โŒ

Normal view

There are new articles available, click to refresh the page.
Today โ€” 23 July 2026Tech

Microsoft 2.5: New security business chief Hayete Gallot on the companyโ€™s push into the agentic era

23 July 2026 at 10:43
Hayete Gallot, now executive vice president of Microsoft Security, speaks at a Microsoft event in France in 2024. (Microsoft Photo)

GeekWire is profiling over the next few weeks some of the people and teams that are shaping the evolution of Microsoft in what weโ€™re calling its โ€œMicrosoft 2.5โ€ era.

AI has had an impact on just about every tech-product category, but especially security. Attackers are using AI; customers are looking to defend with AI. The goalposts keep shifting. โ€œAgentic securityโ€ is now the holy grail, and Hayete Gallot, the newly minted executive vice president of Microsoft Security, is leading the charge toward it.

Gallot, a 16-plus-year Microsoft veteran who rejoined the company in February after a 1.5-year Google detour, replaced Charlie Bell, who came to Microsoft from AWS in 2021 and continues at the company as an individual contributor focused on engineering quality.

โ€œCustomers care about two things: solving for security and being able to afford it,โ€ Gallot said when I asked during our interview this week why she came back to Microsoft.

โ€œI am a problem solver. And an engineer at heart (and by training). Security is the most important problem right now โ€” and Microsoft is the only place with all of the puzzle pieces to help our customers.โ€

Since her return, Gallot hasnโ€™t been shy about shaking things up. As noted recently by The Information, at least nine corporate vice presidents who previously reported to Bell have left the company this year.

โ€œWeโ€™re making changes to ensure weโ€™re in the best formation to go after this opportunity,โ€ she acknowledged.

โ€œIโ€™m motivated by doing the right thing for our customers, my teams, and tech outcomes. I like to move quickly; days and weeks, not months and years, learning through execution, iterating rapidly, and adjusting based on real customer signals.โ€

The company isnโ€™t starting from scratch. As of 2021, Microsoft claimed security was a $10 billion business for the company. By 2023, security had reached a $20 billion annual revenue rate, officials said.

Those claims havenโ€™t been without controversy. Microsoft has built a huge business in finding and fixing security problems which some customers felt were of the companyโ€™s own making.

Microsoft has a wide-ranging and rather unwieldy security portfolio, encompassing identity management (Entra), endpoint protection (Defender), endpoint management (Intune), security information and event management (Sentinel), and compliance (Purview), among others.

In 2023, Microsoft introduced its Security Copilot set of AI analysis services that integrated with some of its existing security offerings. But a portal-based solution like Security Copilot doesnโ€™t offer the kind of end-to-end coverage that an agentic security platform can, Gallot said.

The problem is that attackers are using agents, too. Customers need real-time insight into whatโ€™s happening in their environment, and the ability to act just as quickly, Gallot said.

Agentic security is about โ€œtaking the signals and turning them into a graph that is useful,โ€ Gallot said. โ€œIf youโ€™re trying to reason about 100 trillion signals, itโ€™s not really effective.โ€ The graph, she said, lets agents pick the right model for each threat and close the loop.

In practice, that means the system can quarantine a device or revoke access on its own, for example, rather than waiting for a human.

Microsoftโ€™s core existing security products will continue to play a role as the landscape evolves, both spotting the problems and acting on them. Security Copilot isnโ€™t going away in the process: โ€œYouโ€™ll have Copilot and youโ€™ll have agentic security,โ€ she said.

The companyโ€™s new Agent 365 โ€œcontrol planeโ€ โ€” a central console for tracking every AI agent a company runs โ€” fits in by letting customers see the โ€œblast radiusโ€ of an agent, meaning everything a hijacked agent could reach, Gallot said. Itโ€™s similar in concept to Zero Trust, the โ€œnever trust, always verifyโ€ security model that limited how far an attacker could get with a stolen employee login, but applied now to agents rather than people.

So what exactly is this โ€˜agentic securityโ€™ thing? Microsoft has a whole website dedicated to the very topic.

Traditional AI security and agentic AI security are fundamentally different, Microsoft says. Agentic security doesnโ€™t just protect models and training data; it also can protect tools, workflows, memory, connected systems and more. Because agents can take action, the potential positive and negative stakes are higher.

