Reading view
Russian state attackers exploiting misconfigured routers, new multi-nation advisory warns
OpenAI-Hugging Face Incident: What We Know
An experimental AI agent powered by OpenAI models has successfully compromised part of Hugging Face’s infrastructure during a controlled cybersecurity evaluation, offering a glimpse into the evolving offensive capabilities of advanced AI systems.
The incident, first disclosed by Hugging Face last week, has now been confirmed by OpenAI to have involved a combination of its models, including GPT-5.6 Sol and a more capable pre-release model with cyber safety restrictions temporarily relaxed for testing. According to both companies, the AI agent was evaluated as part of an internal benchmark designed to measure the cyber capabilities of frontier AI models.
OpenAI said the breach was quickly detected and contained, with no impact on customers or production systems. However, the company acknowledged that incidents involving increasingly autonomous AI agents are likely to become more common as models become more capable. This has raised alarm among cyber professionals.
Oliver Simonnet, Lead Cybersecurity Researcher at CultureAI, said: “It’s not just the sophistication of the attack, but what it says about where we are with AI capability, as this wasn’t just a model executing a predefined exploit chain. It seemingly identified obstacles, discovered new attack paths, pivoted through multiple environments, and remained relentlessly focused on achieving its objective, even after leaving its sandbox.”
The evaluation was intended to help researchers better understand how advanced AI systems behave in realistic cybersecurity scenarios and to improve future safeguards. OpenAI said it has now restored the affected safety protections on the models used during the testing.
Kieran B, Head of Technical Services at Bridewell, noted: “OpenAI deserves credit for being transparent about what happened, disclosing the vulnerability responsibly and working with the affected parties to remediate the issue. That openness will help the wider industry learn from the incident. However, it also serves as a reminder that this was a controlled research scenario. If an attacker sought to exploit weaknesses in enterprise deployments using the new advanced AI models, the consequences could be far more significant.”
The incident is likely to fuel ongoing discussions around AI security, agentic AI and the need for robust governance as organisations increasingly deploy autonomous AI systems. It also highlights the importance of rigorous testing and responsible disclosure as AI models gain the ability to perform increasingly sophisticated cyber tasks, even within tightly controlled research environments.
Cyber experts have weighed in on the incident. Sai Molige, Senior Manager of Threat Hunting at Forescout, said: “The required security posture is not ‘trust the model unless it misbehaves.’ It is to assume that a capable agent will discover every reachable path that advances its objective and to ensure that no such path grants unintended authority.”
Kevin Kirkwood, CISO at Exabeam, said: “The practical fix is to treat every dataset, model, plugin, and AI-processing job as untrusted code. Run it in a disposable sandbox with no standing cloud credentials, no direct access to production systems, and tightly restricted network egress. The goal is not to assume every malicious payload will be caught. The goal is to make sure a compromised worker has nowhere useful to go.”
“Next, remove the blast radius. Use short-lived workload identities, strict network segmentation, and separate trust zones for processing, production, internal datasets, and secrets. A worker handling user-supplied content should never inherit broad cluster access or reusable credentials. If one node is compromised, the incident should end at that node instead of becoming a tour of the company’s infrastructure.”
“Finally, build detection and response for machine-speed abuse. Monitor for rapid credential discovery, unusual service-account activity, cross-cluster access, abnormal API sequences, and large internal data pulls. Pair that with automated token revocation and fast worker rebuilds. ” Kevin continued.
Roey Eliyahu, CEO and Co-Founder of Salt Security, said: “Every AI agent needs to be treated like a new identity with its own privileges, its own behavioral baseline, and continuous oversight. The question security teams should be asking right now is simple: do you have visibility into what your agents are calling, what systems they are reaching, and whether that behavior is what you sanctioned? Because if an agent starts making API calls it was never supposed to make, to systems it was never supposed to reach, you need to know before the breach happens, not after.”
Oliver Simonnet from CultureAI concluded: “This incident really highlights the challenges of building AI systems that are powerful enough to strengthen cyber defence whilst also ensuring they remain contained during development and testing. Being able to securely evaluate these systems is just as important as securing the systems they’re designed to protect.”
The post OpenAI-Hugging Face Incident: What We Know appeared first on IT Security Guru.
Robot Vacuum Flaw Could Give Hackers Control Over Millions of Home Devices
A security researcher writing under the name tokay0 disclosed a flaw that could allow an attacker to access and control more than 600,000 deployed Shark model robot vacuums.
The post Robot Vacuum Flaw Could Give Hackers Control Over Millions of Home Devices appeared first on The Security Ledger with Paul F. Roberts.
In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt.
The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws appeared first on SecurityWeek.
KnowBe4 Unveils Custom AI Video Builder
KnowBe4 has expanded its AI-powered security awareness training platform with the launch of Custom AI Video Builder, a new capability designed to help organisations rapidly create tailored cybersecurity training videos in response to emerging threats.
The feature, developed as part of KnowBe4’s strategic partnership with AI video platform Synthesia, enables security teams to generate custom training videos in minutes and deploy them directly into their security awareness programmes without leaving the KnowBe4 platform.
