilities that it said have been exploited in the wild. The vulnerabilities related to an out-of-bounds write vulnerability in the Skia 2D graphics library (CVE-2026-3909) and an inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine (CVE-2026-3910) that could result in out-of-bounds memory access or code execution, respectively. Google did not share additional details about the flaws, but acknowledged that there exist exploits for both of them. The issues were addressed in Chrome versions 146.0.7680.75/76 for Windows and Apple macOS, and 146.0.7680.75 for Linux. Detection Starts the Clock. Response Decisions Shape the Outcome When incidents escalate, early decisions determine containment and impact. Join this SANS IR Command Roundtable to learn how experienced teams avoid investigation drift, improve coordination, and execute faster response across cloud, enterprise, and operational environments. Watch the Webcast ➝ 🔔 Top News Meta to Discontinue Instagram E2EE in May 2026 — Meta announced plans to discontinue support for end-to-end encryption (E2EE) for chats on Instagram after May 8, 2026. In a statement shared with The Hacker News, a Meta spokesperson said, "Very few people were opting in to end-to-end encrypted messaging in DMs, so we're removing this option from Instagram in the coming months. Anyone who wants to keep messaging with end-to-end encryption can easily do that on WhatsApp." Authorities Disrupt SocksEscort Service — A court-authorized international law enforcement operation dismantled a criminal proxy service named SocksEscort that enslaved thousands of residential routers worldwide into a botnet for committing large-scale fraud. "The malware allowed SocksEscort to direct internet traffic through the infected routers. SocksEscort sold this access to its customers," the U.S. Justice Department said. The main thing to note here is that SocksEscort was powered by AVrecon, a malware written in C to explicitly target MIPS and ARM architectures via known security flaws in edge network devices. The malware also featured a novel persistence mechanism that involved flashing custom firmware, which intentionally disables future updates, permanently transforming SOHO routers into SocksEscort proxy nodes to blindside corporate monitoring. UNC6426 Exploits nx npm Supply Chain Attack to Gain AWS Admin Access in 72 Hours — A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package in August 2025 to completely breach a victim's AWS environment within 72 hours. UNC6426 used the access to abuse the GitHub-to-AWS OpenID Connect (OIDC) trust and create a new administrator role in the cloud environment, Google said. Subsequently, this role was abused to exfiltrate files from the client's Amazon Web Services (AWS) Simple Storage Service (S3) buckets and perform data destruction in their production cloud environments. KadNap Enslaves Network Devices to Fuel Illegal Proxy — A takedown-resistant botnet comprising more than 14,000 routers and other network devices has been conscripted into a proxy network that anonymously ferries traffic used for cybercrime. The botnet, named KadNap, exploits known vulnerabilities in Asus routers (among others), leveraging the initial access to drop shell scripts that reach out to a peer-to-peer network based on Kademlia for decentralized control. Infected devices are being used to fuel a proxy service named Doppelganger that, for a fee, tunnels customers' internet traffic through residential IP addresses, offering a way for attackers to blend in and make it harder to differentiate malicious traffic from legitimate activity. APT28 Strikes with Sophisticated Toolkit — The Russian threat actor known as APT28 has been observed using a bespoke toolkit in recent cyber espionage campaigns targeting Ukrainian cyber assets. The primary components of the toolkit are two implants, one of which employs techniques from a malware framework the threat actor used in 2010s, while the other is a heavily modified version of the COVENANT framework for long-term spying. COVENANT is used in concert with BEARDSHELL to facilitate data exfiltration, lateral movement, and execution of PowerShell commands. Also alongside these tools is a malware named SLIMAGENT that shares overlaps with XAgent. ️🔥 Trending CVEs New vulnerabilities show up every week, and the window between disclosure and exploitation keeps getting shorter. The flaws below are this week's most critical — high-severity, widely used software, or already drawing attention from the security community. Check these first, patch what applies, and don't wait on the ones marked urgent — CVE-2026-3909, CVE-2026-3910, CVE-2026-3913 (Google Chrome), CVE-2026-21666, CVE-2026-21667, CVE-2026-21668, CVE-2026-21672, CVE-2026-21708, CVE-2026-21669, CVE-2026-21671 (Veeam Backup & Replication), CVE-2026-27577, CVE-2026-27493, CVE-2026-27495, CVE-2026-27497 (n8n), CVE-2026-26127, CVE-2026-21262 (Microsoft Windows), CVE-2019-17571, CVE-2026-27685 (SAP), CVE-2026-3102 (ExifTool for macOS), CVE-2026-27944 (Nginx UI), CVE-2025-67826 (K7 Ultimate Security), CVE-2026-26224, CVE-2026-26225 (Intego X9), CVE-2026-29000 (pac4j-jwt), CVE-2026-23813 (HPE Aruba Networking AOS-CX), CVE-2025-12818 (PostgreSQL), CVE-2026-2413 (Ally WordPress plugin), CVE-2026-0953 (Tutor LMS Pro WordPress plugin), CVE-2026-25921 (Gogs), CVE-2026-2833, CVE-2026-2835, CVE-2026-2836 (Cloudflare Pingora), CVE-2026-24308 (Apache ZooKeeper), CVE-2026-3059, CVE-2026-3060, CVE-2026-3989 (SGLang), CVE-2026-0231 (Palo Alto Networks Cortex XDR Broker VM), CVE-2026-20040, CVE-2026-20046 (Cisco IOS XR Software), CVE-2025-65587 (graphql-upload-minimal), CVE-2026-3497 (OpenSSH), CVE-2026-26123 (Microsoft Authenticator for Android and iOS), and CVE-2025-61915 (CUPS). 🎥 Cybersecurity Webinars Stop Guessing: Automate Your Defense Against Real-World Attacks → Learn how to move beyond basic security checklists by using automation to test your defenses against real-world attacks. Experts will show you why traditional testing often fails and how to use continuous, data-driven tools to find and fix gaps in your protection. You will learn how to prove your security actually works without increasing your manual workload. Fix Your Identity Security: Closing the Gaps Before Hackers Find Them → This webinar covers a new study about why many companies are struggling to keep their user accounts and digital identities safe. Experts share findings from the Ponemon Institute on the biggest security gaps, such as disconnected apps and the new risks created by AI. You will learn simple, practical steps to fix these problems and get better control over who has access to your company's data. The Ghost in the Machine: Securing the Secret Identities of Your AI Agents → As artificial intelligence (AI) begins to act on its own, businesses face a new challenge: how to give these "AI agents" the right digital IDs. This webinar explains why current security for humans doesn't work for autonomous bots and how to build a better system to track what they do. You will learn simple, real-world steps to give AI agents secure identities and clear rules, ensuring they don't accidentally expose your private company data. 📰 Around the Cyber World Fake Google Security Check Drops Browser RAT — A web page mimicking a Google Account security page has been spotted delivering a fully featured browser-based surveillance toolkit that takes the form of a Progressive Web App (PWA). "Disguised as a routine security checkup, it walks victims through a four-step flow that grants the attacker push notification access, the device's contact list, real-time GPS location, and clipboard contents—all without installing a traditional app," Malwarebytes said. "For victims who follow every prompt, the site also delivers an Android companion package introducing a native implant that includes a custom keyboard (enabling keystroke capture), accessibility-based screen reading capabilities, and permissions consistent with call log access and microphone recording." Forbidden Hyena Delivers BlackReaperRAT — A hacktivist group known as Forbidden Hyena (aka 4B1D) has distributed RAR archives in December 2025 and January 2026 in attacks targeting Russia that led to the deployment of a previously undocumented remote access trojan called BlackReaperRAT and an updated version of the Blackout Locker ransomware, referred to as Milkyway by the threat actors. BlackReaperRAT is capable of running commands via "cmd.exe," uploading/downloading files, spawning an HTTP shell to receive commands, and spreading the malware to connected removable media. "It carries out destructive attacks against organizations across various sectors located within the Russian Federation," BI.ZONE said. "The group publishes information regarding successful attacks on its Telegram channel. It collaborates with the groups Cobalt Werewolf and Hoody Hyena." Chinese Hackers Target the Persian Gulf region with PlugX — A China-nexus threat actor, likely suspected to be Mustang Panda, has targeted countries in the Persian Gulf region. The activity took place within the first 24 hours of the ongoing conflict in the Middle East late last month. The campaign used a multi-stage attack chain that ultimately deployed a PlugX backdoor variant. "The shellcode and PlugX backdoor used obfuscation techniques such as control flow flattening (CFF) and mixed boolean arithmetic (MBA) to hinder reverse engineering," Zscaler said. "The PlugX variant in this campaign supports HTTPS for command-and-control (C2) communication and DNS-over-HTTPS (DOH) for domain resolution." Phishing Campaign Uses SEO Poisoning to Steal Data — A phishing campaign has employed SEO poisoning to direct search engine results to fake traffic ticket portals that impersonate the Government of Canada and specific provincial agencies. "The campaign lures victims to a fake 'Traffic Ticket Search Portal' under the pretense of paying outstanding traffic violations," Palo Alto Networks Unit 42 said. "Submitted data includes license plates, address, date of birth, phone/email, and credit card numbers." The phishing pages utilize a "waiting room" tactic where the victim's browser polls the server every two seconds and triggers redirects based on specific status codes. Roundcube Exploitation Toolkit Discovered — Hunt.io said it discovered a Roundcube exploitation toolkit on an internet-exposed directory on 203.161.50[.]145. It's worth noting that Russian threat actors like APT28, Winter Vivern, and TAG-70 have repeatedly targeted Roundcube vulnerabilities to breach Ukrainian organizations. "The directory included development and production XSS payloads, a Flask-based command-and-control server, CSS-injection tooling, operator bash history, and a Go-based implant deployed on a compromised Ukrainian web application," the company said, attributing it with medium to high confidence to APT28, citing overlaps with Operation RoundPress. The toolkit, dubbed Roundish, supports credential harvesting, persistent mail forwarding, bulk email exfiltration, address book theft, and two-factor authentication (2FA) secret extraction, mirroring a feature present in MDAEMON. One of the primary targets of the attack is mail.dmsu.gov[.]ua, a Roundcube webmail instance associated with Ukraine's State Migration Service (DMSU). Besides the possibility of a shared development lineage, Roundish introduces four new components not previously documented in APT28 webmail activity, including a CSS-based side-channel module, browser credential stealer, and a Go-based backdoor that provides persistence via cron, systemd, and SELinux. The CSS injection component is designed to progressively extract characters from Roundcube's document object model (DOM) without injecting any JavaScript into the victim's page. The technique is likely used for targeting Cross-Site Request Forgery (CSRF) tokens or email UIDs. Central to the Roundish toolkit is an XSS payload that's engineered to steal the victim's email address, harvest account credentials, redirect all incoming emails to a Proton Mail address, export mailbox data from the victim's Inbox and Sent folders, and gather the victim's complete address book. "The combination of hidden autofill credential harvesting, server-side mail forwarding persistence, bulk mailbox exfiltration, and browser credential theft reflects a modular approach designed for sustained access," Hunt.io said. "From a defensive perspective, password resets alone are not sufficient in cases like this. Mail forwarding rules, Sieve filters, and multi-factor authentication secrets must be audited and reset." Phishing Campaign Targeting AWS Console Credentials — An active adversary-in-the-middle (AiTM) phishing campaign is using fake security alert emails to steal AWS Console credentials, per Datadog. "The phishing kit proxies authentication to the legitimate AWS sign-in endpoint in real time, validating credentials before redirecting victims and likely capturing one-time password (OTP) codes," the company said. "This campaign does not exploit AWS vulnerabilities or abuse AWS infrastructure." Post-compromise console access has been observed within 20 minutes of credential submission. These efforts originated from Mullvad VPN infrastructure. Malicious npm Packages Deliver Cipher stealer — Two new malicious npm packages, bluelite-bot-manager and test-logsmodule-v-zisko, were found to deliver via Dropbox a Windows executable designed to siphon sensitive data, including Discord totems, credentials from Chrome, Edge, Opera, Brave, and Yandex browsers, and seed files from cryptocurrency wallet apps like Exodus. from compromised hosts using a stealer named Cipher stealer. "The stealer also uses an embedded Python script and a secondary payload downloaded from GitHub," JFrog said. GIBCRYPTO Ransomware Detailed — A new ransomware called GIBCRYPTO comes with the ability to capture keystrokes and corrupt the Master Boot Record (MBR) so that any attempt to restart the system will cause the system to run into an error. The ransomware uses the Salsa20 algorithm for encryption. It's suspected to be part of Snake Keylogger, indicating the malware authors' attempts to diversify beyond information theft. The development comes as Sygnia highlighted SafePay's OneDrive-based data exfiltration technique during a ransomware attack after breaching a victim by leveraging a FortiGate firewall flaw and a misconfigured administrative account. "SafePay gained initial access by exploiting a firewall misconfiguration, which enabled them to obtain local administrative credentials," the company said. "They rapidly escalated discovery and enumeration activities to identify high-value targets for lateral movement, demonstrating a structured and methodical approach to mapping the environment. Within a matter of hours, SafePay escalated to domain administrator access." The attack culminated in the deployment of ransomware, encrypting more than 60 servers. Fraudulent Account Registration Activity Originating from Vietnam — A sprawling cybercrime ecosystem based in Vietnam has been linked to a cluster of fraudulent account registration activity on platforms like LinkedIn, Instagram, Facebook, and TikTok. In these attacks, attributed to O-UNC-036, the threat actors rely on disposable email addresses in order to execute SMS pumping attacks, also called International Revenue Sharing Fraud (IRSF). "In this scheme, malicious actors automate the creation of puppet accounts in a targeted service provider," Okta said. "Fraudsters use these account registrations to trigger SMS messages to