Monday, August 24, 2026

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.

That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are.

Plenty to clean up. Here’s the short version.

⚡ Threat of the Week

U.S. Warns of AI-Powered Attacks on Siemens PLCs — Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to the U.S. government. The agencies warned: "This is not a theoretical risk—it is an active threat." The exploitation of poorly secured PLCs could result in disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, and compliance violations, not to mention have cascading impacts across interconnected systems. Threat actors have been observed using legitimate scanning services, such as Censys and ZoomEye, to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs. Once vulnerable systems have been identified, AI-generated scripts masquerading as legitimate monitoring tools are deployed to find exploits. For capability development, actors are testing and refining their exploitation techniques against specific PLC models to improve their ability to compromise the PLCs," the agencies said. "To prepare for operational effects, actors are leveraging read access to understand target environments, enabling preparation and positioning for future write operations to cause disruption or other operational impacts." It's currently not known who is behind the activity.

🔔 Top News

  • GitLab Flaw Comes Under Attack — A newly disclosed security flaw in GitLab came under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring credentials, user interaction, or obscure configuration.
  • 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor — A set of 14 trojanized npm packages were found to masquerade as functional calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. RedC2 4.0, marketed on cybercrime forums as a cross-platform toolkit for Windows, macOS, and Linux, offers surveillance, credential theft, payload loading, and mass-operation capabilities. The version was advertised by a threat actor named "MarlboroMan" on Hack Forums in early June 2026, describing it as a command-and-control (C2 or C&C) framework "built for evasion."
  • Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payment Fraud — Academic researchers demonstrated a new Zombie Card attack that bypasses cryptographic checks to complete contactless payments using physically expired Visa credit cards. By taking advantage of a smartphone relay setup to alter the expiration date fed to the point-of-sale (PoS) terminal without breaking the card's cryptography, it's possible to make real in-store purchases. Raja Hasnain Anwar, the lead author, told The Hacker News that transactions succeeded at most of those banks when the team modified the Consumer Device Cardholder Verification Method (CDCVM) flag. There is no evidence the technique has been exploited in the wild.
  • Suspected Russian Hackers Abuse Legitimate Authentication Workflows — Three distinct suspected Russian cyber espionage threat clusters, viz., UNC6293, UNC7005, and UNC5976, have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. "These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms," Google said. UNC7005 has also been attributed to CaptiveCrunch, which targets captive Wi-Fi portals in locations such as hotels, conference centers, and airports in the U.S. and elsewhere to stealthily redirect users to attacker-controlled infrastructure to steal credentials. A new report from Lumen Black Lotus Labs has found that the threat actor likely compromised three Managed Service Providers (MSPs) to conduct the captive portal hijack via a supply chain attack.
  • Cloudflare Workers Spectre Attack Leaks JWT — A remote Spectre attack against Cloudflare Workers has been found to leak a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of a previous attack demonstrated in 2021. "Cloudflare Workers is one of the top three edge-computing solutions and handles millions of HTTP requests per second worldwide across tens of thousands of websites every day," researchers said in a study. "We demonstrate a remote Spectre attack using amplification techniques in combination with a remote timing server, which is capable of leaking 120 bit/h."
  • Cl0p Deploys Bespoke Web Shell in PTC Windchill Attacks — A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software. Per ReliaQuest, the web shell is a fully equipped extortion platform capable of mapping sensitive vault data, decrypting every credential in the Windchill keystore, and running additional code by means of a custom Java class loader. This is not the first time the Clop gang has deployed custom web shells. The e-crime group was previously observed dropping DEWMODE and LEMURLOOT after exploiting SQL injection flaws in Accellion (CVE-2021-27101) and MOVEit Transfer (CVE-2023-34362) file transfer software, respectively. As of August 12, 2026, the ransomware gang started releasing alleged victims' full names. Over 40 organizations are said to have been targeted by the prolific e-crime group. The development continues Cl0p's trend of targeting zero-days in popular SaaS platforms for mass exploitation and extortion.
  • Security Flaw in Unisoc — Researchers disclosed a new unpatched flaw in Unisoc T612 modem firmware that, when combined with a previously disclosed remote code execution (RCE) vulnerability (also unpatched), could allow a threat to obtain elevated access to the Android kernel on affected devices. The exploit can be triggered by first delivering a malicious payload to the phone's modem via the RCE vulnerability and then placing a video call to the device, which the victim would need to answer. "A critical vulnerability has been identified in the Unisoc modem firmware that allows arbitrary code execution with kernel privileges from the modem context," SSD Secure Disclosure said. "By disabling protections on the first memory region (ID 0) of the Memory Protection Unit (MPU), an attacker can gain unrestricted read and write access to physical memory. This can ultimately lead to local privilege escalation, including the ability to modify kernel code."

‎️‍🔥 Trending CVEs

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-15748 (Forminator Forms), CVE-2026-15826 (User Profile Builder), CVE-2026-73570 (Zimbra), CVE-2026-32475 (Elementor Pro), CVE-2026-64849 (MLflow), CVE-2026-25895 (FUXA), CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359, CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318, CVE-2026-20319 (Cisco), CVE-2026-19478 (GitLab), CVE-2026-65346 (Apple), CVE-2026-19505, CVE-2026-19506, CVE-2026-19507, CVE-2026-19508, CVE-2026-19509 (RDK Central RDK-B WebUI), CVE-2026-75874, CVE-2026-74934, CVE-2026-74935, from CVE-2026-74936 through CVE-2026-74949 (Mozilla Firefox and Thunderbird), CVE-2026-76034, CVE-2026-76036, CVE-2026-76017 (Google Chrome), CVE-2026-14682, CVE-2026-12143 (Atlassian Bamboo Data Center), CVE-2026-76404, CVE-2026-76389, CVE-2026-76395, CVE-2026-76310, CVE-2026-76311, CVE-2026-76312 (Splunk), CVE-2026-69106, CVE-2026-65922 (JFrog Artifactory), CVE-2026-6837 (Zyxel), CVE-2026-18051 (W3 Total Cache), CVE-2026-63093 (Cursor), CVE-2026-40144, CVE-2026-40145 (BeyondTrust Endpoint Privilege Management for Windows), CVE-2026-57580 (Authentik), CVE-2026-63182 (PHP litesaml/lightsaml), CVE-2026-41473, CVE-2026-41472 (CyberPanel), CVE-2026-66794 (Multicluster Engine for Kubernetes), CVE-2026-69502, CVE-2026-69555, CVE-2026-65816, CVE-2026-65801, CVE-2026-65770, CVE-2026-69836, CVE-2026-24301 (Microsoft), CVE-2026-15580 (N-Able Passportal), CVE-2026-59270, CVE-2026-47836, CVE-2026-47841 (Spring Security UnboundID LDAP server), CVE-2026-75501 (Calix GS7 XGS GS5239XG router), CVE-2026-18963 (Keycloak), and GHSA-p9r8-2q67-fp86 (AMMOS Instrument ToolkiT-GUI).

🎥 Cybersecurity Webinars

  • AI Coding Is Creating Remediation Debt. See What 300 Enterprise Leaders Found AI coding is accelerating development, but it’s also pushing more unvetted open source into production and expanding the backlog security teams must manage. See what 300 enterprise security and engineering leaders revealed about the growing risk, and which governance approaches are actually helping teams regain control.
  • AI Attacks Can Move in Minutes. Can Your Security Operations Keep Up? → AI is compressing vulnerability discovery, exploit development, and attack chaining into much shorter windows. Learn a practical AI threat-readiness framework for improving attack-surface visibility and accelerating investigation, validation, and remediation before machine-speed threats outpace existing security operations.