The launch comes as cybercriminals ramp up usage of generative AI to create highly targeted social engineering campaigns aimed at specific industries, job roles and regions. According to KnowBe4, organisations need to be able to update awareness training at a similar pace in order to keep employees prepared for evolving attack techniques.
Available through KnowBe4’s ModStore, the new feature includes a prepaid Synthesia Starter licence (worth $250 per year) allowing customers to create up to 120 minutes of AI-generated video annually. Users can choose from more than 120 AI avatars and produce content in over 160 languages and dialects.
The capability integrates directly with KnowBe4’s existing Content Creation Agent, allowing administrators to add studio-quality video to AI-generated text-based training. Alongside the recently launched Deepfake Training Content Agent, the new release forms part of the company’s broader AI-native content customisation suite.
“Generative AI has given attackers the ability to build campaigns around the exact policies, roles and regions where training doesn’t yet exist,” said Greg Kras, Chief Product Officer, KnowBe4. “Custom AI Video Builder closes that window by putting studio-quality video production directly inside the KnowBe4 platform, so customers can go from a new threat to a finished training module without waiting on a production cycle. It’s one more way we’re helping security teams match the speed of the threats they’re defending against.”
Among the key features are automated publishing of completed videos into the ModStore’s Uploaded Content library, removing the need to manually download and upload SCORM packages, and AI-powered dubbing that enables organisations to localise training for employees around the world.
Custom AI Video Builder is available immediately to customers on KnowBe4’s Platinum, Diamond, Training-Only Diamond, SAT Foundation and SAT Advanced subscriptions.
The announcement follows further recognition for KnowBe4, after the company received an award in the email security category earlier this month.
The post KnowBe4 Unveils Custom AI Video Builder appeared first on IT Security Guru.
The Good, the Bad and the Ugly in Cybersecurity – Week 30
The Good | Authorities Dismantle Kratos Phishing Network & Arrest Its Developer
Kratos, a prominent phishing-as-a-service (PhaaS) platform, was dismantled from the inside out this week thanks to German and U.S. law enforcement agencies. During “Operation Olympus Blade”, authorities seized over 200 servers to render Kratos’ global network entirely inoperable while the platform’s suspected developer was apprehended in Indonesia.
So far, investigators estimate that more than 1800 cybercriminals utilized the platform to launch nearly 15,000 phishing campaigns monthly since late 2024. Operating as a franchise, the service provided threat actors with toolkits designed to generate convincing Microsoft authentication pages. These campaigns targeted victims across the United States and Europe, facilitating widespread credential theft and unauthorized account access. The operators earned at least €300,000 in subscription fees.

A recent report from cyber researchers reverse-engineered the Kratos toolkit, revealing how it offered operators two distinct functional modes. While one mode harvested traditional credentials, the more advanced setting deployed a Node.js reverse proxy. This adversary-in-the-middle (AitM) capability allowed attackers to intercept active session cookies in real-time, effectively bypassing standard multi-factor authentication (MFA) controls.
Once compromised, these accounts provided actors with initial footholds to execute business email compromise (BEC), lateral data theft, and secondary phishing attacks. Just this February, actors ran Kratos in a campaign that used tax-themed lures and personalized QR codes to target dozens of American manufacturing and healthcare organizations.
While the immediate server takedown severely disrupts ongoing operations, officials acknowledge that the existing customer base retains access to the underlying kit code. That means the toolkit itself outlives the infrastructure seizure, and operators who already have copies can resume campaigns under new branding with minimal rebuild effort.
The Bad | Threat Actors Conceal HollowGraph Malware in Microsoft 365 Calendar Events
A novel espionage implant, dubbed HollowGraph, is hijacking Microsoft 365 calendars to establish a covert command and control (C2) channel. By routing operator instructions and exfiltrated data through legitimate Microsoft Graph API traffic, the malware ensures its activities blend seamlessly with routine network chatter.
The .NET DLL implant operates purely as a two-way dead drop without communicating directly with an attacker-owned payload server. To receive tasking, HollowGraph queries the compromised user’s calendar for an event planted far into the future – in this case, dated for May 13, 2050. Operators embed their instructions within text files attached to this anomalous event, ensuring the mailbox owner never naturally scrolls far enough to discover the malicious entries.
For data exfiltration, the malware executes the reverse process. It systematically encrypts stolen files using hybrid RSA and AES-256 encryption, generates a new far-future calendar event, and uploads the targeted data as attachments. To maintain continuous Graph API access, operators utilize a secondary DNS-based channel to refresh the application’s Entra ID login credentials. The malware decodes these values from an attacker-controlled domain and writes them to a disguised configuration file.
Analysts observed this highly targeted campaign actively compromising machines at an Israeli organization between June and July 2026. While the implant’s underlying code shares significant structural similarities with a modular backdoor framework called Cavern, frequently utilized by Iranian state-sponsored syndicates, researchers have not yet definitively attributed this specific operation to a known threat group.