premium rate phone numbers and profit from charges incurred. This activity can prove costly for service providers who use SMS to verify registration information in customer accounts or to send multi-factor authentication (MFA) security codes." O-UNC-036 has also been linked to a cybercrime-as–a-service (CaaS) ecosystem that provides paid infrastructure and services to facilitate online fraud. The web-based storefronts are hosted in Vietnam and specialize in the sales of web-based accounts. Hijacked AppsFlyer SDK Distributes Crypto Clipper — The AppsFlyer Web SDK was briefly hijacked to serve malicious code to steal cryptocurrency in a supply chain attack. The clipper malware payload came with capabilities to intercept cryptocurrency wallet addresses entered on websites and replace them with attacker-controlled addresses to divert funds to the threat actor. "The AppsFlyer Web SDK was observed serving obfuscated malicious JavaScript instead of the legitimate SDK from websdk.appsflyer[.]com," Profero said. "The malicious payload appears to have been designed for stealth and compatibility, preserving legitimate SDK functionality while adding hidden browser hooks and wallet-hijacking logic." The incident has since been resolved by AppsFlyer. Operation CamelClone Targets Government and Defense Entities — A new cyber espionage campaign dubbed Operation CamelClone has targeted governments and defense entities in Algeria, Mongolia, Ukraine, and Kuwait using malicious ZIP archives that contain a Windows shortcut (LNK) file, which, when executed, delivers a JavaScript loader named HOPPINGANT. The loader then delivers additional payloads for establishing C2 and exfiltrating data to the MEGA cloud storage service. "One interesting aspect of this campaign is that the threat actor does not rely on traditional command-and-control infrastructure," Seqrite Labs said. "Instead, the payloads are hosted on a public file-sharing service, filebulldogs[.]com, while stolen data is uploaded to MEGA storage using the legitimate tool Rclone." The activity has not been attributed to any known threat group. How Threat Actors Exfiltrate Credentials Using Telegram Bots — Threat actors are abusing the Telegram Bot API to exfiltrate data via text messages or arbitrary file uploads, highlighting how legitimate services can be weaponized to evade detection. Agent Tesla Keylogger is by far the most prominent example of a malware family that uses Telegram for C2. "In general, Telegram C2s appear to be most popular among information stealers, possibly due to Telegram's technically legitimate nature and because information stealers typically only need to exfiltrate data passively rather than provide complex communications beyond simple message or file transfers," Cofense said. Microsoft Launches Copilot Health — Microsoft has become the latest company after OpenAI and Anthropic to launch a dedicated "secure space" called Copilot Health that integrates medical records, biometric data from wearables, and lab test results to give personalized advice in the U.S. "Copilot Health brings together your health records, wearable data, and health history into one place, then applies intelligence to turn them into a coherent story," the company said. Like OpenAI and Anthropic, Microsoft emphasized that Copilot Health isn't meant to replace professional medical care. Rogue AI Agents Can Work Together to Engage in Offensive Behaviors — According to a new report from artificial intelligence (AI) security company Irregular, agents can work together to hack into systems, escalate privileges, disable endpoint protection, and steal sensitive data while evading pattern-matching defenses. What's notable is that the experiment did not rely on adversarial prompting or deliberately unsafe system design. "In one case, an agent convinced another agent to carry out an offensive action, a form of inter-agent collusion that emerged with no external manipulation," Irregular said. "This scenario demonstrates two compounding risks: inter-agent persuasion can erode safety boundaries, and agents can independently develop techniques to circumvent security controls. When an agent is given access to tools or data, particularly but not exclusively shell or code access, the threat model should assume that the agent will use them, and that it will do so in unexpected and possibly malicious ways." 🔧 Cybersecurity Tools Dev Machine Guard → It is a free, open-source tool that scans your computer to show you exactly what developer tools and scripts are running. It creates a simple list of your AI coding assistants, code editor extensions, and software packages to help you find anything suspicious or outdated. It is a single script that works in seconds to give you better visibility into the security of your local coding environment. Trajan → It is an automated security tool designed to find hidden vulnerabilities in "service meshes," which are the systems that manage how different parts of a large software application talk to each other. Because these systems are complex, it is easy for engineers to make small mistakes in the settings that allow hackers to bypass security or steal data. Trajan works by scanning these configurations to spot those specific errors and helping developers fix them before they can be exploited. Disclaimer: For research and educational use only. Not security-audited. Review all code before use, test in isolated environments, and ensure compliance with applicable laws. Conclusion There’s a lot packed in here, and not in a neat way. Some of it is the usual recycled chaos, some of it feels a little more deliberate, and some of it has that nasty “this is going to show up everywhere by next week” energy. Anyway — enough throat-clearing. Here’s the stuff worth your attention.
thehackernews.comMar 16, 2026extracted
Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials
Microsoft has disclosed details of a credential theft campaign that employs fake virtual private network (VPN) clients distributed through search engine optimization (SEO) poisoning techniques. "The campaign redirects users searching for legitimate enterprise software to malicious ZIP files on attacker-controlled websites to deploy digitally signed trojans that masquerade as trusted VPN clients while harvesting VPN credentials," the Microsoft Threat Intelligence and Microsoft Defender Experts teams said. The Windows maker, which observed the activity in mid-January 2026, has attributed it to Storm-2561, a threat activity cluster known for propagating malware through SEO poisoning and impersonating popular software vendors since May 2025. The threat actor's campaigns were first documented by Cyjax, highlighting the use of SEO poisoning to redirect users searching for software programs from companies like SonicWall, Hanwha Vision, and Pulse Secure (now Ivanti Secure Access) on Bing to fake sites and trick them into downloading MSI installers that deploy the Bumblebee loader. A subsequent iteration of the attack was disclosed by Zscaler in October 2025. The campaign was observed taking advantage of users searching for legitimate software on Bing to propagate a trojanized Ivanti Pulse Secure VPN client via bogus websites ("ivanti-vpn[.]org") that ultimately stole VPN credentials from the victim's machine. Microsoft said the activity highlights how threat actors exploit trust in search engine rankings and software branding as a social engineering tactic to steal data from users looking for enterprise VPN software. Compounding matters is the abuse of trusted platforms like GitHub to host the installer files. Specifically, the GitHub repository hosts a ZIP file containing an MSI installer file that masquerades as legitimate VPN software, but sideloads malicious DLL files during installation. The end goal, as before, is to collect and exfiltrate VPN credentials using a variant of an information stealer called Hyrax. A fake, yet convincing, VPN sign-in dialog is displayed to the user to capture the credentials. Once the information is entered by the victim, they are displayed an error message and are instructed to download the legitimate VPN client this time. In some cases, they are redirected to the legitimate VPN website. The malware makes use of the Windows RunOnce registry key to set up persistence, so that it's executed automatically every time following a system reboot. "This campaign exhibits characteristics consistent with financially motivated cybercrime operations employed by Storm-2561," Microsoft said. "The malicious components are digitally signed by 'Taiyuan Lihua Near Information Technology Co., Ltd.'" The tech giant has since taken down the attacker-controlled GitHub repositories and revoked the legitimate certificate to neutralize the operation. To counter such threats, organizations and users are advised to implement multi-factor authentication (MFA) on all accounts, exercise caution when downloading software from websites, and make sure that they are authentic.
thehackernews.comMar 13, 2026extracted
England Hockey investigating ransomware data breach
England Hockey, the governing body for field hockey in England, is investigating a potential data breach after the AiLock ransomware gang listed it as a victim on its data leak site. The threat actor allegedly stole 129GB of data from the organization’s systems and announced that it will soon publish the files, unless a ransom is paid. England Hockey is aware of the threat actor’s claims and has prioritized an inquiry that involves both internal teams and external experts to determine what happened. “We are aware of an incident involving England Hockey and are currently investigating the matter as a priority,” the field hockey organization said in a statement for BleepingComputer. “As part of this investigation, we recently became aware of a post from the group claiming to be responsible for this incident,” a representative said. The organization is responsible for running, regulating, and developing the sport of field hockey nationwide, from grassroots participation to elite national teams. It has a membership of more than 800 clubs across the country, 150,000 registered club players, and 15,000 coaches, umpires, and officials. England Hockey states that it cannot comment on specific details at the moment because of the ongoing investigation. “We take data security matters extremely seriously, and understanding what, if any, data may have been impacted in this incident is a top priority of our ongoing investigation,” assured England Hockey. AiLock is a relatively new ransomware operation that engages in double-extortion attacks. It was documented on April 1st, 2025, by researchers at cybersecurity company Zscaler, who noted that the threat actor was "leveraging sophisticated extortion tactics targeting enterprise networks." The hackers reportedly use privacy law violations as leverage in negotiations. They give victims 72 hours to respond and start negotiating, and wait five days for the payment under the threat of leaking stolen data and destroying recovery tools. According to past analysis from S2W Talon’s researcher Huiseong Yang, the ransomware uses ChaCha20 and NTRUEncrypt to lock files, appending the .AILock extension to the encrypted copies, and leaving ransom notes in all impacted directories. While England Hockey hasn’t confirmed a data breach yet, players in the country should be vigilant for suspicious account activity and phishing attempts, and treat unsolicited communications with caution. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 12, 2026extracted
Zscaler enhances data sovereignty controls with regional processing and logging
Zscaler enhances data sovereignty controls with regional processing and logging Zscaler has expanded its data sovereignty capabilities globally, powered by the Zscaler Zero Trust Exchange cloud security platform. For global enterprises, the conflict between protecting data and enabling cross-border collaboration is a major compliance and business challenge to growth. Zscaler already operates 160+ data centers and is present in most countries. Its architecture is based on isolated control, data, and logging planes, distinct layers and separation for management, traffic inspection, and record-keeping to ensure sensitive data never leaves its required jurisdiction enabling customers to maintain authority over their data. Running a control plane in a country is more complex than just data and logging planes. Zscaler addressed this early on and built a dedicated US & European control plane along with a dedicated logging plane in six different countries. We are now actively extending this functionality to several new regions, with a forthcoming deployment in Canada. Achieving digital sovereignty Zscaler resolves the critical conflict between local data protection and global collaboration through a truly decentralized architecture that offers a distinct advantage over alternatives that still rely on shared, global control planes. To further deepen this local authority, Zscaler has introduced: In-region SSL inspection & malware analysis: Decrypts and inspects encrypted traffic locally to stop hidden threats, ensuring that sensitive data and files never leave the jurisdiction for analysis. Certified on-premises flexibility: Options for customers to leverage Private Service Edges (single-tenant, customer-hosted, and Zscaler-managed appliances) to meet specific hardware certification requirements. Region-specific support: Dedicated technical teams to help CIOs interpret national regulations and configure services appropriately. Customer-controlled security and compliance To support the enterprises’ and organizations’ mandates for audit-ready security, Zscaler’s commitment to digital sovereignty is backed by rigorous third-party validation. Independent assessments verify that the platform encrypts and decrypts traffic without writing data to disk, ensuring absolute confidentiality when it comes to sensitive data handling. Key compliance capabilities include: Total data ownership: Full control over encryption keys via integration with hardware security modules (HSMs), ensuring only authorized parties can decrypt traffic. Unified compliance acceleration: Leverages a “Collect Once, Certify All” framework that maps a single set of security controls to overlapping regulatory requirements, significantly speeding up validation for GDPR, NIS2, and DoD IL5. Flexible logging: Options for regional or on-premises log storage to support strict regional compliance and customer policies. Turning resilience into business continuity Unlike providers whose core security services are reliant on third-party infrastructure, Zscaler owns and operates its own cloud, ensuring that an outage at any single data center does not impact overall service availability. This architecture allows major financial institutions to conduct firedrills and real world exercises, validating that the platform cannot become a single point of failure. “The true measure of a security cloud isn’t just global performance, but its ability to adapt to local realities,” said Misha Kuperman, Chief Reliability Officer at Zscaler. “Effective data sovereignty requires customers to have verified authority over their data residency, telemetry and control data plane data. By separating control, data, and logging planes with a decentralized architecture, Zscaler enables customers to align with strict local sovereignty requirements while maintaining the resilience and availability needed for global business continuity.”