📰 Around the Cyber World

  • Live Stripe keys for 659 merchants leaked — A dataset published on a data-trading forum on August 18, 2026, contains live Stripe API keys for 659 merchant accounts, along with roughly 35 GB of customer and payment data pulled from them. "A Stripe secret key is not a password to a dashboard," Ransomnews said. "It is full programmatic access to the account. Anyone holding one can read every customer record, create charges, issue refunds, and change where payouts are sent. The 519 accounts in that bottom row could, on the collector’s own record, both take money in and move it out."
  • CISA Releases Guidance for Improving Operational Standards — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published the Logging Reference Architecture for federal agencies to establish logging, visibility, and operational standards in an Agency Logging Plan. The guidance implements a practical, risk-based, prioritized logging approach that improves agency network monitoring. "Cyber defense begins with insight. Robust logs provide the critical visibility needed to counter daily threats targeting federal systems. CISA is enhancing agency logging strategies to ensure security teams can rapidly detect and respond to cyber incidents," said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. "The Logging Reference Architecture guides agencies away from fragmented practices, establishing a mature enterprise capability that maximizes the operational value of their data."
  • U.S. Court Partially Overturns Ex-Google Engineer's Conviction Linwei Ding, a former Google software engineer who was convicted earlier this year for allegedly stealing thousands of the company's confidential documents to build a startup in China, had part of the ruling overturned by a U.S. federal judge last week. According to Reuters, U.S. District Court Judge Vince Chhabria in San Francisco ruled there was not enough evidence that the defendant intended or knew his conduct would benefit the government of China. Ding is scheduled to be sentenced on September 1, 2026.
  • How Threat Actors Abuse ScreenConnect — Threat actors are using various methods, ranging from phishing lures and SEO-poisoned balenaEtcher downloads to malvertising redirects and an already-resident SimpleHelp agent, to deploy ScreenConnect via PowerShell and msiexec. "In the one case that reached full hands-on control, the operator rotated domains, deployed multiple ScreenConnect instances disguised as Microsoft services, layered persistence across services, SafeBoot, and credential providers, and ran scripts to evict rival RMM tools before forcing a reboot," Trend Micro said.
  • DCRat in 2026 — Judicial‑themed phishing lures are being used to propagate DCRat, per Trellix. "Every stage of the attack required human interaction, from opening the phishing email to extracting the archive to executing the malicious components alongside trusted libraries by using DLL sideloading," the cybersecurity company said. "In its final stage, the malware employed process hollowing to inject malicious code into a trusted system process, effectively evading detection. The end payload was DCRat, granting attackers full remote access and control. This campaign is particularly notable for a legitimate, signed utility to bypass traditional security perimeters."
  • Using Apple's Find My to Track Live Location — A security researcher who goes by the name Zerotistic has devised a way to enroll a Linux-based machine into Apple's Find My network and read live location data from it for those who have opted to share their locations with the Apple account owner.
  • WebAudio Fingerprinting on Alibaba — Developer Matt Callaghan has accused Alibaba's AliExpress of trying to track web users by playing sounds through browsers vulnerable to audio fingerprinting. The software engineer discovered the issue late last week after investigating why his Bluetooth headphones stopped playing music whenever he visited the AliExpress website. "Shortly after loading the AliExpress homepage, audio from my phone would stop playing," Callaghan said. "Closing the AliExpress tab fixes it immediately. Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page." Firefox issued a statement on X saying its anti-fingerprinting technology blocks Alibaba's tracking technique. Tom Ritter, who leads security efforts for Mozilla Firefox, said: "We made the WebAudio constant in Firefox 118 three years ago as part of our initial round of Fingerprinting Protection features. This eliminated most of the differences."
  • Anthropic Expands Claude Mythos 5 Access — Anthropic said it's working with cybersecurity technology and services partners to integrate Claude Mythos 5 into their products and services to secure their software. "Customers on Claude Enterprise plans can now run our most capable model in Claude Security, using it to scan their codebases for security vulnerabilities and suggest patches," it said. "Our new Defender Advantage Fund (0xDAF) will provide $35 million in credits to organizations working to patch vulnerabilities in open-source projects, automate parts of the process of scanning and patching open-source software, and experiment with new security approaches."
  • Agentic Source Code Review — Google said it uses what's called the Agentic Vulnerability Discovery Harness (AVDH) to "rapidly analyze code and find exploit paths during proactive reviews, penetration tests, red team operations, and incident response engagements." The development comes amid increasing adversarial misuse of AI. The tech giant said its use of AVDH over the past 10 months has led to the discovery of over 100 true-positive critical vulnerabilities, including critical flaws in Drupal (CVE-2026-13242 and CVE-2026-55803). The system outlined by Google is very similar to Microsoft's MDASH.
  • 768 Leaked Corporate AWS Keys Hold Full Admin Rights — Truffle Security's scan has verified 64,024 unique AWS key pairs across 431,875 public findings, including git history, Hugging Face datasets, Docker images, package registries, CI logs. These keys surfaced publicly between August 2022 and August 2026. Of these pairs, 10,616 came with complete credentials. According to Truffle Security: ""88% still authenticate. 768 of the live ones belong to a company and carry full control of its AWS account: 526 root keys plus 242 IAM users holding AdministratorAccess. The median live leaked key is five years old and has never been rotated."

Conclusion

This week’s useful reminder: attackers rarely need everything to fail. One exposed service, one trusted shortcut, or one overlooked dependency can be enough to get started.

So the better question is not “what’s the next big threat?” It’s “what are we still assuming is safe?” That usually finds the problem sooner.



from The Hacker News https://ift.tt/m8kioQI
via IFTTT

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups.

According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) technique to dupe victims into running malicious commands under the pretext of completing CAPTCHA verification checks.

"Once the visitor clicks on the 'I'm not a robot' checkbox, they're walked through the well-known ClickFix flow, where a malicious command is copied into their clipboard and the victim is instructed to paste it into the Windows Run dialog and execute it, leading to the download of WordlistLoader that ultimately results in the execution of Amatera," security researcher Vojtěch Krejsa said.

The ClickFix prompts are displayed on real websites that have been compromised with malicious JavaScript that's injected in the form of a Base64-encoded blob. The blob, for its part, fetches another JavaScript from a smart contract stored on the blockchain, an approach known as EtherHiding, and dynamically executes the retrieved code. Some of the compromised websites serving ClickFix prompts are below -

  • abogadosrosarinos[.]com
  • aptisweb[.]com
  • avene-hebergement[.]com
  • https-xhamster[.]com
  • www.caesarjaco.co[.]id
  • skybap[.]shop

In recent months, ClearFake campaigns have been revamped to use "cdn.jsdelivr[.]net" to host the threat actor's malicious JavaScript, highlighting the abuse of a legitimate Content Delivery Network (CDN) to stage rogue payloads.

"Although the CDN is meant for hosting JavaScript, the threat actors are actually using it to host their malicious PowerShell script," Expel noted earlier this January. "While jsDelivr appears to be taking down the actor's malicious repositories fairly quickly, the first stage's use of EtherHiding allows them to easily swap out burned URLs for fresh working ones."

The ClickFix command uses "conhost" to launch a hidden "cmd.exe" process, then map a remote WebDAV share using pushd, and finally launch the loader via "rundll32.exe." It's worth noting this WebDAV-based approach overlaps with a similar campaign recently highlighted by Microsoft.

In this campaign, a ClickFix prompt instructs the target to run a command that launches "cmd.exe," which subsequently invokes "rundll32.exe" to load a DLL from a remote WebDAV share accessed over HTTPS. Three different versions of the command have been recorded -

  • Direct rundll32 invocation
  • pushd-Mounted WebDAV Share followed by rundll32.exe invocation
  • Headless and obfuscated pushd execution followed by rundll32.exe invocation (which matches the WordlistLoader infection chain)

"In the more advanced variant, threat actors further enhance stealth by launching commands through conhost.exe –headless, suppressing visible console windows, and employing environment variable obfuscation with delayed variable expansion to conceal critical execution components such as pushd, rundll32, and the remote host name," Microsoft said.