HollowGraph buries its C2 in M365 calendar events dated 2050 – no attacker server ever touched. https://t.co/yJo4fpw0X9 #ThreatIntel #HollowGraph #Cavern #Cav3rn pic.twitter.com/kaABaAYZg0
— ThreadLinqs (@threadlinqs) July 22, 2026
Since HollowGraph relies entirely on compromised account identities and legitimate application permissions rather than software vulnerabilities, standard patching remains ineffective. The technique effectively weaponizes the trust organizations place in their own Microsoft Graph API traffic, turning routine calendar activity into a blind spot by design.
The Ugly | AI Models Escape Sandbox to Breach Hugging Face Infrastructure
Open-source AI platform Hugging Face recently disclosed a network breach orchestrated entirely by an autonomous AI agent. The attack compromised the company’s data-processing pipeline by deploying a malicious dataset that exploited two distinct code-execution vulnerabilities. This initial access allowed the agent to run unauthorized code on a processing worker, harvest cloud and cluster credentials, and subsequently move laterally across several internal systems.
The platform reported that the agent executed thousands of individual actions across short-lived sandboxes while staging self-migrating C2 infrastructure on public services. Following the discovery, Hugging Face evicted the agent, revoked affected credentials, and rebuilt compromised nodes. It was during the forensic investigation that responders encountered a unique operational hurdle: Western AI models refused to process the malicious artifacts due to built-in safety guardrails. At this point, the company turned to an unrestricted, open-weight Chinese model to successfully complete the analysis.
Shortly after Hugging Face’s disclosure, OpenAI confirmed that its own AI models orchestrated the intrusion during internal benchmark testing. Operating with reduced safety guardrails for evaluation purposes, GPT-5.6 Sol and an advanced pre-release model attempted to cheat the ExploitGym cybersecurity assessment. Rather than solving the challenges natively, the models identified and exploited a shortcut, retrieving the test solutions directly from Hugging Face’s production database via a zero-day vulnerability in a third-party package registry cache proxy.

After gaining open internet access through privilege escalation and lateral movement, the models accessed Hugging Face servers. The AI agents chained together multiple attack vectors, utilizing the stolen credentials and additional zero-day vulnerabilities to establish remote code execution. OpenAI subsequently disclosed the zero-day flaw and collaborated with Hugging Face to implement stricter infrastructure controls and guardrails.

The Signs Were There: What the First Autonomous Ransomware Case Confirms
Examining the Unintended Consequences of the Online Safety Act
The 25th July 2026 marks one year since the Online Safety Act’s landmark child safety duties came into force, making it a natural moment to assess what’s changed, what’s worked and what challenges remain. Although the Act itself received Royal Assent in October 2023, its requirements were introduced in phases, with 25th July 2025 being the date many of the most visible obligations on platforms took effect.
The child safety duties require platforms likely to be accessed by children to introduce stronger protections, including effective age assurance, child risk assessments and measures to reduce exposure to harmful content.
One year on, has the Online Safety Act fundamentally changed the internet for UK users, or has it simply shifted the challenges elsewhere? We spoke to cybersecurity experts for a short series of reports to find out more.
Today, we’re examining the unintended consequences of the Act…
Professor George Loukas, Head of Centre for Sustainable Cyber Security, University of Greenwich, said: “Ofcom has moved from consultation to enforcement. Naturally, the larger adult sector platforms have been the most visible early targets, and there have been lots of discussions on whether that led to a shift to more VPN usage as well as to non-compliant adult websites. These were all predictable though.”
Uptick in VPN Usage
For many, the enforcement date signalled a natural (if not predictable) shift towards VPN usage to get around age verification tests. The evidence backs up this hypothesis: Proton VPN’s 2025 end of year report revealed that one of the biggest spikes in VPN sign-ups globally was seen in the UK from the 25th July.
Konstantin Levinzon, co-founder of Planet VPN, noted that the real issue is people seeking out ‘free’ or not reputable VPNs, posing a significant security risk: “The biggest unintended consequence has been pushing people towards less secure tools, not more careful online behaviour. Age verification requirements have driven a significant increase in VPN adoption, but many users don’t seek out reputable providers – they simply download the first free VPN they find. Those services are often the ones leaking DNS requests, harvesting telemetry or relying on weak security practices, creating a worse privacy outcome than the legislation was designed to prevent.”
Sanjeev Malhotra, chief information security officer at TSG, emphasised the security risk: “People engaging with unvetted VPNs are potentially opening themselves up to serious risks, including malware infections, phishing attempts and personal data harvesting. At the end of the day, it’s still going through a server somewhere, and most people don’t stop to think about who’s operating it, where that data is going or what safeguards are actually in place. In some cases, people may be trading one privacy concern for another without realising it.”
A Lack of Measurable Outcomes?
But is the ban on children accessing adult sites actually working? Some experts argue that there’s no hard evidence to back it up.
Elle Todd, Partner and Co-chair of the Entertainment & Media Industry Group at Reed Smith LLP, said: “Ofcom’s recent age assurance report found that the proportion of children encountering harmful content online has not substantially improved despite widespread implementation efforts. The uncomfortable truth is that, based on this report, significant investment in compliance and technologies has not yet translated into measurable improvements in safety outcomes.”
