Tag: framework
-
Authority-Modell für KI-Agenten in der Lagerverwaltung
Logistics Reply, ein auf innovative Lösungen für Warehouse- und Supply-Chain-Execution spezialisiertes Unternehmen der Reply Gruppe, präsentiert das ‘LEA AI Agent Authority Model”: Das neue, praxisorientierte Framework wird gemeinsam mit ‘LEA Dynamic Intelligence” bereitgestellt und unterstützt Unternehmen dabei, KI-Agenten mit der jeweils passenden Befugnis für ihre Aufgaben einzusetzen, anstatt ihnen maximale Autonomie zu gewähren. Da KI zunehmend…
-
New 2CLoader Malware Uses Anti-VM and API Hooking to Deliver Vidar and Remus Stealers
A new Windows malware loader, tracked as 2CLoader, that combines extensive anti-analysis logic, indirect system calls, API tampering, and flexible in-memory execution to deliver Vidar and Remus information stealers. Researchers also observed the loader distributing XWorm RAT, indicating that its operators can use the framework to deploy multiple payload families. Its layered design makes it…
-
New 2CLoader Malware Uses Anti-VM and API Hooking to Deliver Vidar and Remus Stealers
A new Windows malware loader, tracked as 2CLoader, that combines extensive anti-analysis logic, indirect system calls, API tampering, and flexible in-memory execution to deliver Vidar and Remus information stealers. Researchers also observed the loader distributing XWorm RAT, indicating that its operators can use the framework to deploy multiple payload families. Its layered design makes it…
-
Hackers Target 5,700 Microsoft 365 Accounts Using Forgotten Service Accounts With No MFA
Threat actors have targeted more than 5,700 Microsoft 365 accounts across 28 tenants in a password-spraying campaign that successfully breached seven forgotten service accounts lacking MFA. The activity, tracked by Proofpoint as UNK_CondorFiltration, focused heavily on Chilean retail and financial organizations and abused the TeamFiltration offensive framework. The framework, initially created for legitimate Microsoft 365…
-
‘NeedyMantis’ Provides Long-Term Access to Compromised Networks
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/needymantis-long-term-access-compromised-networks
-
Apple Fixes iOS Zero-Day Exploited in Sophisticated Targeted Attacks
Apple has released iOS 26.7.1 and iPadOS 26.7.1 to address CVE-2026-86950, a zero-day vulnerability in CoreGraphics that may have been exploited in sophisticated, targeted attacks against specific individuals. Apple’s latest security updates fix an out-of-bounds write vulnerability in CoreGraphics, the graphics rendering framework used on iPhone and iPad devices. This flaw, tracked as CVE-2026-86950, could…
-
Microsoft Tracks NeedyMantis Malware Targeting Telecoms and Government Contractors
Microsoft Threat Intelligence has discovered NeedyMantis, a modular post-compromise malware framework that targets specific industries, including telecommunications firms, government contractors, universities, medical nonprofits, and intergovernmental organizations. Unlike typical malware that serves as an initial access point, NeedyMantis is designed to maintain an attacker’s access and support follow-on operations after an initial breach. NeedyMantis activity has…
-
Microsoft Tracks NeedyMantis Malware Targeting Telecoms and Government Contractors
Microsoft Threat Intelligence has discovered NeedyMantis, a modular post-compromise malware framework that targets specific industries, including telecommunications firms, government contractors, universities, medical nonprofits, and intergovernmental organizations. Unlike typical malware that serves as an initial access point, NeedyMantis is designed to maintain an attacker’s access and support follow-on operations after an initial breach. NeedyMantis activity has…
-
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/carbonato-botnet-ai-agent-hacked-docker-hosts
-
IAM for AI agents: A Practical Enterprise Framework
What is IAM for AI agents?AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved…
-
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that’s targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent.”The implant installs the framework unchanged, then overwrites its SOUL.md persona file,” ThreatDown said. “The 39-line prompt directs it to execute tasks received through First seen on…
-
New Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies
A Python-based information stealer that targets data from 17 Chromium-based browsers, alongside Firefox, to harvest saved credentials, payment-card details, browsing history and active session cookies. The malware is delivered through a builder framework that enables operators to generate customized Windows payloads and configure their own data-exfiltration webhook. The archive included a “TokenGrabber Builder” folder containing…
-
12 Best Cloud Compliance Tools Compared (2026): Features Pricing
For most teams facing an audit, Vanta is the best overall compliance automation platform, with Drata the closest rival choose between them on integrations and framework-crosswalk economics. For technical posture evidence, free open-source Prowler plus a CNAPP compliance view (Wiz, Prisma, Orca) covers the engineering side to prevent cloud misconfigurations that lead to data breaches.…
