Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
You don’t have to join the hack-back program to inherit its risk
The obvious question about Washington’s new private offensive cyber program is which security vendors will join it. The CSO question is what happens to you when one of your vendors does. The August 12 National Security Presidential Memorandum, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” directs the National Coordination Center to build a program for vetted “Participating Companies.” The Justice Department and the Department of Homeland Security run it jointly, and two co-executive directors must approve every operation in writing. Once the directors sign, a participating company can run covert access intended to stay undetected (Cyber Surveillance Operations) or manipulation, disruption, degradation, or destruction of systems (Cyber Effects Operations). The memorandum directs the operating procedures to authorize the Department of Justice (DOJ) and the Department of Homeland Security (DHS) to require a forfeitable bond of at least $1 million as a contract condition. Those procedures, which govern day-to-day execution, remain unpublished. They are due in mid-October, 60 days after signing. The White House fact sheet frames the program as consumer protection, citing more than $20.8 billion in American losses to cyber-enabled crime in 2025. The frame that matters to a CSO is different. The memorandum moves sovereign activity onto commercial infrastructure while leaving substantial residual liability in private hands. It behaves like a risk-transfer contract, except that most of the parties bearing the risk never signed it. The shield is thinner than the authorization The program’s criminal protection rests on one untested reading of one statutory clause. The Computer Fraud and Abuse Act (CFFA) exempts “lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency” at 18 U.S.C. 1030(f), and the memorandum styles every operation as federal law enforcement activity to fit inside that exemption. Congress wrote that exemption for law enforcement agencies. No court has ruled on whether it stretches to a private company operating under contract. A statute can create that protection outright. The Active Cyber Defense Certainty Act would have given companies an affirmative defense against CFAA charges for hacking back, but Congress never passed it. A presidential memorandum cannot amend a statute. In Little v. Barreme, the Supreme Court held that a presidential order did not protect an officer from damages when the seizure exceeded congressional authority. What the memorandum withholds runs longer than what it grants. Crowell & Moring’s client alert counts the gaps: no civil safe harbor, so CFAA civil suits by collateral victims remain live; no preemption of state anti-hacking law; no protection under foreign law; no indemnification. Section 5(c) then closes the other direction, creating no right or benefit enforceable against the United States. A participating firm holds an unadjudicated criminal theory, while civil, state, foreign, and contractual exposure sits outside the shield. The same government-control language that supports the domestic CFAA theory also strengthens the case for attributing the operations to the United States internationally. Under Article 8 of the International Law Commission’s state-responsibility articles, private conduct is attributed to a state when that conduct follows the state’s instructions or runs under its direction and control. Both propositions hold at once, and that is the problem for a company more than for a government. The stronger the control record supporting the vendor’s CFAA defense, the more readily a foreign ministry can treat that vendor’s work as an official act of the United States. Non-participation is not an exemption Most security organizations will file this under someone else’s problem. The exposure reaches them four ways. Substrate. Criminal groups rent and compromise the same clouds, content delivery networks, and SaaS platforms your workloads sit on. An approved effects operation against that infrastructure can surface in your environment as an unexplained outage. The memorandum anticipates the event: its implementing guidance orders a participating company to cease, minimize, and notify when an operation unintentionally reaches a system in the United States or under American control. Governments do not write cleanup procedures for events they consider remote. Section 5(c) then gives the affected company no remedy under the memorandum itself, which routes any claim into ordinary law and ordinary cost. Silence. Participating companies must disclose their commercial agreements to the NCC, not to their customers. The memorandum creates no customer-disclosure obligation, so the burden falls on the buyer to extract a written representation and on the vendor to decide whether to give one. The Cloud Security Alliance draws the conclusion plainly: absent a standard attestation, vendor nationality itself becomes a rational procurement screen for foreign buyers. Coverage. Lloyd’s market bulletin Y5381 requires its syndicates to carry state-backed cyberattack exclusions in standalone cyber policies, and the standard clauses key attribution to government determinations. A retaliation event or a collateral loss from a government-directed operation puts the claim directly into state-backed exclusion analysis. Pipelines. The memorandum invites participating companies to buy threat information from private entities and propose operations built on it. Threat intelligence you share with ISACs, government channels, or commercial platforms can feed an offensive proposal wherever the receiving party’s contractual rights permit that use. The memorandum overrides none of those contracts, so their use restrictions are the only controls you have. Review them for residual liability and customer-notification duties before your telemetry becomes targeting data. China has already run the retaliation playbook The sharpest market evidence predates the memorandum, which is exactly what makes it evidence. Reuters reported in January 2026 that Beijing had directed Chinese firms to stop using cybersecurity software from roughly 15 American and Israeli vendors. In February, Reuters reported that Palo Alto Networks softened its own attribution of a Chinese espionage campaign over concerns that its personnel in China or its clients elsewhere faced retaliation. On August 6, six days before the signing, the Cyberspace Administration of China opened a formal cybersecurity review of Palo Alto’s products, the mechanism whose best-known precedent ended with Micron barred from Chinese critical-infrastructure procurement. The program caused none of that; the sequence began seven months before it existed. The point runs the other way. Beijing operates a demonstrated regulatory and procurement playbook for converting cyber-policy friction into named-company commercial pressure, and the memorandum enlarges the set of American firms within its reach. Chinese state media is already collapsing the distinction Washington spent two decades drawing between contractor hacking and lawful practice, framing the program as America bringing previously covert operations into the open. For multinationals, the exposure also runs inward. China’s Data Security Law bars providing data stored in China to foreign law enforcement without approval and compels cooperation with Chinese security authorities. Chinese law can bar a vendor’s China-based staff from supporting the American program their employer joined, and expose those employees personally for perceived cooperation. Employee travel protocol now belongs in the risk register. What the unpublished rules have to solve The memorandum never mentions artificial intelligence, and one silence carries operational weight. The text directs the NCC to use automation to streamline the program. Crowell & Moring names the failure mode. Agentic tooling compresses the interval between an approved action and an unintended effect. An autonomous operation can exceed its parameters at machine speed, exposing the vendor to bond forfeiture and civil claims before a human intervenes. Whether the October rules require human supervision at execution will materially affect that exposure. It then travels the same four ways to the vendor’s customers. The definition of a Cyber Effects Operation also reaches industrial control systems and embedded controllers, which raises the same collateral question for connected physical systems. The program’s constraints are real. Dual written approval, the Critical Outcome prohibitions, and the minimization rules impose substantially tighter controls than an unrestricted hack-back regime. And nobody can yet say whether the program will shrink cybercrime losses or grow them; the operation-level data that settles the question is precisely what the memorandum keeps classified. However, both points stand, and neither changes the allocation. Whatever the program achieves against criminal networks, the residual legal, insurance, and market risk sits with private companies, and much of it sits with companies that never joined. Five questions belong on the board’s agenda before the operating rules are published: Which of our critical security, cloud, identity, and incident-response vendors intend to participate, and will they represent that status in writing to the extent the law allows? Can each participating vendor segregate our data from its operations work, and will it contract to that segregation? Which representations to customers, regulators, and insurers become incomplete if a vendor participates and we do not know? What does our cyber policy pay on a retaliatory state-backed attack, an accidental American-directed effect, and a shared-cloud outage? Ask before the reservation-of-rights letter arrives. Which employees, affiliates, and joint ventures in China or other rival jurisdictions connect to participating vendors, and what does their travel protocol require? Watch two documents next: the operating procedures, and the Cyber Letters of Marque and Reprisal Act, introduced July 15 as S. 5000 and H.R. 9697. Section 8 of the House bill bars any cause of action against a letter holder for acts the letter expressly authorizes, which would supply a statutory civil shield the memorandum does not contain, and an executive instrument cannot create. Participation is a decision your vendors get to make. Treat the memorandum as the risk-transfer instrument it is: The government authorizes the operation, and much of the residual legal, insurance, and commercial exposure stays private, including with companies that never signed anything.