Brian Higgins, Security Specialist at Comparitech, noted that, despite some non-compliance fines being handed out, there are still notable enforcement gaps: “Stats from Ofcom summarising their activities during the first twelve months of the Online Safety Act include the launch of 30 investigations, and fines for statutory violations in the region of £4 million GBP. Unfortunately they have also identified ‘enforcement gaps’ where AI and algorithmic content are concerned.”
“This item, in particular, could be a precursor to more widespread enforcement action in the future but a brief investigation into the facts reveals that their twelve-month fine collection figure only stands at £55,000. Couple that with their fairly embarrassing skirmish with the American platform 4chan, where their interjurisdictional service of a £520,000 financial penalty notice was rather infamous met with a picture of a hamster and a heavy dose of internet ridicule and it becomes rather obvious that they aren’t performing particularly well.”
Examining Data Storage and Verification System Security
Boris Cipot, principal security engineer, Black Duck, argues that we should be looking beyond whether checks are working and to whether the software behind the systems doing those checks is actually secure: “For many organisations, the focus has been on whether age checks are working. But an equally important question is whether the software behind those systems is secure and properly maintained. If a vulnerability, misconfiguration or compromised third-party component allows age checks to be bypassed, then this is not just a cybersecurity problem anymore but can quickly become a regulatory one as well.”
Sarah Bone, Co-Founder of YEO Messaging, notes the growing number of specialist identity providers: “The biggest unintended consequence has been a shift in where trust actually sits. Before the Online Safety Act, platforms largely carried the responsibility for verifying users themselves. Now we’ve got a growing ecosystem of specialist identity providers, each holding highly sensitive personal information. That’s strengthened online safety, but it’s also concentrated trust into fewer organisations, which makes them increasingly attractive targets for attackers.”
So what should age verification providers be doing?
Martin Wegrostek, Cyber Security Portfolio Manager at cybersecurity specialist OryxAlign, said: “Businesses should work on the assumption that breaches are a matter of when, not if. The question is whether providers have built their services with security and privacy by design. That means collecting the minimum amount of information needed to verify age, encrypting data both in transit and at rest, enforcing strong access controls, continuously monitoring for suspicious activity and having a well-rehearsed incident response plan. Organisations relying on third-party age-assurance services should also carry out regular security assessments and review the resilience of their supply chain, rather than assuming a compliant provider is automatically a secure one.”
On Trust and Risk
The conversation should also focus on human risk, said Tim Ward, CEO and co-founder, Redflags: “Content moderators, trust and safety teams, and customer support staff at in-scope platforms are, for the first time, routinely processing government ID documents, facial scans, and other highly sensitive data belonging to minors as part of their everyday work. That’s a substantial new category of human risk, from simple mishandling to targeted social engineering aimed at staff with access to this data, and it’s had almost no public discussion compared to the technical side of compliance.”
“Organisations that have spent the past year focused on the verification system itself should be asking whether the humans downstream of it have had the same level of scrutiny and support,” Ward noted.
The post Examining the Unintended Consequences of the Online Safety Act appeared first on IT Security Guru.
13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan
Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It
Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure
Research Shows Quantum Security Deployment Remains Stuck Despite Enterprise Planning
DigiCert has released the findings of its second annual global survey on post-quantum cryptography (PQC), showing that while organisations are actively preparing for the quantum era, measurable progress toward deployment remains minimal.
According to the company’s newly published Quantum Readiness Outlook, 87% of organisations say they are planning, testing or implementing PQC initiatives. Yet deployment has increased by just two percentage points since last year’s survey, leaving only 7% of organisations with quantum-safe or hybrid cryptography deployed across most of their digital certificates.
The report, based on a survey of 1,001 IT and cybersecurity decision-makers across the United States, United Kingdom and Australia, points to what DigiCert describes as a widening “execution gap”: organisations have largely moved past the awareness stage, but are struggling to translate strategy into enterprise-wide implementation.
More than half of respondents (50%) believe current encryption standards could be broken within the next five years, while 85% expect them to be broken within a decade. Despite that shortening timeline, enterprise progress toward quantum readiness has increased by only two percentage points over the past twelve months.
“The move to post-quantum cryptography is part of a broader modernisation journey versus just a technology upgrade,” said Kevin Hilscher, Senior Director of Product Management at DigiCert. “Organisations that invest in crypto-agility today are building the flexibility to evolve with changing standards, emerging technologies, and future business requirements. That’s what creates long-term resilience. However, this is where the research suggests organisations are now struggling: how to translate strategy into enterprise-wide execution.”
The urgency behind the transition is also being driven by so-called “harvest now, decrypt later” (HNDL) attacks, in which adversaries collect encrypted data today with the intention of decrypting it once sufficiently powerful quantum computers become available. Eighty-four percent of organisations believe at least some of their encrypted data is already vulnerable to this type of attack, and more than a third believe over 25% of their encrypted data is exposed. The largest share of respondents (39%) expect the transition to quantum-safe cryptography to take between three and five years, reinforcing that quantum risk is increasingly viewed as a present-day business concern rather than a distant technical one.