While AI has helped businesses make strides in finding and fixing vulnerabilities, it hasnโ€™t gone much beyond that. Microsoft introduced its multi-model agentic scanning harness (MDASH) as its first step into the agentic security space, Gallot said.

The company used MDASH internally to boost finding and fixing Windows security issues, and it is now making it available to select customers in an expanded preview. MDASH will allow customers to use the best model for the right task to secure all different types of code bases, she said.

Microsoft is rumored to be readying a more comprehensive agentic security offering, of which MDASH is likely just one piece.

Microsoft is far from the only one doing this. AWS, Anthropic, and OpenAI are offering security tools on their platforms, and dedicated security vendors are building their own agentic platforms.

Microsoft has the advantage of scale in the enterprise. The question is whether Gallot and her new leadership team can turn that scale and emerging AI tools into both a bigger business for the company and better protection for its customers.

Iran-linked crews are probing more flavors of US industrial kit

23 July 2026 at 10:30
The US Cybersecurity and Infrastructure Security Agency (CISA) has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure, including water and energy facilities. The original advisory focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. The update warns that the activity may also target devices from Schneider Electric, Siemens, "and potentially other branded/manufactured PLCs." The conflict between the US and Iran is well into its fourth month, and authorities have noticed Iranian-affiliated advanced persistent threat (APT) crews targeting PLCs to cause disruption since March. PLCs are used to control and monitor industrial processes. Authorities said the activity resembled earlier attacks on PLCs by CyberAv3ngers (aka the Shahid Kaveh Group) - hackers affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC). The focus is principally related to internet-facing PLCs. CISA noted attackers targeting devices through open ports: "The targeting of ports associated with other OT vendors' protocols suggests these actors are opportunistically targeting devices manufactured by companies other than Rockwell Automation/Allen-Bradley, including Schneider Electric and Siemens. "In one reported instance, the actors utilized Dropbear Secure Shell (SSH) software on victim modems to enable them to gain remote access through port 22." Once in, attackers extract device project files and modify or delete their logic. "Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies," CISA said. The expansion of the advisory's scope to include additional PLCs highlights the importance of being aware of what is accessible. On top of to earlier mitigations that included disconnecting the PLC from the public-facing internet, authorities have suggested organizations consider implementing isolated architectures and controlling network access to PLC devices. It would also be a good idea to check project files running on PLCs for unauthorized changes, make sure service providers are aware of threats targeting PLCs, and ensure default passwords are changed. ยฎ

One ChatGPT link could smuggle a rogue AI agent into your company

23 July 2026 at 09:02
One click on what looked like an ordinary ChatGPT link could plant an attacker-controlled AI agent inside a company's ChatGPT workspace, according to researchers who uncovered a flaw in OpenAI's workspace agents. Security firm Zenity Labs has dubbed the bug "AgentForger," saying its proof-of-concept showed it was possible to silently create, configure, publish, and schedule a malicious workspace agent inside a victim's ChatGPT account. The technique depended on the victim belonging to a workspace where agents were enabled and having permission to create them. Any connected apps and actions would also have to be allowed by the organization's administrators. Rather than stealing passwords or browser sessions, the technique effectively tricked ChatGPT into building an autonomous assistant that could act through the employee's connected accounts and permissions. If the victim had already connected services such as Outlook, Teams, Slack, SharePoint, or Google Drive, and the workspace allowed the relevant actions, Zenity says the agent could use them too. According to Zenity, that meant it could rummage through corporate data, send messages as the employee, and continue running long after the original phishing email had done its job. The weak spot was ChatGPT's agent builder, the feature used to spin up AI assistants that can work across email, chat, calendars, and other business apps. Zenity found it would accept instructions embedded inside what looked like an ordinary ChatGPT link. One click later, Zenity says, the builder got to work on the attacker's behalf, wiring up the victim's existing connectors, turning off approval prompts, publishing the new agent, and setting it loose on a schedule. From there, the researchers turned the agent into what amounted to a corporate mole. Instead of reaching out to conventional command-and-control infrastructure, it simply checked the victim's inbox for emails from the attacker with "TASK" in the subject line. Each message became a new assignment, whether that meant searching company files, collecting sensitive documents, or sending the results back by email. "This isn't a forged request, it's a forged insider," Michael Bargury, co-founder and CTO of Zenity, told The Register. "With one click, an attacker gets a fully autonomous agent inside your company that has your peopleโ€™s identity and access, with the guardrails off. Attackers no longer have to break in to steal your data. They can forge an insider to go get it for them. This is an agent trust failure, and existing security controls were never built to see it."โ€จ Zenity's proof-of-concept scenarios included automatically mapping an organization's people and projects by trawling Outlook, Slack, Teams, calendars, and file stores, hunting for passwords and API keys buried in chat messages, and sending convincing phishing messages through the victim's own Teams account. The researchers also demonstrated business email compromise-style lures and other forms of employee impersonation. Zenity reported the issue to OpenAI through Bugcrowd on June 4. According to the researchers, OpenAI acknowledged the report the following day and fixed the vulnerability four days later by removing the URL parameter that enabled the attack before it was publicly disclosed. OpenAI did not immediately respond to The Register's questions. The bug itself may be gone, but as AI agents graduate from answering questions to taking actions across corporate systems, the attack surface starts looking a lot less like software and a lot more like your workforce. ยฎ