helpnetsecurity.comMar 12, 2026extracted
AWS Security Hub is expanding to unify security operations across multicloud environments
AWS Security Hub is expanding to unify security operations across multicloud environments After talking with many customers, one thing is clear: the security challenge has not gotten easier. Enterprises today operate across a complex mix of environments, including on-premises infrastructure, private data centers, and multiple clouds, often with tools that were never designed to work together. The result is enterprise security teams spend more time managing tools than managing risk, making it harder to stay ahead of threats across an increasingly complex environment. At Amazon Web Service (AWS), we believe security should be simple, integrated, and built for the way enterprises actually operate. This belief is what drove us to reimagine AWS Security Hub, delivering full-stack security through a single experience, and this vision is driving our next chapter. Building on a foundation of unified security We transformed Security Hub into a unified security operations solution by bringing together AWS security services, including Amazon GuardDuty, Amazon Inspector, AWS Security Hub Cloud Security Posture Management (Security Hub CSPM), and Amazon Macie, into a single experience that automatically and continuously analyzes security signals across threats, vulnerabilities, misconfigurations, and sensitive data. Security Hub delivers a common foundation, bringing together findings from across your AWS environment so your security team spends less time translating signals and more time acting on them. Built on top of that foundation, a unified operations layer gives security teams near real-time risk analytics, automated analysis, and prioritized insights, helping them focus on what matters most, at scale. We also introduced new capabilities (the Extended plan) that simplify how enterprises procure, deploy, and integrate a full-stack security solution across endpoint, identity, email, network, data, browser, cloud, AI, and security operations. Now, customers can use Security Hub to expand their security portfolio through a curated selection of AWS Partner solutions (at launch: 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk (a Cisco company), Upwind, and Zscaler), all through one unified experience. With AWS as the seller of record, you benefit from pay-as-you-go pricing, a single bill, and no long-term commitments. Our goal is simple: unified security, everywhere your enterprise operates. Freedom to innovate, wherever your workloads are At AWS, interoperability means giving customers the freedom to choose solutions that best suit their needs, and the ability to use them wherever their workloads run. But freedom to innovate across multicloud environments also means that it is critical to secure them consistently, and without adding operational complexity. What’s coming for Security Hub In the coming months, we are expanding Security Hub with new multicloud capabilities that extend unified security operations beyond AWS. The foundation of this expansion is a common data layer that unifies security signals from wherever your workloads run. On top of that, a unified policy and operations layer delivers consistent posture management, exposure analysis, and risk prioritization, so your security team operates from a single view of risk rather than a fragmented collection of consoles. Security Hub will deliver unified risk analytics that surface critical risks across your multicloud estate. You’ll be able to manage cloud security posture with Security Hub CSPM checks that give you consistent posture visibility, and extend vulnerability management with expanded Amazon Inspector capabilities, including virtual machine scanning, container image scanning, and serverless scanning. Security Hub will also deliver external network scanning that enriches security findings with context about internet-facing exposure across your multicloud environment, including for resources not running in AWS. The result is more comprehensive risk coverage across your enterprise. It’s about giving your security team a single, unified experience to detect and respond to risks, wherever you operate. Security as a business enabler The security leaders I speak with aren’t just asking for better tools. They’re asking for a way to get ahead of risk, not just manage it. They want security that keeps pace with the business, not security that slows it down. That’s the vision behind AWS Security Hub: unified security through a single, integrated security operations experience, built on a common data foundation, powered by intelligent analytics, and delivered through a consistent operations layer, to help reduce security risk, improve team productivity, and strengthen security operations across AWS and beyond. Our multicloud expansion is underway, and we are just getting started. You can learn more at aws.amazon.com/security-hub, or visit us at the AWS booth (S-0466) at RSA Conference, March 23–26 in San Francisco.
aws.amazon.comMar 10, 2026extracted
Cybersecurity M&A Roundup: 42 Deals Announced in February 2026
Forty-two cybersecurity-related merger and acquisition (M&A) deals were announced in February 2026. For a detailed view of the more than 420 acquisitions announced in 2025, check out SecurityWeek’s annual M&A report. Here are some of the most important cybersecurity M&A deals announced in February 2026: SOC provider Arctic Wolf acquired US cybersecurity company Sevco Security, with no financial details disclosed. The acquisition aims to enhance Arctic Wolf’s attack surface management capabilities and provide customers with more comprehensive visibility and risk reduction in managed security operations. Technology consulting giant Booz Allen Hamilton acquired cybersecurity services and consulting firm Defy Security. The acquisition aims to expand Booz Allen’s cybersecurity capabilities, as well as support its growing business in the UK and the European Union. Check Point announced three strategic acquisitions to accelerate its push into AI-driven security and exposure management: Cyata, Cyclops, and Rotate. Cyata will help Check Point enhance its end-to-end AI security platform, while Cyclops helps the company strengthen exposure management with AI-driven asset discovery. Rotate brings talent and capabilities to accelerate workspace momentum. Software security company Endor Labs acquired application security firm Autonomous Plane. The acquisition aims to enhance Endor Labs’ reachability capabilities across applications and container images. Experian has acquired identity and data intelligence solutions provider AtData. The acquisition aims to strengthen Experian’s capabilities in identity verification and fraud detection, with a focus on email. Palo Alto Networks has entered into a definitive agreement to acquire endpoint security company Koi. Financial details have not been officially disclosed, but the deal is reportedly valued at $400 million. Palo Alto Networks said it’s buying Koi for its agentic endpoint security technology, aiming to enhance its Prisma AIRS AI security platform and Cortex XDR endpoint security solution. Proofpoint acquired AI security and governance company Acuvity. The integration of Acuvity’s technology will allow Proofpoint to provide real-time visibility and granular controls over how employees and systems interact with AI applications. This deal aims to prevent the accidental exposure of sensitive data while ensuring compliance. Quantum eMotion (QeM) is acquiring SKV Technology (SecureKey), a developer of specialized cryptographic software and hardware. The deal integrates SecureKey solutions into QeM’s portfolio to deliver quantum-resistant security, rapid PQC migration, and policy-driven P2P communication. Sophos has acquired UK-based Arco Cyber, a cybersecurity assurance company that helps organizations improve their security posture. Sophos said the acquisition enables it to deliver AI-powered cybersecurity governance capabilities, through its CISO Advantage offering, to organizations that lack dedicated security leadership. Data security company Varonis Systems has acquired AllTrue.ai for its AI trust, risk, and security management (TRiSM) solutions. The deal has been valued at $150 million. By integrating AllTrue.ai’s capabilities into its own platform, Varonis will enable customers to monitor and control AI behavior, reduce risks, and maintain and demonstrate compliance. Zscaler announced that it has acquired browser security firm SquareX for an undisclosed sum. With the technology provided by SquareX, Zscaler will extend security to unmanaged devices, enabling organizations to secure users within their preferred browser without the need for a full agent or the limitations of a separate, third-party browser. Other cybersecurity M&A deals announced in February 2026: TruthScan acquires Imagedetector.com Related: Zurich Acquires Beazley in $11 Billion Deal to Lead Cyberinsurance Related: Cybersecurity M&A Roundup: 34 Deals Announced in January 2026
securityweek.comMar 9, 2026extracted
Transparent Tribe Uses AI to Mass-Produce Malware Implants in Campaign Targeting India
The Pakistan-aligned threat actor known as Transparent Tribe has become the latest hacking group to embrace artificial intelligence (AI)-powered coding tools to strike targets with various implants. The activity is designed to produce a "high-volume, mediocre mass of implants" that are developed using lesser-known programming languages like Nim, Zig, and Crystal and rely on trusted services like Slack, Discord, Supabase, and Google Sheets to fly under the radar, according to new findings from Bitdefender. "Rather than a breakthrough in technical sophistication, we are seeing a transition toward AI-assisted malware industrialization that allows the actor to flood target environments with disposable, polyglot binaries," security researchers Radu Tudorica, Adrian Schipor, Victor Vrabie, Marius Baciu, and Martin Zugec said in a technical breakdown of the campaign. The transition towards vibe-coded malware, aka vibeware, as a means to complicate detection has been characterized by the Romanian cybersecurity vendor as Distributed Denial of Detection (DDoD). In this approach, the idea is not to sidestep detection efforts through technical sophistication, but rather to flood target environments with disposable binaries, each using a different language and communication protocol. Helping threat actors in this aspect are large language models (LLMs), which lower the barrier to cybercrime and collapse the expertise gap by enabling them to generate functional code in unfamiliar languages, either from scratch or by porting the core business logic from more common ones. The latest set of attacks has been found to target the Indian government and its embassies in multiple foreign countries, with APT36 using LinkedIn to identify high-value targets. The attacks have also singled out the Afghan government and several private businesses, albeit to a lesser extent. The infection chains likely begin with phishing emails bearing Windows shortcuts (LNKs) bundled within ZIP archives or ISO images. Alternatively, PDF lures featuring a prominent "Download Document" button are used to redirect users to an attacker-controlled website that triggers the download of the same ZIP archives. Regardless of the method used, the LNK file is used to execute PowerShell scripts in memory, which then download and run the main backdoor and facilitate post-compromise actions. These include the deployment of known adversary simulation tools like Cobalt Strike and Havoc, indicating a hybrid approach to ensure resilience. Some of the other tools observed as part of the attacks are listed below - Warcode, a custom shellcode loader written in Crystal that's used to reflectively load a Havoc agent directly into memory. NimShellcodeLoader, an experimental counterpart to Warcode that's used to deploy a Cobalt Strike beacon embedded into it. CreepDropper, a .NET malware that's used to deliver and install additional payloads, including SHEETCREEP, a Go-based infostealer that uses Microsoft Graph API for C2, and MAILCREEP, a C#-based backdoor utilizing Google Sheets for C2. Both malware families were detailed by Zscaler ThreatLabz in January 2026. SupaServ, a Rust-based backdoor that establishes a primary communication channel via the Supabase platform, with Firebase acting as a fallback. It contains Unicode emojis, suggesting that it was likely developed using AI. LuminousStealer, a likely vibe-coded, Rust-based infostealer that uses Firebase and Google Drive to exfiltrate files matching certain extensions (.txt, .docx, .pdf, .png, .jpg, .xlsx, .pptx, .zip, .rar, .doc, and .xls). CrystalShell, a backdoor written in Crystal that's capable of targeting Windows, Linux, and macOS systems, and uses hard-coded Discord channel IDs for C2. It supports the ability to run commands and gather host information. One variant of the malware has been found to use Slack for C2. ZigShell, a counterpart to CrystalShell that's written in Zig and uses Slack as its primary C2 infrastructure. It also supports added functionality to upload and download files. CrystalFile, a simple command interpreter written in Crystal that continuously monitors the "C:\Users\Public\AccountPictures\input.txt" and executes the contents using "cmd.exe." LuminousCookies, a Rust-based specialized injector to exfiltrate cookies, passwords, and payment information from Chromium-based browsers by circumventing app-bound encryption. BackupSpy, a Rust-based utility designed to monitor the local file system and external media for high-value data. ZigLoader, a specialized loader written in Zig that decrypts and executes arbitrary shellcode in memory. Gate Sentinel Beacon, a customized version of the open-source GateSentinel C2 framework project. "The transition of APT36 toward vibeware represents a technical regression," Bitdefender said. "While AI-assisted development increases sample volume, the resulting tools are often unstable and riddled with logical errors. The actor's strategy incorrectly targets signature-based detection, which has long been superseded by modern endpoint security." Bitdefender haș warned that the threat posed by AI-assisted malware is the industrialization of the attacks, allowing threat actors to scale their activities quickly and with less effort. "We are seeing a convergence of two trends that have been developing for some time: the adoption of exotic, niche programming languages, and the abuse of trusted services to hide in legitimate network traffic," the researchers said. "This combination allows even mediocre code to achieve high operational success by simply overwhelming standard defensive telemetry."