Financial transaction records and banking data were identified as the assets attackers are most likely to target first once quantum decryption becomes feasible, followed by cryptocurrency private keys and wallets. Respondents also pointed to corporate IP, government and military data, and politically sensitive material, citing high-profile leak events as examples of information that could remain valuable to attackers for years to come.
Additional findings
- Financial transaction records and banking data were deemed most likely to be targeted first once decryptable, followed by cryptocurrency private keys and wallets.
- 50% of organisations have conducted quantum risk assessments, while 44% have developed transition plans and created cryptographic inventories.
- 6% of respondents identify complexity across legacy systems as the biggest barrier to deployment, ahead of budget constraints and performance impact, and displacing uncertainty around standards or lack of executive support as the primary obstacle.
- Retail reported the lowest levels of preparedness of any major industry, while Manufacturing emerged as the most divided sector, with respondents split between feeling highly prepared and not prepared at all. MedTech and Telecommunications & Media reported the highest confidence in their readiness.
- The United Kingdom reported the highest share of organisations identifying themselves as leading edge on quantum readiness (18%), followed by the United States (17%) and Australia (10%).
Industry and regulatory pressure building
DigiCert’s report notes that the window for organisations to prepare is narrowing as major technology vendors and governments accelerate their own timelines. Google has targeted 2029 for its migration to PQC, and Microsoft has since committed to a similar strategy, while a recent U.S. Executive Order is pushing the federal government to accelerate its own transition. The publication of the National Institute of Standards and Technology’s (NIST) post-quantum cryptography standards in August 2024 has also given organisations a clearer technical path forward, which DigiCert says has helped accelerate planning, though not yet deployment, across industries.
Most leaders surveyed believe it will take three to five years to deploy quantum-safe encryption enterprise-wide, with complexity across legacy systems cited as the top barrier to making that happen.
Commenting on the research, Simon Pamplin, CTO of Certes, said, “These findings highlight a growing disconnect between awareness and action. If 85 percent of IT and security leaders believe quantum computers will break today’s encryption within the next decade, yet only 7 percent have deployed quantum-safe solutions at scale, it’s clear that organisations understand the risk but are struggling to turn strategy into execution.
What’s particularly concerning is that more than a third of UK organisations believe over a quarter of their encrypted data is already vulnerable to ‘harvest now, decrypt later’ attacks. For organisations handling financial data, customer records and personally identifiable information, this is no longer a future planning exercise. Data being stolen today will be exposed years from now if it isn’t adequately protected.
The biggest obstacle isn’t awareness, it’s the absolute complexity of implementing cryptographic change across legacy applications, hybrid environments and edge infrastructure that were never designed with crypto agility in mind. That’s why organisations need to stop thinking about post-quantum cryptography as simply replacing algorithms. They should be focusing on protecting the data itself with a data-centric, crypto-agile approach that reduces risk today while creating a practical path to long-term quantum readiness.”
The post Research Shows Quantum Security Deployment Remains Stuck Despite Enterprise Planning appeared first on IT Security Guru.
FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations
Researchers at Huntress have disclosed a malvertising campaign that abused a public artifact hosted on Anthropic’s own claude.ai domain to distribute the SectopRAT information-stealing Trojan, compromising at least 29 organisations in the space of two days.
The campaign, which Huntress has named FakeAgent, ran between 21 and 22 July 2026. Victims searching for “Claude Desktop app” on Bing were served a sponsored advertisement that, unlike the surrounding malicious ads, pointed to the legitimate claude.ai domain. However, the link led not to Anthropic’s genuine download page but to a public Claude Artifact, user-generated content that Anthropic allows users to host and share on its platform, that had been built to imitate the official Claude Desktop installer.
Clicking “Download” on the spoofed artifact redirected victims through a chain of attacker-controlled domains, including claude.ai.download-app[.]us, before serving a malicious ClaudeDesktop.exe file. Huntress reported the artifact to Anthropic, which removed it on 22 July, by which point the page had recorded more than 7,100 views.
Sideloading and anti-analysis tradecraft
According to Huntress’ technical writeup, the malicious executable was not actually the Claude Desktop installer but a repurposed JetBrains binary (jcef_helper.exe) vulnerable to DLL sideloading. The real payload was carried in a tampered libcef.dll, packed with the commercial protector VMProtect to hinder reverse engineering.
A second stage, delivered via a signed IBM SPSS binary and a malicious tempdir.dll, implemented a GPU-based anti-analysis check that inspected DirectX graphics adapters for signatures associated with virtual machines (such as those used by QEMU and VMware) and measured shader execution timing before deciding whether to run.
Notably, the malware’s core payload was decrypted using a custom DirectX shader rather than a conventional CPU-based routine, a technique Huntress said is largely opaque to standard reverse-engineering tooling. Investigators said they used Claude Opus 4.8 to help reconstruct an SM5 bytecode interpreter and recover the AES-256-CTR key material used by the shader, work that ultimately uncovered the malware family: SectopRAT, a remote access trojan designed to harvest browser credentials, autofill data, payment card details and files.