If you get knocked on the head and get all your devices stolen and have amnesia, Google will let you back in with a selfie

23 July 2026 at 08:30
Tired of worrying about how you might recover all the precious data stored in your Google account if you somehow lose your devices and forget your email address and phone number? Just give Google a video of your face and AI will recognize you to restore access. Selfie sign-ins are now available for Google accounts, the Chocolate Factory announced on Thursday. This option is restricted to regaining access after email or phone recovery options fail. Going through the process of adding a verification selfie is rather simple: Just follow the steps outlined on Googleโ€™s help page for selfie video management to enroll. You need a device with a camera and the ability to move your head from side to side in order to show off your profile, as well as your full-frontal face card. That side-to-side movement is designed to prevent the use of live deepfake videos, as real-time face replacement tends to struggle with profiles. According to Google, if you canโ€™t use any other account recovery method, the companyโ€™s system can prompt you to take another selfie video for comparison to the one taken earlier, verifying it's you and letting you back into your account. Why this, why now? This feature announcement from Google raised a number of questions among The Registerโ€™s news team. Why now, for starters? Deepfake videos are constantly improving, and itโ€™s likely only a matter of time until a side view can be handled with ease. A Google rep told The Register that it sees a trend toward passkeys and other forms of device-based authentication, which means a lost device often means a lost account. โ€œUsers can choose whatever method they prefer, we expect most will prefer the ease of use of passkeys for signing in regularly, and use selfie for times like when they lose their phone or the device with their passkey,โ€ Google said in response to our questions. So it is not like Appleโ€™s Face ID or face unlock on Android, Google confirmed โ€“ โ€œthey serve different purposes.โ€ That, and it might not even be sufficient to prove youโ€™re you. โ€œPassing a selfie video alone may not always be sufficient to get back into your account,โ€ Google explained in the email. โ€œWe evaluate the overall risk based on many factors and may require additional sign-in methods to help make sure itโ€™s actually you signing into your account.โ€ That's because Apple devices with Face ID, and some higher-end Android devices, are equipped with infrared cameras that capture depth maps to match points on a userโ€™s face to a stored 3D map of their appearance. Those are harder to fool. Googleโ€™s selfie sign-in system, on the other hand, is essentially relying on plain video, AI, and the hope that deepfakes havenโ€™t become good enough to get around those turn-to-the-side distortions. Unfortunately, facial recognition AI is reliably unreliable. Heck, even Googleโ€™s had plenty of run-ins with it over the years, and good facial recognition algorithms are a hot commodity nowadays. Then there's the fact that youโ€™re giving Google a live recording of your face, and that could be quite valuable to the company in other contexts. As Google noted in its announcement, those facial scans are encrypted at rest, are only stored with user consent, and are โ€œused only for helping you sign in, unless you opt to share it for additional purposes.โ€ โ€œYou have the option to allow Google to use your video and related data to help ongoing efforts to develop and improve facial recognition, age estimation, and other verification methods,โ€ the company notes on the selfie help page. The option, labeled โ€œImprove Google Servicesโ€ on the page where users can record a selfie for account recovery purposes, is unselected by default, but we could imagine Google has a vested interest in getting you to click that. ยฎ