thehackernews.comMar 6, 2026extracted
Preparing for the Quantum Era: Post-Quantum Cryptography Webinar for Security Leaders
Most organizations assume encrypted data is safe. But many attackers are already preparing for a future where today’s encryption can be broken. Instead of trying to decrypt information now, they are collecting encrypted data and storing it so it can be decrypted later using quantum computers. This tactic—known as “harvest now, decrypt later”—means sensitive data transmitted today could become readable years from now once quantum capabilities mature. Security leaders who want to understand this risk and how to prepare can explore it in detail in the upcoming webinar on Post-Quantum Cryptography best practices, where experts will explain practical ways organizations can begin protecting data before quantum decryption becomes possible. Why Post-Quantum Cryptography Matters Quantum computing is advancing quickly, and most modern encryption algorithms, such as RSA and ECC, will not remain secure forever. For organizations that must keep data confidential for many years—financial records, intellectual property, government communications—waiting is not an option. A practical approach emerging today is hybrid cryptography, which combines traditional encryption with quantum-resistant algorithms like ML-KEM. This allows organizations to strengthen security without disrupting existing systems. The Future-Ready Security webinar will explain how hybrid cryptography works in real environments and how organizations can begin transitioning to quantum-safe protections. Preparing for the Quantum Era Organizations preparing for quantum threats are focusing on a few key steps: Identify sensitive data that must remain protected long-term Understand where encryption is used across systems Begin adopting hybrid cryptography strategies Maintain visibility into cryptographic algorithms and compliance needs At the same time, security teams must still inspect encrypted traffic and enforce policies across their networks. Modern Zero Trust architectures play an important role in maintaining this control. These strategies—and how platforms like Zscaler implement them—will be discussed during the live webinar session designed for IT, security, and networking leaders. What You’ll Learn in the Webinar This session will cover: The growing risk of “harvest now, decrypt later” attacks How ML-KEM hybrid encryption helps organizations transition safely How post-quantum traffic inspection enables policy enforcement at scale Best practices for protecting sensitive data in the quantum era Quantum computing will reshape cybersecurity. Organizations that begin preparing early will be better positioned to protect their most critical data. Join the webinar to learn how to build a practical, quantum-ready security strategy before the threat becomes urgent.
thehackernews.comMar 5, 2026extracted
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
A suspected Iran-nexus threat actor has been attributed to a campaign targeting government officials in Iraq by impersonating the country's Ministry of Foreign Affairs to deliver a set of never-before-seen malware. Zscaler ThreatLabz, which observed the activity in January 2026, is tracking the cluster under the name Dust Specter. The attacks, which manifest in the form of two different infection chains, culminate in the deployment of malware dubbed SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM. "Dust Specter used randomly generated URI paths for command-and-control (C2) communication with checksum values appended to the URI paths to ensure that these requests originated from an actual infected system," security researcher Sudeep Singh said. "The C2 server also utilized geofencing techniques and User-Agent verification." A notable aspect of the campaign is the compromise of the Iraqi government-related infrastructure to stage malicious payloads, not to mention the use of evasion techniques to delay execution and fly under the radar. The first attack sequence begins with a password-protected RAR archive, within which there exists a .NET dropper named SPLITDROP, which acts as a conduit for TWINTASK, a worker module, and TWINTALK, a C2 orchestrator. TWINTASK, for its part, is a malicious DLL ("libvlc.dll") that's sideloaded by the legitimate "vlc.exe" binary to periodically poll a file ("C:\ProgramData\PolGuid\in.txt") every 15 seconds for new commands and run them using PowerShell. This also includes commands to establish persistence on the host via Windows Registry changes. The script output and errors are captured in a separate text file ("C:\ProgramData\PolGuid\out.txt"). TWINTASK, upon first launch, is designed to execute another legitimate binary present in the extracted archive ("WingetUI.exe"), causing it to sideload the TWINTALK DLL ("hostfxr.dll"). Its primary goal is to reach out to the C2 server for new commands, coordinate tasks with TWINTASK, and exfiltrate the results back to the server. It supports the ability to write the command body from the C2 response to "in.txt," as well as download and upload files. "The C2 orchestrator works in parallel with the previously described worker module to implement a file-based polling mechanism used for code execution," Singh said. "Upon execution, TWINTALK enters a beaconing loop and delays execution by a random interval before polling the C2 server for new commands." The second attack chain represents an evolution of the first, consolidating all the functionality of TWINTASK and TWINTALK into a single binary dubbed GHOSTFORM. It makes use of in-memory PowerShell script execution to run commands retrieved from the C2 server, thereby eliminating the need for writing artifacts to disk. That's not the only differentiating factor between the two attack chains. Some GHOSTFORM binaries have been found to embed a hard-coded Google Forms URL that's automatically launched on the system's default web browser once the malware begins execution. The form features content written in Arabic and masquerades as an official survey from Iraq's Ministry of Foreign Affairs. Zscaler's analysis of the TWINTALK and GHOSTFORM source code has also uncovered the presence of placeholder values, emojis, and Unicode text, suggesting that generative artificial intelligence (AI) tools may have been used to assist with the malware's development. What's more, the C2 domain associated with TWINTALK, "meetingapp[.]site," is said to have been used by the Dust Specter actors in a July 2025 campaign to host a fake Cisco Webex meeting invitation page that instructs users to copy, paste, and run a PowerShell script to join the meeting. The instructions mirror a tactic widely seen in ClickFix-style social engineering attacks. The PowerShell script, for its part, creates a directory on the host, and attempts to fetch an unspecified payload from the same domain and save it as an executable within the newly created directory. It also creates a scheduled task to run the malicious binary every two hours. Dust Specter's connections to Iran are based on the fact that Iranian hacking groups have a history of developing custom lightweight .NET backdoors to achieve their goals. The use of compromised Iraqi government infrastructure has been observed in past campaigns linked to threat actors like OilRig (aka APT34). "This campaign, attributed with medium-to-high confidence to Dust Specter, likely targeted government officials using convincing social engineering lures impersonating Iraq's Ministry of Foreign Affairs," Zscaler said. "The activity also reflects broader trends, including ClickFix-style techniques and the growing use of generative AI for malware development."
thehackernews.comMar 5, 2026extracted
Iranian Cyber Threat Actor Targets Iraqi Government Officials in AI-Powered Campaign
An Iran-nexus cyber threat actor has been targeting government officials in Iraq by impersonating Iraq’s Ministry of Foreign Affairs, with the use of AI tools. Government–related infrastructure in Iraq was compromised and used to host malicious payloads distributed as part of this campaign. The campaign was detected in January 2026 by Zscaler ThreatLabz, which track the threat actor as Dust Specter and have attributed it to Iran “with medium to high confidence.” ThreatLabz discovered the use of previously undocumented malware in this campaign, including Split Drop, TwinTask, TwinTalk and GhostForm. The researchers also observed several fingerprints in the codebase indicating that Dust Specter leveraged generative AI for malware development. Dust Specter’s January 2026 Attack Campaign Explained The malicious campaign has been deployed following two distinct attack chains. The first attack chain involves the delivery of a password-protected RAR archive named mofa-Network-code.rar. A 32-bit .NET binary, disguised as a WinRAR application, is present inside this archive and starts the attack chain on the endpoint. ThreatLabz called this binary SplitDrop. This binary functions as a dropper for TwinTask and TwinTalk, two malicious dynamic-link library (DLL) files. TwinTask’s main purpose is to poll a file for new commands available for execution and run them using PowerShell to ensure persistence on the target environment. TwinTalk functions as a command-and-control (C2) orchestrator, the main purpose of which is to poll the C2 server for new commands, coordinate with the worker module and exfiltrate the results of command execution. TwinTask and TwinTalk work in parallel to implement a file-based polling mechanism used for code execution. In the report about this campaign, published on March 2, the ThreatLabz researchers said that the TwinTalk C2 domain, was also used by Dust Specter in July 2025 to host a web page disguised as a Cisco Webex meeting invitation. The web page included a link to download the legitimate Cisco Webex software and prompted the victim to choose the “Webex for Government” option, luring the victim into following the instructions to retrieve the meeting ID. These instructions are a typical social engineering method employed by threat actors to implement ClickFix-style attacks. The second attack chain consolidates all the functionality of the first attack chain into a single binary. It uses Google Forms as a social engineering lure and in-memory PowerShell script execution to execute the commands received from the C2 server, reducing the filesystem footprint. Unlike the first attack chain, the threat actor does not use a split architecture with DLL sideloading in this case. Instead, they use a .NET-based remote access trojan (RAT), dubbed GhostForm by ThreatLabz, that consolidates all the functionality of the first attack chain into one binary and uses in-memory PowerShell script execution. ThreatLabz identified the use of emojis and unicode text in the codebase when decompiling TwinTalk and GhostForm. “This unusual coding style strongly suggests that generative AI tools were utilized during the malware's development, and is a trend documented in other campaigns,” they wrote.