"Combined with minimized or headless execution, these techniques reduce user visibility, complicate static analysis and detection, and enable the infection chain to execute with minimal indication to the victim."

The primary difference is that the Python-based loaders observed by Microsoft between late April 2026 and mid-June 2026 in connection with the ACR Stealer intrusion chain have been replaced by WordlistLoader. ACR Stealer has also been propagated via ClickFix prompts that trigger a command spawning MSHTA to retrieve and execute remote HTA content from a threat actor-controlled domain.

This leads to the execution of a VBScript loader that decodes and runs PowerShell designed to fetch a JPEG image from an image-hosting service and extract it from the stealer payload in memory to minimize on-disk artifacts and complicate detection and analysis.

"The primary purpose of WordlistLoader, an intermediate stage in the Amatera infection chain, is to reconstruct a shellcode that serves as the entry point for subsequent stages," Gen Digital said. At the same time, it employs a hardware-breakpoint-based method to bypass Event Tracing for Windows (ETW) and avoid leaving traces of malicious activity.

WordlistLoader gets its name from the fact that the shellcode is stored in encoded form as a sequence of plain English words, with each word representing one byte. Gen said it also identified a variant that replaces the wordlist with an array of 16-byte UUID-encoded chunks.

The shellcode ultimately makes use of a reflective loader responsible for unpacking and loading Amatera. The same reflective loader was observed in late April 2026 in connection with another ClickFix campaign delivering Amatera 4.3.3-alpha1.

The latest version of the stealer comes with updated static obfuscation, hardened syscall invocation through the WoW64 transition, dynamically generated x64 indirect-syscall trampolines invoked through Heaven's Gate, and a redesigned application-bound encryption (ABE) bypass that appears to be directly inspired by Remus Stealer.

SynkLoader Pushed via Microsoft Teams Phishing

The development comes as SynkLoader has been distributed via a Microsoft Teams phishing campaign to siphon a victim's system login credentials by serving a fake lock screen. The activity was detected by Expel in mid-August 2025.

"Someone using a <username>@<company>.onmicrosoft.com email (Microsoft 365's default email domain for companies) reached out to the target using the name IT Service Desk (<Fake Name>)," Expel security researcher Marcus Hutchins said.

"The IT service desk convinced the user to download and install an MSI installer from a Microsoft Azure file storage endpoint (https://filereserve.blob.core.windows[.]net/vgnghuyk/331/331.msi), which gave the file the appearance of having come from Microsoft."

The MSI installer presents itself as a PowerShell Cleaner, which, when run, extracts a ZIP archive and a PowerShell script, the latter of which is automatically run in memory. The script is used to extract the contents of the archive and launch from it a Python-based loader that chooses one of three hard-coded command-and-control (C2) domains and checks in with the server at random, while sleeping for 90 to 120 seconds between requests.

The loader then decrypts and executes the responses from the server. At least seven different modules have been identified -

  • System Profiler, a C# DLL to collect data about the target system.
  • Persistence Module, a native DLL to create a randomly named scheduled task that launches SynkLoader every time the victim logs into the system and daily at 10 a.m.
  • PhishLocker, a DLL to serve a fake Windows lock screen to capture the user's login password
  • TrafficRedirector, a backconnect or reverse proxy that allows the attacker to reach the local network services or route internet traffic through the infected machine
  • Interactive Shell, a remote access trojan (RAT) module to execute PowerShell commands and transmit the result
  • StreamMaster, a Virtual Network Computing (VNC) module to stream the victim's desktop and enable remote mouse and keyboard control
  • Status Checker, a Python script to report back the status of which modules are currently running on the system

It's not clear what the end goals of the operator are, but it's suspected that the toolkit may be part of a ransomware group or an initial access broker.



from The Hacker News https://ift.tt/AwbO8Ld
via IFTTT

MinIO End of Life: How to Stay Patched and Audit-Ready with Docker ELS

MinIO reached end of life in February 2026. Docker Extended Lifecycle Support (ELS) keeps end-of-life software like it patched, compliant, and audit-ready for up to five years, covering versions upstream no longer supports all the way up to entire projects.

On February 13, 2026, the MinIO open-source project was archived upstream. A project with more than a billion Docker pulls stopped shipping releases, bug fixes, and security patches overnight. From that day forward, every environment running MinIO is exposed. New CVEs in MinIO and its Go dependency tree now arrive with no upstream patch behind them, and an audit reads that as unsupported software in production.

And MinIO is only the newest instance of a wider problem. Black Duck’s 2026 Open Source Security and Risk Analysis report found that 93% of commercial codebases carry components with no development activity in at least two years. The same pattern runs across the stack. Node 18, Python 3.8, and older Airflow releases still run in production long after upstream support ended, and frameworks like FedRAMP, DORA, and the Cyber Resilience Act treat unpatched end-of-life software as an audit finding. The migration deadline ends up set by the audit calendar instead of the roadmap.

Docker Hardened Images Extended Lifecycle Support exists to hand that schedule back to you. The model is simple. Request an ELS image, and Docker builds and maintains it for up to five years past upstream end of life. The maintained MinIO image is the newest proof of that model.

MinIO lives on as the newest ELS update

The archive lands on the storage layer, where migrations are measured in petabytes. Moving a production object store to a different system is slow, expensive work, and the CVE exposure keeps growing while that work runs.

Teams running MinIO have three options

  1. Move to a commercial replacement and take on new licensing and lock-in.
  2. Carry the patches yourself, which means staffing sustained Go security engineering for a project that no longer ships fixes.
  3. Keep what you run and put a vendor on the hook for it. 

Doing nothing is not a fourth option. 

Docker identified the archive as a live exposure across its customers’ software supply chains and built the answer into the catalog, where MinIO lives on as a maintained, hardened image. Docker tracks new CVEs across MinIO and its full Go dependency graph, transitive dependencies included at no extra cost, then backports the fixes, rebuilds, and ships. Your object store stays supported and your audits stay clean.

Extended Lifecycle Support for your whole fleet

What ELS does for MinIO, it does for any end-of-life component you need to keep. An EOL finding forces a choice between two bad projects. Rush the migration and risk breaking production, or file the exception and watch the list grow every quarter. ELS removes that deadline. Patches and audit evidence keep flowing on the images already in production while the migration happens on the roadmap’s schedule.

The entitlement is built for how end of life actually arrives, on staggered dates across a fleet. Applied to a repository, it covers every available ELS version there. When one migration completes, you re-point it at the next repository, and the coverage moves with the risk.

Coverage is not limited to a fixed list either. Docker watches the end-of-life calendar and builds ahead of it, and anything you don’t see in the catalog, you can request. The span runs from end-of-life versions of supported software all the way up to entire archived projects. Nginx, Node, and Python ELS images are already there.

ELS is a paid add-on to a Docker Hardened Images subscription, and it runs on the same rails as the rest of DHI:

  • Name it, get it. Tell Docker the end-of-life line your production depends on. Docker builds it hardened and maintains it at the line’s newest patch version.
  • Adopt without a migration. ELS-tagged images appear in the standard DHI catalog alongside LTS tags. Same registry, same workflow, a FROM-line change.
  • Stay patched for years. Critical and high-severity CVEs are patched on a 14-day SLA, for up to five years past end of life.
  • Evidence included. Every ELS image holds the same standard as the rest of the catalog. Built from source and signed, with SBOMs, VEX statements, and SLSA Build Level 3 provenance maintained for the life of the image.