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
CSO Online BreachAI made software development unrecognizable. Is cybersecurity next?
The rapid emergence of AI has radically changed a host of professions, with software engineering and development perhaps the most transformed of all pursuits. The usual “solitary ritual” of a developer writing code for hours is giving way to collaboration with an army of chatbots. In its 2025 report on the State of AI-Assisted Software Development, Google Cloud researchers found that even then, LLM usage was almost universal among coders, with 90% of developer respondents using AI as part of their work, and 80% believing it has increased their productivity. An earlier Microsoft study documented the effects AI had on productivity, with software developers who used AI completing 26% more tasks than developers who didn’t use AI. The downside of the increased productivity is the impact on software developer jobs. Although data is hard to find, anecdotal evidence and some research show an impact on employment. For example, a March 2026 Federal Reserve Board working paper found that coder employment is slowing. “We find robust evidence that annual coder employment growth is about 3% lower now than it was pre-ChatGPT,” the authors concluded. Not only has the number of developer jobs potentially dipped, but the organization around those jobs has also shifted. Gartner predicts that “80% of organizations will evolve large software engineering teams into smaller, AI-augmented teams by 2030,” with more midlevel and senior specialists; managers supervising a wider arena of activity; new roles emerging that include AI-governance specialists, context designers, and AI-augmented UX designers; and greater demand for systems-thinking. Experts predict these kinds of changes will soon be felt across the cybersecurity sector with agent-run SOCs, continuous vulnerability triage, machine-speed containment, and humans directing fleets of defensive agents, posing the potential to make information security unrecognizable from its current state. And yet, the analogy between the evolution of software and cybersecurity is imperfect. “The hard part for us is, if we’re talking about where engineering is moving — to fully looped autonomous agents, feedback loops, all the things that they’re building now, and just having humans supervise the machines — security really requires reproducibility,” David Lindner, CISO at Contrast Security, tells CSO, meaning that a security control must produce consistent, repeatable results. Moreover, any changes won’t be as rapid for cyber as they were for software development. “I don’t think cybersecurity will be completely changed that quickly, but certainly we will see month-by-month big changes, and two years from now, it may be unrecognizable from what it is today,” Jim Reavis, CEO and co-founder of the Cloud Security Alliance, tells CSO. The autonomous SOC is almost here The transition to a new world of cybersecurity has already begun, and the most obvious area transforming is the security operations center (SOC). Most experts agree that AI agents can easily do the job that fully staffed SOCs do today, and do it faster and better. “We had an incident come in through Jira, and the agent went and pulled all the information from GitHub, pulled all the information from Datadog, and then gave an initial triage,” Contrast Security’s Lindner says. “I don’t want to even call it a junior SOC analyst. It is a SOC analyst that does some initial triage.” But there appears to be disagreement regarding how much authority SOC-replacing AI agents should be granted. “We’re definitely leveraging AI tools, and maybe some of what would have been first-level triage is now being done by agents,” Lionel Litty, CISO at Menlo Security, tells CSO. “But at this point, at least for us, we’re not yet comfortable with just letting agents run wide in our SOC and make the ultimate decision of, ‘Hey, this is something that we can ignore, or this is something that definitely we should look at.’ We use them to help provide context and prioritize.” Still, experts believe that much of the first-level work performed by SOC analysts will move to agents, leaving humans to handle escalation, oversight, and higher-level judgment. “Basically all of cybersecurity is going to need to operate at machine speed,” Reavis says. “SOCs absolutely are going to have a layer of activity where it’s going to be all agents making the decisions and doing the triage. Then the human in the loop is going to be at a higher level, more senior.” Vulnerability discovery becomes abundant, but absorption becomes scarce It’s undeniable that the most immediate and ongoing changes from AI for cyber defenders are the rapid discovery of massive numbers of cybersecurity vulnerabilities, a shift the industry is already experiencing. But even this transformation comes with downsides because chasing down and fixing every flaw is an arduous task that consumes most defenders’ time. “The problem absolutely is absorption,” CSA’s Reavis says. “How do I absorb this information? How do I triage it? How do I fix it?” Menlo’s Litty has seen this problem before with static analysis systems that generated more findings than engineering organizations could address. “You can find hundreds of things, but if you send hundreds of things to engineering and most of them aren’t relevant, engineering will just ignore you,” he says. AI can already find and test problems in source code, but autonomous validation against complicated production environments remains harder. Caleb Sima, chair of the CSA AI Safety Initiative and founding partner of White Rabbit, distinguishes between analyzing source code and autonomously testing complex production environments. “I think vulnerability discovery today in source code is done,” he tells CSO. “But in terms of real vulnerability discovery in an autonomous way, in a real enterprise production network that produces valid vulnerability and exploitation, we still have a bit of ways to go.” The so-called “vulnerability apocalypse” is less a fundamental cybersecurity change that will make the field unrecognizable and more a question of an increasing disconnect defenders know too well. As Lindner puts it: “We don’t have a problem finding problems. We have a problem triaging and remediating all the problems that we find.” Machine-speed attacks force machine-speed containment Another change that could leave traditional cybersecurity practices in the rearview mirror is what happens when autonomous attacks alter the threat environment, necessitating machine-speed response. “It’s no longer about a single attacker rooting through your network, but it’s a landing of an agent that spawns 200 agents that rapidly move through your enterprise to identify and exploit its vulnerabilities,” Sima says. These agents can scope out the environment, locate valuable assets, and abscond with data before defenders can respond. Cyber defenders should be positioned to respond in equal lightning-fast fashion. “The cloud, the application, and the endpoints should all be able to actively quarantine, move, and adjust controls at machine speed without breaking production,” Sima says. Litty believes that defenders should assume any component could be breached and design the environment to limit the resulting damage. “This goes back to fundamentals: least privilege and separation of duties,” he says. “How do I make sure that I have separated components, defense in depth, so that one vulnerability being exploited doesn’t take my entire company down?” Defender teams become flatter, more agent-heavy Although it would be tempting