Tag: control
-
New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration
A previously unreported data extortion operation dubbed “Helix” that targets enterprises using identity-focused entry techniques and automated SharePoint exfiltration. The group’s playbook combines voice phishing (vishing), device-code phishing to capture session tokens and bypass Conditional Access controls, rapid MFA registration for persistence, and scripted enumeration and bulk download of SharePoint content all staged from shared…
-
New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration
A previously unreported data extortion operation dubbed “Helix” that targets enterprises using identity-focused entry techniques and automated SharePoint exfiltration. The group’s playbook combines voice phishing (vishing), device-code phishing to capture session tokens and bypass Conditional Access controls, rapid MFA registration for persistence, and scripted enumeration and bulk download of SharePoint content all staged from shared…
-
Claude AI Prompt Injection Attack Turns Chatbot Into Stealthy C2 Agent to Achieve Remote Code Execution
Claude Desktop’s synced Personal Preferences feature can be exploited as a covert prompt-injection vector, transforming the AI assistant into a de facto command-and-control (C2) agent. This method allows for remote code execution on a compromised user workstation without the need for phishing emails or traditional malware delivery. In this attack chain, the initial access is…
-
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer’s computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead.The affected tools are Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google…
-
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution.The list of vulnerabilities is as follows – CVE-2026-50746 (CVSS score: 10.0) – An improper access control vulnerability in UniFi Connect Application that an…
-
Fancy Bear Uses LSB Steganography and Reflective Loading to Run C# Remote-Control Trojan
A new intrusion campaign attributed to APT”‘C”‘20 (aka Fancy Bear, APT28) demonstrates the group’s continued refinement of stealthy, fileless techniques: weaponized Office documents that deploy a COM”‘hijacking DLL. Extract shellcode hidden via LSB steganography in a PNG, and use reflective loading to run an obfuscated C# remote”‘control Trojan that communicates through the legitimate cloud storage…
-
Claude Cowork turns your phone into a remote control for AI work
Anthropic started rolling out Claude Cowork, an AI agent that completes multi-step tasks, in beta for Max users on mobile and the web. They describe a goal, and Claude plans … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/claude-cowork-phone-mobile-web/
-
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network…
-
LONGLEASH Malware Adds Reverse Shell, Proxying, and Intermediate C2 Capabilities
A significant upgrade to malware maintained by the UAT-7810 actor: LONGLEASH, a successor to the previously reported SHORTLEASH implant, now sporting reverse-shell, multi-protocol proxying, and intermediate command-and-control (C2) forwarding capabilities. LONGLEASH retains SHORTLEASH’s ff-agent codebase but expands its operational scope. The implant, internally named “nz1.0,” splits into Base, Executor, and Core modules. The Base module…
-
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed “Rogue Agent,” the flaw exposed a serious design gap in how Dialogflow CX executes custom…
-
GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
A critical vulnerability known as >>GitLost<< has been discovered in GitHub's newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to exfiltrate sensitive data from private repositories. It demonstrates how AI-driven automation within development pipelines can be manipulated to bypass conventional access controls and leak confidential information across repository boundaries. GitLost Vulnerability…
-
EU Pushes for Domestic AI Momentum
Eurozone Banks Told to Strengthen Controls Amid AI Vulnerability Disclosure Wave. Europe is planning for improved capabilities to evaluate the cybersecurity implications of frontier artificial intelligence models – and will possibly mount a grand challenge for developing AI-powered cybersecurity systems – as part of a new strategy unveiled Tuesday. First seen on govinfosecurity.com Jump to…
-
AI Sovereignty Is a New Test for Enterprises
Enterprises are Rethinking Operational Risks to Gain Greater Control of AI Stacks. IBM reports that only 9% of executives fully understand their AI dependencies, while 71% say switching vendors would be difficult. AI sovereignty concerns reached a fevered pitch for tech leaders last month after Anthropic switched off two of its most capable artificial intelligence…
-
AI Sovereignty Is a New Test for Enterprises
Enterprises are Rethinking Operational Risks to Gain Greater Control of AI Stacks. IBM reports that only 9% of executives fully understand their AI dependencies, while 71% say switching vendors would be difficult. AI sovereignty concerns reached a fevered pitch for tech leaders last month after Anthropic switched off two of its most capable artificial intelligence…
-
AI Sovereignty Is a New Test for Enterprises