Those attestations are the difference between extended support and an extended liability. A legacy app with a giant SBOM and no exploitability data just lights up your scanners. ELS ships the evidence with the image, so auditors see signed proof of what’s patched and what’s not exploitable.

If there’s a version in your fleet you can’t migrate off and can’t leave unpatched, that’s an ELS conversation. Browse the DHI catalog to see what’s already covered, and talk to us about the versions you need to keep alive. 



from Docker https://ift.tt/ev8N1Xp
via IFTTT

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical business operations.

According to new research published by Akamai, the top 5% of enterprise power users interact with AI models at 12 times the rate of the bottom 50% of the workforce. The findings, published in Akamai’s State of the Internet: Enterprise AI Usage Risk Report 2026, are based on real-world usage and telemetry data as well as research and threat analysis.

These AI super-adopters are creating a disproportionate security risk by expanding the use of shadow AI, increasing opportunities for data leakage, and introducing autonomous AI agents that operate within the enterprise but outside its established guardrails.

“Small groups of AI power users are casting outsized shadows across enterprise threat surfaces that are already riddled with dips and blind spots,” says Or Eshed, Vice President Enterprise Security Product & Engineering at Akamai. “While security teams are focused on trying to govern all employees’ access to big frontier LLMs, the cumulative long-tail shadow of dozens of smaller AI tools used by power users arguably poses a more significant security risk.”

According to Akamai data, the average employee conversation lasts about five prompts, while the top 5% of power users routinely engage in conversations of 18 prompts or more — evidence that AI models are becoming embedded collaborators in essential business operations.

"AI is no longer just a productivity booster; it is a virtual colleague with keycard access to the company vault,” says Eshed. “Security teams need to identify which employees depend most on AI to know where risk is concentrated."

Enterprise Control vs. Consumer Leakage

Nearly half of all enterprise AI conversations (47.11%) occur through personal identities rather than corporate-managed accounts, according to Akamai’s report.

The situation creates a stark contrast between housebroken AI and feral AI.

AI platforms with dedicated governance controls successfully enforce corporate identity boundaries, while personal-access accounts create significant visibility gaps for IT, security, and compliance teams.

  • Gemini Enterprise (98.15%) and Microsoft Copilot M365 (90.55%) keep the vast majority of interactions inside corporate identity systems.
  • DeepSeek (99.8%), Microsoft Copilot Standard (63.92%), ChatGPT (61.36%), and Claude (61.09%) are overwhelmingly dominated by personal identity logins.

Governance becomes even more muddled when employees use corporate email addresses to register personal AI subscriptions.

"One of the most surprising findings was that 14.4% of enterprise AI conversations occurred via corporate email addresses linked to personal 'freemium' AI subscriptions rather than enterprise-managed licenses," says Eshed. "This means that even when accessed through a corporate identity, the sensitive data employees inject into prompts may be used for public model training."

But even organizations that successfully manage enterprise AI accounts often have little visibility into the growing ecosystem of niche AI tools employees install outside approved channels, the report found.

Long-Tail Blindness

While security teams focus on governing ChatGPT, Claude, Copilot, and Gemini, employees are quietly adopting dozens of niche AI tools, AI-enabled SaaS applications, and personal subscriptions without IT oversight.

“As with mobile devices, employees increasingly 'bring their own AI tools — or BYOAI' to access AI through personal accounts,” says Eshed. “That creates additional visibility gaps around how business data is stored, retained, and processed.”

Browser and IDE extensions represent another rapidly expanding blind spot. Akamai found that 17.7% of employees at midsize enterprises use at least one AI extension, compared with 9.53% at larger organizations. Nearly 75% request high or critical permissions.

Crucially, 16.31% of AI extensions contain known CVE vulnerabilities, compared to 10.80% of browser extensions overall.

“These tools are creating broad, unmanaged pathways directly into active user sessions and sensitive corporate data,” warns Eshed ”This Shadow AI landscape is not just a data privacy issue; it is the infrastructure for the next generation of automated cyberattacks.”

The CISO Imperative

For security teams, this shifting landscape requires a fundamental mindset shift.

The AI problem facing CISOs is no longer whether employees are using AI. They are. The new mission is to identify where AI is operating, which teams depend on it most, and whether those systems remain inside enterprise guardrails.

The challenge is to answer those questions before adversaries do.

Weaponizing the AI Surface

This expanding AI surface is also creating new attack vectors that bypass traditional controls. The Akamai report highlights a few:

  • Vibe Hacking: Attackers subtly modify local instruction files (such as AI_CONFIG.md) to covertly manipulate AI coding assistants into generating vulnerable code or executing unauthorized actions.
  • CursorJacking: Rogue extensions are weaponized to silently harvest API keys, session tokens, and proprietary source code directly from local databases.
  • CometJacking: Adversaries use indirect prompt injection embedded in malicious web pages to trick AI agents into exfiltrating local user files, shifting the target from the human endpoint to the AI collaborator.

Akamai’s CISO Checklist to Secure Enterprise AI:

  • Establish Continuous Visibility: Discover all AI applications, browser/IDE extensions, and agents across the network; inspect prompts, uploads, and responses in real time.
  • Eliminate Shadow AI: Enforce corporate Single Sign-On (SSO), block unmanaged personal logins, and audit corporate email addresses tied to "freemium" subscriptions.
  • Deploy Contextual AI DLP: Implement prompt-level inspection to catch unstructured data leakage—such as code snippets or internal text—that legacy pattern-matching tools miss.
  • Audit Extensions and Permissions: Maintain a rigorous inventory of browser and IDE extensions, enforce strict permission boundaries, and screen add-ons for known CVEs.
  • Govern AI Agents as Identities: Treat autonomous AI agents and browsers as privileged digital identities, applying least-privilege access, strict scope limits, and real-time monitoring.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.



from The Hacker News https://ift.tt/vmE4CAa
via IFTTT

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.

The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open directory hosted at "139.180.197[.]150," which was observed communicating with one of the compromised machines.

"The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale," Cisco Talos said in a two-part report published last week. The actor employed a mixture of open-source offensive frameworks, including Metasploit, ysoserial, PentestGPT, DeepAudit, and multiple privilege escalation exploits to automate intrusion operations and establish persistence."

UAT-10147 has been described as a threat actor that conducts search engine optimization (SEO) fraud and data theft, while integrating artificial intelligence (AI)-powered tools at various phases of the attack cycle to facilitate exploitation, reconnaissance, payload generation, validation, and persistence.

Specifically, this involves using AI to refine exploits, troubleshoot logic, automate post-exploitation workflows, validate exploits, and generate operational documentation, indicating an attempt to implement offensive tradecraft at scale.

An analysis of the exposed directory has identified a text file containing a target list with approximately 170,000 URLs, with the attacker splitting it into 17 smaller files containing about 10,000 URLs each to more efficiently parse the set. The top five destinations based on the target list consist of the U.S., India, the U.K., Germany, and the Netherlands.

Attack chains involve exploiting known flaws to achieve remote code execution (RCE) on a website or a vulnerable IIS server, and then run an automated script to install and deploy malware for SEO fraud or data stealing. Select instances entail the deployment of a web shell, which then paves the way for BadIIS and additional backdoors for persistent access.

Some of the other steps undertaken by UAT-10147 is as follows -

  • Using a batch script that employs certutil to download a privilege escalation tool ("EfsPotato"), a secondary batch script, and Quasar RAT from a remote server ("adminapi.tippusoni[.]in")
  • Using EfsPotato to gain elevated system privileges, configure Microsoft Defender exclusions
  • Deleting initial payloads to cover its tracks and thwart forensic analysis
  • Deploying follow-on implants like Gh0stCringe and a previously unreported cross-platform implant dubbed SPECTRE
  • Using the secondary batch script to silently execute Quasar RAT and establish persistence using a deceptive scheduled task named "Google Chrome Start"
  • Abusing the elevated privileges to download a third batch script, which then installs BadIIS

Interestingly, the core BadIIS malware is the same specific variant that's known to operate under a malware-as-a-service (MaaS) model and is used by multiple Chinese-speaking cybercrime groups.