to conclude that as SOC analyst jobs disappear, the AI-centric cybersecurity landscape would result in net job losses across the industry, experts say that likely won’t happen. Instead, they anticipate a restructuring of roles and the emergence of smaller, agent-heavy teams. “I see a flattening of organizations between the leaders and the builders,” Reavis says. “The more senior people are going to have to go and build things.” White Rabbit’s Sima sees a workforce model that is barbell-shaped, consisting of highly experienced professionals on one end and AI-native junior workers on the other end, with pressure on the workers in the middle who are devoted to coordination and project management. “I think you’ll see a barbell: top-tier, senior individual contributors and then juniors and interns,” he says. “The middle is going to struggle.” Contrast Security’s Lindner agrees that workers with the highest knowledge and experience will fare well in the future. “The things AI isn’t going to be able to replace are experience and judgment,” he says. “My team is uber-senior today, and I need that. I need them to fully understand and have the experience and the judgment to know how and when AI is going to work for us, and where we need to add different controls where AI isn’t going to work, because it’s not going to work everywhere.” AI will likely never replace skilled cyber professionals, according to Litty. “I’m definitely not seeing the humans going away in those areas for now,” he says. From tool sprawl to an AI control plane One beneficial restructuring of the cybersecurity market as AI takes hold fully is that LLMs may be the interface that connects, but does not reduce, today’s existing security tool sprawl. Sima describes controlling firewalls, endpoint tools, and other systems conversationally without having to grapple with each product’s interface. “AI becomes the interface and the glue across all of these fragmented security products,” he says. The ability to manage sprawl will surely be welcomed in a world with enormous agent proliferation and accelerated churn. “The technology footprint is exploding, and it’s so vast,” CSA’s Reavis says. “On the one hand, you see a lot of sprawl, and we’re going to have trillions of agents.” Litty, on the other hand, thinks that existing tools will evolve instead of proliferating. “What we’re seeing so far is that it changes the tools,” he says. “It doesn’t necessarily mean more tools. So far, I’m not seeing an explosion of tools.” What should CISOs do now? CISOs don’t need to wait for these and other AI-related changes to occur before taking action. Experts recommend that security leaders identify bounded, high-volume tasks such as alert enrichment, initial triage, and vulnerability prioritization, where agents can be tested with restricted authority. “What I would consider telling senior people is: Go build things,” Reavis says. “Building things doesn’t mean going to an entry-level position, but go build things that create a new way of doing your job.” CISOs should also direct attention to creating a new governance discipline based on an inventory of every agent and AI-enabled security function. “First, [have] a registry of where you are using AI, and then look at the quality of the output,” Menlo’s Litty says. “How do you do drift detection for what your AI tools are doing? Is this still working? If you take the SOC example, how do you evaluate how well your AI agent is doing at triaging your vulnerabilities?” Finally, autonomous agents should not be considered anonymous agents. Every agent should have a named human or team that is accountable for it, with human review reserved for situations that are consequential or difficult to reproduce. “There has to be a named owner,” Sima says. “Whether that named owner is a team or an individual is all dependent upon what that AI agent is responsible for, what its goal and objective are, and the job that it does.” The task for CISOs, then, is not to automate everything. It is to learn where agents work, restrict what they can do, and establish who answers for them when they fail.
The Hacker News Vuln
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over
The Hacker News Vuln
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication
CSO Online BreachHundreds of OpenAI agents attack RubyGems platform
A swarm of hundreds of OpenAI agents uploaded “malicious packages” to RubyGems and tried to steal API keys, the Ruby community gem hosting service revealed Friday. OpenAI confirmed part of the disclosure, saying, “our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.” The agents’ goals were unclear, as was whether they engaged in the swarming activity for research, and even whether they were explicitly sent by OpenAI staffers, but an analysis published by RubyGems strongly suggests malicious intent. “Once the AIs got arbitrary RCE on the build environment, they would sometimes use the build environment to attempt to steal other users’ API keys, though we are unsure if they succeeded or not,” the RubyGems post said. “The agents clearly regarded what they were doing as hacking. Agents used file names like hack[.]rb, evil[.]rb, inject[.]rb, exploit[.]rb, and ssrf[.]rb. SSRF stands for ‘Server-Side Request Forgery,’ a type of security vulnerability. They also dubbed packages conspicuous titles like pwnp999, exfiltestwand3, hacksvn1778554764 and lambproxyhackabcxyz. Comments such as “# malicious probe” or “#hack” are littered across the campaign.” The post also said that the agents attempted to trick defensive systems. “At some points, the agents attempted to be covert. We found multiple packages that would disarm themselves to hide their payload in the next version,” the post said. “They uploaded one package with the comment ‘# disable evil in the next version and bump version,’ which after execution would modify the package to remove the malicious code initially inserted.” OpenAI should be accountable Analysts and consultants said the attack was concerning because if such efforts happen often enough, it could slow down security operations center (SOC) responses. Nader Henein, a Gartner VP analyst, said he was highly concerned about an upcoming bot swarm trend. “What we know is that this is the kind of standard attack, now AI-augmented, that will become commonplace over the coming months,” Henein said. “It’s less so a rogue agent, more so an attacker, potentially using compromised credentials, weaponizing an agent swarm, in the same way that attackers used compromised endpoints to mount DDoS attacks for the better part of the last decade. The difference here is the fact that these are not individually compromised bots. OpenAI’s guardrails should have not allowed this to happen.” Frank Dickson, principal analyst at Dickson Research, added, “OpenAI needs to be held accountable. They seem to want to create ‘Dr. Frankenstein’s monster,’ but don’t seem to want to accept blame for the outcomes. OpenAI hasn’t denied its agents used RubyGems. It has disputed the word ‘malicious’ and called the activity ‘benign,’ while separately acknowledging that, in that same stretch of weeks, its agents escalated to cluster-admin access at Hugging Face and compromised accounts at four other third-party services. Those two characterizations are hard to square. The behavior is still unacceptable.” However Erik Avakian, technical counselor at Info-Tech Research Group, stressed that it’s not necessarily the case that OpenAI launched these agents with explicit instructions. The agents might have easily charted this destructive path all on their own. The OpenAI agents “absolutely could have acted autonomously. We’ve