Swiss train maker tells ransomware crooks to get off at the next stop

23 July 2026 at 07:58
Swiss rail manufacturer Stadler Rail says it refused a CHF 10 million ($12.3 million) ransom demand after the Everest ransomware gang compromised one of its suppliers. Stadler will not pay, and based on its account of events, the company appears to have got off lightly. It stated that "no security-relevant data [was] affected" in the breach, which was limited to "technical information from a supplier." According to its announcement, "no relevant personal data was stolen," and the incident had no impact on the functioning of its rolling stock (train and tram carriages) or its global production lines. The attackers accessed the technical data through a "data exchange platform" Stadler used with the unnamed supplier, authenticating with compromised login credentials. "Stadler's IT systems were not compromised and remained intact," the company said. At the time of writing, Stadler does not appear on Everest's data leak site (DLS), nor has the swiped technical data been leaked. Stadler's absence from the extortion group's website is unusual. The typical cyber extortion playbook involves the crooks first notifying victims that data has been stolen and/ or encrypted, then issuing their demand and threat to leak data if the ransom is unpaid. Failure to meet the deadline - or refuse outright, as Stadler did - typically lands the victim organization a spot on the extortionist's DLS. That's often when a second countdown timer begins. Criminals typically offer victims another few days to realize they are not bluffing and will leak the stolen data if a fee isn't paid. If they pay, victims are scrubbed from the DLS. If they don't, their data is leaked. That's the usual playbook. However, for a victim to both refuse to pay a ransom and not appear on the gang's DLS is an oddity. Everest, a Russian-speaking cybercrime group, has operated since circa December 2020 and claimed attacks on sportswear giant Under Armour, Mailchimp, AT&T, and Collins Aerospace, to name just a few. It's dabbled in both encryptionless extortion and double extortion, and has branched out into initial access brokering and recruiting corporate insiders. ยฎ

Talking smack about a doctor got him access to private medical files

23 July 2026 at 03:00
PWNED Welcome back to PWNED, the weekly column where we focus on security own-goals so you can avoid them. This weekโ€™s topic involves serious problems in the healthcare sector, specifically the very human problem of compromised gatekeepers. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our legend of lameness comes courtesy of red teamer Dahvid Schloss, who shared so many great stories with us that weโ€™ve featured his tales a couple of times before. Schloss has made a career out of testing not only network security but also physical security at a wide variety of places. He has learned that if you act as you belong, people will usually treat you like you belong. At one hospital, Schloss was hired to test security by getting access to the records room and trying to steal a specific physical file that his client left there for him to pilfer. The challenge was that the records room had both an electronic lock and a nurse gatekeeper guarding it. Schloss told us that he considered several approaches to get into the records room. He could try picking the lock, cloning a badge, or even stealing the badge of someone who had access. Instead, he decided to try social engineering. Schloss did research on the hospital and he put on a pair of appropriate scrubs and made himself a fake security badge that could not possibly swipe in. Then he knew it was time to turn on the charm with the nurse who was on duty at the records room. And by โ€œturn on the charm,โ€ we mean โ€œdiss the doctor.โ€ โ€œNurses talk a lot of shit. It's the law of the land when it comes to the hospital,โ€ Schloss told us. So he tried to swipe his non-working badge and showed frustration when it didnโ€™t work. Then he walked up to the window where the on-duty nurse was standing and won her over. โ€œI'm doing fine, hon. How you doing,โ€ he told the nurse. โ€œLook, I'm gonna save you the details. But Dr Johnson's being an absolute asshole right now; he didn't pull out his patient records that he was supposed to pull out for trauma. We need these records, and they sent me down here. I'm brand new. I just started yesterday.โ€ Schloss had done his research and picked out the name of an actual doctor on staff. What he couldnโ€™t have known is that the doctor was actually a difficult person to work with. And the duty nurse let him know she was on his side before letting him in. โ€œThe nurse goes โ€˜honey, I know exactly the pain that you're going through,โ€™โ€ Schloss continued. โ€œShe goes โ€˜I got youโ€™ and she opens the door, lets me in.โ€ After Schloss went into the records room and retrieved the file, he hung around and talked to the nurse for another 10 minutes, complaining about how security was incompetent for not activating his badge and letting her complain about what jerks some of the doctors were. He even had a backstory about where he had worked before. She invited him to hang out and go for lunch sometime before he left with the folder. Other hospitals he tested had bad network security practices. He told us about one hospital where he sat down in the waiting room and logged into the guest Wi-Fi network and did a scan. What he found was that all the important devices in the hospital were on VLAN 1, the same network as guest Wi-Fi. All of the data coming out of medical devices like the MRI machine was readily accessible and unencrypted. He said that most medical devices at most hospitals heโ€™s tested do not encrypt data that they send over the network. โ€œSo you're getting Social Security numbers just being populated over the network via the MRI machine and you're getting the patient data, the date of birth, all the PII that any organization would lose their shit about,โ€ he said. Schloss said that he thinks hospitals heโ€™s tested prioritize the ability to keep machines running and distributing data quickly over good security hygiene. If someone tried to get data, failed, and had to call IT for help, those precious minutes of delay could cost a life. But even if it's a matter of life and death, do not let someone into a restricted area just because they look and act the part. ยฎ