infosecurity-magazine.comMar 3, 2026extracted
AWS Expands Security Hub Into a Cross-Domain Security Platform
AWS has launched a new version of its Security Hub that solves the massive workload involved in cross domain security solution correlation and management. The original AWS Security Hub was announced in 2018, designed to aggregate and prioritize alerts from AWS and third-party security tools. In late 2025, AWS announced a ‘re-imagined’ Security Hub. It unified several of its own security tools, including Inspector and GuardDuty, effectively into a mini-SOC. Inspector is vulnerability scanning; GuardDuty is threat detection. In the re-imagined Security Hub, they can now integrate under a single pane of glass to map activity against vulnerabilities to highlight the most urgent threats and help customers prioritize and respond to their most critical security risks. Now, in early 2026, AWS announced Security Hub Extended. This allows customers to bring third party solutions into the same mini-SOC. It is, writes AWS, “A plan of Security Hub that simplifies how you procure, deploy, and integrate a full-stack enterprise security solution across endpoint, identity, email, network, data, browser, cloud, AI, and security operations.” For now, this full integration is limited to a range of curated vendors, selected from AWS customers’ own preferences. The current vendors include 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk, Upwind, and Zscaler. The intent is to offer integrated full stack security within AWS. “The selection was customer-driven,” explains Michael Fuller, director of security services at AWS. “Over the last four months, we went directly to our largest and fastest-growing enterprise customers and asked them which specific solutions they wanted us to prioritize in each category for the initial launch. We are committed to listening to customers and expanding the partner set over time.” The integration is made possible by the partner vendors all providing their findings in the open cybersecurity schema framework (OCSF). The data brought into the Security Hub Extended framework is consequently pre-normalized, and Security Hub Extended can perform instant and automatic cross-domain correlation to detect and highlight more granular threats. The new Hub goes beyond simplifying output correlation – it also simplifies product management whenever one of the partner vendors is used. AWS becomes the seller of record, and no matter how many of the partner vendors are used, there is only one invoice combined within the single AWS monthly bill. “AWS is the seller of record, with pre-negotiated pricing and a single bill covering all selected curated partner solutions,” explains Fuller. “Customers select only the solutions they need. A customer using multiple curated partner solutions would pay for each solution selected.” But always within the single invoice. He continues, “Security Hub Extended plan offers flexible pay-as-you-go pricing with no upfront investments and no long-term commitments. Flat-rate pricing is also available.” Customers are not required to use third-party vendors from the curated partners list. “Security Hub already supports multiple third-party partner integrations through its standard program,” adds Fuller, “so a customer’s existing vendor can already send findings into Security Hub today.” But this would require additional work from the customer and would not qualify for the single invoice structure. The triple benefit of Security Hub Extended is intended to be an easier correlation of security findings within the Hub’s mini SOC offering automated and improved full stack security; no additional coding required from the customer; and drastically reduced administrative overhead in finding, negotiating and on-going payment for multiple separate third party solutions. Related: Hundreds of FortiGate Firewalls Hacked in AI-Powered Attacks: AWS Related: AWS Trusted Advisor Tricked Into Showing Unprotected S3 Buckets as Secure Related: AWS Launches Incident Response Service Related: AWS Using MadPot Decoy System to Disrupt APTs, Botnets
securityweek.comMar 2, 2026extracted
North Korean APT Targets Air-Gapped Systems in Recent Campaign
A North Korea-linked threat actor tracked as APT37 has been observed using five new malicious tools in a recent campaign targeting air-gapped systems, Zscaler reports. Also tracked as ScarCruft, Ruby Sleet, and Velvet Chollima, APT37 has been active since 2012, focusing on data theft and surveillance and mainly targeting entities in South Korea. As part of a campaign discovered in December 2025, named Ruby Jumper, APT37 was seen using LNK files to execute a PowerShell script and deploy multiple payloads, including a decoy document in Arabic about the Palestine-Israel conflict. The payloads work together to execute a payload in memory. Dubbed RestLeaf, it uses the Zoho WorkDrive cloud storage for command-and-control (C&C) and attempts to fetch a file containing shellcode from it. The shellcode, which is executed in memory, acts as a launcher, fetching and decrypting second-stage shellcode that loads an embedded Windows executable, dubbed SnakeDropper. The malware creates a working directory and installs the Ruby 3.3.0 runtime environment disguised as a USB speed monitoring utility, backdoors the Ruby interpreter, and creates a scheduled task to execute the interpreter every five minutes, establishing persistence. Executed every time the Ruby interpreter starts, SnakeDropper drops ThumbsBD, a backdoor that uses removable drives to exfiltrate data from air-gapped systems, using them as bidirectional relays. When detecting USB drives, the malware creates a hidden directory in their root folder, which is used to stage backdoor commands and data for exfiltration. ThumbsBD also collects system information, downloads additional payloads, and executes shellcode from a specific directory. SnakeDropper was also observed dropping VirusTask, a removable media propagation tool designed to infect air-gapped systems, which exclusively weaponizes USB drives for initial access. It copies the payload executables to a folder in the drive’s root directory and enumerates files on the drive, replacing them with LNK files that lead to the execution of shellcode on the air-gapped systems when the user attempts to open those files. “VirusTask complements ThumbsBD to form a complete air-gap attack toolkit. While ThumbsBD handles C&C communication and data exfiltration, VirusTask ensures the malware spreads to new systems through social engineering by replacing legitimate files with malicious shortcuts that victims trust and execute,” Zscaler explains. The security firm also observed ThumbsBD deploying FootWine, an encrypted Android package file containing a shellcode launcher with surveillance capabilities, such as keystroke logging and audio and video capturing. FootWine supports various surveillance-related commands, including file manipulation, shell management, and registry and process manipulation. “ThumbsBD and VirusTask weaponize removable media to bypass network isolation and infect air-gapped systems. To maintain a strong security posture, the security community should focus on monitoring endpoint activity and physical access points to counter this threat and other campaigns led by APT37,” Zscaler notes. Related: North Korean Hackers Distributed Android Spyware via Google Play Related: North Korean Hackers Target macOS Developers via Malicious VS Code Projects Related: FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes
securityweek.comMar 2, 2026extracted
APT37 hackers use new malware to breach air-gapped networks
North Korean hackers are deploying newly uncovered tools to move data between internet-connected and air-gapped systems, spread via removable drives, and conduct covert surveillance. The malicious campaign has been named Ruby Jumper and is attributed to the state-backed group APT37, also known as ScarCruft, Ricochet Chollima, and InkySquid. Air-gapped computers are disconnected from external networks, especially the public internet. Physical isolation is achieved at the hardware level by removing all connectivity (Wi-Fi, Bluetooth, Ethernet), while logical segregation relies on various software-defined controls, like VLANs and firewalls. In a physical air-gap environment, typical in critical infrastructure, military, and research sectors, data transfer is done through removable storage drives. Researchers at cloud security company Zscaler analyzed the malware employed in APT37's Ruby Jumper campaign and identified a toolkit of five malicious tools: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE. Bridging the air gap The infection chain begins when the victim opens a malicious Windows shortcut file (LNK), which deploys a PowerShell script that extracts payloads embedded in the LNK file. To divert attention, the script also launches a decoy document. Although the researchers did not specify any victims, they note that the document is an Arabic translation of a North Korean newspaper article about the Palestine-Israel conflict. The PowerShell script loads the first malware component, called RESTLEAF, an implant that communicates with APT37's command-and-control (C2) infrastructure using Zoho WorkDrive. RESTLEAF fetches encrypted shellcode from the C2 to download the next-stage payload, a Ruby-based loader named SNAKEDROPPER. The attack continues with installing the Ruby 3.3.0 runtime environment - complete with the interpreter, standard libraries, and gem infrastructure - disguised as a legitimate USB-related utility named usbspeed.exe. "SNAKEDROPPER is primed for execution by replacing the RubyGems default file operating_system.rb with a maliciously modified version that is automatically loaded when the Ruby interpreter starts," via a scheduled task (rubyupdatecheck) that executes every five minutes, the researchers say. The THUMBSBD backdoor is downloaded as a Ruby file named ascii.rb, as well as the VIRUSTASK malware as the bundler_index_client.rb file. The role of THUMBSBD is to collect system information, stage command files, and prepare data for exfiltration. Its most crucial function is to create hidden directories on detected USB drives and copy files to them. According to the researchers, the malware turns removable storage devices "into a bidirectional covert C2 relay." This allows the threat actor to deliver commands to air-gapped systems as well as extract data from them. “By leveraging removable media as an intermediary transport layer, the malware bridges otherwise air-gapped network segments,” Zscaler researchers say. VIRUSTASK's role is to spread the infection to new air-gapped machines, weaponizing removable drives by hiding legitimate files and replacing them with malicious shortcuts that execute the embedded Ruby interpreter when opened. The module will only trigger an infection process if the inserted removable media has at least 2GB of free space. Zscaler reports that THUMBSBD also delivers FOOTWINE, a Windows spyware backdoor disguised as an Android package file (APK) that supports keylogging, screenshot capture, audio and video recording, file manipulation, registry access, and remote shell commands. Another piece of malware also observed in the APT37's RubyJumper campaign is BLUELIGHT, a full-fledged backdoor previously associated with the North Korean threat group. Zscaler has high confidence attributing the RubyJumper campaign to APT37 based on several indicators, including the use of the BLUELIGHT malware, initial vector relying on LNK files, two-stage shellcode delivery technique, and C2 infrastructure typically observed in attacks from this actor. The researchers also note that the decoy document indicates that the target of the RubyJumper activity is interested in North Korean media narratives, which aligns with the victim profile of this threat group. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comFeb 27, 2026extracted
North Korea's APT37 Expands Toolkit to Breach Air-Gapped Networks
A cyber espionage group linked to North Korea has been observed deploying a new malicious campaign using removable media infection tools to gain access to air-gapped systems. The group, APT37, is well-known hacking team active since at least 2012 and known under many names, including ScarCruft, Ruby Sleet, InkySquid, Ricochet Chollima and Velvet Chollima. Initially focused on the public and private sectors in South Korea, the group expanded its operations in 2017 to include Japan, Vietnam and the Middle East, and to a wider range of industry verticals, including chemicals, electronics, manufacturing, aerospace, automotive and healthcare entities. In this new campaign, spotted by security researchers at Zscaler ThreatLabz and dubbed ‘Ruby Jumper,’ APT37 utilized a set of six malicious tools throughout the attack lifecycle, five of which had never been documented (Restleaf, SnakeDropper, ThumbSBD, VirusTask and FootWine). It also leveraged removable media to infect and pass commands and information between air-gapped systems. APT37’s Ruby Jumper Campaign Explained The Ruby Jumper campaign was discovered by the ThreatLabz team in December 2025. During this campaign, documented in a report published on February 26, APT37 gained access using the group’s traditional method: abusing Windows shortcut (LNK) files. When a victim opens a malicious LNK file, it launches a PowerShell command and scans the current directory to locate itself based on file size. Then, the PowerShell script launched by the LNK file carves multiple embedded payloads from fixed offsets within that LNK, including a decoy document, an executable payload, an additional PowerShell script and a batch file. This document displays an article about the Palestine-Israel conflict, translated from a North Korean newspaper into Arabic. The executable payload is a newly discovered implant, dubbed Restleaf by the ThreatLabz team, that uses Zoho WorkDrive for command-and-control (C2) communications to fetch additional payloads. “To our knowledge, this is the first time APT37 has abused Zoho WorkDrive,” the researchers noted. RestLeaf profiles the compromised system and establishes persistence before retrieving follow‑on components from Zoho WorkDrive. Among these is SnakeDropper, a loader responsible for decrypting and deploying additional modules in memory, reducing on‑disk artefacts. To extend access beyond the initially infected host, APT37 deploys ThumbSBD, a tool specifically designed to propagate via removable media. ThumbSBD monitors for connected USB drives, copies a tailored infection package onto them and abuses shortcut files to ensure execution when the drive is opened on another system. This enables lateral movement into isolated or segmented environments. When a USB device reaches an air‑gapped machine, the infection chain resumes. VirusTask executes as a lightweight backdoor, collecting system information and staging data for exfiltration. Because the system lacks direct internet access, APT37 again relies on removable media: stolen data is written back to the USB drive in hidden or obfuscated form. The operators also deploy FootWine, a reconnaissance and collection utility focused on harvesting documents and monitoring removable drive activity, ensuring valuable data is queued for extraction. Supporting these newer components is BlueLight, a previously documented APT37 tool used for command execution and data theft. In connected environments, BlueLight communicates with external C2 infrastructure. In air‑gapped scenarios, it facilitates tasking and data staging for delayed exfiltration via USB.
infosecurity-magazine.comFeb 27, 2026extracted
Zscaler Acquires Browser Security Firm SquareX
Zscaler (NASDAQ: ZS) on Thursday announced that it has acquired browser security firm SquareX for an undisclosed sum. SquareX offers what it has dubbed a “Browser Detection and Response (BDR)” solution that converts any web browser into an enterprise-grade secure browser, providing the same functionality as dedicated enterprise browsers without cumbersome change management. SquareX claims that its browser extension effectively manages threats like malicious extensions, phishing, genAI data leakage, insider threats, and more, directly within the browser environment, reducing the enterprise attack surface without compromising user experience. With the technology provided by SquareX, Zscaler says it will be able to extend security to unmanaged devices, enabling organizations to secure users within their preferred browser – such as Google Chrome and Microsoft Edge – without the need for a full agent or the limitations of a separate, third-party browser. “Enterprises have historically relied on legacy VPNs and VDIs, but these technologies are fundamentally flawed and laden with security risks,” said Jay Chaudhry, CEO, Chairman, and Founder of Zscaler. “With SquareX, Zscaler is deepening our Zero Trust ExchangeTM Platform’s capabilities in standard browsers, such as Google Chrome or Microsoft Edge, to stop threats without having to deploy a third-party enterprise browser.” “By integrating with Zscaler, we will enable organizations to secure SaaS and private applications across any device – managed or BYOD – without compromising productivity,” said Vivek Ramachandran, founder of SquareX. “This approach allows IT leaders to replace expensive, insecure legacy access tools with precise Zero Trust policies that protect data and AI interactions based on an organization’s specific risk profile.” SquareX raised $20 million in a Series A funding round led by SYN Ventures in April 2025. Zscaler’s acquisition of SquareX closed on February 5, 2026, adding to several other recent acquisitions. In November 2025, Zscaler announced plans to acquire AI security company SPLX, and in recent years acquired Red Canary for $675 million, Avalor for $350 million, and AirGap Networks for an undisclosed sum.