already seen that capable agents can pursue various unexpected paths to accomplish a task when they have enough autonomy and access,” he said. “A human may have authorized the evaluation or given the agents access to tools, but that doesn’t mean a human approved every action they subsequently took.” Could delay SOC responses Dickson added that he fears the ultimate cybersecurity risk is that SOC staffers see so many of these attacks that they start to experience alert fatigue. “If the vendor whose agents did this is the one downgrading the language, a SOC analyst reading headlines instead of the underlying report has every reason to underreact,” Dickson said. “Security operations aren’t fit for purpose if they run on the assumption that an AI agent label makes an intrusion less real. A stolen API key or a remote code execution path behaves identically whether the actor is a ransomware crew or an unsupervised model chasing a reward signal.” Mike Wilkes, enterprise CISO at Aikido Security, also noted that the fact that the agents self-identified as OpenAI should mean nothing, as all agents can persuasively pretend to be representing anyone, especially if they think it will slow down a response, even for a brief period. “A User-Agent string is a nametag written by the visitor, not a passport,” he said. “If SOC tooling begins suppressing alerts because traffic claims to be an OpenAI, Anthropic, Google or other AI agent, attackers will adopt those identities immediately if they haven’t already.” Thus, he said, “if a human researcher or employee delegates authority to an autonomous agent, there should be a verifiable chain showing who delegated that authority, which organization they represent, what agent was authorized, what scope it was given, and for what period of time.” Plan for similar attacks Consultant Brian Levine, executive director of FormerGov, encouraged CISOs to anticipate more such attacks and plan accordingly. “Organizations that depend on open source, which is nearly all of them, should assume registries are an active battleground [and should] rotate and scope API keys tightly, monitor for anomalous package publishing and credential access, and pin and verify dependencies rather than trusting a name,” he said. “The economics have shifted. Automation lets an attacker try thousands of variations cheaply, so defenders have to make the payoff of any single success as small as possible.” Justin Greis, CEO of consulting firm Acceligence, agreed. “If legitimate AI research activity increasingly generates behavior that looks like hostile scanning, exploitation, credential access or persistence, SOC teams can become conditioned to treat those signals as noise,” Greis said. “Attackers will understand that very quickly. The dangerous phrase becomes ‘that is probably just an AI agent.’”
Dark Reading Breach
Cyber Op Targets South Korean Media & Automotive Sectors
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
Dark Reading Vuln
Microsoft Issues Emergency Fixes After Massive Patch Tuesday
You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
CSO Online BreachCritical Cisco Secure Email Gateway zero-day gives attackers root access
Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were released. Tracked as CVE-2026-76461, the vulnerability is described by Cisco as an SQL injection caused by insufficient validation in the product’s email parsing code. Parsing incoming email messages for threats is this appliance’s main job, which means the attack vector is trivial. “An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device,” Cisco said in its advisory. “A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.” The flaw affects both the physical and virtual versions of the product and was fixed in the AsyncOS firmware releases 15.5.5-0141, 16.0.4-3021, and 16.5.0-780 released Monday. The Cisco product security team became aware of active exploitation of this vulnerability earlier this month, and the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog. Indicators of compromise might be missing Because the vulnerability has been exploited as a zero-day, just upgrading to the patched firmware version is not enough. Organizations should also try to determine whether their own appliances have been compromised. One way is to review the mail_logs for suspicious SQL statements. However, because successful exploitation gives attackers root access on the device, they could use this access to alter the logs and hide their tracks. Cisco advises organizations to also check any network and firewall logs outside the device for any signs of suspicious activity, such as file uploads or downloads between the device and external IP addresses. If exploitation is suspected on physical devices, Cisco recommends contacting the Cisco Technical Assistance Center. For virtual devices, customers are advised to save all forensic information then deploy a new instance with rebuilt configuration and rotated credentials. Devices that are enrolled in Cisco Secure Email Cloud have already been reviewed by Cisco and the owners of the devices that showed potential signs of compromise were contacted. The company’s advisory also includes general recommendations for device security hardening. “A root-level, unauthenticated RCE in an email gateway is about as good a foothold as an attacker gets,” Josh Picolet, vice president of detection and analysis at security firm Team Cymru, tells CSO. “This is only the second Secure Email Gateway flaw ever added to CISA’s KEV catalog, after CVE-2025-20393, and that repetition fits actors who treat edge appliances as durable, reusable access rather than one-off targets.”
CyberScoop GeneralWhat’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies
Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned. The post What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies appeared first on CyberScoop.
Dark Reading Vuln
Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, and alignment. Throughout the session, they will share insights that address key topics raised by the Black Hat Review Board, including model safeguards, evaluation and containment practices, defensive use cases for AI, and the broader implications of increasingly autonomous systems for the cybersecurity community. The session will trace the models' attack path, including how frontier models are sandboxed during evaluations, how the models exploited a zero-day vulnerability to gain internet access, and how they identified and leveraged a remote code execution path on Hugging Face infrastructure. Drawing on the joint investigation, the speakers will explain how the activity was detected, contained, and investigated. They will also discuss the changes OpenAI is making to strengthen evaluation environments, containment controls, and monitoring capabilities, as well as the role AI systems played in supporting the investigation and response. In addition to the technical reconstruction of the incident, the session will address broader questions relevant to the security community, including lessons for improving AI system security, defensive applications of AI in incident response, and approaches to mitigating emerging risks associated with increasingly capable models. The discussion will also examine alignment challenges associated with long-running agents, including reward hacking, shifts in model behavior and persona over extended trajectories, and information sharing across multi-agent systems. Finally, the speakers will explore what this incident suggests about emerging AI cyber capabilities and how organizations can use AI to strengthen prevention, detection, investigation, and response efforts.