Enterprises are Rethinking Operational Risks to Gain Greater Control of AI Stacks. IBM reports that only 9% of executives fully understand their AI dependencies, while 71% say switching vendors would be difficult. AI sovereignty concerns reached a fevered pitch for tech leaders last month after Anthropic switched off two of its most capable artificial intelligence…
-
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC.”The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the…
-
Businesses modernizing networks for AI fear expanding attack surface, limited visibility
IT leaders are worried that security controls aren’t keeping pace with threats to AI systems. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-network-expansion-security-concerns-cisco/824581/
-
Businesses modernizing networks for AI fear expanding attack surface, limited visibility
IT leaders are worried that security controls aren’t keeping pace with threats to AI systems. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-network-expansion-security-concerns-cisco/824581/
-
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices.The vulnerabilities are listed below – CVE-2026-40138 (CVSS score: 9.2) – A pre-authentication vulnerability exists in the First seen on thehackernews.com Jump…
-
Cavern Manticore Malware Uses Low-Detection .NET Modules for Reconnaissance and Lateral Movement
A newly identified Iran-linked threat group, tracked as Cavern Manticore, is deploying a sophisticated modular command-and-control (C2) framework built on a shared .NET foundation to conduct stealthy reconnaissance and lateral movement against Israeli government and IT organizations. The group’s custom C2 components exhibit extremely low detection rates on public sandboxes, enabling persistent access while evading…
-
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group affiliated with Iran’s Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations.The activity, which has primarily singled out IT providers and government sectors, has been attributed to a threat cluster tracked by Check Point Research First seen…
-
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
ey Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig…
-
SilverFox Campaign Turns ValleyRAT Into Multi-Stage Malware With Rootkit Capabilities
The SilverFox advanced persistent threat (APT) group has escalated its offensive toolkit by transforming ValleyRAT from a conventional remote access trojan into an eight-stage malware chain culminating in a kernel-mode rootkit. This evolution marks a significant shift in post-exploitation persistence, blending user-mode orchestration with deep kernel control to evade detection and maintain long-term access. The…
-
Hackers Use RedLine C2 Infrastructure to Target South Korean Maritime Industry
A single RedLine Stealer command-and-control (C2) indicator has revealed a focused spear-phishing campaign targeting the South Korean maritime industry, exposing a cluster of attacker-owned domains and mail infrastructure used to distribute credential-stealing payloads. The initial signal originated from a VMRay UniqueSignal feed: an IP observed running RedLine activity on a non-standard high port (194[.]156.79.122:55615). That…
-
New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out.Bad Epoll sits in the same small stretch of kernel code where Anthropic’s most powerful AI model, Mythos,…
-
ISMG Editors: Signs of Russia in Jaguar Land Rover Probe
Also: AI Export Controls Reshape Post-Quantum Debate, Grappling With AI Governance. In this week’s ISMG Editors’ Panel, four editors discussed new developments in the Jaguar Land Rover cyberattack probe, why export controls on artificial intelligence tools are reshaping post-quantum cryptography plans, and cybersecurity leaders’ latest thinking about how to best govern AI. First seen on…
-
ChatGPT Guardrail Bypass Vulnerability Exposes LFI Risk Through Download Flow
A now-patched guardrail bypass in ChatGPT that could be exploited through a Local File Inclusion (LFI) vulnerability via its file download mechanism. This incident underscores how logic flaws in large language model (LLM) workflows, particularly concerning temporary file handling and access controls, can create exploitable weaknesses, even in sandboxed environments. ChatGPT Guardrail Bypass Vulnerability The…
-
Google Disrupts NetNut Residential Proxy Botnet Used for Malware C2 and Password Spray Attacks
Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks. This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat Intelligence Group (GTIG) on July 3, 2026. This action is part of an ongoing campaign to…
-
Why CIOs Need an AI Sovereignty Strategy
IBM Finds AI Vendor Disruptions Are Raising Costs and Operational Risk. Most enterprises are more dependent on their AI vendors than they realize, and a new IBM study puts a dollar figure on what that exposure costs. Here’s what CIOs need to know about taking back control before conditions force their hand. First seen on…
-
Keyfactor stellt Trust Control Plane für einheitliches Management digitaler Vertrauensinfrastrukturen vor
Tags: controlDie Einführung der Trust Control Plane zeigt, dass digitale Vertrauensinfrastruktur nicht länger als Hintergrundtechnik betrachtet werden kann. Sie wird zu einem zentralen Resilienzfaktor. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/keyfactor-stellt-trust-control-plane-fuer-einheitliches-management-digitaler-vertrauensinfrastrukturen-vor/a45658/