securityweek.comFeb 6, 2026extracted
Russian hackers are exploiting recently patched Microsoft Office vulnerability (CVE-2026-21509)
Russian hackers are exploiting recently patched Microsoft Office vulnerability (CVE-2026-21509) Russian state-sponsored hackers Fancy Bear (aka APT 28) are exploiting CVE-2026-21509, a Microsoft Office vulnerability for which Microsoft released an emergency fix last week. The exploitation CVE-2026-21509 allows unauthorized attackers to bypass a security feature (OLE mitigations in Microsoft 365 and Microsoft Office) locally, by creating and tricking targets into opening booby-trapped Office files. On January 29, 2026 – three days after Microsoft released the aforementioned fix – Zscaler researchers flagged an email phishing campaign delivering backdoors via weaponized RTF files. “We observed two variants of the attack chain. Both variants begin with a specially crafted RTF file that weaponizes CVE-2026-21509 and, after successful exploitation, downloads a malicious dropper DLL from the threat actor’s server,” they shared. “The first dropper variant DLL is responsible for deploying a malicious Microsoft Outlook Visual Basic for Applications (VBA) project named MiniDoor. MiniDoor’s primary goal is to steal the user’s emails and forward them to the threat actor.” The second dropper variant triggeres a multi-stage infection chain that starts with the (previously undocumented) PixyNetLoader. PixyNetLoader drops malicious components on the target endpoint and prepares the Windows environment for the download and execution of additional payloads, including a Grunt implant associated with the open source Covenant C2 framework. The targets According to Zscaler, the targets of these campaigns were users in Central and Eastern Europe, including Ukraine, Slovakia, and Romania, and the emails were written in the Romanian, Ukrainian, and English language. The Ukrainian CERT says that one of the booby-trapped files – Consultation_Topics_Ukraine(Final).doc – was created on January 27, just a day after Microsoft’s out-of-band fix was released. The file contains text related to the consultations of the Committee of Permanent Representatives to the EU (COREPER) on the situation in Ukraine. Another file – BULLETEN_H.doc – was sent to via email to 60+ email addresses, predominantly belonging to the central executive authorities of Ukraine, the CERT noted. The email was purportedly sent by the Ukrainian Hydrometeorological Center. In the last days of January 2026, three more documents with a similar exploit were discovered. Ukraine’s CERT says that they expect the number of attacks using this particular vulnerability to increase, as attackers are betting on targets being slow (or unable) to patch or mitigate the flaw. Attack attribution The targets, the MiniDoor backdoor, the abuse of the Filen (cloud storage) API for C2 communication by the Covenant Grunt samples, and the techniques used in the attacks all point to the involvement of the Russia-linked threat actor APT28, according to Zscaler researchers. It’s unknown whether the group exploited CVE-2026-21509 before Microsoft devised a fix, but it seems likely, as they’ve been know to leverage other zero-day vulnerabilities throughout the years. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comFeb 3, 2026extracted
Russia’s APT28 Rapidly Weaponizes Newly Patched Office Vulnerability
The Russian cyberespionage group APT28 has rushed to add a recently patched Office vulnerability to its arsenal, with the first attacks observed just days after Microsoft announced fixes. The flaw, tracked as CVE-2026-21509, was addressed by Microsoft on January 26. The tech giant warned at the time that the vulnerability had been exploited as a zero-day and urged customers to apply the patches immediately. Microsoft initially credited its own security researchers for finding the vulnerability, but later updated its advisory to also credit Google Threat Intelligence Group (GTIG). However, neither Microsoft nor GTIG has released any information on the attacks exploiting CVE-2026-21509. While it remains unclear who exploited the Office vulnerability as a zero-day, Ukraine’s computer emergency response team (CERT-UA) and cybersecurity firm Zscaler revealed this week that the flaw was quickly weaponized by Russia’s APT28 after its disclosure. APT28 is a well-known, highly sophisticated group that is also tracked by the cybersecurity industry as Forest Blizzard, Sofacy, Fancy Bear, and GruesomeLarch. CVE-2026-21509 can be exploited by tricking the targeted user into opening a specially crafted Office file. While both Zscaler and CERT-UA spotted the first malicious file exploiting the vulnerability on January 29, the Ukrainian agency found evidence that the weaponized document had been created on January 27, the day after Microsoft announced patches for CVE-2026-21509. Since there appears to be no publicly available technical information on the vulnerability, the threat actor likely reverse-engineered Microsoft’s patches to develop its exploit. Zscaler, which linked the campaign to APT28 with high confidence based on victimology and TTPs, has observed exploitation of CVE-2026-21509 to deliver a dropper that in turn delivered other malware. One of the pieces of malware deployed by the dropper is MiniDoor, described by the security firm as an Outlook macro-based email stealer. The other malware observed in the attacks has been named PixyNetLoader, which the attackers use to deploy a Covenant Grunt implant that provides them with full remote access and various post-exploitation capabilities. Zscaler has seen attacks targeting users in Central and Eastern Europe, including Slovakia, Romania, and Ukraine. “Social engineering lures were crafted in both English and localized languages, (Romanian, Slovak and Ukrainian) to target the users in the respective countries,” Zscaler explained. Indicators of compromise (IoCs) have been made available by both Zscaler and CERT-UA. Related: Russia’s APT28 Targeting Energy Research, Defense Collaboration Entities Related: Russian APT Hits Ukrainian Government With New Malware via Signal Related: CISA Says Russian Hackers Targeting Western Supply-Lines to Ukraine
securityweek.comFeb 3, 2026extracted
APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks
The Russia-linked state-sponsored threat actor known as APT28 (aka UAC-0001) has been attributed to attacks exploiting a newly disclosed security flaw in Microsoft Office as part of a campaign codenamed Operation Neusploit. Zscaler ThreatLabz said it observed the hacking group weaponizing the shortcoming on January 29, 2026, in attacks targeting users in Ukraine, Slovakia, and Romania, three days after Microsoft publicly disclosed the existence of the bug. The vulnerability in question is CVE-2026-21509 (CVSS score: 7.8), a security feature bypass in Microsoft Office that could allow an unauthorized attacker to send a specially crafted Office file and trigger it. The Microsoft Threat Intelligence Center (MSTIC), Microsoft Security Response Center (MSRC), and Office Product Group Security Team, along with Google Threat Intelligence Group (GTIG), have been credited with discovering and reporting the flaw. "Social engineering lures were crafted in both English and localized languages (Romanian, Slovak, and Ukrainian) to target the users in the respective countries," security researchers Sudeep Singh and Roy Tay said. "The threat actor employed server-side evasion techniques, responding with the malicious DLL only when requests originated from the targeted geographic region and included the correct User-Agent HTTP header." The attack chains, in a nutshell, entail the exploitation of the security hole by means of a malicious RTF file to deliver two different versions of a dropper, one that's designed to drop an Outlook email stealer called MiniDoor, and another, referred to as PixyNetLoader, that's responsible for the deployment of a COVENANT Grunt implant. The first dropper acts as a pathway for serving MiniDoor, a C++-based DLL file that steals a user's emails in various folders (Inbox, Junk, and Drafts) and forwards them to two hard-coded threat actor email addresses: ahmeclaw2002@outlook[.]com and ahmeclaw@proton[.]me. MiniDoor is assessed to be a stripped-down version of NotDoor (aka GONEPOSTAL), which was documented by S2 Grupo LAB52 in September 2025. In contrast, the second dropper, i.e., PixyNetLoader, is used to initiate a much more elaborate attack chain that involves delivering additional components embedded into it and setting up persistence on the host using COM object hijacking. Among the extracted payloads are a shellcode loader ("EhStoreShell.dll") and a PNG image ("SplashScreen.png"). The primary responsibility of the loader is to parse shellcode concealed using steganography within the image and execute it. That said, the loader only activates its malicious logic if the infected machine is not an analysis environment and when the host process that launched the DLL is "explorer.exe." The malware stays dormant if the conditions are not met. The extracted shellcode, ultimately, is used to load an embedded .NET assembly, which is nothing but a Grunt implant associated with the open source .NET COVENANT command-and-control (C2) framework. It's worth noting that APT28's use of the Grunt Stager was highlighted by Sekoia in September 2025 in connection with a campaign named Operation Phantom Net Voxel. "The PixyNetLoader infection chain shares notable overlap with Operation Phantom Net Voxel," Zscaler said. "Although the earlier campaign used a VBA macro, this activity replaces it with a DLL while retaining similar techniques, including (1) COM hijacking for execution, (2) DLL proxying, (3) XOR string encryption techniques, and (4) Covenant Grunt and its shellcode loader embedded in a PNG via steganography." The disclosure coincides with a report from the Computer Emergency Response Team of Ukraine (CERT-UA) that also warned of APT28's abuse of CVE-2026-21509 using Word documents to target more than 60 email addresses associated with central executive authorities in the country. Metadata analysis reveals that one of the lure documents was created on January 27, 2026. "During the investigation, it was found that opening the document using Microsoft Office leads to establishing a network connection to an external resource using the WebDAV protocol, followed by downloading a file with a shortcut file name containing program code designed to download and run an executable file," CERT-UA said. This, in turn, triggers an attack chain that's identical to PixyNetLoader, resulting in the deployment of the COVENANT framework's Grunt implant. Update In a new report published February 4, 2026, Trellix said it observed APT28 leveraging the Microsoft Office 1-day within 24 hours of its public revelation to target European military and government entities, particularly targeting maritime and transport organizations across Poland, Slovenia, Turkey, Greece, the U.A.E., and Ukraine. "This campaign features a multi-stage infection chain and novel payloads, including a simple initial loader, an Outlook VBA backdoor (NotDoor), and a custom C++ implant dubbed 'BEARDSHELL,'" researchers Pham Duy Phuc and Alex Lanstein said. "The threat actors abuse legitimate cloud storage (filen[.]io) as command-and-control (C2) infrastructure, blending malicious traffic with normal user activity." A variation of this exact attack chain was previously detailed by both the Computer Emergency Response Team of Ukraine (CERT-UA) and Sekoia last year. In these attacks, phishing emails with geopolitically-charged narratives related to transnational weapons smuggling, military training programs, and meteorological emergency bulletins contain weaponized documents that exploit CVE-2026-21509 as soon as they are opened, triggering the execution of malicious code without requiring macros or user interaction. This includes downloading a Microsoft Shortcut (LNK) and a DLL codenamed SimpleLoader that's responsible for either dropping NotDoor or the COVENANT Grunt Beacon that then contacts a filen[.]io endpoint to deliver the BEARDSHELL backdoor. "The entire chain is designed for resilience and evasion, utilizing encrypted payloads, legitimate cloud services for C2, in-memory execution, and process injection to minimize forensic artifacts," Trellix said. "This multi-layered approach demonstrates APT28's evolved tradecraft in maintaining persistent access while evading detection across enterprise environments." (The story was updated after publication on February 4, 2026, with insights from Trellix.)
thehackernews.comFeb 3, 2026extracted
AI Security Threats Loom as Enterprise Usage Jumps 91%
AI adoption is accelerating faster than enterprise oversight, creating a rapidly widening attack surface across all sectors, said Zscaler in its ThreatLabz 2026 AI Security Report. The annual report, published on January 27, 2026, analyzed 989.3 billion AI and machine learning transactions across the Zscaler Zero Trust Exchange platform between January and December 2025. The cybersecurity firm found that despite a 91% AI usage growth across an ecosystem of more than 3400 AI applications, many organizations still lack a basic inventory of AI models and embedded AI features. Finance and insurance remain the most AI-driven sectors by volume, together accounting for 23% of all AI/ML traffic, while the technology and education sectors recorded explosive year-over-year growth in AI transactions (202% and 184%, respectively). Departments that used AI the most were engineering, which represented 48.9% of all AI usage, followed by IT (31.8%) and marketing (6.9%). Enterprise AI activity observed by Zscaler was largely concentrated in the US, which accounted for 38% of transactions, followed by India (14%) and Canada (5%). OpenAI services was the top LLM vendor recorded every month of 2025, followed by Codelium and Perplexity. Alongside the uptick in AI usage, Zscaler analysts found critical vulnerabilities in 100% of AI systems and applications observed, with 90% of systems compromised in under 90 minutes. The median time to first critical failure was just 16 minutes, with some of these AI flaws in a single second. Enterprise AI Apps Drive Data Privacy Violations Additionally, in parallel with a surge in AI usage, Zscaler reported a staggering 18,033 TB of enterprise data transferred to AI/ ML applications, a 93% year-over-year rise. “The massive influx has transformed tools like Grammarly (3,615 TB) and ChatGPT (2,021 TB) into the world’s most concentrated repositories of corporate intelligence,” said the report. The scale of this risk is quantified by 410 million data loss prevention (DLP) policy violations tied to ChatGPT alone, including attempts to share social security numbers, source code and medical records. “These findings signal that AI governance has transitioned from a policy discussion to an immediate operational necessity,” noted the Zscaler analysts in the report. Finally, the report anticipates autonomous and semi‑autonomous “agentic” AI will increasingly automate cyber-attacks in the near future, with AI agents assuming responsibility for reconnaissance, exploitation and lateral movement. “Defenders must assume that attacks can scale and adapt at machine speed, not human speed,” warned the report. Deepen Desai, EVP for cybersecurity at Zscaler, said that AI can no longer be considered as a simple productivity tool “but a primary vector for autonomous, machine-speed attacks by both crimeware and nation-state.”