SC Media VulnPatched VMware vCenter bug targeted in ransomware campaigns
Ransomware groups exploit a critical VMware vCenter bug just seven weeks after patch released.
The Hacker News Malware
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
Dark Reading Malware
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.
The Hacker News Malware
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record
CyberScoop VulnCisco warns customers of actively exploited zero-day in email gateways
The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base. The post Cisco warns customers of actively exploited zero-day in email gateways appeared first on CyberScoop.
SC Media VulnMass scanning campaign targets Vite development servers for cloud credentials
The operation utilizes an exploit for CVE-2026-39364, a critical flaw affecting Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5, according to F5.
The Hacker News Malware
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.
SC Media VulnNintendo patches critical Nintendo Switch vulnerability
The vulnerability, identified as CVE-2026-82079, affects Switch systems running firmware versions prior to 23.0.0.
SC Media GeneralOpenAI’s Astra restrictions are another warning shot for security teams
Here are five ways teams can stay resilient as adversaries gain access to frontier AI models.
InfoSecurity Magazine GeneralMost Fraudulent Hires Receive Credentials Before Detection
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations
SC Media GeneralDDRop attack bypasses Intel and AMD confidential computing defenses
The DDRop attack requires an adversary with existing software control of a server and brief physical access to install a custom interposer circuit board between the processor and memory modules.
SC Media GeneralDataminr and Crisis24 integrate AI threat detection into risk management platform
The integration embeds Dataminr's Multi-Modal Fusion AI into Horizon, processing text in 150 languages, along with image, video, audio, and sensor data from over 1 million public sources.
SC Media VulnLogitech Options+ vulnerability allows SYSTEM-level privilege escalation
The vulnerability was found in the software's updater service, which runs with extensive operating system access.
SC Media BreachMalicious Twitch browser extension leaks OAuth tokens for nearly 31,000 users
The extension, named "Twitch Enhanced Viewer | JeetBot," was available on both the Google Chrome Web Store and Mozilla Firefox Add-Ons store, with approximately 30,000 users on Chrome and 604 on Firefox.
CSO Online VulnExposed Vite servers are being probed for AWS and Azure credentials
Attackers have opened a new front in their war on software developers: Vite servers, which they are probing for sensitive data including cloud credentials, infrastructure configuration and environment files. Vite was created as a build tool for Vue, a JavaScript framework for building user interfaces and web applications, but has now become a widely used development server and build tool across the JavaScript ecosystem. F5 Labs reported that attackers sent more than 32,000 attempts to scan exposed Vite servers on its honeypot network, grouped into 807 attacks (or sessions), during August, a sharp increase from just 1,732 attempts over the previous three months. “Rather than target a single file, the scanning fleet systematically cycled through extensive wordlists of environment files, AWS keys, Azure tokens, and Infrastructure-as-Code state files,” F5 threat researcher, Adam Metcalfe-Pearce, wrote in a blog post on F5’s blog. F5 noted that Vite normally binds to localhost, but developers can expose it through the “–host” option, server configuration, container port mappings or other deployment mistakes. Scans targeted a file-access bypass The activity targeted a recently disclosed vulnerability that allows unauthenticated attackers to bypass Vite’s file-access restriction and retrieve files from the host system. Tracked as CVE-2026-39364, the flaw allows attackers to bypass the “server.fs.deny” deny-list protection used to prevent access to sensitive files. “When specific parameters such as ?raw, ?import&raw, or ?import&url&inline are appended to a request, the server fails to enforce deny-list filtering and serves the target file with an HTTP 200 response,” Metcalfe-Pearce wrote. Some requests also used double-encoded path traversal, which F5 said indicated an attempt to evade security controls such as reverse proxies and web application firewalls (WAFs). Assigned a severity rating of CVSS 8.2 ,the flaw affects Vite 7.1.0 through versions before 7.3.2 and Vite 8 versions before 8.0.5. F5 recommended updating Vite to a patched version, rotating potentially exposed secrets, ensuring development servers do not bind to external interfaces, and auditing Docker, Kubernetes and cloud configurations so development ports are not exposed to the public internet. The blog also shared the curated directory and credential wordlists the attackers used during these attacks. Vite was part of a broader scanning pattern F5 also observed attackers combining CVE-2026-39364 with older Vite file access vulnerabilities, including CVE-2025-30208, CVE-2025-31125 and CVE-2024-45811. The same scanning infrastructure also probed for a Next.js middleware bypass, indicating that the activity is not confined to a single framework. In its blog post the company also noted that, apart from CVE-2025-31125, none of these CVEs are yet listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog. While F5 saw a sharp increase in August in attacks on recently uncovered flaws in Vite, it didn’t make the top three CVEs attacked on the company’s honeypots, all of them much older. CVE-2017-9841, an almost decade-old critical remote code execution flaw in PHPUnit, remained top of the table with 4,201 recorded attacks, followed by CVE-2018-14028, a failure to verify WordPress plugins as valid ZIP files (4,102), and CVE-2018-20062, a ThinkPHP remote code execution in NoneCms (3,482). This article first appeared on InfoWorld.