The Linux attacks, like in the case, leverage various known vulnerabilities to obtain an initial foothold, followed by abusing various known Local Privilege Escalation (LPE) exploits to escalate to root, including CVE-2022-0995, CVE-2021-3156, CVE-2015-5287, CVE-2015-3246, CVE-2010-3904, and CVE-2022-0847.

Once root-level access is unlocked, the threat actor has been observed deploying multiple backdoors like Noodle RAT (a variant of Gh0st RAT and Rekoobe), SPECTRE, and Meterpreter to enable outbound connections to remote command-and-control (C2) infrastructure. Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).

"By routing exfiltrated data to a legitimate cloud-based configuration management service, the attackers effectively blend their traffic with normal administrative operations," Talos researcher Joey Chen said. "This infrastructure choice acts as an asynchronous exfiltration sink, allowing the adversaries to poll their own Nacos instance to verify successful exploitation across victims without the operational overhead or detection risk of establishing a persistent reverse shell or maintaining direct inbound connections."

A notable aspect of UAT-10147's tradecraft concerns an AI-driven framework called DeepAudit for vulnerability scanning. Talos said it found no evidence of the threat actor exploiting vulnerabilities discovered by the tool in victim environments, although it was left accessible on the management server.

This has raised the possibility that the attackers are planning on using DeepAudit to identify vulnerabilities within target environments. Conversely, it's also likely that it could be used to improve their own defensive posture by proactively auditing their own infrastructure and tooling to prevent potential exposure and compromise by other threat actors.

UAT-10147 has also been found to install PentestGPT, an open-source autonomous pentesting framework, on their C2 server to scan web servers and execute relevant proof-of-concept exploits. In one case, the threat actor is said to have successfully exploited a website and collected information about the victim host using Linux commands.

Another AI-oriented tool put to use by the threat actor is an ASP.NET ViewState deserialization remote code execution guide, which delves into the following aspects -

  • Making use of the badsecrets library comprising publicly known or leaked ASP.NET MachineKey configurations, checks the key's validity, employs ysoserial.net to build malicious deserialization payloads that bypass View State protection using the pre-exposed MachineKey, and achieves code execution
  • Conducting systematic reconnaissance following code execution via PowerShell to collect system information, privilege tokens, web directory listings, IIS site configurations, network interface data, and running processes, and exfiltrate them to a remote webhook
  • Establishing persistent interactive access using SPECTRE, or alternatively, writing an ASHX web shell to the IIS webroot and a PowerShell TCP reverse shell
  • Elevating privileges from IIS AppPool identity to SYSTEM using the Potato family of tools or SPECTRE through a built-in routine named "spectre_potato()"

Four other AI-generated tools used by UAT-10147 are Python scripts: One which acts as a post-exploitation diagnostic utility to troubleshoot, among other things, web shell write failures, while the second uses the ViewState deserialization primitive to download and launch the SPECTRE implant.

The third script deploys the ASHX web shell onto the compromised IIS server via the same deserialization mechanism. The final script is responsible for blending exfiltration traffic with legitimate software-as-a-service (SaaS) traffic over HTTPS and transmitting webfoot enumeration, IIS site inventory, and privilege assessment details to a webhook endpoint.

SPECTRE, per Talos, is a cross-platform backdoor written in C that features obfuscation and anti-analysis techniques to fly under the radar. It communicates with a C2 server using HTTPS and supports as many as 45 commands that grant the operator extensive control over the infected endpoint. The first use of the implant by the threat actor dates back to April 2026.

"The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality," Talos said.

The Windows version is equipped to perform file operations, record keystrokes, take screenshots, download/upload files, execute shell commands, get running processes, terminate a specific process, get system information, set beacon sleep interval, modify file timestamps, inject shellcode, use process hollowing and Early Bird APC injection, kill EDR processes using the bring your own vulnerable driver (BYOVD) technique, delete itself from the host.

The BYOVD attack utilizes two well-known vulnerable drivers MSI's "RTCore64.sys" (CVE-2019-16098) and Dell's "DBUtil_2_3.sys" (CVE-2021-21551) to obtain elevated privileges and terminate security-related processes.

"By performing targeted kernel writes, the SPECTRE safely unlinks each registered EDR callback from its doubly-linked list," Talos explained. "Consequently, kernel-callback-dependent security products such as CrowdStrike Falcon, SentinelOne, Microsoft Defender, and other well-known EDR vendors are rendered completely blind to new process creations, thread creations, and image load events for the remainder of the session, successfully neutralizing EDR visibility on the target machine."

SPECTRE's Linux variant follows more or less the same pattern, running a series of anti-sandbox checks before setting up a C2 connection. Both versions employ a weighted scoring mechanism that causes the program to self-terminate if the score exceeds 50 points. The evaluation is based on process name blocklists, RAM capacity, CPU core count, disk space, sleep acceleration detection, and common sandbox host names and usernames.

The Linux version's instruction set, in contrast, only supports 29 commands that encompass file system manipulation, system and process reconnaissance, agent management, and unrestricted shell execution. Its most potent capability is an integrated kernel-level rootkit dubbed Specter that's deployed as a kernel module.

It's suspected that the rootkit was developed using a combination of AI-assisted development and human expertise, given the presence of descriptive source code comments, uniform decorative separators to explain each function, and the presence of multiple methods to achieve the same purpose – something that AI models are known to generate when prompted to be thorough, as opposed to just implementing the most effective method.

"This architecture grants the threat actor persistent, kernel-level control of the compromised host that survives both reboots and most user-level security controls," Talos said. "The Spectre backdoor loads the Linux Kernel rootkit, Specter, to prevent detection from security products."



from The Hacker News https://ift.tt/liu93p4
via IFTTT

Sunday, August 23, 2026

NVIDIA's Pivot from Chipmaker to Financier

SUMMARY: Brian, Brandon, and Aaron discuss news about Nvidia’s reported $105B backing of OpenAI’s Ohio data center and what it implies for GPUs as an “asset class” and enterprise AI. Brian argues Jensen Huang is shifting Nvidia’s narrative from needing the newest chips immediately to portraying GPUs as long-lived, cash-flowing assets that can be financed like bonds, pushing risk onto banks and private equity. Brandon agrees scarcity has extended older GPU usefulness but warns the market could be flooded with newer, cheaper, more efficient hardware, leaving debt tied to obsolete equipment. Aaron likens GPUs to airplanes, expensive assets requiring constant utilization, while noting new AI builds demand entirely new data centers for power and cooling. The group questions widespread lack of profitability, compares the financing trend to past bubbles, and debates the optimistic case that breakthroughs could ultimately justify the investment.

SHOW: 1056

SHOW TRANSCRIPT: The Enterprise AI Show #1056 Transcript

SHOW VIDEO: https://youtu.be/vTLTdIZueJM

SHOW SPONSORS:

Show topic: Nvidia's Pivot from Chipmaker to Financier

Nvidia just backed $105B for OpenAI's Ohio data center and helped mobilize $500B+ in Wall Street financing (Apollo, Blackstone, BlackRock, Goldman, KKR) to fund GPU purchases, while AMD, Google, and Cerebras chip away at its tech lead. The moat is moving from silicon to balance sheet.

Core question: Is a GPU actually securitizable like real estate or aircraft, or is this circular financing dressed up as infrastructure?