infosecurity-magazine.comJan 28, 2026extracted
Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities
Indian government entities have been targeted in two campaigns undertaken by a threat actor that operates in Pakistan using previously undocumented tradecraft. The campaigns have been codenamed Gopher Strike and Sheet Attack by Zscaler ThreatLabz, which identified them in September 2025. "While these campaigns share some similarities with the Pakistan-linked Advanced Persistent Threat (APT) group, APT36, we assess with medium confidence that the activity identified during this analysis might originate from a new subgroup or another Pakistan-linked group operating in parallel," researchers Sudeep Singh and Yin Hong Chang said. Sheet Attack gets its name from the use of legitimate services like Google Sheets, Firebase, and email for command-and-control (C2). On the other hand, Gopher Strike is assessed to have leveraged phishing emails as a starting point to deliver PDF documents containing a blurred image that's superimposed by a seemingly harmless pop-up instructing the recipient to download an update for Adobe Acrobat Reader DC. The main purpose of the image is to give the users an impression that it's necessary to install the update in order to access the document's contents. Clicking the "Download and Install" button in the fake update dialog triggers the download of an ISO image file only when the requests originate from IP addresses located in India and the User-Agent string corresponds to Windows. "These server-side checks prevent automated URL analysis tools from fetching the ISO file, ensuring that the malicious file is only delivered to intended targets," Zscaler said. The malicious payload embedded within the ISO image is a Golang-based downloader dubbed GOGITTER that's responsible for creating a Visual Basic Script (VBScript) file if it does not already exist in the following locations: "C:\Users\Public\Downloads," "C:\Users\Public\Pictures," and "%APPDATA%." The script is designed to fetch VBScript commands every 30 seconds from two pre-configured C2 servers. GOGITTER also sets up persistence using a scheduled task that's configured to run the aforementioned VBScript file every 50 minutes. In addition, it ascertains the presence of another file named "adobe_update.zip" in the same three folders. If the ZIP file is not present, it pulls the archive from a private GitHub repository ("github[.]com/jaishankai/sockv6"). The GitHub account was created on June 7, 2025. Once the download is successful, the attack chain sends an HTTP GET request to the domain "adobe-acrobat[.]in" likely to signal the threat actors that the endpoint has been infected. GOGITTER then extracts and executes "edgehost.exe" from the ZIP file. A lightweight Golang-based backdoor, GITSHELLPAD, leverages threat actor-controlled private GitHub repositories for C2. Specifically, it polls the C2 server every 15 seconds by means of a GET request to access the contents of a file named "command.txt." It supports six different commands - cd .., to change working directory to the parent directory cd, to change directory to the specified path run, to run a command in the background without capturing the output upload, to upload a local file specified by the path to the GitHub repository download, to download a file to the specified path default case, to run a command using cmd /c and capture the output The results of the command execution are stored in a file called "result.txt" and uploaded to the GitHub account via an HTTP PUT request. The "command.txt" is then deleted from the GitHub repository once the command is successfully executed. Zscaler said it observed the threat actor also downloading RAR archives using cURL commands after gaining access to the victim's machine. The archives include utilities to gather system information and drop GOSHELL, a bespoke Golang-based loader used to deliver Cobalt Strike Beacon after multiple rounds of decoding. The tools are wiped from the machine after use. "GOSHELL's size was artificially inflated to approximately 1 gigabyte by adding junk bytes to the Portable Executable (PE) overlay, likely to evade detection by antivirus software," the cybersecurity company said. "GOSHELL only executes on specific hostnames by comparing the victim's hostname against a hard-coded list." Sheet Attack Uses Google Sheets, Firebase, Microsoft Graph API for C2 In a follow-up analysis, Zscaler ThreatLabz detailed the Sheet Attack campaign, highlighting the use of three new backdoors codenamed SHEETCREEP, FIREPOWER, and MAILCREEP, along with a PowerShell-based document stealer to exfiltrate files. A brief description of their functionality is as follows - SHEETCREEP, a lightweight backdoor written in C# that uses Google Sheets for C2 to execute commands using "cmd.exe" FIREPOWER, a PowerShell-based backdoor that abuses Google's Firebase Realtime Database for C2 to execute commands to be executed using and download files MAILCREEP, a Golang-based backdoor that leverages the Microsoft Graph API for C2 and manipulate mails "The Sheet Attack campaign leveraged PDFs to deploy lightweight backdoors that utilized multiple C2 channels that abused legitimate cloud services from Google and Microsoft, enabling the network traffic to blend in and evade security controls," the researchers said. Like in the case of Gopher Strike, the attack chain makes use of a geofencing check that uses the "User-Agent" string to ensure that the malicious ZIP archive is distributed only to Windows users in India. Present within the archive is a Windows shortcut (LNK) that poses as a document to trigger the infection. The LNK file, once launched, is responsible for deploying the SHEETCREEP backdoor. The Google Sheet C2 channel, for its part, has been found to serve repeated commands, in some cases containing typos (e.g., "whaomi" and "whomai" instead of "whoami"), raising the possibility that of hands-on-keyboard activity from an operator. However, recent Sheet Attack campaigns have transitioned from SHEETCREEP to using malicious LNK files to distribute FIREPOWER, with the latter also serving as a conduit for a PowerShell-based document stealer and MAILCREEP to select targets. Further analysis of SHEETCREEP and FIREPOWER's source code has revealed the presence of emojis within its error-handling logic and verbose comments, respectively, suggesting the use of generative artificial intelligence (AI) tools for malware development. "While both campaigns share TTPs with APT36, their concurrent operation alongside traditional APT36 activity, use of new tools, and potential generative AI in malware development suggest an evolution of APT36 or the emergence of a closely aligned group," Zscaler concluded. (The story was updated after publication on February 10, 2026, to include details of the Sheet Attack campaign.)
thehackernews.comJan 27, 2026extracted
Zscaler expands AI security capabilities to deliver visibility, control, and governance
Zscaler expands AI security capabilities to deliver visibility, control, and governance Zscaler has announced new AI security innovations designed to empower enterprises to secure the fast growing use of AI, while maintaining visibility, control, and governance. As organizations adopt generative AI and prepare for the use of agentic AI, they face rising risk of cyberattacks and data loss because traditional security models weren’t designed to secure AI. The Zscaler AI Security Suite eliminates the trade-off between AI innovation and risk, providing the visibility and controls needed to securely build, deploy, and govern AI at enterprise scale. Most enterprises lack a complete view of the AI applications and services in use, including GenAI tools, AI development environments, embedded AI in SaaS, models, agents, and underlying infrastructure. This limits their ability to understand AI exposure, data access, and risk. Organizations also struggle to control access and enforce policy as AI traffic shifts to new protocols and non-human patterns that traditional security tools cannot govern. In fact, in the ThreatLabz 2026 AI Security Report published today, Zscaler experts found most enterprise AI systems could be compromised in just 16 minutes with critical flaws uncovered in 100% of systems analyzed. Zscaler’s new innovations provide enterprises with a comprehensive inventory and dependency map of their AI footprint, spanning GenAI services, embedded AI SaaS, AI development environments, MCP servers, agents, models, and AI infrastructure. The solution correlates asset discovery, access relationships, data lineage, runtime behavior, and security posture, enabling organizations to adopt AI faster while maintaining security, governance, and control. “AI is changing how businesses operate, but traditional security approaches were not designed to secure AI,” said Jay Chaudhry, CEO, Chairman, and Founder of Zscaler. “Business leaders are looking for a comprehensive solution – not more point products. At Zscaler, we’re providing the security necessary for leaders to move forward with confidence and embrace the full spectrum of AI. We aren’t just securing the AI era; we’re accelerating it.” The new Zscaler AI Security suite addresses enterprise AI security challenges in three critical ways: AI Asset Management gives CISOs, IT, and governance teams a comprehensive inventory of AI apps, models, infrastructure, agents, and usage, helping them detect shadow AI, understand what data AI touches, and prioritize risk by providing visibility on AI usage. Secure Access to AI helps security architects and IT admins safely enable sanctioned AI services like developer tools and AI models with Zero Trust controls, inline inspection, and prompt classification to reduce data loss and misuse while preserving productivity. Secure AI Infrastructure and Apps equips application teams to protect AI development across the lifecycle with automated AI red teaming, prompt hardening, runtime guardrails and continuous risk posture assessment from build to runtime. “The industry is currently struggling with a massive visibility gap because AI traffic doesn’t behave like traditional web traffic,” said Zeus Kerravala, Principal Analyst, ZK Research. “It’s faster, non-human, and uses protocols that most security stacks simply can’t see. What’s important here isn’t just another security tool; it’s the shift toward a Zero Trust framework that actually understands the context of an AI conversation. Without this level of deep inspection and automated guardrails, enterprises are essentially flying blind into the most significant technology transition of our lifetime.” To simplify global AI adoption, Zscaler now supports customers in aligning their security programs with frameworks such as the NIST AI Risk Management Framework and the EU AI Act. This governance is paired with CXO-level reporting on GenAI usage and deep ecosystem integrations with OpenAI, Anthropic, AWS, Microsoft, and Google. Additionally, Zscaler is expanding its defense capabilities with a new MCP gateway for secure automation and AI Deception to divert and neutralize model-based attacks.