-
Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers
Tags: access, ai, authentication, botnet, control, cyber, data-breach, docker, framework, hacker, open-source, tool, wormA Docker-focused botnet that repurposes the legitimate, open-source Hermes Agent framework as an interactive post-compromise control layer. The campaign, tracked as CARBONATO, targets Docker daemons exposed without authentication on TCP port 2375, then combines worm-like propagation, stealthy persistence, reverse SSH access and Telegram-driven AI-agent operations. The investigation began in August 2026 after researchers identified a…
-
Realizing Value From AI Starts With Redesigning the Business
OpenAI’s Colin Jarvis on Workflow Redesign, Trust Frameworks and Human Oversight. Organizations that simply insert AI into existing workflows might not capture its full value. But those willing to redesign processes, establish governance, control data access and restructure teams around it will derive the most value, said Colin Jarvis, global head of FDE at OpenAI.…
-
KI-Governance umsetzen: Wie CIOs Richtlinie, Rechte und Nachweise zusammenbringen
KI-Governance wird für CIOs zur Umsetzungsdisziplin: Richtlinien allein reichen nicht, wenn Identitäten, Rollen, Freigaben und Protokolle technisch unverbunden bleiben. Der Beitrag zeigt, wie Unternehmen rechtliche Vorgaben in kontrollierbare Zugänge übersetzen, Nachweise auditfest organisieren und den Aufbau eines tragfähigen Frameworks realistisch planen. Management Summary Governance wird erst durchsetzbar: Eine KI-Richtlinie entfaltet Wirkung, wenn jede Regel mit……
-
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/
-
How to Build A SASE Framework for Modern Cybersecurity
Keeping edge computing safe requires organizations to fundamentally rethink security governance. Here is a path forward: a step-by-step guide to building a SASE framework. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/how-to-build-sase-framework
-
CISA Charts New Quality Era for Global CVE Program
CISA has set out a new framework to improve CVE data quality as vulnerability volumes rise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-quality-era-global-cve-program/
-
Researchers uncover malware that uses AI to choose its next move
To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/22/cairn-open-source-framework-ai-malware-closedquorum/
-
A New Tool Found Malware That’s Guided by an AI Hive Mind”, No Humans in Sight
Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots”, and quickly discovered something unusual. First seen on wired.com Jump to article: www.wired.com/story/a-tool-for-tracking-ai-integrated-malware-uncovered-an-autonomous-command-system/
-
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/rogue-behavior-openai-more-model-misalignment-incidents
-
New Exvicy ClickFix Framework Built on Rival ErrTraffic’s Code
Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/exvicy-clickfix-framework/
-
OpenAI Reveals AI Models Concealing Mistakes, Using Exposed API Keys and Sharing Files
OpenAI has introduced a new framework for reporting model misalignment after discovering instances where its AI systems concealed mistakes, accessed exposed API keys, fabricated data, uploaded files without authorization, and communicated through unintended channels. The company released six initial reports detailing behaviors observed during model training and evaluation. They argue that AI developers need more…
-
MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2
A newly identified Windows malware framework dubbed MovieReaper is being distributed through pirated movie torrents after threat actors compromised a public torrent-file repository used by multiple tracker sites. The campaign combines a multi-stage infection chain, anti-analysis techniques, UAC bypass, file-management capabilities, and Solana blockchain-based command-and-control (C2) discovery to make disruption more difficult. Kaspersky researchers identified…
-
OpenAI admits its models lie to cover their own mistakes
OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a formal framework for tracking, investigating, and disclosing cases of model misalignment, paired with six…
-
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded First…
-
Compliance evidence should be a quick query, not a static spreadsheet you constantly need to rebuild FireTail Blog
Sep 16, 2026 – Ayush Sethi – The frameworks are not the hard part. Proving that what you actually run lines up with them, on the day someone asks, is.It usually starts with an email like this one.Nothing in that… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/compliance-evidence-should-be-a-quick-query-not-a-static-spreadsheet-you-constantly-need-to-rebuild-firetail-blog/
-
China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites. Exploiting a vast and routinely ignored category of internet infrastructure to blend malware traffic into apparent gambling activity. The activity expands on earlier findings by Trend Micro, which identified PeckBirdy as a flexible JScript-based C2 framework used by China-aligned…