Yesterday โ€” 22 July 2026Tech

How OpenAIโ€™s human mistake led to the AI-powered hack on Hugging Face

22 July 2026 at 15:11
OpenAI made a mistake setting up what it called a โ€œhighly isolatedโ€ testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.

New Data Shows Suno Breach Affected 55M Accounts

22 July 2026 at 11:53

New data shows 55.3 million Suno accounts were affected in a breach exposing contact details, purchases, and partial payment card information.

The post New Data Shows Suno Breach Affected 55M Accounts appeared first on TechRepublic.

OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face

22 July 2026 at 12:47

OpenAI says an agent powered by its LLM models escaped its sandboxed testing environment to infiltrate Hugging Face's servers as part of an overzealous attempt to obtain solutions to a benchmark test. The company says it considers the unintended infiltration an "an unprecedented cyber incident" and is working with Hugging Face on new protections to prevent a recurrence.

Hugging Face disclosed an intrusion last week that it said involved "unauthorized access to a limited set of internal datasets and to several credentials used by our services." The AI data clearinghouse said it used its own LLM-driven analysis to identify "a swarm of tens of thousands of automated actions" from an "autonomous agent framework." That agentic swarm exploited a flaw in Hugging Face's data-processing pipeline to gain the ability to run code as a processing worker, eventually escalating to high-level access to the company's cloud and server clusters.

At the time, Hugging Face said the LLM being used in the attack was "still not known." But OpenAI took responsibility for the intrusion Tuesday evening, saying it came about during an internal test involving the recently released GPT-5.6 Sol and "an even more capable pre-release model." The models were being tested against the ExploitGym benchmark, an independent testing suite based on hundreds of real-world security vulnerabilities.

Read full article

Comments

ยฉ Getty Images

Linux kernel team publishes 432 CVEs in two days

22 July 2026 at 12:58
If you're responsible for Linux security, someone just dumped a pile of work onto your desk: 432 Linux kernel CVEs were published across Sunday and Monday this week. Linux watchers at nixCraft pointed out the volume on Monday morning, and it didnโ€™t take long for seasoned sysadmins to start expressing concerns. Jan Schaumann, chief information security architect at Akamai Technologies, took to the OSS-SEC mailing list Tuesday to express concerns over the sheer volume of Linux kernel CVEs published in recent days. Aside from noting that the CVE system isnโ€™t the best way to track security changes, Schaumann also wondered in his post whether there was any good way to deal with so many kernel security issues. โ€œThis onslaught really shows it's not feasible to attempt to prioritize individual kernel changes,โ€ Schaumann said. โ€œYou might attempt to process this large set of changes by pointing an LLM at the intake and asking it to prioritize them,โ€ he suggested, โ€œbut if it spits out a dozen today and another 25 the next, you haven't won much.โ€ Schaumann also suggested waiting to see which ones emerge as serious issues and focusing on those in the weeks to come, or updating oneโ€™s entire fleet of Linux machines on a weekly basis. โ€œI sure would like to be able to do [that], but reality keeps getting in my way,โ€ Schaumann said. โ€œI'm not sure what to do here going forward.โ€ In an email to The Register, Schaumann said that individually reviewing vulnerabilities for patching was already difficult enough before things rose to this level, and that automation may be the only option - but it's not a great one. "Automated, regular, and frequent updates that pull in all changes within a given time window of tolerance seem to me the only reasonable approach, but that is very difficult for many large organizations," Schaumann explained. Those orgs often rely on lengthy QA processes, slow and staged development cycles, and may even have contractual requirements for long-term support that make an automated approach an impossible one. The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldnโ€™t be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become โ€œalmost entirely unmanageableโ€ due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." On that note, it's worth understanding what a Linux kernel CVE actually means - many of the vulnerabilities included in the Sunday-to-Monday batch are small in scope, but they're vulnerabilities nonetheless. As senior Linux maintainer Greg Kroah-Hartman noted in a February blog post, the Linux kernel CVE team follows the CVE Program's definition of a vulnerability: a weakness in a product that can negatively affect a system's confidentiality, integrity, or availability. โ€œAt the level that the Linux kernel runs, almost any type of bug that can affect a running system can be classified as a vulnerability,โ€ Kroah-Hartman noted. The kernel team looks at every bugfix that is added to stable kernel releases, he added, and if it fixes an issue that meets that CVE criteria, a CVE is assigned. AI-assisted bug hunting has increased the volume of reports reaching Linux kernel maintainers. We reached out to the Linux kernel team, but didnโ€™t hear back. Kroah-Hartman did tell The Register earlier this year that AI bug reports had become worthwhile in recent months, and he predicted they're likely to keep adding to his workload. Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isnโ€™t one thatโ€™s readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy. Hope youโ€™ve got the coffee machine filled up: The onslaught is unlikely to ease if other recent patch cycles are any indication. ยฎ

Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits

22 July 2026 at 09:00
EXCLUSIVE A Windows information-stealer targeting more than 300 applications comes equipped with a novel surveillance tool: an AI profiler that ranks infected victims so crooks know who to target first. Varonis Threat Labs spotted the new stealer and remote access trojan (RAT), called Dolphin X, for sale on a cybercrime forum, and shared their research exclusively with The Register. The ad for the malware claims it can target upwards of 300 applications and has the ability to bypass browser passwords and steal enterprise credentials, cryptocurrency wallets, .env files, SSH keys, cloud tokens, and DevOps secrets. Dolphin X also promises users a super-sneaky surveillance feature called the AI Profiler. It scores infected users by app usage, browsing history, and installed software, and sends the cybercriminals a daily summary that ranks victimsโ€™ based on the likely payoff from an attack. โ€œThere's two things that stand out,โ€ Daniel Kelley, a senior threat researcher with Varonis, told The Register. โ€œThe first thing is the AI profiler. That's something I've never seen before. And then itโ€™s also the breadth of applications that it steals - and itโ€™s not even just applications. Itโ€™s everything, you name it: it will steal files, or credentials, cryptocurrencies. Itโ€™s probably one of the biggest stealers Iโ€™ve ever seen, and covers the biggest attack surface.โ€ A malware vendor using the alias โ€œKontraktnikโ€ posted Dolphin X for sale, promising: โ€œYou can use it as a stealer, as an HVNC [Hidden Virtual Network Computing], as a DDoS botnet, as a loader.โ€ The crimeware currently only runs under Windows, but โ€œwe are working on Debian,โ€ Kontraktnik claimed, adding that the malware also only supports English and Russian. Kelley suspects the developer is Russian-speaking, and told us that the stealer includes an option not to infect any users in the Commonwealth of Independent States (CIS) countries, a common choice among Russian-based ransomware and cybercrime gangs. Kelley and his team obtained and analyzed the malware builder, operator panel and its network traffic, but didn't examine a malware sample. Varonis therefore canโ€™t guarantee that all of the developerโ€™s claims are true. However, โ€œwhen we looked at the builder, it had everything to suggest the features were legitimate,โ€ he said. โ€œWe couldnโ€™t test out the malware itself, but I would say it probably lives up to most of its expectations.โ€ Feedback left on the forum where the malware is sold supports that analysis. As of Tuesday, the sales thread has passed 3,000 views, weโ€™re told, with Kontraktnik closing at least two confirmed deals. Both of these included positive feedback from the buyers. Three-tier subscription model Beyond the 300 + apps it targets, Dolphin X's operator panel lists 329 features across 10 categories. Buyers can subscribe to one of three tiers, each unlocking new features, or buy a lifetime subscription. The minimalist suscription costs about $80 per month, which buys rewriting and altering capabilities across Windows Portable Executable (PE) timestamp, Rich headers, and section padding, along with capabilities allowing the malware to exploit the brittle YARA rules to bypass detection and hash-based blocklists. The middle tier advertises shuffling the import table, which would change the binary's import hash between builds. The top level sub (about $230 per month) claims to rewrite the codeโ€™s control flow, substitute instructions, and re-encrypt embedded strings with a new random key each time, thus making stable byte sequences harder to identify. Lifetime subscription cost about $1,140 for basic access, $2,280 for mid-tier malware, or $3,420 for perpetual pro-level Pwnage. โ€œIt really lowers the barrier to entry,โ€ Kelley said, adding that in the not-so-distant past, cybercriminals needed a certain level of technical expertise to develop and use different types of malware. โ€œNow it's set up in a way where it's almost like SaaS. Anyone can purchase it. Anyone can take it out of the package and use it.โ€ All of this suggests two takeaways for defenders, according to the security sleuths. First, keep long-lived credentials off disk if possible. โ€œInfostealers are designed to grab everything in one pass, so anything stored locally should be treated as potentially exposed,โ€ the report warns. Second: focus threat detection on behavior - not file signatures - because this and other malwares include capabilities to bypass signature-based detection. โ€œFor example, explorer.exe running under a non-default desktop is a strong indicator of an HVNC session, regardless of how the malware binary is packed or what hash it uses,โ€ the authors wrote. Varonisโ€™ threat hunters previously uncovered other AI-powered malware, including an all-in-one phishing kit called Bluekit, and an email attack tool called SpamGPT. โ€œItโ€™s a huge trend,โ€ Kelley said. โ€œCybercriminals are finding a lot of unique ways to integrate AI, and then they're using it to make their lives a lot easier, which is problematic.โ€ ยฎ