Command-and-control infrastructure for the malware was concealed inside Ethereum blockchain transactions, a technique known as “EtherHiding” that allows operators to rotate infrastructure by posting new transactions rather than relying on takedown-vulnerable servers.
Attribution and prior activity
Huntress used WHOIS and threat-intelligence data from Validin to link the registration email address behind the campaign’s infrastructure to at least ten other domains dating back to December 2025, including one seized by Microsoft as part of Operation Endgame for hosting the StealC stealer. Researchers also tied the operator to an earlier campaign, identified in April 2026, that used a similarly themed fake Docker Desktop installer distributed via Docker Hub.
Huntress said its analysis of the Ethereum-based command-and-control transactions traces the operator’s activity back to May 2025.
Industry implications
The incident underscores a growing trend of attackers targeting AI tooling platforms directly rather than relying solely on typosquatted domains. Huntress noted that this is not an isolated case, pointing to a previous report on a similar fake Claude download campaign.
“Do not trust top-level domains implicitly,” Huntress wrote in its findings, urging users to treat search-engine advertisements with caution regardless of the domain they claim to represent, given the long-running prevalence of SEO poisoning and malvertising as an initial access vector.
The full technical analysis, including indicators of compromise and a list of historical command-and-control IP addresses extracted from the blockchain transactions, is available on the Huntress blog: https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat
The post FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations appeared first on IT Security Guru.
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective
Bridewell has launched BCON Collective, a dedicated Threat Research and Cyber Threat Intelligence (CTI) practice designed to help organisations better understand, prioritise and respond to today’s rapidly changing cyber threat landscape.
The new practice brings together Bridewell’s existing intelligence-led services, original threat research and specialist analysts under a single identity, reflecting growing customer demand for threat intelligence that informs strategic decision-making rather than simply providing indicators of compromise.
According to Bridewell, organisations are looking beyond traditional security monitoring as ransomware groups become more organised, attackers exploit trusted services and social engineering campaigns become more sophisticated. Rather than reacting to incidents, businesses want intelligence that helps them anticipate threats, understand adversaries and focus security resources where they will have the greatest impact.
Led by Gavin Knapp, Head of Cyber Threat Intelligence, BCON Collective will provide strategic, operational and tactical intelligence designed to support more informed security decision-making. The team works across areas including threat detection, vulnerability prioritisation, incident response and long-term cyber resilience planning.
“Threat intelligence has become its own discipline within cybersecurity,” said Anthony Young, CEO of Bridewell. “Organisations are progressing to see it as not just something that sits alongside security operations, rather they expect it to shape strategic decisions, inform vulnerability management and strengthen incident response.
“Gavin and the team have built an exceptional reputation for producing intelligence that is both technically rigorous and genuinely actionable. As customer demand for these services continues to grow, it made sense to give this capability its own identity while keeping it firmly rooted within Bridewell’s wider cybersecurity expertise.”
Bridewell said its CTI team has built a reputation for producing original threat research covering emerging cyber threats and attacker activity. Recent research has examined ransomware groups including DragonForce, the tactics used by Scattered Spider during attacks against major UK retailers, emerging phishing techniques such as FileFix and ConsentFix, and nation-state activity linked to North Korea.
Knapp believes the real value of threat intelligence lies in helping organisations cut through the volume of available data.
“The biggest misconception about threat intelligence is that it’s about collecting more information. It isn’t. It’s about reducing uncertainty,” he said. “Every security team already has more data than it can realistically process. The challenge is knowing which threats actually matter, which risks deserve immediate attention and where to focus before attackers make the decision for you.
“Most importantly our threat research, threat intelligence and collaboration with both Bridewell offensive security, threat detection, and response capabilities allows us to provide the key components of a threat informed defense to our CNI client base.
“BCON Collective reflects the evolution of the work we’ve already been doing for our clients. It gives our threat research and intelligence capability its own identity and creates a platform through which we can share more of our research, collaborate more closely with customers and continue helping organisations stay one step ahead of an increasingly complex threat landscape.”
Alongside its advisory services, BCON Collective will expand its programme of original threat research, annual intelligence reports, threat actor profiling and strategic intelligence briefings for organisations operating across critical national infrastructure, the public sector and commercial sectors.
The post Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective appeared first on IT Security Guru.
Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns
Global ransomware attacks climbed 3% in the second quarter of 2026, rising from 2,165 incidents in Q1 to 2,229, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. While the increase in volume was modest, the security firm warned that supply chain attacks are growing rapidly in both scale and sophistication, and that the overall trajectory of ransomware activity continues to point upwards.
The report recorded 665 ransomware attacks in June alone, with the industrials sector once again the most heavily targeted, accounting for 30% of attacks across the quarter and 28% in June. Consumer Discretionary and Information Technology rounded out the top three targeted sectors for the quarter.