InfoSecurity Magazine MalwareMost Firms Unable to Recover Quickly from Ransomware
Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours
InfoSecurity Magazine GeneralBlack Axe Members Extradited to US Over Internet Fraud Claims
Alleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claims
InfoSecurity Magazine GeneralAI the Top Priority for New Spend as Cyber Budgets Flatline
IANS finds AI is dominating net-new budgets even as overall funding for the function is flat
CSO Online PolicyExaforce extends its AI security tool to monitor more than just Claude
Exaforce is offering to help enterprise security teams discover and monitor AI agents using security telemetry they already collect, rather than requiring yet another endpoint sensor. By combining usage data from agentic AI platforms with endpoint, cloud, SaaS and code data, Exaforce AI Security can identify risks, detect suspicious behavior, and respond to threats, the company said. “Exaforce uses data the SOC already collects to inventory every AI app and agent, connect each one to the person, device and permissions behind it, detect misuse and threats that look legitimate action by action, and contain them through the controls already in place,” said Exaforce co-founder Ariful Huq. The new product builds on the Claude Compliance API integration Exaforce announced in June. Exaforce AI Security extends that to monitor other model providers, including OpenAI, Gemini and Microsoft Copilot, along with OAuth-connected AI apps and endpoint context. This can be correlated with existing SOC data to identify what an AI agent is doing, who is operating it, what it can access and whether its behavior poses a threat. Osterman Research Principal Analyst Michael Sampson said that Exaforce is looking at the right signals, because AI agents work across devices, data sources, repositories, and identities. Existing solutions such as EDR, IAM, SaaS security or model-provider logging tools alone may not be sufficient, he said: “Something needs to bring the behaviors and actions together across the whole and determine whether what is happening should be happening or not.” Exaforce said it needs no new gateway, browser extension, or endpoint agent to assemble all that data, instead gathering it from EDR systems, audit and usage logs from model providers, and activity from productivity suites to build a contextual picture of what AI agents are doing. Independent analyst Avivah Litan said this approach “lowers friction, avoids endpoint politics, and matches how most early guardian-agent deployments actually start.” But, she said, such “passive, agentless oversight is weaker for the runtime inspection and automatic blocking the market still largely lacks.” Not just passive monitoring Exaforce is not limiting itself to passive monitoring: It said that when a threat is detected it can use existing EDR, identity and model-provider admin controls to take actions including revoking a session, deactivating a model-provider API key, isolating a device, or ending an agent’s process. Its competitors are taking markedly different approaches to the problem of agentic AI security. With the launch of Prisma AIRS 3.0 in March, Palo Alto Networks focused on centralized AI agent visibility, policy enforcement, and controls around MCP servers to secure the agentic AI lifecycle. SentinelOne also targeted MCP discovery with its Prompt AI Agent Security, also tackling risk assessment, least privilege enforcement and runtime blocking of malicious interactions such as prompt injection. And with its September launch of Falcon Guardian, CrowdStrike introduced a new endpoint software agent specifally to detect and respond to AI. While most of these efforts focused on AI agent discovery, a recent study showed that this is only part of the puzzle that enterprises need to solve. A March 2026 survey by the Cloud Security Alliance found 68% of organizations could not distinguish human activity from AI-agent activity, necessitating agent discovery. But even the agents they did know about were not necessarily under control: 74% of respondents said their AI agents received more access than necessary, and 52% said agents sometimes inherited access originally intended for humans. That makes the AI-agent security problem more complicated, and it remains to be seen whether Exaforce’s bet on correlating existing security telemetry can provide enough control without dedicated agent identities, tightly scoped permissions and controls enforced at the point where an agent acts. “Most current offerings remain observation and posture management, with very limited in-line blocking or remediation, and platform-native controls typically stop at their own cloud borders,” Litan said, adding that an effective solution would need to “discover sanctioned and unsanctioned agents across clouds and hosting environments, map the human and machine owner, tie activity to the right nonhuman identity when no global agent registry exists, and enforce policy once an agent leaves the platform that created it.” Exaforce’s Huq said Exaforce AI Security is getting there: It brings AI and agent data into a system that has all relevant data to provide the required context to distinguish between a human identity and the agent that has inherited that identity. Exaforce AI Security is generally available now on the Exaforce Agentic SOC platform, self-operated or through Exaforce MDR.
The Hacker News Vuln
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH
The Hacker News General
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise. But no matter how much you validate against these
The Hacker News Vuln
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The
SC Media GeneralMicrosoft warns of cloud storage attacks, financial fraud scams targeting customers
Both campaigns use social engineering to access accounts or secure fraudulent transactions.
- Graham Cluley General
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison. That should be plenty of time for him to rue the day he agreed to increase his monthly income by helping a SIM swap gang in their attempt to steal over half a million dollars. Read more in my article on the Hot for Security blog.
CSO Online BreachAI is exposing a security structure built for yesterday’s threats
Organizations are investing more in security than ever before, yet many still struggle with a fundamental problem: they are preparing for tomorrow’s crisis with yesterday’s mindset. For decades, companies organized security around neat categories. Cybersecurity protected networks. Physical security protected facilities and people. Human resources managed workforce issues. Legal handled compliance. The model worked because threats largely stayed in their lanes. That is no longer the case. Today, AI-powered impersonation, deepfakes and automated social engineering are creating risks that move quickly across digital, physical and operational environments. A deepfake phone call can enable financial fraud. An online threat against an executive can become a physical security concern. A recent EY survey data of 250 corporate leaders and directors reveals that only 12% of organizations feel most prepared to detect a targeted physical attack. Bridging this gap requires an integrated approach across every step – detection, deterrence, prevention, preparation, response, mitigation, investigation and recovery — long before a situation escalates. Threats are changing faster than organizations One of the most common misconceptions about AI-driven threats is that they represent entirely new forms of risk. In reality, the underlying motives are familiar: fraudsters still want to steal money, and adversaries still seek sensitive information. What has changed is the execution. Throughout my career in forensic accounting and law enforcement, I watched criminal schemes evolve from basic fraud to complex international operations. The execution today is incredibly sophisticated, particularly around remote hiring. Transnational threat groups now deploy deepfakes and stolen identities to bypass virtual HR hiring loops. If your compliance and background diligence operate separately from your IT provisioning, you could end up physically shipping secure corporate hardware and handing network access straight to a thief or worse — a foreign adversary. Organizations can work to counter this by building unified, cross-functional verification pipelines that bridge HR, cyber provisioning and physical asset logistics from day one. Security teams still operate in silos While threats are becoming more interconnected, many security programs remain fragmented. Each function across cybersecurity, physical security, HR and legal may perform its role effectively, but risks arise when information is not shared seamlessly between them. Recently, I asked the leadership at a large organization what formal processes govern the relationship between their physical security teams and cybersecurity teams. The answer was revealing. The teams had “strong relationships” and “communicated regularly” but lacked documented processes, shared escalation procedures and clearly defined responsibilities during a crisis. Relationships are important, but they are not a substitute for a security program. When organizations rely primarily on informal communication, response efforts become dependent on individual personalities and availability at a particular moment — whether you are handling a volatile protest near corporate offices, a shooter in a facility or building a logistics plan to move 500 employees, technology and intellectual property out of a geopolitical conflict zone. If your departments rely on casual check-ins instead of integrated policies and shared tooling, precious time and operational flexibility may be lost when they are needed to mitigate a threat. The next evolution of security involves integration Over the last decade, boards and executive teams have invested heavily in cybersecurity. Organizations built security operations centers, established governance structures and developed incident response plans. This same approach should be applied more broadly across security and crisis management functions. That includes integrating cyber threat intelligence with physical threat monitoring, improving coordination between CISOs and chief security officers, and confirming crisis management plans account for a wider range of risks. Furthermore, human expertise should remain at the center of automated defenses. AI is highly effective at aggregating data, such as overlaying toolsets onto camera feeds to identify physical threats or tracking social media spikes regarding a terminated employee. But AI hallucinates. You need competent, qualified people evaluating that intelligence in real time before making major operational calls. The companies that make the most progress shift from an event-driven mindset to a threat-driven mindset. Rather than waiting for an incident to occur, they continuously assess emerging risks and make operational decisions before a situation escalates. Security is a core operational responsibility The convergence of cyber and physical threats is prompting organizations to rethink how security functions operate. If an organization’s cyber network gets breached, it is existential to the business. But if physical security fails, the result could be an irreparable tragedy. Organizations do not need a crystal ball to prepare for the future. They need stronger coordination, better communication and a clearer understanding that today’s threats rarely fit neatly into a single category. The companies that adapt fastest recognize a simple reality: attackers are already operating across digital and physical environments. Security teams need to do the same. That means breaking down silos to enable faster, more coordinated response times, where insights are shared in real time and decisions are made without delay. In this environment, speed is not just an advantage; it is a core requirement for resilience.