Greedy ransomware crews return for seconds after victims cough up first extortion payments

22 July 2026 at 07:49
Authorities have long warned organizations not to pay ransoms, and fresh figures underline why: handing over the money doesn't mean the crooks leave you alone. Proofpoint survey data suggests that 58 percent of affected UK organizations paid a ransom. Worse, 22 percent of those who pay get extorted again anyway. The UK broadly tracks the global picture: 54 percent of victim organizations paid, though the rate swings sharply by region, from just 19 percent in Japan to 93 percent in the US. Cybersecurity biz Proofpoint, which published the data on Wednesday, attributes the regional variation to "a combination of regulatory environment, recovery capability, insurance incentive structures, and cultural norms around negotiation." "But the core finding holds everywhere: ransomware creates enough pressure that a significant share of organizations in each of the surveyed markets choose to pay." UK organizations that paid fared somewhat better than the 37 percent global average for repeat extortion. Still, the core lesson stands: paying doesn't reverse an attack. You can't trust a criminal's word. It just restarts a negotiation where the attacker holds every card, including the data, decryption keys, and the threat of publishing what they've stolen. Operation Cronos, law enforcement's LockBit takedown, provided hard proof of what had long been suspected: cybercriminals often retain victim data even after being paid. Before Dmitry Khoroshev's cybercrime empire collapsed, this was an assumption, not evidence-based. Cronos didn't just shutter the then-leading ransomware gang; it undermined the entire premise that paying restores the status quo. Proofpoint found that 2 percent of victims who paid a ransom never recovered their files at all. Earlier this year, Nitrogen's ESXi ransomware victims hit a similar wall after a coding error in the decryptor left some unable to fully restore access, and it was far from an isolated case. Attackers don't need to hold up their end of the bargain to keep the payments coming. The better answer is to build cyber-resilience into the organization itself. A word on AI No 2026 security report is complete without AI. In the UK, 65 percent of surveyed security practitioners said AI had sharpened the attacks that precede ransomware and extortion, most notably malicious links, business email compromise, malicious attachments, and credential harvesting. AI is not yet a key tool in ransomware payloads themselves, despite recent reports suggesting this may soon change. However, it is being used for more convincing phishing lures, sharper impersonation attempts, and faster system reconnaissance once attackers are inside a network. "AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to it," said Ryan Kalember, chief strategy officer at Proofpoint. "Today's attackers are using AI to create highly convincing phishing emails and credential theft campaigns that exploit human trust at scale. "Organizations that continue treating ransomware as an endpoint or recovery problem are missing where these attacks most frequently begin: people, identities and trusted communications." ยฎ

โŒ
โŒ