OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach. The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The AI exposed hundreds of bugs in Mozilla’s web browser, raising hopes around defensive advantage, alongside fears of dual-use risk. A previously undocumented .NET trojan and its companion Pheno plugin allow attackers to capture mobile authentication codes from Windows systems without compromising the phone. The agentic tool, codenamed MDASH, will open to enterprise customers in private preview in June.
The threat actor known as HoneyMyte (aka Mustang Panda ) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER , that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design. Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. "FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in a GitHub README file, adding the cybersecurity company may already have detections for the flaw by now. The implant is equipped to harvest Windows credentials using pixel-perfect fake lock screens, offer a reverse SOCKS5 pivot into victim networks, execute arbitrary commands, and establish persistence on the host. It also functions as a remote access and browser monitoring toolkit that runs host commands, steals credentials, hijacks sessions...
Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. Security teams must treat autonomous agents as highly privileged identities. Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access. The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients.
HPE Patches Critical RCE Vulnerabilities in AOS-CX
"So if you want to test, you either have to add it to the exclusions or obfuscate the PoC and change the DLL load technique." The PoC, the researcher added, works in a fully updated Windows 11 25H2 machine or Windows Server 2025 with CrowdStrike Falcon. Microsoft has patched three zero-day vulnerabilities in the first patch Tuesday of 2026, including one under active exploitation Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys. Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.
Apple opens its post-Quantum encryption vault
- Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine.
- Jiří Vinopal, a threat researcher and reverse engineer at Check Point Research, presented the findings as a main-stage briefing at Black Hat USA 2026 and DEF CON 34 in Las Vegas and published the accompanying research paper alongside a proof-of-concept tool, BTR_CLI, on August 20, 2026.
- "What makes SilkParasite interesting is the traces of AI-assisted development running through otherwise expert code, which is a different thing from AI-generated malware," Bitdefender Labs said in a technical report shared with The Hacker News.
- The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system.
- A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned .
Map cross-domain privilege escalation to sever breach routes at key choke points. SpecterOps said defenders can look for signs of process injection targeting chrome.exe and msedge.exe using Sysmon Event IDs 8 and 10. "Our analysis confirms that the investigated malware is a new CoolClient variant ... Kaspersky has also published file hashes, paths, and C2 domains as indicators of compromise https://medicalcases.eu/strategies-to-protect-data-and-your-staff-from-phishing-attacks/ (IoCs). If those conditions are not met, the malware skips driver deployment and proceeds to the final-stage implant.
All this so the user can outsource labor to the machine and focus on designing, thinking, and creating. Kaspersky said the attack's geography and payload point to Silver Fox as the likely group behind it, and urged users to avoid software of questionable reputation and to keep it away from security-tool exclusions. Once installed, ValleyRAT (also tracked as Winos 4.0) hands the operator full control of the compromised machine. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper , a genuine Chinese desktop-wallpaper tool that in its unmodified form is adware, bundling partner apps and displaying ad banners. 11 years of practitioner data on what it takes to keep pace with a field that keeps shifting. Nothing malicious was installed, because nothing malicious was needed.
They account for 68.6% of the AI agents Token Security discovers in customer environments, and they often inherit the employee's credentials, network position, and permissions. The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. When Bitdefender analyzed 700,000 security incidents , 84% of the high-severity ones involved binaries that were already on the machine - the same administrative tools your IT team uses every day. The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank , a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon. A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.
Adriatic Port Cyber-Attack by Anubis Sparks Warning Over Maritime Security Risks
They run on developers' machines, execute bash commands locally, and connect to third parties via MCP servers, skills, and plugins. "This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear. ValleyRAT is a sophisticated backdoor capable of... Attacker tools and infrastructure are now changing at machine speed. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year , accounting for 47% of the attacks in their notifications.
The https://nutritioninpill.com/who-likely-to-declare-ebola-an-international-emergency-experts/ updates released by Apple improve state management mechanisms to enforce correct credential validation and prevent unauthorized authentication attempts. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, stating they are being exploited in the wild. Notably, one of the sites has been built using Lovable , an artificial intelligence (AI)-powered website builder, highlighting how readily available tools can further lower the barrier and make it easier to launch convincing new malicious sites. The mechanism allows "malware stagers to fetch commands directly from the protocol's initial response," SOCRadar said in a technical report. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development marks the first time this unusual technique has been spotted in the wild.
- It also functions as a remote access and browser monitoring toolkit that runs host commands, steals credentials, hijacks sessions...
- The implant is equipped to harvest Windows credentials using pixel-perfect fake lock screens, offer a reverse SOCKS5 pivot into victim networks, execute arbitrary commands, and establish persistence on the host.
- Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper , a genuine Chinese desktop-wallpaper tool that in its unmodified form is adware, bundling partner apps and displaying ad banners.
- Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access.
- Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop.
Russian cybersecurity vendor Kaspersky said it identified victims in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities, with CoolClient consistently deployed as a secondary backdoor following a PlugX infection. A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned . According to the analysis , observed execution began from an interactive zsh Terminal session consistent with ClickFix social engineering, followed by curl retrieving attacker-controlled content over a recurring /curl/ path and na... "The investigation also confirmed active data exfiltration, not just beaconing," the company said.
Got a Google Pixel? Find these 4 Android 17 features ASAP
- Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys.
- SpecterOps said defenders can look for signs of process injection targeting chrome.exe and msedge.exe using Sysmon Event IDs 8 and 10.
- It was first observed in April 2026, when the attack was observed delivering a file named "HolidayNotice.pdf.exe" along with a lure that was a fabricated Belgian–Myanmar public holiday calendar.
- The AI exposed hundreds of bugs in Mozilla’s web browser, raising hopes around defensive advantage, alongside fears of dual-use risk.
- While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development marks the first time this unusual technique has been spotted in the wild.
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. While the US has, at least temporarily, curtailed some of this group’s activities, https://www.edhardy-onsale.com/internet-security-tips-for-small-businesses.html the risk to misconfigured endpoint management systems remains high. The requirement for prior code execution and sufficient access to manipulate the target process places the technique in a narrower post-compromise scenario than a remotely exploitable browser flaw. The technique assumes that an operator already has code execution on the Windows host and does not involve exploiting a Chrome or Edge security vulnerability. "An authentication issue was addressed with improved state management," Apple said in an advisory released on August 6, 2026.
The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. It was first observed in April 2026, when the attack was observed delivering a file named "HolidayNotice.pdf.exe" along with a lure that was a fabricated Belgian–Myanmar public holiday calendar. There are no domains, IP addresses or URLs built into the file, and it makes no outbound connection of its own, so an infected host can look clean to tooling that watches for connections to known-bad infrastructure.