  • The bull case: GPUs as productive, cash-flow-generating assets (compute-as-a-service) → financeable like data centers or planes, unlocking capital hyperscalers alone couldn't raise.
  • The bear case: Depreciation risk; GPUs age fast, unlike buildings. What's the residual value of an H100-class chip in 2030? Securitizing a depreciating, obsolescence-prone asset is a very different bet than securitizing land.
  • Circularity concern: Nvidia financing the customers who buy Nvidia chips, who generate the revenue that justifies Nvidia's valuation, echoes vendor financing bubbles (Cisco/telecom, 2000).
  • Precedent: Compare to aircraft leasing/securitization models: what made those work (long asset life, resale markets, standardized valuation), and whether GPUs have any of that yet.
  • Who bears the risk if utilization or model economics don't pan out: Nvidia, the banks, or the credit markets buying the paper?

FEEDBACK?



from The Cloudcast (.NET) https://ift.tt/XYKE8Mc
via IFTTT

Saturday, August 22, 2026

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country.

As part of the settlement, the social media platform will pay $300 million immediately, and an additional $100 million "upon entry of an order vacating a prior consent decree entered against TikTok’s predecessor, Musical.ly," the DoJ said in a press release.

A complaint filed back in August 2024 alongside the Federal Trade Commission (FTC) accused the company of "massive-scale invasions of children's privacy" by knowingly allowing children under 13 to create TikTok accounts and unlawfully collecting data from those who used it in "Kids Mode."

It further alleged TikTok and its parent company ByteDance failed to "comply with parents' requests to delete their children's accounts and information."

At the time, the company disputed the arguments, stating many of them related to "past events and practices" that were either "factually inaccurate or have been addressed."

The DoJ characterized the settlement as "one of the largest recoveries ever" obtained in connection with U.S. federal child privacy law, also referred to as the Children's Online Privacy Protection Act (COPPA).

It also noted that the tech company has since implemented extensive measures to improve safeguards for younger users, strengthen age-related controls, and improve parental oversight.

"This settlement is a major victory for American children and parents," said Associate Attorney General Stanley E. Woodward Jr.

"The Department's priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations. This resolution secures a substantial recovery while reinforcing the protections that families expect and deserve."

This is not the first time TikTok has landed in regulatory crosshairs over child data privacy. In September 2023, TikTok was levied a €345 million fine for violating the European Union's General Data Protection Regulation (GDPR) in relation to its processing of children’s personal data.

Earlier this year, a U.S. joint venture allowed the app to continue operating in the country without a ban in accordance with a divest-or-ban law upheld by the Supreme Court.



from The Hacker News https://ift.tt/ntqjcCP
via IFTTT

Friday, August 21, 2026

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

While supply chain threats have been quietly compounding over the past decade, the last 12–18 months have triggered a drastic shift in the scale and velocity of these attacks. Rather than just hunting for bugs in finished software, attackers are targeting the everyday tools and code developers rely on.

Unit 42 research shows this happening at every step of the building process. We've observed attackers spending years pretending to be helpful contributors just to hide backdoors in core software, as seen in the XZ Utils vulnerability (CVE-2024-3094). We've seen attackers hijack accounts to drop malware into popular libraries, like in the Axios supply chain attack. And we've seen them misuse setup scripts to automatically steal credentials using the Shai-Hulud npm worm.

Simply put, attackers are more focused on poisoning the digital factory that builds an application as opposed to the application itself. By targeting continuous integration/continuous delivery (CI/CD) pipelines and developer environments, they hijack software at the source before it ever hits production.

Threat Analysis: ChainDrop npm Worm

Consider the recent ChainDrop npm worm, which infected over 400 packages including massively popular libraries like keyv and cacheable-request using a highly evasive three-step chain:

  • The hook: Attackers modified package manifests with a malicious preinstall script that downloaded the legitimate Bun runtime to silently launch a 727 KB obfuscated payload in the background.
  • The theft: Rather than just scraping disk files, a hidden Python script directly read live process memory from GitHub Actions runners to steal temporary OpenID Connect (OIDC) tokens and secrets, alongside a massive sweep for local developer credentials.
  • The payload: The worm used those stolen npm and GitHub tokens to self-propagate, silently infecting and republishing additional packages while leaving their legitimate functionality perfectly intact so that developers don't notice.

ChainDrop secured long-term persistence by establishing cross-linked hooks directly inside developer tools like VS Code and Claude Code, while managing its entire command-and-control (C2) infrastructure dynamically through Ethereum blockchain transactions.

The malware triggers silently the second someone runs npm install by misusing npm's setup scripts (preinstall hooks). From there, it hits three distinct targets:

  1. Cloud secret harvesting: It searches build server memory to scrape unencrypted credentials and platform access tokens
  2. Local endpoint backdooring: It modifies local developer tool configs (like VS Code's tasks.json) so the attacker retains access even after the build finishes
  3. Automated propagation: It uses stolen tokens to automatically create rogue code repositories, turning compromised accounts into new launchpads to spread the worm

Package Visibility Across the SDLC

The main takeaway is that open-source and third-party packages touch every single phase of the software development lifecycle (SDLC). Modern applications aren't built from scratch, they are assembled. Because open-source code makes up 80-90% of modern codebases, the attack surface expands to developer laptops, CI/CD pipelines and cloud infrastructure.

Ten years ago, a project might have relied on a few dozen external libraries. Today, even a simple application pulls in thousands of indirect dependencies. Generating a software bill of materials (SBOM) at the end of a build is great for compliance, but an SBOM alone simply doesn't cut it anymore. An inventory list created at the finish line won't catch malware that was executed during the build process. To truly secure an environment, every single place a third-party package touches needs to be mapped.

The Endpoint Attack Surface

Developers today navigate an endless matrix of language-specific package managers. They routinely execute installations across a massive array of ecosystems — npm install, pip install, cargo build, go get, mvn install and many more — while simultaneously juggling 10–30 integrated development environment (IDE) extensions. Why are these attacks so effective? Because developer tools lack basic guardrails.

Think about your web browser. When you visit a website, the browser locks it in a safe container (a sandbox) so it can’t touch your computer. But setup scripts and code editor extensions don't have those walls. The second they run, they get the same permissions you have, giving malware total freedom to read your files, steal keys and run commands on your machine.

This massive, un-isolated weakness is exactly why registries and marketplaces have become prime targets, as seen in the recent GlassWorm campaign. Whether it’s a malicious script running silently during a routine dependency pull or a compromised IDE extension updating automatically in the background, an attacker instantly gains unrestricted execution rights on a developer's machine and access to valuable cloud knowledge.

CI/CD Pipelines

Build pipelines rely on numerous outside tools, plugins and helper scripts to assemble code. Attackers often target these build environments because they are packed with temporary passwords and cloud access keys. The compromise of Trivy highlights the potential attack surface of pipeline security tools. This means that only scanning app code is insufficient. A pipeline bill of materials (PBOM) is also needed, which is an inventory list of every single tool running inside your build system.

The Cloud Runtime

Finally, we can't forget the cloud. A standard application SBOM typically only lists the code libraries developers explicitly add to their software. However, cloud environments rely on containers, which require a broader approach. A container SBOM provides the full picture by tracking both the application code and the hidden operating system tools built into the container image such as basic security utilities and system libraries like OpenSSL. Standard application scans completely overlook these deeper system layers.

The danger of this weakness was starkly illustrated by the wave of OpenSSL zero-day vulnerabilities disclosed in early 2026. Because these critical flaws sit deep within the foundational cryptographic infrastructure of the container's operating system, the application-layer code will look perfectly clean and pass every repository scan, while the underlying cloud workload remains completely exposed to a remote takeover.

Given this extensive attack surface, relying on static, point-in-time gateway scans is an insufficient strategy. True supply chain resilience requires continuous visibility between local developer endpoints, automated pipelines and cloud runtime workloads. Correlating telemetry across all three domains is the only way to intercept malicious behaviors and halt a compromise before it propagates downstream.