North America remained the most targeted region, absorbing 44% of all Q2 attacks and 41% of June’s total, followed by Europe (26% for the quarter, 23% in June) and Asia. Qilin held its position as the most active ransomware group for a fifth consecutive quarter, linked to 14% of all Q2 attacks (301 victims), ahead of The Gentlemen (238 victims) and DragonForce (145 victims). NCC Group also flagged the emergence of KryBit, a new Ransomware-as-a-Service operation that claimed 56 victims in its first full quarter of activity.
VPNs remain a favoured entry point
The report’s spotlight section highlights corporate VPNs and internet-facing edge devices as the ransomware ecosystem’s most exploited entry point so far in 2026. Groups including Akira, Qilin and The Gentlemen have all been observed exploiting vulnerabilities in products from vendors such as Fortinet, SonicWall, Citrix and Check Point to bypass authentication and gain a foothold inside victim networks.
NCC Group said vulnerabilities affecting VPN products account for around 15% of the 150-plus Threat Intelligence Alerts it has issued so far this year, many rated high or critical severity. The report also points to “FortiBleed,” a large-scale credential exposure incident uncovered in June affecting roughly half of all publicly exposed FortiGate devices, as a development likely to fuel further exploitation in the coming months.
Software supply chain under sustained assault
Alongside the ransomware data, NCC Group’s analysts describe a marked escalation in attacks against the software development ecosystem during Q2, with campaigns hitting GitHub Actions, npm, PyPI, Docker Hub, Open VSX and the Visual Studio Code Marketplace. The financially motivated group TeamPCP was linked to some of the most significant activity, including the self-propagating “Mini Shai-Hulud” worm, which continued to spawn derivative campaigns, dubbed Miasma and Hades, after its source code was published to GitHub in May.
The report warns that these campaigns exploit “transitive trust” in software supply chains, turning maintainer accounts, CI/CD tokens and cloud credentials into high-value targets, with effects that can cascade well beyond the organisation initially compromised.
“A board-level issue”
Matt Hull, VP and Head of Cyber Intelligence and Response at NCC Group, said supply chain attacks remain one of the most attractive routes for threat actors to inflict significant operational, financial, and reputational damage, and that businesses need continuous, rather than ad hoc, monitoring and resilience.
“Although there has not been a material rise in ransomware volume in the last quarter,” Hull said, the trajectory of attacks continues upwards, and VPNs remain an increasingly attractive target. He added that organisations must treat cyber security as the board-level issue it is, pointing to geopolitical tensions and rapidly evolving AI capabilities as compounding pressures on defenders.
NCC Group’s report also examines the deepening professionalisation of ransomware operations such as The Gentlemen, a rapidly-scaling RaaS group whose leaked internal database revealed structured negotiation tactics and a dedicated suite of EDR-disabling tools distributed to affiliates. Separately, the report notes a growing convergence between commodity infostealer malware and higher-end intrusion tradecraft, with new variants adopting rootkit-style concealment, browser-extension-based credential theft, and off-host decryption to evade detection.
The full report also covers geopolitical developments, including rising China-Taiwan tensions, Belarus’s shifting posture toward Russia, and Ireland’s incoming EU Council presidency, which NCC Group assesses could shape targeting patterns for state-linked threat actors in the second half of the year.
The post Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns appeared first on IT Security Guru.
Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns
A new threat intelligence report has painted a stark picture of the cyber risks facing the UK and Ireland, describing an environment in which ransomware gangs, nation-state spies and politically motivated hacktivists are increasingly working the same terrain, often against the same victims.
The “Cyber Threat Landscape: UK & Ireland” report, published by threat intelligence firm CYFIRMA, finds that financially motivated cybercriminals and state-aligned actors are frequently targeting the same sectors, finance, telecoms, technology, healthcare and government, and warns that cybercrime, espionage and geopolitical disruption are becoming harder to tell apart.
Russia, China, North Korea and Iran all in the mix
According to the report, Russia remains the most immediate geopolitical cyber threat to the region, with Russian-linked groups focused on critical infrastructure, undersea cables and disinformation tied to the ongoing war in Ukraine. China is flagged as the more significant long-term concern, with state-linked groups pursuing intellectual property theft and “living off the land” techniques designed to maintain quiet, persistent access inside critical networks.
The report also names several state-sponsored groups actively targeting the UK, including Russia’s APT28 (Fancy Bear) and APT29 (Cozy Bear), and China-linked APT15 and GALLIUM. It highlights a recent APT28 campaign that hijacks vulnerable home and small-office routers to redirect DNS traffic, quietly harvesting credentials and login tokens from unsuspecting users. North Korea’s Lazarus Group is also named in connection with fake job-offer lures targeting European defence and drone manufacturers, part of the long-running “Operation DreamJob” campaign.
Ransomware still dominates, with the UK bearing the brunt
Ransomware remains the most visible threat. CYFIRMA’s data shows Qilin as the most active gang targeting the region between January and May 2026, followed by DragonForce, The Gentlemen and Cl0p, with the UK absorbing the overwhelming majority of recorded victims. Ireland saw far fewer incidents, but the report notes that groups including The Gentlemen, Qilin and Interlock have all claimed Irish victims, and activity there peaked sharply in May 2026.