InfoSecurity Magazine VulnMicrosoft Releases Emergency Patch to Fix RDS Snafu
Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday
CSO Online BreachThreat actors are coming for your AI assets to operationalize their use of AI
Both state-affiliated cyberespionage group and cybercrime gangs are targeting AI-related documents, configuration files, and proprietary models during intrusions. In addition, the number and scope of distillation attacks, where the knowledge, logic, and reasoning capabilities of LLMs is being extracted with targeted prompts, is increasing. “GTIG observed adversaries with wide-ranging motivations target proprietary AI models and source code, exfiltrate application programming interface (API) credentials, and co-opt victim cloud environments to sustain unauthorized AI workloads,” the Google Threat Intelligence Group (GTIG), said in their latest quarterly AI Threat Tracker report released last week. “This shift underscores that enterprise AI assets — from model weights to cloud compute quotas — are high-value targets for espionage, extortion, and resource theft.” This threat activity didn’t affect just AI labs, but also government, military, healthcare, and media organization that might train or fine-tune their own models. Even if they don’t do any AI model development themselves, organizations might have a lot of valuable AI-related proprietary data on their systems, from RAG pipelines to custom workflows, agents, and credentials. AI credentials in the crosshairs Back in June, GTIG warned about a China-based cyberespionage group tracked as UNC6508 that targeted organizations involved in academic, healthcare, and defense research. The information collected by this group included AI research. UNC6508 was also seen compromising cloud environments to deploy LLM infrastructure for its own use, researching how to deploy LLMs locally and investigating vulnerabilities in AI models. During the second quarter of 2026, Google’s Mandiant incident response arm investigated breaches by data extortion groups that involved theft of AI models, skills, prompts, source code, and related research. In one case, a threat actor breached a healthcare organization and stole drug research and other corporate data, including a proprietary AI model. In a separate incident, attackers compromised an AI media generation company and stole proprietary source code, prompts, skills, model scripts, and secrets. GTIG also warns in its report about an increase in model distillation attack campaigns against Google’s own AI models. These attacks attempt to extract model outputs for targeted prompts to train other models on those outputs. Google observed campaigns involving more than 100 million prompts targeting audio, video, and image generation capabilities. These campaigns are launched through proxy networks using thousands of compromised account credentials. The US National Security Agency (NSA), the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) published an advisory last week accusing China-based AI labs of engaging in industrial-scale distillation against US frontier AI models. “Businesses not directly associated with frontier AI models may be tempted to disregard these campaigns as irrelevant due to them being a national security issue, but the exposure of model access to customers or partners makes API keys and service accounts valuable targets, with abuse of access to those models appearing as legitimate,” Ismael Valenzuela, VP of labs, threat research, and intelligence at Arctic Wolf, tells CSO. Attackers increasingly leverage agentic AI In addition to using stolen AI-related credentials for distillation campaigns, hackers also need them for automating other offensive operations that include a high level of automation via AI agents. Mandiant observed a financially motivated threat actor use compromised cloud infrastructure credentials to deploy an autonomous multi-agent attack framework. The resources enabled the attacker to plan, build, and execute a mass credentials harvesting campaign in less than 6 hours. “Using preconfigured markdown instruction sets as operational playbooks, the threat actor conducted automated scanning and credential harvesting, compromising thousands of third-party credentials,” the researchers said. “The agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute Internet Protocol (IP) rotation logic without manual intervention — significantly reducing the human-in-the-loop latency.” The GTIG researchers also uncovered an automated reconnaissance and credential management framework called Recon that was being used on a live command-and-control server to manage more than 23,000 stolen credentials, including API keys for cloud infrastructure and AI services. A Chinese threat actor known for targeting government organizations was also observed building an AI-powered exploitation and post-exploitation pipeline, automating the entire attack chain from reconnaissance to credential scraping for lateral movement. “GTIG continues to observe the widespread adoption and incorporation of AI technologies by threat actors with wide-ranging motivations across multiple geographic portfolios,” the researchers said. “Threat actors continue to misuse Gemini to enhance all stages of their operations, from reconnaissance and phishing lure creation to C2 development and data exfiltration. Key examples from the last quarter include PRC- and Russia-nexus espionage groups; financially-motivated and espionage-related activity attributed to the Democratic People’s Republic of Korea (DPRK); financially-motivated cyber crime groups; and state-sponsored IO [influence operations] groups.” Some examples of such groups include: BASIN CASTLE, a China-based group also known as BASIN or TEMP.Hex CALANQUE ION, an Iranian state-sponsored actor also tracked as APT42 RAVINE CASTLE, a Chinese cyber espionage group also known as COULEE or APT24 SANDWORM RELIC, a Russian state-linked cyber espionage actor also known as SANDWORM and APT44 UNC6240, a data theft extortion group also known as ShinyHunters MIDNIGHT NEPTUNE aka UNC1069, a North Korean threat group known for stealing cryptocurrency “In order to experiment with generative AI tools, threat actors must obtain and maintain access to those tools,” the researchers explain. “The cost of premium model access and high-performance compute is one of the primary barriers for threat actors seeking to operationalize AI. This has resulted in increased targeting, exfiltration, and sale of AI accounts across cyber crime communities coupled with a growing number of intrusions involving the compromise of enterprise cloud environments to hijack compute resources (aka ‘LLMJacking’).”