Tips for Hardening Pipelines

Defending against automated supply chain attacks requires shifting from reactive code scanning to strict execution control across the entire build path. Because tools, IDE extensions and package managers run with high privileges, organizations must lock down the developer environment by disabling lifecycle install scripts (--ignore-scripts), enforcing package cooldown periods, restricting CI/CD egress traffic, using ephemeral CI/CD servers and pinning dependencies down to exact commit SHAs.

Beyond environment hardening, neutralizing autonomous malware like Shai-Hulud means eliminating the long-lived credentials that fuel them. By transitioning to brief OIDC authentication and enforcing end-to-end cryptographic provenance, teams can establish an unbroken chain of trust. This trust extends from signed commits at the developer endpoint to signed artifacts and SBOMs in production, helping stop self-propagating worms in their tracks.



from Unit 42 https://ift.tt/nxMz0QK
via IFTTT

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0.

"When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's enterprise cybersecurity business, said in a report published Thursday. "No install hook function call is needed; a single import anywhere in the dependency graph, even a transitive one, is enough to execute the payload."

The list of identified packages is below -

  • streak-metrics-math@1.0.0,1.0.1
  • kit-map-vim@1.0.0
  • streak-map-cache@1.0.0
  • streak-map-kit@1.0.0
  • map-streak-kit@1.0.0
  • streak-cache-map@1.0.0
  • streak-calc-metrics@1.0.0
  • streak-calc-math@1.0.0
  • streak-math-abz@1.0.0
  • streak-metricsaz@1.0.0
  • streak-math-metrics@1.0.0
  • streak-metricazbd@1.0.0
  • streak-metricsazb@1.0.0
  • streak-kit-map@1.0.0

What's notable about these packages is that they are functional and offer the promised functionality. But beneath that garb of date utilities is code designed to drop a Linux backdoor by framing it as a native math accelerator. The name of the file varies across the packages: math-core.bin, math-calc.bin, calc-math.dat, calc-cache.bin, calc.bin, calc-mapping.bin.

It's located either directly within the "dist/" or under "dist/internal/,", but what it contains is the same: the RedShell Linux beacon for RedC2 4.0 that communicates with a remote Windows or Linux server to facilitate post-exploitation activities on the compromised host.

"Delivery is handled by the package entry file, dist/index.mjs, which acts as a trojan loader," security researcher Aliakbar Zahravi said. "It re-exports the date helpers and launches the bundled implant as soon as the module loads, with no install hook and no exported function required."

RedC2 4.0, marketed on cybercrime forums as a cross-platform toolkit for Windows, macOS, and Linux, offers surveillance, credential theft, payload loading, and mass-operation capabilities. The version was advertised by a threat actor named "MarlboroMan" on Hack Forums in early June 2026, describing it as a command-and-control (C2 or C&C) framework "built for evasion."

Version 3.0 of RedC2 was sold earlier this January, while version 2.0 was released in August 2025, indicating the framework has been under active development for at least a year. The RedShell Linux beacon was introduced in version 4.0.

The C2 framework is also feature-rich, supporting terminal access, file transfer, staged payload delivery, data collection, multi-beacon operation, network visualization, host-to-host tunneling, and in-memory execution of Beacon Object Files (BOFs), .NET assemblies, and shellcode.

RedShell Linux execution flow

The Linux variant of the beacon, once deployed, provides an interactive shell through "/bin/sh" and exposes Linux-specific commands to enable system discovery, file operations, data collection (e.g., SSH keys and browser credentials), execution, persistence, in-memory ELF execution, SOCKS5 proxying, and network pivoting.

It also establishes communication with a C2 server and registers the infected system by gathering basic system information and transmitting it in the form of a "check-in message," after which it enters a command-processing loop to process incoming instructions from the operator, execute them via "/bin/sh," and send the results back.

The Windows and macOS counterparts cover a similar ground, allowing file operations, host and network reconnaissance, user enumeration, and data harvesting. The Windows beacon also incorporates User Account Control (UAC) bypass, antivirus and endpoint detection, antivirus tampering, in-memory execution, and lateral movement that the macOS version lacks.

On a clearnet website branded Red Offsec, the threat actor claims, "Red C2 is a multi-language, multi-OS command and control framework designed for Windows, Linux, and macOS. The entire framework was built with evasion as a core principle, utilizing the latest developments and techniques in the offensive security field." It's available for purchase for $99.99.

Red Offsec's Terms of Service expressly prohibit its customers from using the tool for "unauthorized computer access," "hacking without explicit permission," and "abuse, exploitation, or damage of systems you do not own or are not authorized to test."

"Red Offsec provides tools intended for red team professionals and users who understand external offensive security tooling within legal and ethical boundaries," the terms read.

RedC2 extends its control layer with a command-line extension referred to as RedC2 EXT as well as a large language model (LLM)-driven component called Red Agent, the latter of which lets operators orchestrate complex post-exploitation tasks, such as network reconnaissance and credential dumping, using natural language commands.

"RedC2 ships with an AI assistant called Red Agent, an LLM-backed command execution layer that turns natural-language intent into framework beacon commands," Zahravi said. Red Offsec has characterized it as an "AI-powered command execution system specialized for penetration testing."

The findings underscore how previously undocumented AI-integrated C2 frameworks are being distributed via malicious npm packages, while simultaneously lowering the barrier to entry.

"By interacting with a model tuned for red-team operations, an operator inputs natural-language prompts, and the framework translates them into actionable command sequences," TrendAI said. "This abstraction lets operators of varying skill levels execute complex, multi-stage intrusions efficiently."

The development comes close on the heels of a coordinated supply chain attack affecting three legitimate Rust crates (arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9), compromising them with a malicious proc-macro1 dependency that executed cross-platform malware automatically during Cargo builds.

The malware is designed to profile the infected device, catalog Chromium-based browsers, establish persistence, and beacon to attacker-controlled infrastructure for tasking and downloading additional payloads.

It's suspected that the maintainer's publishing credentials were compromised to push the poisoned versions to the package repository. Evidence points to infrastructure overlaps with prior software supply chain attacks targeting Mastra and Axios, both linked to North Korean threat actors.



from The Hacker News https://ift.tt/feC78Rz
via IFTTT

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.

Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.

"The malware spread through the built-in updaters of Android-based automotive head unit firmware," security researcher Dmitry Kalinin said. "This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device."

The activity has been attributed with high confidence to the MoYu Group, which was outed by the HUMAN Satori Threat Intelligence and Research team last year as part of a broader ad fraud and residential proxy scheme dubbed BADBOX. In July 2025, Google filed a lawsuit against 25 unnamed individuals or entities in China for allegedly operating the BADBOX botnet and its infrastructure.

A car head unit is a central hub that combines multimedia functions with partial control over certain vehicle functions. It can be factory-installed or fitted on older vehicles as part of an aftermarket upgrade. Because Android-powered card head units have become popular across both aftermarket retrofits and factory-built vehicles, a huge chunk of the standard apps, and by extension, malware, can also run on them.

This, in turn, makes them an emerging target for bad actors, as they feature a SIM card slot that enables internet access for navigation and software updates.

"The delivery methods for such malware are becoming highly varied – ranging from pre-installed backdoors to compromised IPTV applications," Kalinin said in a statement shared with The Hacker News. "In this researched case, we observed an even more sophisticated delivery method exploiting the legitimate software update functionality of a system app."

Specifically, this involves distributing the malware via the update mechanisms built into the firmware of multiple models of Android-based head units powered by DoFun. Following responsible disclosure, the issue driving the software distribution abuse has been addressed.

The starting point is a legitimate system app called TWCore ("com.tw.core"), which is designed to collect analytics and update the head unit's software in the form of APK files by making use of a MQTT message broker hosted on the "cardoor[.]cn" subdomain. The APK file is downloaded to the "<TWCore external cache dir>/push/apk/" path for installation.