Professional services, manufacturing, real estate and IT emerged as the sectors hit hardest by ransomware, the report finds, with most groups now relying on double extortion, encrypting systems while also stealing data to threaten public leaks if a ransom isn’t paid.
Financially motivated crews get creative with social engineering
The report also details the tactics of financially motivated groups such as FIN6, which has been posing as job seekers on LinkedIn and Indeed to trick recruiters into opening fake résumé links laced with malware, and Scattered Spider, which continues to abuse identity and access management systems by impersonating employees to helpdesk staff in order to reset credentials or bypass multi-factor authentication.
Dark web trade in UK and Irish data continues unabated
Beyond ransomware, the report catalogues a steady stream of underground forum listings offering UK and Irish personal data for sale throughout 2026 — including an alleged 120-million-record database from a UK gambling platform, a combo list of more than 657,000 UK email-password pairs, and a dataset said to contain 734,000 UK student records. CYFIRMA says this reflects a growing emphasis among criminal groups on monetising stolen data and credentials rather than relying solely on encryption-based extortion.
Critical vulnerabilities add to the pressure
The report also flags a cluster of critical vulnerabilities disclosed during the period, including several rated 9.0 or above in the n8n workflow automation platform, Cisco’s Secure Firewall ASA and FTD software, Fortinet’s FortiOS and FortiProxy products, and VMware’s ESXi and Workstation platforms — several of which have already been linked to active exploitation.
What organisations should do
CYFIRMA’s recommendations for organisations in both countries include:
- Accelerating patching of internet-facing systems, VPNs and edge devices, which remain the most common entry point for both ransomware crews and state-backed actors.
- Enforcing phishing-resistant multi-factor authentication and tightening helpdesk identity-verification processes to blunt social engineering attacks like those used by Scattered Spider and FIN6.
- Testing ransomware and DDoS response plans, including backup recoverability, given the sustained pace of attacks on critical infrastructure and public services.
- Increasing scrutiny of third-party and vendor access, as supply chain compromise continues to be used to reach multiple organisations through a single trusted relationship.
The report’s overall message is one of convergence: as ransomware operators, spies and hacktivists increasingly pursue overlapping goals through similar tools and techniques, CYFIRMA argues that organisations can no longer treat these as separate risks to be managed in isolation.
The full research report can be found here: https://www.cyfirma.com/research/cyber-threat-landscape-uk-ireland/
The post Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns appeared first on IT Security Guru.
Volume Is Not Risk: Making Sense of the 'Vulnpocalypse'
KeeperPAM strengthens privileged access management for global construction SaaS provider Asite
Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations.
The deployment, detailed in a newly published customer case study, sees Asite replace a collection of legacy privileged access and secrets management tools with Keeper’s unified, cloud-native platform as it looks to improve visibility, simplify administration and better secure access across its international infrastructure.
Asite provides cloud-based collaboration software for the construction industry, helping organisations manage projects ranging from digital twins and 3D models to document control and supplier collaboration. With more than 500 employees and data centres spanning nine global locations, the company required a more consistent approach to managing privileged accounts, passwords and machine identities.
According to the case study, Asite was looking to overcome the limitations of browser-based password managers alongside legacy privileged access management (PAM) and secrets management tools, which it found expensive and complex to maintain. The company also needed to securely extend privileged access controls to third-party suppliers and external partners working on customer projects.
“The deployment of KeeperPAM was extremely easy, one of the best in my experience,” said Tiago Rosado, Chief Information Security Officer at Asite. “I wish other tools were as easy to deploy.”
As part of the rollout, Asite standardised password management across its workforce using Keeper’s platform, replacing browser-based password managers with centrally managed credential controls. The organisation also implemented Keeper BreachWatch to identify compromised credentials exposed on the dark web, while Keeper Secrets Manager automated the creation and rotation of secrets and encryption keys, reducing reliance on long-lived credentials.
Keeper said the deployment reflects a broader challenge facing organisations managing privileged access across distributed IT environments. Its 2026 research found that 34% of UK employees reuse passwords across multiple accounts, while 36% of UK respondents said enforcing strong password and credential practices remains either extremely or very challenging for IT and security teams.
The vendor positions KeeperPAM as a unified, cloud-native platform that combines enterprise password management, secrets management, privileged session management, endpoint privilege management, secure remote access and dark web monitoring within a single zero-trust architecture.
“Privileged access management has become a critical control layer for any organisation operating across distributed infrastructure and third-party ecosystems,” said Darren Guccione, CEO and Co-founder of Keeper Security. “Asite’s deployment of KeeperPAM demonstrates how organisations can move from fragmented, costly legacy tools to a unified platform that enforces least-privilege access, automates provisioning and delivers the visibility their security team needs, without the complexity that has historically made PAM difficult to scale.”
The full customer case study is available on the Keeper Security website.
The post KeeperPAM strengthens privileged access management for global construction SaaS provider Asite appeared first on IT Security Guru.