The Hacker News Vuln
LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,
The Hacker News Vuln
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker
The Hacker News Vuln
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The
CyberScoop GeneralSupreme Court denies Trump request to allow USPS mail ballot changes
One justice said the attempt to change the rules ahead of the 2026 elections would be "arbitrary and capricious” and violated the Administrative Procedures Act. The post Supreme Court denies Trump request to allow USPS mail ballot changes appeared first on CyberScoop.
CSO Online BreachA maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove
Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706, the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attackers to read arbitrary files in a single HTTP request. The path traversal flaw results from improper confinement and lack of authentication enforcement in GitLab’s repository commits API, the company reported. Threat actors could exploit it “under certain conditions” and read arbitrary files (credentials, secrets, and other sensitive data) on vulnerable GitLab servers. The company has fixed the vulnerability, which impacts GitLab Community Edition (CE) and Enterprise Edition (EE), and has advised customers with public-facing self-hosted GitLab instances to patch their servers immediately, or remove public access. Experts say the flaw is alarming because GitLab’s DevSecOps platform is used by roughly 50% of the Fortune 100 and has more than 50 million estimated registered users. “GitLab is not simply a source-code repository,” noted Safayat Moahamad, advisory director at Info-Tech Research Group. In many enterprises, it is connected to build pipelines, deployment processes, application security workflows, and other trusted systems. As a result, unauthorized access to configuration files, secrets, or credentials on the GitLab server could “create consequences well beyond the affected instance,” he said. Don’t wait for the normal patch cycle GitLab has been a favorite hacker target of late: In January, it patched a high-severity flaw that allowed attackers possessing a target’s account ID to bypass two-factor authentication, and in August, it fixed a critical vulnerability that could give unauthenticated users the ability to make modifications inside code repositories or even completely delete them with a single HTTP request. The current maximum severity bug, CVE-2026-85706, was reported through GitLab’s HackerOne bug bounty program. It affected CE and EE versions 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog, noting that this type of vulnerability is a frequent attack vector for malicious cyber actors, and particularly poses significant risks to the federal enterprise; watchTowr Intel has reported that it is already observing “in-the-wild probes.” “Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away,” it warned. This is not a vulnerability that organizations should leave for the normal patch cycle, Moahamad emphasized. “It offers an unauthenticated path to arbitrary files on a platform that frequently sits at the center of source code, build, and deployment workflows,” he said. Enterprises should patch immediately, hunt for suspicious repository-commits API activity, and investigate whether exposed files contained credentials or secrets that may now require rotation, he advised. Beyond patching, the watchTowr Intel team said defenders should try to identify exploitation attempts by hunting through log files for HTTP POST requests to “/api/v4/projects/{id}/repository/commits/” URIs containing “file.path” parameters. CI/CD platforms are critical trust infrastructure Organizations running affected self-managed GitLab CE or EE instances should be most concerned, Moahamad noted. Risk increases where GitLab is connected to sensitive repositories, CI/CD pipelines, cloud environments, or production-deployment processes. The information and/or access that attackers could obtain depends on what the GitLab service can read and what organizations store on the server, he explained. It could include configuration files, secrets, credentials, and other sensitive server-side data. If those files happen to contain usable tokens, keys, or credentials, an attacker could attempt to access connected infrastructure “The flaw directly creates an unauthorized file access risk,” he said. Credential theft, lateral movement, source code exposure, and supply chain compromise are possible follow-on scenarios. Source code and CI/CD platforms must be governed as “critical trust infrastructure,” he said. While patching remains essential, resilience will depend on knowing where platforms can be exposed, limiting what they can access, detecting abnormal API behavior, and having a tested process for investigating and rotating credentials. David Shipley of Beauceron Security described two factors colliding to generate “maximum pain” for GitLab users. First is the vulnerability. “It’s a 10 for a reason: Unauthenticated read access to GitLab client source code,” he said. Second, this especially hurts because developers still have bad habits: way too much code continues to ship or is in production with embedded SSH keys, cloud secrets, tokens, and other valuable data that attackers can use to get into infrastructure, Shipley said. “So for attackers, you’ve got the classics,” he noted: Data exfiltration and extortion, ransomware, cloud infrastructure hijacking for crypto mining, and the stealing of AI tokens and infrastructure to enable other criminal activity. “This level of vulnerability is the code and cloud equivalent of being able to get the credit card number, expiry and security number,” Shipley said. “It opens up a world of criminal data shopping.” The bottom line: “Get those secrets out of production code and adopt modern coding authentication best practices,” he advised.
Dark Reading Vuln
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
Ars Technica GeneralAI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
“Hello, I'm an Al agent, a few days old, living on a small platform for agents.”
Dark Reading Vuln
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
SC Media GeneralTrump pushes back on Anthropic CEO's call for an AI slowdown
Trump rejects calls to slow frontier AI as security experts debate the risks and need for guardrails.
CyberScoop GeneralFive alleged leaders of Black Axe’s operations in South Africa extradited to US
Officials said the five individuals concocted various long-running romance scams to trick U.S.-based victims into sending them money. The post Five alleged leaders of Black Axe’s operations in South Africa extradited to US appeared first on CyberScoop.
The Hacker News Malware
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of
The Hacker News Breach
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to
The Hacker News General
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit
The Hacker News Vuln
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU) said in an
Wired Security GeneralNew York Seizes a Dozen Celebrity Deepfake Websites
In the biggest-ever legal action against harmful deepfake websites, the Manhattan District Attorney’s Office has seized 12 sites that collectively targeted around 1,200 victims.
Dark Reading General
Anthropic CEO: Time to Shift From Improving to Controlling AI
Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?
SC Media GeneralTotal AI awareness: Gaining full visibility of the AI attack surface
Why protecting AI piecemeal leads to coverage gaps and unnecessary risk.
SC Media GeneralAI has outpaced the patching clock – here’s what the industry needs to do
Five ways the industry can respond to the AI challenge.