helpnetsecurity.comJan 27, 2026extracted
Quantum computing, una minaccia per la crittografia: come prepararsi oggi
Il quantum computing non rappresenta più una prospettiva lontana. La sua accelerazione, documentata da organismi internazionali e centri di ricerca, lo colloca tra le minacce più determinanti per la cyber security globale, con implicazioni dirette sui sistemi crittografici attuali. Il World Economic Forum, nel rapporto “Embracing the Quantum Economy” (2025), descrive il quantum computing come un fattore capace di produrre “impatti sistemici e trasversali” sulla sicurezza digitale. La ragione è semplice: gli algoritmi di crittografia oggi dominanti potrebbero non reggere più sotto la potenza di calcolo quantistica. A confermare questa evoluzione è anche la decisione del NIST, che il 13 agosto 2024 ha pubblicato i primi standard ufficiali di crittografia post-quantum: Fips 203 (ML-Kem), Fips 204 (ML-Dsa) e Fips 205 (Slh-Dsa), ritenuti resistenti ai futuri attacchi quantistici. La trasformazione è ormai tracciata: imprese, PA e infrastrutture critiche devono avviare oggi una migrazione che richiederà anni di revisione tecnologica e organizzativa. In Europa, l’Enisa definisce la minaccia già attiva. Nei report “Post-Quantum Cryptography: Current State and Quantum Mitigation” e “Pqc Integration Study” avverte che gruppi avanzati di attacco stanno già applicando la strategia “harvest now, decrypt later”, intercettando dati cifrati con l’obiettivo di decifrarli in futuro grazie ai progressi quantistici. In questo scenario globale in rapido mutamento si inserisce l’analisi di Yaroslav Rosomakho, Chief Scientist di Zscaler, che chiarisce perché l’urgenza è reale e quali sono i passi tecnici e strategici necessari per evitare che la rivoluzione quantistica si trasformi in una crisi di sicurezza. Indice degli argomenti Rosomakho identifica subito il cuore del problema: la minaccia è già iniziata, anche se i computer quantistici “in grado di compromettere la crittografia” ancora non esistono. “Gli attaccanti possono catturare traffico sensibile oggi e decifrarlo anni dopo” spiega. “Per molti settori come pubblica amministrazione, finanza e sanità, il momento per prepararsi è ora”. Questo scenario riguarda in modo particolare i dati sensibili con un ciclo di vita lungo. Certificati digitali, documenti finanziari, informazioni sanitarie, referti diagnostici, dati giudiziari o diplomatici: tutto ciò che resterà utile anche tra dieci o quindici anni è già a rischio. Ma cosa significa davvero essere “quantum-ready”? Rosomakho chiarisce che non si tratta di un intervento superficiale: “Vuol dire costruire un programma organizzativo capace di sostenere una transizione crittografica pluriennale senza interrompere le operazioni”. Per farlo, indica alcuni elementi imprescindibili: mappare l’uso della crittografia nell’organizzazione, adottare presto algoritmi Pqc ibridi come ML-KEem, ridurre il perimetro di rischio eliminando chiavi e protocolli obsoleti, e rendere l’intera infrastruttura agile nella gestione degli algoritmi. È un percorso che richiede visibilità, governance e capacità di orchestrazione centralizzata. Il modello Zero Trust, sempre più diffuso nelle architetture moderne, si basa sull’idea di “non fidarsi mai e verificare sempre”. Tuttavia, anche questo modello è costruito sulla crittografia, e la minaccia quantistica mette sotto pressione i suoi fondamenti. “L’identità digitale è uno dei punti più esposti” osserva Rosomakho. Le firme digitali che sostengono certificati, token, sistemi di attestazione e radici di fiducia nei dispositivi si basano spesso su Rsa, Ecdsa o EdDsa, algoritmi vulnerabili agli attacchi quantistici futuri. “Un avversario dotato di capacità quantistiche potrebbe generare firme false” spiega, compromettendo dispositivi, workload, utenti e catene di fiducia. Anche i canali sicuri rappresentano un punto critico. “L’approccio Zero Trust fa leva sull’end-to-end encryption, ma il quantum computing minaccia la confidenzialità del traffico cifrato a lungo termine”, chiarisce il Chief Scientist di Zscaler. La mitigazione passa dall’adozione di protocolli moderni come Tls 1.3 e dall’uso di schemi ibridi QR (quantum-resistant), come ML-Kem, già supportati da Tls, Ssh, Ike e Hpke. La filosofia Zero Trust resta quindi valida, ma la sua infrastruttura crittografica deve essere aggiornata. In questo scenario, Rosomakho chiarisce che “adottare algoritmi Pqc è necessario ma non sufficiente”. La migrazione post-quantum non riguarda infatti solo la sostituzione di Rsa o Ecc, ma un ripensamento dell’architettura. Il ragionamento insiste su un concetto chiave: “La crypto-agility è fondamentale”. Molte organizzazioni considerano la crittografia un elemento statico, configurato dispositivo per dispositivo. Questo approccio è incompatibile con un futuro in cui gli algoritmi dovranno essere aggiornati con frequenza crescente. Serve, invece, un modello di distribuzione centralizzato, automatizzato, orchestrabile. Le firme Pqc cambiano radicalmente il modo di gestire identità, certificati, workload e sistemi IoT. “Le organizzazioni dovranno muoversi verso credenziali a vita breve, con rilascio e rotazione automatizzati”, sottolinea Rosomakho. Lo stesso vale per la gestione delle chiavi, che nei modelli Pqc sono più pesanti e richiedono politiche più rigorose. L’inventario delle chiavi, la loro validazione e il monitoraggio continuo non saranno più opzionali ma strutturali. Anche per questo la Enisa raccomanda visibilità continua degli algoritmi effettivamente usati nei sistemi, in un panorama in cui soluzioni classiche e post-quantum coesisteranno per anni. La prima tappa è una sola: “Serve un inventario crittografico accurato” afferma Rosomakho di Zscaler. “La maggior parte delle organizzazioni non conosce davvero dove è utilizzata la crittografia”. Una volta costruita la mappa, bisogna classificare i sistemi in base al rischio e alla durata di vita dei dati. Quelli che trattano informazioni sensibili a lungo termine devono essere migrati per primi. L’inventario deve includere applicazioni, appliance, protocolli di identità, canali di comunicazione, dispositivi. Da qui si stabiliscono le priorità: i sistemi con maggiore esposizione, o nei quali la cifratura protegge dati a lunga vita, richiedono interventi immediati. In generale è raccomandato un approccio graduale: adottare fin da ora scambi ibridi basati su ML-Kem, abbreviare la vita delle chiavi, eliminare i segreti a lunga durata e rafforzare la gestione della rotazione. “La migrazione non deve essere un big bang, ma un percorso misurato e progressivo”, chiarisce Rosomakho. “Abbiamo progettato la nostra Zero Trust Exchange assumendo che i meccanismi crittografici cambieranno nel tempo”, afferma il Chief Scientist di Zscaler. È una scelta che permette alla piattaforma di adattarsi ai nuovi standard senza mettere a rischio la continuità dei clienti. Uno dei punti di forza è la visibilità: “Offriamo ai clienti la possibilità di osservare gli algoritmi realmente negoziati dalle connessioni, anche con Pqc non ancora in uso”. Questo aspetto è cruciale, perché consente alle organizzazioni di individuare applicazioni e dispositivi che non supportano ancora la crittografia ibrida o post-quantum. In parallelo, Zscaler sta lavorando per supportare ML-Kem e le firme Pqc su tutta la piattaforma, collaborando con partner e organismi internazionali per test anticipati di compatibilità e performance. “Il nostro obiettivo – aggiunge, in conclusione, Rosomakho – è garantire sicurezza oggi e posizionare i clienti sempre un passo avanti rispetto all’evoluzione delle minacce quantistiche”. Una visione che restituisce il senso della fase attuale: un passaggio tecnico complesso, che richiede continuità e attenzione, e che le organizzazioni devono affrontare con gradualità e strumenti adeguati.
cybersecurity360.itJan 22, 2026extracted
Cybersecurity M&A Roundup: 30 Deals Announced in November 2025
Thirty cybersecurity-related merger and acquisition (M&A) deals were announced in November 2025. Here are some of the most important cybersecurity M&A deals announced in November 2025: Security operations firm Arctic Wolf has announced buying UpSight Security to strengthen its Aurora Endpoint Security platform. The SOC company is integrating UpSight’s predictive AI and rollback capabilities to provide enhanced defense against ransomware and other threats. Bug bounty company Bugcrowd has acquired application security firm Mayhem Security. Bugcrowd told SecurityWeek that the acquisition of Mayhem has nearly doubled its valuation. Mayhem technology will be integrated with Bugcrowd’s human-driven crowdsourced testing to enable organizations to ship secure software by continuously finding and prioritizing vulnerabilities. Cyberinsurance provider Coalition announced the acquisition of Wirespeed, a managed detection and response (MRD) company. Wirespeed’s MDR solutions will be combined with Coalition’s suite of cyber risk management tools and coverage. Managed security services provider Huntress has acquired Inside Agent, a UK-based company specializing in automated security and insider threat detection for Microsoft 365 environments. The acquisition expands Huntress’ identity security offerings and accelerates the development of a new identity security posture management (ISPM) solution. Cybersecurity advisory and managed services firm MorganFranklin Cyber announced the acquisition of cybersecurity and risk management services provider Lynx Technology Partners. The acquisition enables MorganFranklin Cyber to expand its GRC capabilities. Palo Alto Networks has agreed to acquire observability platform provider Chronosphere in a deal valued at $3.35 billion. The combination of Chronosphere’s observability platform with Palo Alto’s AgentiX will deploy AI agents on massive amounts of data monitored by Chronosphere’s platform to detect performance issues, autonomously investigate the root cause, and close the loop with agentic remediation. Autonomous cyber risk quantification and management solutions provider SAFE announced the acquisition of Balbix, a company specializing in continuous threat exposure management (CTEM). SAFE and Balbix will offer an agentic-AI-powered cyber risk platform that unifies cyber risk and exposure management. Certification authority SSL.com has acquired the digital certificate business of cybersecurity and compliance company VikingCloud. The deal expands SSL.com’s customer base. For VikingCloud, the deal is part of its strategy to focus on its core cybersecurity and compliance offerings. Cloud security firm Zscaler has acquired AI security company SPLX to extend its Zero Trust Exchange platform with AI asset discovery, automated red teaming, and governance capabilities. Other cybersecurity M&A deals announced in November 2025: Related: ServiceNow to Acquire Identity Security Firm Veza in Reported $1 Billion Deal Related: Cybersecurity M&A Roundup: 45 Deals Announced in October 2025
securityweek.comDec 4, 2025extracted
Cybersecurity M&A Roundup: Cyber Giants Strengthen AI Security Offerings
November 2025 marked a significant month for cybersecurity consolidation, as industry leaders raced to integrate AI, observability and exposure management into their offerings. Acquisitions like Palo Alto’s Chronosphere buy and Bugcrowd’s Mayhem deal highlight a push toward AI-driven security automation. Below are the key deals shaping the future of cybersecurity. LevelBlue Finalizes Cybereason Acquisition LevelBlue, the AT&T cybersecurity spinoff, has finalized its acquisition of Cybereason, following an announcement in October. This deal marks LevelBlue’s third major acquisition in 2025, after purchasing Trustwave and Aon’s Cybersecurity & IP Litigation Consulting divisions earlier this year. Palo Alto Networks to Buy Chronosphere for $3.35bn Palo Alto Networks announced on November 19 it plans to acquire Chronosphere, a US-based observability platform for microservices and containers, for $3.35bn. The addition of Chronosphere’s platform will help Palo Alto “address the resilience and uptime demands of the AI era,” the company said in a statement sent to Infosecurity. CTEM Provider Balbix Joins Safe Security Cyber risk quantification provider Safe Security announced on November 18 it has acquired Balbix, a US-based Continuous Threat Exposure Management (CTEM) provider, for an undisclosed amount. Balbix had previously raised $70m in funding. It was named a Visionary in the 2025 Gartner Magic Quadrant for Exposure Assessment Platforms. DoJ Gives Green Light to Google’s Acquisition of Wiz The US Department of Justice (DoJ) recently terminated its investigation into the acquisition of Wiz by Google, expected to close in 2026. During the Wall Street Journal Tech Live California event, held in Napa Valley from November 4 to 6, Wiz CEO Assaf Rappaport confirmed that his company had cleared the regulatory hurdle but added it is “still in the journey between signing and closing”. Arctic Wolf Plans to Buy UpSight Security Arctic Wolf announced on November 4 its intention to acquire UpSight Security in order to enhance its Aurora Endpoint Security platform with AI-powered ransomware prevention and rollback capabilities. The financial details of the deal were not disclosed. Bugcrowd Acquires AI-Powered App Security Firm Mayhem Bugcrowd announced on November 4 it has acquired Mayhem Security (formerly ForAllSecure), an AI-driven application security firm specializing in API security, code analysis and dynamic software bill of materials (SBOM) solutions. Financial terms were not disclosed, but Mayhemhad raised $36m in funding before the acquisition. It will now integrate its AI-powered security testing tools into Bugcrowd’s platform, enhancing its automated vulnerability detection and remediation capabilities. AI Security Company SPLX Joins Cyber Giant Zscaler Cloud security giant Zscaler announced on November 4 it was acquiring SPLX, an AI security startup founded in 2023. Also known as SplxAI, the firm had previously raised $9m in funding. The financial details for the deal were not disclosed.
infosecurity-magazine.comDec 1, 2025extracted
Malicious Blender model files deliver StealC infostealing malware
A Russian-linked campaign delivers the StealC V2 information stealer malware through malicious Blender files uploaded to 3D model marketplaces like CGTrader. Blender is a powerful open-source 3D creation suite that can execute Python scripts for automation, custom user interface panels, add-ons, rendering processes, rigging tools, and pipeline integration. If the Auto Run feature is enabled, when a user opens a character rig, a Python script can automatically load the facial controls and custom UI panels with the required buttons and sliders. Despite the potential for abuse, users often activate the Auto Run option for convenience. Researchers at cybersecurity company Morphisec observed attacks using malicious .blend files with embedded Python code that fetches a malware loader from a Cloudflare Workers domain. The loader then fetches a PowerShell script that retrieves two ZIP archives, ZalypaGyliveraV1 and BLENDERX, from attacker-controlled IPs. The archives unpack into the %TEMP% folder and drop LNK files in the Startup directory for persistence. Next, they deploy two payloads, the StealC infostealer and an auxiliary Python stealer, likely used for redundancy. Morphisec researchers report that the StealC malware used in this campaign was the latest variant of the second major version of the malware that was analyzed by Zscaler researchers earlier this year. The latest StealC has expanded its data-stealing capabilities and supports exfiltration from: 23+ browsers, with server-side credential decryption and compatibility with Chrome 132+ 100+ cryptocurrency wallet browser extensions and 15+ cryptocurrency wallet apps Telegram, Discord, Tox, Pidgin, VPN clients (ProtonVPN, OpenVPN), and mail clients (Thunderbird) Updated UAC bypass mechanism Despite the malware being documented since 2023, subsequent releases appear to remain elusive for anti-virus products. Morphisec comments that no security engine on VirusTotal detected the StealC variant they analyzed. Given that 3D model marketplaces cannot scrutinize the code in user-submitted files, Blender users are advised to exercise caution when using files sourced from such platforms and should consider disabling the auto-execution of code. You can do this from Blender > Edit > Preferences > uncheck the 'Auto Run Python Scripts' option. 3D assets should be treated like executable files, and users should only trust publishers with a proven record. For everything else, it is recommended to use sandboxed environments for testing. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comNov 24, 2025extracted
Loading 40 more…