The threat actors behind the campaign are said to have weaponized this update channel to deliver previously unknown malware directly to the head units using a dropper dubbed JarService, while taking steps to evade detection. The dropper is responsible for launching a loader that performs the following actions -

  • Sends implant information to one of the attackers servers via an HTTP POST request
  • Server responds with a link for downloading the next-stage payload ("144.217.243[.]201/vr34der34/dex3.68.png")

The payload name includes a reference to a version number ("dex3.68"), allowing Kaspersky to retrieve seven distinct variants dating back to "3.57" simply by trying other version numbers.

The attack chain ends with the deployment of the malware as a regular user application. However, it lacks a user interface and covertly operates in the background. It's configured to send a POST request to the command-and-control (C2) endpoint ("/cpc/api/task") every 90 minutes by default, along with information about the infected device and its configuration version.

"If the configuration is outdated, the C2 server returns an updated configuration containing new C2 addresses and new paths for sending HTTP requests," Kaspersky said. "If the configuration version doesn't need updating, the C2 server instead returns integer command identifiers, which the attackers refer to as productId."

"The Trojan maps each identifier to command information, which it stores as a serialized JSON object using the SharedPreferences API."

The malware supports nine commands capable of displaying unwanted advertisements, executing ad fraud, and downloading additional malicious modules. It also allows attackers to receive extensive device information, including display resolution, device model, connected Wi-Fi network identifier, and MAC address. The list of commands is below -

  • return, to return a value from SharedPreferences
  • copy, to set clipboard contents
  • http, to make a POST/GET HTTP request to a specified resource
  • web, to open a link in WebView and execute arbitrary JavaScript code within it
  • loadlib (not fully implemented)
  • loadlib2, to download and execute arbitrary code from an URL
  • loadlib3 (not fully implemented)
  • deeplink, to open a URL in the browser
  • traceroute, to check resource availability via an ICMP ping

The threat actors have been found to leverage "loadlib2" and "http" commands to download "zhima," a reverse proxy module documented by Nokia Deepfield Emergency Response Team last month and selectively delivered via IPTV apps installed in cheap Android TV boxes.

"Despite the efforts of cybersecurity experts and law enforcement agencies to shut down the BADBOX botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide," Kalinin said.

"This malware has become the very first malicious application specifically targeting car head units through an infection chain explicitly tailored for these vehicle systems. This serves as a warning that modern automotive platforms urgently require robust protection against malware."



from The Hacker News https://ift.tt/UM7QBGE
via IFTTT

Thursday, August 20, 2026

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page.

The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the transfer completed without a confirmation step and with no visible warning in its proof-of-concept demonstration.

There is no patch, no CVE identifier, and no user-facing workaround, and the company said it could still reproduce the attack against Grok as of August 19, 2026. The writeup does not report any exploitation in the wild, and does not name the Grok model version or build tested.

The technique ships the attacker's instructions as ciphertext rather than readable text, with the page carrying an encrypted JSON object, the key material, and an instruction to decrypt it, which Grok executes in its own Python code execution runtime.

Recovering the plaintext requires running PBKDF2 and AES-256-GCM, which a content classifier does not do at inspection time. Hence, the instructions reach the model's context as the output of code the model has just executed rather than as fetched web content.

"Strong encryption cannot be read by a content classifier and cannot be shortcut in-weights, so it forces recovery through the runtime the attack depends on. Whether a weaker encoding would also bypass a given target's specific filters is an empirical question," security researcher Rony Utevsky said.

The decrypted instructions then direct the agent to resolve its private session context and embed it in a URL it is told to open to "fetch additional context."

One element of the chain has the model construct an additional "decryption key" that is not key material at all, and whose value is a template string interpolating the name, location, tier, and chat history. Grok then invokes its own navigation tool to load that URL, carrying the data in the request's query parameters.

"The framework built by xAI lets instructions and data parsed from an untrusted external page drive the invocation of a privileged, internet-connected tool; it allows private session metadata and conversation history to be resolved into the inputs of that outbound tool; and it enforces no effective egress boundary or consent gate on this path, and no provenance separation we could observe. The laundered, attacker-controlled instructions reach a privileged egress action unimpeded," Adversa said.

The company said it first reported the issue to xAI on June 3, 2026, and to xAI's HackerOne bug bounty program on the same date; that xAI acknowledged the report without providing specifics or a mitigation timeline, and that further contact attempts on August 4 and August 10 drew no response.

Adversa is the only source for the Grok finding, said it is withholding the operational payloads to avoid exploitation, and xAI has not published a statement or advisory on the research as of August 20, 2026.

A second demonstration in the same writeup targets Google's Gemini in Deep Thinking mode, where a single prompt makes the model decrypt a payload that resolves into a fabricated Python traceback carrying a bogus safety-policy deactivation callback and a first-person reasoning prefix that pre-commits it to the restricted output.

Adversa said the vector produced restricted content and reproduced Gemini's system instructions, which it identified as Gemini 3 Flash (Web) on the paid tier. Google was not notified, Adversa said, because jailbreaks are out of scope for its disclosure program, and the success rate against the company's agents had "dropped significantly by August," with the cause left unattributed between filter updates and model version changes.

The Gemini demonstration was published in substantially the same form five months earlier. Utevsky described the same chain on his personal research site on March 11, 2026, under the name Cryptographic Payload Injection, reporting five out of five independent reproductions and cross-model results in which OpenAI's GPT-5 failed to parse the decryption instructions and Anthropic's Claude Sonnet 4.5 flagged the payload as prompt injection after decrypting it.

"You do not need to fix this at the model layer. Every control that bounds this attack sits in the harness around the agent: what identity it runs as, what it can reach, what it can write, and what you can replay afterward," Adversa said.

Teams running agents are advised to perform the following steps -

  • Quarantine untrusted content in a context with no tools and no credentials, returning only structured data to the privileged context.
  • Gate irreversible and outbound actions, confirming new network destinations, pushes, merges, publishes, and writes outside the workspace with fully resolved arguments rather than templates, and applying a hard deny where no human is present.
  • Capture per-session tool traces with resolved arguments, without which there is neither detection nor forensics.
  • Alert on the sequence rather than on any single payload, treating an opaque blob paired with instructions to decrypt it as a review signal and never as a blocking filter.
  • Make context provenance a procurement requirement and ask vendors whether tool output is separated from the instruction channel.

The development comes as Alexander Panfilov and seven co-authors reported in a preprint published on August 10, 2026, that the encrypted chain-of-thought blocks Anthropic, OpenAI, and Google return to application programming interface (API) clients are interchangeable across sessions, users, and models within a provider's ecosystem, and that attackers can use the flaw to "execute invisible prompt injections, embedding malicious payloads entirely within encrypted blocks to poison public agentic rollouts."

Separately, researchers at UC Berkeley, the Ethereum Foundation, and NYU Shanghai found in work presented at USENIX Security 2026 that a two-turn attack in which the model decodes a substitution cipher and is then asked to act on the decoded text succeeded against Grok 3 on all 12 of the malicious intents tested, while the same cipher used without that second activation turn failed on all 12.

xAI's handling of prompt injection reports against Grok has drawn criticism before. In December 2024, Johann Rehberger demonstrated an end-to-end data exfiltration chain against Grok in the X iOS app, in which an indirect prompt injection caused the assistant to send previous chat information to a third-party server, and said all the issues he reported were closed as "Informational."

"xAI claims there is no practical impact with the reported vulnerability. I'm not sure how leaking user's chat messages and IP address is not a vulnerability, the question is more about severity," Rehberger said.



from The Hacker News https://ift.tt/y45TWMz
via IFTTT