Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.
Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. Security teams must treat autonomous agents as highly privileged identities. Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access. The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients.
Microsoft did not disclose a victim count or attribute the activity to a named threat actor in the report published Tuesday. The tech giant said it required multiple endpoint and network behaviors to align before treating a domain as connected, including process ancestry, command-line patterns, request paths, headers, and upload parameters. “What makes SilkParasite interesting is the traces of AI-assisted development running through otherwise expert code, which is a different thing from AI-generated malware,” Bitdefender Labs said in a technical report shared with The Hacker News. A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. Check Point Research said it found no evidence the technique has been used in real-world attacks.
- “So if you want to test, you either have to add it to the exclusions or obfuscate the PoC and change the DLL load technique.” The PoC, the researcher added, works in a fully updated Windows 11 25H2 machine or Windows Server 2025 with CrowdStrike Falcon.
- The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance.
- “The investigation also confirmed active data exfiltration, not just beaconing,” the company said.
- Nothing malicious was installed, because nothing malicious was needed.
- The tech giant said it required multiple endpoint and network behaviors to align before treating a domain as connected, including process ancestry, command-line patterns, request paths, headers, and upload parameters.
- Russian cybersecurity vendor Kaspersky said it identified victims in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities, with CoolClient consistently deployed as a secondary backdoor following a PlugX infection.
FAQ: What you need to know about expiring Windows Secure Boot certificates
“Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences integrity values,” SOCRadar said . Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. In Formula 1 speed is of the essence and team members need secure, but swift, access to data at all times. How the Anubis ransomware group stole and leaked an Italian Adriatic port authority’s data
Jiří Vinopal, a threat researcher and reverse engineer at Check Point Research, presented the findings as a main-stage briefing at Black Hat USA 2026 and DEF CON 34 in Las Vegas and published the accompanying research paper alongside a proof-of-concept tool, BTR_CLI, on August 20, 2026. “The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale,” Cisco Talos said in a two-part report published last week. Present within the VHD file is a Windows Shortcut (LNK) that mimics a PDF document. Two subsequent artifacts, each detected in June and July 2026, make use of a Virtual Hard Disk (VHD) file that activates the infection chain. Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent.
Map cross-domain privilege escalation to sever breach routes at key choke points. SpecterOps said defenders can look for signs of process injection targeting chrome.exe and msedge.exe using Sysmon Event IDs 8 and 10. “Our analysis confirms that the investigated malware is a new CoolClient variant … Kaspersky has also published file hashes, paths, and C2 domains as indicators of compromise (IoCs). If those conditions are https://www.mlb4s.com/network-security-engineer-skills-what-you-need-to-know.html not met, the malware skips driver deployment and proceeds to the final-stage implant.
Russian cybersecurity vendor Kaspersky said it identified victims in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities, with CoolClient consistently deployed as a secondary backdoor following a PlugX infection. A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned . According to the analysis , observed execution began from an interactive zsh Terminal session consistent with ClickFix social engineering, followed by curl retrieving attacker-controlled content over a recurring /curl/ path and na… “The investigation also confirmed active data exfiltration, not just beaconing,” the company said.
- A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.
- They run on developers’ machines, execute bash commands locally, and connect to third parties via MCP servers, skills, and plugins.
- The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients.
- It impersonates Microsoft’s dpapi.dll, exporting the same seven data protection functions as the genuine system library, and carries a version resource copied from ESET Management Agent.
- The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year , accounting for 47% of the attacks in their notifications.
- The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank , a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon.
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. While the US has, at least temporarily, curtailed some of this group’s activities, the risk to misconfigured endpoint management systems remains high. The requirement for prior code execution and sufficient access to manipulate the target process places the technique in a narrower post-compromise scenario than a remotely exploitable browser flaw. The technique assumes that an operator already has code execution on the Windows host and does not involve exploiting a Chrome or Edge security vulnerability. “An authentication issue was addressed with improved state management,” Apple said in an advisory released on August 6, 2026.
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups. Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. NemoClaw is NVIDIA’s open source reference stack for running agents such as OpenClaw inside its OpenShell sandboxes, and Ollama is one of its supported local inference backends. It impersonates Microsoft’s dpapi.dll, exporting the same seven data protection functions as the genuine system library, and carries a version resource copied from ESET Management Agent.
They run on developers’ machines, execute bash commands locally, and connect to third parties via MCP servers, skills, and plugins. “This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear. ValleyRAT is a sophisticated backdoor capable of… Attacker tools and infrastructure are now changing at machine speed. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year , accounting for 47% of the attacks in their notifications.
Google must open Android to rival AI agents, EU orders
All this so the user can outsource labor to the machine and focus on designing, thinking, and creating. Kaspersky said the attack’s geography and payload point to Silver Fox as the likely group behind it, and urged users to avoid software of questionable reputation and to keep it away from security-tool exclusions. Once installed, ValleyRAT (also tracked as Winos 4.0) hands the operator full control of the compromised machine. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper , a genuine Chinese desktop-wallpaper tool that in its unmodified form is adware, bundling partner apps and displaying ad banners. 11 years of practitioner data on what it takes to keep pace with a field that keeps shifting. Nothing malicious was installed, because nothing malicious was needed.
OpenAI agents made 15,000–18,000 https://unisto-petrostal.ru/sv/programma-proverki-sluzhby-komplaens-kontrolya-v-bankah-komplaens-kontrol-v-organizacii-chto-eto-tak.html autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach. The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The AI exposed hundreds of bugs in Mozilla’s web browser, raising hopes around defensive advantage, alongside fears of dual-use risk. A previously undocumented .NET trojan and its companion Pheno plugin allow attackers to capture mobile authentication codes from Windows systems without compromising the phone. The agentic tool, codenamed MDASH, will open to enterprise customers in private preview in June.